This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows defender and firewall error messages [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Windows defender gives me error code 0x80070424 and windows firewall gives me error 0x8007042c when I try and start them up. Is this a virus?

OTL logfile created on: 6/16/2013 12:02:20 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Stacy Reffitt\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 6.02 Gb Available Physical Memory | 75.22% Memory free
16.00 Gb Paging File | 13.73 Gb Available in Paging File | 85.83% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.50 Gb Total Space | 697.66 Gb Free Space | 74.90% Space Free | Partition Type: NTFS
Drive D: | 1.77 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: GAMER | User Name: Stacy Reffitt | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Stacy Reffitt\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\TPSrvWow.exe (Panda Security, S.L.)
PRC - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\PavFnSvr.exe (Panda Security, S.L.)
PRC - C:\Program Files (x86)\FS\Spyro Portal\FlashPortal.exe (FS)
PRC - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
PRC - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\psksvc.exe (Panda Security, S.L.)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\WebProxy.exe (Panda Security, S.L.)
PRC - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\FIREWALL\PSHost.exe (Panda Security International)
PRC - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD)
PRC - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\PsCtrlS.exe (Panda Security, S.L.)
PRC - C:\Program Files (x86)\Common Files\Panda Security\PavShld\PavPrSrv.exe (Panda Security, S.L.)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files (x86)\CyberLink\PCM4Everio\EverioService.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files (x86)\CyberLink\PCM4Everio\Kernel\common\CLEverioDetector.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (AMD FUEL Service) – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (ZuneWlanCfgSvc) – C:\Program Files\Zune\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV:64bit: - (WMZuneComm) – C:\Program Files\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV:64bit: - (ZuneNetworkSvc) – C:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (TPSrv) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\TPSrvWow.exe (Panda Security, S.L.)
SRV - (PAVFNSVR) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\PavFnSvr.exe (Panda Security, S.L.)
SRV - (SpyroService) – C:\Program Files (x86)\FS\Spyro Portal\FlashPortal.exe (FS)
SRV - (TomTomHOMEService) – C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (PskSvcRetail) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\psksvc.exe (Panda Security, S.L.)
SRV - (PAVSRV) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\pavsrvx86.exe (Panda Security, S.L.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (PSHost) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\FIREWALL\PSHost.exe (Panda Security International)
SRV - (Amazon Download Agent) – C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe (Amazon.com)
SRV - (Panda Software Controller) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\PsCtrlS.exe (Panda Security, S.L.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (PSIMSVC) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\PsImSvc.exe (Panda Security S.L.)
SRV - (PavPrSrv) – C:\Program Files (x86)\Common Files\Panda Security\PavShld\PavPrSrv.exe (Panda Security, S.L.)
SRV - (CCALib8) – C:\Program Files (x86)\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (grmnusb) – C:\Windows\SysNative\drivers\grmnusb.sys (GARMIN Corp.)
DRV:64bit: - (AODDriver4.2) – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys (Advanced Micro Devices)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (APPFLT) – C:\Windows\SysNative\drivers\APPFLT64.SYS (Panda Security, S.L.)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (MHIKEY10) – C:\Windows\SysNative\drivers\MHIKEY10x64.sys (Generic USB smartcard reader)
DRV:64bit: - (IDSFLT) – C:\Windows\SysNative\drivers\idsflt64.sys (Panda Security, S.L.)
DRV:64bit: - (NETIMFLT01060044) – C:\Windows\SysNative\drivers\n64i1644.sys (Panda Security, S.L.)
DRV:64bit: - (pavboot) – C:\Windows\SysNative\drivers\pavboot64.sys (Panda Security, S.L.)
DRV:64bit: - (AmFSM) – C:\Windows\SysNative\drivers\amm6460.sys (Panda Security, S.L.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (BIOS) – C:\Windows\SysNative\drivers\BIOS64.sys (BIOSTAR Group)
DRV:64bit: - (ShldFlt) – C:\Windows\SysNative\drivers\ShldFlt.sys (Panda Security, S.L.)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (WNMFLT) – C:\Windows\SysNative\drivers\wnmflt64.sys (Panda Security, S.L.)
DRV:64bit: - (NETFLTDI) – C:\Windows\SysNative\drivers\NETTDI64.SYS (Panda Security, S.L.)
DRV:64bit: - (DSAFLT) – C:\Windows\SysNative\drivers\dsaflt64.sys (Panda Security, S.L.)
DRV:64bit: - (FNETMON) – C:\Windows\SysNative\drivers\fnetm64.sys (Panda Security, S.L.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (BIOS) – C:\Windows\SysWOW64\drivers\BIOS64.sys (BIOSTAR Group)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FD 53 20 A8 9B 6A CE 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledAddons: %7B38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1%7D:1.0.3.122
FF - prefs.js..extensions.enabledAddons: %7Bd781118d-2508-4a76-8d0e-e69cdbbaebd2%7D:1.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - prefs.js..extensions.enabledItems: {38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}:[removed]
FF - prefs.js..extensions.enabledItems: {d781118d-2508-4a76-8d0e-e69cdbbaebd2}:1.0
FF - prefs.js..keyword.URL: "http://www.google.com/cse?cx=partner-pub-5528014799800033:cevktqnfrvl&ie=ISO-8859-1&q="
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Users\Stacy Reffitt\AppData\LocalLow\Sony Online Entertainment\npsoe.dll ()
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Stacy Reffitt\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/05/18 12:12:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/05/29 09:23:36 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/05/18 12:12:40 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/05/29 09:23:36 | 000,000,000 | —D | M]

[2011/09/25 18:12:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Extensions
[2011/09/25 18:12:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/10/15 19:12:37 | 000,000,000 | —D | M] (No name found) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Extensions\[removed]
[2013/05/24 18:01:26 | 000,000,000 | —D | M] (No name found) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Firefox\Profiles\sbaw357u.default\extensions
[2012/12/03 22:53:32 | 000,000,000 | —D | M] () – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Firefox\Profiles\sbaw357u.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}
[2013/05/29 09:24:04 | 000,000,000 | —D | M] (XUL Cache) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Firefox\Profiles\sbaw357u.default\extensions\{d781118d-2508-4a76-8d0e-e69cdbbaebd2}
[2013/05/24 18:01:26 | 000,534,261 | —- | M] () (No name found) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Firefox\Profiles\sbaw357u.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2013/05/08 19:59:44 | 000,870,680 | —- | M] () (No name found) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Firefox\Profiles\sbaw357u.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013/05/18 12:12:39 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013/05/18 12:12:39 | 000,000,000 | —D | M] (Default) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011/03/18 14:32:12 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npCouponPrinter.dll
[2012/03/15 19:28:30 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2009/07/31 13:06:48 | 001,654,784 | —- | M] (LizardTech) – C:\Program Files (x86)\mozilla firefox\plugins\npdjvu.dll
[2011/03/18 14:32:14 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npMozCouponPrinter.dll

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AmazonGSDownloaderTray] C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe (Amazon.com)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [APVXDWIN] C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\APVXDWIN.EXE (Panda Security, S.L.)
O4 - HKLM..\Run: [EverioService] C:\Program Files (x86)\CyberLink\PCM4Everio\EverioService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [LogitechGalleryRepair] C:\Program Files (x86)\Logitech\ImageStudio\ISStart.exe (Logitech Inc.)
O4 - HKLM..\Run: [QCDriverInstaller] C:\Program Files (x86)\Common Files\Logitech\QCDriver3\Lqdsw.exe (Logitech Inc.)
O4 - HKLM..\Run: [SCANINICIO] C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\Inicio.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [HydraVisionDesktopManager] C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD)
O4 - HKCU..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden File not found
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - HKCU..\Run: [WebCamRT.exe] File not found
O4 - Startup: C:\Users\Stacy Reffitt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {46D8BEE7-0B27-4466-ABA2-A5F1E157971C} http://63.121.244.73:100/RemoteWeb.cab (Remote200 Control)
O16 - DPF: {5FFDFC21-AE40-4C7C-955C-415A1ACE01C8} http://63.121.244.73:100/VideoViewer.cab (CViewerControl Object)
O16 - DPF: {748E146C-5842-4AD4-8A01-ACA7E61C6FCE} http://24.52.114.10/DvrOcx.cab (Dvr Net 85 Multidownload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3005835A-3760-4F56-B232-177F141A1D0A}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18 - Protocol\Handler\gopher - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\avldr: DllName - (avldr64.dll) - C:\Windows\SysNative\avldr64.dll (On-Access Anti-Malware Scanner Sync)
O20:64bit: - Winlogon\Notify\PFW: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{7f6e6163-f8db-11e1-8b04-0030676a3301}\Shell - "" = AutoRun
O33 - MountPoints2\{7f6e6163-f8db-11e1-8b04-0030676a3301}\Shell\AutoRun\command - "" = E:\TL-Bootstrap.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.voxacm160 - C:\Windows\SysWow64\vct3216.acm (Voxware, Inc.)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/06/15 15:45:03 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\AppData\Roaming\PrimoPDF
[2013/06/15 15:28:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrimoPDF
[2013/06/15 15:28:00 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\AppData\Roaming\OpenCandy
[2013/06/15 15:27:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Nitro PDF
[2013/06/11 17:15:54 | 000,751,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/06/11 17:15:54 | 000,492,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\win32spl.dll
[2013/06/11 17:15:52 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptdlg.dll
[2013/06/11 17:15:52 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cryptdlg.dll
[2013/06/11 17:15:50 | 001,424,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2013/06/11 17:15:46 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/06/11 17:15:46 | 001,192,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certutil.exe
[2013/06/11 17:15:46 | 000,903,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certutil.exe
[2013/06/11 17:15:46 | 000,139,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2013/06/11 17:15:46 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certenc.dll
[2013/06/11 17:15:46 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certenc.dll
[2013/06/11 17:15:44 | 001,887,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2013/06/11 17:15:44 | 001,505,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2013/05/29 07:00:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2013/05/26 10:16:11 | 000,000,000 | —D | C] – C:\Program Files\Common Files\McAfee
[2013/05/26 10:15:55 | 000,000,000 | —D | C] – C:\Program Files\McAfee.com
[2013/05/26 10:15:55 | 000,000,000 | —D | C] – C:\Program Files\McAfee
[2013/05/25 09:31:05 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\AppData\Local\AMD
[2013/05/25 09:30:53 | 000,000,000 | —D | C] – C:\ProgramData\ATI
[2013/05/25 09:30:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\AMD AVT
[2013/05/25 09:30:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\ATI Technologies
[2013/05/25 09:29:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD VISION Engine Control Center
[2013/05/25 09:29:15 | 000,000,000 | —D | C] – C:\ProgramData\AMD
[2013/05/25 08:55:11 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\Desktop\Sony
[2013/05/24 19:35:32 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RdpGroupPolicyExtension.dll
[2013/05/24 19:35:32 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
[2013/05/24 19:35:32 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
[2013/05/24 19:35:28 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\TsUsbFlt.sys
[2013/05/24 19:35:28 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\rdpvideominiport.sys
[2013/05/24 19:35:23 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tsgqec.dll
[2013/05/24 19:35:23 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbGDCoInstaller.dll
[2013/05/24 19:35:23 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprtPS.dll
[2013/05/24 19:35:22 | 003,174,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorets.dll
[2013/05/24 19:35:22 | 001,123,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2013/05/24 19:35:22 | 001,048,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2013/05/24 19:35:22 | 000,384,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprt.exe
[2013/05/24 19:35:22 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\aaclient.dll
[2013/05/24 19:35:22 | 000,269,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\aaclient.dll
[2013/05/24 19:35:22 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpudd.dll
[2013/05/24 19:35:22 | 000,228,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpendp_winip.dll
[2013/05/24 19:35:22 | 000,192,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpendp_winip.dll
[2013/05/24 19:35:22 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TSWbPrxy.exe
[2013/05/24 19:35:22 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsRdpWebAccess.dll
[2013/05/24 19:35:22 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MsRdpWebAccess.dll
[2013/05/24 19:35:22 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tsgqec.dll
[2013/05/24 19:35:22 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wksprtPS.dll
[2013/05/24 19:35:21 | 004,916,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2013/05/24 19:35:20 | 005,773,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2013/05/24 19:34:21 | 001,448,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2013/05/24 19:34:17 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qdvd.dll
[2013/05/24 19:34:16 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qdvd.dll
[2013/05/24 17:49:51 | 000,082,952 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\dsaflt64.sys
[2013/05/24 17:49:51 | 000,078,920 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\idsflt64.sys
[2013/05/24 17:49:51 | 000,074,760 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\wnmflt64.sys
[2013/05/24 17:49:44 | 000,170,504 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\NETTDI64.SYS
[2013/05/24 17:49:44 | 000,129,096 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\APPFLT64.SYS
[2013/05/24 17:49:44 | 000,031,752 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\fnetm64.sys
[2013/05/24 17:35:01 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\AppData\Local\Programs
[2013/05/24 10:03:04 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\Desktop\directx9
[2013/05/22 08:18:57 | 000,000,000 | —D | C] – C:\Crash
[2013/05/18 12:12:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2011/09/12 19:50:55 | 000,257,024 | —- | C] (Microsoft Corporation) – C:\Users\Stacy Reffitt\taskmgr.exe
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[4 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/06/16 12:02:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/06/16 11:21:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/16 10:32:13 | 000,015,152 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/16 10:32:13 | 000,015,152 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/16 10:29:24 | 000,779,266 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/06/16 10:29:24 | 000,660,280 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/06/16 10:29:24 | 000,121,208 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/06/16 10:25:32 | 000,001,441 | —- | M] () – C:\Users\Stacy Reffitt\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/06/16 10:25:32 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/16 10:25:00 | 000,000,120 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetAdapt.cfg.bck
[2013/06/16 10:25:00 | 000,000,120 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetAdapt.cfg
[2013/06/16 10:24:59 | 000,000,064 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetAR.wlt.bck
[2013/06/16 10:24:59 | 000,000,064 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetAR.wlt
[2013/06/16 10:24:17 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/06/16 10:23:51 | 000,000,068 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetLoc.wlt
[2013/06/16 10:23:50 | 2146,934,783 | -HS- | M] () – C:\hiberfil.sys
[2013/06/15 15:45:33 | 000,049,202 | —- | M] () – C:\Users\Stacy Reffitt\Documents\House Advertisement.pdf
[2013/06/15 15:28:01 | 000,001,155 | —- | M] () – C:\Users\Public\Desktop\PrimoPDF - Drop Files Here to Convert!.lnk
[2013/06/15 15:28:00 | 000,000,326 | —- | M] () – C:\Windows\primopdf.ini
[2013/06/12 20:02:08 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/06/12 20:02:08 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/05/25 09:52:16 | 000,317,472 | —- | M] () – C:\Windows\SysNative\drivers\etc\DsaFlt.rls.bck
[2013/05/25 09:52:16 | 000,317,472 | —- | M] () – C:\Windows\SysNative\drivers\etc\DsaFlt.rls
[2013/05/25 09:52:16 | 000,001,132 | —- | M] () – C:\Windows\SysNative\drivers\APPFLTR.CFG.bck
[2013/05/25 09:52:16 | 000,001,132 | —- | M] () – C:\Windows\SysNative\drivers\APPFLTR.CFG
[2013/05/25 09:52:16 | 000,000,252 | —- | M] () – C:\Windows\SysNative\drivers\etc\IdsFlt.cfg.bck
[2013/05/25 09:52:16 | 000,000,252 | —- | M] () – C:\Windows\SysNative\drivers\etc\IdsFlt.cfg
[2013/05/25 09:52:16 | 000,000,068 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetLoc.wlt.bck
[2013/05/25 09:52:16 | 000,000,068 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetFlt.cfg.bck
[2013/05/25 09:52:16 | 000,000,068 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetFlt.cfg
[2013/05/25 09:52:16 | 000,000,056 | —- | M] () – C:\Windows\SysNative\drivers\etc\WnmFlt.cfg.bck
[2013/05/25 09:52:16 | 000,000,056 | —- | M] () – C:\Windows\SysNative\drivers\etc\WnmFlt.cfg
[2013/05/25 09:52:16 | 000,000,056 | —- | M] () – C:\Windows\SysNative\drivers\etc\DsaFlt.cfg.bck
[2013/05/25 09:52:16 | 000,000,056 | —- | M] () – C:\Windows\SysNative\drivers\etc\DsaFlt.cfg
[2013/05/25 09:52:02 | 000,253,120 | —- | M] () – C:\Windows\SysNative\drivers\APPFCONT.DAT.bck
[2013/05/25 09:52:02 | 000,253,120 | —- | M] () – C:\Windows\SysNative\drivers\APPFCONT.DAT
[2013/05/24 17:35:35 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/05/24 17:26:01 | 000,000,402 | —- | M] () – C:\Users\Stacy Reffitt\Desktop\repair.bat
[2013/05/24 09:25:14 | 000,001,468 | —- | M] () – C:\Users\Stacy Reffitt\Desktop\EverQuest II (2).lnk
[2013/05/24 08:47:40 | 000,008,627 | —- | M] () – C:\Windows\SysWow64\PAV_FOG.OPC
[2013/05/18 16:01:01 | 000,002,048 | —- | M] () – C:\Users\Stacy Reffitt\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[4 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/06/16 10:25:32 | 000,001,413 | —- | C] () – C:\Users\Stacy Reffitt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2013/06/15 15:45:32 | 000,049,202 | —- | C] () – C:\Users\Stacy Reffitt\Documents\House Advertisement.pdf
[2013/06/15 15:28:01 | 000,001,155 | —- | C] () – C:\Users\Public\Desktop\PrimoPDF - Drop Files Here to Convert!.lnk
[2013/06/15 15:28:00 | 000,095,008 | —- | C] () – C:\Windows\SysNative\Primomonnt.dll
[2013/05/24 17:49:54 | 000,253,120 | —- | C] () – C:\Windows\SysNative\drivers\APPFCONT.DAT.bck
[2013/05/24 17:49:54 | 000,253,120 | —- | C] () – C:\Windows\SysNative\drivers\APPFCONT.DAT
[2013/05/24 17:49:54 | 000,001,132 | —- | C] () – C:\Windows\SysNative\drivers\APPFLTR.CFG.bck
[2013/05/24 17:49:54 | 000,001,132 | —- | C] () – C:\Windows\SysNative\drivers\APPFLTR.CFG
[2013/05/24 17:26:01 | 000,000,402 | —- | C] () – C:\Users\Stacy Reffitt\Desktop\repair.bat
[2013/05/24 09:25:14 | 000,001,498 | —- | C] () – C:\Users\Stacy Reffitt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EverQuest II (2).lnk
[2013/05/24 09:25:14 | 000,001,468 | —- | C] () – C:\Users\Stacy Reffitt\Desktop\EverQuest II (2).lnk
[2013/05/24 08:58:32 | 000,002,506 | —- | C] () – C:\Users\Stacy Reffitt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EverQuest II.lnk
[2013/03/28 22:13:14 | 000,798,734 | —- | C] () – C:\Windows\SysWow64\amdocl_ld32.exe
[2013/03/28 22:13:12 | 000,995,342 | —- | C] () – C:\Windows\SysWow64\amdocl_as32.exe
[2013/03/28 21:38:08 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2013/03/28 21:38:08 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2013/03/20 20:39:04 | 000,000,187 | —- | C] () – C:\Users\Stacy Reffitt\RmDvrUserCfg85.ini
[2012/11/27 01:18:46 | 000,038,912 | —- | C] () – C:\Windows\SysWow64\kdbsdk32.dll
[2012/08/10 18:01:53 | 000,000,241 | —- | C] () – C:\Windows\QSync.INI
[2012/08/10 17:58:39 | 000,000,840 | —- | C] () – C:\Windows\_delis32.ini
[2012/04/04 20:43:06 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2012/02/25 11:12:00 | 000,023,552 | —- | C] () – C:\Windows\SysWow64\DvrOcxPLK.dll
[2012/02/25 11:09:34 | 000,031,744 | —- | C] () – C:\Windows\SysWow64\DvrOcxCHS.dll
[2012/02/20 16:46:24 | 000,022,528 | —- | C] () – C:\Windows\SysWow64\DvrOcxTHA.dll
[2012/01/06 14:42:48 | 000,027,136 | —- | C] () – C:\Windows\SysWow64\DvrOcxFRA.dll
[2012/01/05 14:32:44 | 000,244,736 | —- | C] () – C:\Windows\SysWow64\DvrNet.dll
[2011/12/18 10:01:24 | 000,005,632 | —- | C] () – C:\Users\Stacy Reffitt\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/12 20:12:55 | 000,011,320 | -HS- | C] () – C:\Users\Stacy Reffitt\AppData\Local\gxinlh7k4nei2qoa2gfu5x365g4s
[2011/12/12 20:12:55 | 000,011,320 | -HS- | C] () – C:\ProgramData\gxinlh7k4nei2qoa2gfu5x365g4s
[2011/11/30 16:46:32 | 000,015,872 | —- | C] () – C:\Windows\SysWow64\DvrOcxCHT.dll
[2011/11/29 16:10:20 | 000,021,504 | —- | C] () – C:\Windows\SysWow64\DvrOcxESP.dll
[2011/11/22 09:40:48 | 000,024,576 | —- | C] () – C:\Windows\SysWow64\DvrOcxFRA(yuxin).dll
[2011/11/16 10:02:44 | 000,053,248 | —- | C] () – C:\Windows\SysWow64\winpubf6.dll
[2011/11/15 10:07:56 | 000,024,064 | —- | C] () – C:\Windows\SysWow64\DvrOcxFAR(changshi).dll
[2011/10/19 17:27:32 | 000,021,504 | —- | C] () – C:\Windows\SysWow64\DvrOcxHEB.dll
[2011/09/13 10:15:04 | 000,022,528 | —- | C] () – C:\Windows\SysWow64\DvrOcxHRV.dll
[2011/09/12 18:06:16 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/08/20 11:34:32 | 000,022,528 | —- | C] () – C:\Windows\SysWow64\DvrOcxDEU.dll
[2011/08/04 16:48:48 | 000,021,504 | —- | C] () – C:\Windows\SysWow64\DvrOcxRUS.dll
[2011/07/04 06:53:29 | 000,000,000 | —- | C] () – C:\Users\Stacy Reffitt\AppData\Local\{35ECBA7C-ECD9-4D60-ADA4-9CF224F029B6}
[2011/06/26 17:35:13 | 000,000,007 | —- | C] () – C:\Windows\SysWow64\mkghj.dll

========== ZeroAccess Check ==========

[2013/05/24 10:04:12 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 01:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/06/11 17:18:47 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\.minecraft
[2010/11/24 20:51:22 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\Amazon
[2013/05/29 09:24:03 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\Azureus
[2013/05/29 09:24:03 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\BitTorrent
[2011/12/07 20:49:57 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\calibre
[2013/05/29 09:24:03 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\FreeBurner
[2012/12/03 22:42:07 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\FrostWire
[2012/08/02 18:05:14 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\Garmin
[2013/06/15 15:28:02 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\OpenCandy
[2012/12/03 22:42:10 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\OpenOffice.org
[2013/06/15 15:45:33 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\PrimoPDF
[2013/05/29 09:24:04 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\RIFT
[2012/12/03 22:42:13 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\Rovio
[2013/05/29 09:24:04 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\Sony Online Entertainment
[2012/12/03 22:42:18 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\TomTom
[2012/12/03 22:42:19 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\Trion Worlds
[2011/04/15 08:12:50 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\Unity

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2009/07/13 22:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 16:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 02:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 01:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 01:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 02:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2011/01/16 16:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX0\procs\explorer.exe
[2011/01/16 16:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX1\procs\explorer.exe
[2011/01/16 16:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX2\procs\explorer.exe
[2011/01/16 16:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX3\procs\explorer.exe
[2011/01/16 16:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX4\procs\explorer.exe
[2011/01/16 16:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX5\procs\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/03 02:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 02:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 01:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2004/08/04 08:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\Windows.old\Windows\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | —- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX0\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | —- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX1\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | —- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX2\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | —- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX3\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | —- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX4\h\explorer.exe
[2005/08/16 02:54:58 | 000,001,536 | —- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX5\h\explorer.exe
[2010/11/20 09:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 02:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 01:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 21:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 02:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 02:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/03 02:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 22:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 22:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: EXPLORER.SCF >
[2004/08/04 08:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\Windows.old\Windows\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2004/08/04 08:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\Windows.old\Windows\Help\iexplore.chm

< MD5 for: IEXPLORE.COM >
[2011/01/16 16:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX0\procs\iexplore.com
[2011/01/16 16:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX1\procs\iexplore.com
[2011/01/16 16:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX2\procs\iexplore.com
[2011/01/16 16:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX3\procs\iexplore.com
[2011/01/16 16:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX4\procs\iexplore.com
[2011/01/16 16:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX5\procs\iexplore.com

< MD5 for: IEXPLORE.EXE >
[2011/11/05 01:28:03 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=0377589BF14A6E5667B730D6D6DB59B4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16912_none_0fae4f323e42a646\iexplore.exe
[2013/03/04 00:49:09 | 000,672,928 | —- | M] (Microsoft Corporation) MD5=050A612C1CE0C7095CAD64EA32C570DB – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21484_none_1a42c5438bf82907\iexplore.exe
[2012/10/27 01:02:44 | 000,672,832 | —- | M] (Microsoft Corporation) MD5=06A8334D76DCF0DFFA738A512BDCD5F7 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17153_none_19d8942672c321c5\iexplore.exe
[2012/02/28 01:42:27 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=09F6A10AB424E2DE445153065FA076BF – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16968_none_19d2eba472c68c00\iexplore.exe
[2010/09/08 00:36:39 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=14803EA3E5DD7CB37CB446C74CFDA38F – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20795_none_1a39121b8bff3c23\iexplore.exe
[2012/06/27 03:05:59 | 000,696,408 | —- | M] (Microsoft Corporation) MD5=156169FAD6DEACEEF4BAFFEE8A662C4F – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17051_none_0f81e75a3e642ff5\iexplore.exe
[2013/02/28 12:18:24 | 000,672,912 | —- | M] (Microsoft Corporation) MD5=19025A34D3EAD0FA9634B504194D214D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17256_none_19db96ea72c06af1\iexplore.exe
[2012/04/20 01:08:37 | 000,672,856 | —- | M] (Microsoft Corporation) MD5=27019747D97AB5CEFB97677DBB5CF577 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17006_none_1a11a2ba7297e4ee\iexplore.exe
[2011/04/22 16:15:52 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=281C23EC5BCB1853A5D571F1A6E52FB1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20949_none_101e7c5957724e1d\iexplore.exe
[2009/07/13 21:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_19ba3f8a72d988f3\iexplore.exe
[2011/12/16 04:03:08 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=38668C6CADABC9487C683FADD3D165D0 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16930_none_19eb591872b56d75\iexplore.exe
[2011/01/16 16:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX0\procs\iexplore.exe
[2011/01/16 16:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX1\procs\iexplore.exe
[2011/01/16 16:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX2\procs\iexplore.exe
[2011/01/16 16:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX3\procs\iexplore.exe
[2011/01/16 16:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX4\procs\iexplore.exe
[2011/01/16 16:55:21 | 000,255,488 | —- | M] () MD5=3C33B26F2F7FA61D882515F2D6078691 – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX5\procs\iexplore.exe
[2011/08/20 00:35:15 | 000,673,024 | —- | M] (Microsoft Corporation) MD5=41FE5E37EFE0B587A688BA0E4FA41288 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16869_none_19d3ea0872c5a830\iexplore.exe
[2011/11/05 01:34:31 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=441C397A9ECF07747920F7F5E40B419B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21085_none_0fef13a357968bc7\iexplore.exe
[2012/12/20 09:27:39 | 000,672,832 | —- | M] (Microsoft Corporation) MD5=45C1FCF818565D44531007526CDEF7EF – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21406_none_1a9b45378bb57c2d\iexplore.exe
[2012/04/20 00:53:37 | 000,672,856 | —- | M] (Microsoft Corporation) MD5=4866404D6657D6E50619CCAF56B17D27 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21198_none_1a3bf0cd8bfcb2df\iexplore.exe
[2010/09/08 01:37:57 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=4879CB864E290BED38C5BDB641144B1B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20795_none_0fe467c9579e7a28\iexplore.exe
[2010/09/08 01:49:01 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=498035ABCCF1ED47AE6791D239187587 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16671_none_0f6c69ae3e743d20\iexplore.exe
[2012/08/24 13:15:32 | 000,672,872 | —- | M] (Microsoft Corporation) MD5=4ADB84297505A1627DEEA18529BF4B16 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17115_none_1a05d46a72a0e4af\iexplore.exe
[2012/10/27 01:56:51 | 000,696,384 | —- | M] (Microsoft Corporation) MD5=4CDF8DE0C9F0A245B7348FDD2866F176 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21355_none_100f8919577e2f69\iexplore.exe
[2012/06/27 03:06:52 | 000,696,408 | —- | M] (Microsoft Corporation) MD5=5421E66F9F91F221B9B88AAE11B0CFE7 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21245_none_101a571f57761651\iexplore.exe
[2012/06/27 02:05:29 | 000,672,856 | —- | M] (Microsoft Corporation) MD5=555D62228092C7F87B9930F85F833297 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17051_none_19d691ac72c4f1f0\iexplore.exe
[2010/11/04 01:54:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=58CF468D3FF4CF830339FE5E45356355 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16700_none_1a0bc510729d1f54\iexplore.exe
[2013/03/02 01:06:58 | 000,672,912 | —- | M] (Microsoft Corporation) MD5=58D926F3B2113BF849162C9C26FE21DC – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17267_none_19d1c74872c7a039\iexplore.exe
[2010/09/08 00:31:24 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=61EDBCE47ADF3E52AB0B9F49EE4AEBB8 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16671_none_19c1140072d4ff1b\iexplore.exe
[2011/04/22 15:29:16 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=64EFAF916C4009F1B84153D0BB491FB0 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16800_none_1a0bc6f6729d1c7b\iexplore.exe
[2012/02/28 02:38:39 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=69073D126F71A4F0FFF1DEE5082A0052 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16968_none_0f7e41523e65ca05\iexplore.exe
[2010/11/04 01:54:59 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=6B2258FF6D2332073FE9E90122FA4168 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20831_none_1a75f2618bd22c48\iexplore.exe
[2011/06/21 02:14:22 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=6B2383EDA3956983E3219A62D8408DAB – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20992_none_0fe16ab757a12871\iexplore.exe
[2011/06/21 01:25:30 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=6BB506124872ACDFAC5BD912CA1334CE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20992_none_1a3615098c01ea6c\iexplore.exe
[2010/12/18 02:17:48 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=700B40EA39DFB25517A81032F03D6D20 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16722_none_0fa37b7a3e4ac7e9\iexplore.exe
[2012/10/27 01:37:44 | 000,696,400 | —- | M] (Microsoft Corporation) MD5=7BF529AEFBAD8946747A1D592BCD31AB – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17153_none_0f83e9d43e625fca\iexplore.exe
[2012/08/24 14:10:19 | 000,696,424 | —- | M] (Microsoft Corporation) MD5=85275D3D81C23C8A8D3C915888D11C66 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17115_none_0fb12a183e4022b4\iexplore.exe
[2010/11/20 09:28:25 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Program Files\Internet Explorer\iexplore.exe
[2010/11/20 09:28:25 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2012/02/28 01:44:39 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=8AFD61FB2D96C8229B7D8604F62FA692 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21158_none_1a67307d8bdc431b\iexplore.exe
[2010/12/18 02:11:10 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=8C6C32E4AF8A3D7155656F5897C504E0 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20861_none_1000d84b5789be20\iexplore.exe
[2011/11/05 00:38:00 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=8ED7C19AEFA3673AADB0D6864B03FBCE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16912_none_1a02f98472a36841\iexplore.exe
[2010/12/18 01:32:25 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=9321CF0D023528C71E3645F8433C86C8 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20861_none_1a55829d8bea801b\iexplore.exe
[2012/06/27 02:11:42 | 000,672,832 | —- | M] (Microsoft Corporation) MD5=9B80D4B1CAD7C4160D9B2D65D468E336 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21245_none_1a6f01718bd6d84c\iexplore.exe
[2011/06/21 01:37:00 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=A3AB0A260049BE22AB52E302D9220A92 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16839_none_19f459cc72ad545d\iexplore.exe
[2011/12/16 04:45:57 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=A3F56CED7B94A30BE8954387F0E2B5D2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16930_none_0f96aec63e54ab7a\iexplore.exe
[2011/11/05 00:39:45 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=A8A14CD0CB499B80412F75D53996AE29 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21085_none_1a43bdf58bf74dc2\iexplore.exe
[2013/02/28 13:29:52 | 000,696,464 | —- | M] (Microsoft Corporation) MD5=A976A480AA8FE1AE85B33F543D51752B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21471_none_0ff5e9ff5791ff16\iexplore.exe
[2010/12/18 01:33:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AA08B68EF4E35EFA170CF85A44B23B70 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16722_none_19f825cc72ab89e4\iexplore.exe
[2011/02/24 01:45:11 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AB2BB40A5FE49AD236791AC22BD08869 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_1a9d66118bb386fd\iexplore.exe
[2005/08/16 02:54:58 | 000,001,536 | —- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX0\h\iexplore.exe
[2005/08/16 02:54:58 | 000,001,536 | —- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX1\h\iexplore.exe
[2005/08/16 02:54:58 | 000,001,536 | —- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX2\h\iexplore.exe
[2005/08/16 02:54:58 | 000,001,536 | —- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX3\h\iexplore.exe
[2005/08/16 02:54:58 | 000,001,536 | —- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX4\h\iexplore.exe
[2005/08/16 02:54:58 | 000,001,536 | —- | M] () MD5=ABC6379205DE2618851C4FCBF72112EB – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX5\h\iexplore.exe
[2011/08/20 01:46:07 | 000,696,576 | —- | M] (Microsoft Corporation) MD5=AC1CC7CD5CBE60EFF105BB3C0DC199C5 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16869_none_0f7f3fb63e64e635\iexplore.exe
[2009/05/26 19:47:22 | 000,031,232 | —- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX0\nird\iexplore.exe
[2009/05/26 19:47:22 | 000,031,232 | —- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX1\nird\iexplore.exe
[2009/05/26 19:47:22 | 000,031,232 | —- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX2\nird\iexplore.exe
[2009/05/26 19:47:22 | 000,031,232 | —- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX3\nird\iexplore.exe
[2009/05/26 19:47:22 | 000,031,232 | —- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX4\nird\iexplore.exe
[2009/05/26 19:47:22 | 000,031,232 | —- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX5\nird\iexplore.exe
[2013/03/02 01:50:08 | 000,696,480 | —- | M] (Microsoft Corporation) MD5=AFB0FE34A9B7F1B7A70276B9C1A78114 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17267_none_0f7d1cf63e66de3e\iexplore.exe
[2011/12/12 20:46:43 | 001,008,120 | —- | M] () MD5=B126E9A5878A0C30775619E640669C91 – C:\Users\Stacy Reffitt\Desktop\iExplore.exe
[2011/12/12 20:46:43 | 001,008,120 | —- | M] () MD5=B126E9A5878A0C30775619E640669C91 – C:\Users\Stacy Reffitt\Downloads\iExplore.exe
[2013/03/04 01:42:51 | 000,696,464 | —- | M] (Microsoft Corporation) MD5=B1B17B56E0F9AE84A1F75E757217154E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21484_none_0fee1af15797670c\iexplore.exe
[2011/06/21 02:21:24 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=B38DE184AC135A4B0AE7D286476FA33F – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16839_none_0f9faf7a3e4c9262\iexplore.exe
[2011/02/24 02:29:19 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=B4881B8F6EDB48CABD44BCC9FB5475C4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_1048bbbf5752c502\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2011/12/16 04:42:35 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=C152529FD67ABB61F0609EF5A299794C – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21108_none_104895c75752f56b\iexplore.exe
[2011/12/16 05:19:51 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=C53E41F92B19EC97D987F968403BEC49 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21108_none_1a9d40198bb3b766\iexplore.exe
[2010/11/20 08:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2010/11/20 08:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2011/02/24 01:32:52 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C6697A46554E36541E81182B258A19D6 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_19d0e74472c85f04\iexplore.exe
[2011/08/20 01:42:38 | 000,696,576 | —- | M] (Microsoft Corporation) MD5=C66C8BF791F9DB974022506265518EE0 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21033_none_102322ab576fcd64\iexplore.exe
[2012/08/24 13:10:38 | 000,672,872 | —- | M] (Microsoft Corporation) MD5=C6E8F6DB0FD7B28924D1CBC8AE03ECEE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21313_none_1a8d72878bc04ef2\iexplore.exe
[2012/10/27 00:57:50 | 000,672,832 | —- | M] (Microsoft Corporation) MD5=CAB945F6B0700D84DE40ED1FA6DB15F2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21355_none_1a64336b8bdef164\iexplore.exe
[2012/12/20 09:01:03 | 000,672,832 | —- | M] (Microsoft Corporation) MD5=D1F65F76FA03619706C43CBEF9C1EEC3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17197_none_19b1559e72dff6e5\iexplore.exe
[2011/04/22 16:16:25 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=D6F57A9ECB4606076FB9519D1698FCBA – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16800_none_0fb71ca43e3c5a80\iexplore.exe
[2012/04/20 02:26:39 | 000,696,408 | —- | M] (Microsoft Corporation) MD5=D889681C78E7BFE45587398AC42FC2D4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17006_none_0fbcf8683e3722f3\iexplore.exe
[2010/11/04 02:37:41 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=D8E00EA671A1EFE95C69C7566C505AD4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16700_none_0fb71abe3e3c5d59\iexplore.exe
[2011/02/24 02:32:09 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=E1BBDE0F187194D4B08335234A4B9FC7 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_0f7c3cf23e679d09\iexplore.exe
[2010/11/04 02:42:22 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=E220FB009F54AAF649C6A278A5156764 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20831_none_1021480f57716a4d\iexplore.exe
[2012/08/24 14:24:56 | 000,696,424 | —- | M] (Microsoft Corporation) MD5=E3C361C85ADECFF3A485E4FE17859E0F – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21313_none_1038c835575f8cf7\iexplore.exe
[2013/02/28 13:21:37 | 000,672,912 | —- | M] (Microsoft Corporation) MD5=E9194413FBF8CF085DD548F489BA44F2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21471_none_1a4a94518bf2c111\iexplore.exe
[2012/02/28 02:56:21 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=EFCA1150F17BCE44357F03BB61A29966 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21158_none_1012862b577b8120\iexplore.exe
[2012/04/20 02:13:05 | 000,696,408 | —- | M] (Microsoft Corporation) MD5=F293ACB373FD8F090E08F183C06E07ED – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21198_none_0fe7467b579bf0e4\iexplore.exe
[2009/07/13 21:43:43 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_0f6595383e78c6f8\iexplore.exe
[2012/12/20 10:08:37 | 000,696,384 | —- | M] (Microsoft Corporation) MD5=F44F02FEEB5AC24C37D70BC83A578A7D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21406_none_10469ae55754ba32\iexplore.exe
[2011/04/22 15:11:29 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=F94877A94996B3C12BB31AD722840457 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20949_none_1a7326ab8bd31018\iexplore.exe
[2013/02/28 12:36:35 | 000,696,480 | —- | M] (Microsoft Corporation) MD5=F9F2279A5EBAFB343CDB79FDC5C408C0 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17256_none_0f86ec983e5fa8f6\iexplore.exe
[2011/08/20 00:32:44 | 000,673,024 | —- | M] (Microsoft Corporation) MD5=FA623BE79902A7B49FF4F21117B63C83 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21033_none_1a77ccfd8bd08f5f\iexplore.exe
[2012/12/20 10:09:06 | 000,696,384 | —- | M] (Microsoft Corporation) MD5=FE004EA8558B9C8BF066483A3EA9FDDB – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17197_none_0f5cab4c3e7f34ea\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_09122aaf762607df\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_1366d501aa86c9da\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-1B894AFB.PF >
[2013/06/16 10:38:28 | 000,109,224 | —- | M] () MD5=433BB2C76BE9315FC8CF68088C411184 – C:\Windows\Prefetch\IEXPLORE.EXE-1B894AFB.pf

< MD5 for: IEXPLORE.EXE-F6A52C86.PF >
[2013/06/16 10:20:54 | 000,148,928 | —- | M] () MD5=F0039E547AA9C6DF9C4581AF6B68522C – C:\Windows\Prefetch\IEXPLORE.EXE-F6A52C86.pf

< MD5 for: IEXPLORE.HLP >
[2004/08/04 08:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\Windows.old\Windows\Help\iexplore.hlp

< MD5 for: SERVICES >
[2004/08/04 08:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\Windows.old\Windows\system32\drivers\etc\services
[2009/06/10 17:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.CFG >
[2012/09/23 20:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2013/05/11 06:37:26 | 000,558,990 | —- | M] () MD5=FE8FB005031C2574E990DAC1F9F5ACF8 – C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Services\Services.cfg

< MD5 for: SERVICES.EXE >
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2004/08/04 08:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\Windows.old\Windows\system32\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 22:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2009/07/13 22:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2009/07/13 22:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2009/07/13 22:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
[2004/08/04 08:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\Windows.old\Windows\system32\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: SERVICES.RDB >
[2010/05/21 00:34:38 | 000,262,144 | —- | M] () MD5=00D8C85E07B0D69A27816B54E56EF85B – C:\Program Files (x86)\OpenOffice.org 3\URE\misc\services.rdb
[2010/05/21 00:28:42 | 005,505,024 | —- | M] () MD5=20999743CA8D1F7132B0BFCE952F2295 – C:\Program Files (x86)\OpenOffice.org 3\Basis\program\services.rdb

< MD5 for: WINLOGON.ADML >
[2009/07/13 22:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2004/08/04 08:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\Windows.old\Windows\system32\winlogon.exe
[2010/11/20 09:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 09:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 21:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/28 03:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | —- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX0\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | —- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX1\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | —- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX2\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | —- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX3\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | —- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX4\winlogon.exe
[2009/05/26 19:47:22 | 000,031,232 | —- | M] (NirSoft) MD5=AC6094297CD882B8626466CDEB64F19F – C:\Users\Stacy Reffitt\AppData\Local\Temp\RarSFX5\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/28 02:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 09:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/20 09:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
[2009/07/13 22:29:52 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=56D03B64B8C483C1D12A8E4577B3B332 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_26ed83321dc778e1\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2009/07/13 22:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/13 22:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2012/09/08 12:10:12 | 001,506,415 | —- | M] () – C:\alotserviceruntime.log
[2010/07/20 12:40:54 | 000,000,210 | -H– | M] () – C:\Boot.BAK
[2010/07/21 20:40:22 | 000,000,354 | RHS- | M] () – C:\Boot.ini.saved
[2010/11/20 08:40:07 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2010/07/21 20:40:24 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/07/20 06:24:09 | 001,769,696 | —- | M] () – C:\caisslog.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2011/12/18 18:40:32 | 000,052,324 | —- | M] () – C:\formatter.log
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2013/06/16 10:23:50 | 2146,934,783 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 08:44:20 | 000,855,040 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:44:20 | 000,075,280 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:44:20 | 000,090,128 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:44:20 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:44:20 | 000,094,224 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:44:20 | 000,080,400 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:44:20 | 000,078,864 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:44:20 | 000,074,768 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2012/09/08 12:10:13 | 000,024,188 | —- | M] () – C:\INSTALLHELPER.LOG
[2012/08/10 17:57:44 | 000,000,090 | —- | M] () – C:\LogiSetup.log
[2013/05/25 11:37:21 | 000,003,781 | —- | M] () – C:\netinfo.txt
[2004/08/04 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 08:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2013/06/16 10:23:56 | 4294,238,207 | -HS- | M] () – C:\pagefile.sys
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:50:40 | 001,927,956 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:53:12 | 000,242,176 | —- | M] () – C:\VC_RED.MSI
[2011/03/21 19:46:05 | 000,000,000 | —- | M] () – C:\wizard.txt

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/06/16 10:25:32 | 000,000,221 | -HS- | M] () – C:\Users\Stacy Reffitt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/12/12 20:46:43 | 001,008,120 | —- | M] () – C:\Users\Stacy Reffitt\Desktop\iExplore.exe
[2012/01/01 09:58:35 | 007,009,240 | —- | M] (FS) – C:\Users\Stacy Reffitt\Desktop\spyrowebworldportaldriver.exe
[2011/07/02 10:40:44 | 036,207,128 | —- | M] (NETGEAR ) – C:\Users\Stacy Reffitt\Desktop\WG111v3_v2.0.0_Setup.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >
OTL Extras logfile created on: 6/16/2013 12:02:20 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Stacy Reffitt\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 6.02 Gb Available Physical Memory | 75.22% Memory free
16.00 Gb Paging File | 13.73 Gb Available in Paging File | 85.83% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.50 Gb Total Space | 697.66 Gb Free Space | 74.90% Space Free | Partition Type: NTFS
Drive D: | 1.77 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: GAMER | User Name: Stacy Reffitt | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0220EC2C-DCC2-49B0-924A-4D771CA9801B}" = lport=445 | protocol=6 | dir=in | app=system |
"{0B8D0D39-EBFA-4D76-9C69-5F0EF6339E1C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{11079599-E9B0-47DB-B4B4-20E1A2E169BD}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{1174CC64-7EAE-4FAE-87D2-140368EDFF3E}" = lport=10243 | protocol=6 | dir=in | app=system |
"{1E4FE8ED-CA90-44DB-B484-1EE6EBBF2A34}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{21672C14-D208-48A1-9CFE-84074085ED74}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{26665A75-2366-4A60-BA93-A45CE1C2C966}" = rport=139 | protocol=6 | dir=out | app=system |
"{27D300B9-4B8B-4D06-8EB9-7AB725DAF483}" = lport=139 | protocol=6 | dir=in | app=system |
"{3A3F767F-5755-43C8-9F5E-160DA01E8AA6}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{42D2A0F6-CCD2-4B77-B3C9-C7E0FBCD0A5B}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{48F0F24A-000E-4E5D-BF75-B6BABFA209CC}" = rport=137 | protocol=17 | dir=out | app=system |
"{4DA4D27F-4DBB-4F30-8336-8B91008BF180}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{50763EE1-B928-44F4-8512-C204D11A645F}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{541B49EF-8778-43DF-9750-07020EACE971}" = rport=138 | protocol=17 | dir=out | app=system |
"{55CB61B0-B86F-4814-A15A-BDF45A3901A2}" = rport=10243 | protocol=6 | dir=out | app=system |
"{58856A32-98D0-44DF-ADAD-8C80009E3759}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5A748735-1ECB-4437-B038-638345218452}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6D070009-AD66-4E14-9830-26214E3D0D29}" = lport=138 | protocol=17 | dir=in | app=system |
"{9690E054-B722-481D-BBEB-19CFD47DE698}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B06CA84D-95E3-4E16-8A24-57F12D1315D8}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B6C2660A-7B60-41A7-8202-301F4B8E502E}" = lport=137 | protocol=17 | dir=in | app=system |
"{B9AE3394-322A-448A-8DFC-56C0A69C3E7C}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D26A92F9-71C4-4649-9CC3-5BD8FFC78FC9}" = rport=445 | protocol=6 | dir=out | app=system |
"{F307DA65-DC5F-4D1C-BA34-736B22FDC347}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{053509A0-6DD5-4511-AB33-143B8C6F8038}" = protocol=17 | dir=in | app=c:\program files (x86)\frostwire\frostwire.exe |
"{0EFCC22E-536A-4E09-9D82-539C4887D07F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{1AE02824-D0B9-4D01-82AB-2210F6BE6DF9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{23F300C6-78D1-47B7-966B-3D8C70151CCF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{2A93676E-2822-4BD0-98EB-2DCDF56F6549}" = protocol=17 | dir=in | app=c:\program files (x86)\ventrilo\ventrilo.exe |
"{3136D8CC-494D-4EDC-81D5-7AD52815BAE5}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\bioware\star wars - the old republic\launcher.exe |
"{38261483-8891-433B-A132-71669A86A7B2}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{396D23C2-9876-4F93-B128-886D91EF4201}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{404CC1E0-7F39-4C45-A4C0-1E77C6ECF0EF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{42515B42-A3D6-48F2-B56A-DABF54847EA2}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{46ACCD25-EC79-496D-AE26-E07033705797}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5520B7DF-41BE-4F02-A50B-65BB223B3BD2}" = protocol=17 | dir=in | app=c:\program files (x86)\frostwire\frostwire.exe |
"{5A90E203-623B-438A-BCF9-BA5183A0F7E2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5B9F9C73-55CA-41B1-8968-7B512BB98901}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\bioware\star wars - the old republic\launcher.exe |
"{5D1F302E-5D80-4841-8361-D97647887E40}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{630CFBE9-2816-4CC9-B643-1D544537FA12}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{657D749E-5F7E-4971-B2B2-89945F689642}" = protocol=6 | dir=out | app=system |
"{685AA4E0-025D-4429-96EE-5E558039DF49}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{76753297-F6C3-4908-BB90-DCB029473EE5}" = protocol=17 | dir=in | app=c:\program files (x86)\frostwire 5\frostwire.exe |
"{7ECF051D-BEE2-451D-AC59-1430C101D29C}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\bioware\star wars - the old republic\launcher.exe |
"{8417D4CC-FECE-41D0-9283-374B4023B308}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{8AA8FF39-D543-4734-810C-3D60C76951D3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{92EF5C0C-AE29-4BFC-9592-4E568E1B5C89}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{964F70DF-31D1-4F9E-8BAA-C19572F91D37}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{A0CB8484-AD42-4C04-8408-774C0D5C2C9B}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\bioware\star wars - the old republic\launcher.exe |
"{A319FD9D-9BEC-425A-B49B-E1E8C05979C2}" = protocol=6 | dir=in | app=c:\program files (x86)\frostwire\frostwire.exe |
"{A8C0393F-D0E5-4017-B40E-8E7FDB052F40}" = protocol=6 | dir=in | app=c:\program files (x86)\frostwire 5\frostwire.exe |
"{AAF12D92-384C-4969-B6E7-F3F232C2C838}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{AEE09D30-C4AC-41A6-B610-455802A987D5}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{AFB45750-D98C-45E5-B57E-9FFED8BB7994}" = protocol=6 | dir=in | app=c:\program files (x86)\frostwire\frostwire.exe |
"{BD6B1050-F559-47C9-B5B4-81EC5A2D0380}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C173DBB5-DC54-4489-A475-B8AF3AF24026}" = protocol=6 | dir=in | app=c:\program files (x86)\ventrilo\ventrilo.exe |
"{C54E518F-F17C-4D37-8B87-D08F28F5BC1E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{DA3680E6-8CE0-4BE7-B92E-21722FFFABE7}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{FE11914A-1E10-4E9E-ABAF-A1F5EC1A859A}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{FFE013CB-50A3-4AD4-885D-F991502C6D78}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"TCP Query User{002F980E-2ED9-40C3-BD14-6AAF4D337D3F}C:\sony\everquest ii\eq2voiceservice.exe" = protocol=6 | dir=in | app=c:\sony\everquest ii\eq2voiceservice.exe |
"TCP Query User{18632330-277B-4ACB-A747-98AE422ABEB2}C:\users\public\games\world of warcraft trial\launcher.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft trial\launcher.exe |
"TCP Query User{2766A786-E52A-4FF0-AD8B-BE7CA93BDF28}C:\users\stacy reffitt\desktop\launchpad.exe" = protocol=6 | dir=in | app=c:\users\stacy reffitt\desktop\launchpad.exe |
"TCP Query User{2802A059-3D12-41F5-923F-429B53CCAB02}C:\users\public\games\world of warcraft trial\wow-3.3.3.11685-to-3.3.5.12213-enus-trial-downloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft trial\wow-3.3.3.11685-to-3.3.5.12213-enus-trial-downloader.exe |
"TCP Query User{2C95329B-F7B8-49C0-8F3F-536312003C7B}C:\sony\everquest ii\eq2voiceservice.exe" = protocol=6 | dir=in | app=c:\sony\everquest ii\eq2voiceservice.exe |
"TCP Query User{4999047E-DC16-45E3-BB0C-299A085DC26D}C:\program files (x86)\panda security\panda antivirus pro 2012\apvxdwin.exe" = protocol=6 | dir=in | app=c:\program files (x86)\panda security\panda antivirus pro 2012\apvxdwin.exe |
"TCP Query User{5F985152-3EDB-4DE2-99B1-EC63C0469223}C:\users\stacy reffitt\appdata\locallow\sony online entertainment\installed games\everquest ii extended\eq2voiceservice.exe" = protocol=6 | dir=in | app=c:\users\stacy reffitt\appdata\locallow\sony online entertainment\installed games\everquest ii extended\eq2voiceservice.exe |
"TCP Query User{77872C34-275E-4031-8AD9-C72BA9D2F760}C:\sony\everquest ii\launchpad.exe" = protocol=6 | dir=in | app=c:\sony\everquest ii\launchpad.exe |
"TCP Query User{CDABA118-DEAE-42E3-B2B8-37275F02CA8C}C:\sony\everquest ii\launchpad.exe" = protocol=6 | dir=in | app=c:\sony\everquest ii\launchpad.exe |
"TCP Query User{E1029A4E-6075-4D6E-9EDD-BCD38BB036D5}C:\program files (x86)\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe |
"UDP Query User{07A6B46C-23E5-4FA0-A02E-D9E4E3C57EF1}C:\users\stacy reffitt\desktop\launchpad.exe" = protocol=17 | dir=in | app=c:\users\stacy reffitt\desktop\launchpad.exe |
"UDP Query User{111EF778-A516-4C6A-8D47-1185DF6CC6B4}C:\users\public\games\world of warcraft trial\launcher.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft trial\launcher.exe |
"UDP Query User{135A3FCC-3583-410A-B602-F9C1028FB384}C:\users\stacy reffitt\appdata\locallow\sony online entertainment\installed games\everquest ii extended\eq2voiceservice.exe" = protocol=17 | dir=in | app=c:\users\stacy reffitt\appdata\locallow\sony online entertainment\installed games\everquest ii extended\eq2voiceservice.exe |
"UDP Query User{2E7F62BF-AF81-4914-8B10-15F639EDF9FA}C:\program files (x86)\panda security\panda antivirus pro 2012\apvxdwin.exe" = protocol=17 | dir=in | app=c:\program files (x86)\panda security\panda antivirus pro 2012\apvxdwin.exe |
"UDP Query User{69B04A83-2321-45E1-8DA4-00E382998C11}C:\sony\everquest ii\launchpad.exe" = protocol=17 | dir=in | app=c:\sony\everquest ii\launchpad.exe |
"UDP Query User{88940733-4F53-4B5A-90C3-433C0AE33558}C:\sony\everquest ii\eq2voiceservice.exe" = protocol=17 | dir=in | app=c:\sony\everquest ii\eq2voiceservice.exe |
"UDP Query User{A6F9B5A8-6FA5-4C86-A822-C9E23FEB1472}C:\program files (x86)\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe |
"UDP Query User{AA3C595C-F17A-47B5-8355-15032FEDB820}C:\sony\everquest ii\eq2voiceservice.exe" = protocol=17 | dir=in | app=c:\sony\everquest ii\eq2voiceservice.exe |
"UDP Query User{AB8241E3-CA66-4A92-A5FF-0423C015FA2C}C:\users\public\games\world of warcraft trial\wow-3.3.3.11685-to-3.3.5.12213-enus-trial-downloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft trial\wow-3.3.3.11685-to-3.3.5.12213-enus-trial-downloader.exe |
"UDP Query User{D4259119-CB26-4D22-BD21-9C4B7D395FAD}C:\sony\everquest ii\launchpad.exe" = protocol=17 | dir=in | app=c:\sony\everquest ii\launchpad.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{003B37AE-21F5-5BC5-F5EB-CD60A8928696}" = AMD Accelerated Video Transcoding
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{07EEE598-5F21-4B57-B40B-46592625B3D9}" = Zune Language Pack (PTB)
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.0 RC3
"{26A24AE4-039D-4CA4-87B4-2F86417005FF}" = Java™ 7 Update 5 (64-bit)
"{2C4E2E4E-A7C9-4CCB-BF03-FE6EBD5D4AB7}" = Windows Mobile Device Updater Component
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{35D00343-3BFA-46A1-C6DD-FFD770501E0B}" = AMD Drag and Drop Transcoding
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{56F26668-13DA-497A-883F-61434A10CBAB}" = MobileMe Control Panel
"{5C93E291-A1CC-4E51-85C6-E194209FCDB4}" = Zune Language Pack (PTG)
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6397820D-9FC6-774C-1EF5-CBA09049E426}" = AMD Fuel
"{653B9326-BD45-53BE-681A-A49CAAEE8A3C}" = ccc-utility64
"{6740BCB0-5863-47F4-80F4-44F394DE4FE2}" = Zune Language Pack (NLD)
"{6B33492E-FBBC-4EC3-8738-09E16E395A10}" = Zune Language Pack (ESP)
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7006ED29-58F2-40C3-AE87-039287AD20B6}" = Zune
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{9AB0D5B6-4779-8C4F-CA91-A1FEDB56D7EC}" = AMD Catalyst Install Manager
"{AAFE68DD-A2D5-BDBF-E1B2-CB01DEFD6EB0}" = AMD Media Foundation Decoders
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2913230-094D-4F41-9EEF-CE9571C450D8}" = SpyroPortalDriver
"{B8AD779A-82DA-4365-A7D0-AD3DCFC55CFF}" = Apple Mobile Device Support
"{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}" = Zune Language Pack (DEU)
"{C5D37FFA-7483-410B-982B-91E93FD3B7DA}" = Zune Language Pack (ITA)
"{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}" = Zune Language Pack (FRA)
"{CDDE7049-3EC8-933E-69C9-C65B3AAD8E24}" = ATI Problem Report Wizard
"{CF8FFD12-602B-422D-AF1D-511B411E7632}" = iTunes
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{EB78DD44-9AEE-7160-4AC3-053636D393C6}" = ATI AVIVO64 Codecs
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Zune" = Zune

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{023A5624-E58D-4103-B329-D7F5B7FA4CD5}_is1" = Angry Birds Seasons 2.0.0
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0FBAFFD8-BCBA-4631-97E8-433DE7D1D753}" = Garmin MapInstall
"{105CFC7C-6992-11D5-BD9D-000102C10FD8}" = LizardTech DjVu Control
"{13464292-6666-B2DB-1B0C-A3FE14DAD1F9}" = CCC Help Dutch
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{26D3E377-1DCA-4043-9410-B4A9BACF1033}" = Nero 7 Ultra Edition
"{2B095022-00FF-45D5-8717-3A20DFCB8C6B}" = RIFT
"{338CD56F-1CDC-CF32-33F6-DED2DF92284E}" = CCC Help French
"{34B32B70-8081-11E2-89AF-B8AC6F98CCE3}" = Google Earth Plug-in
"{39CEE1F2-12B6-4C50-9131-04BFCA110578}" = PowerCinema NE for Everio
"{3B11D799-48E0-48ED-BFD7-EA655676D8BB}" = Star Wars: The Old Republic
"{46458556-5C46-79A9-A6FF-81DF1F8B2729}" = CCC Help Hungarian
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{519D68B8-A768-4CDC-E4C9-B115D49CED93}" = CCC Help Norwegian
"{51D383BC-D988-8C1E-FAA1-BC5260A32A87}" = CCC Help Polish
"{561AA971-37EB-4D63-9FB9-810B663B5CC7}" = Angry Birds Space
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{5A24DD7E-7B01-41AC-ADA8-F1776177A3BA}" = Logitech ImageStudio
"{5A883D2B-D279-0D01-6E62-B810AFD8CC62}" = Catalyst Control Center InstallProxy
"{5BDA2F58-1F21-4D10-9910-92B01EBCC958}" = AMD USB Filter Driver
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{662140BE-138C-4DC1-B4CD-B62C6C855A25}" = Pirate101
"{67A4760F-9804-CCF6-C319-27840ED77924}" = CCC Help Korean
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6BE5E4A9-D88B-532D-26E6-883C32BF098A}" = CCC Help Thai
"{6D172D0A-B9F1-4046-AFAB-8599288545BF}" = Safari
"{6E0D26C1-4265-1D02-4D19-D0A8F6A463F8}" = AMD VISION Engine Control Center
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7C5B4583-7CBF-4289-B195-03B553959DEA}" = VoiceOver Kit
"{7D59CEDD-C68B-4506-A7E2-E4D13FC5373B}" = calibre
"{7DD62206-7B6C-E32E-BD11-B49B3B089D16}" = CCC Help Danish
"{83BEEFB4-8C28-4F4F-8A9D-E0D1ADCE335B}" = The Sims Medieval
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{91110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{9739158D-EDED-D628-9865-1460B5A7FAE3}" = CCC Help Portuguese
"{9809124C-0C4C-2367-7889-1E16D8EF1AAF}" = CCC Help Chinese Standard
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A0C39D92-DEB9-434E-9F1A-2A4AEFB0EB86}" = Panda Antivirus Pro 2012
"{A409B55C-DD9B-4157-86D7-FD6F4F0F2C1A}" = Angry Birds Rio
"{A5355F15-F98B-4704-9BAE-E53B9FE48F48}" = SDFormatter
"{A6E1EE9D-01DD-82FD-BDBC-193BCEF9FD5C}" = CCC Help Greek
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9E27FF5-6294-46A8-B8FD-77B1DECA3021}" = Wizard101
"{AB13F192-49FC-A065-F15C-746B10CC43C8}" = CCC Help Japanese
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.03)
"{AE548812-D611-608D-61C6-7E40F28573A2}" = CCC Help Russian
"{B1D3568D-BC21-4C50-92A5-2396570DF1DE}_is1" = Panda Secure Vault 5
"{B77128D1-6826-437A-BD8E-8828809A2A95}" = SpyroDriver
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{BC63AEF9-1367-9F7C-5926-52E56450EDCD}" = CCC Help Spanish
"{C1E2D27F-B363-588E-8859-9EF7F4EBF418}" = CCC Help Chinese Traditional
"{CCB71FF8-DE82-469C-8641-44378F4443EB}" = Garmin WebUpdater
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BC}" = WinZip 14.0
"{CF9CD37C-E29A-11D5-AE3D-005004B8E30C}" = Digital Photo Navigator 1.5
"{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}" = Microsoft Primary Interoperability Assemblies 2005
"{D76AC809-CCC1-6198-4970-A63FA5CF7DCB}" = CCC Help Swedish
"{D7A0A22A-C132-4B6F-8D68-67B95117DE93}" = RIFT
"{DA675EE2-4C04-9699-0EE2-7EF9FE7AB870}" = CCC Help German
"{DE2E1909-12C2-4249-8003-7978BEA3A14F}" = Garmin City Navigator North America NT 2013.10 Update
"{E06F7C95-4D68-63D9-2231-AA5F8E186FCB}" = CCC Help English
"{E21A8F3C-1ACB-46B1-CE72-E9CF09549DED}" = Catalyst Control Center Localization All
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E2F52AC2-B925-C18F-E1AE-42FBD46ECAC7}" = CCC Help Czech
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E55FB276-73C9-4776-AB53-BC028C0509ED}" = Panda Antivirus Pro 2012
"{E649AC39-69C0-C6FE-0A54-4752DB5D1FD2}" = Catalyst Control Center Graphics Previews Common
"{E7951681-CCC7-24AA-7BFE-9647F477DCFF}" = HydraVision
"{E9463114-898C-7C2A-2C47-E9ABC63F5D43}" = CCC Help Finnish
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EDE721EC-870A-11D8-9D75-000129760D75}" = PowerDirector Express
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FDD5463D-879A-46D3-B2B2-E329CF6EB548}" = Panda Antivirus Pro 2012
"{FF10AC4D-3349-99DA-3E58-5197CEA1D833}" = CCC Help Italian
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFEC93FF-C162-C0C3-B5E7-01214B0E5F2D}" = CCC Help Turkish
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Amazon Games & Software Downloader_is1" = Amazon Games & Software Downloader
"BitTorrent" = BitTorrent
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"CCleaner" = CCleaner
"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows
"CSCLIB" = Canon Camera Support Core Library
"EOS Utility" = Canon Utilities EOS Utility
"EQ2MAP Updater" = EQ2MAP Updater 1.2.8
"Fraps" = Fraps
"FrostWire 5" = FrostWire 5.2.9
"gBurner" = gBurner
"InstallShield_{2B095022-00FF-45D5-8717-3A20DFCB8C6B}" = RIFT
"InstallShield_{D7A0A22A-C132-4B6F-8D68-67B95117DE93}" = RIFT
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox 21.0 (x86 en-US)" = Mozilla Firefox 21.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"PhotoStitch" = Canon Utilities PhotoStitch
"Plants vs. Zombies" = Plants vs. Zombies
"PrimoPDF" = PrimoPDF – brought to you by Nitro PDF Software
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"SpeedFan" = SpeedFan (remove only)
"TomTom HOME" = TomTom HOME 2.8.2.2264
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Amazon Kindle" = Amazon Kindle
"SOE-EverQuest" = EverQuest
"SOE-EverQuest II" = EverQuest II
"SOE-LegendsOfNorrath" = Legends of Norrath
"UnityWebPlayer" = Unity Web Player

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 7/5/2012 5:58:26 PM | Computer Name = GAMER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 5008

Error - 7/5/2012 5:58:27 PM | Computer Name = GAMER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 7/5/2012 5:58:27 PM | Computer Name = GAMER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 6006

Error - 7/5/2012 5:58:27 PM | Computer Name = GAMER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 6006

Error - 7/6/2012 5:47:49 PM | Computer Name = GAMER | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 8.0.7601.17514,
time stamp: 0x4ce79912 Faulting module name: ntdll.dll, version: 6.1.7601.17725,
time stamp: 0x4ec49b8f Exception code: 0xc0000005 Fault offset: 0x0002e0d5 Faulting
process id: 0x98c Faulting application start time: 0x01cd5bc0455d5ff6 Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\Windows\SysWOW64\ntdll.dll Report Id: 3a4a5a47-c7b4-11e1-903b-0030676a3301

Error - 7/6/2012 5:47:53 PM | Computer Name = GAMER | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 8.0.7601.17514,
time stamp: 0x4ce79912 Faulting module name: ntdll.dll, version: 6.1.7601.17725,
time stamp: 0x4ec49b8f Exception code: 0xc0000005 Fault offset: 0x00033d24 Faulting
process id: 0x98c Faulting application start time: 0x01cd5bc0455d5ff6 Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\Windows\SysWOW64\ntdll.dll Report Id: 3ce99e54-c7b4-11e1-903b-0030676a3301

Error - 7/6/2012 9:34:08 PM | Computer Name = GAMER | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 8.0.7601.17514,
time stamp: 0x4ce79912 Faulting module name: MSVCR71.dll, version: 7.10.3052.4, time
stamp: 0x3e561eac Exception code: 0xc0000005 Fault offset: 0x00002eee Faulting process
id: 0xe58 Faulting application start time: 0x01cd5bdc91cb80cc Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\Program Files (x86)\Java\jre6\bin\MSVCR71.dll Report Id: d7f00f7a-c7d3-11e1-903b-0030676a3301

Error - 7/7/2012 12:34:19 AM | Computer Name = GAMER | Source = Application Error | ID = 1000
Description = Faulting application name: AppleSyncNotifier.exe, version: 1.6.72.0,
time stamp: 0x4cafabcb Faulting module name: KERNELBASE.dll, version: 6.1.7601.17651,
time stamp: 0x4e211319 Exception code: 0xc06d007e Fault offset: 0x0000b9bc Faulting
process id: 0x83c Faulting application start time: 0x01cd5bf9b76c89ca Faulting application
path: C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
Faulting
module path: C:\Windows\syswow64\KERNELBASE.dll Report Id: 04114d2f-c7ed-11e1-902e-0030676a3301

Error - 7/7/2012 11:49:55 AM | Computer Name = GAMER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 7/7/2012 11:49:55 AM | Computer Name = GAMER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 998

Error - 7/7/2012 11:49:55 AM | Computer Name = GAMER | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 998

[ System Events ]
Error - 6/16/2013 8:16:30 AM | Computer Name = GAMER | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Panda
IManager Service service to connect.

Error - 6/16/2013 8:16:30 AM | Computer Name = GAMER | Source = Service Control Manager | ID = 7000
Description = The Panda IManager Service service failed to start due to the following
error: %%1053

Error - 6/16/2013 10:24:23 AM | Computer Name = GAMER | Source = Service Control Manager | ID = 7023
Description = The Base Filtering Engine service terminated with the following error:
%%5

Error - 6/16/2013 10:24:23 AM | Computer Name = GAMER | Source = Service Control Manager | ID = 7001
Description = The Windows Firewall service depends on the Base Filtering Engine
service which failed to start because of the following error: %%5

Error - 6/16/2013 10:24:27 AM | Computer Name = GAMER | Source = Service Control Manager | ID = 7001
Description = The IKE and AuthIP IPsec Keying Modules service depends on the Base
Filtering Engine service which failed to start because of the following error:
%%5

Error - 6/16/2013 10:24:27 AM | Computer Name = GAMER | Source = Service Control Manager | ID = 7001
Description = The IPsec Policy Agent service depends on the Base Filtering Engine
service which failed to start because of the following error: %%5

Error - 6/16/2013 10:24:27 AM | Computer Name = GAMER | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Panda
IManager Service service to connect.

Error - 6/16/2013 10:24:27 AM | Computer Name = GAMER | Source = Service Control Manager | ID = 7000
Description = The Panda IManager Service service failed to start due to the following
error: %%1053

Error - 6/16/2013 11:56:52 AM | Computer Name = GAMER | Source = Service Control Manager | ID = 7001
Description = The Windows Firewall service depends on the Base Filtering Engine
service which failed to start because of the following error: %%5

Error - 6/16/2013 11:56:52 AM | Computer Name = GAMER | Source = Service Control Manager | ID = 7023
Description = The Base Filtering Engine service terminated with the following error:
%%5


< End of report >
I also just noticed that my McAfee antivirus has uninstalled itself. This has to have happened in just the last week. Tried reinstalling it and it says it can't download - no internet connection detected. But obviously I am connected to the internet. Please help!!!!!
Hi and Welcome!!

My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • If you happen to have a flash drive/thumb drive please have that ready in the event that we need to use it.
  • Please be sure to subscribe to the topic if you have not already done so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your operating system and losing all your programs and data.


Having said that…. [external image: Posted Image] Let's get going!!
———-

Sorry for any delay…..


Please run a new Quick Scan with OTL and post the new OTL.txt log that will be created. Also do the following…

[external image: Posted Image] Please download TDSSKiller
  • Double click TDSSKiller.exe
  • Press Start Scan but do nothing else as we are just looking for what is there.
  • If Malicious objects are found, select Skip by changing the Cure dropdown in the upper right.
  • Attach the log in your next reply
  • A copy of the log will be saved automatically to the root of the drive (typically C:\)
OTL logfile created on: 6/19/2013 7:25:11 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Stacy Reffitt\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 6.33 Gb Available Physical Memory | 79.07% Memory free
16.00 Gb Paging File | 14.06 Gb Available in Paging File | 87.91% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.50 Gb Total Space | 700.55 Gb Free Space | 75.21% Space Free | Partition Type: NTFS
Drive D: | 1.77 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: GAMER | User Name: Stacy Reffitt | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Stacy Reffitt\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\TPSrvWow.exe (Panda Security, S.L.)
PRC - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\PavFnSvr.exe (Panda Security, S.L.)
PRC - C:\Users\Stacy Reffitt\AppData\Local\Temp\mcitinfo_1371406176.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\FS\Spyro Portal\FlashPortal.exe (FS)
PRC - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
PRC - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\psksvc.exe (Panda Security, S.L.)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\WebProxy.exe (Panda Security, S.L.)
PRC - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\FIREWALL\PSHost.exe (Panda Security International)
PRC - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD)
PRC - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\PsCtrlS.exe (Panda Security, S.L.)
PRC - C:\Program Files (x86)\Common Files\Panda Security\PavShld\PavPrSrv.exe (Panda Security, S.L.)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files (x86)\CyberLink\PCM4Everio\EverioService.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files (x86)\CyberLink\PCM4Everio\Kernel\common\CLEverioDetector.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (AMD FUEL Service) – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (ZuneWlanCfgSvc) – C:\Program Files\Zune\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV:64bit: - (WMZuneComm) – C:\Program Files\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV:64bit: - (ZuneNetworkSvc) – C:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (TPSrv) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\TPSrvWow.exe (Panda Security, S.L.)
SRV - (PAVFNSVR) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\PavFnSvr.exe (Panda Security, S.L.)
SRV - (SpyroService) – C:\Program Files (x86)\FS\Spyro Portal\FlashPortal.exe (FS)
SRV - (TomTomHOMEService) – C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (PskSvcRetail) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\psksvc.exe (Panda Security, S.L.)
SRV - (PAVSRV) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\pavsrvx86.exe (Panda Security, S.L.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (PSHost) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\FIREWALL\PSHost.exe (Panda Security International)
SRV - (Amazon Download Agent) – C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe (Amazon.com)
SRV - (Panda Software Controller) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\PsCtrlS.exe (Panda Security, S.L.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (PSIMSVC) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\PsImSvc.exe (Panda Security S.L.)
SRV - (PavPrSrv) – C:\Program Files (x86)\Common Files\Panda Security\PavShld\PavPrSrv.exe (Panda Security, S.L.)
SRV - (CCALib8) – C:\Program Files (x86)\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (grmnusb) – C:\Windows\SysNative\drivers\grmnusb.sys (GARMIN Corp.)
DRV:64bit: - (AODDriver4.2) – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys (Advanced Micro Devices)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (APPFLT) – C:\Windows\SysNative\drivers\APPFLT64.SYS (Panda Security, S.L.)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (MHIKEY10) – C:\Windows\SysNative\drivers\MHIKEY10x64.sys (Generic USB smartcard reader)
DRV:64bit: - (IDSFLT) – C:\Windows\SysNative\drivers\idsflt64.sys (Panda Security, S.L.)
DRV:64bit: - (NETIMFLT01060044) – C:\Windows\SysNative\drivers\n64i1644.sys (Panda Security, S.L.)
DRV:64bit: - (pavboot) – C:\Windows\SysNative\drivers\pavboot64.sys (Panda Security, S.L.)
DRV:64bit: - (AmFSM) – C:\Windows\SysNative\drivers\amm6460.sys (Panda Security, S.L.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (BIOS) – C:\Windows\SysNative\drivers\BIOS64.sys (BIOSTAR Group)
DRV:64bit: - (ShldFlt) – C:\Windows\SysNative\drivers\ShldFlt.sys (Panda Security, S.L.)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (WNMFLT) – C:\Windows\SysNative\drivers\wnmflt64.sys (Panda Security, S.L.)
DRV:64bit: - (NETFLTDI) – C:\Windows\SysNative\drivers\NETTDI64.SYS (Panda Security, S.L.)
DRV:64bit: - (DSAFLT) – C:\Windows\SysNative\drivers\dsaflt64.sys (Panda Security, S.L.)
DRV:64bit: - (FNETMON) – C:\Windows\SysNative\drivers\fnetm64.sys (Panda Security, S.L.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (BIOS) – C:\Windows\SysWOW64\drivers\BIOS64.sys (BIOSTAR Group)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FD 53 20 A8 9B 6A CE 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledAddons: %7B38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1%7D:1.0.3.122
FF - prefs.js..extensions.enabledAddons: %7Bd781118d-2508-4a76-8d0e-e69cdbbaebd2%7D:1.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - prefs.js..extensions.enabledItems: {38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}:[removed]
FF - prefs.js..extensions.enabledItems: {d781118d-2508-4a76-8d0e-e69cdbbaebd2}:1.0
FF - prefs.js..keyword.URL: "http://www.google.com/cse?cx=partner-pub-5528014799800033:cevktqnfrvl&ie=ISO-8859-1&q="
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Users\Stacy Reffitt\AppData\LocalLow\Sony Online Entertainment\npsoe.dll ()
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Stacy Reffitt\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/05/18 12:12:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/05/29 09:23:36 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/05/18 12:12:40 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/05/29 09:23:36 | 000,000,000 | —D | M]

[2011/09/25 18:12:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Extensions
[2011/09/25 18:12:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/10/15 19:12:37 | 000,000,000 | —D | M] (No name found) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Extensions\[removed]
[2013/05/24 18:01:26 | 000,000,000 | —D | M] (No name found) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Firefox\Profiles\sbaw357u.default\extensions
[2012/12/03 22:53:32 | 000,000,000 | —D | M] () – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Firefox\Profiles\sbaw357u.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}
[2013/05/29 09:24:04 | 000,000,000 | —D | M] (XUL Cache) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Firefox\Profiles\sbaw357u.default\extensions\{d781118d-2508-4a76-8d0e-e69cdbbaebd2}
[2013/05/24 18:01:26 | 000,534,261 | —- | M] () (No name found) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Firefox\Profiles\sbaw357u.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2013/05/08 19:59:44 | 000,870,680 | —- | M] () (No name found) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Firefox\Profiles\sbaw357u.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013/05/18 12:12:39 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013/05/18 12:12:39 | 000,000,000 | —D | M] (Default) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011/03/18 14:32:12 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npCouponPrinter.dll
[2012/03/15 19:28:30 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2009/07/31 13:06:48 | 001,654,784 | —- | M] (LizardTech) – C:\Program Files (x86)\mozilla firefox\plugins\npdjvu.dll
[2011/03/18 14:32:14 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npMozCouponPrinter.dll

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AmazonGSDownloaderTray] C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe (Amazon.com)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [APVXDWIN] C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\APVXDWIN.EXE (Panda Security, S.L.)
O4 - HKLM..\Run: [EverioService] C:\Program Files (x86)\CyberLink\PCM4Everio\EverioService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [LogitechGalleryRepair] C:\Program Files (x86)\Logitech\ImageStudio\ISStart.exe (Logitech Inc.)
O4 - HKLM..\Run: [QCDriverInstaller] C:\Program Files (x86)\Common Files\Logitech\QCDriver3\Lqdsw.exe (Logitech Inc.)
O4 - HKLM..\Run: [SCANINICIO] C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\Inicio.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [HydraVisionDesktopManager] C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD)
O4 - HKCU..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden File not found
O4 - HKCU..\Run: [McAfee McItInfo] C:\Users\Stacy Reffitt\AppData\Local\Temp\mcitinfo_1371406176.exe (McAfee, Inc.)
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - HKCU..\Run: [WebCamRT.exe] File not found
O4 - Startup: C:\Users\Stacy Reffitt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {46D8BEE7-0B27-4466-ABA2-A5F1E157971C} http://63.121.244.73:100/RemoteWeb.cab (Remote200 Control)
O16 - DPF: {5FFDFC21-AE40-4C7C-955C-415A1ACE01C8} http://63.121.244.73:100/VideoViewer.cab (CViewerControl Object)
O16 - DPF: {748E146C-5842-4AD4-8A01-ACA7E61C6FCE} http://24.52.114.10/DvrOcx.cab (Dvr Net 85 Multidownload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3005835A-3760-4F56-B232-177F141A1D0A}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18 - Protocol\Handler\gopher - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\avldr: DllName - (avldr64.dll) - C:\Windows\SysNative\avldr64.dll (On-Access Anti-Malware Scanner Sync)
O20:64bit: - Winlogon\Notify\PFW: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{7f6e6163-f8db-11e1-8b04-0030676a3301}\Shell - "" = AutoRun
O33 - MountPoints2\{7f6e6163-f8db-11e1-8b04-0030676a3301}\Shell\AutoRun\command - "" = E:\TL-Bootstrap.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/06/16 14:08:31 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2013/06/16 14:08:31 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\AppData\Local\MFAData
[2013/06/16 14:08:31 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2013/06/16 14:08:31 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\AppData\Local\Avg2013
[2013/06/15 15:45:03 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\AppData\Roaming\PrimoPDF
[2013/06/15 15:28:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrimoPDF
[2013/06/15 15:28:00 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\AppData\Roaming\OpenCandy
[2013/06/15 15:27:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Nitro PDF
[2013/05/29 07:00:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2013/05/26 10:16:11 | 000,000,000 | —D | C] – C:\Program Files\Common Files\McAfee
[2013/05/26 10:15:55 | 000,000,000 | —D | C] – C:\Program Files\McAfee.com
[2013/05/26 10:15:55 | 000,000,000 | —D | C] – C:\Program Files\McAfee
[2013/05/25 09:31:05 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\AppData\Local\AMD
[2013/05/25 09:30:53 | 000,000,000 | —D | C] – C:\ProgramData\ATI
[2013/05/25 09:30:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\AMD AVT
[2013/05/25 09:30:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\ATI Technologies
[2013/05/25 09:29:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD VISION Engine Control Center
[2013/05/25 09:29:15 | 000,000,000 | —D | C] – C:\ProgramData\AMD
[2013/05/25 08:55:11 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\Desktop\Sony
[2013/05/24 17:49:51 | 000,082,952 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\dsaflt64.sys
[2013/05/24 17:49:51 | 000,078,920 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\idsflt64.sys
[2013/05/24 17:49:51 | 000,074,760 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\wnmflt64.sys
[2013/05/24 17:49:44 | 000,170,504 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\NETTDI64.SYS
[2013/05/24 17:49:44 | 000,129,096 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\APPFLT64.SYS
[2013/05/24 17:49:44 | 000,031,752 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\fnetm64.sys
[2013/05/24 17:35:01 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\AppData\Local\Programs
[2013/05/24 10:03:04 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\Desktop\directx9
[2013/05/22 08:18:57 | 000,000,000 | —D | C] – C:\Crash
[2011/09/12 19:50:55 | 000,257,024 | —- | C] (Microsoft Corporation) – C:\Users\Stacy Reffitt\taskmgr.exe
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[4 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/06/19 19:21:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/19 19:02:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/06/19 17:24:50 | 000,015,152 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/19 17:24:50 | 000,015,152 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/19 17:23:16 | 000,779,266 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/06/19 17:23:16 | 000,660,280 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/06/19 17:23:16 | 000,121,208 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/06/19 17:17:45 | 000,000,120 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetAdapt.cfg.bck
[2013/06/19 17:17:45 | 000,000,120 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetAdapt.cfg
[2013/06/19 17:17:45 | 000,000,064 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetAR.wlt.bck
[2013/06/19 17:17:45 | 000,000,064 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetAR.wlt
[2013/06/19 17:17:13 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/19 17:17:04 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/06/19 17:16:59 | 2146,934,783 | -HS- | M] () – C:\hiberfil.sys
[2013/06/17 06:14:34 | 000,000,068 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetLoc.wlt
[2013/06/16 10:25:32 | 000,001,441 | —- | M] () – C:\Users\Stacy Reffitt\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/06/15 15:45:33 | 000,049,202 | —- | M] () – C:\Users\Stacy Reffitt\Documents\House Advertisement.pdf
[2013/06/15 15:28:01 | 000,001,155 | —- | M] () – C:\Users\Public\Desktop\PrimoPDF - Drop Files Here to Convert!.lnk
[2013/06/15 15:28:00 | 000,000,326 | —- | M] () – C:\Windows\primopdf.ini
[2013/05/25 09:52:16 | 000,317,472 | —- | M] () – C:\Windows\SysNative\drivers\etc\DsaFlt.rls.bck
[2013/05/25 09:52:16 | 000,317,472 | —- | M] () – C:\Windows\SysNative\drivers\etc\DsaFlt.rls
[2013/05/25 09:52:16 | 000,001,132 | —- | M] () – C:\Windows\SysNative\drivers\APPFLTR.CFG.bck
[2013/05/25 09:52:16 | 000,001,132 | —- | M] () – C:\Windows\SysNative\drivers\APPFLTR.CFG
[2013/05/25 09:52:16 | 000,000,252 | —- | M] () – C:\Windows\SysNative\drivers\etc\IdsFlt.cfg.bck
[2013/05/25 09:52:16 | 000,000,252 | —- | M] () – C:\Windows\SysNative\drivers\etc\IdsFlt.cfg
[2013/05/25 09:52:16 | 000,000,068 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetLoc.wlt.bck
[2013/05/25 09:52:16 | 000,000,068 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetFlt.cfg.bck
[2013/05/25 09:52:16 | 000,000,068 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetFlt.cfg
[2013/05/25 09:52:16 | 000,000,056 | —- | M] () – C:\Windows\SysNative\drivers\etc\WnmFlt.cfg.bck
[2013/05/25 09:52:16 | 000,000,056 | —- | M] () – C:\Windows\SysNative\drivers\etc\WnmFlt.cfg
[2013/05/25 09:52:16 | 000,000,056 | —- | M] () – C:\Windows\SysNative\drivers\etc\DsaFlt.cfg.bck
[2013/05/25 09:52:16 | 000,000,056 | —- | M] () – C:\Windows\SysNative\drivers\etc\DsaFlt.cfg
[2013/05/25 09:52:02 | 000,253,120 | —- | M] () – C:\Windows\SysNative\drivers\APPFCONT.DAT.bck
[2013/05/25 09:52:02 | 000,253,120 | —- | M] () – C:\Windows\SysNative\drivers\APPFCONT.DAT
[2013/05/24 17:35:35 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/05/24 17:26:01 | 000,000,402 | —- | M] () – C:\Users\Stacy Reffitt\Desktop\repair.bat
[2013/05/24 09:25:14 | 000,001,468 | —- | M] () – C:\Users\Stacy Reffitt\Desktop\EverQuest II (2).lnk
[2013/05/24 08:47:40 | 000,008,627 | —- | M] () – C:\Windows\SysWow64\PAV_FOG.OPC
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[4 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/06/16 10:25:32 | 000,001,413 | —- | C] () – C:\Users\Stacy Reffitt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2013/06/15 15:45:32 | 000,049,202 | —- | C] () – C:\Users\Stacy Reffitt\Documents\House Advertisement.pdf
[2013/06/15 15:28:01 | 000,001,155 | —- | C] () – C:\Users\Public\Desktop\PrimoPDF - Drop Files Here to Convert!.lnk
[2013/06/15 15:28:00 | 000,095,008 | —- | C] () – C:\Windows\SysNative\Primomonnt.dll
[2013/05/24 17:49:54 | 000,253,120 | —- | C] () – C:\Windows\SysNative\drivers\APPFCONT.DAT.bck
[2013/05/24 17:49:54 | 000,253,120 | —- | C] () – C:\Windows\SysNative\drivers\APPFCONT.DAT
[2013/05/24 17:49:54 | 000,001,132 | —- | C] () – C:\Windows\SysNative\drivers\APPFLTR.CFG.bck
[2013/05/24 17:49:54 | 000,001,132 | —- | C] () – C:\Windows\SysNative\drivers\APPFLTR.CFG
[2013/05/24 17:26:01 | 000,000,402 | —- | C] () – C:\Users\Stacy Reffitt\Desktop\repair.bat
[2013/05/24 09:25:14 | 000,001,498 | —- | C] () – C:\Users\Stacy Reffitt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EverQuest II (2).lnk
[2013/05/24 09:25:14 | 000,001,468 | —- | C] () – C:\Users\Stacy Reffitt\Desktop\EverQuest II (2).lnk
[2013/05/24 08:58:32 | 000,002,506 | —- | C] () – C:\Users\Stacy Reffitt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EverQuest II.lnk
[2013/03/28 22:13:14 | 000,798,734 | —- | C] () – C:\Windows\SysWow64\amdocl_ld32.exe
[2013/03/28 22:13:12 | 000,995,342 | —- | C] () – C:\Windows\SysWow64\amdocl_as32.exe
[2013/03/28 21:38:08 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2013/03/28 21:38:08 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2013/03/20 20:39:04 | 000,000,187 | —- | C] () – C:\Users\Stacy Reffitt\RmDvrUserCfg85.ini
[2012/11/27 01:18:46 | 000,038,912 | —- | C] () – C:\Windows\SysWow64\kdbsdk32.dll
[2012/08/10 18:01:53 | 000,000,241 | —- | C] () – C:\Windows\QSync.INI
[2012/08/10 17:58:39 | 000,000,840 | —- | C] () – C:\Windows\_delis32.ini
[2012/04/04 20:43:06 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2012/02/25 11:12:00 | 000,023,552 | —- | C] () – C:\Windows\SysWow64\DvrOcxPLK.dll
[2012/02/25 11:09:34 | 000,031,744 | —- | C] () – C:\Windows\SysWow64\DvrOcxCHS.dll
[2012/02/20 16:46:24 | 000,022,528 | —- | C] () – C:\Windows\SysWow64\DvrOcxTHA.dll
[2012/01/06 14:42:48 | 000,027,136 | —- | C] () – C:\Windows\SysWow64\DvrOcxFRA.dll
[2012/01/05 14:32:44 | 000,244,736 | —- | C] () – C:\Windows\SysWow64\DvrNet.dll
[2011/12/18 10:01:24 | 000,005,632 | —- | C] () – C:\Users\Stacy Reffitt\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/12 20:12:55 | 000,011,320 | -HS- | C] () – C:\Users\Stacy Reffitt\AppData\Local\gxinlh7k4nei2qoa2gfu5x365g4s
[2011/12/12 20:12:55 | 000,011,320 | -HS- | C] () – C:\ProgramData\gxinlh7k4nei2qoa2gfu5x365g4s
[2011/11/30 16:46:32 | 000,015,872 | —- | C] () – C:\Windows\SysWow64\DvrOcxCHT.dll
[2011/11/29 16:10:20 | 000,021,504 | —- | C] () – C:\Windows\SysWow64\DvrOcxESP.dll
[2011/11/22 09:40:48 | 000,024,576 | —- | C] () – C:\Windows\SysWow64\DvrOcxFRA(yuxin).dll
[2011/11/16 10:02:44 | 000,053,248 | —- | C] () – C:\Windows\SysWow64\winpubf6.dll
[2011/11/15 10:07:56 | 000,024,064 | —- | C] () – C:\Windows\SysWow64\DvrOcxFAR(changshi).dll
[2011/10/19 17:27:32 | 000,021,504 | —- | C] () – C:\Windows\SysWow64\DvrOcxHEB.dll
[2011/09/13 10:15:04 | 000,022,528 | —- | C] () – C:\Windows\SysWow64\DvrOcxHRV.dll
[2011/09/12 18:06:16 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/08/20 11:34:32 | 000,022,528 | —- | C] () – C:\Windows\SysWow64\DvrOcxDEU.dll
[2011/08/04 16:48:48 | 000,021,504 | —- | C] () – C:\Windows\SysWow64\DvrOcxRUS.dll
[2011/07/04 06:53:29 | 000,000,000 | —- | C] () – C:\Users\Stacy Reffitt\AppData\Local\{35ECBA7C-ECD9-4D60-ADA4-9CF224F029B6}
[2011/06/26 17:35:13 | 000,000,007 | —- | C] () – C:\Windows\SysWow64\mkghj.dll

========== ZeroAccess Check ==========

[2013/05/24 10:04:12 | 000,000,227 | —- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 01:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/06/11 17:18:47 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\.minecraft
[2010/11/24 20:51:22 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\Amazon
[2013/05/29 09:24:03 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\Azureus
[2013/06/16 14:02:49 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\BitTorrent
[2011/12/07 20:49:57 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\calibre
[2013/05/29 09:24:03 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\FreeBurner
[2012/12/03 22:42:07 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\FrostWire
[2012/08/02 18:05:14 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\Garmin
[2013/06/15 15:28:02 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\OpenCandy
[2012/12/03 22:42:10 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\OpenOffice.org
[2013/06/15 15:45:33 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\PrimoPDF
[2013/05/29 09:24:04 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\RIFT
[2012/12/03 22:42:13 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\Rovio
[2013/05/29 09:24:04 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\Sony Online Entertainment
[2012/12/03 22:42:18 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\TomTom
[2012/12/03 22:42:19 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\Trion Worlds
[2011/04/15 08:12:50 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\Unity

========== Purity Check ==========



< End of report >
[external image: Posted Image] Tweaking.com Registry Backup
  • Download the tool found here to your Desktop so it is easy to find.
  • Double click on the file you just downloaded to install it to your system.
  • Once the tool is installed, double-click on the Tweaking.com Registry Backup icon
    **Note** The tool should automatically open to the Backup Registry tab.

    [external image: Posted Image]
  • Press Backup Now
  • When the back up is complete, the tool will tell you that Successful */* Files Backed Up
  • You have now successfully backed up your Registry.
——————-

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FD 53 20 A8 9B 6A CE 01 [binary data]
    FF - prefs.js..extensions.enabledAddons: %7Bd781118d-2508-4a76-8d0e-e69cdbbaebd2%7D:1.0
    FF - prefs.js..extensions.enabledItems: {d781118d-2508-4a76-8d0e-e69cdbbaebd2}:1.0
    [2013/05/29 09:24:04 | 000,000,000 | —D | M] (XUL Cache) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Firefox\Profiles\sbaw357u.default\extensions\{d781118d-2508-4a76-8d0e-e69cdbbaebd2}
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
    O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
    O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
    O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
    O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
    O16 - DPF: {46D8BEE7-0B27-4466-ABA2-A5F1E157971C} http://63.121.244.73:100/RemoteWeb.cab (Remote200 Control)
    O16 - DPF: {5FFDFC21-AE40-4C7C-955C-415A1ACE01C8} http://63.121.244.73:100/VideoViewer.cab (CViewerControl Object)
    O16 - DPF: {748E146C-5842-4AD4-8A01-ACA7E61C6FCE} http://24.52.114.10/DvrOcx.cab (Dvr Net 85 Multidownload)
    O33 - MountPoints2\{7f6e6163-f8db-11e1-8b04-0030676a3301}\Shell - "" = AutoRun
    O33 - MountPoints2\{7f6e6163-f8db-11e1-8b04-0030676a3301}\Shell\AutoRun\command - "" = E:\TL-Bootstrap.exe
    [2013/06/15 15:28:00 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\AppData\Roaming\OpenCandy
    [4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
    [4 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
    [2011/12/18 10:01:24 | 000,005,632 | —- | C] () – C:\Users\Stacy Reffitt\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/12/12 20:12:55 | 000,011,320 | -HS- | C] () – C:\Users\Stacy Reffitt\AppData\Local\gxinlh7k4nei2qoa2gfu5x365g4s
    [2011/12/12 20:12:55 | 000,011,320 | -HS- | C] () – C:\ProgramData\gxinlh7k4nei2qoa2gfu5x365g4s
    [2013/06/15 15:28:02 | 000,000,000 | —D | M] – C:\Users\Stacy Reffitt\AppData\Roaming\OpenCandy
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [emptytemp]
    [resethosts]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

Post the new OTL log and let me know how your system is running now? :)
I still get the same error codes when trying to start firewall or defender.


OTL logfile created on: 6/20/2013 6:35:05 AM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Stacy Reffitt\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 6.48 Gb Available Physical Memory | 81.06% Memory free
16.00 Gb Paging File | 14.27 Gb Available in Paging File | 89.18% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.50 Gb Total Space | 705.62 Gb Free Space | 75.75% Space Free | Partition Type: NTFS
Drive D: | 1.77 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: GAMER | User Name: Stacy Reffitt | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Stacy Reffitt\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\TPSrvWow.exe (Panda Security, S.L.)
PRC - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\PavFnSvr.exe (Panda Security, S.L.)
PRC - C:\Program Files (x86)\FS\Spyro Portal\FlashPortal.exe (FS)
PRC - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
PRC - C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\psksvc.exe (Panda Security, S.L.)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\WebProxy.exe (Panda Security, S.L.)
PRC - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\FIREWALL\PSHost.exe (Panda Security International)
PRC - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD)
PRC - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\PsCtrlS.exe (Panda Security, S.L.)
PRC - C:\Program Files (x86)\Common Files\Panda Security\PavShld\PavPrSrv.exe (Panda Security, S.L.)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files (x86)\CyberLink\PCM4Everio\EverioService.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files (x86)\CyberLink\PCM4Everio\Kernel\common\CLEverioDetector.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (AMD FUEL Service) – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (ZuneWlanCfgSvc) – C:\Program Files\Zune\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV:64bit: - (WMZuneComm) – C:\Program Files\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV:64bit: - (ZuneNetworkSvc) – C:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (TPSrv) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\TPSrvWow.exe (Panda Security, S.L.)
SRV - (PAVFNSVR) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\PavFnSvr.exe (Panda Security, S.L.)
SRV - (SpyroService) – C:\Program Files (x86)\FS\Spyro Portal\FlashPortal.exe (FS)
SRV - (TomTomHOMEService) – C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (PskSvcRetail) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\psksvc.exe (Panda Security, S.L.)
SRV - (PAVSRV) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\pavsrvx86.exe (Panda Security, S.L.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (PSHost) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\FIREWALL\PSHost.exe (Panda Security International)
SRV - (Amazon Download Agent) – C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe (Amazon.com)
SRV - (Panda Software Controller) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\PsCtrlS.exe (Panda Security, S.L.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (PSIMSVC) – C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\PsImSvc.exe (Panda Security S.L.)
SRV - (PavPrSrv) – C:\Program Files (x86)\Common Files\Panda Security\PavShld\PavPrSrv.exe (Panda Security, S.L.)
SRV - (CCALib8) – C:\Program Files (x86)\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (grmnusb) – C:\Windows\SysNative\drivers\grmnusb.sys (GARMIN Corp.)
DRV:64bit: - (AODDriver4.2) – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys (Advanced Micro Devices)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (APPFLT) – C:\Windows\SysNative\drivers\APPFLT64.SYS (Panda Security, S.L.)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (MHIKEY10) – C:\Windows\SysNative\drivers\MHIKEY10x64.sys (Generic USB smartcard reader)
DRV:64bit: - (IDSFLT) – C:\Windows\SysNative\drivers\idsflt64.sys (Panda Security, S.L.)
DRV:64bit: - (NETIMFLT01060044) – C:\Windows\SysNative\drivers\n64i1644.sys (Panda Security, S.L.)
DRV:64bit: - (pavboot) – C:\Windows\SysNative\drivers\pavboot64.sys (Panda Security, S.L.)
DRV:64bit: - (AmFSM) – C:\Windows\SysNative\drivers\amm6460.sys (Panda Security, S.L.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (BIOS) – C:\Windows\SysNative\drivers\BIOS64.sys (BIOSTAR Group)
DRV:64bit: - (ShldFlt) – C:\Windows\SysNative\drivers\ShldFlt.sys (Panda Security, S.L.)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (WNMFLT) – C:\Windows\SysNative\drivers\wnmflt64.sys (Panda Security, S.L.)
DRV:64bit: - (NETFLTDI) – C:\Windows\SysNative\drivers\NETTDI64.SYS (Panda Security, S.L.)
DRV:64bit: - (DSAFLT) – C:\Windows\SysNative\drivers\dsaflt64.sys (Panda Security, S.L.)
DRV:64bit: - (FNETMON) – C:\Windows\SysNative\drivers\fnetm64.sys (Panda Security, S.L.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (BIOS) – C:\Windows\SysWOW64\drivers\BIOS64.sys (BIOSTAR Group)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP =
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledAddons: %7B38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1%7D:1.0.3.122
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Users\Stacy Reffitt\AppData\LocalLow\Sony Online Entertainment\npsoe.dll ()
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Stacy Reffitt\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/05/18 12:12:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/05/29 09:23:36 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/05/18 12:12:40 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/05/29 09:23:36 | 000,000,000 | —D | M]

[2011/09/25 18:12:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Extensions
[2011/09/25 18:12:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/10/15 19:12:37 | 000,000,000 | —D | M] (No name found) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Extensions\[removed]
[2013/06/20 06:29:03 | 000,000,000 | —D | M] (No name found) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Firefox\Profiles\sbaw357u.default\extensions
[2012/12/03 22:53:32 | 000,000,000 | —D | M] () – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Firefox\Profiles\sbaw357u.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}
[2013/05/24 18:01:26 | 000,534,261 | —- | M] () (No name found) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Firefox\Profiles\sbaw357u.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2013/05/08 19:59:44 | 000,870,680 | —- | M] () (No name found) – C:\Users\Stacy Reffitt\AppData\Roaming\Mozilla\Firefox\Profiles\sbaw357u.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013/05/18 12:12:39 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013/05/18 12:12:39 | 000,000,000 | —D | M] (Default) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011/03/18 14:32:12 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npCouponPrinter.dll
[2012/03/15 19:28:30 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2009/07/31 13:06:48 | 001,654,784 | —- | M] (LizardTech) – C:\Program Files (x86)\mozilla firefox\plugins\npdjvu.dll
[2011/03/18 14:32:14 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npMozCouponPrinter.dll

O1 HOSTS File: ([2013/06/20 06:31:11 | 000,000,098 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4:64bit: - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AmazonGSDownloaderTray] C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe (Amazon.com)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [APVXDWIN] C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\APVXDWIN.EXE (Panda Security, S.L.)
O4 - HKLM..\Run: [EverioService] C:\Program Files (x86)\CyberLink\PCM4Everio\EverioService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [LogitechGalleryRepair] C:\Program Files (x86)\Logitech\ImageStudio\ISStart.exe (Logitech Inc.)
O4 - HKLM..\Run: [QCDriverInstaller] C:\Program Files (x86)\Common Files\Logitech\QCDriver3\Lqdsw.exe (Logitech Inc.)
O4 - HKLM..\Run: [SCANINICIO] C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\Inicio.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [HydraVisionDesktopManager] C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD)
O4 - HKCU..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden File not found
O4 - HKCU..\Run: [McAfee McItInfo] C:\Users\STACYR~1\AppData\Local\Temp\mcitinfo_1371406176.exe /itinsfin:C:\Users\STACYR~1\AppData\Local\Temp\mcininfo_1371406176.ini File not found
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - HKCU..\Run: [WebCamRT.exe] File not found
O4 - Startup: C:\Users\Stacy Reffitt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3005835A-3760-4F56-B232-177F141A1D0A}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18 - Protocol\Handler\gopher - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\avldr: DllName - (avldr64.dll) - C:\Windows\SysNative\avldr64.dll (On-Access Anti-Malware Scanner Sync)
O20:64bit: - Winlogon\Notify\PFW: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/06/20 06:29:02 | 000,000,000 | —D | C] – C:\_OTL
[2013/06/20 06:27:31 | 000,000,000 | —D | C] – C:\RegBackup
[2013/06/20 06:27:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
[2013/06/20 06:27:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Tweaking.com
[2013/06/17 06:22:54 | 000,735,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/06/17 06:22:54 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/06/17 06:22:54 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/06/17 06:22:54 | 000,134,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/06/17 06:22:54 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/06/17 06:22:54 | 000,097,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/06/17 06:22:54 | 000,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/06/16 14:08:31 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2013/06/16 14:08:31 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\AppData\Local\MFAData
[2013/06/16 14:08:31 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2013/06/16 14:08:31 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\AppData\Local\Avg2013
[2013/06/15 15:45:03 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\AppData\Roaming\PrimoPDF
[2013/06/15 15:28:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrimoPDF
[2013/06/15 15:27:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Nitro PDF
[2013/06/11 17:15:54 | 000,751,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/06/11 17:15:54 | 000,492,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\win32spl.dll
[2013/06/11 17:15:52 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptdlg.dll
[2013/06/11 17:15:52 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cryptdlg.dll
[2013/06/11 17:15:50 | 001,424,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2013/06/11 17:15:46 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/06/11 17:15:46 | 001,192,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certutil.exe
[2013/06/11 17:15:46 | 000,903,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certutil.exe
[2013/06/11 17:15:46 | 000,139,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2013/06/11 17:15:46 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certenc.dll
[2013/06/11 17:15:46 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certenc.dll
[2013/06/11 17:15:44 | 001,887,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2013/06/11 17:15:44 | 001,505,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2013/05/29 07:00:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2013/05/26 10:16:11 | 000,000,000 | —D | C] – C:\Program Files\Common Files\McAfee
[2013/05/26 10:15:55 | 000,000,000 | —D | C] – C:\Program Files\McAfee.com
[2013/05/26 10:15:55 | 000,000,000 | —D | C] – C:\Program Files\McAfee
[2013/05/25 09:31:05 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\AppData\Local\AMD
[2013/05/25 09:30:53 | 000,000,000 | —D | C] – C:\ProgramData\ATI
[2013/05/25 09:30:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\AMD AVT
[2013/05/25 09:30:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\ATI Technologies
[2013/05/25 09:29:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD VISION Engine Control Center
[2013/05/25 09:29:15 | 000,000,000 | —D | C] – C:\ProgramData\AMD
[2013/05/25 08:55:11 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\Desktop\Sony
[2013/05/24 19:35:32 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RdpGroupPolicyExtension.dll
[2013/05/24 19:35:32 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
[2013/05/24 19:35:32 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
[2013/05/24 19:35:28 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\TsUsbFlt.sys
[2013/05/24 19:35:28 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\rdpvideominiport.sys
[2013/05/24 19:35:23 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tsgqec.dll
[2013/05/24 19:35:23 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbGDCoInstaller.dll
[2013/05/24 19:35:23 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprtPS.dll
[2013/05/24 19:35:22 | 003,174,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorets.dll
[2013/05/24 19:35:22 | 001,123,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2013/05/24 19:35:22 | 001,048,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2013/05/24 19:35:22 | 000,384,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprt.exe
[2013/05/24 19:35:22 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\aaclient.dll
[2013/05/24 19:35:22 | 000,269,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\aaclient.dll
[2013/05/24 19:35:22 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpudd.dll
[2013/05/24 19:35:22 | 000,228,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpendp_winip.dll
[2013/05/24 19:35:22 | 000,192,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpendp_winip.dll
[2013/05/24 19:35:22 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TSWbPrxy.exe
[2013/05/24 19:35:22 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsRdpWebAccess.dll
[2013/05/24 19:35:22 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MsRdpWebAccess.dll
[2013/05/24 19:35:22 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tsgqec.dll
[2013/05/24 19:35:22 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wksprtPS.dll
[2013/05/24 19:35:21 | 004,916,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2013/05/24 19:35:20 | 005,773,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2013/05/24 19:34:21 | 001,448,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2013/05/24 19:34:17 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qdvd.dll
[2013/05/24 19:34:16 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qdvd.dll
[2013/05/24 17:49:51 | 000,082,952 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\dsaflt64.sys
[2013/05/24 17:49:51 | 000,078,920 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\idsflt64.sys
[2013/05/24 17:49:51 | 000,074,760 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\wnmflt64.sys
[2013/05/24 17:49:44 | 000,170,504 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\NETTDI64.SYS
[2013/05/24 17:49:44 | 000,129,096 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\APPFLT64.SYS
[2013/05/24 17:49:44 | 000,031,752 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\fnetm64.sys
[2013/05/24 17:35:01 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\AppData\Local\Programs
[2013/05/24 10:03:04 | 000,000,000 | —D | C] – C:\Users\Stacy Reffitt\Desktop\directx9
[2013/05/22 08:18:57 | 000,000,000 | —D | C] – C:\Crash
[2011/09/12 19:50:55 | 000,257,024 | —- | C] (Microsoft Corporation) – C:\Users\Stacy Reffitt\taskmgr.exe

========== Files - Modified Within 30 Days ==========

[2013/06/20 06:39:58 | 000,015,152 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/20 06:39:58 | 000,015,152 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/20 06:39:06 | 000,779,266 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/06/20 06:39:06 | 000,660,280 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/06/20 06:39:06 | 000,121,208 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/06/20 06:32:54 | 000,000,064 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetAR.wlt.bck
[2013/06/20 06:32:54 | 000,000,064 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetAR.wlt
[2013/06/20 06:32:24 | 000,000,120 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetAdapt.cfg.bck
[2013/06/20 06:32:24 | 000,000,120 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetAdapt.cfg
[2013/06/20 06:32:20 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/20 06:32:12 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/06/20 06:32:08 | 2146,934,783 | -HS- | M] () – C:\hiberfil.sys
[2013/06/20 06:31:11 | 000,000,098 | —- | M] () – C:\Windows\SysNative\drivers\etc\Hosts
[2013/06/20 06:28:09 | 000,000,207 | —- | M] () – C:\Windows\tweaking.com-regbackup-GAMER-Microsoft-Windows-7-Home-Premium-(64-bit).dat
[2013/06/20 06:27:15 | 000,002,239 | —- | M] () – C:\Users\Public\Desktop\Tweaking.com - Registry Backup.lnk
[2013/06/20 06:21:01 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/19 21:02:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/06/17 06:14:34 | 000,000,068 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetLoc.wlt
[2013/06/16 10:25:32 | 000,001,441 | —- | M] () – C:\Users\Stacy Reffitt\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/06/15 15:45:33 | 000,049,202 | —- | M] () – C:\Users\Stacy Reffitt\Documents\House Advertisement.pdf
[2013/06/15 15:28:01 | 000,001,155 | —- | M] () – C:\Users\Public\Desktop\PrimoPDF - Drop Files Here to Convert!.lnk
[2013/06/15 15:28:00 | 000,000,326 | —- | M] () – C:\Windows\primopdf.ini
[2013/06/12 20:02:08 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/06/12 20:02:08 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/05/25 09:52:16 | 000,317,472 | —- | M] () – C:\Windows\SysNative\drivers\etc\DsaFlt.rls.bck
[2013/05/25 09:52:16 | 000,317,472 | —- | M] () – C:\Windows\SysNative\drivers\etc\DsaFlt.rls
[2013/05/25 09:52:16 | 000,001,132 | —- | M] () – C:\Windows\SysNative\drivers\APPFLTR.CFG.bck
[2013/05/25 09:52:16 | 000,001,132 | —- | M] () – C:\Windows\SysNative\drivers\APPFLTR.CFG
[2013/05/25 09:52:16 | 000,000,252 | —- | M] () – C:\Windows\SysNative\drivers\etc\IdsFlt.cfg.bck
[2013/05/25 09:52:16 | 000,000,252 | —- | M] () – C:\Windows\SysNative\drivers\etc\IdsFlt.cfg
[2013/05/25 09:52:16 | 000,000,068 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetLoc.wlt.bck
[2013/05/25 09:52:16 | 000,000,068 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetFlt.cfg.bck
[2013/05/25 09:52:16 | 000,000,068 | —- | M] () – C:\Windows\SysNative\drivers\etc\NetFlt.cfg
[2013/05/25 09:52:16 | 000,000,056 | —- | M] () – C:\Windows\SysNative\drivers\etc\WnmFlt.cfg.bck
[2013/05/25 09:52:16 | 000,000,056 | —- | M] () – C:\Windows\SysNative\drivers\etc\WnmFlt.cfg
[2013/05/25 09:52:16 | 000,000,056 | —- | M] () – C:\Windows\SysNative\drivers\etc\DsaFlt.cfg.bck
[2013/05/25 09:52:16 | 000,000,056 | —- | M] () – C:\Windows\SysNative\drivers\etc\DsaFlt.cfg
[2013/05/25 09:52:02 | 000,253,120 | —- | M] () – C:\Windows\SysNative\drivers\APPFCONT.DAT.bck
[2013/05/25 09:52:02 | 000,253,120 | —- | M] () – C:\Windows\SysNative\drivers\APPFCONT.DAT
[2013/05/24 17:35:35 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/05/24 17:26:01 | 000,000,402 | —- | M] () – C:\Users\Stacy Reffitt\Desktop\repair.bat
[2013/05/24 09:25:14 | 000,001,468 | —- | M] () – C:\Users\Stacy Reffitt\Desktop\EverQuest II (2).lnk
[2013/05/24 08:47:40 | 000,008,627 | —- | M] () – C:\Windows\SysWow64\PAV_FOG.OPC

========== Files Created - No Company Name ==========

[2013/06/20 06:28:09 | 000,000,207 | —- | C] () – C:\Windows\tweaking.com-regbackup-GAMER-Microsoft-Windows-7-Home-Premium-(64-bit).dat
[2013/06/20 06:27:15 | 000,002,239 | —- | C] () – C:\Users\Public\Desktop\Tweaking.com - Registry Backup.lnk
[2013/06/16 10:25:32 | 000,001,413 | —- | C] () – C:\Users\Stacy Reffitt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2013/06/15 15:45:32 | 000,049,202 | —- | C] () – C:\Users\Stacy Reffitt\Documents\House Advertisement.pdf
[2013/06/15 15:28:01 | 000,001,155 | —- | C] () – C:\Users\Public\Desktop\PrimoPDF - Drop Files Here to Convert!.lnk
[2013/06/15 15:28:00 | 000,095,008 | —- | C] () – C:\Windows\SysNative\Primomonnt.dll
[2013/05/24 17:49:54 | 000,253,120 | —- | C] () – C:\Windows\SysNative\drivers\APPFCONT.DAT.bck
[2013/05/24 17:49:54 | 000,253,120 | —- | C] () – C:\Windows\SysNative\drivers\APPFCONT.DAT
[2013/05/24 17:49:54 | 000,001,132 | —- | C] () – C:\Windows\SysNative\drivers\APPFLTR.CFG.bck
[2013/05/24 17:49:54 | 000,001,132 | —- | C] () – C:\Windows\SysNative\drivers\APPFLTR.CFG
[2013/05/24 17:26:01 | 000,000,402 | —- | C] () – C:\Users\Stacy Reffitt\Desktop\repair.bat
[2013/05/24 09:25:14 | 000,001,498 | —- | C] () – C:\Users\Stacy Reffitt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EverQuest II (2).lnk
[2013/05/24 09:25:14 | 000,001,468 | —- | C] () – C:\Users\Stacy Reffitt\Desktop\EverQuest II (2).lnk
[2013/05/24 08:58:32 | 000,002,506 | —- | C] () – C:\Users\Stacy Reffitt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EverQuest II.lnk
[2013/03/28 22:13:14 | 000,798,734 | —- | C] () – C:\Windows\SysWow64\amdocl_ld32.exe
[2013/03/28 22:13:12 | 000,995,342 | —- | C] () – C:\Windows\SysWow64\amdocl_as32.exe
[2013/03/28 21:38:08 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2013/03/28 21:38:08 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2013/03/20 20:39:04 | 000,000,187 | —- | C] () – C:\Users\Stacy Reffitt\RmDvrUserCfg85.ini
[2012/11/27 01:18:46 | 000,038,912 | —- | C] () – C:\Windows\SysWow64\kdbsdk32.dll
[2012/08/10 18:01:53 | 000,000,241 | —- | C] () – C:\Windows\QSync.INI
[2012/08/10 17:58:39 | 000,000,840 | —- | C] () – C:\Windows\_delis32.ini
[2012/04/04 20:43:06 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2012/02/25 11:12:00 | 000,023,552 | —- | C] () – C:\Windows\SysWow64\DvrOcxPLK.dll
[2012/02/25 11:09:34 | 000,031,744 | —- | C] () – C:\Windows\SysWow64\DvrOcxCHS.dll
[2012/02/20 16:46:24 | 000,022,528 | —- | C] () – C:\Windows\SysWow64\DvrOcxTHA.dll
[2012/01/06 14:42:48 | 000,027,136 | —- | C] () – C:\Windows\SysWow64\DvrOcxFRA.dll
[2012/01/05 14:32:44 | 000,244,736 | —- | C] () – C:\Windows\SysWow64\DvrNet.dll
[2011/11/30 16:46:32 | 000,015,872 | —- | C] () – C:\Windows\SysWow64\DvrOcxCHT.dll
[2011/11/29 16:10:20 | 000,021,504 | —- | C] () – C:\Windows\SysWow64\DvrOcxESP.dll
[2011/11/22 09:40:48 | 000,024,576 | —- | C] () – C:\Windows\SysWow64\DvrOcxFRA(yuxin).dll
[2011/11/16 10:02:44 | 000,053,248 | —- | C] () – C:\Windows\SysWow64\winpubf6.dll
[2011/11/15 10:07:56 | 000,024,064 | —- | C] () – C:\Windows\SysWow64\DvrOcxFAR(changshi).dll
[2011/10/19 17:27:32 | 000,021,504 | —- | C] () – C:\Windows\SysWow64\DvrOcxHEB.dll
[2011/09/13 10:15:04 | 000,022,528 | —- | C] () – C:\Windows\SysWow64\DvrOcxHRV.dll
[2011/09/12 18:06:16 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/08/20 11:34:32 | 000,022,528 | —- | C] () – C:\Windows\SysWow64\DvrOcxDEU.dll
[2011/08/04 16:48:48 | 000,021,504 | —- | C] () – C:\Windows\SysWow64\DvrOcxRUS.dll
[2011/07/04 06:53:29 | 000,000,000 | —- | C] () – C:\Users\Stacy Reffitt\AppData\Local\{35ECBA7C-ECD9-4D60-ADA4-9CF224F029B6}
[2011/06/26 17:35:13 | 000,000,007 | —- | C] () – C:\Windows\SysWow64\mkghj.dll

========== ZeroAccess Check ==========

[2013/05/24 10:04:12 | 000,000,227 | —- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 01:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

< End of report >
[external image: Posted Image] Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
———-
Farbar Service Scanner Version: 16-06-2013 Ran by [removed] (administrator) on 20-06-2013 at 17:47:40 Running from "C:\Users\Stacy Reffitt\Downloads" Windows 7 Home Premium Service Pack 1 (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo.com is accessible. Windows Firewall: ============= MpsSvc Service is not running. Checking service configuration: The start type of MpsSvc service is OK. The ImagePath of MpsSvc service is OK. The ServiceDll of MpsSvc service is OK. bfe Service is not running. Checking service configuration: The start type of bfe service is OK. The ImagePath of bfe service is OK. The ServiceDll of bfe service is OK. Firewall Disabled Policy: ================== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=DWORD:0 System Restore: ============ System Restore Disabled Policy: ======================== Action Center: ============ Action Center Notification Icon =====> Unable to open HKLM\…\ShellServiceObjects\{F56F6FDD-AA9D-4618-A949-C1B91AF43B1A} key. The key does not exist. Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== WinDefend Service is not running. Checking service configuration: Checking Start type: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist. Checking ImagePath: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist. Checking ServiceDll: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist. Other Services: ============== Checking Start type of iphlpsvc: ATTENTION!=====> Unable to retrieve start type of iphlpsvc. The value does not exist. Checking ImagePath of iphlpsvc: ATTENTION!=====> Unable to retrieve ImagePath of iphlpsvc. The value does not exist. Checking ServiceDll of iphlpsvc: ATTENTION!=====> Unable to retrieve ServiceDll of iphlpsvc. The value does not exist. File Check: ======== C:\Windows\System32\nsisvc.dll => MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit C:\Windows\System32\dhcpcore.dll => MD5 is legit C:\Windows\System32\drivers\afd.sys => MD5 is legit C:\Windows\System32\drivers\tdx.sys => MD5 is legit C:\Windows\System32\Drivers\tcpip.sys [2013-06-11 17:15] - [2013-05-08 02:39] - 1910632 ____A (Microsoft Corporation) 9849EA3843A2ADBDD1497E97A85D8CAE C:\Windows\System32\dnsrslvr.dll => MD5 is legit C:\Windows\System32\mpssvc.dll => MD5 is legit C:\Windows\System32\bfe.dll => MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit C:\Windows\System32\SDRSVC.dll => MD5 is legit C:\Windows\System32\vssvc.exe => MD5 is legit C:\Windows\System32\wscsvc.dll => MD5 is legit C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\System32\wuaueng.dll => MD5 is legit C:\Windows\System32\qmgr.dll => MD5 is legit C:\Windows\System32\es.dll => MD5 is legit C:\Windows\System32\cryptsvc.dll [2013-06-11 17:15] - [2013-05-13 01:51] - 0184320 ____A (Microsoft Corporation) D8129C49798CBBFB2E4351D4B7B8EF9C C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\System32\ipnathlp.dll => MD5 is legit C:\Windows\System32\iphlpsvc.dll => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit **** End of log ****
Hi,

Please do another backup of your registry using the Tweaking Registry Backup like you did prior to running the fix for OTL earlier.

Next I would like you to take the following steps:
  • Click Start then in the Start Search bar type Run type Notepad and click Ok
  • Copy and Paste the contents of the Code box below into Notepad

    Windows Registry Editor Version 5.00
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellServiceObjects\{F56F6FDD-AA9D-4618-A949-C1B91AF43B1A}]
    "AutoStart"=""
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend]
    "DisplayName"="@%ProgramFiles%\\Windows Defender\\MsMpRes.dll,-103"
    "ErrorControl"=dword:00000001
    "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
      74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
      00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
      6b,00,20,00,73,00,65,00,63,00,73,00,76,00,63,00,73,00,00,00
    "Start"=dword:00000002
    "Type"=dword:00000020
    "Description"="@%ProgramFiles%\\Windows Defender\\MsMpRes.dll,-1176"
    "DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,00,00
    "ObjectName"="LocalSystem"
    "ServiceSidType"=dword:00000001
    "RequiredPrivileges"=hex(7):53,00,65,00,49,00,6d,00,70,00,65,00,72,00,73,00,6f,\
      00,6e,00,61,00,74,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,\
      65,00,00,00,53,00,65,00,42,00,61,00,63,00,6b,00,75,00,70,00,50,00,72,00,69,\
      00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,52,00,65,00,73,00,\
      74,00,6f,00,72,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,\
      00,00,00,53,00,65,00,44,00,65,00,62,00,75,00,67,00,50,00,72,00,69,00,76,00,\
      69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,43,00,68,00,61,00,6e,00,67,\
      00,65,00,4e,00,6f,00,74,00,69,00,66,00,79,00,50,00,72,00,69,00,76,00,69,00,\
      6c,00,65,00,67,00,65,00,00,00,53,00,65,00,53,00,65,00,63,00,75,00,72,00,69,\
      00,74,00,79,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,\
      53,00,65,00,53,00,68,00,75,00,74,00,64,00,6f,00,77,00,6e,00,50,00,72,00,69,\
      00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,49,00,6e,00,63,00,\
      72,00,65,00,61,00,73,00,65,00,51,00,75,00,6f,00,74,00,61,00,50,00,72,00,69,\
      00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,41,00,73,00,73,00,\
      69,00,67,00,6e,00,50,00,72,00,69,00,6d,00,61,00,72,00,79,00,54,00,6f,00,6b,\
      00,65,00,6e,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,\
      00,00
    "DelayedAutoStart"=dword:00000001
    "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\
      00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00,00,00,00,00,00,00,00,00
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend\Parameters]
    "ServiceDllUnloadOnStop"=dword:00000001
    "ServiceDll"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,00,69,\
      00,6c,00,65,00,73,00,25,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,\
      20,00,44,00,65,00,66,00,65,00,6e,00,64,00,65,00,72,00,5c,00,6d,00,70,00,73,\
      00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,00
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend\Security]
    "Security"=hex:01,00,14,80,dc,00,00,00,e8,00,00,00,14,00,00,00,30,00,00,00,02,\
      00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
      00,00,02,00,ac,00,06,00,00,00,00,00,28,00,ff,01,0f,00,01,06,00,00,00,00,00,\
      05,50,00,00,00,b5,89,fb,38,19,84,c2,cb,5c,6c,23,6d,57,00,77,6e,c0,02,64,87,\
      00,0b,28,00,00,00,00,10,01,06,00,00,00,00,00,05,50,00,00,00,b5,89,fb,38,19,\
      84,c2,cb,5c,6c,23,6d,57,00,77,6e,c0,02,64,87,00,00,14,00,fd,01,02,00,01,01,\
      00,00,00,00,00,05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,\
      05,20,00,00,00,20,02,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,05,\
      04,00,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,05,06,00,00,00,01,\
      01,00,00,00,00,00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend\TriggerInfo]
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend\TriggerInfo\0]
    "Type"=dword:00000005
    "Action"=dword:00000001
    "GUID"=hex:e6,ca,9f,65,db,5b,a9,4d,b1,ff,ca,2a,17,8d,46,e0
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\iphlpsvc]
    "DisplayName"="@%SystemRoot%\\system32\\iphlpsvc.dll,-500"
    "ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
      74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
      00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
      6b,00,20,00,4e,00,65,00,74,00,53,00,76,00,63,00,73,00,00,00
    "Description"="@%SystemRoot%\\system32\\iphlpsvc.dll,-501"
    "ObjectName"="LocalSystem"
    "ErrorControl"=dword:00000001
    "Start"=dword:00000002
    "Type"=dword:00000020
    "DependOnService"=hex(7):52,00,70,00,63,00,53,00,53,00,00,00,54,00,64,00,78,00,\
      00,00,77,00,69,00,6e,00,6d,00,67,00,6d,00,74,00,00,00,74,00,63,00,70,00,69,\
      00,70,00,00,00,6e,00,73,00,69,00,00,00,00,00
    "ServiceSidType"=dword:00000001
    "RequiredPrivileges"=hex(7):53,00,65,00,43,00,72,00,65,00,61,00,74,00,65,00,47,\
      00,6c,00,6f,00,62,00,61,00,6c,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,\
      67,00,65,00,00,00,53,00,65,00,49,00,6d,00,70,00,65,00,72,00,73,00,6f,00,6e,\
      00,61,00,74,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,\
      00,00,53,00,65,00,4c,00,6f,00,61,00,64,00,44,00,72,00,69,00,76,00,65,00,72,\
      00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,00,00
    "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\
      00,01,00,00,00,c0,d4,01,00,01,00,00,00,e0,93,04,00,00,00,00,00,00,00,00,00
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\iphlpsvc\config]
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\iphlpsvc\Interfaces]
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters]
    "ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
      00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
      69,00,70,00,68,00,6c,00,70,00,73,00,76,00,63,00,2e,00,64,00,6c,00,6c,00,00,\
      00
    "ServiceDllUnloadOnStop"=dword:00000001
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\IPHTTPS]
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap]
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{159EAD38-ED61-4503-83D4-4C75B67BA29C}]
    "InterfaceName"="isatap.{82098CE2-95E3-4C76-ABA7-3DDEDDBB674F}"
    "ReusableType"=dword:00000000
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Teredo]
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Teredo\{7F075795-0372-4BAA-B60C-46A17A41A9D3}]
    "InterfaceName"="Teredo Tunneling Pseudo-Interface"
    "ReusableType"=dword:00000000
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\iphlpsvc\Teredo]
    "SP1Installed"=dword:00000001
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\iphlpsvc\Teredo\PreviousState]
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\iphlpsvc\Teredo\PreviousState\52-54-00-12-35-02]
    "ClientLocalPort"=dword:0000d42f
    "AddressCreationTimestamp"=dword:052a4091
    "TeredoAddress"="2001:0:5ef5:79fd:2c2c:1e32:e740:8ffa"
  • Save as regfix.reg to your Desktop
  • Make sure to save file type as All Files
  • Now right-click regfix.reg and select Merge
———-

Once finished with this, please run a new scan with Farbar Service Scanner and post the new log. :)
Farbar Service Scanner Version: 16-06-2013 Ran by [removed] (administrator) on 20-06-2013 at 21:12:07 Running from "C:\Users\Stacy Reffitt\Downloads" Windows 7 Home Premium Service Pack 1 (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo.com is accessible. Windows Firewall: ============= MpsSvc Service is not running. Checking service configuration: The start type of MpsSvc service is OK. The ImagePath of MpsSvc service is OK. The ServiceDll of MpsSvc service is OK. bfe Service is not running. Checking service configuration: The start type of bfe service is OK. The ImagePath of bfe service is OK. The ServiceDll of bfe service is OK. Firewall Disabled Policy: ================== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=DWORD:0 System Restore: ============ System Restore Disabled Policy: ======================== Action Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== WinDefend Service is not running. Checking service configuration: The start type of WinDefend service is OK. The ImagePath of WinDefend service is OK. The ServiceDll of WinDefend service is OK. Other Services: ============== File Check: ======== C:\Windows\System32\nsisvc.dll => MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit C:\Windows\System32\dhcpcore.dll => MD5 is legit C:\Windows\System32\drivers\afd.sys => MD5 is legit C:\Windows\System32\drivers\tdx.sys => MD5 is legit C:\Windows\System32\Drivers\tcpip.sys [2013-06-11 17:15] - [2013-05-08 02:39] - 1910632 ____A (Microsoft Corporation) 9849EA3843A2ADBDD1497E97A85D8CAE C:\Windows\System32\dnsrslvr.dll => MD5 is legit C:\Windows\System32\mpssvc.dll => MD5 is legit C:\Windows\System32\bfe.dll => MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit C:\Windows\System32\SDRSVC.dll => MD5 is legit C:\Windows\System32\vssvc.exe => MD5 is legit C:\Windows\System32\wscsvc.dll => MD5 is legit C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\System32\wuaueng.dll => MD5 is legit C:\Windows\System32\qmgr.dll => MD5 is legit C:\Windows\System32\es.dll => MD5 is legit C:\Windows\System32\cryptsvc.dll [2013-06-11 17:15] - [2013-05-13 01:51] - 0184320 ____A (Microsoft Corporation) D8129C49798CBBFB2E4351D4B7B8EF9C C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\System32\ipnathlp.dll => MD5 is legit C:\Windows\System32\iphlpsvc.dll => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit **** End of log ****
Great Job!! :)

[external image: Posted Image] Download Windows Repair (all in one) from this site

Install and then run the program.

On the Start Repairs tab and click Start
[external image: Posted Image]


When the Repair Options screen populates, be sure to select all items and also check Restart System When Finished.

Now press Start
———-

Once completed with this, run a new scan with Farbar Service Scanner and let me know if you are still getting the error messages. :)
Windows defender and firewall are running now! No error messages. Farbar Service Scanner Version: 16-06-2013 Ran by [removed] (administrator) on 22-06-2013 at 01:39:45 Running from "C:\Users\Stacy Reffitt\Downloads" Windows 7 Home Premium Service Pack 1 (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Action Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== Other Services: ============== File Check: ======== C:\Windows\System32\nsisvc.dll => MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit C:\Windows\System32\dhcpcore.dll => MD5 is legit C:\Windows\System32\drivers\afd.sys => MD5 is legit C:\Windows\System32\drivers\tdx.sys => MD5 is legit C:\Windows\System32\Drivers\tcpip.sys [2013-06-11 17:15] - [2013-05-08 02:39] - 1910632 ____A (Microsoft Corporation) 9849EA3843A2ADBDD1497E97A85D8CAE C:\Windows\System32\dnsrslvr.dll => MD5 is legit C:\Windows\System32\mpssvc.dll => MD5 is legit C:\Windows\System32\bfe.dll => MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit C:\Windows\System32\SDRSVC.dll => MD5 is legit C:\Windows\System32\vssvc.exe => MD5 is legit C:\Windows\System32\wscsvc.dll => MD5 is legit C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\System32\wuaueng.dll => MD5 is legit C:\Windows\System32\qmgr.dll => MD5 is legit C:\Windows\System32\es.dll => MD5 is legit C:\Windows\System32\cryptsvc.dll [2013-06-11 17:15] - [2013-05-13 01:51] - 0184320 ____A (Microsoft Corporation) D8129C49798CBBFB2E4351D4B7B8EF9C C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\System32\ipnathlp.dll => MD5 is legit C:\Windows\System32\iphlpsvc.dll => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit **** End of log ****

Windows defender and firewall are running now! No error messages.

:thumbup:

P2P - I see you have P2P software BitTorrent and Frostwire installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections and possibly Identity Theft. It likely contributed to your current situation. This page will give you further information.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Programs and Features.
———-

[external image: Posted Image] Malwarebytes

Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-

ESET Online Scanner

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
———-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI