This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Babylonsearch [Closed]

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I posted about this before, but I couldn't get back in time to continue the forum conversation. So let's start over. I thought I got rid of babylon search, but I was wrong. Computer has also been generally slow and programs randomly not responding. I ran OTL. The OTL txt file is below, it didn't create an EXTRAS txt file.

OTL logfile created on: 4/27/2013 9:28:08 AM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jack\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.91 Gb Total Physical Memory | 1.26 Gb Available Physical Memory | 32.11% Memory free
9.77 Gb Paging File | 7.51 Gb Available in Paging File | 76.88% Paging File free
Paging file location(s): c:\pagefile.sys 6000 10000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 581.71 Gb Total Space | 460.67 Gb Free Space | 79.19% Space Free | Partition Type: NTFS

Computer Name: JACK-TOSHIBA | User Name: Jack | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Jack\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Users\Jack\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
PRC - C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe ()
PRC - C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe ()
PRC - C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe (Nero AG)
PRC - C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\SeaPort.EXE (Microsoft Corporation.)
PRC - C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe (Motorola)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Toshiba\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files (x86)\Toshiba\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.6.22\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Mindjet\MindManager 7\MmReminderService.exe (Mindjet)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\cx8h17h4.default\extensions\[removed]\platform\WINNT_x86-msvc\components\lpxpcom.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Mindjet\MindManager 7\zlib.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (TOSHIBA eco Utility Service) – C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
SRV:64bit: - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV:64bit: - (MyWiFiDHCPDNS) – C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV:64bit: - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV:64bit: - (TPCHSrv) – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TODDSrv) – C:\Windows\SysNative\TODDSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (Thpsrv) – C:\Windows\SysNative\ThpSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Motorola Device Manager) – C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe ()
SRV - (DeviceMonitorService) – C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe (Nero AG)
SRV - (BBUpdate) – C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (PST Service) – C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe (Motorola)
SRV - (TMachInfo) – C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (PCCUJobMgr) – C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.6.22\ccSvcHst.exe (Symantec Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\avgidsdrivera.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgloga) – C:\Windows\SysNative\drivers\avgloga.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSHA) – C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (motccgp) – C:\Windows\SysNative\drivers\motccgp.sys (Motorola Mobility Inc)
DRV:64bit: - (Motousbnet) – C:\Windows\SysNative\drivers\Motousbnet.sys (Motorola Mobility Inc)
DRV:64bit: - (MotoSwitchService) – C:\Windows\SysNative\drivers\motswch.sys (Motorola)
DRV:64bit: - (motmodem) – C:\Windows\SysNative\drivers\motmodem.sys (Motorola Mobility Inc)
DRV:64bit: - (Fs_Rec) – C:\windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (motccgpfl) – C:\Windows\SysNative\drivers\motccgpfl.sys (Motorola Mobility Inc)
DRV:64bit: - (motusbdevice) – C:\Windows\SysNative\drivers\motusbdevice.sys (Motorola Inc)
DRV:64bit: - (Point64) – C:\Windows\SysNative\drivers\point64.sys (Microsoft Corporation)
DRV:64bit: - (NuidFltr) – C:\Windows\SysNative\drivers\nuidfltr.sys (Microsoft Corporation)
DRV:64bit: - (dc3d) – C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (tos_sps64) – C:\Windows\SysNative\drivers\tos_sps64.sys (TOSHIBA Corporation)
DRV:64bit: - (JMCR) – C:\Windows\SysNative\drivers\jmcr.sys (JMicron Technology Corporation)
DRV:64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (NETwNs64) – C:\Windows\SysNative\drivers\NETwNs64.sys (Intel Corporation)
DRV:64bit: - (wdkmd) – C:\Windows\SysNative\drivers\WDKMD.sys (Intel Corporation)
DRV:64bit: - (MEIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (ivusb) – C:\Windows\SysNative\drivers\ivusb.sys (Initio Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (Tosrfusb) – C:\Windows\SysNative\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV:64bit: - (tosrfbd) – C:\Windows\SysNative\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV:64bit: - (TosRfSnd) – C:\Windows\SysNative\drivers\TosRfSnd.sys (TOSHIBA Corporation)
DRV:64bit: - (LPCFilter) – C:\Windows\SysNative\drivers\LPCFilter.sys (COMPAL ELECTRONIC INC.)
DRV:64bit: - (tdcmdpst) – C:\Windows\SysNative\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV:64bit: - (Tosrfcom) – C:\Windows\SysNative\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV:64bit: - (tosrfnds) – C:\Windows\SysNative\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV:64bit: - (TVALZ) – C:\Windows\SysNative\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (ROOTMODEM) – C:\Windows\SysNative\drivers\rootmdm.sys (Microsoft Corporation)
DRV:64bit: - (Thpevm) – C:\Windows\SysNative\drivers\Thpevm.sys (TOSHIBA Corporation)
DRV:64bit: - (Thpdrv) – C:\Windows\SysNative\drivers\thpdrv.sys (TOSHIBA Corporation)
DRV:64bit: - (PGEffect) – C:\Windows\SysNative\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV:64bit: - (TVALZFL) – C:\Windows\SysNative\drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV:64bit: - (Tosrfhid) – C:\Windows\SysNative\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV:64bit: - (tosrfbnp) – C:\Windows\SysNative\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV:64bit: - (tosporte) – C:\Windows\SysNative\drivers\tosporte.sys (TOSHIBA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (BTCFilterService) – C:\Windows\SysNative\drivers\motfilt.sys (Motorola Inc)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {7F0C8FE2-6CD8-4360-BCA7-4A7CB4CC6261}
IE:64bit: - HKLM\..\SearchScopes\{7F0C8FE2-6CD8-4360-BCA7-4A7CB4CC6261}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSNF
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {D21E6F85-E9E6-4FE8-A3DB-0CBADAF49991}
IE - HKLM\..\SearchScopes\{D21E6F85-E9E6-4FE8-A3DB-0CBADAF49991}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSNF

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.toshiba.com/g/
IE - HKCU\..\SearchScopes,DefaultScope = {85B2C813-618E-4D99-9410-D1ABFC22378C}
IE - HKCU\..\SearchScopes\{85B2C813-618E-4D99-9410-D1ABFC22378C}: "URL" = http://www.google.com/search?sourceid=ie7&…;rlz=1I7TSNF_en
IE - HKCU\..\SearchScopes\{D21E6F85-E9E6-4FE8-A3DB-0CBADAF49991}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSNF
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local;192.168.*.*

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: 2020Player_WEB%402020Technologies.com:[removed]
FF - prefs.js..extensions.enabledAddons: amznUWL2%40amazon.com:1.10
FF - prefs.js..extensions.enabledAddons: foxmarks%40kei.com:4.1.3
FF - prefs.js..extensions.enabledAddons: support%40lastpass.com:2.0.20
FF - prefs.js..extensions.enabledAddons: %7B37fa1426-b82d-11db-8314-0800200c9a66%7D:3.3
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - prefs.js..extensions.enabledItems: [removed]:3.9.9
FF - prefs.js..extensions.enabledItems: [removed]:1.5
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_7_700_169.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Jack\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Jack\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/04/16 21:24:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/04/16 21:24:06 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/04/16 21:24:17 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/04/16 21:24:06 | 000,000,000 | —D | M]

[2011/05/06 23:12:12 | 000,000,000 | —D | M] (No name found) – C:\Users\Jack\AppData\Roaming\Mozilla\Extensions
[2013/04/27 08:27:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\cx8h17h4.default\extensions
[2012/09/30 18:57:52 | 000,000,000 | —D | M] (20-20 3D Viewer - WEB) – C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\cx8h17h4.default\extensions\[removed]
[2012/10/12 10:57:29 | 000,000,000 | —D | M] ("Xmarks") – C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\cx8h17h4.default\extensions\[removed]
[2013/04/27 08:27:47 | 000,000,000 | —D | M] (LastPass) – C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\cx8h17h4.default\extensions\[removed]
[2012/09/27 23:30:31 | 000,243,287 | —- | M] () (No name found) – C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\cx8h17h4.default\extensions\[removed]
[2013/04/27 08:27:40 | 000,223,761 | —- | M] () (No name found) – C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\cx8h17h4.default\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}.xpi
[2011/05/24 06:43:15 | 000,001,635 | —- | M] () – C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\cx8h17h4.default\searchplugins\firefox-add-ons.xml
[2011/05/24 06:44:06 | 000,001,504 | —- | M] () – C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\cx8h17h4.default\searchplugins\imdb.xml
[2011/05/24 06:43:47 | 000,004,140 | —- | M] () – C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\cx8h17h4.default\searchplugins\youtube.xml
[2013/04/16 21:24:05 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/04/16 21:24:17 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/02/22 18:58:26 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npCouponPrinter.dll
[2011/10/03 05:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012/02/22 18:58:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npMozCouponPrinter.dll
[2012/07/15 00:26:12 | 000,002,313 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012/09/21 21:37:58 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013/03/02 15:30:04 | 000,002,086 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Search the web (Babylon) (Enabled)
CHR - default_search_provider: search_url = http://search.babylon.com/?q={searchTerms}…0008ca9825ca72b
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://search.babylon.com/?affID=113959&am;…0008ca9825ca72b
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\plugins/avgnpss.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll File not found
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\Toshiba\TOSHIBA Media Controller Plug-in\x64\TOSHIBAMediaControllerIE.dll (TOSHIBA Corporation)
O2 - BHO: (CmjBrowserHelperObject Object) - {07A11D74-9D25-4fea-A833-8B0D76A5577A} - C:\Program Files (x86)\Mindjet\MindManager 7\Mm7InternetExplorer.dll (Mindjet)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll File not found
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\Toshiba\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (TOSHIBA Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [ThpSrv] C:\windows\SysNative\thpsrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosNC] C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [KeNotify] C:\Program Files (x86)\Toshiba\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [MMReminderService] C:\Program Files (x86)\Mindjet\MindManager 7\MmReminderService.exe (Mindjet)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe (Toshiba)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [ToshibaAppPlace] C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe (Toshiba)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKCU..\Run: [HP Officejet Pro 8600 (NET)] C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - HKCU..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe File not found
O4 - HKCU..\Run: [MotoCast] C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk ()
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\Jack\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKCU..\Run: [uTorrent] C:\Users\Jack\Downloads\utorrent.exe (BitTorrent, Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8:64bit: - Extra context menu item: Add to TOSHIBA Bulletin Board - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll (TODO: <会社名>)
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: Add to TOSHIBA Bulletin Board - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll (TODO: <会社名>)
O9:64bit: - Extra Button: Add to TOSHIBA Bulletin Board - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom64.dll (TODO: <会社名>)
O9:64bit: - Extra 'Tools' menuitem : Add to TOSHIBA Bulletin Board - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom64.dll (TODO: <会社名>)
O9 - Extra Button: Send to Mindjet MindManager - {941E1A34-C6AF-4baa-A973-224F9C3E04BF} - C:\Program Files (x86)\Mindjet\MindManager 7\Mm7InternetExplorer.dll (Mindjet)
O9 - Extra Button: Add to TOSHIBA Bulletin Board - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll (TODO: <会社名>)
O9 - Extra 'Tools' menuitem : Add to TOSHIBA Bulletin Board - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll (TODO: <会社名>)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.7.2)
O16 - DPF: {2AB1C516-D654-4D3A-B3D6-2185BBCEB409} https://webvpn.na.aecom.com/+CSCOL+/relayp.cab (Cisco Systems WebVPN Relay Loader)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BA20463F-FDCE-493E-A9D1-A7D25C2DF232}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll File not found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll File not found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/04/27 08:31:31 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Jack\Desktop\OTL.exe
[2013/04/26 15:59:08 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2013/04/23 23:30:17 | 000,000,000 | —D | C] – C:\Users\Jack\Documents\Business
[2013/04/20 18:45:42 | 000,000,000 | —D | C] – C:\Users\Jack\Documents\3824 Sharp St
[2013/04/20 18:24:35 | 000,000,000 | —D | C] – C:\Users\Jack\Documents\Work Bench Plans
[2013/04/16 21:24:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/04/16 21:00:59 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\mshtmled.dll
[2013/04/16 21:00:58 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\mshtmled.dll
[2013/04/16 21:00:57 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieui.dll
[2013/04/16 21:00:56 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\inetcpl.cpl
[2013/04/16 21:00:56 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\inetcpl.cpl
[2013/04/16 21:00:56 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieui.dll
[2013/04/16 21:00:56 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\url.dll
[2013/04/16 21:00:56 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\url.dll
[2013/04/16 21:00:56 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieUnatt.exe
[2013/04/16 21:00:56 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieUnatt.exe
[2013/04/16 21:00:55 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\jscript9.dll
[2013/04/16 21:00:55 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\msfeeds.dll
[2013/04/16 21:00:53 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\jscript.dll
[2013/04/16 21:00:53 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\jscript.dll
[2013/04/16 21:00:53 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\vbscript.dll
[2013/04/14 17:29:56 | 003,717,632 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\mstscax.dll
[2013/04/14 17:29:55 | 003,217,408 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\mstscax.dll
[2013/04/14 17:29:54 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\aaclient.dll
[2013/04/14 17:29:54 | 000,131,584 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\aaclient.dll
[2013/04/14 17:29:54 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\tsgqec.dll
[2013/04/14 17:29:54 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\tsgqec.dll
[2013/04/14 17:29:40 | 005,550,424 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ntoskrnl.exe
[2013/04/14 17:29:37 | 003,968,856 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntkrnlpa.exe
[2013/04/14 17:29:37 | 003,913,560 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntoskrnl.exe
[2013/04/14 17:29:36 | 000,112,640 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\smss.exe
[2013/04/14 17:29:36 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\csrsrv.dll
[2013/04/14 17:29:36 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\apisetschema.dll
[2013/04/08 00:05:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2013/03/31 19:35:19 | 000,000,000 | —D | C] – C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2013/03/31 19:14:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis
[2013/03/31 19:14:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2013/03/31 19:14:09 | 000,812,344 | —- | C] (Trend Micro Inc.) – C:\Users\Jack\Desktop\HJTInstall.exe
[2013/03/31 17:42:02 | 000,000,000 | —D | C] – C:\Users\Jack\AppData\Roaming\2BrightSparks
[2013/03/31 17:41:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\2BrightSparks
[2013/03/31 17:41:40 | 000,000,000 | —D | C] – C:\Users\Jack\AppData\Local\2BrightSparks
[2013/03/31 17:41:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\2BrightSparks
[2013/03/30 10:35:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013/03/30 10:32:58 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2013/03/30 10:32:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2 C:\windows\SysWow64\*.tmp files -> C:\windows\SysWow64\*.tmp -> ]
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/04/27 09:22:08 | 000,000,830 | —- | M] () – C:\windows\tasks\Adobe Flash Player Updater.job
[2013/04/27 09:18:17 | 000,145,691 | —- | M] () – C:\Users\Jack\Desktop\Are you Infected_ Need Help_.pdf
[2013/04/27 09:06:11 | 000,000,904 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3671255274-3908056842-1801094870-1001UA.job
[2013/04/27 08:37:14 | 000,000,912 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/04/27 08:35:17 | 000,016,304 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/04/27 08:35:17 | 000,016,304 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/04/27 08:32:01 | 000,001,124 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/04/27 08:31:32 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Jack\Desktop\OTL.exe
[2013/04/27 08:30:41 | 000,726,444 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2013/04/27 08:30:41 | 000,624,412 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2013/04/27 08:30:41 | 000,106,756 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2013/04/27 08:27:08 | 000,001,930 | —- | M] () – C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Officejet Pro 8600 (Network).lnk
[2013/04/27 08:26:15 | 000,000,908 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/04/27 08:24:01 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2013/04/27 08:23:58 | 3147,841,536 | -HS- | M] () – C:\hiberfil.sys
[2013/04/27 08:16:18 | 000,000,852 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3671255274-3908056842-1801094870-1001Core.job
[2013/04/20 18:12:42 | 000,001,236 | —- | M] () – C:\Users\Jack\Desktop\SyncBackFree.lnk
[2013/04/18 22:51:33 | 000,691,592 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerApp.exe
[2013/04/18 22:51:33 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/04/18 22:48:36 | 000,002,059 | —- | M] () – C:\Users\Jack\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/04/16 21:28:04 | 000,417,712 | —- | M] () – C:\windows\SysNative\FNTCACHE.DAT
[2013/04/08 00:05:37 | 000,001,081 | —- | M] () – C:\Users\Public\Desktop\VLC media player.lnk
[2013/04/07 21:03:18 | 000,000,976 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/04/04 14:50:32 | 000,025,928 | —- | M] (Malwarebytes Corporation) – C:\windows\SysNative\drivers\mbam.sys
[2013/03/31 23:40:06 | 000,004,074 | —- | M] () – C:\Users\Jack\Documents\TapoutCalendar.csv
[2013/03/31 19:35:19 | 000,002,971 | —- | M] () – C:\Users\Jack\Desktop\HiJackThis.lnk
[2013/03/31 19:33:59 | 001,402,880 | —- | M] () – C:\Users\Jack\Desktop\HiJackThis.msi
[2013/03/31 19:14:11 | 000,812,344 | —- | M] (Trend Micro Inc.) – C:\Users\Jack\Desktop\HJTInstall.exe
[2013/03/31 18:33:55 | 000,001,079 | —- | M] () – C:\Users\Jack\Desktop\ChromePlus.lnk
[2013/03/30 15:51:14 | 000,001,030 | —- | M] () – C:\Users\Jack\Desktop\Dropbox.lnk
[2 C:\windows\SysWow64\*.tmp files -> C:\windows\SysWow64\*.tmp -> ]
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/04/27 09:18:11 | 000,145,691 | —- | C] () – C:\Users\Jack\Desktop\Are you Infected_ Need Help_.pdf
[2013/04/08 00:05:37 | 000,001,081 | —- | C] () – C:\Users\Public\Desktop\VLC media player.lnk
[2013/03/31 19:33:57 | 001,402,880 | —- | C] () – C:\Users\Jack\Desktop\HiJackThis.msi
[2013/03/31 19:14:25 | 000,002,971 | —- | C] () – C:\Users\Jack\Desktop\HiJackThis.lnk
[2013/03/31 18:20:32 | 000,001,124 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/03/31 17:41:45 | 000,001,236 | —- | C] () – C:\Users\Jack\Desktop\SyncBackFree.lnk
[2012/12/23 23:04:40 | 000,001,445 | —- | C] () – C:\Users\Jack\.recently-used.xbel
[2012/12/03 00:36:14 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2012/08/05 10:17:43 | 000,256,000 | —- | C] () – C:\windows\PEV.exe
[2012/08/05 10:17:43 | 000,208,896 | —- | C] () – C:\windows\MBR.exe
[2012/08/05 10:17:43 | 000,098,816 | —- | C] () – C:\windows\sed.exe
[2012/08/05 10:17:43 | 000,080,412 | —- | C] () – C:\windows\grep.exe
[2012/08/05 10:17:43 | 000,068,096 | —- | C] () – C:\windows\zip.exe

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 01:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 00:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\SysWow64\wbem\wbemess.dll

========== LOP Check ==========

[2013/03/31 17:42:02 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\2BrightSparks
[2012/12/16 21:57:03 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\AVG2013
[2012/07/15 00:26:06 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\Babylon
[2011/08/26 10:41:30 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\Bentley
[2011/06/26 20:21:12 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\Book Place
[2013/03/31 18:38:19 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\ChromePlus
[2013/04/26 23:39:41 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\Dropbox
[2012/12/23 22:56:25 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\gtk-2.0
[2012/09/27 23:20:08 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\HandBrake
[2012/12/31 10:17:05 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\MediaMonkey
[2013/04/27 09:12:18 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\MotoCast
[2011/12/26 23:06:48 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\Motorola
[2012/08/10 20:59:33 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\Motorola Mobility
[2012/09/22 10:56:02 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\NASNaviator2
[2012/08/03 21:24:31 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\PCCUStubInstaller
[2012/09/02 21:30:08 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\pdfforge
[2013/02/08 00:52:31 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\Spotify
[2012/10/28 19:09:03 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\SysDev Laboratories
[2011/05/02 23:31:46 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\Tific
[2012/04/14 23:10:45 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\Toshiba
[2012/12/16 21:54:54 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\TuneUp Software
[2012/11/18 14:47:05 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\uTorrent
[2011/05/02 23:22:27 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\WinBatch
[2012/03/26 23:54:10 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\WinTR-55

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2009/07/13 22:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 16:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 02:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 01:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 01:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\erdnt\cache86\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 02:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/03 02:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 02:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 01:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 09:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 02:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 01:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 21:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 02:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 02:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/03 02:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: EXPLORER.EXE.3416.DMP >
[2013/03/03 08:56:49 | 003,099,211 | —- | M] () MD5=09FD3FB4231D44CD07AAC3AC6501B4DA – C:\Users\Jack\AppData\Local\CrashDumps\explorer.exe.3416.dmp

< MD5 for: EXPLORER.EXE.3980.DMP >
[2013/02/07 01:16:00 | 003,567,053 | —- | M] () MD5=BEA54AA1C05BDA7AB49745D04207C313 – C:\Users\Jack\AppData\Local\CrashDumps\explorer.exe.3980.dmp

< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 22:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 22:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: IEXPLORE.EXE >
[2012/06/02 07:47:54 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=004640AB259C1572EBD5FB0A32F63686 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_0dbfc836999db0ca\iexplore.exe
[2013/01/08 21:53:45 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=0100BCF23941C83462E4A70F94C3392E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_0d2c5bc980874648\iexplore.exe
[2012/05/17 19:21:54 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_1798a687b4d6030f\iexplore.exe
[2012/11/13 22:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_178ed6e5b4dd3857\iexplore.exe
[2012/06/29 01:02:52 | 000,754,784 | —- | M] (Microsoft Corporation) MD5=1223ACBFC1093852DFF039E189599BBD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2010/09/08 00:36:39 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=14803EA3E5DD7CB37CB446C74CFDA38F – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20795_none_1a39121b8bff3c23\iexplore.exe
[2012/08/24 03:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2013/02/22 03:04:50 | 000,763,520 | —- | M] (Microsoft Corporation) MD5=25B53709A37C3FD814B68EA0A92D18F9 – C:\Program Files\Internet Explorer\iexplore.exe
[2013/02/22 03:04:50 | 000,763,520 | —- | M] (Microsoft Corporation) MD5=25B53709A37C3FD814B68EA0A92D18F9 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_0d238c71808d94e7\iexplore.exe
[2012/05/17 18:59:46 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_181271f4ce004017\iexplore.exe
[2012/10/08 04:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_178cd651b4df05a9\iexplore.exe
[2009/07/13 21:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_19ba3f8a72d988f3\iexplore.exe
[2012/08/24 07:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2013/02/22 00:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/02/22 00:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_177836c3b4ee56e2\iexplore.exe
[2012/06/02 05:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\erdnt\cache86\iexplore.exe
[2012/06/02 05:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_1799a6d1b4d51c66\iexplore.exe
[2013/02/22 00:10:31 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=4145E2B5663F6FACC08EFDB17B658BB2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_17f703a2ce14129d\iexplore.exe
[2010/09/08 01:37:57 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=4879CB864E290BED38C5BDB641144B1B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20795_none_0fe467c9579e7a28\iexplore.exe
[2012/10/08 08:29:46 | 000,754,848 | —- | M] (Microsoft Corporation) MD5=49442BA6DCE4B4E3C1CB0AB193FE29AD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_0d382bff807e43ae\iexplore.exe
[2010/09/08 01:49:01 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=498035ABCCF1ED47AE6791D239187587 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16671_none_0f6c69ae3e743d20\iexplore.exe
[2012/05/17 22:51:05 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=4E99F42504A99D5024C2EFA015001937 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_0d43fc3580754114\iexplore.exe
[2010/11/04 01:54:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=58CF468D3FF4CF830339FE5E45356355 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16700_none_1a0bc510729d1f54\iexplore.exe
[2012/08/24 06:49:07 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012/06/28 22:45:31 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=5D03518409F37D1483C98869D86E23FF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_0dc0c880999cca21\iexplore.exe
[2012/06/02 08:52:21 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=610F6596921C4BAA8834ADBB9BE272EE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_0d44fc7f80745a6b\iexplore.exe
[2010/09/08 00:31:24 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=61EDBCE47ADF3E52AB0B9F49EE4AEBB8 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16671_none_19c1140072d4ff1b\iexplore.exe
[2012/08/24 03:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2013/01/08 18:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_1781061bb4e80843\iexplore.exe
[2010/11/04 01:54:59 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=6B2258FF6D2332073FE9E90122FA4168 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20831_none_1a75f2618bd22c48\iexplore.exe
[2013/02/02 04:09:12 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=7C2923004FFC497E54F38E835F108EE8 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_0d9c579499b8b898\iexplore.exe
[2010/11/20 09:28:25 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2011/05/08 19:43:04 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2012/06/28 21:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2013/02/02 00:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_17f101e6ce197a93\iexplore.exe
[2013/02/02 03:37:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=A8EBEBCD9F5C49475194099FCD276992 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_0d1d8ab58092fcdd\iexplore.exe
[2011/02/24 01:45:11 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AB2BB40A5FE49AD236791AC22BD08869 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_1a9d66118bb386fd\iexplore.exe
[2012/11/15 23:08:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=AC4957E154F750DF54F36ADC8E3E040D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_0db6f8de99a3ff69\iexplore.exe
[2013/02/22 03:17:45 | 000,763,520 | —- | M] (Microsoft Corporation) MD5=B21A57AA4CB928059A0C0C58A9E77A02 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_0da2595099b350a2\iexplore.exe
[2011/02/24 02:29:19 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=B4881B8F6EDB48CABD44BCC9FB5475C4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_1048bbbf5752c502\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2012/06/02 04:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_18147288cdfe72c5\iexplore.exe
[2010/11/20 08:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2011/02/24 01:32:52 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C6697A46554E36541E81182B258A19D6 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_19d0e74472c85f04\iexplore.exe
[2012/10/08 04:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_1808a252ce07755f\iexplore.exe
[2010/11/04 02:37:41 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=D8E00EA671A1EFE95C69C7566C505AD4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16700_none_0fb71abe3e3c5d59\iexplore.exe
[2013/02/02 00:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_17723507b4f3bed8\iexplore.exe
[2011/02/24 02:32:09 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=E1BBDE0F187194D4B08335234A4B9FC7 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_0f7c3cf23e679d09\iexplore.exe
[2010/11/04 02:42:22 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=E220FB009F54AAF649C6A278A5156764 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20831_none_1021480f57716a4d\iexplore.exe
[2012/06/28 19:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_181572d2cdfd8c1c\iexplore.exe
[2013/01/08 20:51:57 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=EF1F6F41FB2C9BBB484B21017F380201 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_0daa285e99ade8ac\iexplore.exe
[2013/01/08 17:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_17fed2b0ce0eaaa7\iexplore.exe
[2011/05/08 19:43:04 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe
[2009/07/13 21:43:43 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_0f6595383e78c6f8\iexplore.exe
[2012/10/08 07:09:10 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=F61714ABCF9BF0CEF0A6249AD4FD490B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_0db3f80099a6b364\iexplore.exe
[2012/11/13 22:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_180ba330ce04c164\iexplore.exe
[2012/05/17 21:37:57 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=F8B2D47ED17C1D087D14EC747E5AC57A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_0dbdc7a2999f7e1c\iexplore.exe
[2012/11/14 03:11:18 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_0d3a2c93807c765c\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2011/05/08 19:43:04 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2011/05/08 19:43:04 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011/05/08 19:43:04 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2011/05/08 19:43:04 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_09122aaf762607df\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_1366d501aa86c9da\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: SERVICES >
[2009/06/10 17:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.CFG >
[2012/12/18 10:28:18 | 000,558,791 | —- | M] () MD5=A9983CC532F9B3FB1E87918D2313731D – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.EXE >
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\erdnt\cache64\services.exe
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\windows\SysNative\services.exe
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 22:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\windows\SysNative\en-US\services.exe.mui
[2009/07/13 22:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\windows\SysNative\wbem\services.mof
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2009/07/13 22:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\windows\SysNative\en-US\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\windows\SysNative\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2009/07/13 22:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2009/07/13 22:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 09:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\erdnt\cache64\winlogon.exe
[2010/11/20 09:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\windows\SysNative\winlogon.exe
[2010/11/20 09:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 21:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/28 03:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/28 02:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 09:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\windows\SysNative\en-US\winlogon.exe.mui
[2010/11/20 09:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
[2009/07/13 22:29:52 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=56D03B64B8C483C1D12A8E4577B3B332 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_26ed83321dc778e1\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2009/07/13 22:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/13 22:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\windows\SysNative\wbem\winlogon.mof
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2009/07/13 21:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/12/29 02:38:27 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2012/08/05 10:33:09 | 000,020,360 | —- | M] () – C:\ComboFix.txt
[2013/04/27 08:23:58 | 3147,841,536 | -HS- | M] () – C:\hiberfil.sys
[2013/04/27 08:23:58 | 1996,488,703 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/03/08 18:37:20 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\windows\WLXPGSS.SCR
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/08 19:59:13 | 000,000,221 | -HS- | M] () – C:\Users\Jack\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/08/04 21:46:19 | 002,322,184 | —- | M] (ESET) – C:\Users\Jack\Desktop\esetsmartinstaller_enu.exe
[2013/03/31 19:14:11 | 000,812,344 | —- | M] (Trend Micro Inc.) – C:\Users\Jack\Desktop\HJTInstall.exe
[2013/04/27 08:31:32 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Jack\Desktop\OTL.exe
[2012/10/28 18:25:21 | 007,298,916 | —- | M] (Igor Pavlov) – C:\Users\Jack\Desktop\TFTP Boot Recovery LS-WTGL-v3 3.08.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 829 bytes -> C:\Users\Jack\Documents\Adobe v8.0 - Your Serial Numbers.eml:OECustomProperty

< End of report >
Hello Jaclyn,

Welcome back! Let's see if we can get you cleared up this time. :D

=================

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice, this will be a team effort. This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Important Note for Vista and Windows 7 users:

These tools MUST be run from the executable.(.exe) every time you run them with Admin Rights (Right click, choose "Run as Administrator")

Please stay with this topic until I let you know that your system appears to be "All Clear"
Hi Jaclyn,

P2P - I see you have/had P2P software uTorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections and possibly Identity Theft. It likely contributed to your current situation. This page will give you further information.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

I would strongly recommend that you uninstall this now.

Click Start > Control Panel > Programs and Features. Locate and select the following that are present on the list and click the Remove button:
  • uTorrent
If you choose to not remove this program please refrain from using it until we have finished cleaning your computer.

- - - - - Next - - - - -

Did you set a Proxy Override in you Internet Explorer settings?

- - - - - Next - - - - -

Download AdwCleaner to your desktop.

Right click and select "Run as Administrator".
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
- - - - - Next - - - - -

[external image: Posted Image] Please download Junkware Removal Tool to your desktop.

Right click and select "Run as Administrator".
  • Shut down your protection software now to avoid potential conflicts.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
- - - - - Next - - - - -

Reboot

- - - - - Next - - - - -

Re-run OTL (it should be located on your desktop).

Windows Vista and Windows 7 users Right Click and select "Run as Administrator" on the icon to run it.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt. (No Extras.txt will be produced)
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
In your next post please provide the following:
  • Answer to my questions about the ProxyOverride.
  • AdwCleaner.txt
  • JRT.txt
  • OTL.txt (no extras log will be produce)
  • How is the computer running at the moment?
  • Which browser/s is affected by the BabylonSearch?
utorrent uninstalled.
I did not set a Proxy Override in my Internet Explorer settings. At least it doesn't sound familiar. not unless someone at whatthetech told me to do it.
last reboot was faster
i think babylon search was affecting internet explorer, and I'm not seeing it now.

# AdwCleaner v2.300 - Logfile created 04/28/2013 at 12:45:22
# Updated 28/04/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Jack - JACK-TOSHIBA
# Boot Mode : Normal
# Running from : C:\Users\Jack\Desktop\AdwCleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml
Folder Deleted : C:\Program Files\pdfforge
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pdfforge
Folder Deleted : C:\Users\Jack\AppData\Roaming\Babylon
Folder Deleted : C:\Users\Jack\AppData\Roaming\pdfforge

***** [Registry] *****

Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\Software\TENCENT
Key Deleted : HKLM\SOFTWARE\Software

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16476

[OK] Registry is clean.

-\\ Mozilla Firefox v20.0.1 (en-US)

File : C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\cx8h17h4.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v26.0.1410.64

File : C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted [l.27] : icon_url = "hxxp://www.babylon.com/favicon.ico",
Deleted [l.30] : keyword = "babylon.com",
Deleted [l.34] : search_url = "hxxp://search.babylon.com/?q={searchTerms}&affID;=113959&babsrc;=SP_ss&mntrId;=52a[…]
Deleted [l.1828] : homepage = "hxxp://search.babylon.com/?affID=113959&babsrc;=HP_ss&mntrId;=52a2b99a0000000000008ca9[…]
Deleted [l.2047] : urls_to_restore_on_startup = [ "hxxp://search.babylon.com/?affID=113959&babsrc;=HP_ss&mntrId;=5[…]

*************************

AdwCleaner[S1].txt - [1740 octets] - [28/04/2013 12:45:22]

########## EOF - C:\AdwCleaner[S1].txt - [1800 octets] ##########

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.1 (04.27.2013:1)
OS: Windows 7 Home Premium x64
Ran by [removed] on Sun 04/28/2013 at 13:02:41.60
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files

Successfully deleted: [File] "C:\Program Files (x86)\mozilla firefox\plugins\npcouponprinter.dll"
Successfully deleted: [File] "C:\Program Files (x86)\mozilla firefox\plugins\npmozcouponprinter.dll"
Successfully deleted: [File] "C:\windows\couponprinter.ocx"



~~~ Folders

Successfully deleted: [Folder] "C:\Users\Jack\AppData\Roaming\pccustubinstaller"
Successfully deleted: [Folder] "C:\Program Files (x86)\coupons"
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{00D0DBA9-CBDC-4E27-95BA-7C016949192B}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{011FC30A-7AF5-4629-BD01-DC325FF1AD6A}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{01A061BE-2F59-4393-B141-338F35D1284F}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{0258F904-D85F-4B5B-9213-06B42D04C8D1}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{03167E3E-4A2D-46BA-BE64-B6E698B662A5}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{0356D122-9763-4CC3-AB43-A8FEB7ED5D28}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{039D4FE4-ABFD-4061-8655-3997F20D9CA0}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{045BCF50-5323-401D-B72A-DC4D7CECE603}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{0625A2BF-3100-46EF-8755-D0CF357829F7}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{06650B29-215A-4707-B447-D20DE0CBD0CB}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{06DF88E4-73A5-46A0-AE6D-6CFF1620144B}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{080EFB03-48A1-42A5-8FDB-84021C41E09E}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{08D47ABA-5B34-4570-8818-755291C1E26D}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{09A6EA85-DF81-4850-BCA3-27D5A52BDF19}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{0CE15604-9003-4EBD-85B0-AFF45DD5F663}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{0EC4062A-E49E-421C-B1A8-154014B369FF}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{10FC4E71-E20D-453F-9A6B-76AFC2D14809}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{11761000-0B20-4E23-AA96-4AF4EFAD53AF}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{118060EE-6E19-4C75-8FE6-89B77320395D}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{1345FC47-CFD2-4C69-81D9-75999ACBFC79}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{1A72B0C9-49F4-4685-B203-832662F853A1}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{1D5AD227-E7F0-4769-A2CB-0505019EE90B}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{1F905BEC-D3FF-413B-8E15-B623F3B0AA7A}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{20A7F234-3044-45B3-B677-451CE1425185}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{20F8B148-C549-4B1C-9010-18253ADB1C4C}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{2609DDD1-FDEC-41DD-A18D-9454BF89572A}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{260B6821-8A22-4B41-81EA-F1A487CF4230}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{26AC5632-49DC-4F8E-AEBA-4FEB58E23F73}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{28E92ECE-368F-42CC-A49C-1EF778C00CEE}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{29FF216D-B087-4EC4-A12F-21F2278F252C}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{2A08342B-B37B-45D0-B30E-71FFD5982937}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{2A46F88D-59CA-4D19-9442-3B75251571F4}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{2C45CC20-163B-4ED2-AA25-955C3F446081}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{2D4B7D9A-CA4F-47F6-AB9A-9CC659222545}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{2EABD55D-BF23-4C6F-ACE9-30F9BF878C13}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{2F621156-CF8E-4F4F-96C9-6582CF91EA4F}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{2FC1CAE8-3A63-498C-B323-2ED6232940D0}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{2FF9AB27-8C0B-4EC2-8D91-DD29426ECDF3}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{3093D762-1445-412C-B593-40E22C214B0E}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{32B8D1BE-FBB7-4812-8C7E-B926436F68DE}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{33CD8A94-86A6-4BE5-BED4-44E6CA8E24A0}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{3470D410-8287-41DD-8858-D2715450DEFE}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{3866D18E-764D-4C82-8096-EFE6FFCC8F88}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{38B8DF04-4AD9-494E-9688-679EB3FEF2C6}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{3C91FA0D-5B27-4B0E-86A4-97FB16EBC506}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{3EF1AA74-5C90-4B46-8205-61FB3620C378}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{3F492A94-E8F1-456C-BAAB-5BE20A05C682}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{409DA5C4-851F-4FF0-BCB0-83AA8CA55F8F}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{4267CE57-9DF2-4BEC-A5C7-96AB520B5327}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{432B4AE2-FB3B-4AC7-BF7B-26D89A072F85}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{4347BB04-5425-44A6-A20D-CF44DC8DFD18}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{43FB1B5F-9C0A-4674-ABBE-E5A8901D82E4}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{459F15EB-504D-4877-9D08-96AAB4527BB3}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{45E2F2E6-1D88-41D7-B495-91A570C6158A}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{460FF9F5-4DE6-469E-9E98-ABF7E78564F1}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{4729D672-BFC5-4AF9-9FA6-FE0B1680A2D4}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{4A8314DB-B4B4-47D7-97F8-6552B910B9B8}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{4B310971-12E7-47F5-AE45-C487A89D8CFF}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{5319FD83-AD46-4E48-A3BB-3A7E40B79758}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{54D6CFFF-AAD3-43B5-8C80-425F0FD8624B}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{5676FDA7-673B-4909-8E22-7F44C9D17F75}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{5AFDC867-1E61-40E0-A5DD-C3A9A326D4BC}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{5C5DCF3B-8649-44E7-B6E1-C6E46127CA6F}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{5C798CFC-D216-4498-B65B-EE79D7B0B221}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{5CF7BD9F-604B-4E28-B4BC-97BB26BFE0C8}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{5E3B203C-EACC-4DC6-9712-2CA4974905E4}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{5F884972-B626-47D9-8AD1-80B98AD4DE05}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{6165F947-196D-49B3-A24B-C3287008B9CA}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{616BDA3B-9AD4-40E5-B038-BEF670E2555C}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{62E4A023-E67F-45B5-9D41-DB2C62442867}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{63AF0EA7-8734-4A33-AD7C-175BEF365B68}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{65436084-D2C7-490C-BBCB-F6F2A4BA0ABB}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{662004FC-4FF4-43C2-BB78-DC485AFA485F}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{673E247C-7B3D-4F48-B235-B04019B90C8D}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{68DA0EB6-F89B-4ACE-AA8B-2BE47FD5CF16}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{6A3EC824-AE92-4575-8004-82AF49A98CC1}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{6B84D43F-81EF-4210-B080-C3F1FB0C7504}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{6C1823FC-E942-4F72-94B2-49BF052F4711}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{6C8BECF4-33AE-4A34-9948-5FE6C68334E7}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{6DCD7B7B-6599-4EA4-A469-1B5CD5E3462E}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{6DD66517-E8F0-4A02-BBF7-70FE04A900FF}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{6EA90462-7C05-4F92-9D82-5EDDD9BEB668}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{70C2DAEE-D917-4868-B9FE-BB8B64E296A1}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{716BD8CD-441A-4C51-B199-AE356A71813C}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{71D8CC95-272E-476F-8CB2-4D654FBB7A03}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{725326D6-95F8-49AE-9852-EC2A06615CB8}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{735CCAC6-22AC-41ED-98B3-4890E51ADF8A}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{7395AEFE-A9CF-4987-83A5-C6317331D238}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{7528B9D7-1437-4E76-97C1-BA4C1C30FC0D}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{75F1D264-2689-4A11-9594-12E1CDCD8749}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{76C6BD5A-1512-4673-AB2D-EC9361DD0E9C}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{77B8506E-7AFA-4E5A-B08B-DC8C52FF09E7}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{77D4E7D7-DA54-4B92-B145-EE7E2949ED0F}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{785ED645-FE65-4946-9130-1BF013A4BF63}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{7979ED23-237E-4E0B-9FAA-387FEE085CB6}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{79C84DDB-61D0-412D-867F-9C886EB8B0FB}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{7BA46C08-3992-4DDD-A7A4-D842AF0ACD46}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{7C25CFE6-51ED-4B26-AE16-5308C69881AB}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{7C32BDF6-BB8B-45E6-B7CE-973582E626A9}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{7F345A9C-B49B-4100-8E26-E1FEBADD1C11}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{811D875A-F129-4023-BCAC-171428A24935}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{81441687-0458-4392-909C-0E70C3AB5677}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{8151253F-E1A6-4439-9EB4-5639E3D0F9F0}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{83108223-0BC6-48E6-B8C8-3EF602398EEF}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{84E9B196-A88B-459E-A022-1DBF386757BB}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{8991FCFE-41DB-4E61-AFE1-01796851CE2C}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{8BE4F0BE-A128-48F1-8278-EDE879004E24}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{8C5F4E16-0DF9-4D0F-ACA3-5B3F24692E78}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{8CC9B0F2-A0B6-450A-8CA5-0621A6164B81}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{8DB41484-F137-4A23-A7A5-1CC8DFE5533C}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{8ED702D4-DACB-477A-937F-AAA00CA8DDD4}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{8F783A31-F14C-4C73-955C-4A3075A272AB}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{908B0AC1-D045-4482-941B-F7CB14601B43}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{90ACC00F-EE20-4452-8127-6A72E8EB6C62}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{90F666BF-6E16-44AF-A52D-F7B24BB7D6B0}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{972017C7-4EEC-4D08-9127-C1BB95E8FFC1}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{98E81BDB-FD32-468C-9796-30D3E8409388}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{9A3EB79E-60E3-470B-ADD2-CFBE18E7AF4C}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{9A6A739C-5BCE-40DC-8135-57FE3C361899}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{9D2C351A-D0BD-4C1E-B667-2EFA81426ED9}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{9D75E958-5568-4A65-BD57-D1FA94FEC12D}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{9FE95FD1-3A5B-44BA-AC64-4A93B6BAA42E}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{A2310673-BB63-413B-99F1-76FB6788F28F}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{A2AD995E-61B6-4A87-8CB3-09EA3655730E}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{A409C34F-BFEF-421B-ADDF-E486AA9ACFB0}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{A4621F43-E2D5-4A28-8846-AE516AF5E941}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{A82A1C32-FD86-4C15-B3FA-B594E02323A7}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{A97C5A69-AC9B-44ED-8E2B-60F7E2478415}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{AA46F8F8-4D04-46E8-84BA-019D74DEAA72}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{AA837939-0CA2-4E49-B11F-D23B96E588F4}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{AA890B96-CABC-44A6-A71A-B1E674118D23}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{AAECB51A-6530-4A5A-A67B-DD9BE213C354}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{AC11D09E-7F6C-4F01-A72F-43C24EEA1484}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{AC56A7FF-7301-4F8F-889C-0DF842190358}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{AC5C04C9-560E-43FD-BB7F-1AB0EAA5E986}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{AD8132EF-D1B1-4143-925E-138C2BFE114F}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{B009AAEB-13CC-4868-82AE-FF705FDC3721}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{B1B58781-E25C-4938-9794-2A86DE9A1911}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{B1D038FF-4E79-4C2F-9660-520EBAF45504}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{B260D67A-7D62-426F-9DD0-236D9D2D9A12}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{B33E2588-A847-4626-AFC3-9472304F377C}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{B581029E-3B86-4380-8FAD-FFCCD1BC473F}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{B6C52E26-C921-4467-8CCB-E29EBD397C92}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{B72F9D86-7C12-40DF-A165-6D7E678CD071}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{B7B405DC-B41F-4A42-B41C-D6226EE640E1}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{B8C4B97B-B52B-4E78-B434-145FE4153B1B}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{B98066FC-F2FE-40F1-9FAE-51BC74710B67}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{B9DF747F-6CA0-4B02-90C4-F1308102BCA9}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{BB57C555-8372-4A0C-969B-0864633082DE}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{BD67A03F-BAC3-4EB6-AAFC-E2F3846BA76B}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{BE9B645A-7EC7-4D9A-8EC9-4DCA74A3310C}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{C05BFA97-41CA-4766-A179-6F39DDD1E1E2}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{C05C171C-1745-48DC-936C-5022DF6D65B4}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{C1A2B4FD-F5EC-4104-860C-7BD3795CF86C}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{C30958DF-5E79-434F-8055-09ADE30455F5}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{C3252C9E-E383-469B-9209-6EC3B4C07EB4}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{C7758D26-97E7-4B3A-9832-97C5016B7A90}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{C7F653BE-EC80-4E95-A448-141308081C6C}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{CAB94E2D-8BAC-4A18-B883-515B06A2ADEA}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{CC6A464C-B845-4048-B0FB-FA31C9A543B1}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{CDCFB745-6E12-4E10-806B-1B1834612402}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{CE06BE11-E9DF-4AAC-921B-B3DBB929B3E7}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{CF84341A-5A61-4FBA-8DA7-2DA1D9CA09C9}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{D145DB4E-22F0-4A0C-ADAC-BF23A0A762F4}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{D44EEA2D-DFF4-42B3-B8CB-1E3EA972C917}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{D56CF8BB-4C72-4867-8A7D-D7A381DA80A6}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{DC703D8F-E9A4-4AB3-B488-FA0E91DD5C2C}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{DC7599BA-8246-4637-B2BA-8BE0754EF6CC}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{DCFAB98A-4BF1-4807-8F81-EEFEEEB099A9}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{DDE78145-C703-4C0C-9CD8-96670197DC58}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{DE115AC6-6001-46F9-8C28-07D817417FDB}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{DEA4F16C-0AB7-4869-AB9E-82B1875A5306}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{DEDF8B6C-A09A-471C-BDB6-48A187C10E0C}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{E377831E-1805-40F6-B1F2-4DBEF346D61E}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{E3F62B36-1B6D-41F0-A13C-AE0956C3B686}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{E49339B1-A40F-4982-84D9-45166AF4E026}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{E4B01488-D19E-4CA9-87EF-E30508E92AAA}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{E4F3AD85-B8AA-4920-A339-72DA65972998}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{E5994258-81A6-4AD1-8AE7-A4BF5EB971FA}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{E5A1F331-3FB0-4E6E-99FC-80C06FFFDEF4}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{EB1F69B6-F3CB-4F22-8085-B9E6294DEDBF}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{EB2390C4-F656-4CE9-B149-BDEE9257F3F5}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{EBF27105-FFD0-4346-B8B4-15F0C4E8CDF5}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{ECA46C76-4EBC-4110-9C28-B855FFADBA98}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{EDB83316-A16C-4847-95F2-7415FE3512D3}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{EE6F50DD-5A2C-4404-AC30-1DE5FD6AADB1}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{F43B1A9C-34AE-4F69-B124-96CD714CF5AF}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{F51B8D51-2240-49FF-AB71-3932960F5065}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{F58FAA55-DA98-43CC-95D9-F8DB78BD5652}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{F5E3BB39-19B4-4EB4-8270-6F7BDB325172}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{F7588882-C661-4C2C-941A-4FC4817A7F59}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{FB18DF3D-D734-459B-89FD-2B6BB4478710}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{FED13143-7AB6-48E9-9229-D4026DBDFB55}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{FEDBDF14-AA05-47CF-8461-E7CF47B00912}
Successfully deleted: [Empty Folder] C:\Users\Jack\appdata\local\{FF958379-BFB1-4207-B924-C0D282FD4BE4}



~~~ FireFox

Emptied folder: C:\Users\Jack\AppData\Roaming\mozilla\firefox\profiles\cx8h17h4.default\minidumps [37 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sun 04/28/2013 at 13:13:13.55
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

OTL logfile created on: 4/28/2013 1:24:18 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jack\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.91 Gb Total Physical Memory | 2.20 Gb Available Physical Memory | 56.37% Memory free
9.77 Gb Paging File | 7.96 Gb Available in Paging File | 81.55% Paging File free
Paging file location(s): c:\pagefile.sys 6000 10000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 581.71 Gb Total Space | 460.25 Gb Free Space | 79.12% Space Free | Partition Type: NTFS

Computer Name: JACK-TOSHIBA | User Name: Jack | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Jack\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Users\Jack\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
PRC - C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe ()
PRC - C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe ()
PRC - C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoCast.exe (Motorola Mobility Inc.)
PRC - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe ()
PRC - C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe (Nero AG)
PRC - C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BBSvc.EXE (Microsoft Corporation.)
PRC - C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe (Motorola)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Toshiba\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files (x86)\Toshiba\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.6.22\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files (x86)\Mindjet\MindManager 7\MmReminderService.exe (Mindjet)


========== Modules (No Company Name) ==========

MOD - C:\Users\Jack\AppData\Local\Temp\WindowsAPI.dll6177680649104712172.lib ()
MOD - C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstvideoscale.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgsttypefindfunctions.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstvideobox.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstsmpte.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstvorbis.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstsubparse.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstwavpack.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstwavparse.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstvolume.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstvideocrop.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstvideorate.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgsty4menc.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflumpeg4video.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflumpeg2video.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstisomp4.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmatroska.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmpegdemux.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstogg.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflumpegdemux.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflv.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstjpeg.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmpegaudioparse.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmpegtsmux.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstgio.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstinterleave.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstreplaygain.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstid3tag.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstid3demux.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstgdp.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstpng.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmultipart.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmpegvideoparse.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmultifile.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstlevel.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmulaw.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstshift.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflump3enc.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflump3dec.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflummssrc.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflumch264enc.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflumcaacenc.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstfluh264dec.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstfluaacdec.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstfluasfdemux.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstffmpegcolorspace.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstdshowsrcwrapper.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflac.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstequalizer.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstcoreelements.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstavi.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstdshowdecwrapper.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstdecodebin2.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstaudioconvert.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstaudioresample.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstautoconvert.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstautodetect.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstaudiorate.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstamrnb.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstauparse.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstcutter.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstapetag.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstamrwbdec.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstcoreindexers.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libvorbisenc-2.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libxml2-2.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libwavpack-1.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\z.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstalpha.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstaiff.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstadder.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstalaw.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstalphacolor.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstadpcmdec.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\liborc-0.4-0.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libpng14-14.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libvorbis-0.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libopencore-amrwb.0.1.1.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstreamer-0.10.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libjpeg-8.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstbase-0.10.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libopencore-amrnb.0.1.1.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgsttag-0.10.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstcontroller-0.10.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstpbutils-0.10.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstrtp-0.10.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstinterfaces-0.10.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstriff-0.10.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstvideo-0.10.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libogg-0.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstdataprotocol-0.10.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstaudio-0.10.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libFLAC-8.dll ()
MOD - C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe ()
MOD - C:\Users\Jack\AppData\Local\Temp\sqlite-3.6.20-sqlitejdbc.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Mindjet\MindManager 7\zlib.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (TOSHIBA eco Utility Service) – C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
SRV:64bit: - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV:64bit: - (MyWiFiDHCPDNS) – C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV:64bit: - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV:64bit: - (TPCHSrv) – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TODDSrv) – C:\Windows\SysNative\TODDSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (Thpsrv) – C:\Windows\SysNative\ThpSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Motorola Device Manager) – C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe ()
SRV - (DeviceMonitorService) – C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe (Nero AG)
SRV - (BBUpdate) – C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (PST Service) – C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe (Motorola)
SRV - (TMachInfo) – C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (PCCUJobMgr) – C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.6.22\ccSvcHst.exe (Symantec Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\avgidsdrivera.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgloga) – C:\Windows\SysNative\drivers\avgloga.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSHA) – C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (motccgp) – C:\Windows\SysNative\drivers\motccgp.sys (Motorola Mobility Inc)
DRV:64bit: - (Motousbnet) – C:\Windows\SysNative\drivers\Motousbnet.sys (Motorola Mobility Inc)
DRV:64bit: - (MotoSwitchService) – C:\Windows\SysNative\drivers\motswch.sys (Motorola)
DRV:64bit: - (motmodem) – C:\Windows\SysNative\drivers\motmodem.sys (Motorola Mobility Inc)
DRV:64bit: - (Fs_Rec) – C:\windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (motccgpfl) – C:\Windows\SysNative\drivers\motccgpfl.sys (Motorola Mobility Inc)
DRV:64bit: - (motusbdevice) – C:\Windows\SysNative\drivers\motusbdevice.sys (Motorola Inc)
DRV:64bit: - (Point64) – C:\Windows\SysNative\drivers\point64.sys (Microsoft Corporation)
DRV:64bit: - (NuidFltr) – C:\Windows\SysNative\drivers\nuidfltr.sys (Microsoft Corporation)
DRV:64bit: - (dc3d) – C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (tos_sps64) – C:\Windows\SysNative\drivers\tos_sps64.sys (TOSHIBA Corporation)
DRV:64bit: - (JMCR) – C:\Windows\SysNative\drivers\jmcr.sys (JMicron Technology Corporation)
DRV:64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (NETwNs64) – C:\Windows\SysNative\drivers\NETwNs64.sys (Intel Corporation)
DRV:64bit: - (wdkmd) – C:\Windows\SysNative\drivers\WDKMD.sys (Intel Corporation)
DRV:64bit: - (MEIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (ivusb) – C:\Windows\SysNative\drivers\ivusb.sys (Initio Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (Tosrfusb) – C:\Windows\SysNative\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV:64bit: - (tosrfbd) – C:\Windows\SysNative\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV:64bit: - (TosRfSnd) – C:\Windows\SysNative\drivers\TosRfSnd.sys (TOSHIBA Corporation)
DRV:64bit: - (LPCFilter) – C:\Windows\SysNative\drivers\LPCFilter.sys (COMPAL ELECTRONIC INC.)
DRV:64bit: - (tdcmdpst) – C:\Windows\SysNative\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV:64bit: - (Tosrfcom) – C:\Windows\SysNative\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV:64bit: - (tosrfnds) – C:\Windows\SysNative\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV:64bit: - (TVALZ) – C:\Windows\SysNative\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (ROOTMODEM) – C:\Windows\SysNative\drivers\rootmdm.sys (Microsoft Corporation)
DRV:64bit: - (Thpevm) – C:\Windows\SysNative\drivers\Thpevm.sys (TOSHIBA Corporation)
DRV:64bit: - (Thpdrv) – C:\Windows\SysNative\drivers\thpdrv.sys (TOSHIBA Corporation)
DRV:64bit: - (PGEffect) – C:\Windows\SysNative\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV:64bit: - (TVALZFL) – C:\Windows\SysNative\drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV:64bit: - (Tosrfhid) – C:\Windows\SysNative\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV:64bit: - (tosrfbnp) – C:\Windows\SysNative\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV:64bit: - (tosporte) – C:\Windows\SysNative\drivers\tosporte.sys (TOSHIBA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (BTCFilterService) – C:\Windows\SysNative\drivers\motfilt.sys (Motorola Inc)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{7F0C8FE2-6CD8-4360-BCA7-4A7CB4CC6261}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSNF
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{D21E6F85-E9E6-4FE8-A3DB-0CBADAF49991}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSNF

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.toshiba.com/g/
IE - HKCU\..\SearchScopes,DefaultScope = {85B2C813-618E-4D99-9410-D1ABFC22378C}
IE - HKCU\..\SearchScopes\{85B2C813-618E-4D99-9410-D1ABFC22378C}: "URL" = http://www.google.com/search?sourceid=ie7&…1I7TSNF_enUS430
IE - HKCU\..\SearchScopes\{D21E6F85-E9E6-4FE8-A3DB-0CBADAF49991}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSNF
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local;192.168.*.*

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: 2020Player_WEB%402020Technologies.com:[removed]
FF - prefs.js..extensions.enabledAddons: amznUWL2%40amazon.com:1.10
FF - prefs.js..extensions.enabledAddons: foxmarks%40kei.com:4.1.3
FF - prefs.js..extensions.enabledAddons: support%40lastpass.com:2.0.20
FF - prefs.js..extensions.enabledAddons: %7B37fa1426-b82d-11db-8314-0800200c9a66%7D:3.3
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - prefs.js..extensions.enabledItems: [removed]:3.9.9
FF - prefs.js..extensions.enabledItems: [removed]:1.5
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_7_700_169.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Jack\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Jack\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/04/16 21:24:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/04/28 13:10:23 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/04/16 21:24:17 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/04/28 13:10:23 | 000,000,000 | —D | M]

[2011/05/06 23:12:12 | 000,000,000 | —D | M] (No name found) – C:\Users\Jack\AppData\Roaming\Mozilla\Extensions
[2013/04/27 08:27:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\cx8h17h4.default\extensions
[2012/09/30 18:57:52 | 000,000,000 | —D | M] (20-20 3D Viewer - WEB) – C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\cx8h17h4.default\extensions\[removed]
[2012/10/12 10:57:29 | 000,000,000 | —D | M] ("Xmarks") – C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\cx8h17h4.default\extensions\[removed]
[2013/04/27 08:27:47 | 000,000,000 | —D | M] (LastPass) – C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\cx8h17h4.default\extensions\[removed]
[2012/09/27 23:30:31 | 000,243,287 | —- | M] () (No name found) – C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\cx8h17h4.default\extensions\[removed]
[2013/04/27 08:27:40 | 000,223,761 | —- | M] () (No name found) – C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\cx8h17h4.default\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}.xpi
[2011/05/24 06:43:15 | 000,001,635 | —- | M] () – C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\cx8h17h4.default\searchplugins\firefox-add-ons.xml
[2011/05/24 06:44:06 | 000,001,504 | —- | M] () – C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\cx8h17h4.default\searchplugins\imdb.xml
[2011/05/24 06:43:47 | 000,004,140 | —- | M] () – C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\cx8h17h4.default\searchplugins\youtube.xml
[2013/04/16 21:24:05 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/04/16 21:24:17 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/10/03 05:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012/09/21 21:37:58 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013/03/02 15:30:04 | 000,002,086 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Search the web (Babylon) (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\plugins/avgnpss.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll File not found
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\Toshiba\TOSHIBA Media Controller Plug-in\x64\TOSHIBAMediaControllerIE.dll (TOSHIBA Corporation)
O2 - BHO: (CmjBrowserHelperObject Object) - {07A11D74-9D25-4fea-A833-8B0D76A5577A} - C:\Program Files (x86)\Mindjet\MindManager 7\Mm7InternetExplorer.dll (Mindjet)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll File not found
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\Toshiba\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (TOSHIBA Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [ThpSrv] C:\windows\SysNative\thpsrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosNC] C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [KeNotify] C:\Program Files (x86)\Toshiba\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [MMReminderService] C:\Program Files (x86)\Mindjet\MindManager 7\MmReminderService.exe (Mindjet)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe (Toshiba)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [ToshibaAppPlace] C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe (Toshiba)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKCU..\Run: [HP Officejet Pro 8600 (NET)] C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - HKCU..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe File not found
O4 - HKCU..\Run: [MotoCast] C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk ()
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\Jack\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKCU..\Run: [uTorrent] C:\Users\Jack\Downloads\utorrent.exe (BitTorrent, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8:64bit: - Extra context menu item: Add to TOSHIBA Bulletin Board - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll (TODO: <会社名>)
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: Add to TOSHIBA Bulletin Board - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll (TODO: <会社名>)
O9:64bit: - Extra Button: Add to TOSHIBA Bulletin Board - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom64.dll (TODO: <会社名>)
O9:64bit: - Extra 'Tools' menuitem : Add to TOSHIBA Bulletin Board - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom64.dll (TODO: <会社名>)
O9 - Extra Button: Send to Mindjet MindManager - {941E1A34-C6AF-4baa-A973-224F9C3E04BF} - C:\Program Files (x86)\Mindjet\MindManager 7\Mm7InternetExplorer.dll (Mindjet)
O9 - Extra Button: Add to TOSHIBA Bulletin Board - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll (TODO: <会社名>)
O9 - Extra 'Tools' menuitem : Add to TOSHIBA Bulletin Board - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll (TODO: <会社名>)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.7.2)
O16 - DPF: {2AB1C516-D654-4D3A-B3D6-2185BBCEB409} https://webvpn.na.aecom.com/+CSCOL+/relayp.cab (Cisco Systems WebVPN Relay Loader)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BA20463F-FDCE-493E-A9D1-A7D25C2DF232}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll File not found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll File not found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/04/28 13:02:37 | 000,000,000 | —D | C] – C:\windows\ERUNT
[2013/04/28 13:02:33 | 000,000,000 | —D | C] – C:\JRT
[2013/04/28 13:00:47 | 000,536,737 | —- | C] (Oleg N. Scherbakov) – C:\Users\Jack\Desktop\JRT.exe
[2013/04/27 08:31:31 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Jack\Desktop\OTL.exe
[2013/04/26 15:59:08 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2013/04/23 23:30:17 | 000,000,000 | —D | C] – C:\Users\Jack\Documents\Business
[2013/04/20 18:45:42 | 000,000,000 | —D | C] – C:\Users\Jack\Documents\3824 Sharp St
[2013/04/20 18:24:35 | 000,000,000 | —D | C] – C:\Users\Jack\Documents\Work Bench Plans
[2013/04/16 21:24:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/04/16 21:00:59 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\mshtmled.dll
[2013/04/16 21:00:58 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\mshtmled.dll
[2013/04/16 21:00:57 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieui.dll
[2013/04/16 21:00:56 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\inetcpl.cpl
[2013/04/16 21:00:56 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\inetcpl.cpl
[2013/04/16 21:00:56 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieui.dll
[2013/04/16 21:00:56 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\url.dll
[2013/04/16 21:00:56 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\url.dll
[2013/04/16 21:00:56 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieUnatt.exe
[2013/04/16 21:00:56 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieUnatt.exe
[2013/04/16 21:00:55 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\jscript9.dll
[2013/04/16 21:00:55 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\msfeeds.dll
[2013/04/16 21:00:53 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\jscript.dll
[2013/04/16 21:00:53 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\jscript.dll
[2013/04/16 21:00:53 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\vbscript.dll
[2013/04/14 17:29:56 | 003,717,632 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\mstscax.dll
[2013/04/14 17:29:55 | 003,217,408 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\mstscax.dll
[2013/04/14 17:29:54 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\aaclient.dll
[2013/04/14 17:29:54 | 000,131,584 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\aaclient.dll
[2013/04/14 17:29:54 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\tsgqec.dll
[2013/04/14 17:29:54 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\tsgqec.dll
[2013/04/14 17:29:40 | 005,550,424 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ntoskrnl.exe
[2013/04/14 17:29:37 | 003,968,856 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntkrnlpa.exe
[2013/04/14 17:29:37 | 003,913,560 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntoskrnl.exe
[2013/04/14 17:29:36 | 000,112,640 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\smss.exe
[2013/04/14 17:29:36 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\csrsrv.dll
[2013/04/14 17:29:36 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\apisetschema.dll
[2013/04/08 00:05:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2013/03/31 19:35:19 | 000,000,000 | —D | C] – C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2013/03/31 19:14:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis
[2013/03/31 19:14:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2013/03/31 19:14:09 | 000,812,344 | —- | C] (Trend Micro Inc.) – C:\Users\Jack\Desktop\HJTInstall.exe
[2013/03/31 17:42:02 | 000,000,000 | —D | C] – C:\Users\Jack\AppData\Roaming\2BrightSparks
[2013/03/31 17:41:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\2BrightSparks
[2013/03/31 17:41:40 | 000,000,000 | —D | C] – C:\Users\Jack\AppData\Local\2BrightSparks
[2013/03/31 17:41:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\2BrightSparks
[2013/03/30 10:35:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013/03/30 10:32:58 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2013/03/30 10:32:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2 C:\windows\SysWow64\*.tmp files -> C:\windows\SysWow64\*.tmp -> ]
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/04/28 13:25:12 | 000,016,304 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/04/28 13:25:12 | 000,016,304 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/04/28 13:22:00 | 000,000,830 | —- | M] () – C:\windows\tasks\Adobe Flash Player Updater.job
[2013/04/28 13:21:06 | 000,726,444 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2013/04/28 13:21:06 | 000,624,412 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2013/04/28 13:21:06 | 000,106,756 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2013/04/28 13:18:36 | 000,001,930 | —- | M] () – C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Officejet Pro 8600 (Network).lnk
[2013/04/28 13:17:22 | 000,000,908 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/04/28 13:16:43 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2013/04/28 13:16:41 | 3147,841,536 | -HS- | M] () – C:\hiberfil.sys
[2013/04/28 13:06:00 | 000,000,904 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3671255274-3908056842-1801094870-1001UA.job
[2013/04/28 13:00:47 | 000,536,737 | —- | M] (Oleg N. Scherbakov) – C:\Users\Jack\Desktop\JRT.exe
[2013/04/28 12:43:31 | 000,628,743 | —- | M] () – C:\Users\Jack\Desktop\AdwCleaner.exe
[2013/04/28 12:37:00 | 000,000,912 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/04/28 10:56:16 | 000,000,852 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3671255274-3908056842-1801094870-1001Core.job
[2013/04/27 09:18:17 | 000,145,691 | —- | M] () – C:\Users\Jack\Desktop\Are you Infected_ Need Help_.pdf
[2013/04/27 08:32:01 | 000,001,124 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/04/27 08:31:32 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Jack\Desktop\OTL.exe
[2013/04/20 18:12:42 | 000,001,236 | —- | M] () – C:\Users\Jack\Desktop\SyncBackFree.lnk
[2013/04/18 22:51:33 | 000,691,592 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerApp.exe
[2013/04/18 22:51:33 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/04/18 22:48:36 | 000,002,059 | —- | M] () – C:\Users\Jack\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/04/16 21:28:04 | 000,417,712 | —- | M] () – C:\windows\SysNative\FNTCACHE.DAT
[2013/04/08 00:05:37 | 000,001,081 | —- | M] () – C:\Users\Public\Desktop\VLC media player.lnk
[2013/04/07 21:03:18 | 000,000,976 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/04/04 14:50:32 | 000,025,928 | —- | M] (Malwarebytes Corporation) – C:\windows\SysNative\drivers\mbam.sys
[2013/03/31 23:40:06 | 000,004,074 | —- | M] () – C:\Users\Jack\Documents\TapoutCalendar.csv
[2013/03/31 19:35:19 | 000,002,971 | —- | M] () – C:\Users\Jack\Desktop\HiJackThis.lnk
[2013/03/31 19:33:59 | 001,402,880 | —- | M] () – C:\Users\Jack\Desktop\HiJackThis.msi
[2013/03/31 19:14:11 | 000,812,344 | —- | M] (Trend Micro Inc.) – C:\Users\Jack\Desktop\HJTInstall.exe
[2013/03/31 18:33:55 | 000,001,079 | —- | M] () – C:\Users\Jack\Desktop\ChromePlus.lnk
[2013/03/30 15:51:14 | 000,001,030 | —- | M] () – C:\Users\Jack\Desktop\Dropbox.lnk
[2 C:\windows\SysWow64\*.tmp files -> C:\windows\SysWow64\*.tmp -> ]
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/04/28 12:43:31 | 000,628,743 | —- | C] () – C:\Users\Jack\Desktop\AdwCleaner.exe
[2013/04/27 09:18:11 | 000,145,691 | —- | C] () – C:\Users\Jack\Desktop\Are you Infected_ Need Help_.pdf
[2013/04/08 00:05:37 | 000,001,081 | —- | C] () – C:\Users\Public\Desktop\VLC media player.lnk
[2013/03/31 19:33:57 | 001,402,880 | —- | C] () – C:\Users\Jack\Desktop\HiJackThis.msi
[2013/03/31 19:14:25 | 000,002,971 | —- | C] () – C:\Users\Jack\Desktop\HiJackThis.lnk
[2013/03/31 18:20:32 | 000,001,124 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/03/31 17:41:45 | 000,001,236 | —- | C] () – C:\Users\Jack\Desktop\SyncBackFree.lnk
[2012/12/23 23:04:40 | 000,001,445 | —- | C] () – C:\Users\Jack\.recently-used.xbel
[2012/12/03 00:36:14 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2012/08/05 10:17:43 | 000,256,000 | —- | C] () – C:\windows\PEV.exe
[2012/08/05 10:17:43 | 000,208,896 | —- | C] () – C:\windows\MBR.exe
[2012/08/05 10:17:43 | 000,098,816 | —- | C] () – C:\windows\sed.exe
[2012/08/05 10:17:43 | 000,080,412 | —- | C] () – C:\windows\grep.exe
[2012/08/05 10:17:43 | 000,068,096 | —- | C] () – C:\windows\zip.exe

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 01:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 00:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\SysWow64\wbem\wbemess.dll

========== LOP Check ==========

[2013/03/31 17:42:02 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\2BrightSparks
[2012/12/16 21:57:03 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\AVG2013
[2011/08/26 10:41:30 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\Bentley
[2011/06/26 20:21:12 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\Book Place
[2013/03/31 18:38:19 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\ChromePlus
[2013/04/27 22:41:25 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\Dropbox
[2012/12/23 22:56:25 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\gtk-2.0
[2012/09/27 23:20:08 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\HandBrake
[2012/12/31 10:17:05 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\MediaMonkey
[2013/04/28 13:20:07 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\MotoCast
[2011/12/26 23:06:48 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\Motorola
[2012/08/10 20:59:33 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\Motorola Mobility
[2012/09/22 10:56:02 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\NASNaviator2
[2013/02/08 00:52:31 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\Spotify
[2012/10/28 19:09:03 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\SysDev Laboratories
[2011/05/02 23:31:46 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\Tific
[2012/04/14 23:10:45 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\Toshiba
[2012/12/16 21:54:54 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\TuneUp Software
[2013/04/28 12:36:49 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\uTorrent
[2011/05/02 23:22:27 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\WinBatch
[2012/03/26 23:54:10 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\WinTR-55

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 829 bytes -> C:\Users\Jack\Documents\Adobe v8.0 - Your Serial Numbers.eml:OECustomProperty

< End of report >
Hi Jaclyn,

Run OTL.exe
Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local;192.168.*.*
    CHR - default_search_provider: Search the web (Babylon) (Enabled)
    O4 - HKCU..\Run: [uTorrent] C:\Users\Jack\Downloads\utorrent.exe (BitTorrent, Inc.)
    [2013/04/28 12:36:49 | 000,000,000 | —D | M] – C:\Users\Jack\AppData\Roaming\uTorrent
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
- - - - - Next - - - - -

Set your default search engine in Chrome
  • Click the Chrome menu [external image: Posted Image] on the browser toolbar.
  • Select Settings
  • In the "Search" section, select the search engine you want to use from the menu. If the search engine you want to use doesn't appear in the menu, click Manage search engines.
  • In the Search Engines dialog that appears, select the search engine that you'd like to use from the list.
  • Click the Make Default button that appears in the row.
If the search engine you want to use isn't on this list, you can first add it as a new search engine option.

If the "Make Default" button doesn't appear for the search engine you've selected, you may need to edit its URL.

In your next post please provide the following:
  • OTL.txt
  • How is the computer running?
  • Any remaining issues?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI