ad problems in browsers [Solved]
26 min read
OTL logfile created on: 7/10/2013 7:04:27 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\JimAngehr\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.47 Gb Total Physical Memory | 1.71 Gb Available Physical Memory | 49.20% Memory free
6.97 Gb Paging File | 5.10 Gb Available in Paging File | 73.12% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 672.51 Gb Total Space | 493.94 Gb Free Space | 73.45% Space Free | Partition Type: NTFS
Drive D: | 25.36 Gb Total Space | 3.02 Gb Free Space | 11.91% Space Free | Partition Type: NTFS
Computer Name: JIMCOMPUTER | User Name: JimAngehr | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/07/09 09:14:09 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\JimAngehr\Desktop\OTL.exe
PRC - [2013/07/07 09:00:43 | 004,640,768 | —- | M] (Spotify Ltd) – C:\Users\JimAngehr\AppData\Roaming\Spotify\spotify.exe
PRC - [2013/07/07 09:00:35 | 001,104,384 | —- | M] (Spotify Ltd) – C:\Users\JimAngehr\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
PRC - [2013/07/04 14:26:01 | 000,920,472 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2013/06/14 21:28:44 | 000,825,808 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2013/05/24 20:47:30 | 027,776,968 | —- | M] (Dropbox, Inc.) – C:\Users\JimAngehr\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2013/05/09 04:58:30 | 004,858,968 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013/05/09 04:58:30 | 000,046,808 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/07/27 21:21:26 | 000,136,488 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
PRC - [2012/07/09 16:40:02 | 000,580,512 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
PRC - [2012/07/09 16:40:02 | 000,035,232 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
PRC - [2012/06/07 23:34:06 | 000,111,120 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
PRC - [2012/03/28 21:34:30 | 000,091,432 | —- | M] (CyberLink Corp.) – C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
PRC - [2011/08/26 17:37:18 | 001,342,008 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
PRC - [2006/11/02 21:40:12 | 000,174,656 | —- | M] () – C:\Windows\SysWOW64\PSIService.exe
========== Modules (No Company Name) ==========
MOD - [2013/07/07 09:00:36 | 024,985,600 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Spotify\Data\libcef.dll
MOD - [2013/07/04 14:24:58 | 003,285,912 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2013/06/14 21:28:42 | 000,393,168 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppgooglenaclpluginchrome.dll
MOD - [2013/06/14 21:28:41 | 013,140,432 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll
MOD - [2013/06/14 21:28:40 | 004,051,408 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll
MOD - [2013/06/14 21:27:51 | 000,599,504 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\libglesv2.dll
MOD - [2013/06/14 21:27:50 | 000,124,368 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\libegl.dll
MOD - [2013/06/14 21:27:48 | 001,597,392 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ffmpegsumo.dll
MOD - [2013/03/13 16:48:52 | 024,978,944 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Dropbox\bin\libcef.dll
MOD - [2012/11/13 19:32:50 | 003,558,400 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
MOD - [2012/06/08 14:34:06 | 000,016,400 | —- | M] () – C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
MOD - [2012/06/07 23:34:06 | 000,627,216 | —- | M] () – C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
MOD - [2012/02/20 21:29:04 | 000,087,912 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/02/20 21:28:42 | 001,242,472 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
========== Services (SafeList) ==========
SRV:64bit: - [2013/05/09 04:58:30 | 000,046,808 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\AVAST Software\Avast\AvastSvc.exe – (avast! Antivirus)
SRV:64bit: - [2013/05/04 02:58:02 | 000,470,528 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\netprofmsvc.dll – (netprofm)
SRV:64bit: - [2013/05/04 02:57:05 | 000,179,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\bisrv.dll – (BrokerInfrastructure)
SRV:64bit: - [2013/04/09 00:48:42 | 000,169,472 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\AudioEndpointBuilder.dll – (AudioEndpointBuilder)
SRV:64bit: - [2013/03/01 22:45:07 | 000,171,008 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\TimeBrokerServer.dll – (TimeBroker)
SRV:64bit: - [2013/03/01 22:45:05 | 000,180,224 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\SystemEventsBrokerServer.dll – (SystemEventsBroker)
SRV:64bit: - [2013/01/28 21:57:14 | 000,014,920 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MsMpEng.exe – (WinDefend)
SRV:64bit: - [2013/01/09 19:23:16 | 001,964,544 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wlidsvc.dll – (wlidsvc)
SRV:64bit: - [2013/01/09 19:22:35 | 000,438,272 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\lsm.dll – (LSM)
SRV:64bit: - [2012/11/06 00:36:55 | 002,675,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll – (PrintNotify)
SRV:64bit: - [2012/09/20 05:10:47 | 002,367,528 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\WSService.dll – (WSService)
SRV:64bit: - [2012/09/20 02:31:18 | 000,116,736 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\fhsvc.dll – (fhsvc)
SRV:64bit: - [2012/08/23 10:45:42 | 000,029,600 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Windows\SysNative\hpservice.exe – (hpsrv)
SRV:64bit: - [2012/08/09 02:45:58 | 000,239,616 | —- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2012/08/08 13:36:06 | 000,361,984 | —- | M] (Advanced Micro Devices, Inc.) [Auto | Running] – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe – (AMD FUEL Service)
SRV:64bit: - [2012/07/25 23:07:47 | 000,065,536 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wiarpc.dll – (WiaRpc)
SRV:64bit: - [2012/07/25 23:07:42 | 000,263,680 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wcmsvc.dll – (Wcmsvc)
SRV:64bit: - [2012/07/25 23:07:40 | 000,283,648 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\vaultsvc.dll – (VaultSvc)
SRV:64bit: - [2012/07/25 23:07:25 | 000,012,800 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\svsvc.dll – (svsvc)
SRV:64bit: - [2012/07/25 23:06:34 | 000,743,936 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\netlogon.dll – (Netlogon)
SRV:64bit: - [2012/07/25 23:06:33 | 000,161,792 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\NcaSvc.dll – (NcaSvc)
SRV:64bit: - [2012/07/25 23:06:33 | 000,073,728 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\NcdAutoSetup.dll – (NcdAutoSetup)
SRV:64bit: - [2012/07/25 23:05:55 | 000,059,904 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\keyiso.dll – (KeyIso)
SRV:64bit: - [2012/07/25 23:05:34 | 000,037,376 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\efssvc.dll – (EFS)
SRV:64bit: - [2012/07/25 23:05:28 | 000,207,872 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\DeviceSetupManager.dll – (DsmSvc)
SRV:64bit: - [2012/07/25 23:05:24 | 000,342,016 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\das.dll – (DeviceAssociationService)
SRV:64bit: - [2012/07/25 23:05:08 | 000,122,368 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\AUInstallAgent.dll – (AllUserInstallAgent)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmicvss)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmictimesync)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmicshutdown)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmicrdv)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmickvpexchange)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmicheartbeat)
SRV:64bit: - [2012/07/21 12:30:36 | 000,321,536 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Program Files\IDT\WDM\stacsv64.exe – (STacSV)
SRV:64bit: - [2010/04/14 20:56:24 | 001,052,328 | —- | M] ( ) [Auto | Running] – C:\Windows\SysNative\lxebcoms.exe – (lxeb_device)
SRV - [2013/07/04 14:25:59 | 000,117,144 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2013/06/23 09:02:05 | 000,256,904 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2013/05/31 07:19:28 | 000,032,808 | —- | M] (Just Develop It) [Auto | Stopped] – C:\Program Files (x86)\MyPC Backup\BackupStack.exe – (BackupStack)
SRV - [2012/11/06 00:36:55 | 002,675,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll – (PrintNotify)
SRV - [2012/08/10 20:53:44 | 000,085,504 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe – (HP Support Assistant Service)
SRV - [2012/07/25 23:20:04 | 000,018,432 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\StorSvc.dll – (StorSvc)
SRV - [2012/07/25 23:18:41 | 000,408,064 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\inetsrv\iisw3adm.dll – (WAS)
SRV - [2012/07/25 23:17:52 | 000,060,416 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\inetsrv\apphostsvc.dll – (AppHostSvc)
SRV - [2012/07/13 21:02:16 | 002,451,456 | —- | M] (Realsil Microelectronics Inc.) [Auto | Running] – C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe – (IconMan_R)
SRV - [2012/07/09 16:40:02 | 000,035,232 | —- | M] (Hewlett-Packard Development Company, L.P.) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe – (HPWMISVC)
SRV - [2010/10/12 13:59:12 | 000,206,072 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe – (GamesAppService)
SRV - [2006/11/02 21:40:12 | 000,174,656 | —- | M] () [Auto | Running] – C:\Windows\SysWOW64\PSIService.exe – (ProtexisLicensing)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2013/07/07 18:56:36 | 001,030,952 | —- | M] (AVAST Software) [File_System | System | Running] – C:\Windows\SysNative\drivers\aswSnx.sys – (aswSnx)
DRV:64bit: - [2013/07/07 18:56:36 | 000,378,944 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswSP.sys – (aswSP)
DRV:64bit: - [2013/07/07 18:56:36 | 000,189,936 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswVmm.sys – (aswVmm)
DRV:64bit: - [2013/05/09 04:59:07 | 000,072,016 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\aswRdr2.sys – (aswRdr)
DRV:64bit: - [2013/05/09 04:59:07 | 000,065,336 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswRvrt.sys – (aswRvrt)
DRV:64bit: - [2013/05/09 04:59:07 | 000,064,288 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswTdi.sys – (aswTdi)
DRV:64bit: - [2013/05/09 04:59:06 | 000,080,816 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\Drivers\aswMonFlt.sys – (aswMonFlt)
DRV:64bit: - [2013/05/09 04:59:06 | 000,033,400 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswFsBlk.sys – (aswFsBlk)
DRV:64bit: - [2013/05/04 03:34:17 | 000,446,720 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\USBHUB3.SYS – (USBHUB3)
DRV:64bit: - [2013/05/04 03:34:17 | 000,213,248 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\UCX01000.SYS – (UCX01000)
DRV:64bit: - [2013/05/04 03:34:15 | 000,284,416 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\spaceport.sys – (spaceport)
DRV:64bit: - [2013/03/02 06:57:48 | 000,337,128 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\USBXHCI.SYS – (USBXHCI)
DRV:64bit: - [2013/03/02 06:57:46 | 000,077,544 | —- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\storahci.sys – (storahci)
DRV:64bit: - [2013/03/02 06:45:20 | 000,148,712 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\tpm.sys – (TPM)
DRV:64bit: - [2013/03/02 06:45:19 | 000,194,792 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\sdbus.sys – (sdbus)
DRV:64bit: - [2013/03/02 06:39:38 | 000,069,864 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\pdc.sys – (pdc)
DRV:64bit: - [2013/02/02 03:25:23 | 000,037,632 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\BthAvrcpTg.sys – (BthAvrcpTg)
DRV:64bit: - [2013/01/28 21:57:05 | 000,035,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\WdBoot.sys – (WdBoot)
DRV:64bit: - [2013/01/28 19:08:22 | 000,230,904 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\WdFilter.sys – (WdFilter)
DRV:64bit: - [2013/01/09 21:53:32 | 000,028,904 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\msgpiowin32.sys – (msgpiowin32)
DRV:64bit: - [2012/11/26 23:55:44 | 000,029,952 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\BthhfHid.sys – (bthhfhid)
DRV:64bit: - [2012/11/20 00:54:31 | 000,039,936 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\hidi2c.sys – (hidi2c)
DRV:64bit: - [2012/11/05 23:55:44 | 000,022,528 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\fxppm.sys – (FxPPM)
DRV:64bit: - [2012/10/12 04:08:01 | 000,027,880 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\rdpvideominiport.sys – (RdpVideoMiniport)
DRV:64bit: - [2012/10/11 03:25:48 | 000,056,552 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\sdstor.sys – (sdstor)
DRV:64bit: - [2012/10/11 03:13:49 | 000,058,088 | —- | M] (Microsoft Corporation) [Kernel | System | Stopped] – C:\Windows\SysNative\Drivers\dam.sys – (dam)
DRV:64bit: - [2012/09/28 11:32:56 | 000,053,760 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2012/09/20 03:55:30 | 000,120,040 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\msgpioclx.sys – (GPIOClx0101)
DRV:64bit: - [2012/09/20 03:55:27 | 003,265,256 | —- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2012/09/20 03:55:24 | 000,533,224 | —- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2012/08/31 10:40:24 | 000,020,800 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\WirelessButtonDriver64.sys – (WirelessButtonDriver)
DRV:64bit: - [2012/08/24 05:38:28 | 000,448,312 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2012/08/24 05:38:28 | 000,043,832 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\Smb_driver_Intel.sys – (SmbDrvI)
DRV:64bit: - [2012/08/24 05:38:26 | 000,041,272 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\Smb_driver_AMDASF.sys – (SmbDrv)
DRV:64bit: - [2012/08/23 10:45:42 | 000,042,400 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\Accelerometer.sys – (Accelerometer)
DRV:64bit: - [2012/08/23 10:45:42 | 000,029,600 | —- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\hpdskflt.sys – (hpdskflt)
DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2012/08/09 04:03:32 | 010,283,520 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\atikmdag.sys – (amdkmdag)
DRV:64bit: - [2012/08/09 01:48:20 | 000,368,640 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2012/07/31 15:22:00 | 000,645,952 | —- | M] (Intel Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\iaStorA.sys – (iaStorA)
DRV:64bit: - [2012/07/31 04:04:12 | 000,690,832 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\Rt630x64.sys – (RTL8168)
DRV:64bit: - [2012/07/26 01:26:46 | 000,025,328 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2012/07/26 01:26:45 | 000,033,792 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\condrv.sys – (condrv)
DRV:64bit: - [2012/07/26 01:00:58 | 000,322,800 | —- | M] (VIA Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\VSTXRAID.SYS – (VSTXRAID)
DRV:64bit: - [2012/07/26 01:00:58 | 000,106,224 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\VerifierExt.sys – (VerifierExt)
DRV:64bit: - [2012/07/26 01:00:58 | 000,097,008 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\uaspstor.sys – (UASPStor)
DRV:64bit: - [2012/07/26 01:00:57 | 000,077,040 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\acpiex.sys – (acpiex)
DRV:64bit: - [2012/07/26 01:00:55 | 000,064,240 | —- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\mvumis.sys – (mvumis)
DRV:64bit: - [2012/07/26 01:00:55 | 000,030,960 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2012/07/26 01:00:52 | 000,092,400 | —- | M] (LSI Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2012/07/26 01:00:52 | 000,081,136 | —- | M] (LSI Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\lsi_sss.sys – (LSI_SSS)
DRV:64bit: - [2012/07/26 01:00:52 | 000,064,752 | —- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2012/07/26 01:00:51 | 000,113,904 | —- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys – (EhStorTcgDrv)
DRV:64bit: - [2012/07/26 01:00:51 | 000,081,136 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\EhStorClass.sys – (EhStorClass)
DRV:64bit: - [2012/07/26 01:00:49 | 000,258,288 | —- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2012/07/26 01:00:49 | 000,106,736 | —- | M] (LSI) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\3ware.sys – (3ware)
DRV:64bit: - [2012/07/26 01:00:49 | 000,076,016 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2012/07/26 01:00:48 | 000,026,352 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2012/07/26 00:57:54 | 000,361,200 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\clfs.sys – (CLFS)
DRV:64bit: - [2012/07/26 00:54:34 | 000,096,496 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\wfplwfs.sys – (WFPLWFS)
DRV:64bit: - [2012/07/26 00:53:16 | 000,067,824 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\vpci.sys – (vpci)
DRV:64bit: - [2012/07/25 23:17:38 | 000,036,592 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\terminpt.sys – (terminpt)
DRV:64bit: - [2012/07/25 22:29:47 | 000,021,504 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\WSDPrint.sys – (WSDPrintDevice)
DRV:64bit: - [2012/07/25 22:29:14 | 000,010,752 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\mshidumdf.sys – (mshidumdf)
DRV:64bit: - [2012/07/25 22:29:08 | 000,048,640 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\BasicDisplay.sys – (BasicDisplay)
DRV:64bit: - [2012/07/25 22:29:03 | 000,024,576 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\HyperVideo.sys – (HyperVideo)
DRV:64bit: - [2012/07/25 22:28:52 | 000,029,696 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\BasicRender.sys – (BasicRender)
DRV:64bit: - [2012/07/25 22:27:58 | 000,012,288 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\vmgencounter.sys – (gencounter)
DRV:64bit: - [2012/07/25 22:27:41 | 000,018,432 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\kdnic.sys – (kdnic)
DRV:64bit: - [2012/07/25 22:27:37 | 000,010,752 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\acpitime.sys – (acpitime)
DRV:64bit: - [2012/07/25 22:27:33 | 000,023,552 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\npsvctrig.sys – (npsvctrig)
DRV:64bit: - [2012/07/25 22:27:29 | 000,019,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\WpdUpFltr.sys – (WpdUpFltr)
DRV:64bit: - [2012/07/25 22:27:16 | 000,010,240 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\acpipagr.sys – (acpipagr)
DRV:64bit: - [2012/07/25 22:27:01 | 000,011,776 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\hyperkbd.sys – (hyperkbd)
DRV:64bit: - [2012/07/25 22:26:46 | 000,062,976 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\SerCx.sys – (SerCx)
DRV:64bit: - [2012/07/25 22:26:43 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\SpbCx.sys – (SpbCx)
DRV:64bit: - [2012/07/25 22:26:34 | 000,030,208 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2012/07/25 22:26:13 | 000,051,200 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\bthhfenum.sys – (BthHFEnum)
DRV:64bit: - [2012/07/25 22:25:57 | 000,033,280 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\dmvsc.sys – (dmvsc)
DRV:64bit: - [2012/07/25 22:25:56 | 000,057,344 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2012/07/25 22:25:13 | 000,045,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\wpcfltr.sys – (wpcfltr)
DRV:64bit: - [2012/07/25 22:25:01 | 000,126,464 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\NdisImPlatform.sys – (NdisImPlatform)
DRV:64bit: - [2012/07/25 22:23:53 | 000,068,608 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\mslldp.sys – (MsLldp)
DRV:64bit: - [2012/07/25 22:23:42 | 000,097,792 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\Windows\SysNative\Drivers\Ndu.sys – (Ndu)
DRV:64bit: - [2012/07/24 11:44:02 | 003,618,304 | —- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\athw8x.sys – (athr)
DRV:64bit: - [2012/07/24 05:35:12 | 000,079,528 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\amd_sata.sys – (amd_sata)
DRV:64bit: - [2012/07/24 05:35:12 | 000,026,280 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\amd_xata.sys – (amd_xata)
DRV:64bit: - [2012/07/21 12:30:36 | 000,540,160 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\stwrt64.sys – (STHDA)
DRV:64bit: - [2012/07/18 00:59:12 | 000,098,472 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\AtihdW86.sys – (AtiHDAudioService)
DRV:64bit: - [2012/07/03 18:09:08 | 000,269,968 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\RtsP2Stor.sys – (RSP2STOR)
DRV:64bit: - [2012/06/25 13:24:50 | 000,092,536 | —- | M] (CyberLink) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\CLVirtualDrive.sys – (CLVirtualDrive)
DRV:64bit: - [2012/06/23 09:23:38 | 000,199,008 | —- | M] (AppEx Networks Corporation) [Kernel | Auto | Running] – C:\Windows\SysNative\Drivers\appexDrv.sys – (APXACC)
DRV:64bit: - [2012/06/19 10:07:50 | 000,057,000 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\usbfilter.sys – (usbfilter)
DRV:64bit: - [2012/06/02 10:32:26 | 010,627,744 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\igdkmd64.sys – (igfx)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT13/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;pc=HPNTDFJS
IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{F05749BB-0626-4108-9BA0-E2C7F7D1B555}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT13/1
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;pc=HPNTDFJS
IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}
IE - HKLM\..\SearchScopes\{F05749BB-0626-4108-9BA0-E2C7F7D1B555}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;pc=HPNTDFJS
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes\{F05749BB-0626-4108-9BA0-E2C7F7D1B555}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Google"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://search.aol.com/search/search?q={searchTerms}&s;_it=webpickaol-ff&s;_qt=sb&tb;_uuid=D1E32A0EB1E84CB199BF9D10246EAD1B&tb;_oid=25-04-2013&tb;_mrud=26-04-2013"
FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:8.0.1489
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:22.0
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe;=utf-8&q;="
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013/07/07 18:56:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/07/04 14:24:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/07/04 14:24:40 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/07/04 14:24:39 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/07/04 14:24:40 | 000,000,000 | —D | M]
[2012/11/01 21:44:34 | 000,000,000 | —D | M] (No name found) – C:\Users\JimAngehr\AppData\Roaming\Mozilla\Extensions
[2013/07/07 19:12:25 | 000,000,000 | —D | M] (No name found) – C:\Users\JimAngehr\AppData\Roaming\Mozilla\Firefox\Profiles\7zcy930i.default\extensions
[2013/07/07 19:05:10 | 000,002,552 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Mozilla\Firefox\Profiles\7zcy930i.default\searchplugins\aol-search.xml
[2013/07/07 09:01:43 | 000,001,988 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Mozilla\Firefox\Profiles\7zcy930i.default\searchplugins\search.xml
[2013/07/04 14:24:39 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013/07/04 14:26:02 | 000,000,000 | —D | M] (Default) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/07/07 18:56:00 | 000,000,000 | —D | M] (avast! Online Security) – C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll
CHR - plugin: Norton Identity Safe (Enabled) = C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.2.0.18_0\npcoplgn.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - Extension: YouTube = C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Gmail = C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2012/07/26 01:26:49 | 000,000,824 | —- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
O2:64bit: - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
O3:64bit: - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CLVirtualDrive] C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QuickFinder Scheduler] C:\Program Files (x86)\WordPerfect Office X3\Programs\QFSCHD130.EXE (Corel Corporation)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004..\Run: [Spotify] C:\Users\JimAngehr\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004..\Run: [Spotify Web Helper] C:\Users\JimAngehr\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - Startup: C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\JimAngehr\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk = C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Open with WordPerfect - C:\Program Files (x86)\WordPerfect Office X3\Programs\WPLauncher.hta ()
O8 - Extra context menu item: Open with WordPerfect - C:\Program Files (x86)\WordPerfect Office X3\Programs\WPLauncher.hta ()
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3C6BDB04-E01A-40C1-AD9D-37A8A0EE53D6}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/07/10 18:00:46 | 000,595,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qedit.dll
[2013/07/10 18:00:45 | 000,496,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qedit.dll
[2013/07/10 18:00:37 | 001,838,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/07/10 18:00:36 | 002,842,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/07/10 18:00:36 | 002,620,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/07/10 18:00:01 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/07/10 17:59:55 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/07/10 17:59:54 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/07/10 17:59:53 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/07/10 17:59:53 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/07/10 17:53:56 | 000,000,000 | —D | C] – C:\_OTL
[2013/07/09 09:14:08 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\JimAngehr\Desktop\OTL.exe
[2013/07/08 16:17:27 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/07/08 16:16:49 | 000,000,000 | —D | C] – C:\Users\JimAngehr\Desktop\mbar-1.06.0.1004
[2013/07/08 14:54:34 | 000,688,992 | R— | C] (Swearware) – C:\Users\JimAngehr\Desktop\dds(1).scr
[2013/07/07 18:56:32 | 000,378,944 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2013/07/07 18:56:32 | 000,072,016 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr2.sys
[2013/07/07 18:56:32 | 000,064,288 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2013/07/07 18:56:32 | 000,033,400 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2013/07/07 18:56:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2013/07/07 18:56:18 | 001,030,952 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2013/07/07 18:56:18 | 000,080,816 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2013/07/07 18:55:43 | 000,041,664 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2013/07/04 14:24:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/07/04 07:43:26 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tssdisai.dll
[2013/06/23 09:01:20 | 000,000,000 | —D | C] – C:\Users\JimAngehr\AppData\Local\Adobe
[2013/06/18 07:47:13 | 000,000,000 | —D | C] – C:\Users\JimAngehr\AppData\Roaming\DefaultTab
[2013/06/18 07:47:05 | 000,000,000 | —D | C] – C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NexGen Media Player
[2013/06/18 07:46:46 | 000,000,000 | —D | C] – C:\Users\JimAngehr\AppData\Local\NexGenMediaPlayer
[2013/06/18 07:46:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\NexGen Media Player
[2013/06/18 07:46:43 | 000,000,000 | —D | C] – C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
[2013/06/18 07:46:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\MyPC Backup
[2013/06/16 09:11:00 | 001,257,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2013/06/16 09:10:58 | 001,300,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\gdi32.dll
[2013/06/16 09:10:55 | 000,888,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\autochk.exe
[2013/06/16 09:10:55 | 000,793,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\autochk.exe
[2013/06/16 09:10:55 | 000,542,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\untfs.dll
[2013/06/16 09:10:55 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\untfs.dll
[2013/06/15 08:18:24 | 013,644,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Windows.UI.Xaml.dll
[2013/06/15 08:18:21 | 010,788,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Windows.UI.Xaml.dll
[2013/06/15 08:18:19 | 001,131,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AppXDeploymentServer.dll
[2013/06/15 08:18:18 | 010,116,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\twinui.dll
[2013/06/15 08:18:14 | 000,470,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netprofmsvc.dll
[2013/06/15 08:18:13 | 008,857,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\twinui.dll
[2013/06/15 08:18:13 | 002,305,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\authui.dll
[2013/06/15 08:18:12 | 002,035,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\authui.dll
[2013/06/15 08:18:12 | 000,760,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2013/06/15 08:18:11 | 000,446,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\USBHUB3.SYS
[2013/06/15 08:18:11 | 000,328,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ubpm.dll
[2013/06/15 08:18:11 | 000,014,848 | —- | C] (Microsoft) – C:\Windows\SysWow64\rars.rs
[2013/06/15 08:18:11 | 000,014,848 | —- | C] (Microsoft) – C:\Windows\SysNative\rars.rs
[2013/06/15 08:18:10 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\BCP47Langs.dll
[2013/06/15 08:18:10 | 000,330,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\stobject.dll
[2013/06/15 08:18:10 | 000,247,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ubpm.dll
[2013/06/15 08:18:09 | 000,708,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AppXDeploymentExtensions.dll
[2013/06/15 08:18:09 | 000,621,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuapi.dll
[2013/06/15 08:18:08 | 000,812,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Magnify.exe
[2013/06/15 08:18:08 | 000,213,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\UCX01000.SYS
[2013/06/15 08:18:08 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netplwiz.dll
[2013/06/15 08:18:08 | 000,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psmsrv.dll
[2013/06/15 08:18:07 | 000,560,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfmp4srcsnk.dll
[2013/06/15 08:18:07 | 000,151,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netplwiz.dll
[2013/06/15 08:18:06 | 000,501,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DevicePairing.dll
[2013/06/15 08:18:06 | 000,284,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\spaceport.sys
[2013/06/15 08:18:06 | 000,058,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2013/06/15 08:18:05 | 000,758,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Magnify.exe
[2013/06/15 08:18:05 | 000,419,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\intl.cpl
[2013/06/15 08:18:05 | 000,120,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AuthHost.exe
[2013/06/15 08:18:04 | 001,619,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2013/06/15 08:18:04 | 000,449,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\DevicePairing.dll
[2013/06/15 08:18:04 | 000,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\hidclass.sys
[2013/06/15 08:18:03 | 000,251,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUSettingsProvider.dll
[2013/06/15 08:18:03 | 000,122,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\biwinrt.dll
[2013/06/15 08:18:03 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\biwinrt.dll
[2013/06/15 08:18:02 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\intl.cpl
[2013/06/15 08:18:02 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\bisrv.dll
[2013/06/15 08:18:01 | 000,411,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfmp4srcsnk.dll
[2013/06/15 08:18:01 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\storewuauth.dll
[2013/06/15 08:18:01 | 000,141,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2013/06/15 08:18:01 | 000,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuwebv.dll
[2013/06/15 08:18:01 | 000,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2013/06/15 08:18:00 | 000,309,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\BCP47Langs.dll
[2013/06/15 08:18:00 | 000,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wudriver.dll
[2013/06/15 08:18:00 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2013/06/15 08:17:59 | 000,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\muifontsetup.dll
[2013/06/15 08:17:58 | 000,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuapp.exe
[2013/06/15 08:17:58 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\muifontsetup.dll
[2013/06/12 07:10:25 | 001,889,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/06/12 07:10:24 | 001,255,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certutil.exe
[2013/06/12 07:10:24 | 001,013,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certutil.exe
[2013/06/12 07:10:24 | 000,141,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2013/06/12 07:10:21 | 000,733,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/06/12 07:10:19 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptdlg.dll
[2013/06/12 07:10:19 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cryptdlg.dll
[2013/06/12 07:09:30 | 000,915,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\uxtheme.dll
[2013/06/12 07:09:27 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UXInit.dll
[2013/06/12 07:09:27 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UXInit.dll
========== Files - Modified Within 30 Days ==========
[2013/07/10 19:05:00 | 000,000,928 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/10 18:50:07 | 001,573,780 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/07/10 18:50:07 | 000,412,798 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/07/10 18:50:07 | 000,006,364 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/07/10 18:46:29 | 000,000,924 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/10 18:43:56 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/07/10 18:41:22 | 268,435,456 | -HS- | M] () – C:\swapfile.sys
[2013/07/10 18:41:21 | 2981,527,552 | -HS- | M] () – C:\hiberfil.sys
[2013/07/10 18:35:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/07/09 09:14:09 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\JimAngehr\Desktop\OTL.exe
[2013/07/08 16:16:15 | 013,399,154 | —- | M] () – C:\Users\JimAngehr\Desktop\mbar-1.06.0.1004.zip
[2013/07/08 15:21:46 | 551,744,019 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/07/08 14:59:34 | 000,377,856 | —- | M] () – C:\Users\JimAngehr\Desktop\glnzpoxp.exe
[2013/07/08 14:54:35 | 000,688,992 | R— | M] (Swearware) – C:\Users\JimAngehr\Desktop\dds(1).scr
[2013/07/07 18:56:37 | 000,000,175 | —- | M] () – C:\Windows\SysNative\drivers\aswVmm.sys.sum
[2013/07/07 18:56:36 | 001,030,952 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2013/07/07 18:56:36 | 000,378,944 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2013/07/07 18:56:36 | 000,189,936 | —- | M] () – C:\Windows\SysNative\drivers\aswVmm.sys
[2013/07/07 18:56:36 | 000,000,175 | —- | M] () – C:\Windows\SysNative\drivers\aswSP.sys.sum
[2013/07/07 18:56:36 | 000,000,175 | —- | M] () – C:\Windows\SysNative\drivers\aswSnx.sys.sum
[2013/07/07 18:56:33 | 000,001,922 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/07/07 18:56:18 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2013/07/07 08:26:35 | 000,000,372 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForJimAngehr.job
[2013/06/27 18:04:51 | 000,693,112 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/06/27 18:04:51 | 000,078,200 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/06/21 22:39:11 | 000,001,092 | —- | M] () – C:\Users\JimAngehr\Desktop\Continue Vid-Saver Installation.lnk
[2013/06/18 07:47:05 | 000,001,080 | —- | M] () – C:\Users\JimAngehr\Desktop\NexGen Media Player.lnk
[2013/06/18 07:46:44 | 000,001,101 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
[2013/06/18 07:46:44 | 000,001,091 | —- | M] () – C:\Users\JimAngehr\Desktop\MyPC Backup.lnk
[2013/06/18 07:45:40 | 000,000,002 | —- | M] () – C:\END
[2013/06/15 08:56:55 | 000,001,056 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/06/15 08:56:19 | 000,001,032 | —- | M] () – C:\Users\JimAngehr\Desktop\Dropbox.lnk
[2013/06/11 19:43:00 | 000,690,688 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/06/11 19:26:36 | 000,051,712 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/06/11 19:25:29 | 000,603,136 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/06/11 19:25:16 | 003,958,784 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/06/11 19:25:16 | 000,855,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
========== Files Created - No Company Name ==========
[2013/07/08 16:16:12 | 013,399,154 | —- | C] () – C:\Users\JimAngehr\Desktop\mbar-1.06.0.1004.zip
[2013/07/08 14:59:33 | 000,377,856 | —- | C] () – C:\Users\JimAngehr\Desktop\glnzpoxp.exe
[2013/07/07 18:56:37 | 000,000,175 | —- | C] () – C:\Windows\SysNative\drivers\aswVmm.sys.sum
[2013/07/07 18:56:37 | 000,000,175 | —- | C] () – C:\Windows\SysNative\drivers\aswSP.sys.sum
[2013/07/07 18:56:37 | 000,000,175 | —- | C] () – C:\Windows\SysNative\drivers\aswSnx.sys.sum
[2013/07/07 18:56:33 | 000,001,922 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/07/07 18:56:18 | 000,189,936 | —- | C] () – C:\Windows\SysNative\drivers\aswVmm.sys
[2013/07/07 18:56:18 | 000,065,336 | —- | C] () – C:\Windows\SysNative\drivers\aswRvrt.sys
[2013/06/21 22:39:11 | 000,001,092 | —- | C] () – C:\Users\JimAngehr\Desktop\Continue Vid-Saver Installation.lnk
[2013/06/18 07:47:05 | 000,001,080 | —- | C] () – C:\Users\JimAngehr\Desktop\NexGen Media Player.lnk
[2013/06/18 07:46:44 | 000,001,101 | —- | C] () – C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
[2013/06/18 07:46:44 | 000,001,091 | —- | C] () – C:\Users\JimAngehr\Desktop\MyPC Backup.lnk
[2013/06/18 07:45:39 | 000,000,002 | —- | C] () – C:\END
[2013/06/15 08:17:58 | 000,386,646 | —- | C] () – C:\Windows\SysNative\ApnDatabase.xml
[2013/04/01 13:01:32 | 000,000,000 | —- | C] () – C:\Windows\setup32.INI
[2013/01/09 10:33:21 | 000,200,704 | —- | C] () – C:\Windows\SysWow64\Bwbits50.dll
[2013/01/09 10:33:21 | 000,181,760 | —- | C] () – C:\Windows\SysWow64\patchw32.dll
[2013/01/09 10:33:21 | 000,116,736 | —- | C] () – C:\Windows\SysWow64\patchw.dll
[2013/01/09 10:33:21 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\bwplay.exe
[2013/01/09 10:33:21 | 000,053,760 | —- | C] () – C:\Windows\SysWow64\zlib.dll
[2013/01/09 10:33:21 | 000,020,992 | —- | C] () – C:\Windows\SysWow64\bwntsend.dll
[2013/01/09 10:33:21 | 000,016,896 | —- | C] () – C:\Windows\SysWow64\bwnthook.dll
[2012/11/07 13:02:13 | 000,001,056 | -HS- | C] () – C:\Windows\SysWow64\KGyGaAvL.sys
[2012/11/04 15:22:24 | 000,083,968 | —- | C] () – C:\Windows\SysWow64\OEMLicense.dll
[2012/08/16 23:46:43 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2012/08/09 02:10:22 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2012/08/09 02:10:22 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2012/08/03 18:40:09 | 000,916,510 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/07/26 04:13:10 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2012/07/26 04:13:09 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2012/07/26 03:21:26 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2012/07/25 21:17:42 | 000,043,520 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2012/07/25 16:37:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2012/07/25 16:28:31 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2012/07/25 16:22:54 | 000,982,240 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2012/07/25 16:22:54 | 000,439,308 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2012/07/25 16:22:54 | 000,092,356 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2012/06/02 10:31:19 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2012/05/10 19:35:16 | 000,029,184 | —- | C] () – C:\Windows\SysWow64\kdbsdk32.dll
[2011/09/13 10:06:16 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
========== ZeroAccess Check ==========
[2012/08/17 00:03:34 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/03/06 02:31:28 | 019,758,592 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/03/06 01:03:37 | 017,561,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2012/07/25 23:05:38 | 001,004,544 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2012/07/25 23:18:27 | 000,784,896 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2012/07/25 23:07:41 | 000,455,680 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
< End of report >
Combofix should only be run when adviced by a team member!
Link
Important - Save the file to your desktop!
- Deactivate any and all of your antivirus programs /spyware scanners - they can prevent CF from doing its work.
- Run Combofix.exe
When finished, Combofix creates a log file named C:\Combofix.txt. Please post its content in your next reply.
Note: When receiving an error message containing ""Illegal operation attempted on a registry key that has been marked for deletion" simply restart your computer to fix this.
Click on start–>control panel.
Vista/7: Open Programs and Features
XP: Open add/remove programs
Search for and remove the following programs
MyPC Backup
DefaultTab
NexGen Media Player
Close the window.
Run combofix again and post up the log.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Download the attached CFScript.txt and save it to the location where Combofix is.
[external image: Posted Image]
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Please go to here to run the online scannner from ESET.
- Turn off the real time scanner of any existing antivirus program while performing the online scan
- Tick the box next to YES, I accept the Terms of Use.
- Click Start
- When asked, allow the activex control to install
- Click Start
- Make sure that the option Remove found threats is unticked
- Click on Advanced Settings and ensure these options are ticked:
- Scan for potentially unwanted applications
- Scan for potentially unsafe applications
- Enable Anti-Stealth Technology
- Click Scan
- Wait for the scan to finish
- If any threats were found, click the 'List of found threats' , then click Export to text file….
- Save it to your desktop, then please copy and paste that log as a reply to this topic.
- Hit the Windows- and the R-key simultanously..
- Copy the following command into the text field:
- C:\Qoobox\Add-Remove Programs.txt
- Hit OK.
- A textfile will open, please post up its content.
Click on start–>control panel.
Vista/7: Open Programs and Features
XP: Open add/remove programs
Search for and remove the following programs
BBRowsE2savve
EybooikBBriowsue
Price Check by AOL
swMSM
TornTV
Close the window.
Fix with OTL
Please double-click OTL.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
- Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
:FILES
C:\Program Files (x86)\TornTV.com
C:\Program Files (x86)\Yontoo
C:\ProgramData\Tarma Installer\{68F250EA-9638-4DCF-96C4-D68CC340EC48}
C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
C:\Users\All Users\Tarma Installer\{68F250EA-9638-4DCF-96C4-D68CC340EC48}
C:\Users\All Users\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0
C:\Users\JimAngehr\Downloads\Firefox_Setup.exe
C:\Users\JimAngehr\Downloads\GoogleChromeExtensionUpdate_m5.exe
C:\Users\JimAngehr\Downloads\GoogleChromeExtensionUpdate_m6.exe
C:\Users\JimAngehr\Downloads\JazzPlanet)Miles_Davis-The_Complete_Live_at_the_Plugged_Nickel_19658CD_UF_SPG (1).exe
C:\Users\JimAngehr\Downloads\JazzPlanet)Miles_Davis-The_Complete_Live_at_the_Plugged_Nickel_19658CD_UF_SPG.exe
C:\Users\JimAngehr\Downloads\Miles_Davis_-_Complete_at_the_Plugged_Nickel_(8CD)_(1995).exe
C:\Windows\WinSxS\amd64_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.2.9200.20521_none_2ea2287def6db600\sdbinst.exe
:commands
[emptytemp] - Return to OTL, right click in the "Custom Scans/Fixes" section and choose Paste.
- Click the red Run Fix button.
- OTL may ask to reboot the machine. Please do so.
- If OTL did not reboot the machine, click OK and the log will open. Post the contents of the log in your next reply.
- If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
Also post a new OTL log.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI