This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ad problems in browsers [Solved]

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi -

My kid's laptop is infected with something - I've used this forum before and it's been very helpful! Please help again!

The problem occurs with multiple browsers, although mostly firefox. Something is causing a lot of pop-ups, as well as replacing normal banner ads with obviously inappropriate ones (lots of boobs). The laptop had not had any antivirus program on it except for whatever came with the computer (it used to be my husband's - he used avast professional but uninstalled it to use on his new laptop). As a part of tackling the problem, I installed the free version of avast and it found a bunch of suspect add-ons and plug-ins to uninstall - but we still seem to have some problems. I found one plug-in called Google Update which appears to be a fake - there are other plugins for Shockwave, Silverlight, and others that I'm not sure are legit or not. I would very much appreciate advice!


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:22:46 PM, on 7/7/2013
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Boot mode: Normal

Running processes:
C:\Users\JimAngehr\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Users\JimAngehr\AppData\Roaming\Spotify\Spotify.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
C:\Users\JimAngehr\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT13/1
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: DownloadTerms - {2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3} - C:\Users\JimAngehr\AppData\Local\DownloadTerms\temp.dat
O2 - BHO: BBRowsE2savve - {4FA31CBC-669C-8878-251A-D2DA6ACAE0DF} - C:\ProgramData\BBRowsE2savve\5179416ce7628.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: DefaultTabBHO - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\JimAngehr\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Fast Free Converter 4.1 - {B422F1BC-9ADB-48A7-8B13-00C176039DC5} - C:\PROGRA~2\FASTFR~1\FASTFR~1\FASTFR~1.DLL
O2 - BHO: EybooikBBriowsue - {C178AC1C-9A8B-8FF7-88BA-DB329D96695B} - C:\ProgramData\EybooikBBriowsue\5179419ef2e8c.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [CLVirtualDrive] "C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
O4 - HKLM\..\Run: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files (x86)\WordPerfect Office X3\Programs\QFSCHD130.EXE"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\JimAngehr\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [Spotify] "C:\Users\JimAngehr\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart
O4 - Startup: Dropbox.lnk = JimAngehr\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: MyPC Backup.lnk = C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open with WordPerfect - C:\Program Files (x86)\WordPerfect Office X3\Programs\WPLauncher.hta
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Computer Backup (MyPC Backup) (BackupStack) - Just Develop It - C:\Program Files (x86)\MyPC Backup\BackupStack.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DefaultTabSearch - Unknown owner - C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe
O23 - Service: DefaultTabUpdate - Unknown owner - C:\Users\JimAngehr\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: FastFreeConverterUpdt - Unknown owner - C:\Program Files (x86)\Fast Free Converter\FastFreeConverterUpdt.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: @oem20.inf,%hpservice_desc%;HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: lxeb_device - Unknown owner - C:\Windows\system32\lxebcoms.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\SysWOW64\PSIService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 12577 bytes
Hi there,
my name is Marius and I will be assisting you with your Malware related problems.

Before we move on, please read the following points carefully.
  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.




Run DDS by double clicking on it.
  • When finished, DDS will create two logfiles:
    • DDS.txt
    • Attach.txt
  • save both files to your desktop.
  • Post the content of DDS.txt here into your thread.
  • Attach Attach.txt




Please download Gmer from here by clicking on the "Download EXE" Button.
  • Double click on the randomly named GMER.exe. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Show All ( should be unchecked by default )
  • Leave everything else as it is.
  • Close all other running programs as well as your Browser.
  • Click the Scan button & wait for it to finish.
  • Once done click on the Save.. button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop.
  • Please post the content of the ark.txt here.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 10.0.9200.16537 BrowserJavaVersion: 10.13.2 Run by [removed] at 14:54:55 on 2013-07-08 Microsoft Windows 8 6.2.9200.0.1252.1.1033.18.3554.1772 [GMT -4:00] . AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\system32\dwm.exe C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Program Files\IDT\WDM\STacSV64.exe C:\Windows\system32\Hpservice.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe C:\Windows\system32\svchost.exe -k apphost C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Users\JimAngehr\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe C:\Windows\system32\dashost.exe C:\Program Files (x86)\Fast Free Converter\FastFreeConverterUpdt.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe C:\Windows\system32\lxebcoms.exe C:\Windows\SysWOW64\PSIService.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\taskhostex.exe C:\Windows\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE C:\Program Files\IDT\WDM\sttray64.exe C:\Users\JimAngehr\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe C:\Users\JimAngehr\AppData\Roaming\Spotify\spotify.exe C:\Users\JimAngehr\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files\AVAST Software\Avast\AvastUI.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe C:\Windows\system32\taskhost.exe C:\Program Files (x86)\Internet Explorer\IELowutil.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16613_none_6273bd8950d6cae2\TiWorker.exe C:\Windows\system32\msiexec.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.bing.com uSearch Bar = hxxp://www.bing.com mWinlogon: Userinit = userinit.exe BHO: DownloadTerms: {2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3} - C:\Users\JimAngehr\AppData\Local\DownloadTerms\temp.dat BHO: BBRowsE2savve: {4FA31CBC-669C-8878-251A-D2DA6ACAE0DF} - C:\ProgramData\BBRowsE2savve\5179416ce7628.dll BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: DefaultTab Browser Helper: {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\JimAngehr\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll BHO: Fast Free Converter 4.1: {B422F1BC-9ADB-48A7-8B13-00C176039DC5} - C:\Program Files (x86)\Fast Free Converter\FastFreeConverter\FastFreeConverter.dll BHO: EybooikBBriowsue: {C178AC1C-9A8B-8FF7-88BA-DB329D96695B} - C:\ProgramData\EybooikBBriowsue\5179419ef2e8c.dll BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll uRun: [Spotify Web Helper] "C:\Users\JimAngehr\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" uRun: [Spotify] "C:\Users\JimAngehr\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [CLVirtualDrive] "C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R mRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe mRun: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [QuickFinder Scheduler] "C:\Program Files (x86)\WordPerfect Office X3\Programs\QFSCHD130.EXE" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui StartupFolder: C:\Users\JIMANG~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\JimAngehr\AppData\Roaming\Dropbox\bin\Dropbox.exe StartupFolder: C:\Users\JIMANG~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\MYPCBA~1.LNK - C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Open with WordPerfect - C:\Program Files (x86)\WordPerfect Office X3\Programs\WPLauncher.hta IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} TCP: NameServer = 192.168.1.1 TCP: Interfaces\{3C6BDB04-E01A-40C1-AD9D-37A8A0EE53D6} : DHCPNameServer = 192.168.1.1 TCP: Interfaces\{3C6BDB04-E01A-40C1-AD9D-37A8A0EE53D6}\7627F6F667567627F657E646 : DHCPNameServer = 192.168.10.1 TCP: Interfaces\{3C6BDB04-E01A-40C1-AD9D-37A8A0EE53D6}\F4365616E605C616365633C4 : DHCPNameServer = 192.168.2.1 TCP: Interfaces\{3C6BDB04-E01A-40C1-AD9D-37A8A0EE53D6}\F4365616E605C616365643C4 : DHCPNameServer = 192.168.2.1 Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll SSODL: WebCheck - mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\Installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome x64-BHO: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll x64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - x64-SSODL: WebCheck - . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\JimAngehr\AppData\Roaming\Mozilla\Firefox\Profiles\7zcy930i.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/search/search?q={searchTerms}&s_it=webpickaol-ff&s_qt=sb&tb_uuid=D1E32A0EB1E84CB199BF9D10246EAD1B&tb_oid=25-04-2013&tb_mrud=26-04-2013 FF - prefs.js: browser.startup.homepage - google.com FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q= FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\windows\SysWOW64\Adobe\Director\np32dsw.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll FF - plugin: C:\Windows\SysWOW64\npmproxy.dll FF - ExtSQL: 2013-07-07 18:56; [removed]; C:\Program Files\AVAST Software\Avast\WebRep\FF . —- FIREFOX POLICIES —- FF - user.js: extentions.y2layers.installId - 637d194c-2b91-4bea-ae27-c028e609b56d FF - user.js: extentions.y2layers.defaultEnableAppsList - DropDownDeals,buzzdock,YontooNewOffers . FF - user.js: extensions.autoDisableScopes - 14 FF - user.js: network.protocol-handler.warn-external.dnupdate - false ============= SERVICES / DRIVERS =============== . R0 amd_sata;amd_sata;C:\Windows\System32\Drivers\amd_sata.sys [2012-7-24 79528] R0 amd_xata;amd_xata;C:\Windows\System32\Drivers\amd_xata.sys [2012-7-24 26280] R0 aswRvrt;aswRvrt;C:\Windows\System32\Drivers\aswRvrt.sys [2013-7-7 65336] R0 aswVmm;aswVmm;C:\Windows\System32\Drivers\aswVmm.sys [2013-7-7 189936] R1 aswSnx;aswSnx;C:\Windows\System32\Drivers\aswSnx.sys [2013-7-7 1030952] R1 aswSP;aswSP;C:\Windows\System32\Drivers\aswSP.sys [2013-7-7 378944] R1 CLVirtualDrive;CLVirtualDrive;C:\Windows\System32\Drivers\CLVirtualDrive.sys [2012-10-5 92536] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-8-9 239616] R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-8-8 361984] R2 APXACC;AppEx Networks Accelerator LWF;C:\Windows\System32\Drivers\appexDrv.sys [2012-10-5 199008] R2 aswFsBlk;aswFsBlk;C:\Windows\System32\Drivers\aswFsBlk.sys [2013-7-7 33400] R2 aswMonFlt;aswMonFlt;C:\Windows\System32\Drivers\aswMonFlt.sys [2013-7-7 80816] R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-7-7 46808] R2 DefaultTabUpdate;DefaultTabUpdate;C:\Users\JimAngehr\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe [2013-6-18 107520] R2 FastFreeConverterUpdt;FastFreeConverterUpdt;C:\Program Files (x86)\Fast Free Converter\FastFreeConverterUpdt.exe [2012-11-26 687104] R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-8-10 85504] R2 hpsrv;HP Service;C:\Windows\System32\hpservice.exe [2012-8-23 29600] R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-7-9 35232] R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-10-5 2451456] R2 lxeb_device;lxeb_device;C:\Windows\System32\lxebcoms.exe -service –> C:\Windows\System32\lxebcoms.exe -service [?] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\Drivers\AtihdW86.sys [2012-7-18 98472] R3 RSP2STOR;Realtek PCIE CardReader Driver - P2;C:\Windows\System32\Drivers\RtsP2Stor.sys [2012-10-5 269968] R3 RTL8168;Realtek 8168 NT Driver;C:\Windows\System32\Drivers\Rt630x64.sys [2012-10-5 690832] R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\Drivers\usbfilter.sys [2012-10-5 57000] R3 WirelessButtonDriver;HP Wireless Button Driver Service;C:\Windows\System32\Drivers\WirelessButtonDriver64.sys [2012-8-31 20800] S2 BackupStack;Computer Backup (MyPC Backup);C:\Program Files (x86)\MyPC Backup\BackupStack.exe [2013-5-31 32808] S2 DefaultTabSearch;DefaultTabSearch;C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe [2013-2-11 572928] S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] S3 iaStorA;iaStorA;C:\Windows\System32\Drivers\iaStorA.sys [2012-7-31 645952] S3 SmbDrv;SmbDrv;C:\Windows\System32\Drivers\Smb_driver_AMDASF.sys [2012-10-5 41272] S3 SmbDrvI;SmbDrvI;C:\Windows\System32\Drivers\Smb_driver_Intel.sys [2012-10-5 43832] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\Drivers\usbaapl64.sys [2012-9-28 53760] . =============== File Associations =============== . FileExt: .txt: Applications\Winword.exe="C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE" /n /dde [UserChoice] [default=edit - 'Open' doesn't exist] . =============== Created Last 30 ================ . 2013-07-07 22:56:32 72016 —-a-w- C:\Windows\System32\drivers\aswRdr2.sys 2013-07-07 22:56:18 80816 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys 2013-07-07 22:56:18 65336 —-a-w- C:\Windows\System32\drivers\aswRvrt.sys 2013-07-07 22:56:18 189936 —-a-w- C:\Windows\System32\drivers\aswVmm.sys 2013-07-07 22:56:18 1030952 —-a-w- C:\Windows\System32\drivers\aswSnx.sys 2013-07-07 22:55:43 41664 —-a-w- C:\Windows\avastSS.scr 2013-07-07 10:12:52 9552976 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8B905977-F17E-4550-B398-F782F419DF0B}\mpengine.dll 2013-07-07 07:00:06 9552976 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll 2013-07-04 12:33:08 237744 —-a-w- C:\ProgramData\Microsoft\Windows\Sqm\Manifest\Sqm10209.bin 2013-07-04 11:43:26 144384 —-a-w- C:\Windows\System32\tssdisai.dll 2013-06-23 13:01:20 ——– d—–w- C:\Users\JimAngehr\AppData\Local\Adobe 2013-06-18 11:47:26 ——– d—–w- C:\Program Files (x86)\DefaultTab 2013-06-18 11:47:13 ——– d—–w- C:\Users\JimAngehr\AppData\Roaming\DefaultTab 2013-06-18 11:46:46 ——– d—–w- C:\Users\JimAngehr\AppData\Local\NexGenMediaPlayer 2013-06-18 11:46:44 ——– d—–w- C:\Program Files (x86)\NexGen Media Player 2013-06-18 11:46:42 ——– d—–w- C:\Program Files (x86)\MyPC Backup 2013-06-18 11:45:41 ——– d—–w- C:\Users\JimAngehr\AppData\Local\DownloadTerms 2013-06-18 11:45:24 ——– d—–w- C:\Program Files (x86)\File Type Helper 2013-06-18 11:45:20 ——– d—–w- C:\Program Files (x86)\Fast Free Converter 2013-06-18 11:45:16 ——– d—–w- C:\Users\JimAngehr\AppData\Local\SwvUpdater 2013-06-16 13:10:58 1300992 —-a-w- C:\Windows\System32\gdi32.dll 2013-06-16 13:10:58 1022464 —-a-w- C:\Windows\SysWow64\gdi32.dll 2013-06-16 13:10:55 888320 —-a-w- C:\Windows\System32\autochk.exe 2013-06-16 13:10:55 793088 —-a-w- C:\Windows\SysWow64\autochk.exe 2013-06-16 13:10:55 542208 —-a-w- C:\Windows\System32\untfs.dll 2013-06-16 13:10:55 482816 —-a-w- C:\Windows\SysWow64\untfs.dll 2013-06-15 12:17:59 17408 —-a-w- C:\Windows\System32\muifontsetup.dll 2013-06-15 12:17:58 34304 —-a-w- C:\Windows\SysWow64\wuapp.exe 2013-06-15 12:17:58 18432 —-a-w- C:\Windows\SysWow64\npmproxy.dll 2013-06-15 12:17:58 14336 —-a-w- C:\Windows\SysWow64\muifontsetup.dll . ==================== Find3M ==================== . 2013-06-04 22:09:22 78200 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-04 22:09:22 693112 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2013-05-23 18:34:15 1056 –sha-w- C:\Windows\SysWow64\KGyGaAvL.sys 2013-05-15 22:37:03 44032 —-a-w- C:\Windows\SysWow64\UXInit.dll 2013-05-15 22:35:49 53760 —-a-w- C:\Windows\System32\UXInit.dll 2013-05-14 13:14:01 2706432 —-a-w- C:\Windows\System32\mshtml.tlb 2013-05-14 09:23:31 2706432 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2013-05-04 07:58:17 120736 —-a-w- C:\Windows\System32\AuthHost.exe 2013-05-04 07:45:29 2233600 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2013-05-04 07:34:17 446720 —-a-w- C:\Windows\System32\drivers\USBHUB3.SYS 2013-05-04 07:34:17 213248 —-a-w- C:\Windows\System32\drivers\UCX01000.SYS 2013-05-04 07:34:15 284416 —-a-w- C:\Windows\System32\drivers\spaceport.sys 2013-05-04 06:59:56 39424 —-a-w- C:\Windows\System32\wuapp.exe 2013-05-04 06:59:51 1483776 —-a-w- C:\Windows\System32\VSSVC.exe 2013-05-04 06:59:36 812544 —-a-w- C:\Windows\System32\Magnify.exe 2013-05-04 06:59:25 98304 —-a-w- C:\Windows\System32\wudriver.dll 2013-05-04 06:59:25 251904 —-a-w- C:\Windows\System32\WUSettingsProvider.dll 2013-05-04 06:59:25 141824 —-a-w- C:\Windows\System32\wuwebv.dll 2013-05-04 06:59:24 1619968 —-a-w- C:\Windows\System32\wucltux.dll 2013-05-04 06:59:08 13644288 —-a-w- C:\Windows\System32\Windows.UI.Xaml.dll 2013-05-04 06:58:54 328192 —-a-w- C:\Windows\System32\ubpm.dll 2013-05-04 06:58:54 10116096 —-a-w- C:\Windows\System32\twinui.dll 2013-05-04 06:58:49 173568 —-a-w- C:\Windows\System32\storewuauth.dll 2013-05-04 06:58:49 1332736 —-a-w- C:\Windows\System32\sysmain.dll 2013-05-04 06:58:48 330240 —-a-w- C:\Windows\System32\stobject.dll 2013-05-04 06:58:28 93696 —-a-w- C:\Windows\System32\psmsrv.dll 2013-05-04 06:58:02 470528 —-a-w- C:\Windows\System32\netprofmsvc.dll 2013-05-04 06:58:02 151552 —-a-w- C:\Windows\System32\netprofm.dll 2013-05-04 06:58:01 169984 —-a-w- C:\Windows\System32\netplwiz.dll 2013-05-04 06:57:46 560640 —-a-w- C:\Windows\System32\mfmp4srcsnk.dll 2013-05-04 06:57:15 501760 —-a-w- C:\Windows\System32\DevicePairing.dll 2013-05-04 06:57:05 179712 —-a-w- C:\Windows\System32\bisrv.dll 2013-05-04 06:57:05 122368 —-a-w- C:\Windows\System32\biwinrt.dll 2013-05-04 06:57:04 389120 —-a-w- C:\Windows\System32\BCP47Langs.dll 2013-05-04 06:57:04 2305024 —-a-w- C:\Windows\System32\authui.dll 2013-05-04 06:57:00 708096 —-a-w- C:\Windows\System32\AppXDeploymentExtensions.dll 2013-05-04 06:57:00 1131520 —-a-w- C:\Windows\System32\AppXDeploymentServer.dll 2013-05-04 06:56:53 419840 —-a-w- C:\Windows\System32\intl.cpl 2013-05-04 04:58:14 758784 —-a-w- C:\Windows\SysWow64\Magnify.exe 2013-05-04 04:58:02 83968 —-a-w- C:\Windows\SysWow64\wudriver.dll 2013-05-04 04:58:02 125952 —-a-w- C:\Windows\SysWow64\wuwebv.dll 2013-05-04 04:57:49 10788864 —-a-w- C:\Windows\SysWow64\Windows.UI.Xaml.dll 2013-05-04 04:57:39 8857088 —-a-w- C:\Windows\SysWow64\twinui.dll 2013-05-04 04:57:39 247296 —-a-w- C:\Windows\SysWow64\ubpm.dll 2013-05-04 04:57:35 303616 —-a-w- C:\Windows\SysWow64\stobject.dll 2013-05-04 04:57:04 151040 —-a-w- C:\Windows\SysWow64\netplwiz.dll 2013-05-04 04:57:04 115712 —-a-w- C:\Windows\SysWow64\netprofm.dll 2013-05-04 04:56:48 411136 —-a-w- C:\Windows\SysWow64\mfmp4srcsnk.dll 2013-05-04 04:56:14 449536 —-a-w- C:\Windows\SysWow64\DevicePairing.dll 2013-05-04 04:56:06 92160 —-a-w- C:\Windows\SysWow64\biwinrt.dll 2013-05-04 04:56:05 309760 —-a-w- C:\Windows\SysWow64\BCP47Langs.dll 2013-05-04 04:56:05 2035712 —-a-w- C:\Windows\SysWow64\authui.dll 2013-05-04 04:55:58 389632 —-a-w- C:\Windows\SysWow64\intl.cpl 2013-05-04 04:51:38 14848 —-a-w- C:\Windows\System32\rars.rs 2013-05-04 04:48:33 83968 —-a-w- C:\Windows\System32\drivers\hidclass.sys 2013-05-04 04:48:26 27648 —-a-w- C:\Windows\System32\drivers\hidusb.sys 2013-05-04 04:47:02 427520 —-a-w- C:\Windows\System32\drivers\rdbss.sys 2013-05-04 04:10:47 14848 —-a-w- C:\Windows\SysWow64\rars.rs 2013-05-02 15:29:56 278800 ——w- C:\Windows\System32\MpSigStub.exe 2013-04-28 22:30:55 1767936 —-a-w- C:\Windows\SysWow64\wininet.dll 2013-04-28 22:30:12 2877440 —-a-w- C:\Windows\SysWow64\jscript9.dll 2013-04-28 22:28:33 2241024 —-a-w- C:\Windows\System32\wininet.dll 2013-04-28 22:28:29 915968 —-a-w- C:\Windows\System32\uxtheme.dll 2013-04-28 22:28:00 3958784 —-a-w- C:\Windows\System32\jscript9.dll 2013-04-27 05:20:12 733184 —-a-w- C:\Windows\System32\win32spl.dll 2013-04-23 23:13:53 1013248 —-a-w- C:\Windows\SysWow64\certutil.exe 2013-04-23 23:12:44 1569792 —-a-w- C:\Windows\SysWow64\crypt32.dll 2013-04-23 23:12:44 109056 —-a-w- C:\Windows\SysWow64\cryptnet.dll 2013-04-23 22:56:35 1255936 —-a-w- C:\Windows\System32\certutil.exe 2013-04-23 22:55:48 68096 —-a-w- C:\Windows\System32\cryptsvc.dll 2013-04-23 22:55:48 1889280 —-a-w- C:\Windows\System32\crypt32.dll 2013-04-23 22:55:48 141312 —-a-w- C:\Windows\System32\cryptnet.dll 2013-04-16 02:34:44 1455368 —-a-w- C:\Windows\System32\drivers\dxgkrnl.sys 2013-04-13 05:56:35 444416 —-a-w- C:\Windows\apppatch\AcSpecfc.dll 2013-04-11 06:40:48 6987528 —-a-w- C:\Windows\System32\ntoskrnl.exe . ============= FINISH: 14:56:12.17 ===============

Attachments:

I wanted to note that last night as I was posting the original post, I was running Avast Antivirus's long scan, and it did come up with something as a threat. I still have problems with the pop-ups though. But just so you know that the original hijack this could be different. I won't run anything else without your instructions though.
While I was running GMER, there was a notice something like: C:\windows\system32\config system the process cannot be accessed by the file becuase it is being used by another process. And then there was another notice behind that one that I didn't read/write down because I clicked on it too fast (thought it was a duplicate warning).

Here are the results from the text:

GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-07-08 15:03:26
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\000000b1 ST750LM022_HN-M750MBB rev.2AR10002 698.64GB
Running: glnzpoxp.exe; Driver: C:\Users\JIMANG~1\AppData\Local\Temp\uglyyaog.sys


—- Threads - GMER 2.1 —-

Thread C:\Windows\system32\csrss.exe [608:632] fffff960008315e8
Thread C:\Windows\system32\svchost.exe [436:3496] 000007f98fac10f0
Thread C:\Program Files (x86)\Internet Explorer\IELowutil.exe [3468:6256] 00000000771250a7

—- Disk sectors - GMER 2.1 —-

Disk \Device\Harddisk0\DR0 unknown MBR code

—- EOF - GMER 2.1 —-
Please download Malwarebytes Anti-Rootkit from here Malwarebytes : Malwarebytes Anti-Rootkit and save it to your desktop.

Be sure to print out and follow the instructions provided on that same page.

Caution: This is a beta version so please be sure to read the disclaimer and back up any important data before using.

  • Double click the mbar.zip file to open it, then 'Extract all files'.
  • Double click the mbar folder to open it, then double click mbar.exe to start the tool.
Check for Updates, then Scan your system for malware

If malware is found, do NOT press the Cleanup button yet. Click EXIT.

I'd like to see the log first so I can see what it sees. You'll find the log in that mbar folder as MBAR-log-***.txt . Please attach that to your next reply.
It found one thing. I didn't fix it, as you requested. ————————————— Malwarebytes Anti-Rootkit BETA 1.06.0.1004 © Malwarebytes Corporation 2011-2012 OS version: 6.2.9200 Windows 8 x64 Account is Administrative Internet Explorer version: 10.0.9200.16599 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED CPU speed: 2.695000 GHz Memory total: 3726909440, free: 2222694400 Downloaded database version: v2013.07.08.07 Initializing… ———— Kernel report ———— 07/08/2013 16:17:42 ———— Loaded modules ———– \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kd.dll \SystemRoot\system32\mcupdate_AuthenticAMD.dll \SystemRoot\System32\drivers\CLFS.SYS \SystemRoot\System32\drivers\tm.sys \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\system32\CI.dll \SystemRoot\System32\drivers\msrpc.sys \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\System32\Drivers\acpiex.sys \SystemRoot\System32\Drivers\WppRecorder.sys \SystemRoot\System32\drivers\ACPI.sys \SystemRoot\System32\drivers\WMILIB.SYS \SystemRoot\System32\drivers\msisadrv.sys \SystemRoot\System32\drivers\pci.sys \SystemRoot\System32\Drivers\cng.sys \SystemRoot\system32\drivers\tpm.sys \SystemRoot\System32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\pdc.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\System32\drivers\spaceport.sys \SystemRoot\System32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\drivers\amd_sata.sys \SystemRoot\System32\drivers\storport.sys \SystemRoot\System32\drivers\amd_xata.sys \SystemRoot\System32\drivers\EhStorClass.sys \SystemRoot\system32\drivers\fltmgr.sys \SystemRoot\System32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\System32\Drivers\ksecdd.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\system32\DRIVERS\wfplwfs.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\system32\DRIVERS\hpdskflt.sys \SystemRoot\System32\drivers\wd.sys \SystemRoot\System32\drivers\volsnap.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\System32\drivers\disk.sys \SystemRoot\System32\drivers\CLASSPNP.SYS \SystemRoot\System32\Drivers\aswVmm.sys \SystemRoot\System32\Drivers\aswRvrt.sys \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\drivers\cdrom.sys \SystemRoot\System32\Drivers\aswSnx.SYS \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\BasicRender.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\drivers\dxgmms1.sys \SystemRoot\System32\drivers\BasicDisplay.sys \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\System32\Drivers\aswTdi.SYS \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\System32\Drivers\aswrdr2.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\system32\DRIVERS\pacer.sys \SystemRoot\system32\DRIVERS\vwififlt.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\drivers\npsvctrig.sys \SystemRoot\System32\drivers\mssmbios.sys \SystemRoot\System32\drivers\discache.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\system32\DRIVERS\CLVirtualDrive.sys \SystemRoot\System32\Drivers\aswSP.SYS \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\system32\DRIVERS\rassstp.sys \SystemRoot\system32\DRIVERS\AgileVpn.sys \SystemRoot\system32\DRIVERS\tunnel.sys \SystemRoot\System32\drivers\CompositeBus.sys \SystemRoot\system32\DRIVERS\kdnic.sys \SystemRoot\System32\drivers\umbus.sys \SystemRoot\System32\drivers\amdppm.sys \SystemRoot\System32\drivers\WirelessButtonDriver64.sys \SystemRoot\System32\drivers\HIDCLASS.SYS \SystemRoot\System32\drivers\HIDPARSE.SYS \SystemRoot\system32\DRIVERS\atikmpag.sys \SystemRoot\system32\DRIVERS\atikmdag.sys \SystemRoot\System32\drivers\HDAudBus.sys \SystemRoot\system32\DRIVERS\athw8x.sys \SystemRoot\System32\drivers\vwifibus.sys \SystemRoot\System32\drivers\USBXHCI.SYS \SystemRoot\System32\drivers\ucx01000.sys \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys \SystemRoot\System32\drivers\usbohci.sys \SystemRoot\System32\drivers\USBPORT.SYS \SystemRoot\system32\DRIVERS\usbfilter.sys \SystemRoot\System32\drivers\usbehci.sys \SystemRoot\System32\drivers\i8042prt.sys \SystemRoot\system32\DRIVERS\SynTP.sys \SystemRoot\system32\DRIVERS\USBD.SYS \SystemRoot\System32\drivers\kbdclass.sys \SystemRoot\System32\drivers\mouclass.sys \SystemRoot\system32\DRIVERS\RtsP2Stor.sys \SystemRoot\system32\DRIVERS\Rt630x64.sys \SystemRoot\system32\DRIVERS\Accelerometer.sys \SystemRoot\System32\drivers\CmBatt.sys \SystemRoot\System32\drivers\BATTC.SYS \SystemRoot\System32\drivers\wmiacpi.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\System32\drivers\swenum.sys \SystemRoot\System32\drivers\ks.sys \SystemRoot\System32\drivers\rdpbus.sys \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\System32\drivers\usbhub.sys \SystemRoot\system32\drivers\AtihdW86.sys \SystemRoot\system32\drivers\portcls.sys \SystemRoot\system32\drivers\drmk.sys \SystemRoot\System32\Drivers\fastfat.SYS \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\System32\drivers\UsbHub3.sys \SystemRoot\system32\DRIVERS\stwrt64.sys \SystemRoot\System32\drivers\usbccgp.sys \SystemRoot\System32\Drivers\usbvideo.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\Drivers\dump_amd_sata.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\drivers\monitor.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\system32\drivers\luafv.sys \??\C:\Windows\system32\drivers\aswMonFlt.sys \SystemRoot\System32\Drivers\aswFsBlk.SYS \SystemRoot\system32\DRIVERS\appexDrv.sys \SystemRoot\system32\DRIVERS\lltdio.sys \SystemRoot\system32\DRIVERS\nwifi.sys \SystemRoot\system32\DRIVERS\ndisuio.sys \SystemRoot\system32\DRIVERS\rspndr.sys \SystemRoot\system32\DRIVERS\vwifimp.sys \SystemRoot\System32\drivers\condrv.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\system32\drivers\Ndu.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\Drivers\secdrv.SYS \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\System32\drivers\WSDPrint.sys \SystemRoot\system32\DRIVERS\cdfs.sys \??\C:\Windows\system32\drivers\mbamchameleon.sys \??\C:\Windows\system32\drivers\mbamswissarmy.sys ———– End ———– Done! <<<1>>> Upper Device Name: \Device\Harddisk0\DR0 Upper Device Object: 0xfffffa8004e95060 Upper Device Driver Name: \Driver\disk\ Lower Device Name: \Device\000000b1\ Lower Device Object: 0xfffffa80049726e0 Lower Device Driver Name: \Driver\amd_sata\ <<<2>>> Device number: 0, partition: 4 Physical Sector Size: 512 Drive: 0, DevicePointer: 0xfffffa8004e95060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\ ——— Disk Stack —— DevicePointer: 0xfffffa8004e95b10, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa8004e95060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\ DevicePointer: 0xfffffa8004b61040, DeviceName: Unknown, DriverName: \Driver\hpdskflt\ DevicePointer: 0xfffffa8004927b20, DeviceName: Unknown, DriverName: \Driver\amd_xata\ DevicePointer: 0xfffffa80049726e0, DeviceName: \Device\000000b1\, DriverName: \Driver\amd_sata\ ———— End ———- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 Partition type: GUID <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> Device number: 0, partition: 4 Partition type: GUID <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\Windows\system32\drivers… <<<2>>> Device number: 0, partition: 4 Partition type: GUID <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Done! Drive 0 Scanning MBR on drive 0… Inspecting partition table: This drive is a GPT Drive. MBR Signature: 55AA Disk Signature: 3D867707 GPT Protective MBR Partition information: Partition 0 type is EFI-GPT (0xee) Partition is NOT ACTIVE. Partition starts at LBA: 1 Numsec = 1465149167 Partition 1 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 GPT Partition information: GPT Header Signature 4546492050415254 GPT Header Revision 65536 Size 92 CRC 4181424875 GPT Header CurrentLba = 1 BackupLba 1465149167 GPT Header FirstUsableLba 34 LastUsableLba 1465149134 GPT Header Guid cb7f5876-4063-43e7-93fc-47445286b31 GPT Header Contains 128 partition entries starting at LBA 2 GPT Header Partition entry size = 128 Backup GPT header Signature 4546492050415254 Backup GPT header Revision 65536 Size 92 CRC 4181424875 Backup GPT header CurrentLba = 1465149167 BackupLba 1 Backup GPT header FirstUsableLba 34 LastUsableLba 1465149134 Backup GPT header Guid cb7f5876-4063-43e7-93fc-47445286b31 Backup GPT header Contains 128 partition entries starting at LBA 1465149135 Backup GPT header Partition entry size = 128 Partition 0 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac Partition ID 9a1b5b8a-550d-4434-9650-5eeb70f3bc91 FirstLBA 2048 Last LBA 821247 Attributes 1 Partition Name Basic data partition Partition 1 Type c12a7328-f81f-11d2-ba4b-0a0c93ec93b Partition ID a635be17-dc09-42e9-9aa0-b673ca2c88fc FirstLBA 821248 Last LBA 1353727 Attributes 0 Partition Name EFI system partition GPT Partition 1 is bootable Partition 2 Type e3c9e316-b5c-4db8-817d-f92df0215ae Partition ID 81b98761-78c6-4b82-a070-5b7c42ded61 FirstLBA 1353728 Last LBA 1615871 Attributes 0 Partition Name Microsoft reserved partition Partition 3 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7 Partition ID c72d63-ce17-4ae8-8bfb-804be5965c67 FirstLBA 1615872 Last LBA 1411973119 Attributes 0 Partition Name Basic data partition Partition 4 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7 Partition ID 65ca49b5-7ce1-4ef0-9d2-776676da716 FirstLBA 1411973120 Last LBA 1465147391 Attributes 1 Partition Name Basic data partition Disk Size: 750156374016 bytes Sector size: 512 bytes Done! Infected: c:\Users\JimAngehr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KDKQ6G2P\aol_checker[1].exe –> [Trojan.Agent.H] Scan finished
Run another scan with mbar.exe and click the CleanUp button. It will require a reboot. When it has rebooted, run another scan with mbar.exe and click CleanUp again if necessary. Send the mbar-log.txt along with an update on machine behavior.
Hi, So the first scan I cleaned up as requested. During the second scan, there was a notice that said: "Do you want the program to make the following changes: program: jucheck.exe, company oracle, origin; this computer's hard drive." I selected "No." because I didn't know what that program was. Here is the first log, I'll follow it in a second reply with the second log. Malwarebytes Anti-Rootkit BETA 1.06.0.1004 www.malwarebytes.org Database version: v2013.07.09.03 Windows 8 x64 NTFS Internet Explorer 10.0.9200.16599 JimAngehr :: JIMCOMPUTER [administrator] 7/9/2013 7:36:42 AM mbar-log-2013-07-09 (07-36-42).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P Scan options disabled: PUP Objects scanned: 268463 Time elapsed: 12 minute(s), 22 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 c:\Users\JimAngehr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KDKQ6G2P\aol_checker[1].exe (Trojan.Agent.H) -> Delete on reboot. Physical Sectors Detected: 0 (No malicious items detected) (end)
Second scan: Malwarebytes Anti-Rootkit BETA 1.06.0.1004 www.malwarebytes.org Database version: v2013.07.09.03 Windows 8 x64 NTFS Internet Explorer 10.0.9200.16599 JimAngehr :: JIMCOMPUTER [administrator] 7/9/2013 8:07:59 AM mbar-log-2013-07-09 (08-07-59).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P Scan options disabled: PUP Objects scanned: 268256 Time elapsed: 13 minute(s), 31 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end)
As for how my computer is responding, I'm still getting a pop-up when I browse the internet that says: "Reminder Your computer is not backed up, Backup your files online today: Free computer Backup Available.
Download and run OTL

  • Download OTL by OldTimer and save it to your desktop.
  • Double click on the OTL.exe icon on your desktop. If you are using Vista, please right-click and select run as administrator
  • Click the "Scan All Users" checkbox.


    Note: If you are using a Windows 64bit machine, please make sure the checkbox next to Include 64Bit Scans is checked. It will be checked by default.

  • Push the [external image: Posted Image] button.
  • It will now begin to scan, please be paitent while it scans.
  • Two reports will open once it's done.
  • Please copy and paste them in your next reply:
  • OTL.txt <– Will be opened
  • Extras.txt <– Will be minimized

Here are the two reports:


OTL logfile created on: 7/9/2013 9:14:54 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\JimAngehr\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16599)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.47 Gb Total Physical Memory | 2.12 Gb Available Physical Memory | 61.09% Memory free
6.97 Gb Paging File | 5.50 Gb Available in Paging File | 78.95% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 672.51 Gb Total Space | 482.63 Gb Free Space | 71.77% Space Free | Partition Type: NTFS
Drive D: | 25.36 Gb Total Space | 3.02 Gb Free Space | 11.91% Space Free | Partition Type: NTFS

Computer Name: JIMCOMPUTER | User Name: JimAngehr | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/07/09 09:14:09 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\JimAngehr\Desktop\OTL.exe
PRC - [2013/07/07 09:00:35 | 001,104,384 | —- | M] (Spotify Ltd) – C:\Users\JimAngehr\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
PRC - [2013/07/04 14:26:01 | 000,920,472 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2013/06/18 07:47:17 | 000,107,520 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe
PRC - [2013/05/24 20:47:30 | 027,776,968 | —- | M] (Dropbox, Inc.) – C:\Users\JimAngehr\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2013/05/09 04:58:30 | 004,858,968 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013/05/09 04:58:30 | 000,046,808 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/11/26 09:30:00 | 000,687,104 | —- | M] () – C:\Program Files (x86)\Fast Free Converter\FastFreeConverterUpdt.exe
PRC - [2012/07/27 21:21:26 | 000,136,488 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
PRC - [2012/07/09 16:40:02 | 000,580,512 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
PRC - [2012/07/09 16:40:02 | 000,035,232 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
PRC - [2012/06/07 23:34:06 | 000,111,120 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
PRC - [2012/03/28 21:34:30 | 000,091,432 | —- | M] (CyberLink Corp.) – C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
PRC - [2011/08/26 17:37:18 | 001,342,008 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
PRC - [2006/11/02 21:40:12 | 000,174,656 | —- | M] () – C:\Windows\SysWOW64\PSIService.exe


========== Modules (No Company Name) ==========

MOD - [2013/07/04 14:24:58 | 003,285,912 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2013/03/13 16:48:52 | 024,978,944 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Dropbox\bin\libcef.dll
MOD - [2012/11/13 19:32:50 | 003,558,400 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
MOD - [2012/06/08 14:34:06 | 000,016,400 | —- | M] () – C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
MOD - [2012/06/07 23:34:06 | 000,627,216 | —- | M] () – C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
MOD - [2012/02/20 21:29:04 | 000,087,912 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/02/20 21:28:42 | 001,242,472 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/10/05 04:52:30 | 000,756,048 | —- | M] () – C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL


========== Services (SafeList) ==========

SRV:64bit: - [2013/05/09 04:58:30 | 000,046,808 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\AVAST Software\Avast\AvastSvc.exe – (avast! Antivirus)
SRV:64bit: - [2013/05/04 02:58:02 | 000,470,528 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\netprofmsvc.dll – (netprofm)
SRV:64bit: - [2013/05/04 02:57:05 | 000,179,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\bisrv.dll – (BrokerInfrastructure)
SRV:64bit: - [2013/04/09 00:48:42 | 000,169,472 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\AudioEndpointBuilder.dll – (AudioEndpointBuilder)
SRV:64bit: - [2013/03/01 22:45:07 | 000,171,008 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\TimeBrokerServer.dll – (TimeBroker)
SRV:64bit: - [2013/03/01 22:45:05 | 000,180,224 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\SystemEventsBrokerServer.dll – (SystemEventsBroker)
SRV:64bit: - [2013/01/28 21:57:14 | 000,014,920 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MsMpEng.exe – (WinDefend)
SRV:64bit: - [2013/01/09 19:23:16 | 001,964,544 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wlidsvc.dll – (wlidsvc)
SRV:64bit: - [2013/01/09 19:22:35 | 000,438,272 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\lsm.dll – (LSM)
SRV:64bit: - [2012/11/06 00:36:55 | 002,675,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll – (PrintNotify)
SRV:64bit: - [2012/09/20 05:10:47 | 002,367,528 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\WSService.dll – (WSService)
SRV:64bit: - [2012/09/20 02:31:18 | 000,116,736 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\fhsvc.dll – (fhsvc)
SRV:64bit: - [2012/08/23 10:45:42 | 000,029,600 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Windows\SysNative\hpservice.exe – (hpsrv)
SRV:64bit: - [2012/08/09 02:45:58 | 000,239,616 | —- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2012/08/08 13:36:06 | 000,361,984 | —- | M] (Advanced Micro Devices, Inc.) [Auto | Running] – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe – (AMD FUEL Service)
SRV:64bit: - [2012/07/25 23:07:47 | 000,065,536 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wiarpc.dll – (WiaRpc)
SRV:64bit: - [2012/07/25 23:07:42 | 000,263,680 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wcmsvc.dll – (Wcmsvc)
SRV:64bit: - [2012/07/25 23:07:40 | 000,283,648 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\vaultsvc.dll – (VaultSvc)
SRV:64bit: - [2012/07/25 23:07:25 | 000,012,800 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\svsvc.dll – (svsvc)
SRV:64bit: - [2012/07/25 23:06:34 | 000,743,936 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\netlogon.dll – (Netlogon)
SRV:64bit: - [2012/07/25 23:06:33 | 000,161,792 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\NcaSvc.dll – (NcaSvc)
SRV:64bit: - [2012/07/25 23:06:33 | 000,073,728 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\NcdAutoSetup.dll – (NcdAutoSetup)
SRV:64bit: - [2012/07/25 23:05:55 | 000,059,904 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\keyiso.dll – (KeyIso)
SRV:64bit: - [2012/07/25 23:05:34 | 000,037,376 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\efssvc.dll – (EFS)
SRV:64bit: - [2012/07/25 23:05:28 | 000,207,872 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\DeviceSetupManager.dll – (DsmSvc)
SRV:64bit: - [2012/07/25 23:05:24 | 000,342,016 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\das.dll – (DeviceAssociationService)
SRV:64bit: - [2012/07/25 23:05:08 | 000,122,368 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\AUInstallAgent.dll – (AllUserInstallAgent)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmicvss)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmictimesync)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmicshutdown)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmicrdv)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmickvpexchange)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmicheartbeat)
SRV:64bit: - [2012/07/21 12:30:36 | 000,321,536 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Program Files\IDT\WDM\stacsv64.exe – (STacSV)
SRV:64bit: - [2010/04/14 20:56:24 | 001,052,328 | —- | M] ( ) [Auto | Running] – C:\Windows\SysNative\lxebcoms.exe – (lxeb_device)
SRV - [2013/07/04 14:25:59 | 000,117,144 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2013/06/23 09:02:05 | 000,256,904 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2013/06/18 07:47:17 | 000,107,520 | —- | M] () [Auto | Running] – C:\Users\JimAngehr\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe – (DefaultTabUpdate)
SRV - [2013/05/31 07:19:28 | 000,032,808 | —- | M] (Just Develop It) [Auto | Stopped] – C:\Program Files (x86)\MyPC Backup\BackupStack.exe – (BackupStack)
SRV - [2013/02/11 03:42:26 | 000,572,928 | —- | M] () [Auto | Stopped] – C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe – (DefaultTabSearch)
SRV - [2012/11/26 09:30:00 | 000,687,104 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Fast Free Converter\FastFreeConverterUpdt.exe – (FastFreeConverterUpdt)
SRV - [2012/11/06 00:36:55 | 002,675,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll – (PrintNotify)
SRV - [2012/08/10 20:53:44 | 000,085,504 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe – (HP Support Assistant Service)
SRV - [2012/07/25 23:20:04 | 000,018,432 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\StorSvc.dll – (StorSvc)
SRV - [2012/07/25 23:18:41 | 000,408,064 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\inetsrv\iisw3adm.dll – (WAS)
SRV - [2012/07/25 23:17:52 | 000,060,416 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\inetsrv\apphostsvc.dll – (AppHostSvc)
SRV - [2012/07/13 21:02:16 | 002,451,456 | —- | M] (Realsil Microelectronics Inc.) [Auto | Running] – C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe – (IconMan_R)
SRV - [2012/07/09 16:40:02 | 000,035,232 | —- | M] (Hewlett-Packard Development Company, L.P.) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe – (HPWMISVC)
SRV - [2010/10/12 13:59:12 | 000,206,072 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe – (GamesAppService)
SRV - [2006/11/02 21:40:12 | 000,174,656 | —- | M] () [Auto | Running] – C:\Windows\SysWOW64\PSIService.exe – (ProtexisLicensing)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/07/07 18:56:36 | 001,030,952 | —- | M] (AVAST Software) [File_System | System | Running] – C:\Windows\SysNative\drivers\aswSnx.sys – (aswSnx)
DRV:64bit: - [2013/07/07 18:56:36 | 000,378,944 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswSP.sys – (aswSP)
DRV:64bit: - [2013/07/07 18:56:36 | 000,189,936 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswVmm.sys – (aswVmm)
DRV:64bit: - [2013/05/09 04:59:07 | 000,072,016 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\aswRdr2.sys – (aswRdr)
DRV:64bit: - [2013/05/09 04:59:07 | 000,065,336 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswRvrt.sys – (aswRvrt)
DRV:64bit: - [2013/05/09 04:59:07 | 000,064,288 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswTdi.sys – (aswTdi)
DRV:64bit: - [2013/05/09 04:59:06 | 000,080,816 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\Drivers\aswMonFlt.sys – (aswMonFlt)
DRV:64bit: - [2013/05/09 04:59:06 | 000,033,400 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswFsBlk.sys – (aswFsBlk)
DRV:64bit: - [2013/05/04 03:34:17 | 000,446,720 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\USBHUB3.SYS – (USBHUB3)
DRV:64bit: - [2013/05/04 03:34:17 | 000,213,248 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\UCX01000.SYS – (UCX01000)
DRV:64bit: - [2013/05/04 03:34:15 | 000,284,416 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\spaceport.sys – (spaceport)
DRV:64bit: - [2013/03/02 06:57:48 | 000,337,128 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\USBXHCI.SYS – (USBXHCI)
DRV:64bit: - [2013/03/02 06:57:46 | 000,077,544 | —- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\storahci.sys – (storahci)
DRV:64bit: - [2013/03/02 06:45:20 | 000,148,712 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\tpm.sys – (TPM)
DRV:64bit: - [2013/03/02 06:45:19 | 000,194,792 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\sdbus.sys – (sdbus)
DRV:64bit: - [2013/03/02 06:39:38 | 000,069,864 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\pdc.sys – (pdc)
DRV:64bit: - [2013/02/02 03:25:23 | 000,037,632 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\BthAvrcpTg.sys – (BthAvrcpTg)
DRV:64bit: - [2013/01/28 21:57:05 | 000,035,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\WdBoot.sys – (WdBoot)
DRV:64bit: - [2013/01/28 19:08:22 | 000,230,904 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\WdFilter.sys – (WdFilter)
DRV:64bit: - [2013/01/09 21:53:32 | 000,028,904 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\msgpiowin32.sys – (msgpiowin32)
DRV:64bit: - [2012/11/26 23:55:44 | 000,029,952 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\BthhfHid.sys – (bthhfhid)
DRV:64bit: - [2012/11/20 00:54:31 | 000,039,936 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\hidi2c.sys – (hidi2c)
DRV:64bit: - [2012/11/05 23:55:44 | 000,022,528 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\fxppm.sys – (FxPPM)
DRV:64bit: - [2012/10/12 04:08:01 | 000,027,880 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\rdpvideominiport.sys – (RdpVideoMiniport)
DRV:64bit: - [2012/10/11 03:25:48 | 000,056,552 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\sdstor.sys – (sdstor)
DRV:64bit: - [2012/10/11 03:13:49 | 000,058,088 | —- | M] (Microsoft Corporation) [Kernel | System | Stopped] – C:\Windows\SysNative\Drivers\dam.sys – (dam)
DRV:64bit: - [2012/09/28 11:32:56 | 000,053,760 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2012/09/20 03:55:30 | 000,120,040 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\msgpioclx.sys – (GPIOClx0101)
DRV:64bit: - [2012/09/20 03:55:27 | 003,265,256 | —- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2012/09/20 03:55:24 | 000,533,224 | —- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2012/08/31 10:40:24 | 000,020,800 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\WirelessButtonDriver64.sys – (WirelessButtonDriver)
DRV:64bit: - [2012/08/24 05:38:28 | 000,448,312 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2012/08/24 05:38:28 | 000,043,832 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\Smb_driver_Intel.sys – (SmbDrvI)
DRV:64bit: - [2012/08/24 05:38:26 | 000,041,272 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\Smb_driver_AMDASF.sys – (SmbDrv)
DRV:64bit: - [2012/08/23 10:45:42 | 000,042,400 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\Accelerometer.sys – (Accelerometer)
DRV:64bit: - [2012/08/23 10:45:42 | 000,029,600 | —- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\hpdskflt.sys – (hpdskflt)
DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2012/08/09 04:03:32 | 010,283,520 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\atikmdag.sys – (amdkmdag)
DRV:64bit: - [2012/08/09 01:48:20 | 000,368,640 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2012/07/31 15:22:00 | 000,645,952 | —- | M] (Intel Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\iaStorA.sys – (iaStorA)
DRV:64bit: - [2012/07/31 04:04:12 | 000,690,832 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\Rt630x64.sys – (RTL8168)
DRV:64bit: - [2012/07/26 01:26:46 | 000,025,328 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2012/07/26 01:26:45 | 000,033,792 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\condrv.sys – (condrv)
DRV:64bit: - [2012/07/26 01:00:58 | 000,322,800 | —- | M] (VIA Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\VSTXRAID.SYS – (VSTXRAID)
DRV:64bit: - [2012/07/26 01:00:58 | 000,106,224 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\VerifierExt.sys – (VerifierExt)
DRV:64bit: - [2012/07/26 01:00:58 | 000,097,008 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\uaspstor.sys – (UASPStor)
DRV:64bit: - [2012/07/26 01:00:57 | 000,077,040 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\acpiex.sys – (acpiex)
DRV:64bit: - [2012/07/26 01:00:55 | 000,064,240 | —- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\mvumis.sys – (mvumis)
DRV:64bit: - [2012/07/26 01:00:55 | 000,030,960 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2012/07/26 01:00:52 | 000,092,400 | —- | M] (LSI Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2012/07/26 01:00:52 | 000,081,136 | —- | M] (LSI Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\lsi_sss.sys – (LSI_SSS)
DRV:64bit: - [2012/07/26 01:00:52 | 000,064,752 | —- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2012/07/26 01:00:51 | 000,113,904 | —- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys – (EhStorTcgDrv)
DRV:64bit: - [2012/07/26 01:00:51 | 000,081,136 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\EhStorClass.sys – (EhStorClass)
DRV:64bit: - [2012/07/26 01:00:49 | 000,258,288 | —- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2012/07/26 01:00:49 | 000,106,736 | —- | M] (LSI) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\3ware.sys – (3ware)
DRV:64bit: - [2012/07/26 01:00:49 | 000,076,016 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2012/07/26 01:00:48 | 000,026,352 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2012/07/26 00:57:54 | 000,361,200 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\clfs.sys – (CLFS)
DRV:64bit: - [2012/07/26 00:54:34 | 000,096,496 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\wfplwfs.sys – (WFPLWFS)
DRV:64bit: - [2012/07/26 00:53:16 | 000,067,824 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\vpci.sys – (vpci)
DRV:64bit: - [2012/07/25 23:17:38 | 000,036,592 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\terminpt.sys – (terminpt)
DRV:64bit: - [2012/07/25 22:29:47 | 000,021,504 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\WSDPrint.sys – (WSDPrintDevice)
DRV:64bit: - [2012/07/25 22:29:14 | 000,010,752 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\mshidumdf.sys – (mshidumdf)
DRV:64bit: - [2012/07/25 22:29:08 | 000,048,640 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\BasicDisplay.sys – (BasicDisplay)
DRV:64bit: - [2012/07/25 22:29:03 | 000,024,576 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\HyperVideo.sys – (HyperVideo)
DRV:64bit: - [2012/07/25 22:28:52 | 000,029,696 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\BasicRender.sys – (BasicRender)
DRV:64bit: - [2012/07/25 22:27:58 | 000,012,288 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\vmgencounter.sys – (gencounter)
DRV:64bit: - [2012/07/25 22:27:41 | 000,018,432 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\kdnic.sys – (kdnic)
DRV:64bit: - [2012/07/25 22:27:37 | 000,010,752 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\acpitime.sys – (acpitime)
DRV:64bit: - [2012/07/25 22:27:33 | 000,023,552 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\npsvctrig.sys – (npsvctrig)
DRV:64bit: - [2012/07/25 22:27:29 | 000,019,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\WpdUpFltr.sys – (WpdUpFltr)
DRV:64bit: - [2012/07/25 22:27:16 | 000,010,240 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\acpipagr.sys – (acpipagr)
DRV:64bit: - [2012/07/25 22:27:01 | 000,011,776 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\hyperkbd.sys – (hyperkbd)
DRV:64bit: - [2012/07/25 22:26:46 | 000,062,976 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\SerCx.sys – (SerCx)
DRV:64bit: - [2012/07/25 22:26:43 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\SpbCx.sys – (SpbCx)
DRV:64bit: - [2012/07/25 22:26:34 | 000,030,208 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2012/07/25 22:26:13 | 000,051,200 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\bthhfenum.sys – (BthHFEnum)
DRV:64bit: - [2012/07/25 22:25:57 | 000,033,280 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\dmvsc.sys – (dmvsc)
DRV:64bit: - [2012/07/25 22:25:56 | 000,057,344 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2012/07/25 22:25:13 | 000,045,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\wpcfltr.sys – (wpcfltr)
DRV:64bit: - [2012/07/25 22:25:01 | 000,126,464 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\NdisImPlatform.sys – (NdisImPlatform)
DRV:64bit: - [2012/07/25 22:23:53 | 000,068,608 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\mslldp.sys – (MsLldp)
DRV:64bit: - [2012/07/25 22:23:42 | 000,097,792 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\Windows\SysNative\Drivers\Ndu.sys – (Ndu)
DRV:64bit: - [2012/07/24 11:44:02 | 003,618,304 | —- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\athw8x.sys – (athr)
DRV:64bit: - [2012/07/24 05:35:12 | 000,079,528 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\amd_sata.sys – (amd_sata)
DRV:64bit: - [2012/07/24 05:35:12 | 000,026,280 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\amd_xata.sys – (amd_xata)
DRV:64bit: - [2012/07/21 12:30:36 | 000,540,160 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\stwrt64.sys – (STHDA)
DRV:64bit: - [2012/07/18 00:59:12 | 000,098,472 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\AtihdW86.sys – (AtiHDAudioService)
DRV:64bit: - [2012/07/03 18:09:08 | 000,269,968 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\RtsP2Stor.sys – (RSP2STOR)
DRV:64bit: - [2012/06/25 13:24:50 | 000,092,536 | —- | M] (CyberLink) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\CLVirtualDrive.sys – (CLVirtualDrive)
DRV:64bit: - [2012/06/23 09:23:38 | 000,199,008 | —- | M] (AppEx Networks Corporation) [Kernel | Auto | Running] – C:\Windows\SysNative\Drivers\appexDrv.sys – (APXACC)
DRV:64bit: - [2012/06/19 10:07:50 | 000,057,000 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\usbfilter.sys – (usbfilter)
DRV:64bit: - [2012/06/02 10:32:26 | 010,627,744 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\igdkmd64.sys – (igfx)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT13/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;pc=HPNTDFJS
IE:64bit: - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{F05749BB-0626-4108-9BA0-E2C7F7D1B555}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT13/1
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;pc=HPNTDFJS
IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…mrud=25-04-2013
IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}
IE - HKLM\..\SearchScopes\{F05749BB-0626-4108-9BA0-E2C7F7D1B555}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;pc=HPNTDFJS
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…mrud=25-04-2013
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes\{F05749BB-0626-4108-9BA0-E2C7F7D1B555}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Google"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://search.aol.com/search/search?q={searchTerms}&s;_it=webpickaol-ff&s;_qt=sb&tb;_uuid=D1E32A0EB1E84CB199BF9D10246EAD1B&tb;_oid=25-04-2013&tb;_mrud=26-04-2013"
FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:8.0.1489
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:22.0
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe;=utf-8&q;="


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Fast Free Converter\FastFreeConverter\[removed] [2013/06/18 07:45:28 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013/07/07 18:56:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/07/04 14:24:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/07/04 14:24:40 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/07/04 14:24:39 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/07/04 14:24:40 | 000,000,000 | —D | M]

[2012/11/01 21:44:34 | 000,000,000 | —D | M] (No name found) – C:\Users\JimAngehr\AppData\Roaming\Mozilla\Extensions
[2013/07/07 19:12:25 | 000,000,000 | —D | M] (No name found) – C:\Users\JimAngehr\AppData\Roaming\Mozilla\Firefox\Profiles\7zcy930i.default\extensions
[2013/07/07 19:05:10 | 000,002,552 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Mozilla\Firefox\Profiles\7zcy930i.default\searchplugins\aol-search.xml
[2013/07/07 09:01:43 | 000,001,988 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Mozilla\Firefox\Profiles\7zcy930i.default\searchplugins\search.xml
[2013/07/04 14:24:39 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013/07/04 14:26:02 | 000,000,000 | —D | M] (Default) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/07/07 18:56:00 | 000,000,000 | —D | M] (avast! Online Security) – C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll
CHR - plugin: Norton Identity Safe (Enabled) = C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.2.0.18_0\npcoplgn.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - Extension: BBRowsE2savve = C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\anokniebcoameopaknmpbhaaoedjajik\1\
CHR - Extension: YouTube = C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: EybooikBBriowsue = C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\niieikgjphnahhnnmdheblakpelnfgaj\1\
CHR - Extension: Gmail = C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2012/07/26 01:26:49 | 000,000,824 | —- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
O2:64bit: - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (DownloadTerms) - {2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3} - C:\Users\JimAngehr\AppData\Local\DownloadTerms\temp.dat ()
O2 - BHO: (BBRowsE2savve) - {4FA31CBC-669C-8878-251A-D2DA6ACAE0DF} - C:\ProgramData\BBRowsE2savve\5179416ce7628.dll ()
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (DefaultTab Browser Helper) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\JimAngehr\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll (Search Results LLC.)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Fast Free Converter 4.1) - {B422F1BC-9ADB-48A7-8B13-00C176039DC5} - C:\Program Files (x86)\Fast Free Converter\FastFreeConverter\FastFreeConverter.dll (Fast Free Converter)
O2 - BHO: (EybooikBBriowsue) - {C178AC1C-9A8B-8FF7-88BA-DB329D96695B} - C:\ProgramData\EybooikBBriowsue\5179419ef2e8c.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
O3:64bit: - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CLVirtualDrive] C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QuickFinder Scheduler] C:\Program Files (x86)\WordPerfect Office X3\Programs\QFSCHD130.EXE (Corel Corporation)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004..\Run: [Spotify] C:\Users\JimAngehr\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004..\Run: [Spotify Web Helper] C:\Users\JimAngehr\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - Startup: C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\JimAngehr\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk = C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Open with WordPerfect - C:\Program Files (x86)\WordPerfect Office X3\Programs\WPLauncher.hta ()
O8 - Extra context menu item: Open with WordPerfect - C:\Program Files (x86)\WordPerfect Office X3\Programs\WPLauncher.hta ()
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3C6BDB04-E01A-40C1-AD9D-37A8A0EE53D6}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/07/09 09:14:08 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\JimAngehr\Desktop\OTL.exe
[2013/07/08 16:17:43 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2013/07/08 16:17:27 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/07/08 16:16:49 | 000,000,000 | —D | C] – C:\Users\JimAngehr\Desktop\mbar-1.06.0.1004
[2013/07/08 14:54:34 | 000,688,992 | R— | C] (Swearware) – C:\Users\JimAngehr\Desktop\dds(1).scr
[2013/07/07 18:56:32 | 000,378,944 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2013/07/07 18:56:32 | 000,072,016 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr2.sys
[2013/07/07 18:56:32 | 000,064,288 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2013/07/07 18:56:32 | 000,033,400 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2013/07/07 18:56:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2013/07/07 18:56:18 | 001,030,952 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2013/07/07 18:56:18 | 000,080,816 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2013/07/07 18:55:43 | 000,041,664 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2013/07/04 14:24:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/07/04 07:43:26 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tssdisai.dll
[2013/06/23 09:01:20 | 000,000,000 | —D | C] – C:\Users\JimAngehr\AppData\Local\Adobe
[2013/06/18 07:47:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\DefaultTab
[2013/06/18 07:47:13 | 000,000,000 | —D | C] – C:\Users\JimAngehr\AppData\Roaming\DefaultTab
[2013/06/18 07:47:05 | 000,000,000 | —D | C] – C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NexGen Media Player
[2013/06/18 07:46:46 | 000,000,000 | —D | C] – C:\Users\JimAngehr\AppData\Local\NexGenMediaPlayer
[2013/06/18 07:46:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\NexGen Media Player
[2013/06/18 07:46:43 | 000,000,000 | —D | C] – C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
[2013/06/18 07:46:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\MyPC Backup
[2013/06/18 07:45:41 | 000,000,000 | —D | C] – C:\Users\JimAngehr\AppData\Local\DownloadTerms
[2013/06/18 07:45:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\File Type Helper
[2013/06/18 07:45:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Fast Free Converter
[2013/06/18 07:45:16 | 000,000,000 | —D | C] – C:\Users\JimAngehr\AppData\Local\SwvUpdater
[2013/06/16 09:11:00 | 001,257,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2013/06/16 09:10:58 | 001,300,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\gdi32.dll
[2013/06/16 09:10:55 | 000,888,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\autochk.exe
[2013/06/16 09:10:55 | 000,793,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\autochk.exe
[2013/06/16 09:10:55 | 000,542,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\untfs.dll
[2013/06/16 09:10:55 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\untfs.dll
[2013/06/15 08:18:24 | 013,644,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Windows.UI.Xaml.dll
[2013/06/15 08:18:21 | 010,788,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Windows.UI.Xaml.dll
[2013/06/15 08:18:19 | 001,131,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AppXDeploymentServer.dll
[2013/06/15 08:18:18 | 010,116,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\twinui.dll
[2013/06/15 08:18:14 | 000,470,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netprofmsvc.dll
[2013/06/15 08:18:13 | 008,857,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\twinui.dll
[2013/06/15 08:18:13 | 002,305,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\authui.dll
[2013/06/15 08:18:12 | 002,035,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\authui.dll
[2013/06/15 08:18:12 | 000,760,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2013/06/15 08:18:11 | 000,446,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\USBHUB3.SYS
[2013/06/15 08:18:11 | 000,328,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ubpm.dll
[2013/06/15 08:18:11 | 000,014,848 | —- | C] (Microsoft) – C:\Windows\SysWow64\rars.rs
[2013/06/15 08:18:11 | 000,014,848 | —- | C] (Microsoft) – C:\Windows\SysNative\rars.rs
[2013/06/15 08:18:10 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\BCP47Langs.dll
[2013/06/15 08:18:10 | 000,330,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\stobject.dll
[2013/06/15 08:18:10 | 000,247,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ubpm.dll
[2013/06/15 08:18:09 | 000,708,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AppXDeploymentExtensions.dll
[2013/06/15 08:18:09 | 000,621,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuapi.dll
[2013/06/15 08:18:08 | 000,812,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Magnify.exe
[2013/06/15 08:18:08 | 000,213,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\UCX01000.SYS
[2013/06/15 08:18:08 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netplwiz.dll
[2013/06/15 08:18:08 | 000,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psmsrv.dll
[2013/06/15 08:18:07 | 000,560,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfmp4srcsnk.dll
[2013/06/15 08:18:07 | 000,151,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netplwiz.dll
[2013/06/15 08:18:06 | 000,501,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DevicePairing.dll
[2013/06/15 08:18:06 | 000,284,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\spaceport.sys
[2013/06/15 08:18:06 | 000,058,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2013/06/15 08:18:05 | 000,758,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Magnify.exe
[2013/06/15 08:18:05 | 000,419,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\intl.cpl
[2013/06/15 08:18:05 | 000,120,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AuthHost.exe
[2013/06/15 08:18:04 | 001,619,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2013/06/15 08:18:04 | 000,449,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\DevicePairing.dll
[2013/06/15 08:18:04 | 000,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\hidclass.sys
[2013/06/15 08:18:03 | 000,251,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUSettingsProvider.dll
[2013/06/15 08:18:03 | 000,122,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\biwinrt.dll
[2013/06/15 08:18:03 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\biwinrt.dll
[2013/06/15 08:18:02 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\intl.cpl
[2013/06/15 08:18:02 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\bisrv.dll
[2013/06/15 08:18:01 | 000,411,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfmp4srcsnk.dll
[2013/06/15 08:18:01 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\storewuauth.dll
[2013/06/15 08:18:01 | 000,141,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2013/06/15 08:18:01 | 000,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuwebv.dll
[2013/06/15 08:18:01 | 000,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2013/06/15 08:18:00 | 000,309,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\BCP47Langs.dll
[2013/06/15 08:18:00 | 000,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wudriver.dll
[2013/06/15 08:18:00 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2013/06/15 08:17:59 | 000,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\muifontsetup.dll
[2013/06/15 08:17:58 | 000,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuapp.exe
[2013/06/15 08:17:58 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\muifontsetup.dll
[2013/06/12 07:10:25 | 001,889,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/06/12 07:10:24 | 001,255,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certutil.exe
[2013/06/12 07:10:24 | 001,013,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certutil.exe
[2013/06/12 07:10:24 | 000,141,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2013/06/12 07:10:21 | 000,733,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/06/12 07:10:19 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptdlg.dll
[2013/06/12 07:10:19 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cryptdlg.dll
[2013/06/12 07:09:39 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/06/12 07:09:30 | 000,915,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\uxtheme.dll
[2013/06/12 07:09:29 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/06/12 07:09:29 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/06/12 07:09:28 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/06/12 07:09:27 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/06/12 07:09:27 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UXInit.dll
[2013/06/12 07:09:27 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UXInit.dll

========== Files - Modified Within 30 Days ==========

[2013/07/09 09:14:09 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\JimAngehr\Desktop\OTL.exe
[2013/07/09 09:12:11 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/07/09 09:05:00 | 000,000,928 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/09 09:05:00 | 000,000,924 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/09 08:35:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/07/09 08:11:28 | 001,560,144 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/07/09 08:11:28 | 000,408,394 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/07/09 08:11:28 | 000,006,364 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/07/09 08:04:30 | 000,000,372 | —- | M] () – C:\Windows\tasks\AmiUpdXp.job
[2013/07/09 08:02:57 | 268,435,456 | -HS- | M] () – C:\swapfile.sys
[2013/07/09 08:02:55 | 2981,527,552 | -HS- | M] () – C:\hiberfil.sys
[2013/07/08 16:16:15 | 013,399,154 | —- | M] () – C:\Users\JimAngehr\Desktop\mbar-1.06.0.1004.zip
[2013/07/08 15:21:46 | 551,744,019 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/07/08 14:59:34 | 000,377,856 | —- | M] () – C:\Users\JimAngehr\Desktop\glnzpoxp.exe
[2013/07/08 14:54:35 | 000,688,992 | R— | M] (Swearware) – C:\Users\JimAngehr\Desktop\dds(1).scr
[2013/07/07 18:56:37 | 000,000,175 | —- | M] () – C:\Windows\SysNative\drivers\aswVmm.sys.sum
[2013/07/07 18:56:36 | 001,030,952 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2013/07/07 18:56:36 | 000,378,944 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2013/07/07 18:56:36 | 000,189,936 | —- | M] () – C:\Windows\SysNative\drivers\aswVmm.sys
[2013/07/07 18:56:36 | 000,000,175 | —- | M] () – C:\Windows\SysNative\drivers\aswSP.sys.sum
[2013/07/07 18:56:36 | 000,000,175 | —- | M] () – C:\Windows\SysNative\drivers\aswSnx.sys.sum
[2013/07/07 18:56:33 | 000,001,922 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/07/07 18:56:18 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2013/07/07 08:26:35 | 000,000,372 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForJimAngehr.job
[2013/07/07 08:26:26 | 000,349,016 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/06/21 22:39:11 | 000,001,092 | —- | M] () – C:\Users\JimAngehr\Desktop\Continue Vid-Saver Installation.lnk
[2013/06/18 07:47:24 | 000,000,258 | RHS- | M] () – C:\Users\JimAngehr\ntuser.pol
[2013/06/18 07:47:05 | 000,001,080 | —- | M] () – C:\Users\JimAngehr\Desktop\NexGen Media Player.lnk
[2013/06/18 07:46:44 | 000,001,101 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
[2013/06/18 07:46:44 | 000,001,091 | —- | M] () – C:\Users\JimAngehr\Desktop\MyPC Backup.lnk
[2013/06/18 07:45:40 | 000,000,002 | —- | M] () – C:\END
[2013/06/15 08:56:55 | 000,001,056 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/06/15 08:56:19 | 000,001,032 | —- | M] () – C:\Users\JimAngehr\Desktop\Dropbox.lnk

========== Files Created - No Company Name ==========

[2013/07/08 16:16:12 | 013,399,154 | —- | C] () – C:\Users\JimAngehr\Desktop\mbar-1.06.0.1004.zip
[2013/07/08 14:59:33 | 000,377,856 | —- | C] () – C:\Users\JimAngehr\Desktop\glnzpoxp.exe
[2013/07/07 18:56:37 | 000,000,175 | —- | C] () – C:\Windows\SysNative\drivers\aswVmm.sys.sum
[2013/07/07 18:56:37 | 000,000,175 | —- | C] () – C:\Windows\SysNative\drivers\aswSP.sys.sum
[2013/07/07 18:56:37 | 000,000,175 | —- | C] () – C:\Windows\SysNative\drivers\aswSnx.sys.sum
[2013/07/07 18:56:33 | 000,001,922 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/07/07 18:56:18 | 000,189,936 | —- | C] () – C:\Windows\SysNative\drivers\aswVmm.sys
[2013/07/07 18:56:18 | 000,065,336 | —- | C] () – C:\Windows\SysNative\drivers\aswRvrt.sys
[2013/07/07 08:26:05 | 000,349,016 | —- | C] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/06/21 22:39:11 | 000,001,092 | —- | C] () – C:\Users\JimAngehr\Desktop\Continue Vid-Saver Installation.lnk
[2013/06/18 07:47:24 | 000,000,258 | RHS- | C] () – C:\Users\JimAngehr\ntuser.pol
[2013/06/18 07:47:05 | 000,001,080 | —- | C] () – C:\Users\JimAngehr\Desktop\NexGen Media Player.lnk
[2013/06/18 07:46:44 | 000,001,101 | —- | C] () – C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
[2013/06/18 07:46:44 | 000,001,091 | —- | C] () – C:\Users\JimAngehr\Desktop\MyPC Backup.lnk
[2013/06/18 07:45:39 | 000,000,002 | —- | C] () – C:\END
[2013/06/18 07:45:17 | 000,000,372 | —- | C] () – C:\Windows\tasks\AmiUpdXp.job
[2013/06/15 08:17:58 | 000,386,646 | —- | C] () – C:\Windows\SysNative\ApnDatabase.xml
[2013/04/01 13:01:32 | 000,000,000 | —- | C] () – C:\Windows\setup32.INI
[2013/01/09 10:33:21 | 000,200,704 | —- | C] () – C:\Windows\SysWow64\Bwbits50.dll
[2013/01/09 10:33:21 | 000,181,760 | —- | C] () – C:\Windows\SysWow64\patchw32.dll
[2013/01/09 10:33:21 | 000,116,736 | —- | C] () – C:\Windows\SysWow64\patchw.dll
[2013/01/09 10:33:21 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\bwplay.exe
[2013/01/09 10:33:21 | 000,053,760 | —- | C] () – C:\Windows\SysWow64\zlib.dll
[2013/01/09 10:33:21 | 000,020,992 | —- | C] () – C:\Windows\SysWow64\bwntsend.dll
[2013/01/09 10:33:21 | 000,016,896 | —- | C] () – C:\Windows\SysWow64\bwnthook.dll
[2012/11/07 13:02:13 | 000,001,056 | -HS- | C] () – C:\Windows\SysWow64\KGyGaAvL.sys
[2012/11/04 15:22:24 | 000,083,968 | —- | C] () – C:\Windows\SysWow64\OEMLicense.dll
[2012/08/16 23:46:43 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2012/08/09 02:10:22 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2012/08/09 02:10:22 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2012/08/03 18:40:09 | 000,916,510 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/07/26 04:13:10 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2012/07/26 04:13:09 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2012/07/26 03:21:26 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2012/07/25 21:17:42 | 000,043,520 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2012/07/25 16:37:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2012/07/25 16:28:31 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2012/07/25 16:22:54 | 000,982,240 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2012/07/25 16:22:54 | 000,439,308 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2012/07/25 16:22:54 | 000,092,356 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2012/06/02 10:31:19 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2012/05/10 19:35:16 | 000,029,184 | —- | C] () – C:\Windows\SysWow64\kdbsdk32.dll
[2011/09/13 10:06:16 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2012/08/17 00:03:34 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/03/06 02:31:28 | 019,758,592 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/03/06 01:03:37 | 017,561,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2012/07/25 23:05:38 | 001,004,544 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2012/07/25 23:18:27 | 000,784,896 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2012/07/25 23:07:41 | 000,455,680 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

< End of report >
OTL Extras logfile created on: 7/9/2013 9:14:54 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\JimAngehr\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16599)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.47 Gb Total Physical Memory | 2.12 Gb Available Physical Memory | 61.09% Memory free
6.97 Gb Paging File | 5.50 Gb Available in Paging File | 78.95% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 672.51 Gb Total Space | 482.63 Gb Free Space | 71.77% Space Free | Partition Type: NTFS
Drive D: | 25.36 Gb Total Space | 3.02 Gb Free Space | 11.91% Space Free | Partition Type: NTFS

Computer Name: JIMCOMPUTER | User Name: JimAngehr | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2393212166-3480209652-2217339028-1004\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – C:\Program Files (x86)\File Type Helper\FileTypeHelper.exe "%1" (Microsoft)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – C:\Program Files (x86)\File Type Helper\FileTypeHelper.exe "%1" (Microsoft)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05465A48-0908-4B53-9AF0-7E46102225CB}" = rport=445 | protocol=6 | dir=out | app=system |
"{1B72A1B9-5E3C-44CC-A547-23BD6C388A7C}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{1B80A7CE-8D55-4EE4-A9AA-53BBC2503FD1}" = rport=10243 | protocol=6 | dir=out | app=system |
"{21E63CA2-B8BF-45E4-8542-A46B3CBF2C1F}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{28C8B5DC-487A-4D3E-993C-E451CB1E40E0}" = rport=137 | protocol=17 | dir=out | app=system |
"{2FD3C2BF-420A-46C7-99EA-DBFEDBD3A7EE}" = lport=2869 | protocol=6 | dir=in | app=system |
"{3560D1DA-0D16-4763-9971-C3C27F7B6997}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4B866E97-3F76-4FB7-A518-B748F685D26F}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{5123B85F-F34C-4ECB-AEC0-3B6CB540CD2F}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{561DB4B8-4365-418B-BFDD-08E7130D8E5E}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7D2FAC9A-D001-4925-AE61-A246F82E22E6}" = lport=445 | protocol=6 | dir=in | app=system |
"{956603A6-5079-4593-9739-D352E262B33D}" = lport=138 | protocol=17 | dir=in | app=system |
"{9E78E38B-0BB1-4448-BAB6-E583335C20A3}" = lport=10243 | protocol=6 | dir=in | app=system |
"{A97FD650-C6EB-4F62-A9E5-A74557710864}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{AA274E0C-AD27-4E18-B610-D4CC17EFACA6}" = rport=139 | protocol=6 | dir=out | app=system |
"{AAF0E9C5-09D7-4CEE-82D7-C965C7410262}" = lport=139 | protocol=6 | dir=in | app=system |
"{AE0E0076-0329-4908-9568-6BA0F320CC80}" = rport=138 | protocol=17 | dir=out | app=system |
"{BB6F6AAE-92CC-4A0D-AAEA-9BAD320F00DC}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{BE6671C4-DDD7-4CCB-83B2-4F1A23C1F14F}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E00FF754-17C6-40D2-B2FE-61A0D42DF6FC}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E6417916-172C-4F56-96F7-A9C7005FC3DD}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E9F2CED8-FB26-4AAD-8722-5E0D62901CE4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{EB36EF9F-D626-4D49-8B33-E7A119CC2924}" = lport=137 | protocol=17 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{048218C3-13DE-436E-A9BE-02DA50C3D50C}" = dir=out | name=iheartradio |
"{12D81068-1B7B-4642-B216-E34D50BA454F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{15C731B5-782E-4EC0-8632-A7F519DA8367}" = dir=out | name=hp connected photo powered by snapfish |
"{191487FE-D290-4C6D-BE29-896BB8402A76}" = dir=out | name=windows_ie_ac_001 |
"{1CD99269-3A46-40AE-8C2E-2575EEE275CC}" = dir=in | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} |
"{1CFB44EB-352D-4563-B2FF-EEF7F8A2B98F}" = dir=in | name=kindle |
"{1DAF7213-149D-483F-919C-FC9A1782BF10}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd10.exe |
"{224DFAE6-65C0-4443-9D0F-A1AD89FCD02C}" = dir=out | name=@{microsoft.bingmaps_1.2.0.136_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{26E2B2B2-F046-420B-B1FA-5FA4101884C7}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\apple\windows migration assistant\migrationassistant.exe |
"{276ED55C-9E79-4BB4-B953-46997E25CF26}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{290C564B-A2EF-4E81-B8A7-BAE6F9436C7D}" = dir=out | name=@{microsoft.zunevideo_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} |
"{29928DF5-125D-4E34-8F2D-CB381E8B2B4B}" = dir=out | name=@{microsoft.bingweather_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} |
"{2C1A618F-1FD3-4E53-B9D2-6D732A10AAC7}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\apple\windows migration assistant\migrationassistant.exe |
"{2D789190-5FA8-497D-8FBC-BD2CF4CA3DFC}" = dir=out | name=ebay |
"{2F46F642-FA61-4252-B5A5-835D1CE25069}" = protocol=17 | dir=in | app=c:\users\jimangehr\appdata\roaming\dropbox\bin\dropbox.exe |
"{2FDDF51D-8C19-4E1F-8145-E5BB0420F88C}" = dir=out | name=hp registration |
"{354A4561-8002-4285-B23F-99F8B4762D7A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{36804125-ABD5-4E85-8463-EA15352F20B4}" = dir=in | name=ebay |
"{3B81847F-CCA5-41A5-BE27-74C63ECAB5B7}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\apple\windows migration assistant\migrationassistant.exe |
"{3BEFE5B4-F9C3-4F06-BC34-B7BDB6B43477}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{40FFA31D-CF18-4299-802D-04CD34E1EA7C}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} |
"{4C49CD81-5BCD-4523-AC19-CE26820A0ED7}" = dir=out | name=norton studio |
"{543DE030-8B4F-4A05-9E4A-1E84BAEF3474}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{5452F377-C7F4-4CC1-A5FE-947B6E6CAFDB}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} |
"{5484C865-613F-481B-A95D-FB52A45DC003}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{578C5A14-4ACE-4FA3-A006-358194C9742A}" = dir=out | name=netflix |
"{5835A819-FC7C-4A89-A376-E0A9A063B886}" = dir=out | name=microsoft mahjong |
"{5AB8A759-4FC3-4113-A2F7-81CA9E6B7159}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{5F0C700E-240C-4EC7-AB2A-CC8690142538}" = dir=out | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{5F937257-754C-42BB-B88A-88CD74083006}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{60DBCCBF-EEBD-4E3B-A7E8-4528F7AC90FE}" = dir=in | name=@{microsoft.reader_6.2.8516.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{6193F822-D2E4-4469-8883-03EFF6959832}" = dir=out | name=getting started with windows 8 |
"{649E4EB4-6C5A-4018-A4DA-BB763993DAAC}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{65533AB3-0D7C-4811-BB9B-E944B614600B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{6AFE43E9-10B6-4037-A7D2-2423A808AF0B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6BD742B1-5535-46C4-9CE3-031FDCC8A44F}" = dir=out | name=skype |
"{6D817E35-73E4-4C80-BA60-F1AAD54F78B4}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{76104D3B-BA28-462A-83C8-64346241E36E}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{7A151392-A3FA-4305-81BC-9B477A487E27}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\apple\windows migration assistant\migrationassistant.exe |
"{7AAC1848-69CD-40EF-AC9A-843FF12DBE42}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{7E49604C-A70A-4213-955E-C2A565027A60}" = dir=out | name=@{microsoft.xboxlivegames_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{81D66DD7-A8A0-4C3D-B69D-7FD932F2637D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{87BBD29F-A52E-4AAB-9B50-FF89B590521D}" = dir=out | name=kindle |
"{8B12381C-6FC7-4527-AC28-B50692401F14}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{90E353EE-151B-46F5-9B61-ED5AE7992C3A}" = dir=in | name=skype |
"{96766299-A9A5-40BF-AA00-FD806786A493}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{9A3987EB-8A87-46D5-A917-F20F228487B0}" = protocol=6 | dir=in | app=c:\users\jimangehr\appdata\roaming\dropbox\bin\dropbox.exe |
"{A6E2E4D3-2064-4911-91E6-AB5DA5CAA952}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{AC7271D2-8DAE-4456-87D4-EE9B32BD5CA2}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{B43020A4-85C3-4011-9148-EB77CE08DC27}" = dir=out | name=@{microsoft.bingfinance_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} |
"{B43DC248-7E2B-44C0-8BF7-C77450A61C13}" = dir=out | name=@{microsoft.bingnews_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} |
"{B65E681C-9ADF-44DD-A2BF-B01C5FA75E6A}" = dir=out | name=@{microsoft.bing_1.2.0.137_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} |
"{B69BD6F7-3252-4837-B45A-CD842A6E73FF}" = dir=out | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{C0C59FC1-9500-4175-9EB3-CAA88271A48D}" = protocol=6 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe |
"{C3F5A523-E83F-4647-8D1A-4F09A8DACED9}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{C4485C55-3CB0-462D-986A-7EC189676C61}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C4B45471-F57B-42E3-8828-EE8E37F3BBEF}" = dir=in | name=@{microsoft.windowsphotos_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{C58AAC7D-BC17-4A8D-8500-852B444F2EE0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C66A9E9C-1C4B-45C5-8263-E0EA5E6ACD43}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4204.712_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} |
"{C812482F-A1BF-4A7A-A15D-F9D15CEBDF0B}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C8F96060-2AD9-41E4-B64E-8A5282DD4A3A}" = dir=in | app=c:\windows\system32\lxebcoms.exe |
"{CC5D2CEB-6621-48A0-B7C0-ACE2B888B4C8}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{D04BDB92-7E39-42F2-A953-CAAD134C9E32}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{DB51749A-FCE9-423A-B36A-BF51DBEAF97E}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{E20F1EF7-794B-4169-8566-1CABAD9BE426}" = dir=out | name=@{microsoft.zunemusic_1.0.927.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} |
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{E7BFD6D3-5992-4413-8ECB-78F8C86A7A51}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector10\pdr10.exe |
"{E7E47A49-7754-4ED1-8B49-3952B94C2C60}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{EAF69157-64E6-4671-88D0-2D032D9FF761}" = dir=out | name=hp+ |
"{F24B129B-A742-46AC-B017-93B8BCAE9626}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F4255B85-2DB8-44AB-903B-3B19121EBC48}" = dir=out | name=microsoft solitaire collection |
"{FB535B77-F0D4-4F73-AC7D-D6B29677319F}" = protocol=6 | dir=out | app=system |
"{FE666417-27C9-4E79-922A-7DB168F241D5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FF196385-AE87-4150-A0F6-D7BEB0918D86}" = protocol=17 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe |
"TCP Query User{61CEF9D8-6374-4A46-87A2-2B2DD91AF381}C:\users\jimangehr\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\jimangehr\appdata\roaming\spotify\spotify.exe |
"TCP Query User{BB38DA19-A730-4FDB-A12B-8EA7DFBBC2C4}C:\users\jimangehr\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\jimangehr\appdata\roaming\spotify\spotify.exe |
"TCP Query User{F52A8D6F-674F-483D-8719-1135AAC2254D}C:\users\jimangehr\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\jimangehr\appdata\roaming\dropbox\bin\dropbox.exe |
"UDP Query User{03D35D39-C5E7-4307-9927-5B4ED6FC27ED}C:\users\jimangehr\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\jimangehr\appdata\roaming\spotify\spotify.exe |
"UDP Query User{329ACE80-CAA2-4DD0-A9A8-8A9986A4F5F5}C:\users\jimangehr\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\jimangehr\appdata\roaming\spotify\spotify.exe |
"UDP Query User{F4B0EB35-5F59-4086-A555-9A711BDEE7CD}C:\users\jimangehr\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\jimangehr\appdata\roaming\dropbox\bin\dropbox.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{08F2724F-3B6A-91BD-E63F-1B9F8463D097}" = AMD Accelerated Video Transcoding
"{0E5D76AD-A3FB-48D5-8400-8903B10317D3}" = iTunes
"{0FA995CC-C849-4755-B14B-5404CC75DC24}" = Energy Star
"{14D155F8-40FC-F843-30C6-8776BF5CEBAA}" = AMD Fuel
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6821D775-9303-46DD-977A-2D97CA18B054}" = HP 3D DriveGuard
"{6E14E6D6-3175-4E1A-B934-CAB5A86367CD}" = HP Postscript Converter
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.02
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A257DDD7-AFD4-ABEA-0F67-9C3930091B19}" = ccc-utility64
"{D01E0B82-7D6E-F9AC-9A7D-C6076264F419}" = AMD Catalyst Install Manager
"{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{E4D6CCF2-0AAF-4B9C-9DE5-893EDC9B4BAA}" = HP Registration Service
"{E9EED4AE-682B-4501-9574-D09A21717599}_is1" = AMD Quick Stream
"MyPC Backup" = MyPC Backup
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{83FBD495-DDF6-4C8D-92D6-10261DD6F6A3}" = WordPerfect Office X3
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{097CB5A1-D19E-F62A-6400-91DBF8D97B17}" = CCC Help Turkish
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0C57987A-A03A-4B95-A309-D23F78F406CA}" = HP Utility Center
"{0DCCD5F4-29E7-4AA0-8C1D-F8E1503B91F4}" = Catalyst Control Center - Branding
"{0EF2A1AF-6F24-FD4B-3140-3656CC9A6BEC}" = CCC Help Italian
"{11230C68-9248-D3B8-A0C5-0461D8C0691E}" = CCC Help Dutch
"{16B7BDA1-B967-4D2D-8B27-E12727C28350}" = HP CoolSense
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1AC082E0-049D-4C5C-9ECF-9473AD5A949D}" = HP Documentation
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 10
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83217013FF}" = Java 7 Update 13
"{29A6A747-07ED-DB5E-AD38-5F66B06E8888}" = CCC Help Russian
"{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8
"{2BE3A1BC-D155-1D32-9080-685C54689C34}" = CCC Help Korean
"{2F413B34-8C18-328C-E68C-0332AB527CFF}" = CCC Help Czech
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3D062C86-0CCA-8F10-A575-3564BD50372C}" = Catalyst Control Center Graphics Previews Common
"{3E2D81D1-5FEE-6E90-2E0C-B8C15F05237A}" = CCC Help Norwegian
"{47B3FDA1-E7F2-D3C3-0970-B9916C5530F3}" = AMD VISION Engine Control Center
"{4862344A-A39C-4897-ACD4-A1BED5163C5A}" = CyberLink PhotoDirector
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4ED7050C-9332-4FB2-AB07-E94F25A53D39}" = HP Quick Launch
"{528AB81B-D65A-4AB0-A2B6-82B51A087D01}" = HP Recovery Manager
"{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5CBA9A98-4CAE-92DC-4662-A77268EE1D04}" = CCC Help English
"{5F1C0CF4-49C6-B096-0F72-AA2C319BBEE0}" = CCC Help German
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{650AA9FB-CA49-A284-8E13-F3732CC20D9A}" = Catalyst Control Center Localization All
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6DF0DAF1-BED0-F5BB-B96E-10AA15DF65E7}" = CCC Help Swedish
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.0.0
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp" = WildTangent Games App
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{73AD6CBA-D50D-F30C-E579-14389FF41D1D}" = Catalyst Control Center InstallProxy
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7AF962CF-7018-C589-8439-EA7C9F2FA200}" = CCC Help Danish
"{7BB80D45-4024-2E0C-FC0D-45A319CD3F99}" = CCC Help Thai
"{835B275B-F29B-464B-BD4B-097FD55FAB0A}" = HP Software Framework
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{83FBD495-DDF6-4C8D-92D6-10261DD6F6A3}" = WordPerfect Office X3
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{941DE69D-6CEE-4171-8F1F-3D7E352AA498}" = HP Wireless Button Driver
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office
"{95A762D1-99E7-F428-99B3-E3CC636C48D9}" = CCC Help Hungarian
"{96DAE3D0-5008-F1FC-186D-0B364071C98C}" = CCC Help French
"{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}" = Software Version Updater
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B42457E-3781-7293-5643-C722BA43397E}" = CCC Help Greek
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C35EDE5-4B0F-45E7-A438-314BA889948E}" = HP MyRoom
"{9E2BCF78-EDAD-A8BC-123D-10E0D9234753}" = CCC Help Chinese Traditional
"{9FEDC691-A307-D525-7D71-EDB97240CFF3}" = CCC Help Chinese Standard
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A8656CC0-6E08-11D4-9A83-00A0CC3530CA}" = BibleWorks 5
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB1F1677-926B-894A-A890-56A3FCD9794B}" = CCC Help Finnish
"{ACC5984D-6859-874C-B939-058DED2692FA}" = CCC Help Portuguese
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}" = CyberLink PowerDirector 10
"{B8019B54-F9BE-490A-9619-6D06F18F129F}" = HP Support Assistant
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Qualcomm Atheros Driver Installation Program
"{C3F3165C-74D3-6FDB-3274-14FDA8698CFA}" = BBRowsE2savve
"{C458E818-0B4F-C961-AFDF-29F172EE5A1B}" = CCC Help Spanish
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D8BC400A-9D14-468B-A674-1D76A987AAFC}" = Windows Migration Assistant
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E175B925-538F-6D69-A9C9-4D0699648752}" = CCC Help Japanese
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E46BF405-4ADF-36F4-A0EA-EF4CDF1A21E6}" = CCC Help Polish
"{E5B7E1B4-21FC-6765-A3D7-BA0416DC6AF7}" = EybooikBBriowsue
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"1ClickDownload" = TornTV
"Adobe Acrobat 4.0" = Adobe Acrobat 4.0
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"avast" = avast! Free Antivirus
"BitTorrent" = BitTorrent
"DefaultTab" = DefaultTab
"Fast Free Converter" = Fast Free Converter
"FLAC" = FLAC 1.2.1b (remove only)
"Google Chrome" = Google Chrome
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 10
"InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8
"InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}" = CyberLink PhotoDirector
"InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}" = CyberLink PowerDirector 10
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD
"Mozilla Firefox 22.0 (x86 en-US)" = Mozilla Firefox 22.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NexGen Media Player" = NexGen Media Player - a modern video player
"Price Check by AOL" = Price Check by AOL
"SoftwareUpdUtility" = Download Updater (AOL Inc.)
"StartHPConnectedMusic" = HP Connected Music (Meridian - installer)
"WildTangent hp Master Uninstall" = HP Games
"WildTangent wildgames Master Uninstall" = WildTangent Games
"WinLiveSuite" = Windows Live Essentials
"WTA-00baa5ad-405b-45be-b76c-f7cd720fb875" = Luxor Evolved
"WTA-11904447-aeec-4a83-bc9a-0e898f7d1ecc" = Peggle Nights
"WTA-22e144ef-0e54-402a-8e8d-7956111917c0" = Final Drive Fury
"WTA-3326af20-4185-4eeb-b21c-f92ae5262cea" = Vacation Quest™ - Australia
"WTA-3ea31c40-7bb6-4539-ad55-6ca8f5d9acda" = Hoyle Card Games
"WTA-40296e69-861f-49aa-9b11-cd74f4c7997b" = 4 Elements II
"WTA-44de53d1-60b4-49cc-a969-ebbbee69e3fd" = Build-a-lot 4 - Power Source
"WTA-7859ed3a-f9bb-4ecc-8fdd-7675c7ff0f44" = Cradle Of Egypt Collector's Edition
"WTA-794cc034-7c97-4213-987e-d1b6b3e25300" = Governor of Poker 2 Premium Edition
"WTA-8666b0aa-9eda-4186-a86b-1edae9863489" = Mahjongg Dimensions Deluxe: Tiles in Time
"WTA-9960e2a1-f3b8-40f4-9140-e33ee8b152c9" = Tales of Lagoona
"WTA-9adf3ca6-8ccd-4d33-bfd4-2d5647d1add2" = Polar Bowler
"WTA-d0c5e141-e286-473c-a8b3-3ba79cd85c1b" = Bejeweled 3
"WTA-d38c2603-dc0d-4600-8c50-85e168a32fc7" = FlatOut 2
"WTA-d5e630e9-50ed-4707-a13f-8248e887cfa1" = Chuzzle Deluxe
"WTA-d5ef4623-f5c8-42c8-b456-8aeee3689251" = Mortimer Beckett and the Crimson Thief Premium Edition
"WTA-d927e1ca-63ba-46e7-972a-4884827bb63f" = Penguins!
"WTA-df6ac5cb-4374-4808-a040-b18d084fa968" = FATE: The Cursed King
"WTA-e2575787-5570-4380-b546-cdd9aaaa8db1" = Roads of Rome 3
"WTA-e69fe33b-6e8c-4143-9ab9-ff76f3ac250e" = Farm Frenzy
"WTA-eba1e600-06dc-47b9-a7d7-342d380f75dc" = John Deere Drive Green
"WTA-f434d5d5-a362-4cb0-adc9-9a50f05c672d" = Cradle of Rome 2
"WTA-f4cb67d4-8bd3-4d85-9eea-c66a889148e1" = Zuma's Revenge
"WTA-f565934b-df5b-4f46-af4d-b4ac943c0e82" = Jewel Match 3
"WTA-fb10edb6-a2cc-42e8-8d78-4ade1313ac3b" = Mystery P.I. - Curious Case of Counterfeit Cove
"WTA-fc1fe18d-b526-49af-a01f-68630df4284d" = Polar Golfer
"Zoombinis Mountain Rescue™" = Zoombinis Mountain Rescue™

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2393212166-3480209652-2217339028-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"DownloadTerms" = DownloadTerms
"Dropbox" = Dropbox
"Spotify" = Spotify

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 6/28/2013 4:46:12 PM | Computer Name = jimcomputer | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2621

Error - 6/28/2013 4:46:13 PM | Computer Name = jimcomputer | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 6/28/2013 4:46:13 PM | Computer Name = jimcomputer | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3869

Error - 6/28/2013 4:46:13 PM | Computer Name = jimcomputer | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3869

Error - 6/28/2013 8:02:21 PM | Computer Name = jimcomputer | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 6/28/2013 8:02:21 PM | Computer Name = jimcomputer | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2153

Error - 6/28/2013 8:02:21 PM | Computer Name = jimcomputer | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2153

Error - 6/28/2013 8:02:23 PM | Computer Name = jimcomputer | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 6/28/2013 8:02:23 PM | Computer Name = jimcomputer | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3916

Error - 6/28/2013 8:02:23 PM | Computer Name = jimcomputer | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3916

[ System Events ]
Error - 6/18/2013 7:45:21 AM | Computer Name = jimcomputer | Source = Service Control Manager | ID = 7030
Description = The FastFreeConverterUpdt service is marked as an interactive service.
However, the system is configured to not allow interactive services. This service
may not function properly.

Error - 6/18/2013 7:47:27 AM | Computer Name = jimcomputer | Source = Service Control Manager | ID = 7030
Description = The DefaultTabSearch service is marked as an interactive service.
However, the system is configured to not allow interactive services. This service
may not function properly.

Error - 6/20/2013 2:33:16 PM | Computer Name = jimcomputer | Source = NetBT | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 192.168.1.2. The computer with the IP address 192.168.1.9 did not
allow the name to be claimed by this computer.

Error - 7/5/2013 8:48:06 AM | Computer Name = jimcomputer | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80246007: Update for Windows 8 for x64-based Systems (KB2821895).

Error - 7/7/2013 8:27:07 AM | Computer Name = jimcomputer | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Computer
Backup (MyPC Backup) service to connect.

Error - 7/7/2013 8:27:07 AM | Computer Name = jimcomputer | Source = Service Control Manager | ID = 7000
Description = The Computer Backup (MyPC Backup) service failed to start due to the
following error: %%1053

Error - 7/7/2013 8:27:26 AM | Computer Name = jimcomputer | Source = Service Control Manager | ID = 7034
Description = The DefaultTabSearch service terminated unexpectedly. It has done
this 1 time(s).

Error - 7/7/2013 8:29:49 AM | Computer Name = jimcomputer | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Computer
Backup (MyPC Backup) service to connect.

Error - 7/7/2013 8:29:49 AM | Computer Name = jimcomputer | Source = Service Control Manager | ID = 7000
Description = The Computer Backup (MyPC Backup) service failed to start due to the
following error: %%1053

Error - 7/7/2013 8:30:00 AM | Computer Name = jimcomputer | Source = Service Control Manager | ID = 7034
Description = The DefaultTabSearch service terminated unexpectedly. It has done
this 1 time(s).


< End of report >
Remove the following programs:

DefaultTab
Fast Free Converter



Please double-click OTL.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :OTL
    IE:64bit: - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o=HPNTDF
    IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o=HPNTDF
    IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…mrud=25-04-2013
    IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o=HPNTDF
    IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/redire…mrud=25-04-2013
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Fast Free Converter
    CHR - Extension: BBRowsE2savve = C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\anokniebcoameopaknmpbhaaoedjajik\1\
    CHR - Extension: EybooikBBriowsue = C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\niieikgjphnahhnnmdheblakpelnfgaj\1\
    O2 - BHO: (DownloadTerms) - {2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3} - C:\Users\JimAngehr\AppData\Local\DownloadTerms
    O2 - BHO: (BBRowsE2savve) - {4FA31CBC-669C-8878-251A-D2DA6ACAE0DF} - C:\ProgramData\BBRowsE2savve
    O2 - BHO: (DefaultTab Browser Helper) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\JimAngehr\AppData\Roaming\DefaultTab\DefaultTab
    O2 - BHO: (Fast Free Converter 4.1) - {B422F1BC-9ADB-48A7-8B13-00C176039DC5} - C:\Program Files (x86)\Fast Free Converter\FastFreeConverter\FastFreeConverter.dll (Fast Free Converter)
    O2 - BHO: (EybooikBBriowsue) - {C178AC1C-9A8B-8FF7-88BA-DB329D96695B} - C:\ProgramData\EybooikBBriowsue
    [2013/07/09 08:04:30 | 000,000,372 | —- | M] () – C:\Windows\tasks\AmiUpdXp.job
    [2013/06/18 07:47:24 | 000,000,258 | RHS- | M] () – C:\Users\JimAngehr\ntuser.pol

    :SERVICES
    DefaultTabUpdate
    DefaultTabSearch
    FastFreeConverterUpdt

    :FILES
    C:\Program Files (x86)\DefaultTab
    C:\Program Files (x86)\File Type Helper
    C:\Users\JimAngehr\AppData\Local\SwvUpdater

    :commands
    [emptytemp]

  • Return to OTL, right click in the "Custom Scans/Fixes" section and choose Paste.
  • Click the red Run Fix button.
  • OTL may ask to reboot the machine. Please do so.
  • If OTL did not reboot the machine, click OK and the log will open. Post the contents of the log in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.

    Also post a new OTL log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI