This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer has been going slow [Closed]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So the past few days, maybe week, my computer has been going slower than normal So, I did the following yesterday to try to help the situation: - Ran ATF-Cleaner to clear out some junk - Ran Dick Cleanup to clear out some more junk Didn't help much, so today I updated my MBAM & did a full scan. It didn't find anything Anything else I can do to make sure it's not malware slowing me down?
Hello ezpkns34 and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Download and run OTL
  • download OTL to your desktop.
  • double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • click Scan all users.
  • under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    consrv.dll
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT

  • click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • you may need two posts to fit them both in.
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply
Logs to include with next post:

OTL.txt
Extras.txt
aswMBR log


Thanks

Satchfan
Hey Satchfan, thanks for the reply. Here are 2 of the .txts below (the Extras.txt from OTL never opened or saved to my desktop, though OTL.txt did)

OTL
OTL logfile created on: 4/17/2013 8:38:05 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Nick\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.94 Gb Total Physical Memory | 2.59 Gb Available Physical Memory | 65.82% Memory free
7.87 Gb Paging File | 6.08 Gb Available in Paging File | 77.24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 453.47 Gb Total Space | 280.74 Gb Free Space | 61.91% Space Free | Partition Type: NTFS

Computer Name: NICK-PC | User Name: Nick | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Nick\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Nick\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe (SlimWare Utilities, Inc.)
PRC - C:\Users\Nick\AppData\Local\Google\Update\1.3.21.135\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Ad-Aware Antivirus\AdAware.exe (Lavasoft Limited)
PRC - C:\Windows\Runservice.exe ()
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe (GFI Software)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe ()
PRC - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Users\Nick\Local Settings\Apps\F.lux\flux.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\b26c0ed378c4b15c60cef0baada4e0dc\System.ServiceModel.Routing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\ebf949aee7febad1902974b1a2bd77a2\System.ServiceModel.Discovery.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\800370766976fd4ec232b4e29781717d\System.ServiceModel.Channels.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\b15622741724e17f1335c4771c3700a0\System.ServiceModel.Activities.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\a0445401f2473a1aa4b66c9c0791c7f6\System.ServiceModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\c1b67737c13c99776cde5989ec2885c8\System.IdentityModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\IAStorDataMgrSvcInt#\dedf199d04be73f377dca07663d16314\IAStorDataMgrSvcInterfaces.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\866894ebe5258bf9f45d6b063229e990\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\IAStorUtil\a0e807949b2aea788d359fed84f8139f\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\IAStorCommon\f860592ad08cd50636eb3fc2904a7b64\IAStorCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\910fe53ec2122cf3a2ad11c2b2f5cbfd\System.Runtime.Serialization.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\e7b4706dfe18f29486dbaf5d35e01765\System.Runtime.DurableInstancing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\dcb0e7d56ffca14d7c483103235b11ad\System.Transactions.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\ef7642a4f2724135d445e2ea36582e78\SMDiagnostics.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\39f4c7717661667c68f9af8c4f6402b9\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\27dcf04ed7a3506045597c02a5a1fc31\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\43cd41484df96d15df949eb17dd88152\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\b573c6a62bb88df0ee2af59b6a8ca910\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\5de5d8c1c02e33789e3cf7e3f54c0ec9\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\15872842e3e63ddf0f720f406706198e\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3f95a6d480ed1ebe45cf27b770ba94ed\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe ()
MOD - C:\Users\Nick\Local Settings\Apps\F.lux\flux.exe ()


========== Services (SafeList) ==========

SRV:64bit: - (ZeroConfigService) – C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel® Corporation)
SRV:64bit: - (MyWiFiDHCPDNS) – C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV:64bit: - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV:64bit: - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV:64bit: - (BTHSSecurityMgr) – C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel® Corporation)
SRV:64bit: - (AMPPALR3) – C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel Corporation)
SRV:64bit: - (btwdins) – C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV:64bit: - (TurboBoost) – C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel® Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (RtkAudioService) – C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Realtek Semiconductor)
SRV:64bit: - (AERTFilters) – C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (TeamViewer8) – C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (IAStorDataMgrSvc) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (Ad-Aware Service) – C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe (Lavasoft Limited)
SRV - (LicCtrlService) – C:\Windows\Runservice.exe ()
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (SBAMSvc) – C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe (GFI Software)
SRV - (npggsvc) – C:\Windows\SysWOW64\GameMon.des (INCA Internet Co., Ltd.)
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) – C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SWDUMon) – C:\Windows\SysNative\drivers\SWDUMon.sys ()
DRV:64bit: - (dtsoftbus01) – C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (iaStorA) – C:\Windows\SysNative\drivers\iaStorA.sys (Intel Corporation)
DRV:64bit: - (iaStorF) – C:\Windows\SysNative\drivers\iaStorF.sys (Intel Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (NETwNs64) – C:\Windows\SysNative\drivers\Netwsw00.sys (Intel Corporation)
DRV:64bit: - (AMPPALP) – C:\Windows\SysNative\drivers\AmpPal.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (AMPPAL) – C:\Windows\SysNative\drivers\AmpPal.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (sbhips) – C:\Windows\SysNative\drivers\sbhips.sys (GFI Software)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (sbapifs) – C:\Windows\SysNative\drivers\sbapifs.sys (GFI Software)
DRV:64bit: - (SBRE) – C:\Windows\SysNative\drivers\sbredrv.sys (GFI Software)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Rovi Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (HECIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (stdcfltn) – C:\Windows\SysNative\drivers\stdcfltn.sys (ST Microelectronics)
DRV:64bit: - (Acceler) – C:\Windows\SysNative\drivers\Accelern.sys (ST Microelectronics)
DRV:64bit: - (qicflt) – C:\Windows\SysNative\drivers\qicflt.sys (Quanta Computer)
DRV:64bit: - (TurboB) – C:\Windows\SysNative\drivers\TurboB.sys ()
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (xnacc) – C:\Windows\SysNative\drivers\xnacc.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (regi) – C:\Windows\SysNative\drivers\regi.sys (InterVideo)
DRV:64bit: - (BTWAMPFL) – C:\Windows\SysNative\drivers\btwampfl.sys (Broadcom Corporation.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (btwavdt) – C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (btwaudio) – C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (JMCR) – C:\Windows\SysNative\drivers\jmcr.sys (JMicron Technology Corporation)
DRV:64bit: - (btwl2cap) – C:\Windows\SysNative\drivers\btwl2cap.sys (Broadcom Corporation.)
DRV:64bit: - (btwrchid) – C:\Windows\SysNative\drivers\btwrchid.sys (Broadcom Corporation.)
DRV - (SBRE) – C:\Windows\SysWOW64\drivers\SBREDrv.sys (GFI Software)
DRV - (Htsysm) – C:\Windows\SysWOW64\HtsysmNT.sys ()
DRV - (cpuz134) – C:\Program Files (x86)\pc-wizard\pcwiz_x64.sys (Windows ® Win 7 DDK provider)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (NPPTNT2) – C:\Windows\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-762202037-2163149629-1470818234-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKU\S-1-5-21-762202037-2163149629-1470818234-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-762202037-2163149629-1470818234-1000\..\SearchScopes\{88833EF9-5986-4DBD-850E-44C299234F1E}: "URL" = http://www.mysearchresults.com/search?&…q={searchTerms}
IE - HKU\S-1-5-21-762202037-2163149629-1470818234-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-762202037-2163149629-1470818234-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =


========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Wikipedia (en)"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://www.google.com/"
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.2.145
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.3
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20120515
FF - prefs.js..extensions.enabledItems: [removed]:1.7.3
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.20
FF - prefs.js..extensions.enabledItems: [removed]:1.3.3
FF - prefs.js..extensions.enabledItems: [removed]:1.1.3
FF - prefs.js..extensions.enabledItems: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:5.9
FF - prefs.js..extensions.enabledItems: [removed]:3.6.7
FF - prefs.js..extensions.enabledItems: [removed]:1.0.1
FF - prefs.js..extensions.enabledItems: {4a313247-8330-4a81-948e-b79936516f78}:2.0.2
FF - prefs.js..extensions.enabledItems: {ab4b5718-3998-4a2c-91ae-18a7c2db513e}:1.0.3
FF - prefs.js..extensions.enabledItems: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.2.2
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.10
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3279141&SearchSource;=2&CUI;=UN21365894533171620&sspv;=SP_FFNSP06&q;="


FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll File not found
FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Nick\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Nick\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/03/28 14:39:44 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/02/07 06:14:23 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.25\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/02/07 06:14:23 | 000,000,000 | —D | M]

[2011/12/03 02:01:56 | 000,000,000 | —D | M] (No name found) – C:\Users\Nick\AppData\Roaming\Mozilla\Extensions
[2013/02/11 05:27:27 | 000,000,000 | —D | M] (No name found) – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\wn3b2hsv.default\extensions
[2012/12/08 05:31:08 | 000,000,000 | —D | M] (Stylish) – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\wn3b2hsv.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2012/11/14 15:46:40 | 000,000,000 | —D | M] (Image Search Options) – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\wn3b2hsv.default\extensions\{4a313247-8330-4a81-948e-b79936516f78}
[2012/05/18 01:45:05 | 000,000,000 | —D | M] (WOT) – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\wn3b2hsv.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2012/11/14 15:46:40 | 000,000,000 | —D | M] (Search by Image for Google) – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\wn3b2hsv.default\extensions\{ab4b5718-3998-4a2c-91ae-18a7c2db513e}
[2013/02/11 00:36:24 | 000,000,000 | —D | M] ("Free YouTube Download (Free Studio) Menu") – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\wn3b2hsv.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012/07/11 15:29:39 | 000,000,000 | —D | M] (Easy YouTube Video Downloader) – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\wn3b2hsv.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}
[2012/01/23 14:47:19 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\wn3b2hsv.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2012/07/29 15:15:41 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\wn3b2hsv.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2012/07/29 15:15:38 | 000,000,000 | —D | M] ("Flash Video Downloader Youtube Downloader") – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\wn3b2hsv.default\extensions\[removed]
[2011/12/03 02:08:10 | 000,000,000 | —D | M] (Firebug) – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\wn3b2hsv.default\extensions\[removed]
[2012/01/23 14:46:52 | 000,000,000 | —D | M] ("urn:mozilla:install-manifest" em:creator="Matthew David Kesack" em:description="Upload images from the web directly to your Photobucket account." em:homepageURL="http://www.photobucket.com/" em:iconURL="chrome://photobucket/content/images/pb-logo.png" em:id="[removed]" em:name="Photobucket Uploader" em:version="1.3.3">) – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\wn3b2hsv.default\extensions\[removed]
[2012/08/18 00:27:57 | 000,000,000 | —D | M] ("Turn Off the Lights") – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\wn3b2hsv.default\extensions\[removed]
[2012/02/12 22:45:16 | 000,000,000 | —D | M] (Tab Utilities Lite) – C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\wn3b2hsv.default\extensions\[removed]
[2013/03/18 21:13:16 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/03/28 14:39:44 | 000,000,000 | —D | M] (DivX Plus Web Player HTML5 ) – C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{
google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Nick\AppData\Local\Google\Chrome\Application\26.0.1410.64\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Nick\AppData\Local\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Nick\AppData\Local\Google\Chrome\Application\26.0.1410.64\pdf.dll
CHR - plugin: Chrome Toolbox Plugin (Enabled) = C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjccknnhdnkbanjilpjddjhmkghmachn\1.0.32_0\plugin/convenience.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Java™ Platform SE 7 U9 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonEU\NGM\npNxGameeu.dll
CHR - plugin: Power Challenge Loader (Enabled) = C:\Users\Nick\AppData\LocalLow\POWERC~1\nppowerloader.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Nick\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 7.0.70.11 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: Turn Off the Lights = C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn\2.2_0\
CHR - Extension: WOT = C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.4.11_0\
CHR - Extension: YouTube = C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Firebug Lite for Google Chrome\u2122 = C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmagokdooijbeehmkpknfglimnifench\1.4.0.11967_0\
CHR - Extension: Adblock Plus = C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.4_0\
CHR - Extension: AdBlock+ = C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\chmimgmjdabgiilljdjfbonifbhiglao\1.1.9.18_0\
CHR - Extension: Google Search = C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Recent History = C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbmkfdfomhhlonpbnpiibloacemdhjjm\2.1.4.1_0\
CHR - Extension: Chrome Toolbox (by Google) = C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjccknnhdnkbanjilpjddjhmkghmachn\1.0.32_0\
CHR - Extension: AdBlock = C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.61_0\
CHR - Extension: Change Colors = C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbmkekhehjedonbhoikhhkmlapalklgn\2.144_0\
CHR - Extension: Shortcut Manager = C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgjjeipcdnnjhgodgjpfkffcejoljijf\0.7.9_0\
CHR - Extension: DVDVideoSoft Browser Extension = C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.2_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: One Window = C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\papnlnnbddhckngcblfljaelgceffobn\3.0.0_0\
CHR - Extension: Gmail = C:\Users\Nick\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2011/12/03 22:12:29 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2:64bit: - BHO: (DVDVideoSoft WebPageAdjuster Class) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Ad-Aware Security Toolbar) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll ()
O2 - BHO: (DVDVideoSoft WebPageAdjuster Class) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O3 - HKLM\..\Toolbar: (Ad-Aware Security Toolbar) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe ()
O4:64bit: - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SBRegRebootCleaner] C:\Program Files (x86)\Ad-Aware Antivirus\SBRC.exe (GFI Software)
O4 - HKLM..\Run: [Ad-Aware Antivirus] C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher.exe (Lavasoft Limited)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
O4 - HKU\S-1-5-21-762202037-2163149629-1470818234-1000..\Run: [Akamai NetSession Interface] "C:\Users\Nick\AppData\Local\Akamai\netsession_win.exe" File not found
O4 - HKU\S-1-5-21-762202037-2163149629-1470818234-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-762202037-2163149629-1470818234-1000..\Run: [F.lux] C:\Users\Nick\Local Settings\Apps\F.lux\flux.exe ()
O4 - HKU\S-1-5-21-762202037-2163149629-1470818234-1000..\Run: [Overwolf] C:\Program Files (x86)\Overwolf\Overwolf.exe -silent File not found
O4 - HKU\S-1-5-21-762202037-2163149629-1470818234-1001..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\S-1-5-21-762202037-2163149629-1470818234-1001..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Nick\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-762202037-2163149629-1470818234-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-762202037-2163149629-1470818234-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-762202037-2163149629-1470818234-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm ()
O8 - Extra context menu item: Free YouTube Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm ()
O9:64bit: - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
O9:64bit: - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
O9 - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O9 - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-21-762202037-2163149629-1470818234-1000\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-762202037-2163149629-1470818234-1000\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-762202037-2163149629-1470818234-1000\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-762202037-2163149629-1470818234-1000\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.systemrequirementslab.com.s…nt_4.4.26.0.cab (SysInfo Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.17.2)
O16 - DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8EA59F4E-36FB-428B-9FD6-1D47CD6AFFC2}: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O22:64bit: - SharedTaskScheduler: {73526E5A-FD53-4BE7-B5E2-D3C89D7413DC} - Ave's FolderBg - C:\Windows\W7FBC\dll.dll ()
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/04/17 20:36:24 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Nick\Desktop\OTL.exe
[2013/04/15 13:32:22 | 000,000,000 | —D | C] – C:\Malwarebytes' Anti-Malware
[2013/04/05 09:19:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Corporation
[2013/04/05 09:18:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PureSim Baseball 4
[2013/04/04 23:39:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PureSim Baseball 5
[2013/04/04 23:39:48 | 000,501,248 | –S- | C] ( datenhaus GmbH) – C:\Windows\SysWow64\dhRichClient3.dll
[2013/04/04 23:39:47 | 004,145,264 | –S- | C] (Kelly Ethridge) – C:\Windows\SysWow64\VBCorLib.dll
[2013/04/04 23:39:47 | 001,029,968 | –S- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mschrt20.ocx
[2013/04/04 23:39:47 | 000,215,880 | –S- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MCI32.OCX
[2013/04/04 23:39:47 | 000,150,528 | –S- | C] (Microsoft Corporation) – C:\Windows\SysWow64\TLBINF32.DLL
[2013/04/04 23:39:47 | 000,136,008 | –S- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSINET.OCX
[2013/04/01 20:53:49 | 000,000,000 | -H-D | C] – C:\ProgramData\{C5A3BAE5-4380-48C7-B0EB-49DD52078659}
[2013/04/01 20:53:46 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCAA 2011 Real World
[2013/04/01 19:16:57 | 000,000,000 | —D | C] – C:\Windows\W7FBC
[2013/03/31 21:12:58 | 001,388,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.03D
[2013/03/31 21:12:58 | 000,326,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.03E
[2013/03/31 21:12:58 | 000,164,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.03A
[2013/03/31 21:12:58 | 000,147,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.03B
[2013/03/31 21:12:58 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.03C
[2013/03/31 21:12:57 | 000,598,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.039
[2013/03/31 21:12:57 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.038
[2013/03/25 13:05:10 | 000,000,000 | —D | C] – C:\Users\Nick\AppData\Local\Broadcom
[2013/03/25 05:52:28 | 000,210,984 | —- | C] (Broadcom Corporation.) – C:\Windows\SysNative\drivers\btwavdt.sys
[2013/03/25 05:52:28 | 000,184,872 | —- | C] (Broadcom Corporation.) – C:\Windows\SysNative\drivers\btwaudio.sys
[2013/03/25 05:52:28 | 000,039,976 | —- | C] (Broadcom Corporation.) – C:\Windows\SysNative\drivers\btwl2cap.sys
[2013/03/25 05:52:28 | 000,021,544 | —- | C] (Broadcom Corporation.) – C:\Windows\SysNative\drivers\btwrchid.sys
[2013/03/25 05:38:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Intel Corporation
[2013/03/25 05:35:07 | 000,000,000 | —D | C] – C:\Users\Nick\AppData\Roaming\Intel Corporation
[2013/03/25 05:35:00 | 000,175,928 | —- | C] (JMicron Technology Corporation) – C:\Windows\SysNative\drivers\jmcr.sys
[2013/03/25 05:29:49 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
[2013/03/25 05:28:29 | 000,652,344 | —- | C] (Intel Corporation) – C:\Windows\SysNative\drivers\iaStorA.sys
[2013/03/25 05:28:29 | 000,028,216 | —- | C] (Intel Corporation) – C:\Windows\SysNative\drivers\iaStorF.sys
[2013/03/25 05:28:08 | 000,000,000 | —D | C] – C:\Users\Nick\AppData\Roaming\InstallShield
[2013/03/25 05:23:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Audio
[2013/03/25 05:23:22 | 000,000,000 | —D | C] – C:\Windows\SysNative\SRSLabs
[2013/03/25 05:23:19 | 000,000,000 | —D | C] – C:\Windows\SysWow64\RTCOM
[2013/03/25 05:22:43 | 002,080,120 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\WavesGUILib64.dll
[2013/03/25 05:22:43 | 000,518,896 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSTSX64.dll
[2013/03/25 05:22:43 | 000,155,888 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSWOW64.dll
[2013/03/25 05:22:42 | 000,211,184 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSTSH64.dll
[2013/03/25 05:22:42 | 000,198,896 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSHP64.dll
[2013/03/25 05:22:38 | 002,743,440 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtPgEx64.dll
[2013/03/25 05:22:38 | 001,561,744 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RTSnMg64.cpl
[2013/03/25 05:22:36 | 000,331,880 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtlCPAPI64.dll
[2013/03/25 05:22:34 | 003,673,232 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkAPO64.dll
[2013/03/25 05:22:34 | 000,378,000 | —- | C] (Realtek Semiconductor) – C:\Windows\SysNative\RtkGuiCompLib.dll
[2013/03/25 05:22:34 | 000,149,608 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkCfg64.dll
[2013/03/25 05:22:34 | 000,014,952 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkCoLDR64.dll
[2013/03/25 05:22:33 | 001,269,904 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RTCOM64.dll
[2013/03/25 05:22:33 | 000,881,808 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RtkApi64.dll
[2013/03/25 05:22:33 | 000,375,128 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEP64A.dll
[2013/03/25 05:22:33 | 000,204,120 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEED64A.dll
[2013/03/25 05:22:33 | 000,101,208 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEL64A.dll
[2013/03/25 05:22:33 | 000,078,680 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RTEEG64A.dll
[2013/03/25 05:22:32 | 010,612,736 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RCORES64.dat
[2013/03/25 05:22:32 | 000,310,104 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RP3DHT64.dll
[2013/03/25 05:22:32 | 000,310,104 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\SysNative\RP3DAA64.dll
[2013/03/25 05:22:32 | 000,118,928 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\SysNative\RCoInstII64.dll
[2013/03/25 05:22:26 | 000,897,152 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysNative\MBAPO64.dll
[2013/03/25 05:22:26 | 000,753,280 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysWow64\MBAPO32.dll
[2013/03/25 05:22:26 | 000,628,064 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysNative\MBTHX64.dll
[2013/03/25 05:22:26 | 000,563,552 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysWow64\MBTHX32.dll
[2013/03/25 05:22:26 | 000,083,072 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysNative\MBWrp64.dll
[2013/03/25 05:22:26 | 000,065,112 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysNative\MBppld64.dll
[2013/03/25 05:22:26 | 000,060,504 | —- | C] (Creative Technology Ltd.) – C:\Windows\SysNative\MBPPCn64.dll
[2013/03/25 05:22:25 | 009,546,616 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioRealtek64.dll
[2013/03/25 05:22:25 | 000,394,616 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxVolumeSDAPO.dll
[2013/03/25 05:22:24 | 001,460,600 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioRealtek264.dll
[2013/03/25 05:22:23 | 002,028,920 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioEQ64.dll
[2013/03/25 05:22:23 | 000,869,752 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioAPOShell64.dll
[2013/03/25 05:22:22 | 000,394,616 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioAPO30.dll
[2013/03/25 05:22:22 | 000,318,808 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioAPO20.dll
[2013/03/25 05:22:01 | 002,714,720 | —- | C] (Fortemedia Corporation) – C:\Windows\SysNative\FMAPO64.dll
[2013/03/25 05:22:01 | 000,693,352 | —- | C] (DTS) – C:\Windows\SysNative\DTSVoiceClarityDLL64.dll
[2013/03/25 05:21:56 | 001,756,264 | —- | C] (DTS) – C:\Windows\SysNative\DTSS2SpeakerDLL64.dll
[2013/03/25 05:21:56 | 000,712,296 | —- | C] (DTS) – C:\Windows\SysNative\DTSSymmetryDLL64.dll
[2013/03/25 05:21:55 | 001,568,360 | —- | C] (DTS) – C:\Windows\SysNative\DTSS2HeadphoneDLL64.dll
[2013/03/25 05:21:55 | 000,491,112 | —- | C] (DTS) – C:\Windows\SysNative\DTSNeoPCDLL64.dll
[2013/03/25 05:21:55 | 000,432,744 | —- | C] (DTS) – C:\Windows\SysNative\DTSLimiterDLL64.dll
[2013/03/25 05:21:55 | 000,242,792 | —- | C] (DTS) – C:\Windows\SysNative\DTSLFXAPO64.dll
[2013/03/25 05:21:54 | 001,486,952 | —- | C] (DTS) – C:\Windows\SysNative\DTSBoostDLL64.dll
[2013/03/25 05:21:54 | 000,728,680 | —- | C] (DTS) – C:\Windows\SysNative\DTSBassEnhancementDLL64.dll
[2013/03/25 05:21:54 | 000,428,648 | —- | C] (DTS) – C:\Windows\SysNative\DTSGainCompensatorDLL64.dll
[2013/03/25 05:21:54 | 000,242,792 | —- | C] (DTS) – C:\Windows\SysNative\DTSGFXAPO64.dll
[2013/03/25 05:21:54 | 000,241,768 | —- | C] (DTS) – C:\Windows\SysNative\DTSGFXAPONS64.dll
[2013/03/25 05:21:53 | 000,110,592 | —- | C] (Real Sound Lab SIA) – C:\Windows\SysNative\CONEQMSAPOGUILibrary.dll
[2013/03/25 05:21:46 | 000,202,336 | —- | C] (Andrea Electronics Corporation) – C:\Windows\SysNative\AERTAC64.dll
[2013/03/25 05:21:46 | 000,108,640 | —- | C] (Andrea Electronics Corporation) – C:\Windows\SysNative\AERTAR64.dll
[2013/03/25 05:10:37 | 000,053,248 | —- | C] (Windows XP Bundled build C-Centric Single User) – C:\Windows\SysWow64\CSVer.dll
[2013/03/25 05:01:37 | 000,565,352 | —- | C] (Realtek ) – C:\Windows\SysNative\drivers\Rt64win7.sys
[2013/03/25 04:53:35 | 000,000,000 | -H-D | C] – C:\Windows\SysNative\WLANProfiles
[2013/03/25 04:53:19 | 000,000,000 | —D | C] – C:\Users\Nick\Roaming
[2013/03/25 04:53:18 | 000,000,000 | —D | C] – C:\ProgramData\Roaming
[2013/03/25 04:53:15 | 000,000,000 | —D | C] – C:\ProgramData\Intel
[2013/03/25 04:51:44 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless
[2013/03/25 04:50:28 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Intel
[2013/03/25 04:50:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Cisco
[2013/03/25 04:33:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2013/03/25 04:29:14 | 000,189,288 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\drivers\nvhda64v.sys
[2013/03/25 04:29:14 | 000,031,080 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdap64.dll
[2013/03/25 04:29:13 | 026,931,488 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2013/03/25 04:29:13 | 025,256,224 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2013/03/25 04:29:13 | 020,450,080 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2013/03/25 04:29:13 | 018,054,672 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2013/03/25 04:29:13 | 017,560,352 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2013/03/25 04:29:13 | 012,641,480 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2013/03/25 04:29:13 | 007,932,256 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2013/03/25 04:29:13 | 007,565,088 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvopencl.dll
[2013/03/25 04:29:13 | 006,263,632 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvopencl.dll
[2013/03/25 04:29:13 | 002,904,352 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2013/03/25 04:29:13 | 002,720,544 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2013/03/25 04:29:13 | 002,344,736 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2013/03/25 04:29:13 | 001,985,824 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2013/03/25 04:29:13 | 001,510,176 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispgenco64.dll
[2013/03/25 04:29:07 | 009,390,760 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2013/03/25 04:23:11 | 000,000,000 | —D | C] – C:\Users\Nick\AppData\Local\SlimWare Utilities Inc
[2013/03/25 04:23:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimDrivers
[2013/03/25 04:23:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\SlimDrivers
[2013/03/25 04:22:52 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Downloaded Installers
[2013/03/25 03:59:25 | 000,367,616 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2013/03/25 03:59:25 | 000,295,424 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2013/03/25 03:59:25 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2013/03/25 03:59:25 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2013/03/25 03:57:58 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/03/25 03:57:58 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/03/25 03:57:58 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/03/25 03:57:57 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/03/25 03:57:57 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/03/25 03:57:57 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/03/25 03:57:57 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/03/25 03:57:56 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/03/25 03:57:55 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/03/25 03:57:55 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/03/25 03:57:55 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/03/25 03:57:55 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/03/25 03:57:53 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/03/25 03:57:53 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/03/25 03:57:53 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/03/25 03:52:12 | 002,746,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\gameux.dll
[2013/03/25 03:52:12 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Wpc.dll
[2013/03/25 03:52:12 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\SysWow64\fpb.rs
[2013/03/25 03:52:12 | 000,046,592 | —- | C] (Microsoft) – C:\Windows\SysNative\fpb.rs
[2013/03/25 03:52:12 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\SysWow64\oflc-nz.rs
[2013/03/25 03:52:12 | 000,045,568 | —- | C] (Microsoft) – C:\Windows\SysNative\oflc-nz.rs
[2013/03/25 03:52:12 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegibbfc.rs
[2013/03/25 03:52:12 | 000,044,544 | —- | C] (Microsoft) – C:\Windows\SysNative\pegibbfc.rs
[2013/03/25 03:52:12 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\SysWow64\csrr.rs
[2013/03/25 03:52:12 | 000,043,520 | —- | C] (Microsoft) – C:\Windows\SysNative\csrr.rs
[2013/03/25 03:52:12 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\SysWow64\cob-au.rs
[2013/03/25 03:52:12 | 000,040,960 | —- | C] (Microsoft) – C:\Windows\SysNative\cob-au.rs
[2013/03/25 03:52:12 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\SysWow64\usk.rs
[2013/03/25 03:52:12 | 000,030,720 | —- | C] (Microsoft) – C:\Windows\SysNative\usk.rs
[2013/03/25 03:52:12 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\SysWow64\grb.rs
[2013/03/25 03:52:12 | 000,021,504 | —- | C] (Microsoft) – C:\Windows\SysNative\grb.rs
[2013/03/25 03:52:12 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi-pt.rs
[2013/03/25 03:52:12 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi-pt.rs
[2013/03/25 03:52:12 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi.rs
[2013/03/25 03:52:12 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi.rs
[2013/03/25 03:52:12 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\SysWow64\djctq.rs
[2013/03/25 03:52:12 | 000,015,360 | —- | C] (Microsoft) – C:\Windows\SysNative\djctq.rs
[2013/03/25 03:52:11 | 002,576,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\gameux.dll
[2013/03/25 03:52:11 | 000,308,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Wpc.dll
[2013/03/25 03:52:11 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\SysWow64\cero.rs
[2013/03/25 03:52:11 | 000,055,296 | —- | C] (Microsoft) – C:\Windows\SysNative\cero.rs
[2013/03/25 03:52:11 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\SysWow64\esrb.rs
[2013/03/25 03:52:11 | 000,051,712 | —- | C] (Microsoft) – C:\Windows\SysNative\esrb.rs
[2013/03/25 03:52:11 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\SysWow64\oflc.rs
[2013/03/25 03:52:11 | 000,023,552 | —- | C] (Microsoft) – C:\Windows\SysNative\oflc.rs
[2013/03/25 03:52:11 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysWow64\pegi-fi.rs
[2013/03/25 03:52:11 | 000,020,480 | —- | C] (Microsoft) – C:\Windows\SysNative\pegi-fi.rs
[2013/03/25 03:51:34 | 005,553,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013/03/25 03:51:33 | 003,967,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2013/03/25 03:51:33 | 003,913,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2013/03/25 03:51:28 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2013/03/25 03:51:28 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2013/03/25 03:51:28 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2013/03/25 03:51:28 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2013/03/25 03:51:28 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2013/03/25 03:51:28 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2013/03/25 03:51:22 | 000,288,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2013/03/25 03:51:19 | 000,750,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/03/25 03:51:18 | 000,492,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\win32spl.dll
[2013/03/25 03:51:17 | 000,800,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\usp10.dll
[2013/03/25 03:51:17 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2013/03/25 03:48:56 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2013/03/25 03:48:55 | 001,161,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2013/03/25 03:48:55 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2013/03/25 03:48:55 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2013/03/25 03:48:55 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2013/03/25 03:48:55 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2013/03/25 03:48:55 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2013/03/25 03:48:54 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2013/03/25 03:48:54 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2013/03/25 03:48:54 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2013/03/25 03:48:54 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2013/03/25 03:48:54 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2013/03/25 03:48:54 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2013/03/25 03:48:54 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2013/03/25 03:48:54 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2013/03/25 03:48:54 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/03/25 03:48:54 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/03/25 03:48:54 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2013/03/25 03:48:54 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2013/03/25 03:48:54 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2013/03/25 03:48:54 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2013/03/25 03:48:54 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2013/03/25 03:48:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2013/03/25 03:48:52 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2013/03/25 03:48:52 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2013/03/25 03:48:52 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2013/03/25 03:48:52 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2013/03/25 03:48:07 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskhost.exe
[2013/03/25 03:04:45 | 000,491,520 | —- | C] (vbAccelerator) – C:\Windows\SysWow64\vbalsgrid6.ocx
[2013/03/25 03:04:42 | 001,227,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\DX8VB.DLL
[2013/03/25 03:04:42 | 000,063,488 | —- | C] (Spider Eye Studios P/L) – C:\Windows\SysWow64\flexbag.dll
[2013/03/25 03:04:42 | 000,040,960 | —- | C] (vbAccelerator) – C:\Windows\SysWow64\ssubtmr6.dll
[2013/03/25 03:04:32 | 000,098,304 | —- | C] (Oceanview Software Limited) – C:\Windows\SysWow64\ovsButtonControl.ocx
[2013/03/25 03:04:23 | 000,326,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.037
[2013/03/25 03:04:22 | 001,388,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.036
[2013/03/25 03:04:22 | 000,598,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.032
[2013/03/25 03:04:22 | 000,164,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.033
[2013/03/25 03:04:22 | 000,147,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.034
[2013/03/25 03:04:22 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.031
[2013/03/25 03:04:22 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.035
[2013/03/24 14:40:06 | 000,000,000 | —D | C] – C:\Users\Nick\AppData\Local\Rovi_Corporation
[2013/03/24 14:38:09 | 000,000,000 | —D | C] – C:\Users\Nick\AppData\Roaming\Roxio
[2013/03/24 14:21:26 | 000,000,000 | —D | C] – C:\ProgramData\FLEXnet
[2013/03/24 14:21:10 | 000,000,000 | —D | C] – C:\ProgramData\Sonic
[2013/03/24 14:15:23 | 000,000,000 | —D | C] – C:\ProgramData\Roxio
[2013/03/24 14:15:06 | 000,000,000 | —D | C] – C:\ProgramData\Macrovision
[2013/03/24 14:13:35 | 000,010,224 | —- | C] (Sonic Solutions) – C:\Windows\SysNative\drivers\cdr4_xp.sys
[2013/03/24 14:13:34 | 000,055,952 | —- | C] (Rovi Corporation) – C:\Windows\SysNative\drivers\PxHlpa64.sys
[2013/03/24 14:13:34 | 000,010,224 | —- | C] (Sonic Solutions) – C:\Windows\SysNative\drivers\cdralw2k.sys
[2013/03/24 14:13:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\SmartSound Software
[2013/03/24 14:13:14 | 000,000,000 | —D | C] – C:\ProgramData\SmartSound Software Inc
[2013/03/24 14:07:45 | 000,000,000 | —D | C] – C:\Users\Nick\AppData\Roaming\Roxio Log Files
[2013/03/22 20:32:48 | 000,326,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.030
[2013/03/22 20:32:47 | 001,388,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.02F
[2013/03/22 20:32:47 | 000,598,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.02B
[2013/03/22 20:32:47 | 000,164,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.02C
[2013/03/22 20:32:47 | 000,147,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.02D
[2013/03/22 20:32:47 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.02E
[2013/03/22 20:32:46 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\temp.02A
[2013/03/18 21:11:10 | 000,262,560 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/03/18 21:10:59 | 000,095,648 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/01/21 21:46:05 | 000,940,544 | —- | C] (Apache Software Foundation) – C:\Users\Nick\AppData\Local\log4cxx.dll
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/04/17 20:36:25 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Nick\Desktop\OTL.exe
[2013/04/17 19:57:00 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-762202037-2163149629-1470818234-1000UA.job
[2013/04/17 13:57:01 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-762202037-2163149629-1470818234-1000Core.job
[2013/04/17 13:14:44 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/04/17 13:14:44 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/04/17 12:59:08 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/04/15 13:32:24 | 000,000,710 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/04/15 09:57:58 | 000,728,300 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/04/15 09:57:58 | 000,625,466 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/04/15 09:57:58 | 000,107,308 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/04/15 09:54:17 | 000,000,408 | —- | M] () – C:\Windows\tasks\SlimDrivers Startup.job
[2013/04/15 09:54:10 | 000,001,870 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
[2013/04/15 09:53:38 | 000,016,152 | —- | M] () – C:\Windows\SysNative\drivers\SWDUMon.sys
[2013/04/15 09:53:20 | 000,003,929 | -HS- | M] () – C:\Windows\SysWow64\mmf.sys
[2013/04/15 09:52:49 | 3169,759,232 | -HS- | M] () – C:\hiberfil.sys
[2013/04/11 16:59:44 | 000,002,323 | —- | M] () – C:\Users\Nick\Desktop\Google Chrome.lnk
[2013/04/09 15:19:34 | 164,257,094 | —- | M] () – C:\Users\Nick\Desktop\whistle.avi
[2013/04/09 12:28:01 | 000,013,367 | —- | M] () – C:\Users\Nick\AppData\Local\recently-used.xbel
[2013/04/05 09:18:48 | 000,000,872 | —- | M] () – C:\Users\Public\Desktop\PureSim Baseball 4.lnk
[2013/04/04 23:47:39 | 248,960,149 | —- | M] () – C:\Users\Nick\Desktop\puresim5_v103.zip
[2013/04/04 23:39:51 | 000,000,872 | —- | M] () – C:\Users\Public\Desktop\PureSim Baseball 5.lnk
[2013/04/04 14:50:32 | 000,025,928 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/04/02 12:09:27 | 000,155,378 | —- | M] () – C:\Users\Nick\Documents\2011TaxReturn.PDF
[2013/04/01 20:50:28 | 000,001,584 | —- | M] () – C:\Users\Public\Desktop\DDSCB2.lnk
[2013/03/26 22:18:56 | 000,001,012 | —- | M] () – C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/03/26 22:18:33 | 000,000,978 | —- | M] () – C:\Users\Nick\Desktop\Dropbox.lnk
[2013/03/25 06:13:46 | 000,000,834 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
[2013/03/25 05:38:37 | 000,744,030 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/03/25 05:23:24 | 000,074,442 | —- | M] () – C:\Windows\SysNative\drivers\RTWAVES30.dat
[2013/03/25 04:54:01 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_AMPPAL_01009.Wdf
[2013/03/25 04:23:02 | 000,002,467 | —- | M] () – C:\Users\Public\Desktop\SlimDrivers.lnk
[2013/03/25 04:18:32 | 000,461,192 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/03/24 14:20:57 | 000,002,078 | —- | M] () – C:\Users\Public\Desktop\DivX Plus Converter.lnk
[2013/03/18 21:10:55 | 000,095,648 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/03/18 21:10:54 | 000,782,240 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/03/18 21:10:54 | 000,262,560 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/03/18 21:10:54 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/03/18 21:10:54 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/04/09 14:47:58 | 164,257,094 | —- | C] () – C:\Users\Nick\Desktop\whistle.avi
[2013/04/09 12:28:01 | 000,013,367 | —- | C] () – C:\Users\Nick\AppData\Local\recently-used.xbel
[2013/04/05 09:18:48 | 000,000,872 | —- | C] () – C:\Users\Public\Desktop\PureSim Baseball 4.lnk
[2013/04/04 23:41:26 | 248,960,149 | —- | C] () – C:\Users\Nick\Desktop\puresim5_v103.zip
[2013/04/04 23:39:51 | 000,000,872 | —- | C] () – C:\Users\Public\Desktop\PureSim Baseball 5.lnk
[2013/04/04 23:39:47 | 000,340,992 | –S- | C] () – C:\Windows\SysWow64\sqlite36_engine.dll
[2013/04/04 23:39:47 | 000,047,616 | –S- | C] () – C:\Windows\SysWow64\zlibocx.ocx
[2013/04/02 12:09:27 | 000,155,378 | —- | C] () – C:\Users\Nick\Documents\2011TaxReturn.PDF
[2013/04/01 20:50:28 | 000,001,584 | —- | C] () – C:\Users\Public\Desktop\DDSCB2.lnk
[2013/03/25 05:52:06 | 000,000,834 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
[2013/03/25 05:38:37 | 000,744,030 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/03/25 05:22:32 | 000,381,365 | —- | C] () – C:\Windows\SysNative\drivers\RTAIODAT.DAT
[2013/03/25 05:01:37 | 000,074,272 | —- | C] () – C:\Windows\SysNative\RtNicProp64.dll
[2013/03/25 04:54:01 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_AMPPAL_01009.Wdf
[2013/03/25 04:23:16 | 000,000,408 | —- | C] () – C:\Windows\tasks\SlimDrivers Startup.job
[2013/03/25 04:23:12 | 000,016,152 | —- | C] () – C:\Windows\SysNative\drivers\SWDUMon.sys
[2013/03/25 04:23:02 | 000,002,467 | —- | C] () – C:\Users\Public\Desktop\SlimDrivers.lnk
[2013/01/21 21:46:05 | 000,196,608 | —- | C] () – C:\Users\Nick\AppData\Local\common_functions.dll
[2012/11/23 08:54:40 | 000,114,688 | —- | C] () – C:\Users\Nick\AppData\Local\ie_runner_app.exe
[2012/11/20 05:51:14 | 000,645,632 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2012/11/20 05:51:14 | 000,240,640 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2012/08/17 23:02:06 | 000,384,844 | —- | C] () – C:\Users\Nick\AppData\Local\funmoods-speeddial.crx
[2012/07/15 12:59:20 | 000,012,288 | —- | C] () – C:\Users\Nick\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/07/02 20:28:06 | 000,112,640 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2012/06/25 02:09:09 | 000,002,304 | —- | C] () – C:\Windows\SysWow64\HtsysmNT.sys
[2012/06/24 20:29:35 | 000,004,150 | —- | C] () – C:\ProgramData\qxfoespp.eyj
[2012/06/23 16:08:59 | 000,000,269 | —- | C] () – C:\Windows\PowerReg.dat
[2012/06/09 19:21:56 | 000,178,688 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2012/05/30 12:45:37 | 000,002,828 | -HS- | C] () – C:\ProgramData\KGyGaAvL.sys
[2012/05/30 12:45:37 | 000,000,088 | RHS- | C] () – C:\ProgramData\D0D84BB80B.sys
[2012/05/30 11:52:20 | 004,305,920 | —- | C] () – C:\Windows\SysWow64\x264vfw.dll
[2012/05/21 18:28:58 | 000,155,648 | —- | C] () – C:\Windows\SysWow64\mlc.dll
[2012/01/10 23:22:52 | 000,007,619 | —- | C] () – C:\Users\Nick\AppData\Local\Resmon.ResmonCfg
[2012/01/10 02:33:37 | 000,000,000 | —- | C] () – C:\Users\Nick\__ng3d.lock
[2012/01/07 06:20:28 | 000,003,929 | -HS- | C] () – C:\Windows\SysWow64\mmf.sys
[2012/01/07 06:20:27 | 000,048,640 | —- | C] () – C:\Windows\mmfs.dll
[2012/01/07 06:20:27 | 000,002,560 | —- | C] () – C:\Windows\Runservice.exe
[2011/12/19 14:05:40 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2011/12/07 23:32:24 | 000,216,064 | —- | C] ( ) – C:\Windows\SysWow64\lagarith.dll
[2011/12/05 16:25:56 | 000,000,064 | —- | C] () – C:\Windows\SysWow64\rp_stats.dat
[2011/12/05 16:25:56 | 000,000,044 | —- | C] () – C:\Windows\SysWow64\rp_rules.dat
[2011/12/03 22:01:17 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/12/03 22:01:17 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/12/03 22:01:17 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/12/03 22:01:17 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/12/03 22:01:17 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/12/01 11:43:17 | 000,066,856 | —- | C] () – C:\Windows\SysWow64\SynTPEnhPS.dll

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 01:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 00:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/12/01 11:48:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=00B0358734CAA32C39D181FE6916B178 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_b8b0208ee0ce1889\explorer.exe
[2011/12/01 11:49:42 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\ERDNT\cache86\explorer.exe
[2011/12/01 11:49:42 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/12/01 11:49:42 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/12/01 11:49:42 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2011/12/01 11:49:44 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/12/01 11:49:42 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/12/01 11:49:42 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/12/01 11:49:42 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/12/01 11:49:42 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/12/01 11:48:47 | 002,868,736 | —- | M] (Microsoft Corporation) MD5=6D4F9E4B640B413C6F73414327484C80 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_addea9f19345cd81\explorer.exe
[2011/12/01 11:48:54 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/12/01 11:49:42 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/12/01 11:49:42 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2011/12/01 11:49:44 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2011/12/01 11:48:54 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 09:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2011/12/01 11:49:43 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2011/12/01 11:48:54 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 21:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2011/12/01 11:49:43 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/12/01 11:48:47 | 002,868,736 | —- | M] (Microsoft Corporation) MD5=CA17F8620815267DC838E30B68CB5052 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_ae5b763cac6d568e\explorer.exe
[2011/12/01 11:49:42 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2011/12/01 11:48:54 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
[2011/12/01 11:48:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=FC89FACA0473641CB625EDA9277D0885 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_b8335443c7a68f7c\explorer.exe

< MD5 for: SVCHOST.EXE >
[2012/12/14 17:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\ERDNT\cache86\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/13 21:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\ERDNT\cache64\svchost.exe
[2009/07/13 21:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 21:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 08:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 08:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 21:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\ERDNT\cache86\userinit.exe
[2009/07/13 21:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 21:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\ERDNT\cache64\userinit.exe
[2009/07/13 21:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 09:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 09:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 09:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 09:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 21:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012/12/14 17:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2011/12/01 11:49:44 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2011/12/01 11:49:44 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\ERDNT\cache64\winlogon.exe
[2011/12/01 11:49:44 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: ATA TOSHIBA MK5061GS SCSI Disk Device
Partitions: 3
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 39.00MB
Starting Offset: 32256
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 12.00GB
Starting Offset: 41943040
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 453.00GB
Starting Offset: 13195280384
Hidden sectors: 0


========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\System32\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
[C:\Windows\System32\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
[C:\Windows\System32\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
[C:\Windows\System32\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
[C:\Windows\System32\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
[C:\Windows\System32\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\System32\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
[C:\Windows\System32\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
[C:\Windows\SysWOW64\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
[C:\Windows\SysWOW64\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
[C:\Windows\SysWOW64\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction

< End of report >





aswMBR
aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-04-17 21:01:40
—————————–
21:01:40.024 OS Version: Windows x64 6.1.7601 Service Pack 1
21:01:40.025 Number of processors: 8 586 0x1E05
21:01:40.025 ComputerName: NICK-PC UserName: Nick
21:01:41.672 Initialize success
21:01:56.786 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000006f
21:01:56.791 Disk 0 Vendor: ATA_____ 0D__ Size: 476940MB BusType: 11
21:01:56.905 Disk 0 MBR read successfully
21:01:56.910 Disk 0 MBR scan
21:01:56.914 Disk 0 Windows VISTA default MBR code
21:01:56.918 Disk 0 Partition 1 00 DE Dell Utility DELL 4.1 39 MB offset 63
21:01:56.932 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 12544 MB offset 81920
21:01:56.945 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 464352 MB offset 25772032
21:01:56.966 Disk 0 scanning C:\Windows\system32\drivers
21:02:02.951 Service scanning
21:02:20.064 Modules scanning
21:02:20.077 Disk 0 trace - called modules:
21:02:20.096 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStorF.sys ACPI.sys storport.sys hal.dll iaStorA.sys
21:02:20.102 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004dc3790]
21:02:20.109 3 CLASSPNP.SYS[fffff880013cb43f] -> nt!IofCallDriver -> [0xfffffa8004cca8d0]
21:02:20.123 5 iaStorF.sys[fffff880018379a0] -> nt!IofCallDriver -> [0xfffffa8004ba8380]
21:02:20.136 7 ACPI.sys[fffff88000ef57a1] -> nt!IofCallDriver -> \Device\0000006f[0xfffffa8004b26060]
21:02:20.146 Scan finished successfully
21:02:28.871 Disk 0 MBR has been saved successfully to "C:\Users\Nick\Desktop\MBR.dat"
21:02:28.878 The log file has been saved successfully to "C:\Users\Nick\Desktop\aswMBR.txt"
Hello ezpkns34 Thanks for the logs which I am looking at now. The OTL log you sent me was the result of the second time that it was run which is why there was no Extras log. However, one would have been produced on the first run and should be located in the same place as OTL, which is your desktop in this case. Satchfan
It appears that ComboFix has been run on this computer, (albeit some time ago). If it is still on the computer, please delete it.


Note: If you have MalwareBytes Anti-Malware 1.6 or higher installed and are using the Pro version or trial version, please temporarily disable it for the duration of this fix as it may interfere with the successfully execution of the script below.

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKU\S-1-5-21-762202037-2163149629-1470818234-1000\..\SearchScopes\{88833EF9-5986-4DBD-850E-44C299234F1E}: "URL" = http://www.mysearchresults.com/search?&…q={searchTerms}
    FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3279141&SearchSource=2&CUI=UN21365894533171620&sspv=SP_FFNSP06&q="
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll File not found
    FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll File not found
    FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
    O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
    O4 - HKU\S-1-5-21-762202037-2163149629-1470818234-1000..\Run: [Akamai NetSession Interface] "C:\Users\Nick\AppData\Local\Akamai\netsession_win.exe" File not found
    O4 - HKU\S-1-5-21-762202037-2163149629-1470818234-1000..\Run: [Overwolf] C:\Program Files (x86)\Overwolf\Overwolf.exe -silent File not found
    O4 - HKU\S-1-5-21-762202037-2163149629-1470818234-1001..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
    [2012/08/17 23:02:06 | 000,384,844 | —- | C] () – C:\Users\Nick\AppData\Local\funmoods-speeddial.crx
    [2012/06/24 20:29:35 | 000,004,150 | —- | C] () – C:\ProgramData\qxfoespp.eyj
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • please post the OTL fix log
===================================================

Download and run ComboFix

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2

**Note: It MUST be saved directly to your desktop. Choose save as and then make sure you choose Desktop

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • when finished, it will produce a report for you.
  • please post the C:\ComboFix.txt in your next post.
Logs to include in the next post:

OTL fix log
Extras.txt
ComboFix.txt


Please see my previous post for OTL Extras log location.

Thanks

Satchfan
Hi ezpkns34 It has been several days days since I replied with instructions to help with your computer problems. Please let me know if you are having problems and still need help. Thanks Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI