This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Remove the Win32/Small.CA virus from your PC

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello all, hope you can help me out. I have been seeing this message on my sisters computer under the actions center flag and have done some research online to try and resolve the matter with no luck. I have ran malwarebytes, emisoft and my antivirus but none of them have found anything related to the virus mentioned. I have downloaded OTL as per your instructions in the link http://forums.whatthetech.com/Are_you_Infected_t106388.html and followed the instructions. Here is the first text file:

OTL logfile created on: 4/19/2013 12:21:20 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:UsersNathan StrykerDownloads
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16540)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1023.43 Mb Total Physical Memory | 266.39 Mb Available Physical Memory | 26.03% Memory free
2.00 Gb Paging File | 0.84 Gb Available in Paging File | 41.93% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files
Drive C: | 111.80 Gb Total Space | 91.74 Gb Free Space | 82.05% Space Free | Partition Type: NTFS

Computer Name: NATHANSTRYKER | User Name: Nathan Stryker | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:UsersNathan StrykerDownloadsOTL.exe (OldTimer Tools)
PRC - C:Program FilesGoogleChromeApplicationchrome.exe (Google Inc.)
PRC - C:Program FilesAVG Secure Searchvprot.exe ()
PRC - C:Program FilesCommon FilesAVG Secure SearchvToolbarUpdater14.2.0ToolbarUpdater.exe ()
PRC - C:WindowsSystem32taskhost.exe (Microsoft Corporation)
PRC - C:Program FilesAVGAVG10avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:Program FilesAVGAVG10Identity ProtectionAgentBinAVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:Program FilesAVGAVG10avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:Program FilesAVGAVG10avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:Program FilesAVGAVG10avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:Program FilesAVGAVG10avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:Windowsexplorer.exe (Microsoft Corporation)
PRC - C:Program FilesAVGAVG10Identity ProtectionAgentBinAVGIDSMonitor.exe ()
PRC - C:Program FilesAVGAVG10avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:WindowsSOUNDMAN.EXE (Realtek Semiconductor Corp.)


========== Modules (No Company Name) ==========

MOD - C:Program FilesGoogleChromeApplication26.0.1410.64ppgooglenaclpluginchrome.dll ()
MOD - C:Program FilesGoogleChromeApplication26.0.1410.64pdf.dll ()
MOD - C:Program FilesGoogleChromeApplication26.0.1410.64libglesv2.dll ()
MOD - C:Program FilesGoogleChromeApplication26.0.1410.64libegl.dll ()
MOD - C:Program FilesGoogleChromeApplication26.0.1410.64ffmpegsumo.dll ()
MOD - C:Program FilesCommon FilesAVG Secure SearchSiteSafetyInstaller14.2.0SiteSafety.dll ()
MOD - C:Program FilesAVG Secure Searchvprot.exe ()
MOD - C:Program FilesCommon Filesmicrosoft sharedOFFICE14CulturesOFFICE.ODF ()
MOD - C:Program FilesAVGAVG10Identity ProtectionAgentBinAVGIDSMonitor.exe ()
MOD - C:Program FilesMicrosoft OfficeOffice141033GrooveIntlResource.dll ()


========== Services (SafeList) ==========

SRV - (MozillaMaintenance) – C:Program FilesMozilla Maintenance Servicemaintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:WindowsSystem32MacromedFlashFlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (vToolbarUpdater14.2.0) – C:Program FilesCommon FilesAVG Secure SearchvToolbarUpdater14.2.0ToolbarUpdater.exe ()
SRV - (WatAdminSvc) – C:WindowsSystem32WatWatAdminSvc.exe (Microsoft Corporation)
SRV - (AVGIDSAgent) – C:Program FilesAVGAVG10Identity ProtectionAgentBinAVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:Program FilesAVGAVG10avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:Program FilesMicrosoft OfficeOffice14GROOVE.EXE (Microsoft Corporation)
SRV - (SensrSvc) – C:WindowsSystem32sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:WindowsSystem32PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:Program FilesWindows DefenderMpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (VGPU) – System32driversrdvgkmd.sys File not found
DRV - (nvlddmkm) – C:WindowsSystem32driversnvlddmkm.sys (NVIDIA Corporation)
DRV - (avgtp) – C:WindowsSystem32driversavgtpx86.sys (AVG Technologies)
DRV - (Avgldx86) – C:WindowsSystem32driversavgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (terminpt) – C:WindowsSystem32driversterminpt.sys (Microsoft Corporation)
DRV - (RdpVideoMiniport) – C:WindowsSystem32driversrdpvideominiport.sys (Microsoft Corporation)
DRV - (TsUsbGD) – C:WindowsSystem32driversTsUsbGD.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:WindowsSystem32driversTsUsbFlt.sys (Microsoft Corporation)
DRV - (AVGIDSDriver) – C:WindowsSystem32driversAVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:WindowsSystem32driversavgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:WindowsSystem32driversavgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:WindowsSystem32driversavgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:WindowsSystem32driversAVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:WindowsSystem32driversAVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:WindowsSystem32driversAVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (ANDModem) – C:WindowsSystem32driverslgandmodem.sys (LG Electronics Inc.)
DRV - (AndDiag) – C:WindowsSystem32driverslganddiag.sys (LG Electronics Inc.)
DRV - (AndGps) – C:WindowsSystem32driverslgandgps.sys (LG Electronics Inc.)
DRV - (Andbus) – C:WindowsSystem32driverslgandbus.sys (LG Electronics Inc.)
DRV - (vmbus) – C:WindowsSystem32driversvmbus.sys (Microsoft Corporation)
DRV - (tsusbhub) – C:WindowsSystem32driverstsusbhub.sys (Microsoft Corporation)
DRV - (Synth3dVsc) – C:WindowsSystem32driversSynth3dVsc.sys (Microsoft Corporation)
DRV - (dmvsc) – C:WindowsSystem32driversdmvsc.sys (Microsoft Corporation)
DRV - (storflt) – C:WindowsSystem32driversvmstorfl.sys (Microsoft Corporation)
DRV - (WinUsb) – C:WindowsSystem32driverswinusb.sys (Microsoft Corporation)
DRV - (storvsc) – C:WindowsSystem32driversstorvsc.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:WindowsSystem32driversVMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:WindowsSystem32driversvms3cap.sys (Microsoft Corporation)
DRV - (SASENUM) – C:Program FilesSUPERAntiSpywareSASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:Program FilesSUPERAntiSpywaresasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:Program FilesSUPERAntiSpywareSASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (ltmodem5) – C:WindowsSystem32driversltmdmnt.sys (Agere Systems)
DRV - (NVENETFD) – C:WindowsSystem32driversnvm60x32.sys (NVIDIA Corporation)
DRV - (ALCXWDM) – C:WindowsSystem32driversRTKVAC.SYS (Realtek Semiconductor Corp.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM..SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM..SearchScopes{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.msn.com/?ocid=EIE9HP&PC;=UP50
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Secondary Start Pages = http://www.google.ca/ [binary data]
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = www.google.ca
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page Redirect Cache = http://ca.msn.com/?rd=1&ucc;=CA&dcc;…0&ocid;=iehp
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page Redirect Cache_TIMESTAMP = D0 E4 20 79 47 E5 CD 01 [binary data]
IE - HKCU..SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU..SearchScopes{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…1I7NDKB_enCA516
IE - HKCU..SearchScopes{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={CF1A620…mp;d=2012-12-28 16:25:14&v;=14.2.0.1&pid;=avg&sg;=&sap;=dsp&q;={searchTerms}
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.ca"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - user.js - File not found

FF - [removed]/FlashPlayer: C:Windowssystem32MacromedFlashNPSWF32_11_6_602_180.dll ()
FF - [removed]/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:Program FilesCommon FilesAVG Secure SearchSiteSafetyInstaller14.2.0npsitesafety.dll ()
FF - [removed]/EPPEX: C:Program FilesCanonMy Image GardenAddOnCIGnpmigfpi.dll (CANON INC.)
FF - [removed]/Foxit Reader Plugin,version=1.0,application/pdf: C:Program FilesFoxit SoftwareFoxit ReaderpluginsnpFoxitReaderPlugin.dll (Foxit Corporation)
FF - [removed]/GENUINE: disabled File not found
FF - [removed]/OfficeAuthz,version=14.0: C:PROGRA~1MICROS~2Office14NPAUTHZ.DLL (Microsoft Corporation)
FF - [removed]/SharePoint,version=14.0: C:PROGRA~1MICROS~2Office14NPSPWRAP.DLL (Microsoft Corporation)
FF - [removed]/Google Update;version=3: C:Program FilesGoogleUpdate1.3.21.135npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/Google Update;version=9: C:Program FilesGoogleUpdate1.3.21.135npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINEsoftwaremozillaFirefoxExtensions{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:Program FilesAVGAVG10Firefox4 [2013/04/09 09:54:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaFirefoxExtensionsavg@toolbar: C:ProgramDataAVG Secure SearchFireFoxExt14.2.0.1 [2013/02/18 09:24:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 20.0.1extensionsComponents: C:Program FilesMozilla Firefoxcomponents [2013/04/18 07:45:24 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 20.0.1extensionsPlugins: C:Program FilesMozilla Firefoxplugins
FF - HKEY_CURRENT_USERsoftwaremozillaMozilla Firefox 20.0.1extensionsComponents: C:Program FilesMozilla Firefoxcomponents [2013/04/18 07:45:24 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USERsoftwaremozillaMozilla Firefox 20.0.1extensionsPlugins: C:Program FilesMozilla Firefoxplugins

[2012/12/28 19:58:31 | 000,000,000 | —D | M] (No name found) – C:UsersNathan StrykerAppDataRoamingMozillaExtensions
[2013/02/06 14:24:26 | 000,000,000 | —D | M] (No name found) – C:UsersNathan StrykerAppDataRoamingMozillaFirefoxProfilesyfyrhpf6.defaultextensions
[2013/01/15 19:54:10 | 000,036,763 | —- | M] () (No name found) – C:UsersNathan StrykerAppDataRoamingMozillaFirefoxProfilesyfyrhpf6.defaultextensionsaut
[removed]
[2013/02/06 14:24:26 | 000,157,239 | —- | M] () (No name found) – C:UsersNathan StrykerAppDataRoamingMozillaFirefoxProfilesyfyrhpf6.defaultextensionsjid
[removed]
[2013/04/18 07:44:37 | 000,000,000 | —D | M] (No name found) – C:Program FilesMozilla Firefoxextensions
[2013/04/18 07:45:23 | 000,263,064 | —- | M] (Mozilla Foundation) – C:Program Filesmozilla firefoxcomponentsbrowsercomps.dll
[2013/02/18 09:24:05 | 000,003,714 | —- | M] () – C:Program Filesmozilla firefoxsearchpluginsavg-secure-search.xml
[2012/11/29 01:27:12 | 000,002,465 | —- | M] () – C:Program Filesmozilla firefoxsearchpluginsbing.xml
[2013/02/27 19:41:36 | 000,002,086 | —- | M] () – C:Program Filesmozilla firefoxsearchpluginstwitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}
{
google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:Program FilesGoogleChromeApplication26.0.1410.64PepperFlashpepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:Program FilesGoogleChromeApplication26.0.1410.64ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:Program FilesGoogleChromeApplication26.0.1410.64pdf.dll
CHR - plugin: Google Update (Enabled) = C:Program FilesGoogleUpdate1.3.21.115npGoogleUpdate3.dll
CHR - Extension: YouTube = C:UsersNathan StrykerAppDataLocalGoogleChromeUser DataDefaultExtensionsblpcfgokakmgnkcojhhkbfbldkacnbeo4.2.6_0
CHR - Extension: Google Search = C:UsersNathan StrykerAppDataLocalGoogleChromeUser DataDefaultExtensionscoobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR - Extension: AVG Safe Search = C:UsersNathan StrykerAppDataLocalGoogleChromeUser DataDefaultExtensionsjmfkcklnlgedgbglfkkgedjfmejoahla10.0.0.1409_0
CHR - Extension: Northern Lights = C:UsersNathan StrykerAppDataLocalGoogleChromeUser DataDefaultExtensionslbnkklencjcmkepldaineciclcheaoef1.1_0
CHR - Extension: AVG Security Toolbar = C:UsersNathan StrykerAppDataLocalGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof14.2.0.1_0
CHR - Extension: Gmail = C:UsersNathan StrykerAppDataLocalGoogleChromeUser DataDefaultExtensionspjkljhegncpnkpknbcohdijeoejaedia7_1

O1 HOSTS File: ([2009/06/10 14:39:37 | 000,000,824 | —- | M]) - C:WindowsSystem32driversetchosts
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:Program FilesAVGAVG10avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:Program FilesMicrosoft OfficeOffice14GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:Program FilesAVG Secure Search14.2.0.1AVG Secure Search_toolbar.dll ()
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:Program FilesMicrosoft OfficeOffice14URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM..Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:Program FilesAVG Secure Search14.2.0.1AVG Secure Search_toolbar.dll ()
O4 - HKLM..Run: [AVG_TRAY] C:Program FilesAVGAVG10avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..Run: [BCSSync] C:Program FilesMicrosoft OfficeOffice14BCSSync.exe (Microsoft Corporation)
O4 - HKLM..Run: [CanonSolutionMenu] C:Program FilesCanonSolutionMenuCNSLMAIN.exe (CANON INC.)
O4 - HKLM..Run: [SoundMan] C:WindowsSOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..Run: [vProt] C:Program FilesAVG Secure Searchvprot.exe ()
O4 - HKCU..Run: [SUPERAntiSpyware] C:Program FilesSUPERAntiSpywareSUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: ConsentPromptBehaviorAdmin = 5
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:Program FilesMicrosoft OfficeOffice14EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O17 - HKLMSystemCCSServicesTcpipParameters: DhcpNameServer = 192.168.0.1
O17 - HKLMSystemCCSServicesTcpipParametersInterfaces{7990D035-B7F6-495D-B477-92331DB18D78}: DhcpNameServer = 192.168.0.1
O18 - ProtocolHandlerlinkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:Program FilesAVGAVG10avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - ProtocolHandlerviprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:Program FilesCommon FilesAVG Secure SearchViProtocolInstaller14.2.0ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:Windowsexplorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:Windowssystem32userinit.exe) - C:WindowsSystem32userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:WindowsSystem32SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - WinlogonNotify!SASWinLogon: DllName - (C:Program FilesSUPERAntiSpywareSASWINLO.dll) - C:Program FilesSUPERAntiSpywareSASWINLO.dll (SUPERAntiSpyware.com)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:Program FilesSUPERAntiSpywareSASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:Program FilesMicrosoft OfficeOffice14GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | —- | M] () - C:autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:PROGRA~1AVGAVG10avgchsvx.exe /sync)
O34 - HKLM BootExecute: (C:PROGRA~1AVGAVG10avgrsx.exe /sync /restart)
O35 - HKLM..comfile [open] – "%1" %*
O35 - HKLM..exefile [open] – "%1" %*
O37 - HKLM…com [@ = comfile] – "%1" %*
O37 - HKLM…exe [@ = exefile] – "%1" %*
O38 - SubSystemsWindows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystemsWindows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystemsWindows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:WindowsSystem32ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:WindowsSystem32l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:WindowsSystem32iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/04/18 19:29:21 | 000,000,000 | —D | C] – C:UsersNathan StrykerAppDataRoamingMalwarebytes
[2013/04/18 19:29:05 | 000,000,000 | —D | C] – C:ProgramDataMicrosoftWindowsStart MenuProgramsMalwarebytes' Anti-Malware
[2013/04/18 19:29:03 | 000,000,000 | —D | C] – C:ProgramDataMalwarebytes
[2013/04/18 19:29:00 | 000,022,856 | —- | C] (Malwarebytes Corporation) – C:WindowsSystem32driversmbam.sys
[2013/04/18 19:29:00 | 000,000,000 | —D | C] – C:Program FilesMalwarebytes' Anti-Malware
[2013/04/18 19:28:46 | 000,000,000 | —D | C] – C:UsersNathan StrykerAppDataLocalPrograms
[2013/04/18 07:44:30 | 000,000,000 | —D | C] – C:Program FilesMozilla Firefox
[2013/04/11 19:18:38 | 002,706,432 | —- | C] (Microsoft Corporation) – C:WindowsSystem32mshtml.tlb
[2013/04/11 19:18:34 | 002,877,440 | —- | C] (Microsoft Corporation) – C:WindowsSystem32jscript9.dll
[2013/04/11 19:18:34 | 000,039,424 | —- | C] (Microsoft Corporation) – C:WindowsSystem32jsproxy.dll
[2013/04/11 19:18:33 | 000,061,440 | —- | C] (Microsoft Corporation) – C:WindowsSystem32iesetup.dll
[2013/04/11 19:18:32 | 000,391,168 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ieui.dll
[2013/04/11 19:18:31 | 000,493,056 | —- | C] (Microsoft Corporation) – C:WindowsSystem32msfeeds.dll
[2013/04/11 19:18:31 | 000,071,680 | —- | C] (Microsoft Corporation) – C:WindowsSystem32RegisterIEPKEYs.exe
[2013/04/11 19:18:31 | 000,042,496 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ie4uinit.exe
[2013/04/11 19:18:31 | 000,033,280 | —- | C] (Microsoft Corporation) – C:WindowsSystem32iernonce.dll
[2013/04/11 19:18:30 | 000,109,056 | —- | C] (Microsoft Corporation) – C:WindowsSystem32iesysprep.dll
[2013/04/10 06:58:45 | 002,347,008 | —- | C] (Microsoft Corporation) – C:WindowsSystem32win32k.sys
[2013/04/10 06:58:32 | 003,913,560 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ntoskrnl.exe
[2013/04/10 06:58:31 | 003,968,856 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ntkrnlpa.exe
[2013/04/10 06:58:30 | 000,038,912 | —- | C] (Microsoft Corporation) – C:WindowsSystem32csrsrv.dll
[2013/03/23 03:04:23 | 000,745,472 | —- | C] (Microsoft Corporation) – C:WindowsSystem32MsSpellCheckingFacility.exe
[2013/03/23 03:04:22 | 000,185,344 | —- | C] (Microsoft Corporation) – C:WindowsSystem32elshyph.dll
[2013/03/23 03:04:19 | 000,158,720 | —- | C] (Microsoft Corporation) – C:WindowsSystem32msls31.dll
[2013/03/23 03:04:17 | 000,163,840 | —- | C] (Microsoft Corporation) – C:WindowsSystem32msrating.dll
[2013/03/23 03:04:17 | 000,082,432 | —- | C] (Microsoft Corporation) – C:WindowsSystem32inseng.dll
[2013/03/23 03:04:16 | 000,138,752 | —- | C] (Microsoft Corporation) – C:WindowsSystem32wextract.exe
[2013/03/23 03:04:15 | 000,150,528 | —- | C] (Microsoft Corporation) – C:WindowsSystem32iexpress.exe
[2013/03/23 03:04:14 | 000,137,216 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ieUnatt.exe
[2013/03/23 03:04:11 | 000,057,344 | —- | C] (Microsoft Corporation) – C:WindowsSystem32pngfilt.dll
[2013/03/23 03:04:10 | 000,117,248 | —- | C] (Microsoft Corporation) – C:WindowsSystem32iepeers.dll
[2013/03/23 03:04:10 | 000,038,400 | —- | C] (Microsoft Corporation) – C:WindowsSystem32imgutil.dll
[2013/03/23 03:04:09 | 000,110,592 | —- | C] (Microsoft Corporation) – C:WindowsSystem32IEAdvpack.dll
[2013/03/23 03:04:09 | 000,041,984 | —- | C] (Microsoft Corporation) – C:WindowsSystem32msfeedsbs.dll
[2013/03/23 03:04:09 | 000,011,776 | —- | C] (Microsoft Corporation) – C:WindowsSystem32msfeedssync.exe
[2013/03/23 03:04:05 | 000,073,728 | —- | C] (Microsoft Corporation) – C:WindowsSystem32SetIEInstalledDate.exe
[2013/03/23 03:04:05 | 000,048,640 | —- | C] (Microsoft Corporation) – C:WindowsSystem32mshtmler.dll
[2013/03/23 03:04:00 | 000,361,984 | —- | C] (Microsoft Corporation) – C:WindowsSystem32html.iec
[2013/03/23 03:04:00 | 000,357,888 | —- | C] (Microsoft Corporation) – C:WindowsSystem32dxtmsft.dll
[2013/03/23 03:04:00 | 000,226,816 | —- | C] (Microsoft Corporation) – C:WindowsSystem32dxtrans.dll
[2013/03/23 03:03:59 | 001,400,416 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ieapfltr.dat
[2013/03/23 03:03:59 | 000,629,248 | —- | C] (Microsoft Corporation) – C:WindowsSystem32ieapfltr.dll
[2013/03/23 03:03:54 | 000,719,360 | —- | C] (Microsoft Corporation) – C:WindowsSystem32mshtmlmedia.dll
[2013/03/23 03:03:54 | 000,232,960 | —- | C] (Microsoft Corporation) – C:WindowsSystem32url.dll
[2013/03/23 03:03:52 | 000,242,200 | —- | C] (Microsoft Corporation) – C:WindowsSystem32iedkcs32.dll
[2013/03/23 03:03:50 | 001,441,280 | —- | C] (Microsoft Corporation) – C:WindowsSystem32inetcpl.cpl
[2013/03/23 03:03:47 | 000,023,040 | —- | C] (Microsoft Corporation) – C:WindowsSystem32licmgr10.dll
[2013/03/21 03:20:42 | 000,000,000 | -HSD | C] – C:found.000
[2013/03/20 13:29:18 | 000,015,872 | —- | C] (Microsoft Corporation) – C:WindowsSystem32driversusb8023.sys
[1 C:Windows*.tmp files -> C:Windows*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/04/19 12:14:27 | 000,000,902 | —- | M] () – C:WindowstasksGoogleUpdateTaskMachineUA.job
[2013/04/19 12:07:09 | 000,000,830 | —- | M] () – C:WindowstasksAdobe Flash Player Updater.job
[2013/04/19 11:49:33 | 000,023,904 | -H– | M] () – C:WindowsSystem327B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/04/19 11:49:33 | 000,023,904 | -H– | M] () – C:WindowsSystem327B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/04/19 11:49:20 | 117,960,503 | —- | M] () – C:WindowsSystem32driversAVGincavi.avm
[2013/04/19 11:42:11 | 000,000,898 | —- | M] () – C:WindowstasksGoogleUpdateTaskMachineCore.job
[2013/04/19 11:41:48 | 000,067,584 | –S- | M] () – C:Windowsbootstat.dat
[2013/04/19 11:41:41 | 804,855,808 | -HS- | M] () – C:hiberfil.sys
[2013/04/18 22:57:44 | 000,001,863 | —- | M] () – C:UsersPublicDesktopDefraggler.lnk
[2013/04/18 21:31:16 | 000,000,965 | —- | M] () – C:UsersPublicDesktopCCleaner.lnk
[2013/04/18 21:04:49 | 000,623,940 | —- | M] () – C:WindowsSystem32perfh009.dat
[2013/04/18 21:04:49 | 000,106,316 | —- | M] () – C:WindowsSystem32perfc009.dat
[2013/04/18 19:29:07 | 000,001,067 | —- | M] () – C:UsersPublicDesktopMalwarebytes Anti-Malware.lnk
[2013/04/17 18:15:40 | 000,217,841 | —- | M] () – C:WindowsSystem32driversAVGiavichjg.avm
[2013/04/11 19:39:51 | 003,805,616 | —- | M] () – C:WindowsSystem32FNTCACHE.DAT
[2013/04/10 06:46:19 | 000,002,129 | —- | M] () – C:UsersPublicDesktopGoogle Chrome.lnk
[2013/04/04 14:50:32 | 000,022,856 | —- | M] (Malwarebytes Corporation) – C:WindowsSystem32driversmbam.sys
[2013/03/23 03:04:23 | 000,745,472 | —- | M] (Microsoft Corporation) – C:WindowsSystem32MsSpellCheckingFacility.exe
[2013/03/23 03:04:22 | 000,185,344 | —- | M] (Microsoft Corporation) – C:WindowsSystem32elshyph.dll
[2013/03/23 03:04:19 | 000,158,720 | —- | M] (Microsoft Corporation) – C:WindowsSystem32msls31.dll
[2013/03/23 03:04:17 | 000,163,840 | —- | M] (Microsoft Corporation) – C:WindowsSystem32msrating.dll
[2013/03/23 03:04:17 | 000,082,432 | —- | M] (Microsoft Corporation) – C:WindowsSystem32inseng.dll
[2013/03/23 03:04:16 | 000,138,752 | —- | M] (Microsoft Corporation) – C:WindowsSystem32wextract.exe
[2013/03/23 03:04:15 | 000,150,528 | —- | M] (Microsoft Corporation) – C:WindowsSystem32iexpress.exe
[2013/03/23 03:04:14 | 000,137,216 | —- | M] (Microsoft Corporation) – C:WindowsSystem32ieUnatt.exe
[2013/03/23 03:04:11 | 000,057,344 | —- | M] (Microsoft Corporation) – C:WindowsSystem32pngfilt.dll
[2013/03/23 03:04:10 | 000,117,248 | —- | M] (Microsoft Corporation) – C:WindowsSystem32iepeers.dll
[2013/03/23 03:04:10 | 000,038,400 | —- | M] (Microsoft Corporation) – C:WindowsSystem32imgutil.dll
[2013/03/23 03:04:09 | 000,110,592 | —- | M] (Microsoft Corporation) – C:WindowsSystem32IEAdvpack.dll
[2013/03/23 03:04:09 | 000,041,984 | —- | M] (Microsoft Corporation) – C:WindowsSystem32msfeedsbs.dll
[2013/03/23 03:04:09 | 000,011,776 | —- | M] (Microsoft Corporation) – C:WindowsSystem32msfeedssync.exe
[2013/03/23 03:04:05 | 000,073,728 | —- | M] (Microsoft Corporation) – C:WindowsSystem32SetIEInstalledDate.exe
[2013/03/23 03:04:05 | 000,048,640 | —- | M] (Microsoft Corporation) – C:WindowsSystem32mshtmler.dll
[2013/03/23 03:04:00 | 000,361,984 | —- | M] (Microsoft Corporation) – C:WindowsSystem32html.iec
[2013/03/23 03:04:00 | 000,357,888 | —- | M] (Microsoft Corporation) – C:WindowsSystem32dxtmsft.dll
[2013/03/23 03:04:00 | 000,226,816 | —- | M] (Microsoft Corporation) – C:WindowsSystem32dxtrans.dll
[2013/03/23 03:03:59 | 001,400,416 | —- | M] (Microsoft Corporation) – C:WindowsSystem32ieapfltr.dat
[2013/03/23 03:03:59 | 000,629,248 | —- | M] (Microsoft Corporation) – C:WindowsSystem32ieapfltr.dll
[2013/03/23 03:03:55 | 000,025,185 | —- | M] () – C:WindowsSystem32ieuinit.inf
[2013/03/23 03:03:54 | 000,719,360 | —- | M] (Microsoft Corporation) – C:WindowsSystem32mshtmlmedia.dll
[2013/03/23 03:03:54 | 000,232,960 | —- | M] (Microsoft Corporation) – C:WindowsSystem32url.dll
[2013/03/23 03:03:53 | 000,242,200 | —- | M] (Microsoft Corporation) – C:WindowsSystem32iedkcs32.dll
[2013/03/23 03:03:50 | 001,441,280 | —- | M] (Microsoft Corporation) – C:WindowsSystem32inetcpl.cpl
[2013/03/23 03:03:47 | 000,023,040 | —- | M] (Microsoft Corporation) – C:WindowsSystem32licmgr10.dll
[1 C:Windows*.tmp files -> C:Windows*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/04/18 22:57:44 | 000,001,863 | —- | C] () – C:UsersPublicDesktopDefraggler.lnk
[2013/04/18 21:31:16 | 000,000,965 | —- | C] () – C:UsersPublicDesktopCCleaner.lnk
[2013/04/18 19:29:07 | 000,001,067 | —- | C] () – C:UsersPublicDesktopMalwarebytes Anti-Malware.lnk
[2013/03/23 03:03:55 | 000,025,185 | —- | C] () – C:WindowsSystem32ieuinit.inf
[2013/01/20 16:20:05 | 000,053,248 | —- | C] () – C:WindowsSystem32CommonDL.dll
[2013/01/20 16:20:05 | 000,002,411 | —- | C] () – C:WindowsSystem32lgAxconfig.ini

========== ZeroAccess Check ==========

[2009/07/13 21:42:31 | 000,000,227 | RHS- | M] () – C:WindowsassemblyDesktop.ini

[HKEY_CURRENT_USERSoftwareClassesclsid{42aedc87-2188-41fd-b9a3-0c966feabec1}InProcServer32]

[HKEY_CURRENT_USERSoftwareClassesclsid{fbeb8a05-beee-4442-804e-409d6c4515e9}InProcServer32]

[HKEY_LOCAL_MACHINESoftwareClassesclsid{42aedc87-2188-41fd-b9a3-0c966feabec1}InProcServer32]
"" = %SystemRoot%system32shell32.dll – [2012/06/08 21:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINESoftwareClassesclsid{5839FCA9-774D-42A1-ACDA-D6A79037F57F}InProcServer32]
"" = %systemroot%system32wbemfastprox.dll – [2010/11/20 14:29:20 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINESoftwareClassesclsid{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}InProcServer32]
"" = %systemroot%system32wbemwbemess.dll – [2009/07/13 18:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/12/28 17:27:54 | 000,000,000 | —D | M] – C:UsersNathan StrykerAppDataRoamingAVG10
[2012/12/28 17:30:27 | 000,000,000 | —D | M] – C:UsersNathan StrykerAppDataRoamingCanneverbe Limited
[2012/12/29 18:02:15 | 000,000,000 | —D | M] – C:UsersNathan StrykerAppDataRoamingCanon
[2012/12/28 19:34:15 | 000,000,000 | —D | M] – C:UsersNathan StrykerAppDataRoamingNotepad++
[2012/12/28 17:23:47 | 000,000,000 | —D | M] – C:UsersNathan StrykerAppDataRoamingTuneUp Software

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%..|smtmp;true;true;true /FP >

< %temp%smtmp*.* /s > >

< MD5 for: EXPLORER.ADML >
[2010/11/20 17:38:36 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:WindowsPolicyDefinitionsen-USExplorer.adml
[2010/11/20 17:38:36 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:Windowswinsxsx86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_22d6d5b5cba907ceExplorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 14:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:WindowsPolicyDefinitionsExplorer.admx
[2009/06/10 14:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:Windowswinsxsx86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/25 22:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:Windowswinsxsx86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fcexplorer.exe
[2010/11/20 14:29:20 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:Windowswinsxsx86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87caexplorer.exe
[2011/02/24 22:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:Windowsexplorer.exe
[2011/02/24 22:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:Windowswinsxsx86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2010/11/20 17:38:27 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:Windowsen-USexplorer.exe.mui
[2010/11/20 17:38:27 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:Windowswinsxsx86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_05c8dd40d4f56065explorer.exe.mui

< MD5 for: EXPLORER.EXE-7A3328DA.PF >
[2013/04/19 12:19:24 | 000,022,854 | —- | M] () MD5=31E91E499FA115F60611048ECE1E8712 – C:WindowsPrefetchEXPLORER.EXE-7A3328DA.pf

< MD5 for: EXPLORER.ZIP >
[2009/06/03 22:15:06 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:Program FilesMicrosoft Visual Studio 8Common7IDEVSTAItemTemplatesVisualBasic1033Explorer.zip

< MD5 for: IEXPLORE.EXE >
[2013/03/23 03:04:21 | 000,770,560 | —- | M] (Microsoft Corporation) MD5=2859EBC065D2E1CCC94161CE28BAC085 – C:Windowswinsxsx86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16521_none_ba715a6a65dbf461iexplore.exe
[2013/01/08 15:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:Windowswinsxsx86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_b10dc045c829d512iexplore.exe
[2013/02/24 16:52:40 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=A11C5E3E288256C540B7ED8BE3A04B01 – C:Windowswinsxsx86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20644_none_a39aa01e7f89ef98iexplore.exe
[2013/02/01 21:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – C:Windowswinsxsx86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_b17dbc10e15b4762iexplore.exe
[2012/12/28 15:09:16 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=B201AF83DF2E85323E29EB83E4046810 – C:Windowswinsxsx86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_b11b910fc81f0526iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:Program FilesMalwarebytes' Anti-MalwareChameleoniexplore.exe
[2010/11/20 14:29:33 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:Windowswinsxsx86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_b5780d7c8309d95ciexplore.exe
[2013/02/01 21:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:Windowswinsxsx86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_b0feef31c8358ba7iexplore.exe
[2013/02/21 04:28:11 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:Program FilesInternet Exploreriexplore.exe
[2013/02/21 04:28:11 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:Windowswinsxsx86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16540_none_ba7371c665da0d6eiexplore.exe
[2013/01/08 14:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:Windowswinsxsx86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_b18b8cdae1507776iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2012/12/28 15:09:16 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:Windowswinsxsx86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_aae2948effb95a30iexplore.exe.mui
[2013/03/23 03:04:22 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:Program FilesInternet Exploreren-USiexplore.exe.mui
[2013/03/23 03:04:22 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:Windowswinsxsx86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_b41defe19d893548iexplore.exe.mui
[2009/07/13 19:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:Windowswinsxsx86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_af24a2f3bab71a43iexplore.exe.mui

< MD5 for: SERVICES >
[2009/06/10 14:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:WindowsSystem32driversetcservices
[2009/06/10 14:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:Windowswinsxsx86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90daservices

< MD5 for: SERVICES.EXE >
[2009/07/13 18:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:WindowsSystem32services.exe
[2009/07/13 18:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:Windowswinsxsx86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967bservices
.exe

< MD5 for: SERVICES.EXE.MUI >
[2010/11/20 17:38:26 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:WindowsSystem32en-USservices.exe.mui
[2010/11/20 17:38:26 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:Windowswinsxsx86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/13 21:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:ProgramDataMicrosoftWindowsStart MenuProgramsAdministrative Toolsservices.lnk
[2009/07/13 21:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:UsersAll UsersMicrosoftWindowsStart MenuProgramsAdministrative Toolsservices.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 14:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:WindowsSystem32wbemservices.mof
[2009/06/10 14:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:Windowswinsxsx86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967bservices
.mof

< MD5 for: SERVICES.MSC >
[2010/11/20 17:38:25 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:WindowsSystem32en-USservices.msc
[2009/06/10 14:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:WindowsSystem32services.msc
[2010/11/20 17:38:25 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:Windowswinsxsx86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25services.msc
[2009/06/10 14:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:Windowswinsxsx86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54services.ms
c

< MD5 for: SERVICES.PTXML >
[2009/07/13 13:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:WindowsSystem32wdiperftrackServices.ptxml
[2009/07/13 13:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:Windowswinsxsx86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967bServices
.ptxml

< MD5 for: WINLOGON.ADML >
[2010/11/20 17:38:36 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:WindowsPolicyDefinitionsen-USWinLogon.adml
[2010/11/20 17:38:36 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:Windowswinsxsx86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_94da67ab3e358f3aWinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 14:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:WindowsPolicyDefinitionsWinLogon.admx
[2009/06/10 14:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:Windowswinsxsx86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 14:29:06 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:WindowsSystem32winlogon.exe
[2010/11/20 14:29:06 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:Windowswinsxsx86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:Program FilesMalwarebytes' Anti-MalwareChameleonwinlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 17:38:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:WindowsSystem32en-USwinlogon.exe.mui
[2010/11/20 17:38:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:Windowswinsxsx86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_ccfffb7662588b45winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2010/11/20 17:38:26 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:WindowsSystem32wbemen-USwinlogon.mfl
[2010/11/20 17:38:26 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:Windowswinsxsx86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_2891397980a26140winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 13:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:WindowsSystem32wbemwinlogon.mof
[2009/07/13 13:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:Windowswinsxsx86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9winlogon.mof

< %SYSTEMDRIVE%*.* >
[2009/06/10 14:42:20 | 000,000,024 | —- | M] () – C:autoexec.bat
[2012/12/28 01:13:20 | 000,000,211 | -H– | M] () – C:Boot.BAK
[2012/12/28 13:41:51 | 000,000,355 | RHS- | M] () – C:Boot.ini.saved
[2010/11/20 14:29:06 | 000,383,786 | RHS- | M] () – C:bootmgr
[2012/12/28 13:41:53 | 000,008,192 | RHS- | M] () – C:BOOTSECT.BAK
[2009/06/10 14:42:20 | 000,000,010 | —- | M] () – C:config.sys
[2013/04/19 11:41:41 | 804,855,808 | -HS- | M] () – C:hiberfil.sys
[2012/12/28 01:19:41 | 000,000,000 | RHS- | M] () – C:IO.SYS
[2012/12/28 01:19:41 | 000,000,000 | RHS- | M] () – C:MSDOS.SYS
[2008/04/14 05:00:00 | 000,047,564 | RHS- | M] () – C:NTDETECT.COM
[2008/04/14 05:00:00 | 000,250,048 | RHS- | M] () – C:ntldr
[2013/04/19 11:41:41 | 1073,741,824 | -HS- | M] () – C:pagefile.sys
[2012/12/28 14:58:56 | 000,402,286 | RHS- | M] () – C:RTOQE
[2012/12/28 14:58:57 | 000,000,020 | RHS- | M] () – C:win7.ld

< %systemroot%Fonts*.com >
[2009/07/13 21:52:25 | 000,026,040 | —- | M] () – C:WindowsFontsGlobalMonospace.CompositeFont
[2009/07/13 21:52:25 | 000,026,489 | —- | M] () – C:WindowsFontsGlobalSansSerif.CompositeFont
[2009/07/13 21:52:25 | 000,029,779 | —- | M] () – C:WindowsFontsGlobalSerif.CompositeFont
[2009/07/13 21:52:25 | 000,043,318 | —- | M] () – C:WindowsFontsGlobalUserInterface.CompositeFont

< %systemroot%Fonts*.dll >

< %systemroot%Fonts*.ini >
[2009/06/10 14:31:19 | 000,000,065 | —- | M] () – C:WindowsFontsdesktop.ini

< %systemroot%Fonts*.ini2 >

< %systemroot%Fonts*.exe >

< %systemroot%system32spoolprtprocsw32x86*.* >
[2010/04/24 06:00:00 | 000,027,648 | —- | M] (CANON INC.) – C:Windowssystem32spoolprtprocsw32x86CNMPD9Y.DLL
[2010/04/24 06:00:00 | 000,070,656 | —- | M] (CANON INC.) – C:Windowssystem32spoolprtprocsw32x86CNMPP9Y.DLL
[2009/07/13 18:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:Windowssystem32spoolprtprocsw32x86jnwppr.dll
[2010/11/20 14:29:21 | 000,030,208 | —- | M] (Microsoft Corporation) – C:Windowssystem32spoolprtprocsw32x86winprint.dll

< %systemroot%REPAIR*.bak1 >

< %systemroot%REPAIR*.ini >

< %systemroot%system32*.jpg >

< %systemroot%*.jpg >

< %systemroot%*.png >

< %systemroot%*.scr >

< %systemroot%*._sy >

< %APPDATA%AdobeUpdate*.* >

< %ALLUSERSPROFILE%Favorites*.* >

< %APPDATA%Microsoft*.* >

< %PROGRAMFILES%*.* >
[2009/07/13 21:41:57 | 000,000,174 | -HS- | M] () – C:Program Filesdesktop.ini

< %APPDATA%Update*.* >

< %systemroot%*. /mp /s >

< %systemroot%System32config*.sav >

< %PROGRAMFILES%bak. /s >

< %systemroot%system32bak. /s >

< %ALLUSERSPROFILE%Start Menu*.lnk /x >

< %systemroot%system32configsystemprofile*.dat /x >

< %systemroot%*.config >

< %systemroot%system32*.db >

< %PROGRAMFILES%Internet Explorer*.dat >

< %APPDATA%MicrosoftInternet ExplorerQuick Launch*.lnk /x >
[2012/12/28 15:12:15 | 000,000,221 | -HS- | M] () – C:UsersNathan StrykerAppDataRoamingMicrosoftInternet ExplorerQuick Launchdesktop.ini

< %USERPROFILE%Desktop*.exe >

< %PROGRAMFILES%Common Files*.* >

< %systemroot%*.src >

< %systemroot%install*.* >

< %systemroot%system32DLL*.* >

< %systemroot%system32HelpFiles*.* >

< %systemroot%system32rundll*.* >

< %systemroot%winn32*.* >

< %systemroot%Java*.* >

< %systemroot%system32test*.* >

< %systemroot%system32Rundll32*.* >

< %systemroot%AppPatchCustom*.* >

< HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU >

< HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rs >
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstallLastSuccessTime: 2013-04-18 14:37:34

< End of report >

Here is the second text file you requested:

OTL Extras logfile created on: 4/19/2013 12:04:15 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:UsersNathan StrykerDownloads
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16540)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1023.43 Mb Total Physical Memory | 340.41 Mb Available Physical Memory | 33.26% Memory free
2.00 Gb Paging File | 0.81 Gb Available in Paging File | 40.51% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files
Drive C: | 111.80 Gb Total Space | 92.05 Gb Free Space | 82.33% Space Free | Partition Type: NTFS

Computer Name: NATHANSTRYKER | User Name: Nathan Stryker | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINESOFTWAREClasses]
.cpl [@ = cplfile] – C:WindowsSystem32control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:Windowswinhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:Program FilesGoogleChromeApplicationchrome.exe (Google Inc.)

[HKEY_USERSS-1-5-21-493392108-1660724981-1100240717-1001SOFTWAREClasses]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%System32control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – "%systemroot%system32rundll32.exe" "%systemroot%system32mshtml.dll",PrintHTML "%1"
http [open] – "C:Program FilesGoogleChromeApplicationchrome.exe" – "%1" (Google Inc.)
https [open] – "C:Program FilesGoogleChromeApplicationchrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%System32InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]
"cval" = 1

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoring]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterSvc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterSvcVol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyPublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyFirewallRules]
"{0E302F7A-47B3-4B12-9CA2-9599E2A358DC}" = lport=2869 | protocol=6 | dir=in | app=system |
"{0EF6C4BF-0EBA-4548-A2B0-3A40E4DA174C}" = rport=445 | protocol=6 | dir=out | app=system |
"{1DAE884C-DCA7-432A-A1C9-EBCFF0564106}" = lport=6004 | protocol=17 | dir=in | app=c:program filesmicrosoft officeoffice14outlook.exe |
"{1E4B939A-1512-4E9E-8B21-669DACE95429}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%system32svchost.exe |
"{327320E2-0000-4077-BB51-CF6927E56B4B}" = lport=139 | protocol=6 | dir=in | app=system |
"{3A35F6E9-AB92-40E9-AA8C-297006121680}" = lport=137 | protocol=17 | dir=in | app=system |
"{3C78BB6A-CADE-42CD-9EA1-179B8D7A7431}" = lport=138 | protocol=17 | dir=in | app=system |
"{4A83B83E-8CD6-49F2-848F-A7E09301F2E4}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%system32svchost.exe |
"{4D505BFE-0847-4DF1-B7F8-2444DF61DC38}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%system32svchost.exe |
"{5ED89500-5DDB-4CAE-803E-89CB44C3825C}" = rport=10243 | protocol=6 | dir=out | app=system |
"{5FE4CECC-898B-468A-8B03-7523F57BB6F4}" = rport=138 | protocol=17 | dir=out | app=system |
"{64DA7A6B-27FC-400B-8604-70F2B7396974}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{72A95513-0BCB-4B05-847D-4B0FB16ECE37}" = lport=10243 | protocol=6 | dir=in | app=system |
"{8FA9FDE9-11D9-44A7-B70F-A0BCE74C8419}" = lport=445 | protocol=6 | dir=in | app=system |
"{AB61B3A7-4AE3-4A9A-8141-CAED44EEED70}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%system32svchost.exe |
"{B0936B27-AD3D-4ADC-90CE-DFAF2040F6BE}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%system32svchost.exe |
"{BC6DE8F7-2FB4-40B3-A99D-FE950ED2A0A0}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%system32svchost.exe |
"{C14E27D2-849A-4D8B-8D5B-366D7067F09F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%system32svchost.exe |
"{C745985D-0229-4F4D-95C2-CF86A2C36FDE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%system32svchost.exe |
"{CA21AC82-8E27-40A3-A28E-9182DE105F22}" = rport=139 | protocol=6 | dir=out | app=system |
"{CC973BB8-0063-4A0B-8082-3251637B63B2}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%system32svchost.exe |
"{DBE84298-AC62-4BDF-AD0C-67A57E94567F}" = rport=137 | protocol=17 | dir=out | app=system |
"{EC552EA0-5F2C-4B90-A289-60AC59933A88}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%system32svchost.exe |
"{EFEB6D83-834A-4C8B-91E0-2E2233FBD88A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%system32spoolsv.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyFirewallRules]
"{0FFF4CCF-D306-45BE-9A58-181E9DB038B5}" = protocol=17 | dir=out | app=%programfiles%windows media playerwmpnetwk.exe |
"{1D079A1B-AC23-4AAF-90FE-3871EE1368F6}" = protocol=6 | dir=in | app=%programfiles%windows media playerwmpnetwk.exe |
"{3CFFCB4E-BC26-46D9-BF00-41ED72FA4675}" = protocol=17 | dir=in | app=c:program filesmicrosoft officeoffice14groove.exe |
"{3DF3FF87-CB74-4EA2-89E2-5D6475EA28F8}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{4E9B8F81-0124-41F8-A81F-BD8920470529}" = protocol=17 | dir=in | app=c:program filesavgavg10avgnsx.exe |
"{7047DCC8-449E-4FCC-A228-6C004416D70E}" = protocol=6 | dir=in | app=c:program filesmicrosoft officeoffice14groove.exe |
"{733053FF-22F4-4F2F-9F70-B338BD63D8CE}" = protocol=6 | dir=in | app=c:program filesavgavg10avgemcx.exe |
"{74C2E1D7-2A80-460D-9513-88B735583AA2}" = protocol=6 | dir=out | app=%programfiles%windows media playerwmpnetwk.exe |
"{7ACDFCE2-C483-4CB1-AFAE-F7DBDC5DCF9E}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{80EB062A-EC4D-4E5C-B3A1-C7F417C1B033}" = protocol=17 | dir=in | app=%programfiles%windows media playerwmplayer.exe |
"{885DA803-B603-424A-9C9B-8DBBC2037538}" = protocol=17 | dir=out | app=%programfiles%windows media playerwmplayer.exe |
"{8BC325D4-FBE7-4D0A-BCD6-D690528666AC}" = protocol=17 | dir=in | app=c:program filesavgavg10avgemcx.exe |
"{8ED4BE9C-B21A-4A5F-8192-63826B2837ED}" = protocol=6 | dir=out | app=system |
"{91E79EF9-8516-496F-B06E-D7E930F6D477}" = protocol=6 | dir=in | app=c:program filesavgavg10avgnsx.exe |
"{9499B597-A184-4099-B8DE-9FEED646A431}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{A0ECB497-9AD9-432C-8B93-0BEF3EB5CE16}" = protocol=6 | dir=out | app=%programfiles%windows media playerwmplayer.exe |
"{A36B94D9-83AB-4127-B71C-05BE727FF4D2}" = protocol=17 | dir=in | app=c:program filesavgavg10avgdiagex.exe |
"{AD190F53-63EF-4C42-A90D-43C6E07AD8DB}" = protocol=17 | dir=in | app=%programfiles%windows media playerwmpnetwk.exe |
"{BB2C957A-A048-4137-ABA4-49D9294C050D}" = protocol=6 | dir=in | app=c:program filesavgavg10avgdiagex.exe |
"{C0448733-202A-4149-B21D-0D5EC64968EB}" = protocol=17 | dir=in | app=c:program filesavgavg10avgmfapx.exe |
"{CA6F9D96-5FD8-49FF-BBD6-418B1060A297}" = protocol=6 | dir=in | app=c:program filesavgavg10avgmfapx.exe |
"{D435B755-B374-4527-999C-C4CF5EC32648}" = protocol=6 | dir=out | app=%programfiles%windows media playerwmplayer.exe |
"{DA57B9A6-5EF7-4278-8F67-466722644E18}" = protocol=17 | dir=in | app=%programfiles%windows media playerwmplayer.exe |
"{DC480BF8-6627-421C-93E1-CB0B1530AA50}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{E608369F-25E4-478C-9F5F-80970D711E3D}" = protocol=17 | dir=out | app=%programfiles%windows media playerwmplayer.exe |
"{EA9C1029-C675-4B8D-9A3F-BC870246CABD}" = protocol=6 | dir=in | app=c:program filesmicrosoft officeoffice14onenote.exe |
"{F78BE575-F0C4-4312-8F85-8BE037447DF9}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%system32svchost.exe |
"{FE9DFA6E-8586-4BAB-8920-C152E8F890FB}" = protocol=17 | dir=in | app=c:program filesmicrosoft officeoffice14onenote.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0A76507B-063D-44E7-9008-249E88238C0E}" = AVG 2011
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP490_series" = Canon MP490 series MP Drivers
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2A3A4BD6-6CE0-4E2A-80D2-1D0FF6ACBFBA}" = LG United Mobile Driver
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{56504C77-8B9F-4EB2-B33B-C5B9F50B5D64}" = AVG 2011
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUS_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"AVG" = AVG 2011
"AVG Secure Search" = AVG Security Toolbar
"Canon My Image Garden" = Canon My Image Garden
"Canon My Image Garden Design Files" = Canon My Image Garden Design Files
"Canon My Image Garden On-screen Manual" = Canon My Image Garden On-screen Manual
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CCleaner" = CCleaner
"Defraggler" = Defraggler
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"Foxit Reader_is1" = Foxit Reader 5.1
"Google Chrome" = Google Chrome
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 20.0.1 (x86 en-US)" = Mozilla Firefox 20.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 3.0" = Canon MP Navigator EX 3.0
"Notepad++" = Notepad++
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 4/14/2013 12:42:04 PM | Computer Name = NathanStryker | Source = WinMgmt | ID = 10
Description =

Error - 4/15/2013 11:38:30 PM | Computer Name = NathanStryker | Source = Application Error | ID = 1000
Description = Faulting application name: nvvsvc.exe, version: 8.17.12.5896, time
stamp: 0x4c378fb1 Faulting module name: nvapi.dll_unloaded, version: 0.0.0.0, time
stamp: 0x510a1ca1 Exception code: 0xc0000005 Fault offset: 0x71100906 Faulting process
id: 0x5d8 Faulting application start time: 0x01ce3a53ce61bbf2 Faulting application
path: C:Windowssystem32nvvsvc.exe Faulting module path: nvapi.dll Report Id: 1ac2e8ea-a647-11e2-97ef-000c6e5a5b46

Error - 4/15/2013 11:39:23 PM | Computer Name = NathanStryker | Source = WinMgmt | ID = 10
Description =

Error - 4/16/2013 6:03:21 AM | Computer Name = NathanStryker | Source = Application Error | ID = 1000
Description = Faulting application name: DrvInst.exe, version: 6.1.7600.16385, time
stamp: 0x4a5bc04d Faulting module name: nvapi.dll_unloaded, version: 0.0.0.0, time
stamp: 0x510a1ca1 Exception code: 0xc0000005 Fault offset: 0x67e40906 Faulting process
id: 0xa6c Faulting application start time: 0x01ce3a898712beaa Faulting application
path: C:Windowssystem32DrvInst.exe Faulting module path: nvapi.dll Report Id:
de43f5cc-a67c-11e2-97ef-000c6e5a5b46

Error - 4/17/2013 6:04:34 AM | Computer Name = NathanStryker | Source = Application Error | ID = 1000
Description = Faulting application name: DrvInst.exe, version: 6.1.7600.16385, time
stamp: 0x4a5bc04d Faulting module name: nvapi.dll_unloaded, version: 0.0.0.0, time
stamp: 0x510a1ca1 Exception code: 0xc0000005 Fault offset: 0x67890906 Faulting process
id: 0x10f4 Faulting application start time: 0x01ce3b52b0a5eb06 Faulting application
path: C:Windowssystem32DrvInst.exe Faulting module path: nvapi.dll Report Id:
341fefd6-a746-11e2-97ef-000c6e5a5b46

Error - 4/18/2013 10:37:13 AM | Computer Name = NathanStryker | Source = Application Error | ID = 1000
Description = Faulting application name: DrvInst.exe, version: 6.1.7600.16385, time
stamp: 0x4a5bc04d Faulting module name: nvapi.dll_unloaded, version: 0.0.0.0, time
stamp: 0x510a1ca1 Exception code: 0xc0000005 Fault offset: 0x63ff0906 Faulting process
id: 0x13c8 Faulting application start time: 0x01ce3c41c357c805 Faulting application
path: C:Windowssystem32DrvInst.exe Faulting module path: nvapi.dll Report Id:
74dd8340-a835-11e2-97ef-000c6e5a5b46

Error - 4/18/2013 10:12:48 PM | Computer Name = NathanStryker | Source = Application Error | ID = 1000
Description = Faulting application name: nvvsvc.exe, version: 8.17.12.5896, time
stamp: 0x4c378fb1 Faulting module name: nvapi.dll_unloaded, version: 0.0.0.0, time
stamp: 0x510a1ca1 Exception code: 0xc0000005 Fault offset: 0x71610906 Faulting process
id: 0x554 Faulting application start time: 0x01ce3ca3596f4bc8 Faulting application
path: C:Windowssystem32nvvsvc.exe Faulting module path: nvapi.dll Report Id: a0fb144a-a896-11e2-9f62-000c6e5a5b46

Error - 4/18/2013 10:13:50 PM | Computer Name = NathanStryker | Source = WinMgmt | ID = 10
Description =

Error - 4/19/2013 2:42:14 PM | Computer Name = NathanStryker | Source = Application Error | ID = 1000
Description = Faulting application name: nvvsvc.exe, version: 8.17.12.5896, time
stamp: 0x4c378fb1 Faulting module name: nvapi.dll_unloaded, version: 0.0.0.0, time
stamp: 0x510a1ca1 Exception code: 0xc0000005 Fault offset: 0x73090906 Faulting process
id: 0x574 Faulting application start time: 0x01ce3d2d905106d8 Faulting application
path: C:Windowssystem32nvvsvc.exe Faulting module path: nvapi.dll Report Id: da012c36-a920-11e2-b750-000c6e5a5b46

Error - 4/19/2013 2:43:22 PM | Computer Name = NathanStryker | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 4/17/2013 10:13:18 AM | Computer Name = NathanStryker | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the ShellHWDetection service.

Error - 4/18/2013 6:09:47 AM | Computer Name = NathanStryker | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x800705b4: nVidia - Graphics Adapter WDDM1.1, Other hardware - NVIDIA
GeForce 6200.

Error - 4/18/2013 10:29:29 AM | Computer Name = NathanStryker | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the ShellHWDetection service.

Error - 4/18/2013 10:37:38 AM | Computer Name = NathanStryker | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x800700ff: nVidia - Graphics Adapter WDDM1.1, Other hardware - NVIDIA
GeForce 6200.

Error - 4/18/2013 11:23:36 AM | Computer Name = NathanStryker | Source = Server | ID = 2505
Description = The server could not bind to the transport DeviceNetBT_Tcpip_{7990D035-B7F6-495D-B477-92331DB18D78}
because another computer on the network has the same name. The server could not
start.

Error - 4/18/2013 10:09:49 PM | Computer Name = NathanStryker | Source = DCOM | ID = 10010
Description =

Error - 4/18/2013 10:10:13 PM | Computer Name = NathanStryker | Source = DCOM | ID = 10010
Description =

Error - 4/18/2013 10:12:06 PM | Computer Name = NathanStryker | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description = Some processor performance power management features have been disabled
due to a known firmware problem. Check with the computer manufacturer for updated
firmware.

Error - 4/19/2013 2:42:39 AM | Computer Name = NathanStryker | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.

Error - 4/19/2013 2:41:32 PM | Computer Name = NathanStryker | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description = Some processor performance power management features have been disabled
due to a known firmware problem. Check with the computer manufacturer for updated
firmware.


< End of report >
Unfortunately I have to go back to work for two weeks so I guess you may delete this thread. I'll try again on my next week off.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI