This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slowing and skipping [Solved]

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Just in the last two days, my laptop has started slowing down to near inoperable levels, skipping audio and video, and sometimes inactive windows bleed through. I want to rule out standard software issues before doing a complete restore. Thanks, as always , for your help!

OTL Extras logfile created on: 5/21/2013 8:57:34 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Joshua\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.93 Gb Total Physical Memory | 0.69 Gb Available Physical Memory | 23.51% Memory free
5.86 Gb Paging File | 2.56 Gb Available in Paging File | 43.73% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 283.84 Gb Total Space | 7.15 Gb Free Space | 2.52% Space Free | Partition Type: NTFS
Drive D: | 13.95 Gb Total Space | 2.31 Gb Free Space | 16.54% Space Free | Partition Type: NTFS
Drive E: | 99.34 Mb Total Space | 95.24 Mb Free Space | 95.88% Space Free | Partition Type: FAT32
Drive F: | 7.70 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive G: | 3.77 Gb Total Space | 3.48 Gb Free Space | 92.49% Space Free | Partition Type: FAT32

Computer Name: JOSHUA-PC | User Name: Joshua | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] – "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0523A8F3-3C7C-4A50-8C52-09BC0A83E7C2}" = rport=139 | protocol=6 | dir=out | app=system |
"{0F426E95-039A-42E6-A2F4-6107C26308BA}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{15A10746-20BF-44BC-89E5-232AE697E9B4}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{1A51B81B-06D7-4D16-BF7F-BCC8E44A8D77}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{1BCAA51D-BF64-43C6-A3BF-785388919863}" = lport=137 | protocol=17 | dir=in | app=system |
"{1F3C36DC-2E1A-48E6-9C8E-EDA75B1A95EE}" = rport=445 | protocol=6 | dir=out | app=system |
"{2254C260-DA48-4370-97DF-ADF280DEAD2A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{35E3E69B-EA49-4EE3-BEEC-5E5B54504DF7}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{3DE5D356-CC9F-4D13-9434-5389B202ED9A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{4189E4B2-3075-4D71-8FBA-746DF3454A2E}" = rport=137 | protocol=17 | dir=out | app=system |
"{4840643F-E43C-4C04-B962-D5A61724CD68}" = lport=445 | protocol=6 | dir=in | app=system |
"{66740C8F-C587-4C37-88D3-F73FC10D74A8}" = lport=139 | protocol=6 | dir=in | app=system |
"{6DAFC3B2-F640-4FC4-9D13-0BC4F5F0CE0E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{9488A42A-EEE0-4DD8-8E13-A3591D3ACFDB}" = lport=2869 | protocol=6 | dir=in | app=system |
"{988495F4-F5CF-4C0E-970C-3B9145E1FB0C}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{9AEF8F1F-9A4E-4E13-AB2C-748A27D408D8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A1343C0B-8743-4E36-9561-880D8D59C08D}" = rport=138 | protocol=17 | dir=out | app=system |
"{A425EB3B-C933-4884-9F19-3EAF9BA2B2F3}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A4669AB0-B9CF-4EDD-ACC8-982617398699}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A83BCCAF-0D00-4637-8D20-E49426F6E4DD}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{A8CB9F0E-6FB1-47F6-AC60-431772F42FE4}" = lport=10243 | protocol=6 | dir=in | app=system |
"{BBEF2A7B-BFD4-4CB9-801E-006844320F5B}" = lport=138 | protocol=17 | dir=in | app=system |
"{BD17B062-BD89-4BDE-8A2D-96D0A9C3D760}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{BF0CF5F1-F804-456D-A21F-AC3948C82906}" = lport=5432 | protocol=6 | dir=in | name=postgres |
"{E01CBE59-284C-4A16-8E96-276EFE633480}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E17F4EA9-FB50-4C7B-A7FC-2A7608DDB0A6}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{E7B996A9-D776-4B76-9247-8BBD361EF28E}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{E940E5F1-0E7C-4026-AB69-B4B7CE3F8E5D}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{F5CF4D19-AFDC-4BDE-8849-F1B0CC6E8E01}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{F5EC3300-3D16-4ADA-9A73-CCAA1528C369}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FBFEB2AF-195A-4217-836B-36F4FD8DFB82}" = rport=10243 | protocol=6 | dir=out | app=system |
"{FD567062-8632-45DC-B3EE-0036B086872F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{011FA9A3-E45C-4C6B-9054-2CBA5EFD1EDE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\a valley without wind 2\valley2.exe |
"{0125E353-F6FF-49BC-A1C1-7E1148719058}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\breath of death vii\bodviipc.exe |
"{01535D0C-116B-429A-9DFF-CEBA717B0A64}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v\launcher.exe |
"{01EB9EB5-D807-4CF3-ACC0-43C1AE9C354A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\altitude\altitude.exe |
"{02DE61AB-6E7A-4379-9D4C-93FF2EA54D01}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\patrician iv\patrician4.exe |
"{0361FFAE-5977-4A47-BD7B-2AC1D5011B92}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeons of dredmor\dungeons of dredmor.exe |
"{03C20CDB-1761-4CC2-A89D-BB96911911C7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\a valley without wind\avww.exe |
"{0537CF72-838A-4977-ABA9-9AE890E12C0A}" = protocol=17 | dir=in | app=c:\program files (x86)\tango\tango.exe |
"{07B26955-6306-489A-A7FF-8BEA22A85202}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\king's bounty - the legend\save_fixer.exe |
"{07C3F52E-BFD4-49EA-BC2A-657F699B543B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deadpixels\dead pixels launcher.exe |
"{0865F7AE-EE1F-433B-9AB5-7FB21732B3CD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\just cause 2\justcause2.exe |
"{08B91D83-5D56-49F2-8EC7-044D2107878E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\audiosurf\engine\questviewer.exe |
"{0926AFD6-2CD1-4BCE-9837-820CCA2572A5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\torchlight2.exe |
"{0963920A-B64F-4305-8AB5-B1E944280B4E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rome total war gold\rometw.exe |
"{0C2A01A0-9773-452D-80FC-2CD1A4B41F61}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight\torchlight.exe |
"{0D6517A5-F1A3-4FFE-BCAA-483301802CEF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\cave story+\cavestory+.exe |
"{0DB65395-9E86-4C2C-9309-7D51457BBBC4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the binding of isaac\isaac.exe |
"{0E36C6D9-CD39-4C04-BE20-9C7181F982F3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\beat hazard\runme.exe |
"{0EC6E5AD-47CD-4C79-B8C6-1CB770C93E1D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\altitude\altitude.exe |
"{0F081786-FD72-4969-9BEA-6A6B5E04665E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\cthulhu saves the world\cstw.exe |
"{0FAA85CE-BFE8-421A-8165-62F2CB9FDD6F}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpdevicedetection3.exe |
"{103C0BD9-D489-422B-ACB9-B67FB1A59848}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\shatter\shatter.exe |
"{13303544-1201-4036-88CD-E1D6892A6781}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\half minute hero\hmh.exe |
"{13754276-693A-4550-9F17-019EFB6EE3AB}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{14C18923-AFCE-4283-96D6-618625BDC9E2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\command and conquer red alert 3\runme.exe |
"{14DD5B82-08BD-4BC4-9EEC-9FA08551907E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\and yet it moves\and yet it moves.exe |
"{1508B0BC-3B05-4384-AAFB-06001F514F85}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\cogs\cogs.exe |
"{18A5C3B3-C551-420A-BB15-D66D2774DE73}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\to the moon\to the moon\to the moon.exe |
"{19B43CEB-588A-4058-9CA1-CAE5A9076761}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher enhanced edition\system\witcher.exe |
"{1A7559C9-0115-4440-A868-4327397E28B6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\puzzlequest2\puzzlequest2.exe |
"{1BB5A795-C473-44E1-9B42-F5DF5DF10F25}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spellforce 2 gold edition\spellforce2.exe |
"{1C8DB511-2A74-4F7F-ABC8-CB37D3158DC9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tidalis\tidalis.exe |
"{1CCC6B09-C724-4881-B369-66BD0B49187B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\darksiders\darksiderspc.exe |
"{1EA1FD00-8ED3-4F96-A6B7-04F1820F872A}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpwarrantychecker.exe |
"{203C1027-1075-492E-AD14-EF4303BB04F0}" = protocol=6 | dir=in | app=c:\program files (x86)\atari\neverwinter nights 2\nwn2server.exe |
"{205F0E3B-4071-44AE-B499-79CFCA65A6AC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{208C4A43-7C34-4B96-B609-7AAC4E8F9C56}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{20C36ACF-0D6A-4014-A6C5-B972C93FCF17}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\commandos 2 men of courage\comm2.exe |
"{24692CF7-499E-4483-AC49-C7F3FFE2F53C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bit.trip runner\runner.exe |
"{24830DA4-39CA-440A-AA21-56A8FEE888F5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dangerous high school girls in trouble\prog\brigiton.exe |
"{24AA76D6-C0C3-4688-8CC6-607840809844}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\swkotor\swkotor.exe |
"{24B19B9E-18BB-4926-A128-BB68813E0086}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{260309B1-B641-454B-B7A1-83EBA42F11C7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warlock - master of the arcane\game.exe |
"{26C1010B-05FE-4248-99F8-23EC72582F19}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\modlauncher.exe |
"{276D447A-C5B4-4660-9042-F7319CF743DF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{28825105-227D-49E4-B5AB-07E8EB122219}" = protocol=17 | dir=in | app=c:\program files (x86)\expressfiles\expressdl.exe |
"{289324A8-1D22-40B4-956F-AD2741AD1F8E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction armageddon\rf4_launcher.exe |
"{28EA50F1-3660-4D33-81EE-583DEF4F2B26}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\depths of peril\depthsofperil.exe |
"{290EBCF8-D393-40EC-9020-24487A8DD7D7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\commandos 2 men of courage\comm2.exe |
"{2A2FF3BD-342C-44F8-8AAC-85F2AAFC468B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{2B688FC5-45F2-4973-A00B-695DEB9F818B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\knights of the old republic ii\swkotor2.exe |
"{2C087948-6241-4319-A877-F2F2EB896CBC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\divine_divinity\div.exe |
"{2CEDE6BF-9648-4E62-B219-40C336C64D7A}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{2CFA487C-A425-4570-83F2-C8ABD61D1C8E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\freedom force\fforce.exe |
"{2E29E800-1C85-49EA-998E-108C928BC277}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\age of empires 3\bin\age3.exe |
"{2E76CF7C-3C72-4D11-875A-F7B3746AA336}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{2EDB8039-1D57-46B0-BF8E-5B7ED26C41C0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout 2\fallout2.exe |
"{2F72B9DD-26B1-49E6-B3D4-1CA19B77A1F7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\darksiders\darksiderspc.exe |
"{3005D80C-E858-46B0-A71B-2BAE55F26C89}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{3058DECC-01DE-4BE3-ABA8-4295EE332862}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ftl faster than light\ftlgame.exe |
"{306DF7F2-0C27-4BB4-83EC-069E8C00B1DF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\king's bounty - the legend\kb.exe |
"{311D1C95-4B05-47E3-BEA9-EDF8BA3416A1}" = protocol=17 | dir=in | app=c:\program files (x86)\atari\neverwinter nights 2\nwn2main.exe |
"{318BD373-4920-491D-ADDF-753F676AC9B3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\shatter\shattersettingseditor.exe |
"{3213396E-ECA1-4C67-9002-2729F64C37B4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{324B1058-7765-448B-8DF0-AA1575C1304C}" = protocol=6 | dir=in | app=c:\program files (x86)\atari\neverwinter nights 2\nwn2main_amdxp.exe |
"{333A3707-7DA5-4816-A684-383B86941E45}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the sims 3\game\bin\sims3launcher.exe |
"{33C84DC2-0047-4EA3-A329-9BB3A4687763}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{3436F1B8-20FE-4054-A44A-F31838773813}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout\falloutw.exe |
"{35808A6D-B0F5-46BC-B302-0249381D7EEB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\breath of death vii\bodviipc.exe |
"{36325B20-6ADE-4552-8906-B612A976CF8B}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{3716DB5B-85A2-4023-B3D1-736A9DAF007A}" = protocol=17 | dir=in | app=c:\program files (x86)\atari\neverwinter nights 2\nwn2server.exe |
"{372C833A-B34A-4D42-9518-768D62F03952}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout tactics\ft tools.exe |
"{37F419DC-B9C2-4F04-98E1-9B64197E43EA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ftl faster than light\ftlgame.exe |
"{38412A84-AD3C-4865-947F-A4F0B6B70742}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\defcon\defcon.exe |
"{3855B6A2-C7E9-48DE-A185-45297F868F1F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\costume quest\cq.exe |
"{387C6548-2762-41CA-A648-AC07450921AC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wormsgolf2010\wormscrazygolf.exe |
"{39AAAF98-CAE7-4A83-8633-A5383DC7E7D4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\runespelloverture\runespell.exe |
"{3ADE2E5D-309A-4B4B-B879-A15270C94641}" = protocol=17 | dir=in | app=c:\program files (x86)\expressfiles\expressfiles.exe |
"{3B003D52-09F2-43A6-A8C9-C229753EEBF9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\age of empires 3\bin\age3x.exe |
"{3B326D7E-4075-4D77-BB93-1B94BE1ABE66}" = protocol=6 | dir=in | app=c:\program files (x86)\tango\tango.exe |
"{3B92943A-E59A-4EB4-9E43-AB34DA8E30EA}" = protocol=6 | dir=in | app=c:\program files (x86)\expressfiles\expressfiles.exe |
"{3BF50909-A1C2-4463-8F06-83CD3747C35D}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{3C4F9FD4-80F3-47E7-807D-3BC200E65C2F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\shank\bin\shank.exe |
"{3CA9BFEC-4B31-4A3A-B19B-696061FD01A6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\shatter\shattersettingseditor.exe |
"{3D6FBD1D-4FF9-4114-89F1-B2844EA8082A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\and yet it moves\and yet it moves.exe |
"{3D8E885D-909F-4EA3-89A6-E1B68D2831EB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\command and conquer red alert 3\support\ea help\electronic_arts_technical_support.htm |
"{3D90BED3-457E-47ED-ADBE-CDEADDA8220A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warlock - master of the arcane\support\paradox.url |
"{40F46230-AAEA-4635-BE45-4CE201F895D3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v\launcher.exe |
"{41650341-DFAB-4349-B00C-633E8E288A2B}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{43C0CA01-0962-470A-9002-25CB5645ACF1}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{4405C54F-5A43-41A8-832C-88DB28092A93}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rome total war gold\rometw.exe |
"{445896A4-8EF7-4580-93EF-A14BC3EF6874}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alpha protocol\aplauncher.exe |
"{44CF982F-A6E0-4409-A0CE-46AAD9270799}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ys origin\config.exe |
"{4592892B-20CB-4E74-A3A6-431D39A62BD4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\men of war\mow_editor.exe |
"{46C8DAB9-F526-4DF9-98F0-48E70A7AC690}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{47C56BAA-EDF0-4230-B85E-63143221243C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\cthulhu saves the world\cstw.exe |
"{48652A29-F49B-4A25-AF38-F1B130503376}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\vvvvvv\vvvvvv.exe |
"{48B69E67-F607-4C65-896D-2682CA5738E6}" = protocol=6 | dir=in | app=c:\program files (x86)\expressfiles\expressdl.exe |
"{4B7746D5-5372-4467-A195-FF2E88D8D004}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\might and magic clash of heroes\clashofheroes.exe |
"{4B90EC41-A262-413C-82C2-EEAB1FE13D72}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{4BB947CC-E93F-4769-A4F4-4B067C6B4A07}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{4BC9F928-3DF7-4F2B-B30C-E3DE124AD6BB}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{4C09F45F-9310-48BD-817A-BE3578FB9189}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spellforce platinum edition\spellforce.exe |
"{4E18FC2D-F9F6-4BBE-9F5F-FBAD389EE26D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex - human revolution\dxhr.exe |
"{506E99B0-CD8F-4116-AB81-F24AFE05F0F0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout tactics\bos.exe |
"{50BFBA15-4D85-4774-99D9-4237228A033D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terraria.exe |
"{51CAD59E-3100-4FC5-86E4-FAA0A4435CED}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mark_of_the_ninja\bin\game.exe |
"{5307637E-506D-4A79-9848-799F5B004D9B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\cave story+\cavestory+.exe |
"{533934B2-5F92-4B08-9D0D-78D589DCBEF8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect\docs\ea help\electronic_arts_technical_support.htm |
"{548A3081-55A9-451C-9409-3D6A29ED856A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\altitude\altitude.exe |
"{5558CA6A-68D0-4715-BAE4-FF0503FFB742}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\a valley without wind\avww.exe |
"{55770764-8474-461B-B37E-7E47769F3DFE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\costume quest\cq.exe |
"{5692499A-E9D0-45F6-8704-B978D2CA01BF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the political machine 2012\polmachine2012.exe |
"{570E62AC-EDF1-47A9-8A79-499B17E1A0B5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\defcon\defcon.exe |
"{578D849A-6344-4450-940E-FC24A0A2EEB3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{57D6D6F6-1BE8-471C-B11D-BA2A84083423}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{57E9CAD0-DF95-4A4B-A000-A14F05FD7E27}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spellforce 2 gold edition\spellforce2.exe |
"{58B3FF26-0C6C-458C-8D61-33EF21067AE2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\peggle nights\pegglenights.exe |
"{5A7E8A4D-0C63-4EBB-86E2-1F7E3D2D034E}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{5B6102C1-9911-48EE-ABA2-87173D66DE4C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\nation red\nationred.exe |
"{5C3B3669-B6FD-4E4D-B045-DA67BB616A99}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warlock - master of the arcane\support\paradox.url |
"{5D0B0954-F1A1-4663-9F98-E49339866490}" = protocol=6 | dir=in | app=c:\program files (x86)\atari\neverwinter nights 2\nwupdate.exe |
"{5D135CE5-524D-4FEA-B27F-D95491F14A3A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\europa universalis iii - complete\eu3game.exe |
"{5D502254-AE90-4DB7-9D33-469B534C1014}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\10000000\10000000.exe |
"{5F514170-FC3B-4DE7-B87F-DF022691ABF3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\europa universalis iii - complete\eu3game.exe |
"{61FA15BB-CA8C-4B93-95D0-A20C9BC84405}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon hearts\dungeonhearts.exe |
"{63DB18D1-BA93-42CE-B550-643A91D26F02}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{644BA253-13AA-4C32-A842-D8A60E61685A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warlock - master of the arcane\support\game.url |
"{651E78A4-96DE-4EED-849D-2087D7A1C920}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\might and magic clash of heroes\clashofheroes.exe |
"{654D7A8A-0338-4961-B1DA-E651216AE493}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the sims 3\game\bin\sims3launcher.exe |
"{67626E30-98D1-4954-93D7-299F9C9F0E01}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\simcity 4 deluxe edition\apps\simcity 4.exe |
"{68051637-73AE-430B-8752-BD11769E0583}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alpha protocol\aplauncher.exe |
"{6A137240-3C4B-497C-AAD5-073DFB2F8975}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\divine_divinity\configtool.exe |
"{6B61DB56-9333-49D3-A50A-9D612E56A9E6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{6EA5F448-ABAD-4FBA-9DDB-4BCFCBD50372}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\grotesque tactics\grotesquetactics.exe |
"{6F2EDD44-FC4C-4138-8A33-F7B4BBA7AC5F}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd9.exe |
"{6F81F17D-B225-444A-BDCE-0E695B493AD4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\precipice of darkness 3\rainslick3.exe |
"{70E18C3A-64EC-47E1-AA1E-2B07C6B74E5A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher enhanced edition\system\witcher.exe |
"{725086AE-06AF-4950-9DFD-9736E9D5EE4A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout tactics\bos.exe |
"{72DB0F21-03F9-48D1-A1E9-2588747EC0F9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{755D976C-3C24-49A0-A0F4-D7ECE8F75C2C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect\binaries\masseffect.exe |
"{7812E344-1A85-4822-87E1-19FA2CE69539}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7945AA2B-0827-42D6-9628-619046D08F11}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex - human revolution\dxhr.exe |
"{7C688B9B-7A99-4F2C-823B-07B02303A5B6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\shatter\shatter.exe |
"{7CA8ABD3-5495-4B77-B1CF-A46EAFFC55AF}" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{7D2558C6-F6D6-4998-9924-D401CD9EFEEE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warlock - master of the arcane\support\ino_co_com.url |
"{7D2CDEB9-7613-4E54-A9C3-74D618B302F4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\men of war\mow.exe |
"{7D3A3785-1E99-43C9-8737-51E119A40EBB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\to the moon\to the moon\to the moon.exe |
"{7D50E6EF-5C09-492E-9886-873D5B530C5E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\railroad tycoon 2 platinum\rt2_plat.exe |
"{7E031FCF-79EB-4B98-8763-B62284458BC0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the political machine 2012\polmachine2012.exe |
"{7EE2DB0C-EC95-4675-985B-A13BA3AC0277}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction armageddon\rf4_launcher.exe |
"{7F1FBAB3-24DD-42F4-89B1-F524080814BD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warlock - master of the arcane\support\game.url |
"{7F70CECB-D89A-4341-B3EF-A97B79D6DDAE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\faerie solitaire\faeriesolitaire.exe |
"{800E532D-400A-4128-87F6-15B6441A32B0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ticket to ride\ticket to ride.exe |
"{8410B5FD-0478-412F-9B46-03016AC023B5}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{84886164-5FB4-4807-BF9B-AA70E1277EA9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\heroes of might and magic 5\bin\h5_game.exe |
"{874AAD36-A0EC-4397-AF9F-C62DFF364B2D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{886F9AF1-42AE-43EE-89F7-6EAC1039DF6A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wizorb\wizorb.exe |
"{89C3904F-C87E-4190-9CEC-939A3B588746}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout\falloutw.exe |
"{89EFD36E-6861-4FDE-84BE-E783E4360FA0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher enhanced edition\system\djinni!.exe |
"{8ABAEC28-DC6A-42F4-93F2-C08A574BFDB7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spellforce platinum edition\spellforce.exe |
"{8B0FF929-7D06-45C6-919F-210D7243AC91}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout 2\fallout2.exe |
"{8BCDAA55-35D9-4C5A-A354-DCDF02FFEC97}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\age of empires 3\bin\age3x.exe |
"{8C116773-36B9-4E7F-8FE8-EAC11ED76862}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the longest journey\game.exe |
"{8C2B889D-1C8F-4F99-9E94-FD191614AA2C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\10000000\10000000.exe |
"{8C9FABDC-5AAC-4130-9E33-F75A52D83F93}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\commandos 2 men of courage\readme.rtf |
"{8D1DFE27-2601-45A8-AB4A-36968E490CBD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\democracy 2\democracy2.exe |
"{8EE28FF5-D273-4D0B-8C3F-744EE64A88BF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\nation red\nationred.exe |
"{9179BE7C-5ED6-4CDC-9AE7-48A889EAA868}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rome total war gold\rometw-bi.exe |
"{92362891-ADB5-4307-AE82-5988E30F421A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\runespelloverture\runespell.exe |
"{93EFC25C-FE62-430A-B039-8965A8205C4C}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{96F96DD1-D216-4F5C-BA53-8E0F441A5BEC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wizorb\wizorb.exe |
"{9896859F-BBC5-4324-A425-968D865D14A0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\cart life\cart life.exe |
"{98A13824-3431-479A-AE4C-2EE6AB923AB8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\torchlight2.exe |
"{9AAAF6E2-A5DF-430B-A657-81E9E8E07977}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\divine_divinity\div.exe |
"{9AEAC33A-87CE-495C-BD8E-26CD61499CE6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tidalis\tidalis.exe |
"{9BCF1D27-E2D6-4C61-ADEC-D7C232C2E8A3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\turba\turba.exe |
"{9DEAF7B8-24A7-4588-A887-BC8BD04D22D2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\reliccoh.exe |
"{9E361B24-2309-4C00-8987-EEC045424D83}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ys origin\yso_win.exe |
"{A1EF8C70-CDC4-436D-924C-611028009254}" = protocol=17 | dir=in | app=c:\program files (x86)\atari\neverwinter nights 2\nwn2main_amdxp.exe |
"{A27CEF76-9A63-48A8-9D79-E6F428E08ED4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\patrician iv\patrician4.exe |
"{A2CC2FCF-CF21-429C-B51D-14B84DA4C73F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{A2EB9AF8-87F9-4C2B-9305-A82AE459EA6E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bully scholarship edition\bully.exe |
"{A3B44C3E-066E-491D-AB3B-480ED650C917}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\crayon physics deluxe\launcher.exe |
"{A3E1B194-F3C0-42C3-A6FE-7E3F79494022}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\wormsgolf2010\wormscrazygolf.exe |
"{A8D4B45B-9E84-45C8-A5D7-BE2DC6E2893E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\heroes of might and magic 5\bin\h5_game.exe |
"{AB6593FC-2207-462A-BE01-F46E41C7859C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\divine_divinity\configtool.exe |
"{ACD3EA68-E800-4634-AE5C-1F9A80164DF6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bully scholarship edition\bully.exe |
"{AD43E0DE-3220-4672-8A95-E1526C98E4C4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\turba\turba.exe |
"{AE2E6A89-0664-445B-B24C-B5D7F92D7672}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\age of empires 3\bin\age3y.exe |
"{AEB8D392-CF6F-430B-8A4B-7E1B1613664E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bit.trip runner\runner.exe |
"{AF07AFEE-82DE-4AA2-8FB0-4C2F693A55B8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deadpixels\dead pixels launcher.exe |
"{B095FDEA-5F43-4805-9550-0FF7EAE60CC7}" = protocol=17 | dir=in | app=c:\program files (x86)\atari\neverwinter nights 2\nwupdate.exe |
"{B0C8E0C0-8739-46E7-8DF6-64817562370F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\anodyne\anodyne.exe |
"{B10E723E-AD29-44E9-B8F2-12DC736C60A5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ys origin\config.exe |
"{B145C812-13C3-452B-AD02-ED2A8EBFE8B9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect\binaries\masseffect.exe |
"{B14BB1EB-9BCE-4ECB-BD7C-F4A7A910E9D3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\audiosurf\engine\questviewer.exe |
"{B1DB9C45-0E7C-46BC-8F4D-10CC3B471329}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fairy bloom freesia\fairybloomfreesia.exe |
"{B22FEDC4-194D-43B5-8031-C38E7E5B2B0F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\supreme commander 2\bin\supremecommander2.exe |
"{B30B5F30-29DC-448C-A221-DE6CA41D730A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\modlauncher.exe |
"{B358B8F9-B960-4B99-9C9F-9CD657234A7D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\freedom force\fforce.exe |
"{B37DA1B7-B121-40D5-A9DC-B94E03DE44A1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\supreme commander 2\bin\supremecommander2.exe |
"{B564494A-8227-40B8-97E1-3756F04205FA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\vvvvvv\vvvvvv.exe |
"{B611208C-53A4-4D38-A0DA-5B2A47AD3186}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ticket to ride\ticket to ride.exe |
"{B61A69FF-BC2B-4161-8A12-035CE10877EF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{B66044AC-05DF-4314-9218-B6481D18E5AE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\crayon physics deluxe\launcher.exe |
"{B749FD40-BFD6-4419-BD61-7DE749FEEF4F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ys origin\yso_win.exe |
"{B784395A-EB75-42AD-B1C7-D5D5CB2F32DF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\nightsky\nightsky.exe |
"{B7C3B9E9-0B3D-4D2B-BB76-44F1CE3CB3FA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\grand theft auto san andreas\gta-sa.exe |
"{B8905A07-CAE8-4C68-AAEB-5BE7D3E94B1A}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{BA38794B-17C0-4F02-91FD-83B4066EAF4B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\age of empires 3\bin\age3.exe |
"{BA4A3E65-8832-4637-811C-D2256290CC14}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the longest journey\game.exe |
"{BB4811EE-783D-4A6D-B4F7-125A419D692B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\depths of peril\depthsofperil.exe |
"{BBDF25C4-D02D-4665-98CD-04FD8AAA0EAF}" = dir=in | app=c:\users\joshua\appdata\local\microsoft\skydrive\skydrive.exe |
"{BCB4ADC4-A7DE-4374-A93C-0B6399ACCF84}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher enhanced edition\system\djinni!.exe |
"{BCDC1AE8-9320-42A8-91E1-0EC116C75ABF}" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{BD2A8F26-D9D8-4A67-B956-211C62AAE928}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\puzzlequest2\puzzlequest2.exe |
"{BD66BF9C-28FB-4BCC-A48E-A3F61A182F91}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{BD723BA9-0681-44CC-83C7-6FE9258FFB98}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{BD7C0420-8345-49D9-AD6D-61670B2C77E1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\king's bounty - the legend\kb.exe |
"{BDB9BADD-1C2C-4D57-B079-BB98433AA95F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\men of war\mow.exe |
"{BDD4C492-8537-491E-8D5F-89FF78A79638}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight\torchlight.exe |
"{BDF93157-09AC-45E5-8A96-6CF52C993531}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\a valley without wind 2\valley2.exe |
"{BF5660C2-8AAB-444C-811F-7183F84FEF75}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\jamestown\jamestown.exe |
"{BF638E1B-04B1-47A2-99B9-A656DA2E5CDA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\beat hazard\beathazard.exe |
"{BFC03245-23F6-4D6B-A4CD-221608311B05}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mark_of_the_ninja\bin\game.exe |
"{BFF7F422-7DB3-458E-8AF8-71B3715DEBBA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bastion\bastion.exe |
"{C223AD35-E9B5-4AE7-8D98-4FF9230EA603}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bastion\bastion.exe |
"{C2B43558-614B-497D-AF19-3BCE5D8F9104}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout tactics\ft tools.exe |
"{C2F6B442-F510-4391-BFCA-98F82F729CD9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\age of empires 3\bin\age3y.exe |
"{C2FC5B6B-DE3A-4E73-BD5A-9910684B4CD1}" = protocol=6 | dir=in | app=c:\program files (x86)\atari\neverwinter nights 2\nwn2main.exe |
"{C62DC787-3766-484A-BA4F-32435EE92665}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeons of dredmor\dungeons of dredmor.exe |
"{C6DF9BC6-CF98-41CF-A05B-5A92B6D36751}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\democracy 2\democracy2.exe |
"{C8A166CD-7DB7-45BD-B0B2-5E6D268BD06B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\cart life\cart life.exe |
"{C8BC3D51-7102-4BD4-A7EF-C6CB3FC9FEBF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hotline_miami\hotlinemiami.exe |
"{C8CA4BD4-A356-4108-8E45-A6A8E7E8605D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C9B2CC48-6B79-4115-8D2A-53E6EC170BE5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\railroad tycoon 2 platinum\rt2_plat.exe |
"{CA75BB75-566C-4BE4-8353-0507FFC8C560}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dangerous high school girls in trouble\prog\brigiton.exe |
"{CAA8BDC9-3AE0-49EB-9C3D-72D12C0FD462}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the sims 3\support\ea help\electronic_arts_technical_support.htm |
"{CBE23826-839E-4543-8FDD-A8E4FEB559A1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hotline_miami\hotlinemiami.exe |
"{CBE412B5-C2F3-42A2-B5F9-DF27F1259592}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\reliccoh.exe |
"{CC3EF1F3-F31B-451D-814F-873B4BD1892F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\men of war\mow_editor.exe |
"{CC4EE6EF-78AA-4080-AE38-5AE8ED58AD21}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\beat hazard\beathazard.exe |
"{CE1C3363-0589-4DB3-A0DC-83683A21CB8D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\grand theft auto san andreas\gta-sa.exe |
"{D2DF78F6-47DF-47D5-AAD2-9E365CEB8E93}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\faerie solitaire\faeriesolitaire.exe |
"{D305FF01-B1A2-4F4B-A2A9-3CFA563DA6E9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fairy bloom freesia\fairybloomfreesia.exe |
"{D473B692-5F81-4D20-8CC8-8FB0C55EAA14}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dlc quest\dlc.exe |
"{D4EA45A1-A410-4B9B-87C7-F8B338405FE5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\commandos 2 men of courage\readme.rtf |
"{D80C4825-04A0-4BB6-B3D7-C851C1AA1FDC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warlock - master of the arcane\game.exe |
"{D87F6D8E-4DD0-40E0-81C0-E94DB55002E3}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\simcity 4 deluxe edition\apps\simcity 4.exe |
"{DA7753AE-B206-4B7B-9052-F550AEF690E1}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{DC267900-01F5-4074-894F-434C38BE2418}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the binding of isaac\isaac.exe |
"{DD24CC63-DBDC-4111-A2C2-8E84751AF6D8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\king's bounty - the legend\save_fixer.exe |
"{DD6627A8-0B83-412F-87DE-002E77A008C3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\just cause 2\justcause2.exe |
"{DEC95F95-7EDA-40FD-97A7-6F86CDA07A52}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\anodyne\anodyne.exe |
"{DED2294B-057F-4A9B-9416-83E68940CBD3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\altitude\altitude.exe |
"{DEFCF243-A6EC-41E4-A929-6D55FE4B62AB}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{DF689033-3BDA-4327-B5C5-217FC7523BF0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\cogs\cogs.exe |
"{E2A04BEF-87AE-461F-8724-4AEFD93F13BE}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{E2B63067-1ACF-4AC8-95A9-18290F8EF34A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\shank\bin\shank.exe |
"{E38B31F4-E6A3-477A-A029-C20E513D73C3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the sims 3\support\ea help\electronic_arts_technical_support.htm |
"{E5572DA1-CE30-4D39-A8F4-9C7D0BB52BDD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\half minute hero\hmh.exe |
"{E5FE4A67-7BA1-4AFF-81C5-BD55F7135C8E}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{E6307889-EDEE-4F6F-9659-2D2914438577}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\grotesque tactics\grotesquetactics.exe |
"{E7AB8AF6-4C17-4922-B4F5-708538BD6D74}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\command and conquer red alert 3\support\ea help\electronic_arts_technical_support.htm |
"{E8691D17-7986-46AC-B1AA-CD97B1FA8121}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rome total war gold\rometw-bi.exe |
"{EA302B38-852E-4FA0-985C-CFC87C938E17}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\cart life\winsetup.exe |
"{EAE69433-0ABA-457E-9510-0F7A9AA71217}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\precipice of darkness 3\rainslick3.exe |
"{EC45475A-6E69-4D63-A719-DA76A6EF94BB}" = protocol=6 | dir=out | app=system |
"{EDEBFF7F-831F-4FA0-AFD4-B0866F49A485}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tropico 4\tropico4.exe |
"{EFBE2C5C-FBE3-46F6-9C3C-70ADE6A6717F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tropico 3\tropico3.exe |
"{F03A6A18-E89A-4EF2-8981-27FDBCF091AF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\nightsky\nightsky.exe |
"{F1796114-9116-4FA3-8CAC-E91C00341379}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\command and conquer red alert 3\runme.exe |
"{F24AF2C1-6EFB-4458-8FD3-771002B2663D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\peggle nights\pegglenights.exe |
"{F2749DD8-DE74-4562-B8A7-C716CD0BF33B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon hearts\dungeonhearts.exe |
"{F2790C9E-3DA5-424C-8F66-42DD162F54FF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terraria.exe |
"{F4F5667A-C7AD-4165-9112-0C9474FD585C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dlc quest\dlc.exe |
"{F5383C6D-89C5-4A38-9354-0BCCE45789ED}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F62B19BB-4D4B-4BD9-82C8-4D085AD6DCCB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect\docs\ea help\electronic_arts_technical_support.htm |
"{F69B3FE3-1BAF-4802-A9E0-53547FDD7EB0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\cart life\winsetup.exe |
"{F7F69B8A-3BE6-4F7B-8912-4D87475ED597}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\jamestown\jamestown.exe |
"{F954DC66-2CDE-4F10-B0E8-1C5BE0B275D5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tropico 4\tropico4.exe |
"{F9EB689A-5803-49AC-AAD4-27DF29692B49}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\beat hazard\runme.exe |
"{FAC5F477-755A-4867-8568-A14BB60B5582}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\swkotor\swkotor.exe |
"{FCECE9D6-F264-4624-920E-838F8FCB0908}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warlock - master of the arcane\support\ino_co_com.url |
"{FD0D44A2-D642-4D81-889B-84B334F5EA37}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{FE3EC6CD-AF2C-41DD-AC46-B2B30D4A8F13}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\knights of the old republic ii\swkotor2.exe |
"{FE9767E9-D46A-46EE-8DE5-2F626C5319F4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tropico 3\tropico3.exe |
"{FFC7AA36-F45E-4E3E-A418-B19C7571956A}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"TCP Query User{297AF5F3-5CF0-4030-83A5-3235E5C7FD36}C:\users\joshua\appdata\local\pokeit\rsync.exe" = protocol=6 | dir=in | app=c:\users\joshua\appdata\local\pokeit\rsync.exe |
"TCP Query User{84A57AC7-30BD-4CDF-84B3-9B8DCD420592}C:\users\joshua\appdata\local\pokeit\rsync.exe" = protocol=6 | dir=in | app=c:\users\joshua\appdata\local\pokeit\rsync.exe |
"TCP Query User{93FF9520-F43B-49A5-BD0B-2DDEBEB598B1}C:\program files (x86)\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"TCP Query User{9B615886-61C1-48D6-9D4A-8B8695A3F95D}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"TCP Query User{A4D53EB2-6A77-49A6-B4C5-5A8CB88DA891}C:\program files (x86)\gog.com\nox\game.exe" = protocol=6 | dir=in | app=c:\program files (x86)\gog.com\nox\game.exe |
"TCP Query User{A6522902-72EC-4D59-B748-BBD29C8C260C}C:\program files (x86)\steam\steamapps\common\worms reloaded\wormsreloaded.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\worms reloaded\wormsreloaded.exe |
"TCP Query User{AD963356-B340-4C6A-AC7E-B637B85B821C}C:\program files (x86)\tango\tango.exe" = protocol=6 | dir=in | app=c:\program files (x86)\tango\tango.exe |
"TCP Query User{EC614D47-39D7-4D75-B297-5D3DF970CE5E}C:\program files (x86)\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe |
"TCP Query User{F71822FA-25B0-47E4-8CCA-C08C7BC612FB}C:\program files (x86)\bitcoin\bitcoin-qt.exe" = protocol=6 | dir=in | app=c:\program files (x86)\bitcoin\bitcoin-qt.exe |
"TCP Query User{FDF71371-D6C1-4106-AF12-7247F83D0861}C:\program files (x86)\nestalgia\nestalgia.exe" = protocol=6 | dir=in | app=c:\program files (x86)\nestalgia\nestalgia.exe |
"UDP Query User{2A5B5F05-A9DE-40A8-84ED-08C93A030E6C}C:\program files (x86)\tango\tango.exe" = protocol=17 | dir=in | app=c:\program files (x86)\tango\tango.exe |
"UDP Query User{2B03A6B5-414A-4700-9011-28C300BF8DB4}C:\users\joshua\appdata\local\pokeit\rsync.exe" = protocol=17 | dir=in | app=c:\users\joshua\appdata\local\pokeit\rsync.exe |
"UDP Query User{2C04A7E4-D6EE-4F38-A943-80F6FF027B5D}C:\program files (x86)\steam\steamapps\common\worms reloaded\wormsreloaded.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\worms reloaded\wormsreloaded.exe |
"UDP Query User{2EFF274D-57BA-46A9-8533-69E099E24A3F}C:\program files (x86)\bitcoin\bitcoin-qt.exe" = protocol=17 | dir=in | app=c:\program files (x86)\bitcoin\bitcoin-qt.exe |
"UDP Query User{4106A40A-674B-4A46-9C94-B40C25984F7C}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"UDP Query User{4F12F63C-9C8A-4731-8D3C-C67175188F6F}C:\program files (x86)\nestalgia\nestalgia.exe" = protocol=17 | dir=in | app=c:\program files (x86)\nestalgia\nestalgia.exe |
"UDP Query User{9CB86A72-2ADC-4E7A-B071-B6EF3BB83AA6}C:\program files (x86)\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"UDP Query User{A9752608-6C35-4DAC-9F8D-6EEB1426BE82}C:\users\joshua\appdata\local\pokeit\rsync.exe" = protocol=17 | dir=in | app=c:\users\joshua\appdata\local\pokeit\rsync.exe |
"UDP Query User{C49D548F-012F-4359-8FCB-379845192D15}C:\program files (x86)\gog.com\nox\game.exe" = protocol=17 | dir=in | app=c:\program files (x86)\gog.com\nox\game.exe |
"UDP Query User{F2A3E2C9-3DB0-45D6-8631-58B6EA96B207}C:\program files (x86)\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{091A0130-A82F-4A6D-9C61-3BBBB3289030}" = RtVOsd
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{26A24AE4-039D-4CA4-87B4-2F86416017FF}" = Java™ 6 Update 17 (64-bit)
"{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{3C28BFD4-90C7-3138-87EF-418DC16E9598}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4FFA2088-8317-3B14-93CD-4C699DB37843}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729
"{5AF4E09F-5C9B-3AAF-B731-544D3DC821DD}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}" = Windows Mobile Device Center
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7FCDABCC-1A1E-4D61-909D-BA9495172774}" = iTunes
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{B8ED63AE-B171-3D63-8C35-40B82C4A5FBA}" = Microsoft Windows SDK for Windows 7 (7.0)
"{C78D3032-9DFD-41D0-9DE9-58EAE750CBA4}" = Microsoft Security Client
"{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant
"{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F6822EFD-3F7D-4B35-8845-757A26AEC8E2}" = Windows Live MIME IFilter
"BatteryBar" = BatteryBar (remove only)
"DriverAgent.exe" = DriverAgent by eSupport.com
"JustCloud" = JustCloud
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Security Client" = Microsoft Security Essentials
"Pokeit_is1" = Pokeit
"SDKSetup_7.0.7600.16385.40715" = Microsoft Windows SDK for Windows 7 (7.0)
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{14DC0059-00F1-4F62-BD1A-AB23CD51A95E}" = Adobe AIR
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{17B4760F-334B-475D-829F-1A3E94A6A4E6}" = HP Setup
"{18272881-CFC0-434D-A975-E5BE44206AA0}" = Windows Live UX Platform Language Pack
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1EA7C505-E6DA-4B85-9432-EBD3C70D510D}" = Windows Live Messenger
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{23A3E560-069F-4CFC-8F6C-1B526EC735FC}" = Windows Live Writer Resources
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{30F99474-EBE3-4134-A02B-F6CD38CFE243}" = Photo Gallery
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Windows 7
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{3F0D0ABE-CDAF-431A-00BC-CBBE018EA74E}" = SimCity 4 Deluxe
"{400C31E4-796F-4E86-8FDC-C3C4FACC6847}" = Junk Mail filter update
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{456A5815-604D-4D72-94DF-346D2B978A59}_is1" = GOG.com Downloader version 3.4.8
"{47D7C9B8-BD44-4D2E-9040-E946477B2F9A}" = Microsoft Live Search Toolbar
"{49A143E9-4A6A-43E7-86B1-388194C79248}" = HP Smart Web Printing
"{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.3
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{54CC7901-804D-4155-B353-21F0CC9112AB}" = HP Wireless Assistant
"{5BABDA39-61CF-41EE-992D-4054B6649A9B}" = Movie Maker
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{6753B40C-0FBD-3BED-8A9D-0ACAC2DCD85D}" = Microsoft Document Explorer 2008
"{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform
"{6AFDE3BE-BC01-45A4-9D06-BBF5AD207313}" = LightScribe System Software
"{6C772996-BFF3-3C8C-860B-B3D48FF05D65}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106
"{6D0C6BE4-F674-43D2-96BC-3509345108C9}_is1" = PokerStove version 1.24
"{6e8f74e0-43bd-4dce-8477-6ff6828acc07}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.1.1
"{70854FE6-3BF1-4C69-94D0-BEB821102E34}" = Windows Live Mail
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83D6B5DC-9C8C-4DE2-B66C-14FA5C8680B5}_is1" = Fallout FIXT alpha 5.3
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86C40513-B5A4-476E-9EAB-EC118DCF4502}" = Windows Live Writer
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions
"{8A809006-C25A-4A3A-9DAB-94659BCDB107}" = NVIDIA PhysX
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{8e70e4e1-06d7-470b-9f74-a51bef21088e}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{901F0D4C-009D-1112-8DE4-03599E7B0C5C}" = REALTEK Wireless LAN Software
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{91B9368F-6C6F-3DB5-9CBA-6CAD56035B26}" = Google Talk Plugin
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{97174E88-52F9-445A-A28E-704A45332D19}" = HP Software Framework
"{97C79BEC-43F7-4BD8-A6A7-85C0257E488A}" = Windows Live Writer
"{98813202-6C6E-4ABE-A128-6E8FB3368BE0}" = Photobucket Backup
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.5.5 MUI
"{B80D3EA9-A252-4AE5-AC51-81729F5C586F}" = Windows Live Mail
"{B93EEE50-9C8F-45DF-95E4-3D85A6E242F3}" = DarksidersInstaller
"{BC146E5F-A2B0-40DB-90E7-2833807E98DF}" = HP User Guides 0183
"{C034A6F9-6569-491B-B3BF-F5D15221A708}" = Windows Live Essentials
"{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C71067FC-288F-4E0B-88C6-44DFDA8311E2}" = System Requirements Lab for Intel
"{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D2C146B1-948D-47EF-8387-5D1C6B980F7C}" = Windows Live Writer
"{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}" = Microsoft XNA Framework Redistributable 4.0 Refresh
"{D888F114-7537-4D48-AF03-5DA9C82D7540}" = Photo Common
"{D8DFA46A-39F7-4368-810D-18AFCFDDAEAF}" = Adobe Shockwave Player
"{DE626616-D7C4-4F00-7E0B-EAF26FA65749}" = muvee Reveal
"{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E5F05232-96B6-4552-A480-785A60A94B21}" = System Requirements Lab CYRI
"{E824E81C-80A4-3DFF-B5F9-4842A9FF5F7F}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106
"{EB58480C-0721-483C-B354-9D35A147999F}" = HP Quick Launch
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{ED6C77F9-4D7E-447C-9EC0-9A212D075535}" = Movie Maker
"{ED8DE18A-421A-46CE-884B-E913EB16AB49}" = calibre
"{EE202411-2C26-49E8-9784-1BC1DBF7DE96}" = HP Support Assistant
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F20C1251-1D0A-4944-B2AE-678581B33B19}" = Neverwinter Nights 2
"{F2235E5E-7881-4293-9B6F-04B2609FBFF0}" = Windows Live Messenger
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FC6C7107-7D72-41A1-A031-3CE751159BAB}" = Photo Gallery
"{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"686663F1-6B75-433C-B44B-BA8F555A6C14" = Poker4You
"8461-7759-5462-8226" = Vuze
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"atariluckylettersdeluxe_is1" = Pat Sajak's Lucky Letters Deluxe
"CarbonPoker Odds Calculator_is1" = CarbonPoker Odds Calculator 1.0.3
"CarbonPoker Omaha Calculator_is1" = CarbonPoker Omaha Calculator 1.0.2
"Coupon Companion" = Coupon Companion
"DD Tournament Poker 1.0" = DD Tournament Poker 1.0
"ESET Online Scanner" = ESET Online Scanner v3
"ffdshow_is1" = ffdshow v1.1.3800 [2011-03-28]
"Game Booster_is1" = Game Booster 3
"GameSpy Arcade" = GameSpy Arcade
"GOGPACKBALDURSGATE2_is1" = Baldur's Gate 2 Complete
"GOGPACKCAPITALISM2_is1" = Capitalism 2
"Google Chrome" = Google Chrome
"HoldemManager2" = Holdem Manager 2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Smart Web Printing" = HP Smart Web Printing
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
"InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft Document Explorer 2008" = Microsoft Document Explorer 2008
"Mozilla Firefox 19.0.2 (x86 en-US)" = Mozilla Firefox 19.0.2 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP3 Rocket" = MP3 Rocket
"My HP Game Console" = HP Game Console
"NEStalgia" = NEStalgia
"NOX_is1" = NOX
"OpenAL" = OpenAL
"Origin" = Origin
"Out of the Park Baseball11" = Out of the Park Baseball 11
"Poker Tracker Stud Version 1.05.09_is1" = Poker Tracker Stud Version 1.05.09
"PokerTracker4" = PokerTracker 4 (remove only)
"PostgreSQL 8.4" = PostgreSQL 8.4
"Steam App 102200" = Runespell: Overture
"Steam App 105450" = Age of Empires® III: Complete Collection
"Steam App 105600" = Terraria
"Steam App 107100" = Bastion
"Steam App 107300" = Breath of Death VII
"Steam App 107310" = Cthulhu Saves the World
"Steam App 108200" = Ticket to Ride
"Steam App 113200" = The Binding of Isaac
"Steam App 115100" = Costume Quest
"Steam App 12120" = Grand Theft Auto: San Andreas
"Steam App 12200" = Bully: Scholarship Edition
"Steam App 12910" = Audiosurf Demo
"Steam App 15170" = Heroes of Might and Magic V
"Steam App 1520" = DEFCON
"Steam App 1523" = DEFCON Beta Demo
"Steam App 17460" = Mass Effect
"Steam App 17480" = Command and Conquer: Red Alert 3
"Steam App 18700" = And Yet It Moves
"Steam App 200130" = Puzzler World 2
"Steam App 200710" = Torchlight II
"Steam App 200900" = Cave Story+
"Steam App 203630" = Warlock - Master of the Arcane
"Steam App 20540" = Company of Heroes: Tales of Valor
"Steam App 206440" = To the Moon
"Steam App 207350" = Ys Origin
"Steam App 207420" = Wizorb
"Steam App 20820" = Shatter
"Steam App 208580" = Star Wars: Knights of the Old Republic II
"Steam App 20900" = The Witcher: Enhanced Edition
"Steam App 209330" = A Valley Without Wind
"Steam App 211120" = The Political Machine 2012
"Steam App 212680" = FTL: Faster Than Light
"Steam App 213030" = Penny Arcade's On the Rain-Slick Precipice of Darkness 3
"Steam App 214170" = Divine Divinity
"Steam App 214560" = Mark of the Ninja
"Steam App 214590" = Fairy Bloom Freesia
"Steam App 214830" = Half Minute Hero: Super Mega Neo Climax Ultimate Boy
"Steam App 218040" = Democracy 2
"Steam App 219150" = Hotline Miami
"Steam App 222980" = Dead Pixels
"Steam App 22600" = Worms Reloaded
"Steam App 227580" = 10,000,000
"Steam App 228320" = A Valley Without Wind 2
"Steam App 229520" = Dungeon Hearts
"Steam App 230050" = DLC Quest
"Steam App 233390" = Cart Life
"Steam App 234900" = Anodyne
"Steam App 23600" = Depths of Peril
"Steam App 25800" = Europa Universalis III
"Steam App 25900" = King's Bounty: The Legend
"Steam App 26500" = Cogs
"Steam App 26900" = Crayon Physics Deluxe
"Steam App 27400" = Dangerous High School Girls in Trouble!
"Steam App 28050" = Deus Ex: Human Revolution
"Steam App 32370" = Star Wars: Knights of the Old Republic
"Steam App 34010" = Alpha Protocol
"Steam App 3540" = Peggle Nights
"Steam App 3590" = Plants vs. Zombies: Game of the Year
"Steam App 38400" = Fallout
"Steam App 38410" = Fallout 2
"Steam App 38420" = Fallout Tactics
"Steam App 38600" = Faerie Solitaire
"Steam App 39540" = Spellforce: Platinum Edition
"Steam App 39550" = Spellforce 2: Gold Edition
"Steam App 39800" = Nation Red
"Steam App 40100" = Supreme Commander 2
"Steam App 40420" = Tidalis
"Steam App 41300" = Altitude
"Steam App 41500" = Torchlight
"Steam App 4560" = Company of Heroes
"Steam App 46450" = Grotesque Tactics: Evil Heroes
"Steam App 47540" = Puzzle Quest 2
"Steam App 4760" = Rome: Total War
"Steam App 47890" = The Sims™ 3
"Steam App 49600" = Beat Hazard
"Steam App 50620" = Darksiders
"Steam App 55110" = Red Faction: Armageddon
"Steam App 57600" = Tropico 3: Absolute Power
"Steam App 57620" = Patrician IV: Steam Special Edition
"Steam App 57690" = Tropico 4
"Steam App 58400" = Turba
"Steam App 6120" = Shank
"Steam App 61700" = Might and Magic: Clash of Heroes
"Steam App 6310" = The Longest Journey
"Steam App 63710" = BIT.TRIP RUNNER
"Steam App 6830" = Commandos 2: Men of Courage
"Steam App 70300" = VVVVVV
"Steam App 70620" = Worms Crazy Golf
"Steam App 7620" = Railroad Tycoon 2: Platinum
"Steam App 7830" = Men of War
"Steam App 8190" = Just Cause 2
"Steam App 8880" = Freedom Force
"Steam App 8930" = Sid Meier's Civilization V
"Steam App 94200" = Jamestown
"Steam App 98800" = Dungeons of Dredmor
"Steam App 99700" = NightSky
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite" = Windows Live Essentials
"WT082122" = Blackhawk Striker 2
"WT082124" = Blasterball 3
"WT082133" = Dora's Carnival Adventure
"WT082141" = FATE
"WT082168" = Penguins!
"WT082170" = Plants vs. Zombies
"WT082171" = Poker Superstars III
"WT082172" = Polar Bowler
"WT082173" = Polar Golfer
"WT082188" = Virtual Families
"WT082189" = Wheel of Fortune 2
"WT082192" = Bejeweled 2 Deluxe
"WT082200" = Chuzzle Deluxe
"WT082241" = Virtual Villagers - The Secret City
"WT082396" = Diner Dash 2 Restaurant Rescue
"WT082438" = Build-a-lot 2
"WT082442" = Faerie Solitaire
"WT082443" = Jewel Quest 3
"WT082456" = Mystery P.I. - The New York Fortune
"WT082463" = Zuma's Revenge
"WT082468" = Jewel Quest Solitaire 2
"WT083477" = Cake Mania
"WT083484" = Escape Rosecliff Island
"WT083491" = TextTwist 2
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Bitcoin" = Bitcoin
"CarbonPoker" = CarbonPoker
"SkyDriveSetup.exe" = Microsoft SkyDrive
"WinDirStat" = WinDirStat 1.1.2

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 2/4/2013 12:16:24 AM | Computer Name = Joshua-PC | Source = PostgreSQL | ID = 0
Description = 2013-02-03 23:16:24 ESTFATAL: the database system is starting up

Error - 2/4/2013 12:16:25 AM | Computer Name = Joshua-PC | Source = PostgreSQL | ID = 0
Description = 2013-02-03 23:16:25 ESTFATAL: the database system is starting up

Error - 2/4/2013 8:35:12 AM | Computer Name = Joshua-PC | Source = PostgreSQL | ID = 0
Description = 2013-02-04 07:35:12 ESTFATAL: the database system is starting up

Error - 2/4/2013 8:35:13 AM | Computer Name = Joshua-PC | Source = PostgreSQL | ID = 0
Description = 2013-02-04 07:35:13 ESTFATAL: the database system is starting up

Error - 2/4/2013 10:06:03 AM | Computer Name = Joshua-PC | Source = Bonjour Service | ID = 100
Description = ERROR: mDNSPlatformReadTCP - recv: 10053

Error - 2/4/2013 10:06:03 AM | Computer Name = Joshua-PC | Source = Bonjour Service | ID = 100
Description = 456: ERROR: read_msg errno 0 (The operation completed successfully.)

Error - 2/4/2013 10:06:09 AM | Computer Name = Joshua-PC | Source = PostgreSQL | ID = 0
Description = 2013-02-04 09:06:09 ESTFATAL: the database system is starting up

Error - 2/4/2013 12:18:37 PM | Computer Name = Joshua-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "c:\program files (x86)\ESET\eset
online scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 2/5/2013 4:26:23 AM | Computer Name = Joshua-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "c:\program files (x86)\ESET\eset
online scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 2/6/2013 6:16:39 AM | Computer Name = Joshua-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "c:\program files (x86)\ESET\eset
online scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

[ Hewlett-Packard Events ]
Error - 8/31/2012 2:05:22 PM | Computer Name = Joshua-PC | Source = HPSF.exe | ID = 4000
Description =

Error - 8/31/2012 2:07:26 PM | Computer Name = Joshua-PC | Source = HPSF.exe | ID = 4000
Description =

Error - 8/31/2012 2:07:44 PM | Computer Name = Joshua-PC | Source = HPSF.exe | ID = 4000
Description =

Error - 8/31/2012 2:08:40 PM | Computer Name = Joshua-PC | Source = HPSF.exe | ID = 4000
Description =

Error - 8/31/2012 2:11:19 PM | Computer Name = Joshua-PC | Source = HPSF.exe | ID = 4000
Description =

Error - 9/21/2012 3:19:05 PM | Computer Name = Joshua-PC | Source = HPSF.exe | ID = 4000
Description =

Error - 9/21/2012 3:59:36 PM | Computer Name = Joshua-PC | Source = HPSF.exe | ID = 4000
Description =

Error - 9/21/2012 3:59:54 PM | Computer Name = Joshua-PC | Source = HPSF.exe | ID = 4000
Description =

Error - 11/24/2012 4:11:40 PM | Computer Name = Joshua-PC | Source = HPSF.exe | ID = 4000
Description = HP Error ID: -2146233087 Server stack trace: at System.ServiceModel.Channels.ServiceChannel.Call(String
action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[]
outs, TimeSpan timeout) at System.ServiceModel.Channels.ServiceChannel.Call(String
action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[]
outs) at System.ServiceModel.Channels.ServiceChannelProxy.InvokeService(IMethodCallMessag
e
methodCall, ProxyOperationRuntime operation) at System.ServiceModel.Channels.ServiceChannelProxy.Invoke(IMessage
message) Exception rethrown at [0] Message: The server did not provide a meaningful
reply; this might be caused by a contract mismatch, a premature session shutdown
or an internal server error. StackTrace: Server stack trace: at System.ServiceModel.Channels.ServiceChannel.Call(String
action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[]
outs, TimeSpan timeout) at System.ServiceModel.Channels.ServiceChannel.Call(String
action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[]
outs) at System.ServiceModel.Channels.ServiceChannelProxy.InvokeService(IMethodCallMessag
e
methodCall, ProxyOperationRuntime operation) at System.ServiceModel.Channels.ServiceChannelProxy.Invoke(IMessage
message) Exception rethrown at [0]: at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage
reqMsg, IMessage retMsg) at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData&
msgData, Int32 type) at HP.SupportFramework.Communicator.MessengerComm.IMessengerCommunicator.UpdateTime
r()

at HP.SupportAssistant.UI.MessengerCommunication.sendTimerUpdate() Source: mscorlib

Name:
HPSF.exe Version: 06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support
Framework\HPSF.exe Format: en-US RAM: 3002 Ram Utilization: 40 TargetSite: Void HandleReturnMessage(System.Runtime.Remoting.Messaging.IMessage,
System.Runtime.Remoting.Messaging.IMessage)

[ HP Software Framework Events ]
Error - 1/27/2013 2:39:07 PM | Computer Name = Joshua-PC | Source = hpqWmiEx | ID = 5
Description = 2013/01/27 13:39:07.533|00000F38|Error |ChpqWmiExModule::Start|The
hpqwmiex service failed to start (1063). A system restart may correct this problem.

[ System Events ]
Error - 12/16/2012 11:28:01 PM | Computer Name = Joshua-PC | Source = DCOM | ID = 10010
Description =

Error - 12/19/2012 9:02:38 PM | Computer Name = Joshua-PC | Source = DCOM | ID = 10010
Description =

Error - 12/20/2012 1:23:32 AM | Computer Name = Joshua-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Steam
Client Service service to connect.

Error - 12/20/2012 1:23:32 AM | Computer Name = Joshua-PC | Source = Service Control Manager | ID = 7000
Description = The Steam Client Service service failed to start due to the following
error: %%1053

Error - 12/23/2012 8:21:36 AM | Computer Name = Joshua-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 7:19:16 AM on ?12/?23/?2012 was unexpected.

Error - 12/24/2012 5:36:02 PM | Computer Name = Joshua-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 4:34:10 PM on ?12/?24/?2012 was unexpected.

Error - 12/26/2012 9:58:38 AM | Computer Name = Joshua-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 8:53:39 AM on ?12/?26/?2012 was unexpected.

Error - 12/30/2012 5:20:14 AM | Computer Name = Joshua-PC | Source = DCOM | ID = 10010
Description =

Error - 12/30/2012 5:20:44 AM | Computer Name = Joshua-PC | Source = DCOM | ID = 10010
Description =

Error - 1/1/2013 6:10:06 AM | Computer Name = Joshua-PC | Source = DCOM | ID = 10010
Description =


< End of report >


OTL logfile created on: 5/21/2013 8:57:34 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Joshua\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.93 Gb Total Physical Memory | 0.69 Gb Available Physical Memory | 23.51% Memory free
5.86 Gb Paging File | 2.56 Gb Available in Paging File | 43.73% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 283.84 Gb Total Space | 7.15 Gb Free Space | 2.52% Space Free | Partition Type: NTFS
Drive D: | 13.95 Gb Total Space | 2.31 Gb Free Space | 16.54% Space Free | Partition Type: NTFS
Drive E: | 99.34 Mb Total Space | 95.24 Mb Free Space | 95.88% Space Free | Partition Type: FAT32
Drive F: | 7.70 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive G: | 3.77 Gb Total Space | 3.48 Gb Free Space | 92.49% Space Free | Partition Type: FAT32

Computer Name: JOSHUA-PC | User Name: Joshua | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Joshua\Downloads\OTL (4).exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files (x86)\CarbonPoker\client.exe ()
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
PRC - c:\postgreSQL\bin\pg_ctl.exe (PostgreSQL Global Development Group)
PRC - c:\postgreSQL\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)


========== Modules (No Company Name) ==========

MOD - C:\Users\Joshua\AppData\Local\Temp\javasysmo7246806689054932858.dll ()
MOD - C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.202\pepflashplayer.dll ()
MOD - C:\Program Files (x86)\JustCloud\MPCBIconOverlays.dll ()
MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files (x86)\Steam\SDL2.dll ()
MOD - C:\Program Files (x86)\CarbonPoker\client.exe ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\ffmpegsumo.dll ()
MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\Program Files (x86)\CarbonPoker\browser\mozjs.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\HP.ActiveSupportLibrary\2.0.0.1__01a974bc1760f423\HP.ActiveSupportLibrary.dll ()
MOD - C:\Program Files (x86)\CarbonPoker\poker.dll ()
MOD - C:\Program Files (x86)\CarbonPoker\swt-extension-win32.dll ()
MOD - C:\Program Files (x86)\CarbonPoker\rt\jetrt\baseline720.dll ()
MOD - C:\Program Files (x86)\CarbonPoker\rt\bin\zip.dll ()
MOD - C:\Program Files (x86)\CarbonPoker\rt\bin\java.dll ()
MOD - C:\Program Files (x86)\CarbonPoker\rt\bin\jetvm\jvm.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avutil-51.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\66694f9192bd0dddc2eaf90fbcbcd555\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7c4de95aa433eb8d81a81caf805947a8\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\03cfab5534482e8fc313ead6edc19100\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\413288993ff690e8251d2dbe32bee01f\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\a30d7e65103254213dc62f238be50f97\System.EnterpriseServices.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\4d7a457d9f9adcce4d201119b5179c29\System.Transactions.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\3d4e9d4f6c945d6d3b7d423fdb6bd274\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\1ec80905a71750be50dfc7981ad5ae28\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d040079bc7148afeca03c5abb6fc3c61\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\4e80768a2d88c7a333e43cbb7a6c0705\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\dc28c9f7d8d36447c704c0ef119df673\UIAutomationTypes.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\53d6d827964619285771ed72332d3659\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\b311b783e1efaa9527f4c2c9680c44d1\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\25e672ea505e50ab058258ac72a54f02\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c64ca3678261c8ffcd9e7efd1af6ed54\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9dd758ac0bf7358ac6e4720610fcc63c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\187d7c66735c533de851c76384f86912\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Yahoo!\Messenger\yui.dll ()
MOD - C:\Program Files (x86)\Yahoo!\Messenger\pcre.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Program Files (x86)\JustCloud\x86\System.Data.SQLite.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Pillars\PCAlerts\PCAlertsPillar.dll ()
MOD - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Pillars\ECenter\ECLibrary.dll ()
MOD - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingServer.dll ()
MOD - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingClients.dll ()
MOD - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\RemotingClient.dll ()
MOD - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingInterface.dll ()
MOD - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\MessagingMessages.dll ()
MOD - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (RtVOsdService) – C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe (Realtek Semiconductor Corp.)
SRV:64bit: - (AERTFilters) – C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (BackupStack) – C:\Program Files (x86)\JustCloud\BackupStack.exe (Just Develop It)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe (McAfee, Inc.)
SRV - (HP Support Assistant Service) – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company)
SRV - (postgresql-8.4) – c:\postgreSQL\bin\pg_ctl.exe (PostgreSQL Global Development Group)
SRV - (HPWMISVC) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (WcesComm) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (rtl8192se) – C:\Windows\SysNative\drivers\rtl8192se.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (IntcHdmiAddService) – C:\Windows\SysNative\drivers\IntcHdmi.sys (Intel® Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (usb_rndisx) – C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (xusb21) – C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV - (DrvAgent64) – C:\Windows\SysWOW64\drivers\DrvAgent64.SYS (Phoenix Technologies)
DRV - (WinRing0_1_2_0) – C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys (OpenLibSys.org)
DRV - (RSUSBSTOR) – C:\Windows\SysWOW64\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {B81FBA82-D4E2-4A74-8293-E6DA97C42EA5}
IE:64bit: - HKLM\..\SearchScopes\{B81FBA82-D4E2-4A74-8293-E6DA97C42EA5}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{EF0C734F-06CB-4868-8F4E-B1B2329DB6E8}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\..\SearchScopes,DefaultScope = {B81FBA82-D4E2-4A74-8293-E6DA97C42EA5}
IE - HKLM\..\SearchScopes\{B81FBA82-D4E2-4A74-8293-E6DA97C42EA5}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{EF0C734F-06CB-4868-8F4E-B1B2329DB6E8}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKCU\..\SearchScopes,DefaultScope = {B81FBA82-D4E2-4A74-8293-E6DA97C42EA5}
IE - HKCU\..\SearchScopes\{14478331-DB2D-4915-9F96-8B026A6768F0}: "URL" = http://websearch.ask.com/redirect?client=i…75-94FF92DEE31A
IE - HKCU\..\SearchScopes\{B81FBA82-D4E2-4A74-8293-E6DA97C42EA5}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{EF0C734F-06CB-4868-8F4E-B1B2329DB6E8}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Google"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0037-ABCDEFFEDCBA%7D:6.0.37


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Joshua\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Joshua\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/22 03:19:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/08 23:25:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2012/09/20 05:13:04 | 000,000,000 | —D | M] (No name found) – C:\Users\Joshua\AppData\Roaming\Mozilla\Extensions
[2013/03/02 21:43:58 | 000,000,000 | —D | M] (No name found) – C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\ai252rld.default\extensions
[2012/12/20 14:42:14 | 000,679,123 | —- | M] () (No name found) – C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\ai252rld.default\extensions\[removed]
[2013/03/02 21:01:49 | 000,002,308 | —- | M] () – C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\ai252rld.default\searchplugins\askcom.xml
[2013/03/08 23:25:13 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/03/08 23:25:13 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2013/03/08 23:25:54 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2013/03/08 23:25:33 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013/03/08 23:25:33 | 000,002,086 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{
google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.202\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Talk Plugin Video Renderer (Enabled) = C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npo1d.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll
CHR - plugin: McAfee Security Scanner + (Enabled) = C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll
CHR - plugin: Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll
CHR - plugin: Java Deployment Toolkit 7.0.210.11 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: RuneScape = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajjblpfpopipimofkhbglcoeknpnfijj\1.1_0\
CHR - Extension: Google Docs = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: PriceBlink = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\aoiidodopnnhiflaflbfeblnojefhigh\3.6.1_0\
CHR - Extension: Google Drive = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: WOT = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.4.12_0\
CHR - Extension: YouTube = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Adblock Plus = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.4_0\
CHR - Extension: Google Search = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: RollApps = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhikinngnhnkeknickhgpdjhomepafhj\1.0.0.1_0\
CHR - Extension: High Contrast = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\djcfdncoelnlbldjfhinnjlhdjlikmph\0.5_0\
CHR - Extension: Google Launcher = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgjhjbiflegkfaoacjdgjggidcpbidk\2.6.3_0\
CHR - Extension: imgur Extension by Metronomik = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehoopddfhgaehhmphfcooacjdpmbjlao\2.0.4_0\
CHR - Extension: Mini Maps = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbfnldkfkplmmmbfnjkdbbhjbopnocda\2.0.3_0\
CHR - Extension: 1-ClickWeather for Chrome = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgmbighdoomjmebfbgplfmhcdbomjkoa\1.1.0.3_0\
CHR - Extension: TinEye Reverse Image Search = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl\1.1.2_0\
CHR - Extension: Desktop Wallpaper Tool = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfhbpblckhcihdkoogjmgfpkpnfndel\1.0_0\
CHR - Extension: MP3 Rocket Downloader = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfimfliilbabfohebppnfomgjljicpdm\1.0_0\
CHR - Extension: SuperSorter = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjebfgojnlefhdgmomncgjglmdckngij\0.4.3_0\
CHR - Extension: Crackle = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibfamoapbmmmlknoopmmfofgladlinic\7.1.7_0\
CHR - Extension: Cool Clock = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\icegcmhgphfkgglbljbkdegiaaihifce\3.0_0\
CHR - Extension: FB unseen = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcedcpmfdpjijiamkaeaefgfagnnpei\0.1.6.6_0\
CHR - Extension: Yet Another Google Bookmarks Extension = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdnejaepfmacfdmhkplckpfdcjgbeode\1.32_0\
CHR - Extension: Reddit Enhancement Suite = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb\4.2.0.1_0\
CHR - Extension: StumbleUpon = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcahibnffhnnjcedflmchmokndkjnhpg\5.4.23.1_0\
CHR - Extension: Google Voice (by Google) = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcnhkahnjcbndmmehfkdnkjomaanaooo\2.4.1_0\
CHR - Extension: PadMapper = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\lljagjbdinjommccodelnfmkepbdoafl\1_0\
CHR - Extension: Word\u00B2 = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpibnckjjeaabeepofhfmmpjmnomohee\2.5_0\
CHR - Extension: Google Mail Multi-Account Checker = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcpnehokodklgijkcakcfmccgpanipfp\2.0.24_0\
CHR - Extension: Mint = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhgffcfekbglhpcdjkhhjekhdnddkflg\1.5_0\
CHR - Extension: Quick Note = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\mijlebbfndhelmdpmllgcfadlkankhok\1.4.8_0\
CHR - Extension: Ghostery = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\4.1.1_0\
CHR - Extension: Diet Diary = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\neckeibmjhibmgoigmffjlihekefmffd\1.1_0\
CHR - Extension: Facebook Notifications = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmameahlembdcigphohgiodcgjomcgeo\1.27_0\
CHR - Extension: G+ Images Hover Zoom = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadickpipbiodolpmnhnfkloanjmjbjn\0.4_0\
CHR - Extension: Fade to White Aero Skin (by Skarv) = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\oekemfmehiakocmomemagciajlikigkl\1.0_0\
CHR - Extension: Bookmax = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofjpkfadmfhloombfmmlllnbhkoehckm\2.2_0\
CHR - Extension: Enhanced Steam = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg\3.2_0\
CHR - Extension: YTshowRating = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\olohkebleofongajeodnhideeiapohgi\1.0.7_0\
CHR - Extension: Coupon Companion = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbkdpahkifcigckmhiafindmaflfifgm\1.23.91_0\crossrider
CHR - Extension: Coupon Companion = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbkdpahkifcigckmhiafindmaflfifgm\1.23.91_0\
CHR - Extension: Gmail = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/09/22 16:28:26 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtkOSD] C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe (Realtek Semiconductor Corp.)
O4:64bit: - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [ShowBatteryBar] C:\Program Files\BatteryBar\ShowBatteryBar.exe ()
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JustCloud.lnk = C:\Program Files (x86)\JustCloud\JustCloud.exe (JustCloud.com)
O4 - Startup: C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Pokeit.lnk = C:\Users\Joshua\AppData\Local\Pokeit\Pokeit.exe (Pokeit LLC)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F4F0062C-F2A6-4A0F-949E-AAFAEA641171}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: vidc.VP60 - C:\Windows\system32\vp6vfw.dll File not found
Drivers32: vidc.VP61 - C:\Windows\system32\vp6vfw.dll File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/05/21 19:36:46 | 000,000,000 | —D | C] – C:\Windows\pss
[2013/05/21 17:12:58 | 000,000,000 | —D | C] – C:\Users\Joshua\SyncFolder
[2013/05/21 17:09:53 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JustCloud
[2013/05/21 17:09:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\JustCloud
[2013/05/21 08:11:40 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\Photobucket
[2013/05/21 08:10:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photobucket Backup
[2013/05/21 08:10:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Photobucket Backup
[2013/05/21 08:05:10 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\GameSave Manager 3
[2013/05/18 04:50:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fallout FIXT
[2013/05/16 22:01:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/05/16 21:59:44 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2013/05/16 21:59:42 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2013/05/16 21:59:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2013/05/16 21:59:42 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013/05/16 03:59:31 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\FairyBloomRe
[2013/05/14 23:39:11 | 009,195,912 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2013/05/08 00:11:57 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\Beat Hazard
[2013/05/06 07:03:22 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade
[2013/05/06 07:03:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade
[2013/05/06 07:03:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\GameSpy Arcade
[2013/05/04 01:32:39 | 000,000,000 | —D | C] – C:\Windows\WindowsMobile
[2013/04/28 03:52:22 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Local\tt
[2013/04/28 03:51:50 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Local\Ticket to Ride
[2013/04/23 21:51:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013/04/23 21:51:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2013/04/23 21:40:47 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2013/04/23 19:47:05 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\Broken Rules
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Joshua\*.tmp files -> C:\Users\Joshua\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/05/21 20:39:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/05/21 20:34:17 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/21 20:34:17 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/21 20:30:01 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-330554514-1544093356-3601766899-1001UA.job
[2013/05/21 20:26:20 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/21 20:25:28 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/05/21 20:25:23 | 2361,589,760 | -HS- | M] () – C:\hiberfil.sys
[2013/05/21 20:23:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/21 19:35:19 | 000,779,266 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/05/21 19:35:19 | 000,660,530 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/05/21 19:35:19 | 000,121,426 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/05/21 17:12:58 | 000,001,625 | —- | M] () – C:\Users\Joshua\Desktop\Sync Folder.lnk
[2013/05/21 17:09:53 | 000,001,073 | —- | M] () – C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JustCloud.lnk
[2013/05/21 17:09:53 | 000,001,063 | —- | M] () – C:\Users\Joshua\Desktop\JustCloud.lnk
[2013/05/21 08:11:40 | 000,000,104 | —- | M] () – C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2013/05/21 05:30:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-330554514-1544093356-3601766899-1001Core.job
[2013/05/18 04:50:16 | 000,001,377 | —- | M] () – C:\Users\Public\Desktop\Fallout FIXT.lnk
[2013/05/16 22:01:24 | 000,001,783 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/05/16 03:18:59 | 000,002,014 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2013/05/15 00:09:31 | 000,000,336 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForJoshua.job
[2013/05/14 23:40:24 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/05/14 23:40:23 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/05/14 23:39:27 | 009,195,912 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2013/05/07 11:23:36 | 000,866,720 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npdeployJava1.dll
[2013/05/07 11:23:36 | 000,788,896 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/05/06 07:03:55 | 000,000,996 | —- | M] () – C:\Users\Joshua\Desktop\GameSpy Arcade.lnk
[2013/05/04 01:34:26 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
[2013/04/23 21:51:30 | 000,002,515 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Joshua\*.tmp files -> C:\Users\Joshua\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/05/21 20:24:10 | 000,002,046 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2013/05/21 20:24:10 | 000,001,942 | —- | C] () – C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Pokeit.lnk
[2013/05/21 20:24:10 | 000,001,073 | —- | C] () – C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JustCloud.lnk
[2013/05/21 17:12:58 | 000,001,625 | —- | C] () – C:\Users\Joshua\Desktop\Sync Folder.lnk
[2013/05/21 17:09:53 | 000,001,063 | —- | C] () – C:\Users\Joshua\Desktop\JustCloud.lnk
[2013/05/21 08:11:40 | 000,000,104 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2013/05/18 04:50:16 | 000,001,377 | —- | C] () – C:\Users\Public\Desktop\Fallout FIXT.lnk
[2013/05/16 22:01:24 | 000,001,783 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/05/06 07:03:55 | 000,000,996 | —- | C] () – C:\Users\Joshua\Desktop\GameSpy Arcade.lnk
[2013/05/04 01:34:26 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
[2013/05/04 01:33:43 | 000,002,419 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Mobile Device Center.lnk
[2013/04/23 21:41:02 | 000,002,515 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2012/12/14 23:59:55 | 000,080,896 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2012/11/12 15:58:43 | 000,000,016 | —- | C] () – C:\Users\Joshua\persistent_state
[2012/10/16 10:24:32 | 000,005,022 | —- | C] () – C:\ProgramData\flwjycbm.bab
[2012/10/05 01:17:50 | 000,000,198 | —- | C] () – C:\Users\Joshua\AppData\Roaming\wklnhst.dat
[2012/09/23 01:33:47 | 000,007,605 | —- | C] () – C:\Users\Joshua\AppData\Local\resmon.resmoncfg
[2012/09/02 01:32:52 | 000,773,482 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/07/07 19:41:41 | 000,451,072 | —- | C] () – C:\Windows\SysWow64\ISSRemoveSP.exe
[2011/07/07 19:37:38 | 000,000,268 | —- | C] () – C:\Windows\SysWow64\RStoneLog2.ini
[2011/07/07 19:37:38 | 000,000,209 | —- | C] () – C:\Windows\SysWow64\RStoneLog.ini

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 01:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 00:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/03/25 05:26:34 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\Anodyne
[2013/05/07 11:00:14 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\Azureus
[2013/05/21 21:25:30 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\BatteryBar
[2013/05/08 00:12:07 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\Beat Hazard
[2013/02/05 02:26:05 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\Bitcoin
[2013/03/08 20:25:23 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\Braid
[2013/04/23 19:47:05 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\Broken Rules
[2012/10/11 07:03:08 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\calibre
[2013/03/28 21:07:27 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\Crayon Physics Deluxe
[2012/08/31 02:02:11 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\Doublefine
[2012/11/04 22:00:18 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\Faerie Solitaire
[2013/05/16 04:14:18 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\FairyBloomRe
[2012/10/16 01:07:12 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\FireShot
[2013/05/21 08:05:28 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\GameSave Manager 3
[2013/01/09 15:20:24 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\HEM Data
[2013/02/21 22:54:06 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\HoldemManager
[2012/08/29 04:31:07 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\Kalypso Media
[2013/04/22 17:03:58 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\MP3Rocket
[2012/10/11 04:33:03 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\NationRed
[2012/12/21 15:05:14 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\Origin
[2012/12/21 06:12:40 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\Out of the Park Developments
[2013/05/21 08:14:37 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\Photobucket
[2012/08/30 04:24:32 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\runic games
[2012/12/15 03:28:50 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\SystemRequirementsLab
[2012/10/05 01:17:59 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\Template
[2012/11/24 21:12:26 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\The Longest Journey
[2013/02/19 05:09:11 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\To the Moon - Freebird Games
[2012/09/09 16:00:47 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\Tropico 4
[2012/11/09 05:20:22 | 000,000,000 | —D | M] – C:\Users\Joshua\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2009/07/13 22:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 16:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\erdnt\cache86\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 02:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 09:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 22:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 22:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2013/05/21 17:04:21 | 000,266,496 | —- | M] () MD5=E4E77914E247BF22C1D89318642B8D9E – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf

< MD5 for: IEXPLORE.EXE >
[2012/11/13 22:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2012/11/13 22:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_178ed6e5b4dd3857\iexplore.exe
[2012/08/24 08:27:38 | 000,754,784 | —- | M] (Microsoft Corporation) MD5=1223ACBFC1093852DFF039E189599BBD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2012/08/24 03:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2012/10/08 04:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_178cd651b4df05a9\iexplore.exe
[2012/08/24 07:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2012/10/08 08:29:46 | 000,754,848 | —- | M] (Microsoft Corporation) MD5=49442BA6DCE4B4E3C1CB0AB193FE29AD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_0d382bff807e43ae\iexplore.exe
[2012/08/24 06:49:07 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012/08/24 03:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2012/08/24 08:27:41 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\erdnt\cache86\iexplore.exe
[2012/08/24 08:27:41 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2012/11/15 23:08:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=AC4957E154F750DF54F36ADC8E3E040D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_0db6f8de99a3ff69\iexplore.exe
[2012/10/08 04:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_1808a252ce07755f\iexplore.exe
[2012/10/08 07:09:10 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=F61714ABCF9BF0CEF0A6249AD4FD490B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_0db3f80099a6b364\iexplore.exe
[2012/11/13 22:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_180ba330ce04c164\iexplore.exe
[2012/11/14 03:11:18 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Program Files\Internet Explorer\iexplore.exe
[2012/11/14 03:11:18 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_0d3a2c93807c765c\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2012/08/24 08:27:39 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2012/08/24 08:27:39 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2012/08/24 08:27:41 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2012/08/24 08:27:41 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui

< MD5 for: SERVICES >
[2009/06/10 17:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.EXE >
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\erdnt\cache64\services.exe
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 22:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2009/07/13 22:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2009/07/13 22:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2009/07/13 22:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2009/07/13 22:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 09:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\erdnt\cache64\winlogon.exe
[2010/11/20 09:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 09:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 09:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/20 09:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2009/07/13 22:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/13 22:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2009/07/13 21:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2008/04/11 10:07:18 | 000,010,134 | —- | M] () – C:\eula.1049.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2013/05/21 20:25:23 | 2361,589,760 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2008/04/11 10:09:24 | 000,093,200 | —- | M] (Microsoft Corporation) – C:\install.res.1049.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2013/05/21 20:25:29 | 3148,787,712 | -HS- | M] () – C:\pagefile.sys
[2012/08/30 04:56:03 | 000,002,491 | —- | M] () – C:\RHDSetup.log
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/09/12 16:57:44 | 000,322,048 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/08/24 13:29:36 | 000,000,221 | -HS- | M] () – C:\Users\Joshua\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >
Hi Alyaz,

Sorry for the delay responding to your post. It's been a few days since you generated the logs posted, please run these tools to give me a fresh look.

=========================

1. Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Right click SecurityCheck.exe, select "Run as Administrator" and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
=========================

2. aswMBR

Download aswMBR.exe and save it to your desktop.

Right click and select "Run as Administrator".
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
=========================

3. AdwCleaner

Download AdwCleaner to your desktop.

Right click and select "Run as Administrator".
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
=========================

4. Junkware Removal Tool

[external image: Posted Image] Please download Junkware Removal Tool to your desktop.

Right click and select "Run as Administrator".
  • Shut down your protection software now to avoid potential conflicts.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
=========================

5. Re-run OTL (it should be located on your desktop).

Windows Vista and Windows 7 users Right Click and select "Run as Administrator" on the icon to run it.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt. (No Extras.txt will be produced)
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
=========================

In your next post please provide the following:
  • checkup.txt
  • aswMBR.txt
  • attach MBR.zip
  • AdwCleaner[S1].txt
  • JRT.txt
  • OTL.txt
  • Symptoms you are experiencing
1)checkup.txt

So I ran this program, got a log, and forgot to save it when I went further along in the process. Now if I try to run it again, it aborts and says I have an unsupported system…

2)aswMBR. txt

aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-05-26 14:42:52
—————————–
14:42:52.795 OS Version: Windows x64 6.1.7601 Service Pack 1
14:42:52.795 Number of processors: 2 586 0x170A
14:42:52.796 ComputerName: JOSHUA-PC UserName: Joshua
14:42:56.200 Initialize success
14:44:45.203 AVAST engine defs: 13052600
15:00:28.404 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
15:00:28.409 Disk 0 Vendor: Hitachi_ PB3O Size: 305245MB BusType: 3
15:00:28.604 Disk 0 MBR read successfully
15:00:28.611 Disk 0 MBR scan
15:00:28.683 Disk 0 unknown MBR code
15:00:28.703 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
15:00:28.760 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 290654 MB offset 409600
15:00:28.858 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 14287 MB offset 595668992
15:00:28.922 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 103 MB offset 624928768
15:00:29.467 Disk 0 scanning C:\Windows\system32\drivers
15:00:55.767 Service scanning
15:01:57.920 Modules scanning
15:01:57.922 Disk 0 trace - called modules:
15:01:57.956 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
15:01:57.957 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80050d8060]
15:01:57.958 3 CLASSPNP.SYS[fffff88001dba43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8002e35050]
15:01:59.396 AVAST engine scan C:\Windows
15:02:05.001 AVAST engine scan C:\Windows\system32
15:11:28.355 AVAST engine scan C:\Windows\system32\drivers
15:11:58.803 AVAST engine scan C:\Users\Joshua
15:52:09.644 AVAST engine scan C:\ProgramData
16:13:33.212 Scan finished successfully
16:28:57.382 Disk 0 MBR has been saved successfully to "C:\Users\Joshua\Desktop\MBR.dat"
16:28:57.603 The log file has been saved successfully to "C:\Users\Joshua\Desktop\aswMBR.txt"


3)MBR.zip

See attachment

4)ADWCleaner

# AdwCleaner v2.301 - Logfile created 05/26/2013 at 19:04:26
# Updated 16/05/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Joshua - JOSHUA-PC
# Boot Mode : Normal
# Running from : C:\Users\Joshua\Desktop\AdwCleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
File Deleted : C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\ai252rld.default\searchplugins\Askcom.xml
File Deleted : C:\Users\Public\Desktop\eBay.lnk
Folder Deleted : C:\Program Files (x86)\Coupon Companion
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\Users\Joshua\AppData\Local\APN
Folder Deleted : C:\Users\Joshua\AppData\Local\Coupon Companion
Folder Deleted : C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfimfliilbabfohebppnfomgjljicpdm

***** [Registry] *****

Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\ExpressFiles
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKCU\Software\pc optimizer pro
Key Deleted : HKCU\Software\PIP
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0004493.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0004493.FBApi
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0004493.FBApi.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0004493.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0004493.Sandbox.1
Key Deleted : HKLM\Software\ExpressFiles
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\hfimfliilbabfohebppnfomgjljicpdm

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16457

[OK] Registry is clean.

-\\ Mozilla Firefox v19.0.2 (en-US)

File : C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\ai252rld.default\prefs.js

C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\ai252rld.default\user.js … Deleted !

Deleted : user_pref("browser.search.order.1", "Ask.com");
Deleted : user_pref("browser.search.selectedEngine", "Ask.com");
Deleted : user_pref("extensions.crossriderapp4493.4493.InstallationThankYouPage", true);
Deleted : user_pref("extensions.crossriderapp4493.4493.InstallationTime", 1347574841);
Deleted : user_pref("extensions.crossriderapp4493.4493.InstallationUserSettings.searchUserConifr
mation", false[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.InstallationUserSettings.setHomepage", false);
Deleted : user_pref("extensions.crossriderapp4493.4493.InstallationUserSettings.setNewTab", false);
Deleted : user_pref("extensions.crossriderapp4493.4493.InstallationUserSettings.setSearch", false);
Deleted : user_pref("extensions.crossriderapp4493.4493.active", true);
Deleted : user_pref("extensions.crossriderapp4493.4493.addressbar", "");
Deleted : user_pref("extensions.crossriderapp4493.4493.affid", "0");
Deleted : user_pref("extensions.crossriderapp4493.4493.backgroundjs", "\n\n\"undefined\"!=typeof _GPL_BG_NEW&&[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.backgroundver", 6);
Deleted : user_pref("extensions.crossriderapp4493.4493.can_run_bg_code", true);
Deleted : user_pref("extensions.crossriderapp4493.4493.certdomaininstaller", "");
Deleted : user_pref("extensions.crossriderapp4493.4493.changeprevious", false);
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie.InstallationTime.expiration", "Fri Feb 01 2030 0[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie.InstallationTime.value", "1347574841");
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 […]
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie._GPL_aoi.value", "1347574841");
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie._GPL_blocklist.expiration", "Mon Sep 17 2012 19:[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie._GPL_blocklist.value", "%22nonexistantdomain.com[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie._GPL_country_code.expiration", "Fri Sep 21 2012 […]
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie._GPL_country_code.value", "%22US%22");
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie._GPL_crr.expiration", "Fri Feb 01 2030 00:00:00 […]
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie._GPL_crr.value", "1347920461");
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie._GPL_hotfix20111102645.expiration", "Fri Feb 01 […]
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie._GPL_hotfix20111102645.value", "%221%22");
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie._GPL_installer_params.expiration", "Fri Feb 01 2[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie._GPL_installer_params.value", "%7B%22source_id%2[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie._GPL_parent_zoneid.value", "%2214019%22");
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie._GPL_pc_20120828.expiration", "Fri Feb 01 2030 0[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie._GPL_pc_20120828.value", "1347649652342");
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie._GPL_product_id.expiration", "Fri Feb 01 2030 00[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie._GPL_product_id.value", "%221238%22");
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:00:[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie._GPL_zoneid.value", "%2281656%22");
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie.dbtest.expiration", "Fri Feb 01 2030 00:00:00 GM[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.cookie.dbtest.value", "1347649379044");
Deleted : user_pref("extensions.crossriderapp4493.4493.description", "Coupon Companion");
Deleted : user_pref("extensions.crossriderapp4493.4493.domain", "");
Deleted : user_pref("extensions.crossriderapp4493.4493.emailsig", "");
Deleted : user_pref("extensions.crossriderapp4493.4493.enablesearch", false);
Deleted : user_pref("extensions.crossriderapp4493.4493.exposesites", "");
Deleted : user_pref("extensions.crossriderapp4493.4493.fbremoteurl", "");
Deleted : user_pref("extensions.crossriderapp4493.4493.group", 0);
Deleted : user_pref("extensions.crossriderapp4493.4493.homepage", "");
Deleted : user_pref("extensions.crossriderapp4493.4493.iframe", false);
Deleted : user_pref("extensions.crossriderapp4493.4493.internaldb.InstallerIdentifiers.expiratio
n", "Fri Feb 0[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.internaldb.InstallerIdentifiers.value", "%7B%22installe[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.internaldb.Resources_appVer.expiration", "Fri Feb 01 20[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.internaldb.Resources_appVer.value", "34");
Deleted : user_pref("extensions.crossriderapp4493.4493.internaldb.Resources_lastVersion.expirati
on", "Fri Feb […]
Deleted : user_pref("extensions.crossriderapp4493.4493.internaldb.Resources_lastVersion.value", "0");
Deleted : user_pref("extensions.crossriderapp4493.4493.internaldb.Resources_meta.expiration", "Fri Feb 01 2030[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.internaldb.Resources_meta.value", "%7B%7D");
Deleted : user_pref("extensions.crossriderapp4493.4493.internaldb.Resources_nextCheck.expiration", "Tue Sep 18[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.internaldb.Resources_nextCheck.value", "true");
Deleted : user_pref("extensions.crossriderapp4493.4493.internaldb.Resources_queue.expiration", "Fri Feb 01 203[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.internaldb.Resources_queue.value", "%7B%7D");
Deleted : user_pref("extensions.crossriderapp4493.4493.js", "\n\nif(\"undefined\"!=typeof _GPL_PLUGIN){var _GP[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.manifesturl", "");
Deleted : user_pref("extensions.crossriderapp4493.4493.name", "Coupon Companion");
Deleted : user_pref("extensions.crossriderapp4493.4493.newtab", "");
Deleted : user_pref("extensions.crossriderapp4493.4493.opensearch", "");
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_1.code", "appAPI._cr_config={appID:funct[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_1.name", "base");
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_1.ver", 3);
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_1000014.code", "Array.prototype.indexOf|[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_1000014.name", "GPL Plugin (Loader)");
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_1000014.ver", 5);
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_1000015.code", "var _GPL_BG={vars:{},rul[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_1000015.name", "GPL Background (BG)");
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_1000015.ver", 3);
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_13.code", "(function(a){a.selectedText=f[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_13.name", "CrossriderAppUtils");
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_13.ver", 2);
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_14.code", "if(typeof(appAPI)===\"undefin[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_14.name", "CrossriderUtils");
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_14.ver", 2);
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_15.code", "(function(f){var u={};var e=M[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_15.name", "FacebookFFIE");
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_15.ver", 1);
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_16.code", "(function(f,B){if(typeof(B)==[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_16.name", "FFAppAPIWrapper");
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_16.ver", 3);
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_17.code", "if(typeof window!==\"undefine[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_17.name", "jQuery");
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_17.ver", 3);
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_21.code", "var CrossriderDebugManager=(f[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_21.name", "debug");
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_21.ver", 3);
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_22.code", "(function(a){appAPI.queueMana[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_22.name", "resources");
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_22.ver", 2);
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_28.code", "var CrossriderInitializerPlug[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_28.name", "initializer");
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_28.ver", 2);
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_4.code", "/*! jQuery v1.7.1 jquery.com |[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_4.name", "jquery_1_7_1");
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_4.ver", 3);
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_47.code", "(function(){appAPI.ready=func[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_47.name", "resources_background");
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins.plugin_47.ver", 1);
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins_lists.plugins_0", "17,14,16,47,1000015");
Deleted : user_pref("extensions.crossriderapp4493.4493.plugins_lists.plugins_1", "17,14,13,16,15,4,1,21,22,100[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.pluginsurl", "hxxp://app-static.crossrider.com/plugin/a[…]
Deleted : user_pref("extensions.crossriderapp4493.4493.pluginsversion", 13);
Deleted : user_pref("extensions.crossriderapp4493.4493.premium", true);
Deleted : user_pref("extensions.crossriderapp4493.4493.publisher", "215 Apps");
Deleted : user_pref("extensions.crossriderapp4493.4493.searchstatus", 0);
Deleted : user_pref("extensions.crossriderapp4493.4493.setnewtab", false);
Deleted : user_pref("extensions.crossriderapp4493.4493.settingsurl", "");
Deleted : user_pref("extensions.crossriderapp4493.4493.thankyou", "hxxp://crossrider.com/thank_you/4493");
Deleted : user_pref("extensions.crossriderapp4493.4493.updateinterval", 360);
Deleted : user_pref("extensions.crossriderapp4493.4493.ver", 34);
Deleted : user_pref("extensions.crossriderapp4493.adsOldValue", 14);
Deleted : user_pref("extensions.crossriderapp4493.apps", "4493");
Deleted : user_pref("extensions.crossriderapp4493.bic", "139c628e0086a4b6bf3f6ea958af0b19");
Deleted : user_pref("extensions.crossriderapp4493.cid", 4493);
Deleted : user_pref("extensions.crossriderapp4493.firstrun", false);
Deleted : user_pref("extensions.crossriderapp4493.hadappinstalled", true);
Deleted : user_pref("extensions.crossriderapp4493.installationdate", 1347649331);
Deleted : user_pref("extensions.crossriderapp4493.lastcheck", 22465341);
Deleted : user_pref("extensions.crossriderapp4493.lastcheckitem", 22465377);
Deleted : user_pref("extensions.crossriderapp4493.misc.lastBgWorkerTimer", "1347650112493");
Deleted : user_pref("extensions.crossriderapp4493.misc.lastDomWorkerTimer", "1347650112491");
Deleted : user_pref("extensions.crossriderapp4493.modetype", "production");

-\\ Google Chrome v27.0.1453.94

File : C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted [l.4480] : urls_to_restore_on_startup = [ "hxxp://search.conduit.com/?ctid=CT2504091&SearchSource;=48" ]

*************************

AdwCleaner[S1].txt - [321 octets] - [26/05/2013 16:30:28]
AdwCleaner[S2].txt - [15368 octets] - [26/05/2013 19:04:26]

########## EOF - C:\AdwCleaner[S2].txt - [15429 octets] ##########


5)JRT

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows 7 Home Premium x64
Ran by [removed] on Sun 05/26/2013 at 19:27:45.85
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{22222222-2222-2222-2222-220022442293}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{33333333-3333-3333-3333-330033443393}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\wow6432node\clsid\{22222222-2222-2222-2222-220022442293}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\wow6432node\clsid\{33333333-3333-3333-3333-330033443393}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{14478331-DB2D-4915-9F96-8B026A6768F0}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{EF0C734F-06CB-4868-8F4E-B1B2329DB6E8}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{EF0C734F-06CB-4868-8F4E-B1B2329DB6E8}



~~~ Files

Successfully deleted: [File] C:\eula.1028.txt
Successfully deleted: [File] C:\eula.1031.txt
Successfully deleted: [File] C:\eula.1033.txt
Successfully deleted: [File] C:\eula.1036.txt
Successfully deleted: [File] C:\eula.1040.txt
Successfully deleted: [File] C:\eula.1041.txt
Successfully deleted: [File] C:\eula.1042.txt
Successfully deleted: [File] C:\eula.1049.txt
Successfully deleted: [File] C:\eula.2052.txt
Successfully deleted: [File] C:\install.res.1028.dll
Successfully deleted: [File] C:\install.res.1031.dll
Successfully deleted: [File] C:\install.res.1033.dll
Successfully deleted: [File] C:\install.res.1036.dll
Successfully deleted: [File] C:\install.res.1040.dll
Successfully deleted: [File] C:\install.res.1041.dll
Successfully deleted: [File] C:\install.res.1042.dll
Successfully deleted: [File] C:\install.res.1049.dll
Successfully deleted: [File] C:\install.res.2052.dll
Successfully deleted: [File] C:\install.res.3082.dll



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\pc optimizer pro"



~~~ FireFox

Successfully deleted: [File] C:\Users\Joshua\AppData\Roaming\mozilla\firefox\profiles\ai252rld.default\invalidprefs.js
Successfully deleted the following from C:\Users\Joshua\AppData\Roaming\mozilla\firefox\profiles\ai252rld.default\prefs.js

user_pref("extensions.crossrider.bic", "139c628e0086a4b6bf3f6ea958af0b19");
Emptied folder: C:\Users\Joshua\AppData\Roaming\mozilla\firefox\profiles\ai252rld.default\minidumps [10 files]



~~~ Chrome

Successfully deleted: [Folder] C:\Users\Joshua\appdata\local\Google\Chrome\User Data\Default\Extensions\aoiidodopnnhiflaflbfeblnojefhigh
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\pbkdpahkifcigckmhiafindmaflfifgm



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sun 05/26/2013 at 19:37:09.11
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


6)OTL logfile created on: 5/26/2013 7:41:23 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Joshua\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.93 Gb Total Physical Memory | 1.31 Gb Available Physical Memory | 44.79% Memory free
5.86 Gb Paging File | 3.82 Gb Available in Paging File | 65.13% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 283.84 Gb Total Space | 8.19 Gb Free Space | 2.89% Space Free | Partition Type: NTFS
Drive D: | 13.95 Gb Total Space | 2.31 Gb Free Space | 16.54% Space Free | Partition Type: NTFS
Drive E: | 99.34 Mb Total Space | 95.24 Mb Free Space | 95.88% Space Free | Partition Type: FAT32

Computer Name: JOSHUA-PC | User Name: Joshua | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Joshua\Desktop\JRT.exe (Oleg N. Scherbakov)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Users\Joshua\Downloads\OTL (4).exe (OldTimer Tools)
PRC - c:\postgreSQL\bin\pg_ctl.exe (PostgreSQL Global Development Group)
PRC - c:\postgreSQL\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Windows\SysWOW64\cmd.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ffmpegsumo.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (RtVOsdService) – C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe (Realtek Semiconductor Corp.)
SRV:64bit: - (AERTFilters) – C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe (McAfee, Inc.)
SRV - (HP Support Assistant Service) – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company)
SRV - (postgresql-8.4) – c:\postgreSQL\bin\pg_ctl.exe (PostgreSQL Global Development Group)
SRV - (HPWMISVC) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (WcesComm) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (rtl8192se) – C:\Windows\SysNative\drivers\rtl8192se.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (IntcHdmiAddService) – C:\Windows\SysNative\drivers\IntcHdmi.sys (Intel® Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (usb_rndisx) – C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (xusb21) – C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV - (DrvAgent64) – C:\Windows\SysWOW64\drivers\DrvAgent64.SYS (Phoenix Technologies)
DRV - (WinRing0_1_2_0) – C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys (OpenLibSys.org)
DRV - (RSUSBSTOR) – C:\Windows\SysWOW64\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{B81FBA82-D4E2-4A74-8293-E6DA97C42EA5}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{EF0C734F-06CB-4868-8F4E-B1B2329DB6E8}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{B81FBA82-D4E2-4A74-8293-E6DA97C42EA5}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{B81FBA82-D4E2-4A74-8293-E6DA97C42EA5}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Google"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0037-ABCDEFFEDCBA%7D:6.0.37
FF - prefs.js..extensions.enabledAddons: %7B0113D088-8ED1-468C-B225-585A9C53B5E3%7D:1.0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Joshua\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Joshua\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/22 03:19:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/08 23:25:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2013/05/22 00:19:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Joshua\AppData\Roaming\Mozilla\Extensions
[2013/05/22 00:19:18 | 000,000,000 | —D | M] (No name found) – C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\ai252rld.default\extensions
[2013/05/22 00:19:18 | 000,000,000 | —D | M] (TopArcadeHits) – C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\ai252rld.default\extensions\{0113D088-8ED1-468C-B225-585A9C53B5E3}
[2012/12/20 14:42:14 | 000,679,123 | —- | M] () (No name found) – C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\ai252rld.default\extensions\[removed]
[2013/03/08 23:25:13 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/03/08 23:25:13 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2013/03/08 23:25:54 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2013/03/08 23:25:33 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013/03/08 23:25:33 | 000,002,086 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Talk Plugin Video Renderer (Enabled) = C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npo1d.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll
CHR - plugin: McAfee Security Scanner + (Enabled) = C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll
CHR - plugin: Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - plugin: Java Deployment Toolkit 7.0.210.11 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - Extension: RuneScape = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajjblpfpopipimofkhbglcoeknpnfijj\1.1_0\
CHR - Extension: Splendid = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdfkbdkkfmmckaadapdipihjfaacnkgd\3_0\
CHR - Extension: WOT = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.4.12_0\
CHR - Extension: Adblock Plus = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.4_0\
CHR - Extension: RollApps = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhikinngnhnkeknickhgpdjhomepafhj\1.0.0.1_0\
CHR - Extension: High Contrast = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\djcfdncoelnlbldjfhinnjlhdjlikmph\0.5_0\
CHR - Extension: Google Launcher = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgjhjbiflegkfaoacjdgjggidcpbidk\2.7_0\
CHR - Extension: imgur Extension by Metronomik = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehoopddfhgaehhmphfcooacjdpmbjlao\2.0.4_0\
CHR - Extension: Mini Maps = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbfnldkfkplmmmbfnjkdbbhjbopnocda\2.0.3_0\
CHR - Extension: 1-ClickWeather for Chrome = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgmbighdoomjmebfbgplfmhcdbomjkoa\1.1.0.3_0\
CHR - Extension: TinEye Reverse Image Search = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl\1.1.2_0\
CHR - Extension: Desktop Wallpaper Tool = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfhbpblckhcihdkoogjmgfpkpnfndel\1.0_0\
CHR - Extension: SuperSorter = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjebfgojnlefhdgmomncgjglmdckngij\0.4.3_0\
CHR - Extension: Crackle = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibfamoapbmmmlknoopmmfofgladlinic\7.1.7_0\
CHR - Extension: Cool Clock = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\icegcmhgphfkgglbljbkdegiaaihifce\3.0_0\
CHR - Extension: FB unseen = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcedcpmfdpjijiamkaeaefgfagnnpei\0.1.6.6_0\
CHR - Extension: Yet Another Google Bookmarks Extension = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdnejaepfmacfdmhkplckpfdcjgbeode\1.32_0\
CHR - Extension: Reddit Enhancement Suite = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb\4.2.0.1_0\
CHR - Extension: StumbleUpon = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcahibnffhnnjcedflmchmokndkjnhpg\5.4.23.1_0\
CHR - Extension: Google Voice (by Google) = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcnhkahnjcbndmmehfkdnkjomaanaooo\2.4.1_0\
CHR - Extension: PadMapper = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\lljagjbdinjommccodelnfmkepbdoafl\1_0\
CHR - Extension: Word\u00B2 = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpibnckjjeaabeepofhfmmpjmnomohee\2.5_0\
CHR - Extension: Google Mail Multi-Account Checker = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcpnehokodklgijkcakcfmccgpanipfp\2.0.24_0\
CHR - Extension: Mint = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhgffcfekbglhpcdjkhhjekhdnddkflg\1.5_0\
CHR - Extension: Quick Note = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\mijlebbfndhelmdpmllgcfadlkankhok\1.4.8_0\
CHR - Extension: Ghostery = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\4.1.1_0\
CHR - Extension: Diet Diary = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\neckeibmjhibmgoigmffjlihekefmffd\1.1_0\
CHR - Extension: Facebook Notifications = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmameahlembdcigphohgiodcgjomcgeo\1.27_0\
CHR - Extension: G+ Images Hover Zoom = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadickpipbiodolpmnhnfkloanjmjbjn\0.4_0\
CHR - Extension: Bookmax = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofjpkfadmfhloombfmmlllnbhkoehckm\2.2_0\
CHR - Extension: Enhanced Steam = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg\3.2_0\
CHR - Extension: YTshowRating = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\olohkebleofongajeodnhideeiapohgi\1.0.7_0\

O1 HOSTS File: ([2012/09/22 16:28:26 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (TopArcadeHits Games) - {A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} - C:\Users\Joshua\AppData\Local\TopArcadeHits\Toparcadehits.dll ()
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtkOSD] C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe (Realtek Semiconductor Corp.)
O4:64bit: - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKCU..\Run: [ShowBatteryBar] C:\Program Files\BatteryBar\ShowBatteryBar.exe ()
O4 - Startup: C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Pokeit.lnk = C:\Users\Joshua\AppData\Local\Pokeit\Pokeit.exe (Pokeit LLC)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F4F0062C-F2A6-4A0F-949E-AAFAEA641171}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/05/26 19:27:42 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/05/26 19:27:28 | 000,000,000 | —D | C] – C:\JRT
[2013/05/26 13:59:54 | 000,545,954 | —- | C] (Oleg N. Scherbakov) – C:\Users\Joshua\Desktop\JRT.exe
[2013/05/26 13:56:48 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Joshua\Desktop\aswMBR.exe
[2013/05/22 03:29:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/05/22 00:26:16 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2013/05/22 00:26:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2013/05/22 00:26:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\SpeedFan
[2013/05/22 00:19:28 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TopArcadeHits
[2013/05/22 00:19:02 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Local\TopArcadeHits
[2013/05/21 19:36:46 | 000,000,000 | —D | C] – C:\Windows\pss
[2013/05/21 17:12:58 | 000,000,000 | —D | C] – C:\Users\Joshua\SyncFolder
[2013/05/21 17:09:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\JustCloud
[2013/05/21 08:11:40 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\Photobucket
[2013/05/21 08:10:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photobucket Backup
[2013/05/21 08:10:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Photobucket Backup
[2013/05/21 08:05:10 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\GameSave Manager 3
[2013/05/18 04:50:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fallout FIXT
[2013/05/16 22:01:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/05/16 21:59:44 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2013/05/16 21:59:42 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2013/05/16 21:59:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2013/05/16 21:59:42 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013/05/16 03:59:31 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\FairyBloomRe
[2013/05/14 23:39:11 | 009,195,912 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2013/05/08 00:11:57 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\Beat Hazard
[2013/05/06 07:03:22 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade
[2013/05/06 07:03:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade
[2013/05/06 07:03:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\GameSpy Arcade
[2013/05/04 01:32:39 | 000,000,000 | —D | C] – C:\Windows\WindowsMobile
[2013/04/28 03:52:22 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Local\tt
[2013/04/28 03:51:50 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Local\Ticket to Ride
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Joshua\*.tmp files -> C:\Users\Joshua\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/05/26 19:32:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/26 19:30:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-330554514-1544093356-3601766899-1001UA.job
[2013/05/26 19:15:20 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/26 19:15:20 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/26 19:13:19 | 000,000,268 | —- | M] () – C:\Windows\tasks\TopArcadeHits.job
[2013/05/26 19:09:16 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/26 19:07:59 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/05/26 19:07:53 | 2361,589,760 | -HS- | M] () – C:\hiberfil.sys
[2013/05/26 16:28:57 | 000,000,512 | —- | M] () – C:\Users\Joshua\Desktop\MBR.dat
[2013/05/26 14:00:05 | 000,545,954 | —- | M] (Oleg N. Scherbakov) – C:\Users\Joshua\Desktop\JRT.exe
[2013/05/26 13:59:36 | 000,632,031 | —- | M] () – C:\Users\Joshua\Desktop\AdwCleaner.exe
[2013/05/26 13:58:23 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Joshua\Desktop\aswMBR.exe
[2013/05/26 13:56:07 | 000,890,854 | —- | M] () – C:\Users\Joshua\Desktop\SecurityCheck.exe
[2013/05/24 05:30:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-330554514-1544093356-3601766899-1001Core.job
[2013/05/23 18:32:58 | 000,002,183 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/05/22 13:07:19 | 000,002,279 | —- | M] () – C:\Users\Joshua\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/05/22 04:17:16 | 000,007,601 | —- | M] () – C:\Users\Joshua\AppData\Local\resmon.resmoncfg
[2013/05/22 00:26:17 | 000,001,007 | —- | M] () – C:\Users\Joshua\Desktop\SpeedFan.lnk
[2013/05/22 00:26:10 | 000,000,045 | —- | M] () – C:\Windows\SysWow64\initdebug.nfo
[2013/05/21 19:35:19 | 000,779,266 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/05/21 19:35:19 | 000,660,530 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/05/21 19:35:19 | 000,121,426 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/05/21 17:12:58 | 000,001,625 | —- | M] () – C:\Users\Joshua\Desktop\Sync Folder.lnk
[2013/05/21 08:11:40 | 000,000,104 | —- | M] () – C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2013/05/18 04:50:16 | 000,001,377 | —- | M] () – C:\Users\Public\Desktop\Fallout FIXT.lnk
[2013/05/16 22:01:24 | 000,001,783 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/05/16 03:18:59 | 000,002,014 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2013/05/15 00:09:31 | 000,000,336 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForJoshua.job
[2013/05/14 23:39:27 | 009,195,912 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2013/05/07 11:23:36 | 000,866,720 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npdeployJava1.dll
[2013/05/07 11:23:36 | 000,788,896 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/05/06 07:03:55 | 000,000,996 | —- | M] () – C:\Users\Joshua\Desktop\GameSpy Arcade.lnk
[2013/05/04 01:34:26 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Joshua\*.tmp files -> C:\Users\Joshua\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/05/26 16:28:57 | 000,000,512 | —- | C] () – C:\Users\Joshua\Desktop\MBR.dat
[2013/05/26 13:59:27 | 000,632,031 | —- | C] () – C:\Users\Joshua\Desktop\AdwCleaner.exe
[2013/05/26 13:56:01 | 000,890,854 | —- | C] () – C:\Users\Joshua\Desktop\SecurityCheck.exe
[2013/05/22 03:29:19 | 000,002,279 | —- | C] () – C:\Users\Joshua\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/05/22 03:29:19 | 000,002,183 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/05/22 03:27:39 | 000,000,898 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/22 03:27:38 | 000,000,894 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/22 00:26:17 | 000,001,007 | —- | C] () – C:\Users\Joshua\Desktop\SpeedFan.lnk
[2013/05/22 00:26:09 | 000,000,045 | —- | C] () – C:\Windows\SysWow64\initdebug.nfo
[2013/05/22 00:19:03 | 000,000,268 | —- | C] () – C:\Windows\tasks\TopArcadeHits.job
[2013/05/21 20:24:10 | 000,001,942 | —- | C] () – C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Pokeit.lnk
[2013/05/21 17:12:58 | 000,001,625 | —- | C] () – C:\Users\Joshua\Desktop\Sync Folder.lnk
[2013/05/21 08:11:40 | 000,000,104 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2013/05/18 04:50:16 | 000,001,377 | —- | C] () – C:\Users\Public\Desktop\Fallout FIXT.lnk
[2013/05/16 22:01:24 | 000,001,783 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/05/06 07:03:55 | 000,000,996 | —- | C] () – C:\Users\Joshua\Desktop\GameSpy Arcade.lnk
[2013/05/04 01:34:26 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
[2013/05/04 01:33:43 | 000,002,419 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Mobile Device Center.lnk
[2012/12/14 23:59:55 | 000,080,896 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2012/11/12 15:58:43 | 000,000,016 | —- | C] () – C:\Users\Joshua\persistent_state
[2012/10/16 10:24:32 | 000,005,022 | —- | C] () – C:\ProgramData\flwjycbm.bab
[2012/10/05 01:17:50 | 000,000,198 | —- | C] () – C:\Users\Joshua\AppData\Roaming\wklnhst.dat
[2012/09/23 01:33:47 | 000,007,601 | —- | C] () – C:\Users\Joshua\AppData\Local\resmon.resmoncfg
[2012/09/02 01:32:52 | 000,773,482 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/07/07 19:41:41 | 000,451,072 | —- | C] () – C:\Windows\SysWow64\ISSRemoveSP.exe
[2011/07/07 19:37:38 | 000,000,268 | —- | C] () – C:\Windows\SysWow64\RStoneLog2.ini
[2011/07/07 19:37:38 | 000,000,209 | —- | C] () – C:\Windows\SysWow64\RStoneLog.ini

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 01:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 00:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

< End of report >


Symptoms: Startup either goes really fast or takes 2/3 minutes. Slows down to a crawl at 100% CPU usage, but it seems like that comes from Google processes? Videos are unwatchable, flash games are virtually unplayable, Netflix also is slow and stutters. Computer is ok until I try to watch a video, then whole system seems to slow down.

Attachments:

Hi Alyaz,

1)checkup.txt
So I ran this program, got a log, and forgot to save it when I went further along in the process. Now if I try to run it again, it aborts and says I have an unsupported system…

On your next reboot, try and run it again.

=========================

1. Root Directory

As you can see by the information below, your C drive (primary) is running with a very low amount of free space. This most likely is the primary cause of the sluggishness you are experiencing. To help alleviate this issue try and free up some space by removing any unused programs or moving them to an external hard drive. You should try and maintain at least 20% free space on your primary drive.

Drive C: | 283.84 Gb Total Space | 8.19 Gb Free Space | 2.89% Space Free | Partition Type: NTFS

=========================

2. Run OTL.exe

Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE:64bit: - HKLM\..\SearchScopes\{EF0C734F-06CB-4868-8F4E-B1B2329DB6E8}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
    O2 - BHO: (TopArcadeHits Games) - {A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} - C:\Users\Joshua\AppData\Local\TopArcadeHits\Toparcadehits.dll ()
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
    [2013/05/22 00:19:28 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TopArcadeHits
    [2013/05/22 00:19:02 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Local\TopArcadeHits
    [2013/05/06 07:03:22 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade
    [2013/05/06 07:03:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade
    [2013/05/06 07:03:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\GameSpy Arcade
    [2013/05/26 19:13:19 | 000,000,268 | —- | M] () – C:\Windows\tasks\TopArcadeHits.job
    [2013/05/06 07:03:55 | 000,000,996 | —- | C] () – C:\Users\Joshua\Desktop\GameSpy Arcade.lnk
    
    :Files
    C:\ProgramData\flwjycbm.bab
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptyjava]
    [emptyflash]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then re-run OTL and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
=========================

2. P2P - (Peer to Peer)

I see you have/had P2P software Azureus installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections and possibly Identity Theft. It likely contributed to your current situation. This page will give you further information.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

I would strongly recommend that you uninstall this now.

Click Start > Control Panel > Programs and Features. Locate and select the following that are present on the list and click the Remove button:
  • Azureus
If you choose to not remove this programs please refrain from using it until we have finished cleaning your computer.

Please let me know what you decide on Azureus, there are remants we should remove if you decide to uninstall it.

=========================

In your next post please provide the following:

  • OTL fix log
  • OTL.txt
  • checkup.txt (if located)
  • Azureus status
1)OTL fix log

I didn't get one of those, I don't think. It just said to reboot to finish repairing.

2) OTL log

OTL logfile created on: 5/26/2013 10:24:35 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Joshua\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.93 Gb Total Physical Memory | 0.97 Gb Available Physical Memory | 32.92% Memory free
5.86 Gb Paging File | 3.27 Gb Available in Paging File | 55.81% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 283.84 Gb Total Space | 7.82 Gb Free Space | 2.76% Space Free | Partition Type: NTFS
Drive D: | 13.95 Gb Total Space | 2.31 Gb Free Space | 16.54% Space Free | Partition Type: NTFS
Drive E: | 99.34 Mb Total Space | 95.24 Mb Free Space | 95.88% Space Free | Partition Type: FAT32

Computer Name: JOSHUA-PC | User Name: Joshua | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Users\Joshua\Downloads\OTL (4).exe (OldTimer Tools)
PRC - c:\postgreSQL\bin\pg_ctl.exe (PostgreSQL Global Development Group)
PRC - c:\postgreSQL\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ffmpegsumo.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (RtVOsdService) – C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe (Realtek Semiconductor Corp.)
SRV:64bit: - (AERTFilters) – C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe (McAfee, Inc.)
SRV - (HP Support Assistant Service) – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company)
SRV - (postgresql-8.4) – c:\postgreSQL\bin\pg_ctl.exe (PostgreSQL Global Development Group)
SRV - (WinHttpAutoProxySvc) – winhttp.dll (Microsoft Corporation)
SRV - (HPWMISVC) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (WcesComm) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (rtl8192se) – C:\Windows\SysNative\drivers\rtl8192se.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (IntcHdmiAddService) – C:\Windows\SysNative\drivers\IntcHdmi.sys (Intel® Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (usb_rndisx) – C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (xusb21) – C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV - (DrvAgent64) – C:\Windows\SysWOW64\drivers\DrvAgent64.SYS (Phoenix Technologies)
DRV - (WinRing0_1_2_0) – C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys (OpenLibSys.org)
DRV - (RSUSBSTOR) – C:\Windows\SysWOW64\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{B81FBA82-D4E2-4A74-8293-E6DA97C42EA5}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{B81FBA82-D4E2-4A74-8293-E6DA97C42EA5}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{B81FBA82-D4E2-4A74-8293-E6DA97C42EA5}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Google"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0037-ABCDEFFEDCBA%7D:6.0.37
FF - prefs.js..extensions.enabledAddons: %7B0113D088-8ED1-468C-B225-585A9C53B5E3%7D:1.0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Joshua\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Joshua\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/22 03:19:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/08 23:25:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2013/05/22 00:19:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Joshua\AppData\Roaming\Mozilla\Extensions
[2013/05/22 00:19:18 | 000,000,000 | —D | M] (No name found) – C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\ai252rld.default\extensions
[2013/05/22 00:19:18 | 000,000,000 | —D | M] (TopArcadeHits) – C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\ai252rld.default\extensions\{0113D088-8ED1-468C-B225-585A9C53B5E3}
[2012/12/20 14:42:14 | 000,679,123 | —- | M] () (No name found) – C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\ai252rld.default\extensions\[removed]
[2013/03/08 23:25:13 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/03/08 23:25:13 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2013/03/08 23:25:54 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2013/03/08 23:25:33 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013/03/08 23:25:33 | 000,002,086 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Talk Plugin Video Renderer (Enabled) = C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npo1d.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll
CHR - plugin: McAfee Security Scanner + (Enabled) = C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll
CHR - plugin: Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - plugin: Java Deployment Toolkit 7.0.210.11 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - Extension: RuneScape = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajjblpfpopipimofkhbglcoeknpnfijj\1.1_0\
CHR - Extension: Splendid = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdfkbdkkfmmckaadapdipihjfaacnkgd\3_0\
CHR - Extension: WOT = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.4.12_0\
CHR - Extension: Adblock Plus = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.4_0\
CHR - Extension: RollApps = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhikinngnhnkeknickhgpdjhomepafhj\1.0.0.1_0\
CHR - Extension: High Contrast = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\djcfdncoelnlbldjfhinnjlhdjlikmph\0.5_0\
CHR - Extension: Google Launcher = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgjhjbiflegkfaoacjdgjggidcpbidk\2.7_0\
CHR - Extension: imgur Extension by Metronomik = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehoopddfhgaehhmphfcooacjdpmbjlao\2.0.4_0\
CHR - Extension: Mini Maps = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbfnldkfkplmmmbfnjkdbbhjbopnocda\2.0.3_0\
CHR - Extension: 1-ClickWeather for Chrome = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgmbighdoomjmebfbgplfmhcdbomjkoa\1.1.0.3_0\
CHR - Extension: TinEye Reverse Image Search = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl\1.1.2_0\
CHR - Extension: Desktop Wallpaper Tool = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfhbpblckhcihdkoogjmgfpkpnfndel\1.0_0\
CHR - Extension: SuperSorter = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjebfgojnlefhdgmomncgjglmdckngij\0.4.3_0\
CHR - Extension: Crackle = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibfamoapbmmmlknoopmmfofgladlinic\7.1.7_0\
CHR - Extension: Cool Clock = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\icegcmhgphfkgglbljbkdegiaaihifce\3.0_0\
CHR - Extension: FB unseen = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcedcpmfdpjijiamkaeaefgfagnnpei\0.1.6.6_0\
CHR - Extension: Yet Another Google Bookmarks Extension = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdnejaepfmacfdmhkplckpfdcjgbeode\1.32_0\
CHR - Extension: Reddit Enhancement Suite = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb\4.2.0.1_0\
CHR - Extension: StumbleUpon = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcahibnffhnnjcedflmchmokndkjnhpg\5.4.23.1_0\
CHR - Extension: Google Voice (by Google) = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcnhkahnjcbndmmehfkdnkjomaanaooo\2.4.1_0\
CHR - Extension: PadMapper = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\lljagjbdinjommccodelnfmkepbdoafl\1_0\
CHR - Extension: Word\u00B2 = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpibnckjjeaabeepofhfmmpjmnomohee\2.5_0\
CHR - Extension: Google Mail Multi-Account Checker = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcpnehokodklgijkcakcfmccgpanipfp\2.0.24_0\
CHR - Extension: Mint = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhgffcfekbglhpcdjkhhjekhdnddkflg\1.5_0\
CHR - Extension: Quick Note = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\mijlebbfndhelmdpmllgcfadlkankhok\1.4.8_0\
CHR - Extension: Ghostery = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\4.1.1_0\
CHR - Extension: Diet Diary = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\neckeibmjhibmgoigmffjlihekefmffd\1.1_0\
CHR - Extension: Facebook Notifications = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmameahlembdcigphohgiodcgjomcgeo\1.27_0\
CHR - Extension: G+ Images Hover Zoom = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadickpipbiodolpmnhnfkloanjmjbjn\0.4_0\
CHR - Extension: Bookmax = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofjpkfadmfhloombfmmlllnbhkoehckm\2.2_0\
CHR - Extension: Enhanced Steam = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg\3.2_0\
CHR - Extension: YTshowRating = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\olohkebleofongajeodnhideeiapohgi\1.0.7_0\

O1 HOSTS File: ([2012/09/22 16:28:26 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (MP3 Rocket Downloader) - {c5e9c0b3-8b18-4b1b-ad67-c1a063ab2b34} - mscoree.dll (Microsoft Corporation)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtkOSD] C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe (Realtek Semiconductor Corp.)
O4:64bit: - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKCU..\Run: [ShowBatteryBar] C:\Program Files\BatteryBar\ShowBatteryBar.exe ()
O4 - Startup: C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Pokeit.lnk = C:\Users\Joshua\AppData\Local\Pokeit\Pokeit.exe (Pokeit LLC)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F4F0062C-F2A6-4A0F-949E-AAFAEA641171}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - Explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/05/26 21:36:44 | 000,000,000 | —D | C] – C:\_OTL
[2013/05/26 19:27:42 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/05/26 19:27:28 | 000,000,000 | —D | C] – C:\JRT
[2013/05/26 13:59:54 | 000,545,954 | —- | C] (Oleg N. Scherbakov) – C:\Users\Joshua\Desktop\JRT.exe
[2013/05/26 13:56:48 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Joshua\Desktop\aswMBR.exe
[2013/05/22 03:29:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/05/22 00:26:16 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2013/05/22 00:26:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2013/05/22 00:26:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\SpeedFan
[2013/05/21 19:36:46 | 000,000,000 | —D | C] – C:\Windows\pss
[2013/05/21 17:12:58 | 000,000,000 | —D | C] – C:\Users\Joshua\SyncFolder
[2013/05/21 17:09:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\JustCloud
[2013/05/21 08:11:40 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\Photobucket
[2013/05/21 08:10:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photobucket Backup
[2013/05/21 08:10:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Photobucket Backup
[2013/05/21 08:05:10 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\GameSave Manager 3
[2013/05/18 04:50:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fallout FIXT
[2013/05/16 22:01:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/05/16 21:59:44 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2013/05/16 21:59:42 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2013/05/16 21:59:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2013/05/16 21:59:42 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013/05/16 03:59:31 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\FairyBloomRe
[2013/05/14 23:39:11 | 009,195,912 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2013/05/08 00:11:57 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\Beat Hazard
[2013/05/04 01:32:39 | 000,000,000 | —D | C] – C:\Windows\WindowsMobile
[2013/04/28 03:52:22 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Local\tt
[2013/04/28 03:51:50 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Local\Ticket to Ride
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Joshua\*.tmp files -> C:\Users\Joshua\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/05/26 22:30:01 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-330554514-1544093356-3601766899-1001UA.job
[2013/05/26 21:59:08 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/26 21:59:08 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/26 21:56:32 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/26 21:51:33 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/05/26 21:51:27 | 2361,589,760 | -HS- | M] () – C:\hiberfil.sys
[2013/05/26 21:32:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/26 20:06:17 | 000,000,531 | —- | M] () – C:\Users\Joshua\Desktop\MBR.zip
[2013/05/26 16:28:57 | 000,000,512 | —- | M] () – C:\Users\Joshua\Desktop\MBR.dat
[2013/05/26 14:00:05 | 000,545,954 | —- | M] (Oleg N. Scherbakov) – C:\Users\Joshua\Desktop\JRT.exe
[2013/05/26 13:59:36 | 000,632,031 | —- | M] () – C:\Users\Joshua\Desktop\AdwCleaner.exe
[2013/05/26 13:58:23 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Joshua\Desktop\aswMBR.exe
[2013/05/26 13:56:07 | 000,890,854 | —- | M] () – C:\Users\Joshua\Desktop\SecurityCheck.exe
[2013/05/24 05:30:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-330554514-1544093356-3601766899-1001Core.job
[2013/05/23 18:32:58 | 000,002,183 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/05/22 13:07:19 | 000,002,279 | —- | M] () – C:\Users\Joshua\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/05/22 04:17:16 | 000,007,601 | —- | M] () – C:\Users\Joshua\AppData\Local\resmon.resmoncfg
[2013/05/22 00:26:17 | 000,001,007 | —- | M] () – C:\Users\Joshua\Desktop\SpeedFan.lnk
[2013/05/22 00:26:10 | 000,000,045 | —- | M] () – C:\Windows\SysWow64\initdebug.nfo
[2013/05/21 19:35:19 | 000,779,266 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/05/21 19:35:19 | 000,660,530 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/05/21 19:35:19 | 000,121,426 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/05/21 17:12:58 | 000,001,625 | —- | M] () – C:\Users\Joshua\Desktop\Sync Folder.lnk
[2013/05/21 08:11:40 | 000,000,104 | —- | M] () – C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2013/05/18 04:50:16 | 000,001,377 | —- | M] () – C:\Users\Public\Desktop\Fallout FIXT.lnk
[2013/05/16 22:01:24 | 000,001,783 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/05/16 03:18:59 | 000,002,014 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2013/05/15 00:09:31 | 000,000,336 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForJoshua.job
[2013/05/14 23:39:27 | 009,195,912 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2013/05/07 11:23:36 | 000,866,720 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npdeployJava1.dll
[2013/05/07 11:23:36 | 000,788,896 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/05/04 01:34:26 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Joshua\*.tmp files -> C:\Users\Joshua\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/05/26 20:06:17 | 000,000,531 | —- | C] () – C:\Users\Joshua\Desktop\MBR.zip
[2013/05/26 16:28:57 | 000,000,512 | —- | C] () – C:\Users\Joshua\Desktop\MBR.dat
[2013/05/26 13:59:27 | 000,632,031 | —- | C] () – C:\Users\Joshua\Desktop\AdwCleaner.exe
[2013/05/26 13:56:01 | 000,890,854 | —- | C] () – C:\Users\Joshua\Desktop\SecurityCheck.exe
[2013/05/22 03:29:19 | 000,002,279 | —- | C] () – C:\Users\Joshua\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/05/22 03:29:19 | 000,002,183 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/05/22 03:27:39 | 000,000,898 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/22 03:27:38 | 000,000,894 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/22 00:26:17 | 000,001,007 | —- | C] () – C:\Users\Joshua\Desktop\SpeedFan.lnk
[2013/05/22 00:26:09 | 000,000,045 | —- | C] () – C:\Windows\SysWow64\initdebug.nfo
[2013/05/21 20:24:10 | 000,001,942 | —- | C] () – C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Pokeit.lnk
[2013/05/21 17:12:58 | 000,001,625 | —- | C] () – C:\Users\Joshua\Desktop\Sync Folder.lnk
[2013/05/21 08:11:40 | 000,000,104 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2013/05/18 04:50:16 | 000,001,377 | —- | C] () – C:\Users\Public\Desktop\Fallout FIXT.lnk
[2013/05/16 22:01:24 | 000,001,783 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/05/04 01:34:26 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
[2013/05/04 01:33:43 | 000,002,419 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Mobile Device Center.lnk
[2012/12/14 23:59:55 | 000,080,896 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2012/11/12 15:58:43 | 000,000,016 | —- | C] () – C:\Users\Joshua\persistent_state
[2012/10/05 01:17:50 | 000,000,198 | —- | C] () – C:\Users\Joshua\AppData\Roaming\wklnhst.dat
[2012/09/23 01:33:47 | 000,007,601 | —- | C] () – C:\Users\Joshua\AppData\Local\resmon.resmoncfg
[2012/09/02 01:32:52 | 000,773,482 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/07/07 19:41:41 | 000,451,072 | —- | C] () – C:\Windows\SysWow64\ISSRemoveSP.exe
[2011/07/07 19:37:38 | 000,000,268 | —- | C] () – C:\Windows\SysWow64\RStoneLog2.ini
[2011/07/07 19:37:38 | 000,000,209 | —- | C] () – C:\Windows\SysWow64\RStoneLog.ini

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 01:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 00:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

< End of report >

3)checkup.txt

Results of screen317's Security Check version 0.99.64
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Adobe Reader 9 Adobe Reader out of Date!
Mozilla Firefox 19.0.2 Firefox out of Date!
Google Chrome 27.0.1453.93
Google Chrome 27.0.1453.94
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````

4)Azureus/deleting things

I actually tried to delete Vuze - says that no JVS(?) can be found on my system? Also, I went to Add/Delete programs…a lot of my things don't show any size listed. I have downloaded a LOT of games via Steam -would those count towards the space?…DRM aside, I don't think it'd be an issue to uninstall them. Also, I have a postgreSQL program that says 108GB…I'm worried about taking it out, as I don't know what it is and google hasn't really been helpful on it.
Hi Alyaz,

1. postgreSQL program that says 108GB

Here is some information that might help you decide if you should remove that program:
http://www.postgresql.org/
http://en.wikipedia.org/wiki/PostgreSQL

=========================

1. Uninstall via Programs and Features

Click Start > Control Panel > Programs and Features. Locate and select the following that are present on the list and click the Remove button:

  • McAfee Security Scan

=========================

2. Run OTL.exe

Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
    CHR - plugin: McAfee Security Scanner + (Enabled) = C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll
    
    :Files
    C:\Users\Joshua\AppData\Roaming\Azureus
    C:\Program Files (x86)\McAfee Security Scan
    
    :Services
    McComponentHostService
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
=========================

3. Malwarebytes' Anti-Malware

Please download Malwarebytes' Anti-Malware to your desktop.

  • Right click and select "Run as Administrator" mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]

  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
=========================
4. ESET Online Scanner

*Note:
  • It is recommended to disable on-board antivirus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
  • Please don't go surfing while your resident protection is disabled!
  • Once the scan is finished remember to re-enable your antivirus along with your anti-spyware programs.
** You need to run your browser with Administrator Rights, to do so right click your browsers short cut and select "Run as Administrator".

= = = = = = = = = = = = = = = = = = = =

Go here to run ESET Online Scanner

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.
=========================

In your next post please provide the following:
  • OTL fix log
  • MBAM log
  • ESET's log.txt
Still no OTL fix log… MBAM: Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.05.27.01 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Joshua :: JOSHUA-PC [administrator] 5/27/2013 3:13:28 AM mbam-log-2013-05-27 (03-13-28).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 265891 Time elapsed: 12 minute(s), 8 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ESET didn't generate a report that I could see, unless this is it: C:\Program Files (x86)\Coupon Companion\Coupon Companion.dll Win32/Toolbar.CrossRider application C:\ProgramData\Tarma Installer\{C049526F-B3EB-4151-9B11-B11F00F53A96}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application C:\Users\Joshua\Downloads\cnet2_Chipset Driver Intel Ver_8_3_0_1010_zip.exe a variant of Win32/InstallCore.D application C:\Users\Joshua\Downloads\EFdownloader (1).exe a variant of Win32/ExpressFiles application C:\Users\Joshua\Downloads\EFdownloader (2).exe a variant of Win32/ExpressFiles application C:\Users\Joshua\Downloads\EFdownloader.exe a variant of Win32/ExpressFiles application C:\Users\Joshua\Downloads\WinZip165 (1).exe a variant of Win32/OpenInstall application C:\Users\Joshua\Downloads\WinZip165.exe a variant of Win32/OpenInstall application
Hi Alyaz,

1. Run OTL.exe

Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Files
    C:\Program Files (x86)\Coupon Companion
    C:\ProgramData\Tarma Installer\{C049526F-B3EB-4151-9B11-B11F00F53A96}\_Setupx.dll
    C:\Users\Joshua\Downloads\cnet2_Chipset Driver Intel Ver_8_3_0_1010_zip.exe
    C:\Users\Joshua\Downloads\EFdownloader (1).exe
    C:\Users\Joshua\Downloads\EFdownloader (2).exe
    C:\Users\Joshua\Downloads\EFdownloader.exe
    C:\Users\Joshua\Downloads\WinZip165 (1).exe
    C:\Users\Joshua\Downloads\WinZip165.exe
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then re-run OTL and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
=========================

In your next post please provide the following:
  • OTL.txt
  • Hows the computer running?
All processes killed
========== FILES ==========
File\Folder C:\Program Files (x86)\Coupon Companion not found.
File\Folder C:\ProgramData\Tarma Installer\{C049526F-B3EB-4151-9B11-B11F00F53A96}\_Setupx.dll not found.
File\Folder C:\Users\Joshua\Downloads\cnet2_Chipset Driver Intel Ver_8_3_0_1010_zip.exe not found.
File\Folder C:\Users\Joshua\Downloads\EFdownloader (1).exe not found.
File\Folder C:\Users\Joshua\Downloads\EFdownloader (2).exe not found.
File\Folder C:\Users\Joshua\Downloads\EFdownloader.exe not found.
File\Folder C:\Users\Joshua\Downloads\WinZip165 (1).exe not found.
File\Folder C:\Users\Joshua\Downloads\WinZip165.exe not found.
========== COMMANDS ==========
Restore point Set: OTL Restore Point

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User

User: Joshua
->Temp folder emptied: 366974 bytes
->Temporary Internet Files folder emptied: 43654674 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 272842937 bytes
->Flash cache emptied: 856 bytes

User: postgres
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: postgres.Joshua-PC
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 10456 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 302.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 05272013_205532

Files\Folders moved on Reboot…
C:\Users\Joshua\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…

—

OTL logfile created on: 5/27/2013 9:09:03 PM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Joshua\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.93 Gb Total Physical Memory | 1.25 Gb Available Physical Memory | 42.74% Memory free
5.86 Gb Paging File | 3.58 Gb Available in Paging File | 61.09% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 283.84 Gb Total Space | 39.75 Gb Free Space | 14.00% Space Free | Partition Type: NTFS
Drive D: | 13.95 Gb Total Space | 2.31 Gb Free Space | 16.54% Space Free | Partition Type: NTFS
Drive E: | 99.34 Mb Total Space | 95.24 Mb Free Space | 95.88% Space Free | Partition Type: FAT32
Drive F: | 207.96 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: JOSHUA-PC | User Name: Joshua | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Users\Joshua\Downloads\OTL (4).exe (OldTimer Tools)
PRC - c:\postgreSQL\bin\pg_ctl.exe (PostgreSQL Global Development Group)
PRC - c:\postgreSQL\bin\postgres.exe (PostgreSQL Global Development Group)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ffmpegsumo.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (RtVOsdService) – C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe (Realtek Semiconductor Corp.)
SRV:64bit: - (AERTFilters) – C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (HP Support Assistant Service) – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company)
SRV - (postgresql-8.4) – c:\postgreSQL\bin\pg_ctl.exe (PostgreSQL Global Development Group)
SRV - (WinHttpAutoProxySvc) – winhttp.dll (Microsoft Corporation)
SRV - (HPWMISVC) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (WcesComm) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (rtl8192se) – C:\Windows\SysNative\drivers\rtl8192se.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (IntcHdmiAddService) – C:\Windows\SysNative\drivers\IntcHdmi.sys (Intel® Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (usb_rndisx) – C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (xusb21) – C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV - (DrvAgent64) – C:\Windows\SysWOW64\drivers\DrvAgent64.SYS (Phoenix Technologies)
DRV - (WinRing0_1_2_0) – C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys (OpenLibSys.org)
DRV - (RSUSBSTOR) – C:\Windows\SysWOW64\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{B81FBA82-D4E2-4A74-8293-E6DA97C42EA5}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{B81FBA82-D4E2-4A74-8293-E6DA97C42EA5}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKCU\..\SearchScopes,DefaultScope = {B81FBA82-D4E2-4A74-8293-E6DA97C42EA5}
IE - HKCU\..\SearchScopes\{B81FBA82-D4E2-4A74-8293-E6DA97C42EA5}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Google"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0037-ABCDEFFEDCBA%7D:6.0.37
FF - prefs.js..extensions.enabledAddons: %7B0113D088-8ED1-468C-B225-585A9C53B5E3%7D:1.0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Joshua\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Joshua\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/22 03:19:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/08 23:25:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2013/05/22 00:19:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Joshua\AppData\Roaming\Mozilla\Extensions
[2013/05/22 00:19:18 | 000,000,000 | —D | M] (No name found) – C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\ai252rld.default\extensions
[2013/05/22 00:19:18 | 000,000,000 | —D | M] (TopArcadeHits) – C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\ai252rld.default\extensions\{0113D088-8ED1-468C-B225-585A9C53B5E3}
[2012/12/20 14:42:14 | 000,679,123 | —- | M] () (No name found) – C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\ai252rld.default\extensions\[removed]
[2013/03/08 23:25:13 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/03/08 23:25:13 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2013/03/08 23:25:54 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2013/03/08 23:25:33 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013/03/08 23:25:33 | 000,002,086 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Talk Plugin Video Renderer (Enabled) = C:\Users\Joshua\AppData\Roaming\Mozilla\plugins\npo1d.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll
CHR - plugin: McAfee Security Scanner + (Enabled) = C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll
CHR - plugin: Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - plugin: Java Deployment Toolkit 7.0.210.11 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - Extension: RuneScape = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajjblpfpopipimofkhbglcoeknpnfijj\1.1_0\
CHR - Extension: Splendid = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdfkbdkkfmmckaadapdipihjfaacnkgd\3_0\
CHR - Extension: WOT = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.4.12_0\
CHR - Extension: Adblock Plus = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.4_0\
CHR - Extension: RollApps = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhikinngnhnkeknickhgpdjhomepafhj\1.0.0.1_0\
CHR - Extension: High Contrast = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\djcfdncoelnlbldjfhinnjlhdjlikmph\0.5_0\
CHR - Extension: Google Launcher = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgjhjbiflegkfaoacjdgjggidcpbidk\2.7_0\
CHR - Extension: imgur Extension by Metronomik = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehoopddfhgaehhmphfcooacjdpmbjlao\2.0.4_0\
CHR - Extension: Mini Maps = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbfnldkfkplmmmbfnjkdbbhjbopnocda\2.0.3_0\
CHR - Extension: 1-ClickWeather for Chrome = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgmbighdoomjmebfbgplfmhcdbomjkoa\1.1.0.3_0\
CHR - Extension: TinEye Reverse Image Search = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl\1.1.2_0\
CHR - Extension: Desktop Wallpaper Tool = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfhbpblckhcihdkoogjmgfpkpnfndel\1.0_0\
CHR - Extension: SuperSorter = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjebfgojnlefhdgmomncgjglmdckngij\0.4.3_0\
CHR - Extension: Crackle = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibfamoapbmmmlknoopmmfofgladlinic\7.1.7_0\
CHR - Extension: Cool Clock = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\icegcmhgphfkgglbljbkdegiaaihifce\3.0_0\
CHR - Extension: FB unseen = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcedcpmfdpjijiamkaeaefgfagnnpei\0.1.6.6_0\
CHR - Extension: Yet Another Google Bookmarks Extension = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdnejaepfmacfdmhkplckpfdcjgbeode\1.32_0\
CHR - Extension: Reddit Enhancement Suite = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb\4.2.0.1_0\
CHR - Extension: StumbleUpon = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcahibnffhnnjcedflmchmokndkjnhpg\5.4.23.1_0\
CHR - Extension: Google Voice (by Google) = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcnhkahnjcbndmmehfkdnkjomaanaooo\2.4.1_0\
CHR - Extension: PadMapper = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\lljagjbdinjommccodelnfmkepbdoafl\1_0\
CHR - Extension: Word\u00B2 = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpibnckjjeaabeepofhfmmpjmnomohee\2.5_0\
CHR - Extension: Google Mail Multi-Account Checker = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcpnehokodklgijkcakcfmccgpanipfp\2.0.24_0\
CHR - Extension: Mint = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhgffcfekbglhpcdjkhhjekhdnddkflg\1.5_0\
CHR - Extension: Quick Note = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\mijlebbfndhelmdpmllgcfadlkankhok\1.4.8_0\
CHR - Extension: Ghostery = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\4.1.1_0\
CHR - Extension: Diet Diary = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\neckeibmjhibmgoigmffjlihekefmffd\1.1_0\
CHR - Extension: Facebook Notifications = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmameahlembdcigphohgiodcgjomcgeo\1.27_0\
CHR - Extension: G+ Images Hover Zoom = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadickpipbiodolpmnhnfkloanjmjbjn\0.4_0\
CHR - Extension: Bookmax = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofjpkfadmfhloombfmmlllnbhkoehckm\2.2_0\
CHR - Extension: Enhanced Steam = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg\3.3_0\
CHR - Extension: YTshowRating = C:\Users\Joshua\AppData\Local\Google\Chrome\User Data\Default\Extensions\olohkebleofongajeodnhideeiapohgi\1.0.7_0\

O1 HOSTS File: ([2012/09/22 16:28:26 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MP3 Rocket Downloader) - {c5e9c0b3-8b18-4b1b-ad67-c1a063ab2b34} - mscoree.dll (Microsoft Corporation)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtkOSD] C:\Program Files (x86)\Realtek\Audio\OSD\RtVOsd64.exe (Realtek Semiconductor Corp.)
O4:64bit: - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKCU..\Run: [ShowBatteryBar] C:\Program Files\BatteryBar\ShowBatteryBar.exe ()
O4 - Startup: C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Pokeit.lnk = C:\Users\Joshua\AppData\Local\Pokeit\Pokeit.exe (Pokeit LLC)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F4F0062C-F2A6-4A0F-949E-AAFAEA641171}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - Explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/25 21:51:20 | 000,000,025 | R— | M] () - F:\AUTORUN.INF – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/05/27 18:20:12 | 000,692,104 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/05/27 18:20:12 | 000,071,048 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/05/27 03:28:20 | 002,347,384 | —- | C] (ESET) – C:\Users\Joshua\Desktop\esetsmartinstaller_enu (2).exe
[2013/05/27 03:12:38 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\Malwarebytes
[2013/05/27 03:11:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/05/27 03:11:30 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/05/27 03:11:26 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/05/27 03:11:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/05/27 03:09:40 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Local\Programs
[2013/05/27 02:29:28 | 010,285,040 | —- | C] (Malwarebytes Corporation ) – C:\Users\Joshua\Desktop\mbam-setup-1.75.0.1300.exe
[2013/05/26 21:36:44 | 000,000,000 | —D | C] – C:\_OTL
[2013/05/26 19:27:42 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/05/26 19:27:28 | 000,000,000 | —D | C] – C:\JRT
[2013/05/26 13:59:54 | 000,545,954 | —- | C] (Oleg N. Scherbakov) – C:\Users\Joshua\Desktop\JRT.exe
[2013/05/26 13:56:48 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Joshua\Desktop\aswMBR.exe
[2013/05/22 03:29:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/05/22 00:26:16 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2013/05/22 00:26:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2013/05/22 00:26:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\SpeedFan
[2013/05/21 19:36:46 | 000,000,000 | —D | C] – C:\Windows\pss
[2013/05/21 17:12:58 | 000,000,000 | —D | C] – C:\Users\Joshua\SyncFolder
[2013/05/21 17:09:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\JustCloud
[2013/05/21 08:11:40 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\Photobucket
[2013/05/21 08:10:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photobucket Backup
[2013/05/21 08:10:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Photobucket Backup
[2013/05/21 08:05:10 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\GameSave Manager 3
[2013/05/18 04:50:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fallout FIXT
[2013/05/16 22:01:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/05/16 21:59:44 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2013/05/16 21:59:42 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2013/05/16 21:59:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2013/05/16 21:59:42 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013/05/16 03:59:31 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\FairyBloomRe
[2013/05/14 23:39:11 | 009,195,912 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2013/05/08 00:11:57 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Roaming\Beat Hazard
[2013/05/04 01:32:39 | 000,000,000 | —D | C] – C:\Windows\WindowsMobile
[2013/04/28 03:52:22 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Local\tt
[2013/04/28 03:51:50 | 000,000,000 | —D | C] – C:\Users\Joshua\AppData\Local\Ticket to Ride
[1 C:\Users\Joshua\*.tmp files -> C:\Users\Joshua\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/05/27 21:06:37 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/27 21:06:37 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/27 20:59:04 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/27 20:58:44 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/05/27 20:58:38 | 2361,589,760 | -HS- | M] () – C:\hiberfil.sys
[2013/05/27 20:32:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/27 20:30:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-330554514-1544093356-3601766899-1001UA.job
[2013/05/27 18:20:13 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/05/27 18:20:12 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/05/27 05:30:02 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-330554514-1544093356-3601766899-1001Core.job
[2013/05/27 03:28:23 | 002,347,384 | —- | M] (ESET) – C:\Users\Joshua\Desktop\esetsmartinstaller_enu (2).exe
[2013/05/27 03:11:41 | 000,001,109 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/05/27 02:29:48 | 010,285,040 | —- | M] (Malwarebytes Corporation ) – C:\Users\Joshua\Desktop\mbam-setup-1.75.0.1300.exe
[2013/05/26 20:06:17 | 000,000,531 | —- | M] () – C:\Users\Joshua\Desktop\MBR.zip
[2013/05/26 16:28:57 | 000,000,512 | —- | M] () – C:\Users\Joshua\Desktop\MBR.dat
[2013/05/26 14:00:05 | 000,545,954 | —- | M] (Oleg N. Scherbakov) – C:\Users\Joshua\Desktop\JRT.exe
[2013/05/26 13:59:36 | 000,632,031 | —- | M] () – C:\Users\Joshua\Desktop\AdwCleaner.exe
[2013/05/26 13:58:23 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Joshua\Desktop\aswMBR.exe
[2013/05/26 13:56:07 | 000,890,854 | —- | M] () – C:\Users\Joshua\Desktop\SecurityCheck.exe
[2013/05/23 18:32:58 | 000,002,183 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/05/22 13:07:19 | 000,002,279 | —- | M] () – C:\Users\Joshua\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/05/22 04:17:16 | 000,007,601 | —- | M] () – C:\Users\Joshua\AppData\Local\resmon.resmoncfg
[2013/05/22 00:26:17 | 000,001,007 | —- | M] () – C:\Users\Joshua\Desktop\SpeedFan.lnk
[2013/05/22 00:26:10 | 000,000,045 | —- | M] () – C:\Windows\SysWow64\initdebug.nfo
[2013/05/21 19:35:19 | 000,779,266 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/05/21 19:35:19 | 000,660,530 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/05/21 19:35:19 | 000,121,426 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/05/21 17:12:58 | 000,001,625 | —- | M] () – C:\Users\Joshua\Desktop\Sync Folder.lnk
[2013/05/21 08:11:40 | 000,000,104 | —- | M] () – C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2013/05/18 04:50:16 | 000,001,377 | —- | M] () – C:\Users\Public\Desktop\Fallout FIXT.lnk
[2013/05/16 22:01:24 | 000,001,783 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/05/16 03:18:59 | 000,002,014 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2013/05/15 00:09:31 | 000,000,336 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForJoshua.job
[2013/05/14 23:39:27 | 009,195,912 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2013/05/07 11:23:36 | 000,866,720 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npdeployJava1.dll
[2013/05/07 11:23:36 | 000,788,896 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/05/04 01:34:26 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
[1 C:\Users\Joshua\*.tmp files -> C:\Users\Joshua\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/05/27 03:11:41 | 000,001,109 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/05/26 20:06:17 | 000,000,531 | —- | C] () – C:\Users\Joshua\Desktop\MBR.zip
[2013/05/26 16:28:57 | 000,000,512 | —- | C] () – C:\Users\Joshua\Desktop\MBR.dat
[2013/05/26 13:59:27 | 000,632,031 | —- | C] () – C:\Users\Joshua\Desktop\AdwCleaner.exe
[2013/05/26 13:56:01 | 000,890,854 | —- | C] () – C:\Users\Joshua\Desktop\SecurityCheck.exe
[2013/05/22 03:29:19 | 000,002,279 | —- | C] () – C:\Users\Joshua\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/05/22 03:29:19 | 000,002,183 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/05/22 03:27:39 | 000,000,898 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/22 03:27:38 | 000,000,894 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/22 00:26:17 | 000,001,007 | —- | C] () – C:\Users\Joshua\Desktop\SpeedFan.lnk
[2013/05/22 00:26:09 | 000,000,045 | —- | C] () – C:\Windows\SysWow64\initdebug.nfo
[2013/05/21 20:24:10 | 000,001,942 | —- | C] () – C:\Users\Joshua\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Pokeit.lnk
[2013/05/21 17:12:58 | 000,001,625 | —- | C] () – C:\Users\Joshua\Desktop\Sync Folder.lnk
[2013/05/21 08:11:40 | 000,000,104 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2013/05/18 04:50:16 | 000,001,377 | —- | C] () – C:\Users\Public\Desktop\Fallout FIXT.lnk
[2013/05/16 22:01:24 | 000,001,783 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/05/04 01:34:26 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
[2013/05/04 01:33:43 | 000,002,419 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Mobile Device Center.lnk
[2012/12/14 23:59:55 | 000,080,896 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2012/11/12 15:58:43 | 000,000,016 | —- | C] () – C:\Users\Joshua\persistent_state
[2012/10/05 01:17:50 | 000,000,198 | —- | C] () – C:\Users\Joshua\AppData\Roaming\wklnhst.dat
[2012/09/23 01:33:47 | 000,007,601 | —- | C] () – C:\Users\Joshua\AppData\Local\resmon.resmoncfg
[2012/09/02 01:32:52 | 000,773,482 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/07/07 19:41:41 | 000,451,072 | —- | C] () – C:\Windows\SysWow64\ISSRemoveSP.exe
[2011/07/07 19:37:38 | 000,000,268 | —- | C] () – C:\Windows\SysWow64\RStoneLog2.ini
[2011/07/07 19:37:38 | 000,000,209 | —- | C] () – C:\Windows\SysWow64\RStoneLog.ini

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 01:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 00:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

< End of report >

The computer itself seems to be ok, for the most part. The issues are still coming from videos (Netflix, Youtube, etc.) and Steam FB games with stuttering video and sometimes scratchy sounding audio. The audio issues aren't happening with things like iTunes, and I can watch a DVD without issue so I'm hoping that doesn't been hardware problems, but it almost seems like overkill to completely restore to factory..
Hi Alyaz,

The computer itself seems to be ok, for the most part. The issues are still coming from videos (Netflix, Youtube, etc.) and Steam FB games with stuttering video and sometimes scratchy sounding audio. The audio issues aren't happening with things like iTunes, and I can watch a DVD without issue so I'm hoping that doesn't been hardware problems, but it almost seems like overkill to completely restore to factory..

In this part of the forum we generally focus on malware related issues. Sometimes it can be a fuzzy line and we can offer limited suggestions on how to correct some issues. (like what you are experiencing). If you like after we finish here I can refer you to our Tech Team. They might have a better idea of how to correct the sluggish issue with video streaming.

Although you have freed up some space on you primary drive you still might be plagued with low system resources for the tasks you are trying to accomplish.

I don't think a complete restore to factory settings will resolve this issue. Here are a few suggestions:

=========================

1. RAM - Random Access Memory and Hard Drive

Your computer's configuration (RAM - Random Access Memory) 2.93 Gb Total Physical Memory might be considered at the low end of what is needed to run at a smooth level.

To help improve this situation you have a few options:
  • Upgrade to a new computer
  • Upgarde your current computers RAM
  • Move as much programs, data to an external hard drive
Obviously, these options come with a financial commitment.

=========================

2. SpeedTest

Since you are having difficulty streaming videos and playing online games your Internet connection might be a contributing factor also.

As far as your Internet connection you can go here and do a speed test.

http://www.speedtest.net/

=========================

3. Disable Plug-ins in Google Chrome

  • Click the Chrome menu [external image: Posted Image] on the browser toolbar.
  • Select Settings.
  • Scroll down to Show advanced settings…
  • Locate the Privacy Section, select Content Settings
  • In the pop up window scoll to Plug-Ins, select Disable individual plug-ins…
  • Locate the following plug-ins and set them to Disable:
    • McAfee Security Scanner
  • Exit Chrome settings menu.
=========================

4. Run OTL.exe

Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    [2013/05/22 00:19:18 | 000,000,000 | —D | M] (TopArcadeHits) – C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\ai252rld.default\extensions\{0113D088-8ED1-468C-B225-585A9C53B5E3}
    
    :Files
    C:\Program Files (x86)\McAfee Security Scan
    
    :Commands
    [createrestorepoint]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
=========================

In your next post please provide the following:
  • What did you find out about your Internet speed?
  • OTL.txt
  • Any remaining issues?
1) Internet speed seems to be about 14 down, 6 up, which seems standard for the service I have. 2)Here's the OTL. txt: ========== OTL ========== C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\ai252rld.default\extensions\{0113D088-8ED1-468C-B225-585A9C53B5E3}\skin folder moved successfully. C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\ai252rld.default\extensions\{0113D088-8ED1-468C-B225-585A9C53B5E3}\chrome\content folder moved successfully. C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\ai252rld.default\extensions\{0113D088-8ED1-468C-B225-585A9C53B5E3}\chrome folder moved successfully. C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\ai252rld.default\extensions\{0113D088-8ED1-468C-B225-585A9C53B5E3} folder moved successfully. ========== FILES ========== File\Folder C:\Program Files (x86)\McAfee Security Scan not found. ========== COMMANDS ========== Restore point Set: OTL Restore Point OTL by OldTimer - Version 3.2.69.0 log created on 05282013_004838 3)There was no McAfee plugin to disable. Still having the same audio/visual video and Steam game issues. *sigh* It doesn't seem like it's a virus or malware issue (which could either be a good thing or a bad thing, depending on severity), so I thank you repeatedly for all or your help in analyzing that aspect of it - you've been amazing. If you don't see anything too pressing with that latest log, could you refer me over to your Tech Team? (It is an older computer, but if I can ride it out 6 months-1 year, that would be awesome.)
Hi Alyaz,

If you don't see anything too pressing with that latest log, could you refer me over to your Tech Team?

Yes I can do that, but first we need to do a bit of housekeeping.

=========================

Your log appears to be clean. :thumbup:

We have a few items to take care of before we get to the All Clean Speech.

=========================

1. Clean up with OTL:
  • Right-click OTL.exe select "Run as Administrator" to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
=========================

2. You can now delete any tools and/or logs remaining on your desktop.

=========================

3. Uninstall via Programs and Features

Click Start > Control Panel > Programs and Features. Locate and select the following that are present on the list and click the Remove button:

  • Adobe Reader 9

=========================

4. Adobe Flash Player:

Go to http://get.adobe.com/flashplayer/?no_ab=1
  • Remove the check mark from the box "Free! McAfee Security Scan Plus"
  • Click the Download button, and follow the onscreen directions to complete the installation.
Please note, depending on your settings, you may have to temporarily disable your antivirus software for the Adobe Reader update.

=========================

5. Update Firefox

  • At the top of the Firefox window, click the Firefox button, go over to the Help sub-menu
  • Click the Check for Updates button
  • Follow the onscreen instructions to update
  • Firefox will close and be reset. Close when finished,
=========================

6. Delete All But the Most Recent Restore Point
  • Open Disk Cleanup by clicking the Start button [external image: Posted Image]. In the search box, type Disk Cleanup, and then, in the list of results, click Disk Cleanup.
  • If prompted, select the drive that you want to clean up, and then click OK.
  • In the Disk Cleanup for (drive letter) dialog box, click Clean up system files. [external image: Posted Image] Administrator permission required If you're prompted for an administrator password or confirmation, type the password or provide confirmation.
  • If prompted, select the drive that you want to clean up, and then click OK.
  • Click the More Options tab, under System Restore and Shadow Copies, click Clean up.
  • In the Disk Cleanup dialog box, click Delete.
  • Click Delete Files, and then click OK.

=========================

With the above items taken care of let's move on to the All Clean part of the process.

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.

Here are some tips to reduce the potential for spyware infection in the future:

Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
Make your Mozilla Firefox more secure - This can be done by adding these add-ons:
Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

Free Anti-Virus
  • Avast Free Antivirus
  • Avira Free Antivirus 2013
  • PC Tools AntiVirus Free
  • Ad-Aware Free Antivirus +
Free Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. A tutorial on firewalls can be found here.
  • Online Armor Free
  • Agnitum Outpost Firewall Free
  • Comodo Firewall
Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI