This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Uninstalled Software leaves registry keys, Malware? [Solved]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My pc has been acting very strange. It's been getting slow. The internet has been getting very slow, and on top of that sometimes the browser will just stop, like it has no internet connection. I will disconnect from wifi using the icon in the bottom right corner next to the clock, and reconnect, right click and run the diagnostic on it until i'm ready to reboot and right before restarting most of the time it will just come back on all of a sudden and the connection is good and everything is fine. And then the other day I had to search the internet for a fix (called folderfix.reg inside a .zip, can provide) because when I was in my computer using right click on my computer > open. I was trying to add a new folder in C:\acer\example\new folder so I right clicked and there wasn't any "New Folder" option anywhere at all that I could find. Could these issues be walware? Can anyone help me with these issues.? Thank you for your time,.


OTL logfile created on: 7/6/2013 12:19:29 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Karen\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16614)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 2.68 Gb Available Physical Memory | 71.48% Memory free
7.50 Gb Paging File | 6.10 Gb Available in Paging File | 81.33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 286.27 Gb Total Space | 202.13 Gb Free Space | 70.61% Space Free | Partition Type: NTFS

Computer Name: KAREN-PC | User Name: Karen | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Karen\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\USB Optical Mouse\USB Optical Mouse\MouseHid.exe ()
PRC - C:\Program Files (x86)\USB Optical Mouse\USB Optical Mouse\Tra.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\USB Optical Mouse\USB Optical Mouse\MouseHid.exe ()
MOD - C:\Program Files (x86)\USB Optical Mouse\USB Optical Mouse\Tra.exe ()


========== Services (SafeList) ==========

SRV:64bit: - (Live Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (XAudioService) – C:\Windows\SysNative\drivers\XAudio64.exe (Conexant Systems, Inc.)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (vToolbarUpdater14.2.0) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe ()
SRV - (avgfws) – C:\Program Files (x86)\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (dg_ssudbus) – C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (ssudmdm) – C:\Windows\SysNative\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (ssadmdm) – C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation)
DRV:64bit: - (ssadbus) – C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
DRV:64bit: - (androidusb) – C:\Windows\SysNative\drivers\ssadadb.sys (Google Inc)
DRV:64bit: - (ssadmdfl) – C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Qualcomm Atheros Communications, Inc.)
DRV:64bit: - (avgtp) – C:\Windows\SysNative\drivers\avgtpx64.sys (AVG Technologies)
DRV:64bit: - (usb_rndisx) – C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (pwdrvio) – C:\Windows\SysNative\pwdrvio.sys ()
DRV:64bit: - (pwdspio) – C:\Windows\SysNative\pwdspio.sys ()
DRV:64bit: - (taphss6) – C:\Windows\SysNative\drivers\taphss6.sys (Anchorfree Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\avgidsdrivera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (AVGIDSHA) – C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\avgidsfiltera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgfwfd) – C:\Windows\SysNative\drivers\avgfwd6a.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (NMgamingmsFltr) – C:\Windows\SysNative\drivers\NMgamingms.sys (Primax Ltd)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (k57nd60a) – C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (WDC_SAM) – C:\Windows\SysNative\drivers\wdcsam64.sys (Western Digital Technologies)
DRV:64bit: - (HSF_DPV) – C:\Windows\SysNative\drivers\CAX_DPV.sys (Conexant Systems, Inc.)
DRV:64bit: - (CAXHWAZL) – C:\Windows\SysNative\drivers\CAXHWAZL.sys (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) – C:\Windows\SysNative\drivers\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (XAudio) – C:\Windows\SysNative\drivers\XAudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (mdmxsdk) – C:\Windows\SysNative\drivers\mdmxsdk.sys (Conexant)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.sweetpacks.com/?src=10&st;…0-00262D7BE3A6}
IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{84dc9f6c-c9a5-4c64-ab67-d6ef60f963c8}: "URL" = http://search.mywebsearch.com/mywebsearch/…r={searchTerms}
IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.helpmefindyour.info/?l=1&…lg=EN&cc;=US
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://start.sweetpacks.com/?src=6&q;={…0-00262D7BE3A6}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {4A6AA337-BCDF-4E13-A072-C640AB2FBB09}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{4A6AA337-BCDF-4E13-A072-C640AB2FBB09}: "URL" = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sear
IE - HKCU\..\SearchScopes\{7A0333EB-26A7-4F8B-92C1-862428320E4F}: "URL" = http://searchou.com/?q={searchTerms}&i;…filt=5&r;=92
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={62F2CD1…mp;d=2012-11-25 19:36:44&v;=14.2.0.1&pid;=avg&sg;=&sap;=dsp&q;={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 64.191.70.164:8090


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\14.2.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\14.2.0.1 [2013/02/18 13:46:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\statuswinks@StatusWinks: C:\Users\Karen\AppData\Roaming\Mozilla\Extensions\statuswinks@StatusWinks
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack\ [2012/11/25 22:34:36 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\statuswinks@StatusWinks: C:\Users\Karen\AppData\Roaming\Mozilla\Extensions\statuswinks@StatusWinks

[2013/06/17 02:51:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Karen\AppData\Roaming\mozilla\Extensions
[2013/06/17 17:14:34 | 000,000,000 | —D | M] (Speed Analysis 2) – C:\Users\Karen\AppData\Roaming\mozilla\Extensions\[removed]

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: AVG SiteSafety plugin (Enabled) = C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\14.2.0\\npsitesafety.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U21 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll
CHR - Extension: Google Drive = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: The Weather Channel for Chrome = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\iflpcokdamgefbghpdipcibmhlkdopop\1.0.0.4_0\
CHR - Extension: Click&Clean; App = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp\8.0_0\
CHR - Extension: Gmail = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2013/05/10 02:15:32 | 000,447,225 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.123fporn.info
O1 - Hosts: 15354 more lines…
O2:64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (no name) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - No CLSID value found.
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll ()
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [USB Optical Mouse] C:\Program Files (x86)\USB Optical Mouse\USB Optical Mouse\MouseHid.exe ()
O4 - HKCU..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKLM..\RunOnce: [Del1568231] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [Del1568231] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_13)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.17.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{41E3175A-0BE7-433E-82CA-03AE7DC02D4D}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\14.2.0\ViProtocol.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{59e7e991-7e37-11e2-9de6-00262d7be3a6}\Shell - "" = AutoRun
O33 - MountPoints2\{59e7e991-7e37-11e2-9de6-00262d7be3a6}\Shell\AutoRun\command - "" = E:\PcOptions.exe
O33 - MountPoints2\{75f45eba-92fb-11e2-b25c-00262d7be3a6}\Shell - "" = AutoRun
O33 - MountPoints2\{75f45eba-92fb-11e2-b25c-00262d7be3a6}\Shell\AutoRun\command - "" = "E:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.bdmpeg - bdmpega64.acm ()
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.mjpg - bdmjpeg64.dll ()
Drivers32:64bit: vidc.mpeg - bdmpegv64.dll ()
Drivers32: msacm.bdmpeg - C:\Windows\SysWow64\bdmpega.acm ()
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.mjpg - C:\Windows\SysWow64\bdmjpeg.dll ()
Drivers32: vidc.mpeg - C:\Windows\SysWow64\bdmpegv.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/07/06 11:56:58 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Karen\Desktop\OTL.exe
[2013/07/06 11:28:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Open It!
[2013/07/06 11:28:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\OpenIt
[2013/07/06 02:04:49 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\USB Optical Mouse
[2013/07/06 02:01:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\USB Optical Mouse
[2013/07/06 02:00:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\USB Optical Mouse
[2013/07/05 16:45:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/07/04 20:48:14 | 000,000,000 | —D | C] – C:\Users\Public\Documents\CrashDump
[2013/07/04 17:09:50 | 000,000,000 | —D | C] – C:\Users\Karen\Desktop\Apks-7_4_2013
[2013/06/30 02:12:23 | 001,919,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WdfCoInstaller01005.dll
[2013/06/30 02:12:23 | 001,919,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WdfCoInstaller01005.dll
[2013/06/30 02:12:23 | 000,188,232 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadmdm.sys
[2013/06/30 02:12:23 | 000,169,288 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadbus.sys
[2013/06/30 02:12:23 | 000,038,080 | —- | C] (Google Inc) – C:\Windows\SysNative\drivers\ssadadb.sys
[2013/06/30 02:12:23 | 000,021,320 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadmdfl.sys
[2013/06/30 02:12:23 | 000,017,736 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadwhnt.sys
[2013/06/30 02:12:23 | 000,017,736 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadwh.sys
[2013/06/30 02:12:23 | 000,017,224 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadcmnt.sys
[2013/06/30 02:12:23 | 000,017,224 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadcm.sys
[2013/06/30 01:59:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
[2013/06/30 01:59:26 | 000,821,824 | —- | C] (Devguru Co., Ltd.) – C:\Windows\SysWow64\dgderapi.dll
[2013/06/24 23:07:48 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Local\Facebook
[2013/06/17 19:02:37 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/06/17 19:02:37 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/06/17 19:02:37 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/06/17 19:02:37 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/06/17 19:02:37 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/06/17 19:02:37 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/06/17 19:02:37 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/06/17 19:02:37 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/06/17 19:02:37 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/06/17 19:02:35 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/06/17 19:02:35 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/06/17 19:02:35 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/06/17 19:02:34 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/06/17 19:01:39 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/06/17 19:01:38 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/06/17 17:26:58 | 000,751,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/06/17 17:26:57 | 000,492,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\win32spl.dll
[2013/06/17 17:26:45 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptdlg.dll
[2013/06/17 17:26:45 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cryptdlg.dll
[2013/06/17 17:26:39 | 001,424,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2013/06/17 17:26:00 | 001,192,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certutil.exe
[2013/06/17 17:26:00 | 000,903,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certutil.exe
[2013/06/17 17:25:59 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/06/17 17:25:59 | 000,139,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2013/06/17 17:25:59 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certenc.dll
[2013/06/17 17:25:59 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certenc.dll
[2013/06/17 17:25:46 | 001,887,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2013/06/17 17:25:46 | 001,505,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2013/06/17 02:51:44 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\Mozilla
[2013/06/17 02:51:43 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\SpeedAnalysis2
[2013/06/17 02:51:35 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
[2013/06/16 05:25:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Acoustica Shared Effects
[2013/06/14 23:07:36 | 000,000,000 | —D | C] – C:\Users\Karen\Desktop\MINE
[2013/06/14 09:29:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\GPLGS
[2013/06/14 09:29:04 | 000,000,000 | —D | C] – C:\Program Files\PDFCreator
[2013/06/14 09:29:01 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\Babylon
[2013/06/14 09:29:01 | 000,000,000 | —D | C] – C:\ProgramData\Babylon
[2013/06/13 16:00:16 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\Malwarebytes
[2013/06/13 16:00:04 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/06/12 14:06:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\Realtek
[2013/06/12 14:05:20 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Temp
[2013/06/12 06:40:03 | 000,000,000 | —D | C] – C:\ProgramData\Innovative Solutions
[2013/06/12 06:40:03 | 000,000,000 | —D | C] – C:\Windows\Fonts\AdvUninstal
[2013/06/12 06:39:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\Innovative Solutions
[2013/06/12 05:35:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2013/06/12 05:35:39 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2013/06/12 05:25:59 | 000,000,000 | —D | C] – C:\ProgramData\SparkTrust

========== Files - Modified Within 30 Days ==========

[2013/07/06 12:14:01 | 000,000,374 | —- | M] () – C:\Windows\tasks\WpsUpdateTask_Karen.job
[2013/07/06 11:56:59 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Karen\Desktop\OTL.exe
[2013/07/06 11:51:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/07/06 11:49:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/06 11:28:53 | 000,001,078 | —- | M] () – C:\Users\Public\Desktop\Open It!.lnk
[2013/07/06 11:28:53 | 000,000,286 | —- | M] () – C:\Windows\tasks\DSite.job
[2013/07/06 11:11:50 | 000,015,824 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/07/06 11:11:50 | 000,015,824 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/07/06 11:05:18 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/06 11:03:15 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/07/06 11:03:00 | 3018,608,640 | -HS- | M] () – C:\hiberfil.sys
[2013/07/06 08:21:26 | 125,748,209 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2013/07/05 21:00:55 | 000,871,798 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/07/05 21:00:55 | 000,726,172 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/07/05 21:00:55 | 000,146,158 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/07/05 16:55:53 | 000,002,247 | —- | M] () – C:\Users\Karen\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/07/05 16:45:23 | 000,002,223 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/07/05 03:38:13 | 044,615,733 | —- | M] () – C:\Users\Karen\Desktop\I747UCDLK3_aio.tar.md5
[2013/07/04 22:17:07 | 006,400,000 | —- | M] () – C:\Users\Karen\recovery-twrp-2.5.0.0-SGHI747.tar
[2013/07/04 22:15:51 | 006,092,800 | —- | M] () – C:\Users\Karen\recovery-cwmtouch-6.0.3.1-SGHI747.tar
[2013/07/01 04:20:13 | 000,401,592 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2013/07/01 00:46:06 | 000,000,211 | —- | M] () – C:\ProgramData\acer.zip
[2013/06/30 05:22:15 | 000,000,792 | —- | M] () – C:\Users\Karen\Desktop\New folder - Shortcut.lnk
[2013/06/30 01:59:45 | 000,001,994 | —- | M] () – C:\Users\Karen\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies (Lite).lnk
[2013/06/30 01:59:45 | 000,001,984 | —- | M] () – C:\Users\Karen\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2013/06/30 01:57:54 | 000,866,014 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/06/29 05:38:31 | 000,007,601 | —- | M] () – C:\Users\Karen\AppData\Local\Resmon.ResmonCfg
[2013/06/17 00:21:48 | 000,000,005 | —- | M] () – C:\Users\Karen\AppData\Roaming\WBPU-TTL.DAT
[2013/06/12 06:03:58 | 000,073,612 | —- | M] () – C:\Users\Karen\Documents\cc_20130612_060345.reg
[2013/06/11 19:09:51 | 000,011,623 | —- | M] () – C:\Users\Karen\AppData\Roaming\UserTile.png
[2013/06/11 17:51:22 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/06/11 17:51:22 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/06/08 09:06:58 | 000,526,336 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/06/08 06:40:02 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll

========== Files Created - No Company Name ==========

[2013/07/06 11:28:53 | 000,001,078 | —- | C] () – C:\Users\Public\Desktop\Open It!.lnk
[2013/07/05 16:45:23 | 000,002,223 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/07/05 16:44:49 | 000,000,896 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/05 16:44:48 | 000,000,892 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/05 03:37:24 | 044,615,733 | —- | C] () – C:\Users\Karen\Desktop\I747UCDLK3_aio.tar.md5
[2013/07/04 22:17:07 | 006,400,000 | —- | C] () – C:\Users\Karen\recovery-twrp-2.5.0.0-SGHI747.tar
[2013/07/04 22:15:51 | 006,092,800 | —- | C] () – C:\Users\Karen\recovery-cwmtouch-6.0.3.1-SGHI747.tar
[2013/06/30 05:22:15 | 000,000,792 | —- | C] () – C:\Users\Karen\Desktop\New folder - Shortcut.lnk
[2013/06/30 01:59:45 | 000,001,994 | —- | C] () – C:\Users\Karen\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies (Lite).lnk
[2013/06/30 01:59:45 | 000,001,984 | —- | C] () – C:\Users\Karen\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2013/06/16 00:30:31 | 000,000,005 | —- | C] () – C:\Users\Karen\AppData\Roaming\WBPU-TTL.DAT
[2013/06/12 06:03:51 | 000,073,612 | —- | C] () – C:\Users\Karen\Documents\cc_20130612_060345.reg
[2013/06/11 19:09:51 | 000,011,623 | —- | C] () – C:\Users\Karen\AppData\Roaming\UserTile.png
[2013/05/27 00:39:51 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2013/05/27 00:39:51 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2013/05/27 00:39:45 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2013/05/22 20:43:52 | 000,030,568 | —- | C] () – C:\Windows\MusiccityDownload.exe
[2013/05/15 22:47:06 | 000,003,584 | —- | C] () – C:\Users\Karen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/05/15 13:51:41 | 000,000,047 | —- | C] () – C:\Windows\WinInit.Ini
[2013/05/01 15:25:32 | 000,004,096 | —- | C] () – C:\Windows\d3dx.dat
[2013/02/11 19:14:10 | 000,000,258 | RHS- | C] () – C:\Users\Karen\ntuser.pol
[2013/02/05 17:52:50 | 000,974,848 | —- | C] () – C:\Windows\SysWow64\cis-2.4.dll
[2013/02/05 17:52:50 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2013/02/05 17:52:50 | 000,065,536 | —- | C] () – C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2013/02/05 17:52:50 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\issacapi_se-2.3.dll
[2013/02/01 01:46:57 | 000,000,211 | —- | C] () – C:\ProgramData\acer.zip
[2013/01/22 03:11:45 | 000,109,784 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2013/01/21 09:24:37 | 000,866,014 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/11/24 09:34:32 | 000,007,601 | —- | C] () – C:\Users\Karen\AppData\Local\Resmon.ResmonCfg
[2012/11/19 02:33:32 | 000,065,656 | —- | C] () – C:\Windows\SysWow64\bdmpegv.dll
[2012/11/19 02:33:30 | 000,022,640 | —- | C] () – C:\Windows\SysWow64\bdmjpeg.dll
[2012/11/17 01:47:00 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 00:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/26 23:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 07:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/04/08 10:03:12 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Acoustica
[2013/03/09 04:22:57 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\AVG
[2013/06/17 17:15:07 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\AVG2012
[2013/06/14 09:29:01 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Babylon
[2013/06/17 17:15:07 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\BANDISOFT
[2013/06/29 09:04:11 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Canon
[2013/01/21 09:45:12 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\com.AdamOutler
[2013/04/27 20:38:21 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\DriverCure
[2013/05/15 19:44:32 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\DSite
[2013/01/13 09:54:30 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\FileOpen
[2013/05/08 22:00:54 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\FixBee
[2013/06/12 07:12:56 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\iPumper
[2013/06/17 17:10:29 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Kingsoft
[2013/05/14 22:43:09 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Lexmark Productivity Studio
[2013/05/15 19:48:46 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Mipony
[2013/03/17 03:21:04 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\MusicNet
[2013/05/18 15:22:23 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Nico Mak Computing
[2013/06/17 17:10:32 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Nitro
[2013/02/04 04:20:18 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Nitro PDF
[2013/07/03 03:45:47 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Notepad++
[2013/06/17 17:10:33 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\OpenOffice.org
[2013/02/18 13:13:55 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\PDF Architect
[2013/06/17 02:57:57 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\PerformerSoft
[2013/06/17 17:15:08 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Pinger Inc
[2013/06/17 17:15:08 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\player
[2013/05/07 12:58:06 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Sammsoft
[2013/03/21 23:12:30 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Samsung
[2013/06/17 02:51:44 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\SpeedAnalysis2
[2013/01/27 20:28:12 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\StatusWinks
[2013/05/24 02:52:29 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Strongvault
[2013/04/08 10:03:19 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\SynthMaker
[2013/03/04 19:20:20 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\TuneUp Software
[2013/02/28 07:38:35 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Unified Remote
[2013/01/07 20:22:35 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Unity
[2013/07/06 02:04:49 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\USB Optical Mouse
[2013/07/06 11:30:23 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\uTorrent
[2013/05/15 00:09:25 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\X5400 Series

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2009/07/13 21:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 15:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 01:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 07:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 08:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 21:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 21:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/13 21:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 21:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: EXPLORER.EXE-D5E97654.PF >
[2013/07/06 11:08:23 | 000,068,468 | —- | M] () MD5=39AA2CE244EFAC50D7139B346070AFAA – C:\Windows\Prefetch\EXPLORER.EXE-D5E97654.pf

< MD5 for: IEXPLORE.EXE >
[2013/01/08 20:53:45 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=0100BCF23941C83462E4A70F94C3392E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_0d2c5bc980874648\iexplore.exe
[2013/05/16 21:32:12 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=07DFD28E57879554D054464EE4A5662D – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/05/16 21:32:12 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=07DFD28E57879554D054464EE4A5662D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16614_none_20d88bb252a3770f\iexplore.exe
[2012/11/13 21:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_178ed6e5b4dd3857\iexplore.exe
[2012/11/18 00:02:28 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_178cd651b4df05a9\iexplore.exe
[2013/03/12 19:47:53 | 000,770,560 | —- | M] (Microsoft Corporation) MD5=2859EBC065D2E1CCC94161CE28BAC085 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16521_none_20e4a040529a2792\iexplore.exe
[2013/02/24 19:58:09 | 000,775,232 | —- | M] (Microsoft Corporation) MD5=28F93BAFB3EB407E99A7ED3D9DBDE04C – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20644_none_ffb93ba237e760ce\iexplore.exe
[2013/04/05 00:55:38 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=2DC6BD1047553611DAEF97C751131A5D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20681_none_0a122b746c443b42\iexplore.exe
[2013/05/16 20:57:28 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=3902E280F6117A468D5573343A7AA1F6 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20719_none_09ffa3426c5372da\iexplore.exe
[2012/11/18 00:02:22 | 000,754,848 | —- | M] (Microsoft Corporation) MD5=49442BA6DCE4B4E3C1CB0AB193FE29AD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_0d382bff807e43ae\iexplore.exe
[2013/02/21 07:59:57 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=6554208814632C25C77EE02355EB8E95 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16540_none_16920d4a1e377ea4\iexplore.exe
[2013/03/12 19:47:49 | 000,775,184 | —- | M] (Microsoft Corporation) MD5=681B380492ACB571ED6CCC1F37F53343 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16521_none_168ff5ee1e396597\iexplore.exe
[2013/01/08 17:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_1781061bb4e80843\iexplore.exe
[2013/02/02 03:09:12 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=7C2923004FFC497E54F38E835F108EE8 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_0d9c579499b8b898\iexplore.exe
[2013/05/16 22:02:08 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=8F00471CA24ADF8D2AFAACF856EB70A4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20719_none_ffaaf8f037f2b0df\iexplore.exe
[2013/02/24 18:52:40 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=A11C5E3E288256C540B7ED8BE3A04B01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20644_none_0a0de5f46c4822c9\iexplore.exe
[2013/02/01 23:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_17f101e6ce197a93\iexplore.exe
[2013/02/02 02:37:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=A8EBEBCD9F5C49475194099FCD276992 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_0d1d8ab58092fcdd\iexplore.exe
[2013/04/05 01:02:26 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=AAD90795E84E710543C6C7C2F7048E30 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16576_none_20e92fca5296266a\iexplore.exe
[2012/11/15 22:08:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=AC4957E154F750DF54F36ADC8E3E040D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_0db6f8de99a3ff69\iexplore.exe
[2013/04/05 02:53:33 | 000,775,232 | —- | M] (Microsoft Corporation) MD5=CEA304830B4770BDA3572B87D0841848 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16576_none_169485781e35646f\iexplore.exe
[2013/02/01 23:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_17723507b4f3bed8\iexplore.exe
[2013/04/05 02:23:03 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=DE751E18F8DBF7BCCE46989CBA4A9828 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20681_none_ffbd812237e37947\iexplore.exe
[2013/02/21 06:28:11 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16540_none_20e6b79c5298409f\iexplore.exe
[2013/05/16 22:30:45 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=EDC77CF787FA015205936C9A3228486E – C:\Program Files\Internet Explorer\iexplore.exe
[2013/05/16 22:30:45 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=EDC77CF787FA015205936C9A3228486E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16614_none_1683e1601e42b514\iexplore.exe
[2013/01/08 19:51:57 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=EF1F6F41FB2C9BBB484B21017F380201 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_0daa285e99ade8ac\iexplore.exe
[2013/01/08 16:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_17fed2b0ce0eaaa7\iexplore.exe
[2012/11/13 21:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_180ba330ce04c164\iexplore.exe
[2012/11/14 02:11:18 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_0d3a2c93807c765c\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2012/11/18 00:02:23 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2012/11/18 00:02:28 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2013/03/12 19:47:53 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2013/03/12 19:47:49 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/03/12 19:47:49 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_103c8b6555e6a67e\iexplore.exe.mui
[2013/03/12 19:47:53 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_1a9135b78a476879\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-A033F7A0.PF >
[2013/07/05 16:49:24 | 000,122,998 | —- | M] () MD5=50DD82EA441D65DF8B41599834D6E0DE – C:\Windows\Prefetch\IEXPLORE.EXE-A033F7A0.pf

< MD5 for: SERVICES >
[2009/06/10 16:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.CFG >
[2012/09/23 21:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2013/05/11 05:37:26 | 000,558,990 | —- | M] () MD5=FE8FB005031C2574E990DAC1F9F5ACF8 – C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Services\Services.cfg

< MD5 for: SERVICES.EXE >
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 21:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2009/07/13 21:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2009/07/13 21:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2009/07/13 21:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2009/07/13 21:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/07/13 21:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2009/07/13 21:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 16:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 08:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/20 08:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2009/07/13 21:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/13 21:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2009/07/13 20:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2013/07/06 11:03:00 | 3018,608,640 | -HS- | M] () – C:\hiberfil.sys
[2013/07/06 11:03:06 | 4024,811,520 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2012/11/25 20:49:31 | 000,001,670 | -HS- | M] () – C:\Users\Karen\AppData\Roaming\Microsoft\LastFlashConfig.wfc

< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is ACER
Volume Serial Number is 58AF-192C
Directory of C:\
07/14/2009 12:08 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/14/2009 12:08 AM Application Data [C:\ProgramData]
07/14/2009 12:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/14/2009 12:08 AM All Users [C:\ProgramData]
07/14/2009 12:08 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\14d Trial - MX6 6-23
06/23/2013 02:04 PM Application Data [C:\Users\14d Trial - MX6 6-23\AppData\Roaming]
06/23/2013 02:04 PM Cookies [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\Cookies]
06/23/2013 02:04 PM Local Settings [C:\Users\14d Trial - MX6 6-23\AppData\Local]
06/23/2013 02:04 PM My Documents [C:\Users\14d Trial - MX6 6-23\Documents]
06/23/2013 02:04 PM NetHood [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
06/23/2013 02:04 PM PrintHood [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
06/23/2013 02:04 PM Recent [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\Recent]
06/23/2013 02:04 PM SendTo [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\SendTo]
06/23/2013 02:04 PM Start Menu [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\Start Menu]
06/23/2013 02:04 PM Templates [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\14d Trial - MX6 6-23\AppData\Local
06/23/2013 02:04 PM Application Data [C:\Users\14d Trial - MX6 6-23\AppData\Local]
06/23/2013 02:04 PM History [C:\Users\14d Trial - MX6 6-23\AppData\Local\Microsoft\Windows\History]
06/23/2013 02:04 PM Temporary Internet Files [C:\Users\14d Trial - MX6 6-23\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\14d Trial - MX6 6-23\Documents
06/23/2013 02:04 PM My Music [C:\Users\14d Trial - MX6 6-23\Music]
06/23/2013 02:04 PM My Pictures [C:\Users\14d Trial - MX6 6-23\Pictures]
06/23/2013 02:04 PM My Videos [C:\Users\14d Trial - MX6 6-23\Videos]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/14/2009 12:08 AM Application Data [C:\ProgramData]
07/14/2009 12:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Cecil
11/21/2012 08:26 PM Application Data [C:\Users\Cecil\AppData\Roaming]
11/21/2012 08:26 PM Cookies [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\Cookies]
11/21/2012 08:26 PM Local Settings [C:\Users\Cecil\AppData\Local]
11/21/2012 08:26 PM My Documents [C:\Users\Cecil\Documents]
11/21/2012 08:26 PM NetHood [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
11/21/2012 08:26 PM PrintHood [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
11/21/2012 08:26 PM Recent [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\Recent]
11/21/2012 08:26 PM SendTo [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\SendTo]
11/21/2012 08:26 PM Start Menu [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\Start Menu]
11/21/2012 08:26 PM Templates [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Cecil\AppData\Local
11/21/2012 08:26 PM Application Data [C:\Users\Cecil\AppData\Local]
11/21/2012 08:26 PM History [C:\Users\Cecil\AppData\Local\Microsoft\Windows\History]
11/21/2012 08:26 PM Temporary Internet Files [C:\Users\Cecil\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Cecil\Documents
11/21/2012 08:26 PM My Music [C:\Users\Cecil\Music]
11/21/2012 08:26 PM My Pictures [C:\Users\Cecil\Pictures]
11/21/2012 08:26 PM My Videos [C:\Users\Cecil\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/14/2009 12:08 AM Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009 12:08 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009 12:08 AM Local Settings [C:\Users\Default\AppData\Local]
07/14/2009 12:08 AM My Documents [C:\Users\Default\Documents]
07/14/2009 12:08 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009 12:08 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009 12:08 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009 12:08 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009 12:08 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/14/2009 12:08 AM Application Data [C:\Users\Default\AppData\Local]
07/14/2009 12:08 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009 12:08 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/14/2009 12:08 AM My Music [C:\Users\Default\Music]
07/14/2009 12:08 AM My Pictures [C:\Users\Default\Pictures]
07/14/2009 12:08 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Karen
11/17/2012 01:29 AM Application Data [C:\Users\Karen\AppData\Roaming]
11/17/2012 01:29 AM Cookies [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Cookies]
11/17/2012 01:29 AM Local Settings [C:\Users\Karen\AppData\Local]
11/17/2012 01:29 AM My Documents [C:\Users\Karen\Documents]
11/17/2012 01:29 AM NetHood [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
11/17/2012 01:29 AM PrintHood [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
11/17/2012 01:29 AM Recent [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Recent]
11/17/2012 01:29 AM SendTo [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\SendTo]
11/17/2012 01:29 AM Start Menu [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Start Menu]
11/17/2012 01:29 AM Templates [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Karen\AppData\Local
11/17/2012 01:29 AM Application Data [C:\Users\Karen\AppData\Local]
11/17/2012 01:29 AM History [C:\Users\Karen\AppData\Local\Microsoft\Windows\History]
11/17/2012 01:29 AM Temporary Internet Files [C:\Users\Karen\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Karen\Documents
11/17/2012 01:29 AM My Music [C:\Users\Karen\Music]
11/17/2012 01:29 AM My Pictures [C:\Users\Karen\Pictures]
11/17/2012 01:29 AM My Videos [C:\Users\Karen\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/14/2009 12:08 AM My Music [C:\Users\Public\Music]
07/14/2009 12:08 AM My Pictures [C:\Users\Public\Pictures]
07/14/2009 12:08 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public Account
04/24/2013 05:00 PM Application Data [C:\Users\Public Account\AppData\Roaming]
04/24/2013 05:00 PM Cookies [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\Cookies]
04/24/2013 05:00 PM Local Settings [C:\Users\Public Account\AppData\Local]
04/24/2013 05:00 PM My Documents [C:\Users\Public Account\Documents]
04/24/2013 05:00 PM NetHood [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
04/24/2013 05:00 PM PrintHood [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
04/24/2013 05:00 PM Recent [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\Recent]
04/24/2013 05:00 PM SendTo [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\SendTo]
04/24/2013 05:00 PM Start Menu [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\Start Menu]
04/24/2013 05:00 PM Templates [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Public Account\AppData\Local
04/24/2013 05:00 PM Application Data [C:\Users\Public Account\AppData\Local]
04/24/2013 05:00 PM History [C:\Users\Public Account\AppData\Local\Microsoft\Windows\History]
04/24/2013 05:00 PM Temporary Internet Files [C:\Users\Public Account\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Public Account\Documents
04/24/2013 05:00 PM My Music [C:\Users\Public Account\Music]
04/24/2013 05:00 PM My Pictures [C:\Users\Public Account\Pictures]
04/24/2013 05:00 PM My Videos [C:\Users\Public Account\Videos]
0 File(s) 0 bytes
Directory of C:\Users\test
06/16/2013 05:44 AM Application Data [C:\Users\test\AppData\Roaming]
06/16/2013 05:44 AM Cookies [C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies]
06/16/2013 05:44 AM Local Settings [C:\Users\test\AppData\Local]
06/16/2013 05:44 AM My Documents [C:\Users\test\Documents]
06/16/2013 05:44 AM NetHood [C:\Users\test\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
06/16/2013 05:44 AM PrintHood [C:\Users\test\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
06/16/2013 05:44 AM Recent [C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent]
06/16/2013 05:44 AM SendTo [C:\Users\test\AppData\Roaming\Microsoft\Windows\SendTo]
06/16/2013 05:44 AM Start Menu [C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu]
06/16/2013 05:44 AM Templates [C:\Users\test\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\test\AppData\Local
06/16/2013 05:44 AM Application Data [C:\Users\test\AppData\Local]
06/16/2013 05:44 AM History [C:\Users\test\AppData\Local\Microsoft\Windows\History]
06/16/2013 05:44 AM Temporary Internet Files [C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\test\Documents
06/16/2013 05:44 AM My Music [C:\Users\test\Music]
06/16/2013 05:44 AM My Pictures [C:\Users\test\Pictures]
06/16/2013 05:44 AM My Videos [C:\Users\test\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
114 Dir(s) 217,006,120,960 bytes free

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/11/18 03:06:52 | 000,000,221 | -HS- | M] () – C:\Users\Karen\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2013/07/06 11:56:59 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Karen\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 205 bytes -> C:\ProgramData\TEMP:0B4227B4

< End of report >

OTL Extras logfile created on: 7/6/2013 12:19:29 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Karen\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16614)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 2.68 Gb Available Physical Memory | 71.48% Memory free
7.50 Gb Paging File | 6.10 Gb Available in Paging File | 81.33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 286.27 Gb Total Space | 202.13 Gb Free Space | 70.61% Space Free | Partition Type: NTFS

Computer Name: KAREN-PC | User Name: Karen | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04353690-03D4-4A57-9863-4DBDCEB97442}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0A528707-4401-4F98-8432-16242EC3E287}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{1E951B86-E28F-4DD0-BD2A-7FA925210629}" = lport=138 | protocol=17 | dir=in | app=system |
"{449985BB-9195-4E88-8634-8016EEF0B94E}" = rport=445 | protocol=6 | dir=out | app=system |
"{4C1FF8B0-DF2A-46A0-96B6-E58B479D3DAC}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4E090BA2-FC5E-4603-943C-670857F6331C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{56C274C6-046C-4C64-BD06-9EE20D093BE8}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{596DBDF7-85D2-488A-B838-6A969CE77F9C}" = rport=138 | protocol=17 | dir=out | app=system |
"{751F9B82-3A12-4656-94DE-9FB96B237879}" = lport=137 | protocol=17 | dir=in | app=system |
"{80BBCCF9-033E-482E-B72D-2C98977A6066}" = rport=139 | protocol=6 | dir=out | app=system |
"{87D08CB7-FF0E-4E1B-A89C-2E785D494F14}" = rport=10243 | protocol=6 | dir=out | app=system |
"{8DC73AA1-EFF9-4783-95E5-AD3F0CE0894D}" = lport=6102 | protocol=6 | dir=in | name=rdm |
"{A64D2A49-DC84-41AD-985D-C4ACE09E60CC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A74C8063-62ED-41AE-B487-975BBAE77AA1}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{AE3F06D3-7775-4B0E-B458-8F69080537AB}" = lport=139 | protocol=6 | dir=in | app=system |
"{BED21E29-E923-4815-9206-17AFADE16E2D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C3A66DDF-E9A2-4C6E-8029-3A6F0317F4C3}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D1EA2668-418B-4ADC-9A41-B6B20AA1152A}" = rport=137 | protocol=17 | dir=out | app=system |
"{E0C150C3-94F5-40A6-8967-73BD94722284}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E3F416FF-410E-42E7-9D44-9D4F88E5321A}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E7DC880E-9467-482F-9B2A-A48406F6CCB9}" = lport=10243 | protocol=6 | dir=in | app=system |
"{E85E3204-E598-4EFB-B68B-9A9E7B42A4CD}" = lport=445 | protocol=6 | dir=in | app=system |
"{F02E49F6-D3D8-47A8-8A4E-37BB0EADC9EE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0A641224-7230-400C-9395-188024214D22}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{12A25B82-8FE4-455C-99DC-65234700253F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{17D1EFB9-2EEF-4E31-B922-3565EE6B0D29}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{208BFEF4-257A-4744-BEC7-DFF27732712C}" = protocol=17 | dir=in | app=c:\users\karen\appdata\roaming\utorrent\utorrent.exe |
"{212CC471-B83C-4989-8123-E92E5D7694CF}" = protocol=6 | dir=out | app=system |
"{217DD729-2729-4EF5-91B8-3724F90E3F46}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{2BE468CF-739A-4A49-B9E1-447DCD227CF1}" = protocol=17 | dir=in | app=c:\windows\syswow64\muzapp.exe |
"{2CB7F60B-F2A1-4D52-B0B7-505744938BDA}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{2D66DF65-85A1-46A1-AA20-930EBE03E7B0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{2DF4A00C-5F00-49ED-8585-A8FC345CFDCF}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{2EC655F1-820C-4036-8DB4-8DA7AAA0CF76}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{35CB2FC3-4D0E-4610-B08A-E79F179E4D1B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3CAAF28C-30D0-4F01-8822-E927768F0476}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{3D6DEBDB-EF5C-4037-95CB-F9D80CDF5ADD}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4F2E5FA2-773C-4EF7-B933-268060A43C4B}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{4FF73137-72FC-4EFE-937C-D800DFAFA75F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{53FC0DD2-86D5-4073-9D0B-FADF8011C6AF}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{5CA8B13D-3CB0-44F0-85E1-FEC219813A31}" = dir=in | app=c:\program files (x86)\file type assistant\tsassist.exe |
"{5D13D74D-6CFF-4B37-BB06-502123AD0789}" = protocol=6 | dir=in | app=c:\windows\syswow64\muzapp.exe |
"{675DA394-AEC4-43AB-B7FF-FA2A947256A6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6A477AFA-A2A9-43CD-9D52-DDCBF3879B93}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{6BDFEFBF-3283-4FD2-960B-C625572F08D8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7E4993FE-BAC1-42C0-A598-AE02C431DA32}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{8D4FC570-77DA-461C-A57D-9E4A60D01F97}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{934F65A0-62F9-4BA2-AF92-001E322E6A2E}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{9A2A56F3-E746-42CC-9EAA-7F295C7A473F}" = dir=in | app=c:\program files (x86)\file type assistant\tsassist.exe |
"{9AED4ED0-DF61-41A2-A2D0-83CE65951BBE}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{AA298193-39C5-4CF9-91CD-FC6110CFC106}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{AA766D47-2BDC-4B77-A0A5-FC8FCE2F6143}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{AB93609D-B3D8-433C-A690-A3314BB51067}" = protocol=6 | dir=in | app=c:\users\karen\appdata\roaming\utorrent\utorrent.exe |
"{C437F080-C2C6-4DEB-8F30-9AC722DA96E1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{CDC4C15B-1196-4257-97FE-8D30B4121EDD}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DBC5B321-F6D1-4C99-80D7-0C15AE122854}" = dir=in | app=c:\program files (x86)\file type assistant\tsassist.exe |
"{DC299E5B-CDFD-4D64-81FC-6B07700C00DB}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{EE97D8AC-B6D8-4870-B8F6-5FFC7B68875C}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{F43AA4BA-2052-4F30-8A18-5003F6DA099C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{FDFF5759-4AA0-4E6C-90FD-7BFB33C026A6}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.0 RC4
"{21B133D6-5979-47F0-BE1C-F6A6B304693F}" = Visual Studio 2010 x64 Redistributables
"{26A24AE4-039D-4CA4-87B4-2F86417017FF}" = Java 7 Update 17 (64-bit)
"{2F14965D-567B-4E59-ADEB-0A2CC1E3ADDF}" = Sql Server Customer Experience Improvement Program
"{5340A3B5-3853-4745-BED2-DD9FF5371331}" = Microsoft SQL Server 2008 Common Files
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7ACE202B-1B01-4B43-B6AE-03D66D621CDE}" = Microsoft SQL Server 2008 RsFx Driver
"{893F27E6-D6BE-4B9F-80E6-0ADA694A31A8}" = Microsoft SQL Server 2008 Common Files
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{BCA26999-EC22-3007-BB79-638913079C9A}" = Microsoft Visual Studio 2010 Express Prerequisites x64 - ENU
"{CC8BA866-16A7-4667-BA0C-C494A1E7B2BF}" = Microsoft SQL Server 2008 Database Engine Shared
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D50E19B5-A29A-4A78-8381-0E562B40CDFD}" = AVG 2012
"{DF167CE3-60E7-44EA-99EC-2507C51F37AE}" = Microsoft SQL Server 2008 Database Engine Shared
"{DFE4E6BB-70F0-4292-B7EB-7A3AD48EBB5C}" = AVG 2012
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FA7394B8-CE65-4F9E-AC99-F372AD365424}" = Microsoft SQL Server 2008 Database Engine Services
"{FBD367D1-642F-47CF-B79B-9BE48FB34007}" = Microsoft SQL Server 2008 Database Engine Services
"{FCADA26A-5672-31DD-BF0E-BA76ECF9B02D}" = Microsoft Help Viewer 1.0
"AVG" = AVG 2012
"CCleaner" = CCleaner
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2BFAOR2C06_118" = HDAUDIO Soft Data Fax Modem with SmartCP
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0
"WinRAR archiver" = WinRAR 4.00 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{23170F69-40C1-2701-0921-000001000000}" = 7-Zip 9.21
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 21
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.03)
"{BA8B8ADA-084F-4F79-A0CA-6E58A0808794}" = FlashPlayer
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{EEAE45EB-C1E3-4CCD-930D-D7B40F810063}" = USB Optical Mouse
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"Acoustica Mixcraft 6" = Acoustica Mixcraft 6
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AVG Secure Search" = AVG Security Toolbar
"Bandicam" = Bandicam
"BandiMPEG1" = Bandisoft MPEG-1 Decoder
"DomaIQ Uninstaller" = DomaIQ
"Google Chrome" = Google Chrome
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"Kingsoft Office" = Kingsoft Office 2012 (8.1.0.3385)
"OpenIt Open It!" = Open It!
"Trusted Software Assistant_is1" = File Type Assistant
"uTorrent" = µTorrent

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"DSite" = Update for Zip Opener

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 4/15/2013 11:12:21 PM | Computer Name = Karen-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1199461

Error - 4/15/2013 11:12:22 PM | Computer Name = Karen-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 4/15/2013 11:12:22 PM | Computer Name = Karen-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1200678

Error - 4/15/2013 11:12:22 PM | Computer Name = Karen-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1200678

Error - 4/17/2013 1:02:57 PM | Computer Name = Karen-PC | Source = Windows Search Service | ID = 3038
Description =

Error - 4/17/2013 1:02:58 PM | Computer Name = Karen-PC | Source = Windows Search Service | ID = 7040
Description =

Error - 4/17/2013 1:02:58 PM | Computer Name = Karen-PC | Source = Windows Search Service | ID = 7042
Description =

Error - 4/17/2013 1:02:59 PM | Computer Name = Karen-PC | Source = Windows Search Service | ID = 3028
Description =

Error - 4/17/2013 1:02:59 PM | Computer Name = Karen-PC | Source = Windows Search Service | ID = 3058
Description =

Error - 4/17/2013 1:02:59 PM | Computer Name = Karen-PC | Source = Windows Search Service | ID = 7010
Description =

[ Media Center Events ]
Error - 12/22/2012 12:49:22 AM | Computer Name = Karen-PC | Source = MCUpdate | ID = 0
Description = 10:49:22 PM - Error connecting to the internet. 10:49:22 PM - Unable
to contact server..

Error - 12/22/2012 12:52:52 AM | Computer Name = Karen-PC | Source = MCUpdate | ID = 0
Description = 10:52:47 PM - Error connecting to the internet. 10:52:47 PM - Unable
to contact server..

Error - 12/22/2012 6:23:33 AM | Computer Name = Karen-PC | Source = MCUpdate | ID = 0
Description = 4:23:33 AM - Error connecting to the internet. 4:23:33 AM - Unable
to contact server..

Error - 12/22/2012 6:24:29 AM | Computer Name = Karen-PC | Source = MCUpdate | ID = 0
Description = 4:24:28 AM - Error connecting to the internet. 4:24:28 AM - Unable
to contact server..

Error - 5/28/2013 5:02:58 PM | Computer Name = Karen-PC | Source = MCUpdate | ID = 0
Description = 4:02:57 PM - Error connecting to the internet. 4:02:57 PM - Unable
to contact server..

[ System Events ]
Error - 7/6/2013 11:16:09 AM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535

Error - 7/6/2013 12:05:56 PM | Computer Name = Karen-PC | Source = PNRPSvc | ID = 102
Description =

Error - 7/6/2013 12:05:56 PM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535

Error - 7/6/2013 12:05:56 PM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
error: %%-2140993535

Error - 7/6/2013 12:06:04 PM | Computer Name = Karen-PC | Source = PNRPSvc | ID = 102
Description =

Error - 7/6/2013 12:06:04 PM | Computer Name = Karen-PC | Source = PNRPSvc | ID = 102
Description =

Error - 7/6/2013 12:06:04 PM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
error: %%-2140993535

Error - 7/6/2013 12:06:04 PM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535

Error - 7/6/2013 12:06:04 PM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
error: %%-2140993535

Error - 7/6/2013 12:06:04 PM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535


< End of report >
:welcome:

You have some bogus toolbars and such, lets get rid of them

First, lets make sure there isn't a rootkit involved

aswMBR Log

Important! Please do not perform any fix options offered in aswMBR

Please download aswMBR to your desktop.


  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the Save Log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Here is the logfile you requested. Thank you for your time. aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software Run date: 2013-07-12 03:40:59 —————————– 03:40:59.435 OS Version: Windows x64 6.1.7601 Service Pack 1 03:40:59.435 Number of processors: 2 586 0x602 03:40:59.436 ComputerName: KAREN-PC UserName: Karen 03:41:01.003 Initialize success 03:45:34.984 AVAST engine defs: 13071102 03:46:08.834 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 03:46:08.840 Disk 0 Vendor: WDC_WD3200BEVT-22ZCT0 11.01A11 Size: 305245MB BusType: 3 03:46:08.945 Disk 0 MBR read successfully 03:46:08.951 Disk 0 MBR scan 03:46:08.962 Disk 0 Windows 7 default MBR code 03:46:08.970 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 12000 MB offset 2048 03:46:08.988 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 24578048 03:46:09.002 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 293143 MB offset 24782848 03:46:09.027 Disk 0 scanning C:\Windows\system32\drivers 03:46:22.941 Service scanning 03:47:00.483 Modules scanning 03:47:00.502 Disk 0 trace - called modules: 03:47:00.556 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys 03:47:00.916 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80046a7060] 03:47:00.929 3 CLASSPNP.SYS[fffff8800180a43f] -> nt!IofCallDriver -> [0xfffffa80044da520] 03:47:00.941 5 ACPI.sys[fffff88000e0b7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80044e0060] 03:47:02.575 AVAST engine scan C:\Windows 03:47:05.445 AVAST engine scan C:\Windows\system32 03:52:44.784 AVAST engine scan C:\Windows\system32\drivers 03:53:03.007 AVAST engine scan C:\Users\Karen 03:59:56.150 AVAST engine scan C:\ProgramData 04:01:59.465 Scan finished successfully 04:03:47.072 Disk 0 MBR has been saved successfully to "C:\Users\Karen\Desktop\MBR.dat" 04:03:47.087 The log file has been saved successfully to "C:\Users\Karen\Desktop\aswMBR.txt"
Good Morning,

Lets get rid of that garbage

Go here and download AdwCleaner to your desktop

  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete
  • A logfile will automatically open after the scan has finished.
  • Please post the content of that logfile in your reply.
  • You can find the logfile at C:\AdwCleaner[Rn].txt as well - n is the order number.

[external image: Posted Image]







Please download Junkware Removal Tool to your desktop.
  • Shutdown your antivirus to avoid any conflicts.
  • Double click JRT.exe to run the tool
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message
Next
  • Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please



Let me see the reports for each of the above tools please
Here are the requested results. In order # AdwCleaner v2.305 - Logfile created 07/12/2013 at 10:05:03 # Updated 11/07/2013 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Karen - KAREN-PC # Boot Mode : Normal # Running from : C:\Users\Karen\Desktop\AdwCleaner.exe # Option [Delete] ***** [Services] ***** Stopped & Deleted : vToolbarUpdater14.2.0 ***** [Files / Folders] ***** File Deleted : C:\Windows\Tasks\DSite.job Folder Deleted : C:\Program Files (x86)\AVG Secure Search Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search Folder Deleted : C:\Program Files (x86)\Conduit Folder Deleted : C:\Program Files\DomaIQ Uninstaller Folder Deleted : C:\ProgramData\APN Folder Deleted : C:\ProgramData\Ask Folder Deleted : C:\ProgramData\AVG Secure Search Folder Deleted : C:\ProgramData\Babylon Folder Deleted : C:\ProgramData\Browser Manager Folder Deleted : C:\ProgramData\cioonteinuEitossave Folder Deleted : C:\ProgramData\cyontinyueotoSavE Folder Deleted : C:\ProgramData\InstallMate Folder Deleted : C:\ProgramData\SpeedMaxPc Folder Deleted : C:\ProgramData\Syeuaorch-NewTaab Folder Deleted : C:\ProgramData\Tarma Installer Folder Deleted : C:\ProgramData\Wondershare Folder Deleted : C:\Users\Cecil\AppData\Local\AVG Secure Search Folder Deleted : C:\Users\Karen\AppData\Local\APN Folder Deleted : C:\Users\Karen\AppData\Local\AVG Secure Search Folder Deleted : C:\Users\Karen\AppData\Local\Conduit Folder Deleted : C:\Users\Karen\AppData\Local\Discount Buddy Folder Deleted : C:\Users\Karen\AppData\Local\iac Folder Deleted : C:\Users\Karen\AppData\Local\PackageAware Folder Deleted : C:\Users\Karen\AppData\Local\SwvUpdater Folder Deleted : C:\Users\Karen\AppData\Local\Wondershare Folder Deleted : C:\Users\Karen\AppData\LocalLow\AVG Secure Search Folder Deleted : C:\Users\Karen\AppData\LocalLow\Claro LTD Folder Deleted : C:\Users\Karen\AppData\LocalLow\Conduit Folder Deleted : C:\Users\Karen\AppData\LocalLow\iac Folder Deleted : C:\Users\Karen\AppData\LocalLow\Syeuaorch-NewTaab Folder Deleted : C:\Users\Karen\AppData\Roaming\Babylon Folder Deleted : C:\Users\Karen\AppData\Roaming\DriverCure Folder Deleted : C:\Users\Karen\AppData\Roaming\DSite Folder Deleted : C:\Users\Karen\AppData\Roaming\PerformerSoft Folder Deleted : C:\Users\Karen\AppData\Roaming\SpeedAnalysis2 Folder Deleted : C:\Users\Karen\AppData\Roaming\StatusWinks Folder Deleted : C:\Users\Public Account\AppData\Local\AVG Secure Search Folder Deleted : C:\Users\Public Account\AppData\Local\Ilivid Folder Deleted : C:\Users\Public Account\AppData\Local\Wondershare ***** [Registry] ***** Key Deleted : HKCU\Software\1ClickDownload Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider Key Deleted : HKCU\Software\AppDataLow\Software\LyricsFinder Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar Key Deleted : HKCU\Software\AppDataLow\SProtector Key Deleted : HKCU\Software\AVG Secure Search Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\DataMngr Key Deleted : HKCU\Software\ExpressFiles Key Deleted : HKCU\Software\ilivid Key Deleted : HKCU\Software\Imesh Key Deleted : HKCU\Software\InstallCore Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com Key Deleted : HKCU\Software\Softonic Key Deleted : HKCU\Software\SpeedMaxPC Key Deleted : HKCU\Software\5ee8f8fb535ee12 Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{84DC9F6C-C9A5-4C64-AB67-D6EF60F963C8} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\Software\AVG Secure Search Key Deleted : HKLM\Software\AVG Security Toolbar Key Deleted : HKLM\SOFTWARE\Classes\AppID\{18B9B16E-716F-43DF-A6AD-512C7D2EB983} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C3110516-8EFC-49D6-8B72-69354F332062} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Key Deleted : HKLM\SOFTWARE\Classes\AppID\PropertySync.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\secman.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1 Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1 Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755} Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\DataMngr Key Deleted : HKLM\Software\Discount Buddy Key Deleted : HKLM\Software\ExpressFiles Key Deleted : HKLM\Software\Freeze.com Key Deleted : HKLM\Software\InstallIQ Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Key Deleted : HKLM\Software\SpeedMaxPC Key Deleted : HKLM\Software\SProtector Key Deleted : HKLM\Software\Supreme Savings Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bbffdhejhaoiflnpooogkckfdcmmjppn Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jbpkiefagocgkmemidfngdkamloieekf Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{84DC9F6C-C9A5-4C64-AB67-D6EF60F963C8} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\DomaIQ Uninstaller Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317} Key Deleted : HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnUpdater Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} Key Deleted : HKLM\SOFTWARE\Tarma Installer Key Deleted : HKU\S-1-5-21-2818275571-1308961900-3806129831-1001\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [statuswinks@StatusWinks] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [statuswinks@StatusWinks] Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] ***** [Internet Browsers] ***** -\\ Internet Explorer v10.0.9200.16635 Replaced : [HKCU\Software\Microsoft\Internet Explorer\SearchUrl - Default] = hxxp://feed.snap.do/?publisher=Tightrope&dpid=Tightrope&co=US&userid=e4310653-a2f1-4dfb-a9d4-631d43e8f648&searchtype=ds&q={searchTerms} –> hxxp://www.google.com Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl - Default] = hxxp://feed.snap.do/?publisher=Tightrope&dpid=Tightrope&co=US&userid=e4310653-a2f1-4dfb-a9d4-631d43e8f648&searchtype=ds&q={searchTerms} –> hxxp://www.google.com Replaced : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Page] = hxxp://start.sweetpacks.com/?src=10&st=12&crg=3.5000006.10042&barid={9B3DBF80-A622-11E2-B090-00262D7BE3A6} –> hxxp://www.google.com -\\ Google Chrome v28.0.1500.71 File : C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. File : C:\Users\Cecil\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. File : C:\Users\Public Account\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [14584 octets] - [12/07/2013 10:05:03] ########## EOF - C:\AdwCleaner[S1].txt - [14645 octets] ########## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.0.7 (07.11.2013:1) OS: Windows 7 Home Premium x64 Ran by [removed] on Fri 07/12/2013 at 10:12:19.97 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\anchorfree Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\distromatic Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\sparktrust Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sparktrust Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\apnstub_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\apnstub_rasmancs Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{7A0333EB-26A7-4F8B-92C1-862428320E4F} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\sparktrust" Successfully deleted: [Folder] "C:\Users\Karen\AppData\Roaming\strongvault" Successfully deleted: [Folder] "C:\Program Files (x86)\aol toolbar" Successfully deleted: [Folder] "C:\ai_recyclebin" Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin" ~~~ Chrome Successfully deleted: [Registry Key] hkey_local_machine\software\policies\google\chrome\extensioninstallforcelist ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Fri 07/12/2013 at 10:19:10.77 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.07.12.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16635 Karen :: KAREN-PC [administrator] 7/12/2013 10:21:28 AM mbam-log-2013-07-12 (10-21-28).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 307594 Time elapsed: 4 minute(s), 41 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 C:\Users\Public Account\Local Settings\Temporary Internet Files\Content.IE5\W57I82XC\Solid-SavingsUS[1].exe (Heuristics.Shuriken) -> Quarantined and deleted successfully. (end)
:thumbup: Good job. When you download a program from the internet, you need to read the EULA ( End Users License Agreement ) , you also need to read read read read what your installing, during the installation you need read the next step before clicking on next, a lot of the garbage on your system comes bundled sometimes with programs you may install, you need to be very careful. Why dont you go ahead and run a new scan with OTL and post the log, there wont be a extras log this time so dont lose sleep trying to find it
Here it is… And again I can't thank you enough for your advice and time. Does this take care of it??

OTL logfile created on: 7/12/2013 2:45:41 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Karen\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 2.58 Gb Available Physical Memory | 68.71% Memory free
7.50 Gb Paging File | 6.22 Gb Available in Paging File | 82.94% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 286.27 Gb Total Space | 198.77 Gb Free Space | 69.43% Space Free | Partition Type: NTFS

Computer Name: KAREN-PC | User Name: Karen | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Karen\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)


========== Modules (No Company Name) ==========


========== Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (Live Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (avgfws) – C:\Program Files (x86)\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (HsfXAudioService) – C:\Windows\SysWOW64\XAudio64.dll (Conexant Systems, Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (dg_ssudbus) – C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Qualcomm Atheros Communications, Inc.)
DRV:64bit: - (avgtp) – C:\Windows\SysNative\drivers\avgtpx64.sys (AVG Technologies)
DRV:64bit: - (usb_rndisx) – C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (pwdrvio) – C:\Windows\SysNative\pwdrvio.sys ()
DRV:64bit: - (pwdspio) – C:\Windows\SysNative\pwdspio.sys ()
DRV:64bit: - (taphss6) – C:\Windows\SysNative\drivers\taphss6.sys (Anchorfree Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\avgidsdrivera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (AVGIDSHA) – C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\avgidsfiltera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgfwfd) – C:\Windows\SysNative\drivers\avgfwd6a.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (NMgamingmsFltr) – C:\Windows\SysNative\drivers\NMgamingms.sys (Primax Ltd)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (k57nd60a) – C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (XAudio) – C:\Windows\SysNative\drivers\XAudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (HSF_DPV) – C:\Windows\SysNative\drivers\CAX_DPV.sys (Conexant Systems, Inc.)
DRV:64bit: - (CAXHWAZL) – C:\Windows\SysNative\drivers\CAXHWAZL.sys (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) – C:\Windows\SysNative\drivers\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (WDC_SAM) – C:\Windows\SysNative\drivers\wdcsam64.sys (Western Digital Technologies)
DRV:64bit: - (mdmxsdk) – C:\Windows\SysNative\drivers\mdmxsdk.sys (Conexant)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{4A6AA337-BCDF-4E13-A072-C640AB2FBB09}: "URL" = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searcerms}…amp;FORM=IE10SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 64.191.70.164:8090


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.14\npapicomadapter.dll (Oberon-Media )
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack\ [2012/11/25 22:34:36 | 000,000,000 | —D | M]

[2013/06/17 02:51:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Karen\AppData\Roaming\mozilla\Extensions
[2013/06/17 17:14:34 | 000,000,000 | —D | M] (Speed Analysis 2) – C:\Users\Karen\AppData\Roaming\mozilla\Extensions\[removed]

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\PepperFlash\11.8.800.97\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.71\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.71\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Oberon com adapter (Enabled) = C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.14\npapicomadapter.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U21 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll
CHR - Extension: express-files = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\iibmmjhgclhlahmjniokmhleigemjpbh\10.16.4.512_0\
CHR - Extension: Trustworthy = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\kheelobnibmchifldedamogdmhemfjio\10.16.4.512_0\
CHR - Extension: Amazon for Chrome = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam\2.2.2012.272_0\

O1 HOSTS File: ([2013/05/10 02:15:32 | 000,447,225 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.123fporn.info
O1 - Hosts: 15354 more lines…
O2:64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKCU..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_13)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.17.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{41E3175A-0BE7-433E-82CA-03AE7DC02D4D}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{59e7e991-7e37-11e2-9de6-00262d7be3a6}\Shell - "" = AutoRun
O33 - MountPoints2\{59e7e991-7e37-11e2-9de6-00262d7be3a6}\Shell\AutoRun\command - "" = E:\PcOptions.exe
O33 - MountPoints2\{75f45eba-92fb-11e2-b25c-00262d7be3a6}\Shell - "" = AutoRun
O33 - MountPoints2\{75f45eba-92fb-11e2-b25c-00262d7be3a6}\Shell\AutoRun\command - "" = "E:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{ba49fb56-307d-11e2-a886-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{ba49fb56-307d-11e2-a886-806e6f6e6963}\Shell\AutoRun\command - "" = D:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/07/12 10:12:11 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/07/12 10:03:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/07/12 10:03:17 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/07/12 10:03:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/07/12 09:57:20 | 010,285,040 | —- | C] (Malwarebytes Corporation ) – C:\Users\Karen\Desktop\mbam-setup-1.75.0.1300.exe
[2013/07/12 09:55:39 | 000,559,306 | —- | C] (Oleg N. Scherbakov) – C:\Users\Karen\Desktop\JRT.exe
[2013/07/12 03:40:39 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Karen\Desktop\aswMBR.exe
[2013/07/10 21:48:52 | 000,000,000 | —D | C] – C:\Users\Public\Documents\CrashDump
[2013/07/10 20:25:44 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\LegacyInteractive
[2013/07/10 20:24:56 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\Oberon Media
[2013/07/10 20:24:51 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
[2013/07/10 20:24:39 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games of the Month
[2013/07/10 20:24:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Oberon Media SIDR
[2013/07/10 20:24:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Oberon Media
[2013/07/10 20:21:40 | 000,000,000 | —D | C] – C:\ProgramData\Oberon Media
[2013/07/10 20:21:20 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Local\Arcadesafari
[2013/07/10 00:49:50 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/07/10 00:49:50 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/07/10 00:49:48 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/07/10 00:49:48 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/07/10 00:49:48 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/07/10 00:49:48 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/07/10 00:49:48 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/07/10 00:49:48 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/07/10 00:49:48 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/07/10 00:49:48 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/07/10 00:49:47 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/07/10 00:49:46 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/07/10 00:49:45 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/07/10 00:49:45 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/07/10 00:49:44 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/07/10 00:09:04 | 000,624,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qedit.dll
[2013/07/10 00:09:03 | 000,509,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qedit.dll
[2013/07/10 00:09:00 | 001,887,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/07/10 00:08:59 | 001,620,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/07/10 00:08:25 | 001,643,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/07/08 01:23:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2013/07/08 01:21:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Synchronization Services
[2013/07/08 01:21:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DESIGNER
[2013/07/08 01:21:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Sync Framework
[2013/07/08 01:21:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2013/07/08 01:18:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Visual Studio 8
[2013/07/08 01:17:53 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2013/07/08 01:17:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Analysis Services
[2013/07/08 01:17:05 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Local\Microsoft Help
[2013/07/08 01:17:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Office
[2013/07/08 01:17:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2013/07/07 08:55:12 | 001,485,824 | —- | C] (Conexant Systems, Inc.) – C:\Windows\SysNative\drivers\CAX_DPV.sys
[2013/07/07 08:55:12 | 000,740,864 | —- | C] (Conexant Systems, Inc.) – C:\Windows\SysNative\drivers\CAX_CNXT.sys
[2013/07/07 08:55:12 | 000,292,864 | —- | C] (Conexant Systems, Inc.) – C:\Windows\SysNative\drivers\CAXHWAZL.sys
[2013/07/07 08:53:10 | 000,436,736 | —- | C] (Conexant Systems, Inc.) – C:\Windows\SysWow64\XAudio64.dll
[2013/07/07 08:53:10 | 000,394,752 | —- | C] (Conexant Systems, Inc.) – C:\Windows\SysNative\UCI64M41.dll
[2013/07/07 08:53:10 | 000,010,240 | —- | C] (Conexant Systems, Inc.) – C:\Windows\SysNative\drivers\XAudio64.sys
[2013/07/06 11:56:58 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Karen\Desktop\OTL.exe
[2013/07/06 11:28:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Open It!
[2013/07/06 11:28:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\OpenIt
[2013/07/06 02:04:49 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\USB Optical Mouse
[2013/07/05 16:45:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/07/04 17:09:50 | 000,000,000 | —D | C] – C:\Users\Karen\Desktop\Apks-7_4_2013
[2013/06/30 02:12:23 | 001,919,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WdfCoInstaller01005.dll
[2013/06/30 02:12:23 | 001,919,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WdfCoInstaller01005.dll
[2013/06/30 02:12:23 | 000,017,736 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadwh.sys
[2013/06/30 02:12:23 | 000,017,224 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadcm.sys
[2013/06/30 01:59:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
[2013/06/30 01:59:26 | 000,821,824 | —- | C] (Devguru Co., Ltd.) – C:\Windows\SysWow64\dgderapi.dll
[2013/06/24 23:07:48 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Local\Facebook
[2013/06/17 17:26:58 | 000,751,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/06/17 17:26:57 | 000,492,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\win32spl.dll
[2013/06/17 17:26:45 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptdlg.dll
[2013/06/17 17:26:45 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cryptdlg.dll
[2013/06/17 17:26:39 | 001,424,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2013/06/17 17:26:00 | 001,192,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certutil.exe
[2013/06/17 17:26:00 | 000,903,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certutil.exe
[2013/06/17 17:25:59 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/06/17 17:25:59 | 000,139,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2013/06/17 17:25:59 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certenc.dll
[2013/06/17 17:25:59 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certenc.dll
[2013/06/17 17:25:46 | 001,887,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2013/06/17 17:25:46 | 001,505,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2013/06/17 02:51:44 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\Mozilla
[2013/06/17 02:51:35 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
[2013/06/16 05:25:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Acoustica Shared Effects
[2013/06/14 23:07:36 | 000,000,000 | —D | C] – C:\Users\Karen\Desktop\MINE
[2013/06/14 09:29:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\GPLGS
[2013/06/14 09:29:04 | 000,000,000 | —D | C] – C:\Program Files\PDFCreator
[2013/06/13 16:00:16 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\Malwarebytes
[2013/06/13 16:00:04 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes

========== Files - Modified Within 30 Days ==========

[2013/07/12 14:45:31 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/12 14:42:55 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/07/12 14:42:38 | 3018,608,640 | -HS- | M] () – C:\hiberfil.sys
[2013/07/12 12:21:29 | 126,566,283 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2013/07/12 12:17:14 | 000,015,824 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/07/12 12:17:14 | 000,015,824 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/07/12 10:03:19 | 000,001,077 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/07/12 09:57:32 | 010,285,040 | —- | M] (Malwarebytes Corporation ) – C:\Users\Karen\Desktop\mbam-setup-1.75.0.1300.exe
[2013/07/12 09:56:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/12 09:55:40 | 000,559,306 | —- | M] (Oleg N. Scherbakov) – C:\Users\Karen\Desktop\JRT.exe
[2013/07/12 09:55:12 | 000,662,345 | —- | M] () – C:\Users\Karen\Desktop\AdwCleaner.exe
[2013/07/12 09:51:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/07/12 03:40:52 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Karen\Desktop\aswMBR.exe
[2013/07/12 01:52:23 | 000,000,464 | —- | M] () – C:\Windows\tasks\Arcadesafari.job
[2013/07/12 00:31:55 | 000,401,630 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2013/07/11 22:54:57 | 000,002,147 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/07/10 13:16:11 | 000,417,120 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/07/10 00:56:22 | 000,886,168 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/07/10 00:56:22 | 000,726,172 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/07/10 00:56:22 | 000,146,158 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/07/08 01:23:20 | 000,002,621 | —- | M] () – C:\Users\Public\Desktop\Microsoft Word 2010.lnk
[2013/07/08 01:23:20 | 000,002,621 | —- | M] () – C:\Users\Public\Desktop\Microsoft PowerPoint 2010.lnk
[2013/07/08 01:23:20 | 000,002,621 | —- | M] () – C:\Users\Public\Desktop\Microsoft Outlook 2010.lnk
[2013/07/08 01:23:20 | 000,002,621 | —- | M] () – C:\Users\Public\Desktop\Microsoft Excel 2010.lnk
[2013/07/08 01:23:20 | 000,002,621 | —- | M] () – C:\Users\Public\Desktop\Microsoft Access 2010.lnk
[2013/07/07 00:40:39 | 000,000,005 | —- | M] () – C:\Users\Karen\AppData\Roaming\WBPU-TTL.DAT
[2013/07/06 11:56:59 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Karen\Desktop\OTL.exe
[2013/07/06 11:28:53 | 000,001,078 | —- | M] () – C:\Users\Public\Desktop\Open It!.lnk
[2013/07/05 16:55:53 | 000,002,247 | —- | M] () – C:\Users\Karen\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/07/05 03:38:13 | 044,615,733 | —- | M] () – C:\Users\Karen\Desktop\I747UCDLK3_aio.tar.md5
[2013/07/04 22:17:07 | 006,400,000 | —- | M] () – C:\Users\Karen\recovery-twrp-2.5.0.0-SGHI747.tar
[2013/07/04 22:15:51 | 006,092,800 | —- | M] () – C:\Users\Karen\recovery-cwmtouch-6.0.3.1-SGHI747.tar
[2013/07/01 00:46:06 | 000,000,211 | —- | M] () – C:\ProgramData\acer.zip
[2013/06/30 01:59:45 | 000,001,994 | —- | M] () – C:\Users\Karen\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies (Lite).lnk
[2013/06/30 01:59:45 | 000,001,984 | —- | M] () – C:\Users\Karen\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2013/06/30 01:57:54 | 000,866,014 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/06/29 05:38:31 | 000,007,601 | —- | M] () – C:\Users\Karen\AppData\Local\Resmon.ResmonCfg

========== Files Created - No Company Name ==========

[2013/07/12 10:03:19 | 000,001,077 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/07/12 09:55:10 | 000,662,345 | —- | C] () – C:\Users\Karen\Desktop\AdwCleaner.exe
[2013/07/10 20:21:23 | 000,000,464 | —- | C] () – C:\Windows\tasks\Arcadesafari.job
[2013/07/08 01:23:20 | 000,002,621 | —- | C] () – C:\Users\Public\Desktop\Microsoft Word 2010.lnk
[2013/07/08 01:23:20 | 000,002,621 | —- | C] () – C:\Users\Public\Desktop\Microsoft PowerPoint 2010.lnk
[2013/07/08 01:23:20 | 000,002,621 | —- | C] () – C:\Users\Public\Desktop\Microsoft Outlook 2010.lnk
[2013/07/08 01:23:20 | 000,002,621 | —- | C] () – C:\Users\Public\Desktop\Microsoft Excel 2010.lnk
[2013/07/08 01:23:20 | 000,002,621 | —- | C] () – C:\Users\Public\Desktop\Microsoft Access 2010.lnk
[2013/07/07 08:55:12 | 000,146,036 | —- | C] () – C:\Windows\SysNative\drivers\HSFProf.cty
[2013/07/06 11:28:53 | 000,001,078 | —- | C] () – C:\Users\Public\Desktop\Open It!.lnk
[2013/07/05 16:45:23 | 000,002,147 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/07/05 16:44:49 | 000,000,896 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/05 16:44:48 | 000,000,892 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/05 03:37:24 | 044,615,733 | —- | C] () – C:\Users\Karen\Desktop\I747UCDLK3_aio.tar.md5
[2013/07/04 22:17:07 | 006,400,000 | —- | C] () – C:\Users\Karen\recovery-twrp-2.5.0.0-SGHI747.tar
[2013/07/04 22:15:51 | 006,092,800 | —- | C] () – C:\Users\Karen\recovery-cwmtouch-6.0.3.1-SGHI747.tar
[2013/06/30 01:59:45 | 000,001,994 | —- | C] () – C:\Users\Karen\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies (Lite).lnk
[2013/06/30 01:59:45 | 000,001,984 | —- | C] () – C:\Users\Karen\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2013/06/16 00:30:31 | 000,000,005 | —- | C] () – C:\Users\Karen\AppData\Roaming\WBPU-TTL.DAT
[2013/06/11 19:09:51 | 000,011,623 | —- | C] () – C:\Users\Karen\AppData\Roaming\UserTile.png
[2013/05/27 00:39:51 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2013/05/27 00:39:51 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2013/05/27 00:39:45 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2013/05/22 20:43:52 | 000,030,568 | —- | C] () – C:\Windows\MusiccityDownload.exe
[2013/05/15 22:47:06 | 000,003,584 | —- | C] () – C:\Users\Karen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/05/15 13:51:41 | 000,000,047 | —- | C] () – C:\Windows\WinInit.Ini
[2013/05/01 15:25:32 | 000,004,096 | —- | C] () – C:\Windows\d3dx.dat
[2013/02/11 19:14:10 | 000,000,258 | RHS- | C] () – C:\Users\Karen\ntuser.pol
[2013/02/05 17:52:50 | 000,974,848 | —- | C] () – C:\Windows\SysWow64\cis-2.4.dll
[2013/02/05 17:52:50 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2013/02/05 17:52:50 | 000,065,536 | —- | C] () – C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2013/02/05 17:52:50 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\issacapi_se-2.3.dll
[2013/02/01 01:46:57 | 000,000,211 | —- | C] () – C:\ProgramData\acer.zip
[2013/01/22 03:11:45 | 000,109,784 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2013/01/21 09:24:37 | 000,866,014 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/11/24 09:34:32 | 000,007,601 | —- | C] () – C:\Users\Karen\AppData\Local\Resmon.ResmonCfg
[2012/11/19 02:33:32 | 000,065,656 | —- | C] () – C:\Windows\SysWow64\bdmpegv.dll
[2012/11/19 02:33:30 | 000,022,640 | —- | C] () – C:\Windows\SysWow64\bdmjpeg.dll
[2012/11/17 01:47:00 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 00:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/26 23:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 07:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Alternate Data Streams ==========

@Alternate Data Stream - 350 bytes -> C:\ProgramData\TEMP:214562D2
@Alternate Data Stream - 205 bytes -> C:\ProgramData\TEMP:0B4227B4

< End of report >
Hi, how are ya doing ?? Did you set this proxy server ? IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 64.191.70.164:8090
No I wasn't instructed to. But when I go to settings via Google Chrome and pull up the dialogue to set a proxy server, I set it as you posted and cannot get any webpages to load using that proxy. It says Unable to connect through proxy server.
Hi,

I just asked if you set it as its set already most likely from one of the garbage toolbars you had installed, I didn't ask you to set it, we need to remove it as your internet traffic is going through that proxy

Go to Start > Control Panel > Internet Options > Connections tab > Local Area Network > Lan Settings and if Proxy Server is checked, uncheck it an ok your way out



Open OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = [removed]:8090
    
    
    :Services
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top. <–Not run Scan
  • Let the program run unhindered, reboot when it is done
  • Then post the results of the log it produces
OH. oops. LOL. I was still asleep when I responded to the last post. Sorry about that. And I'm doing great now that someone that knows what they are doing is helping me with my issues. Thank You.

Here are the results as requested.

All processes killed
========== OTL ==========
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Karen\Desktop\cmd.bat deleted successfully.
C:\Users\Karen\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: 14d Trial - MX6 6-23
->Temp folder emptied: 33178872 bytes
->Temporary Internet Files folder emptied: 17970130 bytes
->Flash cache emptied: 651 bytes

User: All Users

User: Cecil
->Temp folder emptied: 160443795 bytes
->Temporary Internet Files folder emptied: 49554 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 124549176 bytes
->Apple Safari cache emptied: 10205184 bytes
->Flash cache emptied: 778 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Karen
->Temp folder emptied: 97017444 bytes
->Temporary Internet Files folder emptied: 1204622 bytes
->Java cache emptied: 37750 bytes
->Google Chrome cache emptied: 380703153 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 564 bytes

User: Public

User: Public Account
->Temp folder emptied: 50252380 bytes
->Temporary Internet Files folder emptied: 1230287712 bytes
->Java cache emptied: 75731 bytes
->Google Chrome cache emptied: 177592026 bytes
->Flash cache emptied: 136051 bytes

User: test
->Temp folder emptied: 4722358 bytes
->Temporary Internet Files folder emptied: 9495446 bytes
->Flash cache emptied: 598 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 45485355 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 36126371 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 2,269.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 07132013_091210

Files\Folders moved on Reboot…
C:\Users\Karen\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…
It seems to be running a whole lot smoother now. I haven't experienced any issues with wifi connectivity, programs not responding, or anything like that. THANK YOU SO MUCH. For your time and expertise. Running great so far. Now if it starts to run slow or experience some of the same problems in the future is it safe to re-trace these steps?
Hi,

No as the problem could be different and what we removed wont be there, it may be another issue. I will close this thread tomorrow so if any other issues just start a new topic.

Glad all is ok :thumbup:


Open OTL and click on Clean Up and it will remove programs we used to clean your system along with there backups, any programs that where not removed you can just drag to the trash.


Malwarebytes is the free version and yours to keep and will not be removed


  • How did I get infected in the first place ?
    Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • WhattheTech
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports


Safe Surfn
Ken

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI