This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ad problems in browsers [Solved]

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

It did reboot, but after I rebooted and opened firefox, the same popup as usual came up. All processes killed ========== OTL ========== 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}\ not found. Registry key HKEY_USERS\S-1-5-21-2393212166-3480209652-2217339028-1004\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}\ not found. Registry key HKEY_USERS\S-1-5-21-2393212166-3480209652-2217339028-1004\Software\Microsoft\Internet Explorer\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}\ not found. Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed] deleted successfully. C:\Program Files (x86)\Fast Free Converter\FastFreeConverter\[removed]\defaults\preferences folder moved successfully. C:\Program Files (x86)\Fast Free Converter\FastFreeConverter\[removed]\defaults folder moved successfully. C:\Program Files (x86)\Fast Free Converter\FastFreeConverter\[removed]\content folder moved successfully. C:\Program Files (x86)\Fast Free Converter\FastFreeConverter\[removed] folder moved successfully. C:\Program Files (x86)\Fast Free Converter\FastFreeConverter folder moved successfully. C:\Program Files (x86)\Fast Free Converter\Extensions\FastFreeConverter folder moved successfully. C:\Program Files (x86)\Fast Free Converter\Extensions folder moved successfully. C:\Program Files (x86)\Fast Free Converter folder moved successfully. C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\anokniebcoameopaknmpbhaaoedjajik\1 folder moved successfully. C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\niieikgjphnahhnnmdheblakpelnfgaj\1 folder moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C4BA31C-0C15-11E2-90C7-9BFCBEB168B3}\ deleted successfully. C:\Users\JimAngehr\AppData\Local\DownloadTerms folder moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4FA31CBC-669C-8878-251A-D2DA6ACAE0DF}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4FA31CBC-669C-8878-251A-D2DA6ACAE0DF}\ deleted successfully. C:\ProgramData\BBRowsE2savve folder moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7F6AFBF1-E065-4627-A2FD-810366367D01}\ deleted successfully. C:\Users\JimAngehr\AppData\Roaming\DefaultTab\DefaultTab folder moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B422F1BC-9ADB-48A7-8B13-00C176039DC5}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B422F1BC-9ADB-48A7-8B13-00C176039DC5}\ deleted successfully. File C:\Program Files (x86)\Fast Free Converter\FastFreeConverter\FastFreeConverter.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C178AC1C-9A8B-8FF7-88BA-DB329D96695B}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C178AC1C-9A8B-8FF7-88BA-DB329D96695B}\ deleted successfully. C:\ProgramData\EybooikBBriowsue folder moved successfully. C:\Windows\Tasks\AmiUpdXp.job moved successfully. C:\Users\JimAngehr\ntuser.pol moved successfully. ========== SERVICES/DRIVERS ========== Service DefaultTabUpdate stopped successfully! Service DefaultTabUpdate deleted successfully! Service DefaultTabSearch stopped successfully! Service DefaultTabSearch deleted successfully! Service FastFreeConverterUpdt stopped successfully! Service FastFreeConverterUpdt deleted successfully! ========== FILES ========== C:\Program Files (x86)\DefaultTab folder moved successfully. C:\Program Files (x86)\File Type Helper folder moved successfully. C:\Users\JimAngehr\AppData\Local\SwvUpdater folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: James ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: JimAngehr ->Temp folder emptied: 363093061 bytes ->Temporary Internet Files folder emptied: 337019100 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 182590034 bytes ->Google Chrome cache emptied: 360746950 bytes ->Flash cache emptied: 158402 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 183641507 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 428135 bytes RecycleBin emptied: 12879280299 bytes Total Files Cleaned = 13,644.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 07102013_175356 Files\Folders moved on Reboot… File\Folder C:\Users\JimAngehr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRD0000.doc not found! File\Folder C:\Users\JimAngehr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRD0002.doc not found! File\Folder C:\Users\JimAngehr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{A8AF6B5C-D657-46C0-AFDB-62C972A2422D}.tmp not found! File\Folder C:\Users\JimAngehr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{FCA18517-5455-4F67-BB7F-089DFB669F0D}.tmp not found! C:\Users\JimAngehr\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully. File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot. PendingFileRenameOperations files… Registry entries deleted on Reboot…
I couldn't tell exactly whether you meant for me to do this, but I ran an OTL scan again, and here's the log:

OTL logfile created on: 7/10/2013 7:04:27 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\JimAngehr\Desktop
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.47 Gb Total Physical Memory | 1.71 Gb Available Physical Memory | 49.20% Memory free
6.97 Gb Paging File | 5.10 Gb Available in Paging File | 73.12% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 672.51 Gb Total Space | 493.94 Gb Free Space | 73.45% Space Free | Partition Type: NTFS
Drive D: | 25.36 Gb Total Space | 3.02 Gb Free Space | 11.91% Space Free | Partition Type: NTFS

Computer Name: JIMCOMPUTER | User Name: JimAngehr | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/07/09 09:14:09 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\JimAngehr\Desktop\OTL.exe
PRC - [2013/07/07 09:00:43 | 004,640,768 | —- | M] (Spotify Ltd) – C:\Users\JimAngehr\AppData\Roaming\Spotify\spotify.exe
PRC - [2013/07/07 09:00:35 | 001,104,384 | —- | M] (Spotify Ltd) – C:\Users\JimAngehr\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
PRC - [2013/07/04 14:26:01 | 000,920,472 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2013/06/14 21:28:44 | 000,825,808 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2013/05/24 20:47:30 | 027,776,968 | —- | M] (Dropbox, Inc.) – C:\Users\JimAngehr\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2013/05/09 04:58:30 | 004,858,968 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013/05/09 04:58:30 | 000,046,808 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/07/27 21:21:26 | 000,136,488 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
PRC - [2012/07/09 16:40:02 | 000,580,512 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
PRC - [2012/07/09 16:40:02 | 000,035,232 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
PRC - [2012/06/07 23:34:06 | 000,111,120 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
PRC - [2012/03/28 21:34:30 | 000,091,432 | —- | M] (CyberLink Corp.) – C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
PRC - [2011/08/26 17:37:18 | 001,342,008 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
PRC - [2006/11/02 21:40:12 | 000,174,656 | —- | M] () – C:\Windows\SysWOW64\PSIService.exe


========== Modules (No Company Name) ==========

MOD - [2013/07/07 09:00:36 | 024,985,600 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Spotify\Data\libcef.dll
MOD - [2013/07/04 14:24:58 | 003,285,912 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2013/06/14 21:28:42 | 000,393,168 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppgooglenaclpluginchrome.dll
MOD - [2013/06/14 21:28:41 | 013,140,432 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll
MOD - [2013/06/14 21:28:40 | 004,051,408 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll
MOD - [2013/06/14 21:27:51 | 000,599,504 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\libglesv2.dll
MOD - [2013/06/14 21:27:50 | 000,124,368 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\libegl.dll
MOD - [2013/06/14 21:27:48 | 001,597,392 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ffmpegsumo.dll
MOD - [2013/03/13 16:48:52 | 024,978,944 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Dropbox\bin\libcef.dll
MOD - [2012/11/13 19:32:50 | 003,558,400 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
MOD - [2012/06/08 14:34:06 | 000,016,400 | —- | M] () – C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
MOD - [2012/06/07 23:34:06 | 000,627,216 | —- | M] () – C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
MOD - [2012/02/20 21:29:04 | 000,087,912 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/02/20 21:28:42 | 001,242,472 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll


========== Services (SafeList) ==========

SRV:64bit: - [2013/05/09 04:58:30 | 000,046,808 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\AVAST Software\Avast\AvastSvc.exe – (avast! Antivirus)
SRV:64bit: - [2013/05/04 02:58:02 | 000,470,528 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\netprofmsvc.dll – (netprofm)
SRV:64bit: - [2013/05/04 02:57:05 | 000,179,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\bisrv.dll – (BrokerInfrastructure)
SRV:64bit: - [2013/04/09 00:48:42 | 000,169,472 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\AudioEndpointBuilder.dll – (AudioEndpointBuilder)
SRV:64bit: - [2013/03/01 22:45:07 | 000,171,008 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\TimeBrokerServer.dll – (TimeBroker)
SRV:64bit: - [2013/03/01 22:45:05 | 000,180,224 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\SystemEventsBrokerServer.dll – (SystemEventsBroker)
SRV:64bit: - [2013/01/28 21:57:14 | 000,014,920 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MsMpEng.exe – (WinDefend)
SRV:64bit: - [2013/01/09 19:23:16 | 001,964,544 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wlidsvc.dll – (wlidsvc)
SRV:64bit: - [2013/01/09 19:22:35 | 000,438,272 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\lsm.dll – (LSM)
SRV:64bit: - [2012/11/06 00:36:55 | 002,675,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll – (PrintNotify)
SRV:64bit: - [2012/09/20 05:10:47 | 002,367,528 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\WSService.dll – (WSService)
SRV:64bit: - [2012/09/20 02:31:18 | 000,116,736 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\fhsvc.dll – (fhsvc)
SRV:64bit: - [2012/08/23 10:45:42 | 000,029,600 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Windows\SysNative\hpservice.exe – (hpsrv)
SRV:64bit: - [2012/08/09 02:45:58 | 000,239,616 | —- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2012/08/08 13:36:06 | 000,361,984 | —- | M] (Advanced Micro Devices, Inc.) [Auto | Running] – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe – (AMD FUEL Service)
SRV:64bit: - [2012/07/25 23:07:47 | 000,065,536 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\wiarpc.dll – (WiaRpc)
SRV:64bit: - [2012/07/25 23:07:42 | 000,263,680 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\wcmsvc.dll – (Wcmsvc)
SRV:64bit: - [2012/07/25 23:07:40 | 000,283,648 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\vaultsvc.dll – (VaultSvc)
SRV:64bit: - [2012/07/25 23:07:25 | 000,012,800 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\svsvc.dll – (svsvc)
SRV:64bit: - [2012/07/25 23:06:34 | 000,743,936 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\netlogon.dll – (Netlogon)
SRV:64bit: - [2012/07/25 23:06:33 | 000,161,792 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\NcaSvc.dll – (NcaSvc)
SRV:64bit: - [2012/07/25 23:06:33 | 000,073,728 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\NcdAutoSetup.dll – (NcdAutoSetup)
SRV:64bit: - [2012/07/25 23:05:55 | 000,059,904 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\SysNative\keyiso.dll – (KeyIso)
SRV:64bit: - [2012/07/25 23:05:34 | 000,037,376 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\efssvc.dll – (EFS)
SRV:64bit: - [2012/07/25 23:05:28 | 000,207,872 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\DeviceSetupManager.dll – (DsmSvc)
SRV:64bit: - [2012/07/25 23:05:24 | 000,342,016 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\das.dll – (DeviceAssociationService)
SRV:64bit: - [2012/07/25 23:05:08 | 000,122,368 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\AUInstallAgent.dll – (AllUserInstallAgent)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmicvss)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmictimesync)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmicshutdown)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmicrdv)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmickvpexchange)
SRV:64bit: - [2012/07/25 20:24:02 | 000,336,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\icsvc.dll – (vmicheartbeat)
SRV:64bit: - [2012/07/21 12:30:36 | 000,321,536 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Program Files\IDT\WDM\stacsv64.exe – (STacSV)
SRV:64bit: - [2010/04/14 20:56:24 | 001,052,328 | —- | M] ( ) [Auto | Running] – C:\Windows\SysNative\lxebcoms.exe – (lxeb_device)
SRV - [2013/07/04 14:25:59 | 000,117,144 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2013/06/23 09:02:05 | 000,256,904 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2013/05/31 07:19:28 | 000,032,808 | —- | M] (Just Develop It) [Auto | Stopped] – C:\Program Files (x86)\MyPC Backup\BackupStack.exe – (BackupStack)
SRV - [2012/11/06 00:36:55 | 002,675,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll – (PrintNotify)
SRV - [2012/08/10 20:53:44 | 000,085,504 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe – (HP Support Assistant Service)
SRV - [2012/07/25 23:20:04 | 000,018,432 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\StorSvc.dll – (StorSvc)
SRV - [2012/07/25 23:18:41 | 000,408,064 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\inetsrv\iisw3adm.dll – (WAS)
SRV - [2012/07/25 23:17:52 | 000,060,416 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysWOW64\inetsrv\apphostsvc.dll – (AppHostSvc)
SRV - [2012/07/13 21:02:16 | 002,451,456 | —- | M] (Realsil Microelectronics Inc.) [Auto | Running] – C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe – (IconMan_R)
SRV - [2012/07/09 16:40:02 | 000,035,232 | —- | M] (Hewlett-Packard Development Company, L.P.) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe – (HPWMISVC)
SRV - [2010/10/12 13:59:12 | 000,206,072 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe – (GamesAppService)
SRV - [2006/11/02 21:40:12 | 000,174,656 | —- | M] () [Auto | Running] – C:\Windows\SysWOW64\PSIService.exe – (ProtexisLicensing)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/07/07 18:56:36 | 001,030,952 | —- | M] (AVAST Software) [File_System | System | Running] – C:\Windows\SysNative\drivers\aswSnx.sys – (aswSnx)
DRV:64bit: - [2013/07/07 18:56:36 | 000,378,944 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswSP.sys – (aswSP)
DRV:64bit: - [2013/07/07 18:56:36 | 000,189,936 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswVmm.sys – (aswVmm)
DRV:64bit: - [2013/05/09 04:59:07 | 000,072,016 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\aswRdr2.sys – (aswRdr)
DRV:64bit: - [2013/05/09 04:59:07 | 000,065,336 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswRvrt.sys – (aswRvrt)
DRV:64bit: - [2013/05/09 04:59:07 | 000,064,288 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswTdi.sys – (aswTdi)
DRV:64bit: - [2013/05/09 04:59:06 | 000,080,816 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\Drivers\aswMonFlt.sys – (aswMonFlt)
DRV:64bit: - [2013/05/09 04:59:06 | 000,033,400 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswFsBlk.sys – (aswFsBlk)
DRV:64bit: - [2013/05/04 03:34:17 | 000,446,720 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\USBHUB3.SYS – (USBHUB3)
DRV:64bit: - [2013/05/04 03:34:17 | 000,213,248 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\UCX01000.SYS – (UCX01000)
DRV:64bit: - [2013/05/04 03:34:15 | 000,284,416 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\spaceport.sys – (spaceport)
DRV:64bit: - [2013/03/02 06:57:48 | 000,337,128 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\USBXHCI.SYS – (USBXHCI)
DRV:64bit: - [2013/03/02 06:57:46 | 000,077,544 | —- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\storahci.sys – (storahci)
DRV:64bit: - [2013/03/02 06:45:20 | 000,148,712 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\tpm.sys – (TPM)
DRV:64bit: - [2013/03/02 06:45:19 | 000,194,792 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\sdbus.sys – (sdbus)
DRV:64bit: - [2013/03/02 06:39:38 | 000,069,864 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\pdc.sys – (pdc)
DRV:64bit: - [2013/02/02 03:25:23 | 000,037,632 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\BthAvrcpTg.sys – (BthAvrcpTg)
DRV:64bit: - [2013/01/28 21:57:05 | 000,035,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\WdBoot.sys – (WdBoot)
DRV:64bit: - [2013/01/28 19:08:22 | 000,230,904 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\WdFilter.sys – (WdFilter)
DRV:64bit: - [2013/01/09 21:53:32 | 000,028,904 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\msgpiowin32.sys – (msgpiowin32)
DRV:64bit: - [2012/11/26 23:55:44 | 000,029,952 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\BthhfHid.sys – (bthhfhid)
DRV:64bit: - [2012/11/20 00:54:31 | 000,039,936 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\hidi2c.sys – (hidi2c)
DRV:64bit: - [2012/11/05 23:55:44 | 000,022,528 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\fxppm.sys – (FxPPM)
DRV:64bit: - [2012/10/12 04:08:01 | 000,027,880 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\rdpvideominiport.sys – (RdpVideoMiniport)
DRV:64bit: - [2012/10/11 03:25:48 | 000,056,552 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\sdstor.sys – (sdstor)
DRV:64bit: - [2012/10/11 03:13:49 | 000,058,088 | —- | M] (Microsoft Corporation) [Kernel | System | Stopped] – C:\Windows\SysNative\Drivers\dam.sys – (dam)
DRV:64bit: - [2012/09/28 11:32:56 | 000,053,760 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2012/09/20 03:55:30 | 000,120,040 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\msgpioclx.sys – (GPIOClx0101)
DRV:64bit: - [2012/09/20 03:55:27 | 003,265,256 | —- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2012/09/20 03:55:24 | 000,533,224 | —- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2012/08/31 10:40:24 | 000,020,800 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\WirelessButtonDriver64.sys – (WirelessButtonDriver)
DRV:64bit: - [2012/08/24 05:38:28 | 000,448,312 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2012/08/24 05:38:28 | 000,043,832 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\Smb_driver_Intel.sys – (SmbDrvI)
DRV:64bit: - [2012/08/24 05:38:26 | 000,041,272 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\Smb_driver_AMDASF.sys – (SmbDrv)
DRV:64bit: - [2012/08/23 10:45:42 | 000,042,400 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\Accelerometer.sys – (Accelerometer)
DRV:64bit: - [2012/08/23 10:45:42 | 000,029,600 | —- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\hpdskflt.sys – (hpdskflt)
DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2012/08/09 04:03:32 | 010,283,520 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\atikmdag.sys – (amdkmdag)
DRV:64bit: - [2012/08/09 01:48:20 | 000,368,640 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2012/07/31 15:22:00 | 000,645,952 | —- | M] (Intel Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\iaStorA.sys – (iaStorA)
DRV:64bit: - [2012/07/31 04:04:12 | 000,690,832 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\Rt630x64.sys – (RTL8168)
DRV:64bit: - [2012/07/26 01:26:46 | 000,025,328 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2012/07/26 01:26:45 | 000,033,792 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\condrv.sys – (condrv)
DRV:64bit: - [2012/07/26 01:00:58 | 000,322,800 | —- | M] (VIA Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\VSTXRAID.SYS – (VSTXRAID)
DRV:64bit: - [2012/07/26 01:00:58 | 000,106,224 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\VerifierExt.sys – (VerifierExt)
DRV:64bit: - [2012/07/26 01:00:58 | 000,097,008 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\uaspstor.sys – (UASPStor)
DRV:64bit: - [2012/07/26 01:00:57 | 000,077,040 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\acpiex.sys – (acpiex)
DRV:64bit: - [2012/07/26 01:00:55 | 000,064,240 | —- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\mvumis.sys – (mvumis)
DRV:64bit: - [2012/07/26 01:00:55 | 000,030,960 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2012/07/26 01:00:52 | 000,092,400 | —- | M] (LSI Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2012/07/26 01:00:52 | 000,081,136 | —- | M] (LSI Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\lsi_sss.sys – (LSI_SSS)
DRV:64bit: - [2012/07/26 01:00:52 | 000,064,752 | —- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2012/07/26 01:00:51 | 000,113,904 | —- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys – (EhStorTcgDrv)
DRV:64bit: - [2012/07/26 01:00:51 | 000,081,136 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\EhStorClass.sys – (EhStorClass)
DRV:64bit: - [2012/07/26 01:00:49 | 000,258,288 | —- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2012/07/26 01:00:49 | 000,106,736 | —- | M] (LSI) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\3ware.sys – (3ware)
DRV:64bit: - [2012/07/26 01:00:49 | 000,076,016 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2012/07/26 01:00:48 | 000,026,352 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] – C:\Windows\SysNative\Drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2012/07/26 00:57:54 | 000,361,200 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\clfs.sys – (CLFS)
DRV:64bit: - [2012/07/26 00:54:34 | 000,096,496 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\wfplwfs.sys – (WFPLWFS)
DRV:64bit: - [2012/07/26 00:53:16 | 000,067,824 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\vpci.sys – (vpci)
DRV:64bit: - [2012/07/25 23:17:38 | 000,036,592 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\terminpt.sys – (terminpt)
DRV:64bit: - [2012/07/25 22:29:47 | 000,021,504 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\WSDPrint.sys – (WSDPrintDevice)
DRV:64bit: - [2012/07/25 22:29:14 | 000,010,752 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\mshidumdf.sys – (mshidumdf)
DRV:64bit: - [2012/07/25 22:29:08 | 000,048,640 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\BasicDisplay.sys – (BasicDisplay)
DRV:64bit: - [2012/07/25 22:29:03 | 000,024,576 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\HyperVideo.sys – (HyperVideo)
DRV:64bit: - [2012/07/25 22:28:52 | 000,029,696 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\BasicRender.sys – (BasicRender)
DRV:64bit: - [2012/07/25 22:27:58 | 000,012,288 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\vmgencounter.sys – (gencounter)
DRV:64bit: - [2012/07/25 22:27:41 | 000,018,432 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\kdnic.sys – (kdnic)
DRV:64bit: - [2012/07/25 22:27:37 | 000,010,752 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\acpitime.sys – (acpitime)
DRV:64bit: - [2012/07/25 22:27:33 | 000,023,552 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\npsvctrig.sys – (npsvctrig)
DRV:64bit: - [2012/07/25 22:27:29 | 000,019,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\WpdUpFltr.sys – (WpdUpFltr)
DRV:64bit: - [2012/07/25 22:27:16 | 000,010,240 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\acpipagr.sys – (acpipagr)
DRV:64bit: - [2012/07/25 22:27:01 | 000,011,776 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\hyperkbd.sys – (hyperkbd)
DRV:64bit: - [2012/07/25 22:26:46 | 000,062,976 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\SerCx.sys – (SerCx)
DRV:64bit: - [2012/07/25 22:26:43 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\SpbCx.sys – (SpbCx)
DRV:64bit: - [2012/07/25 22:26:34 | 000,030,208 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2012/07/25 22:26:13 | 000,051,200 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\bthhfenum.sys – (BthHFEnum)
DRV:64bit: - [2012/07/25 22:25:57 | 000,033,280 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\dmvsc.sys – (dmvsc)
DRV:64bit: - [2012/07/25 22:25:56 | 000,057,344 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2012/07/25 22:25:13 | 000,045,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\wpcfltr.sys – (wpcfltr)
DRV:64bit: - [2012/07/25 22:25:01 | 000,126,464 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\NdisImPlatform.sys – (NdisImPlatform)
DRV:64bit: - [2012/07/25 22:23:53 | 000,068,608 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\mslldp.sys – (MsLldp)
DRV:64bit: - [2012/07/25 22:23:42 | 000,097,792 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\Windows\SysNative\Drivers\Ndu.sys – (Ndu)
DRV:64bit: - [2012/07/24 11:44:02 | 003,618,304 | —- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\athw8x.sys – (athr)
DRV:64bit: - [2012/07/24 05:35:12 | 000,079,528 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\amd_sata.sys – (amd_sata)
DRV:64bit: - [2012/07/24 05:35:12 | 000,026,280 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\amd_xata.sys – (amd_xata)
DRV:64bit: - [2012/07/21 12:30:36 | 000,540,160 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\stwrt64.sys – (STHDA)
DRV:64bit: - [2012/07/18 00:59:12 | 000,098,472 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\AtihdW86.sys – (AtiHDAudioService)
DRV:64bit: - [2012/07/03 18:09:08 | 000,269,968 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\RtsP2Stor.sys – (RSP2STOR)
DRV:64bit: - [2012/06/25 13:24:50 | 000,092,536 | —- | M] (CyberLink) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\CLVirtualDrive.sys – (CLVirtualDrive)
DRV:64bit: - [2012/06/23 09:23:38 | 000,199,008 | —- | M] (AppEx Networks Corporation) [Kernel | Auto | Running] – C:\Windows\SysNative\Drivers\appexDrv.sys – (APXACC)
DRV:64bit: - [2012/06/19 10:07:50 | 000,057,000 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\usbfilter.sys – (usbfilter)
DRV:64bit: - [2012/06/02 10:32:26 | 010,627,744 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\igdkmd64.sys – (igfx)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT13/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;pc=HPNTDFJS
IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{F05749BB-0626-4108-9BA0-E2C7F7D1B555}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT13/1
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;pc=HPNTDFJS
IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}
IE - HKLM\..\SearchScopes\{F05749BB-0626-4108-9BA0-E2C7F7D1B555}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;pc=HPNTDFJS
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\..\SearchScopes\{F05749BB-0626-4108-9BA0-E2C7F7D1B555}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Google"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://search.aol.com/search/search?q={searchTerms}&s;_it=webpickaol-ff&s;_qt=sb&tb;_uuid=D1E32A0EB1E84CB199BF9D10246EAD1B&tb;_oid=25-04-2013&tb;_mrud=26-04-2013"
FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:8.0.1489
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:22.0
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe;=utf-8&q;="


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013/07/07 18:56:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/07/04 14:24:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/07/04 14:24:40 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/07/04 14:24:39 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/07/04 14:24:40 | 000,000,000 | —D | M]

[2012/11/01 21:44:34 | 000,000,000 | —D | M] (No name found) – C:\Users\JimAngehr\AppData\Roaming\Mozilla\Extensions
[2013/07/07 19:12:25 | 000,000,000 | —D | M] (No name found) – C:\Users\JimAngehr\AppData\Roaming\Mozilla\Firefox\Profiles\7zcy930i.default\extensions
[2013/07/07 19:05:10 | 000,002,552 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Mozilla\Firefox\Profiles\7zcy930i.default\searchplugins\aol-search.xml
[2013/07/07 09:01:43 | 000,001,988 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Mozilla\Firefox\Profiles\7zcy930i.default\searchplugins\search.xml
[2013/07/04 14:24:39 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013/07/04 14:26:02 | 000,000,000 | —D | M] (Default) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/07/07 18:56:00 | 000,000,000 | —D | M] (avast! Online Security) – C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll
CHR - plugin: Norton Identity Safe (Enabled) = C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.2.0.18_0\npcoplgn.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - Extension: YouTube = C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Gmail = C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2012/07/26 01:26:49 | 000,000,824 | —- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
O2:64bit: - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
O3:64bit: - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CLVirtualDrive] C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QuickFinder Scheduler] C:\Program Files (x86)\WordPerfect Office X3\Programs\QFSCHD130.EXE (Corel Corporation)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004..\Run: [Spotify] C:\Users\JimAngehr\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004..\Run: [Spotify Web Helper] C:\Users\JimAngehr\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - Startup: C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\JimAngehr\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk = C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-2393212166-3480209652-2217339028-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Open with WordPerfect - C:\Program Files (x86)\WordPerfect Office X3\Programs\WPLauncher.hta ()
O8 - Extra context menu item: Open with WordPerfect - C:\Program Files (x86)\WordPerfect Office X3\Programs\WPLauncher.hta ()
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3C6BDB04-E01A-40C1-AD9D-37A8A0EE53D6}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/07/10 18:00:46 | 000,595,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qedit.dll
[2013/07/10 18:00:45 | 000,496,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qedit.dll
[2013/07/10 18:00:37 | 001,838,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/07/10 18:00:36 | 002,842,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/07/10 18:00:36 | 002,620,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/07/10 18:00:01 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/07/10 17:59:55 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/07/10 17:59:54 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/07/10 17:59:53 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/07/10 17:59:53 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/07/10 17:53:56 | 000,000,000 | —D | C] – C:\_OTL
[2013/07/09 09:14:08 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\JimAngehr\Desktop\OTL.exe
[2013/07/08 16:17:27 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/07/08 16:16:49 | 000,000,000 | —D | C] – C:\Users\JimAngehr\Desktop\mbar-1.06.0.1004
[2013/07/08 14:54:34 | 000,688,992 | R— | C] (Swearware) – C:\Users\JimAngehr\Desktop\dds(1).scr
[2013/07/07 18:56:32 | 000,378,944 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2013/07/07 18:56:32 | 000,072,016 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr2.sys
[2013/07/07 18:56:32 | 000,064,288 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2013/07/07 18:56:32 | 000,033,400 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2013/07/07 18:56:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2013/07/07 18:56:18 | 001,030,952 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2013/07/07 18:56:18 | 000,080,816 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2013/07/07 18:55:43 | 000,041,664 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2013/07/04 14:24:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/07/04 07:43:26 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tssdisai.dll
[2013/06/23 09:01:20 | 000,000,000 | —D | C] – C:\Users\JimAngehr\AppData\Local\Adobe
[2013/06/18 07:47:13 | 000,000,000 | —D | C] – C:\Users\JimAngehr\AppData\Roaming\DefaultTab
[2013/06/18 07:47:05 | 000,000,000 | —D | C] – C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NexGen Media Player
[2013/06/18 07:46:46 | 000,000,000 | —D | C] – C:\Users\JimAngehr\AppData\Local\NexGenMediaPlayer
[2013/06/18 07:46:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\NexGen Media Player
[2013/06/18 07:46:43 | 000,000,000 | —D | C] – C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
[2013/06/18 07:46:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\MyPC Backup
[2013/06/16 09:11:00 | 001,257,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2013/06/16 09:10:58 | 001,300,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\gdi32.dll
[2013/06/16 09:10:55 | 000,888,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\autochk.exe
[2013/06/16 09:10:55 | 000,793,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\autochk.exe
[2013/06/16 09:10:55 | 000,542,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\untfs.dll
[2013/06/16 09:10:55 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\untfs.dll
[2013/06/15 08:18:24 | 013,644,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Windows.UI.Xaml.dll
[2013/06/15 08:18:21 | 010,788,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Windows.UI.Xaml.dll
[2013/06/15 08:18:19 | 001,131,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AppXDeploymentServer.dll
[2013/06/15 08:18:18 | 010,116,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\twinui.dll
[2013/06/15 08:18:14 | 000,470,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netprofmsvc.dll
[2013/06/15 08:18:13 | 008,857,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\twinui.dll
[2013/06/15 08:18:13 | 002,305,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\authui.dll
[2013/06/15 08:18:12 | 002,035,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\authui.dll
[2013/06/15 08:18:12 | 000,760,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2013/06/15 08:18:11 | 000,446,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\USBHUB3.SYS
[2013/06/15 08:18:11 | 000,328,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ubpm.dll
[2013/06/15 08:18:11 | 000,014,848 | —- | C] (Microsoft) – C:\Windows\SysWow64\rars.rs
[2013/06/15 08:18:11 | 000,014,848 | —- | C] (Microsoft) – C:\Windows\SysNative\rars.rs
[2013/06/15 08:18:10 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\BCP47Langs.dll
[2013/06/15 08:18:10 | 000,330,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\stobject.dll
[2013/06/15 08:18:10 | 000,247,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ubpm.dll
[2013/06/15 08:18:09 | 000,708,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AppXDeploymentExtensions.dll
[2013/06/15 08:18:09 | 000,621,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuapi.dll
[2013/06/15 08:18:08 | 000,812,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Magnify.exe
[2013/06/15 08:18:08 | 000,213,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\UCX01000.SYS
[2013/06/15 08:18:08 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netplwiz.dll
[2013/06/15 08:18:08 | 000,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psmsrv.dll
[2013/06/15 08:18:07 | 000,560,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfmp4srcsnk.dll
[2013/06/15 08:18:07 | 000,151,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netplwiz.dll
[2013/06/15 08:18:06 | 000,501,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DevicePairing.dll
[2013/06/15 08:18:06 | 000,284,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\spaceport.sys
[2013/06/15 08:18:06 | 000,058,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2013/06/15 08:18:05 | 000,758,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Magnify.exe
[2013/06/15 08:18:05 | 000,419,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\intl.cpl
[2013/06/15 08:18:05 | 000,120,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AuthHost.exe
[2013/06/15 08:18:04 | 001,619,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2013/06/15 08:18:04 | 000,449,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\DevicePairing.dll
[2013/06/15 08:18:04 | 000,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\hidclass.sys
[2013/06/15 08:18:03 | 000,251,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUSettingsProvider.dll
[2013/06/15 08:18:03 | 000,122,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\biwinrt.dll
[2013/06/15 08:18:03 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\biwinrt.dll
[2013/06/15 08:18:02 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\intl.cpl
[2013/06/15 08:18:02 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\bisrv.dll
[2013/06/15 08:18:01 | 000,411,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfmp4srcsnk.dll
[2013/06/15 08:18:01 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\storewuauth.dll
[2013/06/15 08:18:01 | 000,141,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2013/06/15 08:18:01 | 000,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuwebv.dll
[2013/06/15 08:18:01 | 000,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2013/06/15 08:18:00 | 000,309,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\BCP47Langs.dll
[2013/06/15 08:18:00 | 000,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wudriver.dll
[2013/06/15 08:18:00 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2013/06/15 08:17:59 | 000,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\muifontsetup.dll
[2013/06/15 08:17:58 | 000,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuapp.exe
[2013/06/15 08:17:58 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\muifontsetup.dll
[2013/06/12 07:10:25 | 001,889,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/06/12 07:10:24 | 001,255,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certutil.exe
[2013/06/12 07:10:24 | 001,013,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certutil.exe
[2013/06/12 07:10:24 | 000,141,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2013/06/12 07:10:21 | 000,733,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/06/12 07:10:19 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptdlg.dll
[2013/06/12 07:10:19 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cryptdlg.dll
[2013/06/12 07:09:30 | 000,915,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\uxtheme.dll
[2013/06/12 07:09:27 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UXInit.dll
[2013/06/12 07:09:27 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UXInit.dll

========== Files - Modified Within 30 Days ==========

[2013/07/10 19:05:00 | 000,000,928 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/10 18:50:07 | 001,573,780 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/07/10 18:50:07 | 000,412,798 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/07/10 18:50:07 | 000,006,364 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/07/10 18:46:29 | 000,000,924 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/10 18:43:56 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/07/10 18:41:22 | 268,435,456 | -HS- | M] () – C:\swapfile.sys
[2013/07/10 18:41:21 | 2981,527,552 | -HS- | M] () – C:\hiberfil.sys
[2013/07/10 18:35:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/07/09 09:14:09 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\JimAngehr\Desktop\OTL.exe
[2013/07/08 16:16:15 | 013,399,154 | —- | M] () – C:\Users\JimAngehr\Desktop\mbar-1.06.0.1004.zip
[2013/07/08 15:21:46 | 551,744,019 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/07/08 14:59:34 | 000,377,856 | —- | M] () – C:\Users\JimAngehr\Desktop\glnzpoxp.exe
[2013/07/08 14:54:35 | 000,688,992 | R— | M] (Swearware) – C:\Users\JimAngehr\Desktop\dds(1).scr
[2013/07/07 18:56:37 | 000,000,175 | —- | M] () – C:\Windows\SysNative\drivers\aswVmm.sys.sum
[2013/07/07 18:56:36 | 001,030,952 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2013/07/07 18:56:36 | 000,378,944 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2013/07/07 18:56:36 | 000,189,936 | —- | M] () – C:\Windows\SysNative\drivers\aswVmm.sys
[2013/07/07 18:56:36 | 000,000,175 | —- | M] () – C:\Windows\SysNative\drivers\aswSP.sys.sum
[2013/07/07 18:56:36 | 000,000,175 | —- | M] () – C:\Windows\SysNative\drivers\aswSnx.sys.sum
[2013/07/07 18:56:33 | 000,001,922 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/07/07 18:56:18 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2013/07/07 08:26:35 | 000,000,372 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForJimAngehr.job
[2013/06/27 18:04:51 | 000,693,112 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/06/27 18:04:51 | 000,078,200 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/06/21 22:39:11 | 000,001,092 | —- | M] () – C:\Users\JimAngehr\Desktop\Continue Vid-Saver Installation.lnk
[2013/06/18 07:47:05 | 000,001,080 | —- | M] () – C:\Users\JimAngehr\Desktop\NexGen Media Player.lnk
[2013/06/18 07:46:44 | 000,001,101 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
[2013/06/18 07:46:44 | 000,001,091 | —- | M] () – C:\Users\JimAngehr\Desktop\MyPC Backup.lnk
[2013/06/18 07:45:40 | 000,000,002 | —- | M] () – C:\END
[2013/06/15 08:56:55 | 000,001,056 | —- | M] () – C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/06/15 08:56:19 | 000,001,032 | —- | M] () – C:\Users\JimAngehr\Desktop\Dropbox.lnk
[2013/06/11 19:43:00 | 000,690,688 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/06/11 19:26:36 | 000,051,712 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/06/11 19:25:29 | 000,603,136 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/06/11 19:25:16 | 003,958,784 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/06/11 19:25:16 | 000,855,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll

========== Files Created - No Company Name ==========

[2013/07/08 16:16:12 | 013,399,154 | —- | C] () – C:\Users\JimAngehr\Desktop\mbar-1.06.0.1004.zip
[2013/07/08 14:59:33 | 000,377,856 | —- | C] () – C:\Users\JimAngehr\Desktop\glnzpoxp.exe
[2013/07/07 18:56:37 | 000,000,175 | —- | C] () – C:\Windows\SysNative\drivers\aswVmm.sys.sum
[2013/07/07 18:56:37 | 000,000,175 | —- | C] () – C:\Windows\SysNative\drivers\aswSP.sys.sum
[2013/07/07 18:56:37 | 000,000,175 | —- | C] () – C:\Windows\SysNative\drivers\aswSnx.sys.sum
[2013/07/07 18:56:33 | 000,001,922 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/07/07 18:56:18 | 000,189,936 | —- | C] () – C:\Windows\SysNative\drivers\aswVmm.sys
[2013/07/07 18:56:18 | 000,065,336 | —- | C] () – C:\Windows\SysNative\drivers\aswRvrt.sys
[2013/06/21 22:39:11 | 000,001,092 | —- | C] () – C:\Users\JimAngehr\Desktop\Continue Vid-Saver Installation.lnk
[2013/06/18 07:47:05 | 000,001,080 | —- | C] () – C:\Users\JimAngehr\Desktop\NexGen Media Player.lnk
[2013/06/18 07:46:44 | 000,001,101 | —- | C] () – C:\Users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
[2013/06/18 07:46:44 | 000,001,091 | —- | C] () – C:\Users\JimAngehr\Desktop\MyPC Backup.lnk
[2013/06/18 07:45:39 | 000,000,002 | —- | C] () – C:\END
[2013/06/15 08:17:58 | 000,386,646 | —- | C] () – C:\Windows\SysNative\ApnDatabase.xml
[2013/04/01 13:01:32 | 000,000,000 | —- | C] () – C:\Windows\setup32.INI
[2013/01/09 10:33:21 | 000,200,704 | —- | C] () – C:\Windows\SysWow64\Bwbits50.dll
[2013/01/09 10:33:21 | 000,181,760 | —- | C] () – C:\Windows\SysWow64\patchw32.dll
[2013/01/09 10:33:21 | 000,116,736 | —- | C] () – C:\Windows\SysWow64\patchw.dll
[2013/01/09 10:33:21 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\bwplay.exe
[2013/01/09 10:33:21 | 000,053,760 | —- | C] () – C:\Windows\SysWow64\zlib.dll
[2013/01/09 10:33:21 | 000,020,992 | —- | C] () – C:\Windows\SysWow64\bwntsend.dll
[2013/01/09 10:33:21 | 000,016,896 | —- | C] () – C:\Windows\SysWow64\bwnthook.dll
[2012/11/07 13:02:13 | 000,001,056 | -HS- | C] () – C:\Windows\SysWow64\KGyGaAvL.sys
[2012/11/04 15:22:24 | 000,083,968 | —- | C] () – C:\Windows\SysWow64\OEMLicense.dll
[2012/08/16 23:46:43 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2012/08/09 02:10:22 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2012/08/09 02:10:22 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2012/08/03 18:40:09 | 000,916,510 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/07/26 04:13:10 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2012/07/26 04:13:09 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2012/07/26 03:21:26 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2012/07/25 21:17:42 | 000,043,520 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2012/07/25 16:37:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2012/07/25 16:28:31 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2012/07/25 16:22:54 | 000,982,240 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2012/07/25 16:22:54 | 000,439,308 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2012/07/25 16:22:54 | 000,092,356 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2012/06/02 10:31:19 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2012/05/10 19:35:16 | 000,029,184 | —- | C] () – C:\Windows\SysWow64\kdbsdk32.dll
[2011/09/13 10:06:16 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2012/08/17 00:03:34 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/03/06 02:31:28 | 019,758,592 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/03/06 01:03:37 | 017,561,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2012/07/25 23:05:38 | 001,004,544 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2012/07/25 23:18:27 | 000,784,896 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2012/07/25 23:07:41 | 000,455,680 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

< End of report >
Combofix

Combofix should only be run when adviced by a team member!

Link


Important - Save the file to your desktop!


  • Deactivate any and all of your antivirus programs /spyware scanners - they can prevent CF from doing its work.
  • Run Combofix.exe

When finished, Combofix creates a log file named C:\Combofix.txt. Please post its content in your next reply.

Note: When receiving an error message containing ""Illegal operation attempted on a registry key that has been marked for deletion" simply restart your computer to fix this.
ComboFix 13-07-09.01 - JimAngehr 07/11/2013 8:20.1.2 - x64 Microsoft Windows 8 6.2.9200.0.1252.1.1033.18.3554.2411 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\Microsoft\Windows\Start Menu\Programs\BBRowsE2savve c:\programdata\Microsoft\Windows\Start Menu\Programs\BBRowsE2savve\BBRowsE2savve.lnk c:\programdata\Microsoft\Windows\Start Menu\Programs\BBRowsE2savve\Uninstall.lnk c:\programdata\Microsoft\Windows\Start Menu\Programs\EybooikBBriowsue c:\programdata\Microsoft\Windows\Start Menu\Programs\EybooikBBriowsue\EybooikBBriowsue.lnk c:\programdata\Microsoft\Windows\Start Menu\Programs\EybooikBBriowsue\Uninstall.lnk . . ((((((((((((((((((((((((( Files Created from 2013-06-11 to 2013-07-11 ))))))))))))))))))))))))))))))) . . 2013-07-11 12:32 . 2013-07-11 12:32 ——– d—–w- c:\users\JimAngehr\AppData\Local\temp 2013-07-11 12:32 . 2013-07-11 12:32 ——– d—–w- c:\users\James\AppData\Local\temp 2013-07-11 12:32 . 2013-07-11 12:32 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-07-10 22:01 . 2013-04-10 22:35 1617920 —-a-w- c:\program files\Windows Journal\NBDoc.DLL 2013-07-10 22:01 . 2013-04-10 22:35 2035200 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll 2013-07-10 22:01 . 2013-04-10 22:35 1272320 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2013-07-10 22:01 . 2013-04-10 22:35 1318912 —-a-w- c:\program files\Windows Journal\JNWDRV.dll 2013-07-10 22:01 . 2013-04-10 22:35 1306112 —-a-w- c:\program files\Windows Journal\JNTFiltr.dll 2013-07-10 22:01 . 2013-04-11 04:12 1029632 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\Ink\journal.dll 2013-07-10 22:01 . 2013-04-11 04:12 1413632 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\Ink\InkObj.dll 2013-07-10 21:53 . 2013-07-10 21:53 ——– d—–w- C:\_OTL 2013-07-08 20:17 . 2013-07-08 20:17 ——– d—–w- c:\programdata\Malwarebytes 2013-07-07 22:56 . 2013-07-07 22:56 378944 —-a-w- c:\windows\system32\drivers\aswSP.sys 2013-07-07 22:56 . 2013-05-09 08:59 72016 —-a-w- c:\windows\system32\drivers\aswRdr2.sys 2013-07-07 22:56 . 2013-05-09 08:59 64288 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2013-07-07 22:56 . 2013-05-09 08:59 33400 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2013-07-07 22:56 . 2013-07-07 22:56 189936 —-a-w- c:\windows\system32\drivers\aswVmm.sys 2013-07-07 22:56 . 2013-07-07 22:56 1030952 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2013-07-07 22:56 . 2013-05-09 08:59 65336 —-a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-07-07 22:56 . 2013-05-09 08:59 80816 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-07-07 22:55 . 2013-05-09 08:58 41664 —-a-w- c:\windows\avastSS.scr 2013-07-07 10:12 . 2013-06-12 03:08 9552976 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8B905977-F17E-4550-B398-F782F419DF0B}\mpengine.dll 2013-07-04 12:33 . 2013-07-04 12:33 237744 —-a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10209.bin 2013-07-04 11:43 . 2013-05-15 22:35 144384 —-a-w- c:\windows\system32\tssdisai.dll 2013-06-23 13:01 . 2013-06-23 13:02 ——– d—–w- c:\users\JimAngehr\AppData\Local\Adobe 2013-06-18 11:47 . 2013-07-10 21:54 ——– d—–w- c:\users\JimAngehr\AppData\Roaming\DefaultTab 2013-06-18 11:46 . 2013-07-01 00:24 ——– d—–w- c:\users\JimAngehr\AppData\Local\NexGenMediaPlayer 2013-06-18 11:46 . 2013-06-18 11:47 ——– d—–w- c:\program files (x86)\NexGen Media Player 2013-06-18 11:46 . 2013-06-18 11:47 ——– d—–w- c:\program files (x86)\MyPC Backup 2013-06-16 13:11 . 2013-05-30 23:24 1257472 —-a-w- c:\windows\system32\kernel32.dll 2013-06-16 13:10 . 2013-05-23 23:01 1300992 —-a-w- c:\windows\system32\gdi32.dll 2013-06-16 13:10 . 2013-05-23 22:27 1022464 —-a-w- c:\windows\SysWow64\gdi32.dll 2013-06-16 13:10 . 2013-05-15 02:25 888320 —-a-w- c:\windows\system32\autochk.exe 2013-06-16 13:10 . 2013-05-15 02:25 542208 —-a-w- c:\windows\system32\untfs.dll 2013-06-16 13:10 . 2013-05-15 02:24 793088 —-a-w- c:\windows\SysWow64\autochk.exe 2013-06-16 13:10 . 2013-05-15 02:24 482816 —-a-w- c:\windows\SysWow64\untfs.dll 2013-06-15 12:17 . 2013-05-04 06:57 17408 —-a-w- c:\windows\system32\muifontsetup.dll 2013-06-15 12:17 . 2013-05-04 04:58 34304 —-a-w- c:\windows\SysWow64\wuapp.exe 2013-06-15 12:17 . 2013-05-04 04:57 18432 —-a-w- c:\windows\SysWow64\npmproxy.dll 2013-06-15 12:17 . 2013-05-04 04:57 14336 —-a-w- c:\windows\SysWow64\muifontsetup.dll 2013-06-12 11:10 . 2013-04-23 23:12 1569792 —-a-w- c:\windows\SysWow64\crypt32.dll 2013-06-12 11:10 . 2013-04-23 22:55 1889280 —-a-w- c:\windows\system32\crypt32.dll 2013-06-12 11:10 . 2013-04-23 23:13 1013248 —-a-w- c:\windows\SysWow64\certutil.exe 2013-06-12 11:10 . 2013-04-23 23:12 109056 —-a-w- c:\windows\SysWow64\cryptnet.dll 2013-06-12 11:10 . 2013-04-23 22:56 1255936 —-a-w- c:\windows\system32\certutil.exe 2013-06-12 11:10 . 2013-04-23 22:55 68096 —-a-w- c:\windows\system32\cryptsvc.dll 2013-06-12 11:10 . 2013-04-23 22:55 141312 —-a-w- c:\windows\system32\cryptnet.dll 2013-06-12 11:10 . 2013-05-04 07:45 2233600 —-a-w- c:\windows\system32\drivers\tcpip.sys 2013-06-12 11:10 . 2013-04-27 05:20 733184 —-a-w- c:\windows\system32\win32spl.dll 2013-06-12 11:10 . 2013-04-02 23:37 25088 —-a-w- c:\windows\SysWow64\cryptdlg.dll 2013-06-12 11:10 . 2013-04-02 23:12 30720 —-a-w- c:\windows\system32\cryptdlg.dll 2013-06-12 11:09 . 2013-04-28 22:30 108032 —-a-w- c:\program files (x86)\Internet Explorer\jsdebuggeride.dll 2013-06-12 11:09 . 2013-04-28 22:28 915968 —-a-w- c:\windows\system32\uxtheme.dll 2013-06-12 11:09 . 2013-04-28 22:28 148992 —-a-w- c:\program files\Internet Explorer\jsdebuggeride.dll 2013-06-12 11:09 . 2013-05-15 22:37 44032 —-a-w- c:\windows\SysWow64\UXInit.dll 2013-06-12 11:09 . 2013-05-15 22:35 53760 —-a-w- c:\windows\system32\UXInit.dll 2013-06-12 11:09 . 2013-05-14 13:14 2706432 —-a-w- c:\windows\system32\mshtml.tlb 2013-06-12 11:09 . 2013-05-14 09:23 2706432 —-a-w- c:\windows\SysWow64\mshtml.tlb . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-07-10 22:08 . 2012-12-15 22:44 78185248 —-a-w- c:\windows\system32\MRT.exe 2013-06-27 22:04 . 2013-02-11 14:29 78200 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-27 22:04 . 2013-02-11 14:29 693112 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-05-15 16:32 . 2012-07-26 08:13 22240 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2013-05-09 08:58 . 2012-11-02 01:52 287840 —-a-w- c:\windows\system32\aswBoot.exe 2013-05-02 15:29 . 2012-12-21 21:51 278800 ——w- c:\windows\system32\MpSigStub.exe 2013-04-22 23:16 . 2013-03-16 13:26 17536 —-a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin 2013-04-16 02:34 . 2013-05-15 16:36 1455368 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys 2013-04-13 05:56 . 2013-05-15 12:56 444416 —-a-w- c:\windows\apppatch\AcSpecfc.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Spotify Web Helper"="c:\users\JimAngehr\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2013-07-07 1104384] "Spotify"="c:\users\JimAngehr\AppData\Roaming\Spotify\Spotify.exe" [2013-07-07 4640768] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-08-08 642216] "CLVirtualDrive"="c:\program files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" [2012-07-26 491320] "RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2012-03-29 91432] "HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2012-07-09 580512] "HP CoolSense"="c:\program files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe" [2011-08-26 1342008] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "QuickFinder Scheduler"="c:\program files (x86)\WordPerfect Office X3\Programs\QFSCHD130.EXE" [2007-01-03 83568] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968] . c:\users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-24 27776968] MyPC Backup.lnk - c:\program files (x86)\MyPC Backup\MyPC Backup.exe [2013-5-31 1934376] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "EnableUIADesktopToggle"= 0 (0x0) "EnableCursorSuppression"= 1 (0x1) "ConsentPromptBehaviorUser"= 3 (0x3) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer"=wdmaud.drv . R2 BackupStack;Computer Backup (MyPC Backup);c:\program files (x86)\MyPC Backup\BackupStack.exe;c:\program files (x86)\MyPC Backup\BackupStack.exe [x] R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x] R3 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x] R3 SmbDrv;SmbDrv;c:\windows\System32\drivers\Smb_driver_AMDASF.sys;c:\windows\SYSNATIVE\drivers\Smb_driver_AMDASF.sys [x] R3 SmbDrvI;SmbDrvI;c:\windows\System32\drivers\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\drivers\Smb_driver_Intel.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\System32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] S0 amd_sata;amd_sata;c:\windows\System32\drivers\amd_sata.sys;c:\windows\SYSNATIVE\drivers\amd_sata.sys [x] S0 amd_xata;amd_xata;c:\windows\System32\drivers\amd_xata.sys;c:\windows\SYSNATIVE\drivers\amd_xata.sys [x] S0 aswRvrt;aswRvrt; [x] S0 aswVmm;aswVmm; [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 CLVirtualDrive;CLVirtualDrive;c:\windows\system32\DRIVERS\CLVirtualDrive.sys;c:\windows\SYSNATIVE\DRIVERS\CLVirtualDrive.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x] S2 APXACC;AppEx Networks Accelerator LWF;c:\windows\system32\DRIVERS\appexDrv.sys;c:\windows\SYSNATIVE\DRIVERS\appexDrv.sys [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x] S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x] S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [x] S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x] S2 lxeb_device;lxeb_device;c:\windows\system32\lxebcoms.exe;c:\windows\SYSNATIVE\lxebcoms.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW86.sys;c:\windows\SYSNATIVE\drivers\AtihdW86.sys [x] S3 RSP2STOR;Realtek PCIE CardReader Driver - P2;c:\windows\system32\DRIVERS\RtsP2Stor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsP2Stor.sys [x] S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x] S3 WirelessButtonDriver;HP Wireless Button Driver Service;c:\windows\System32\drivers\WirelessButtonDriver64.sys;c:\windows\SYSNATIVE\drivers\WirelessButtonDriver64.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] apphost REG_MULTI_SZ apphostsvc iissvcs REG_MULTI_SZ w3svc was . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-06-20 19:02 1165776 —-a-w- c:\program files (x86)\Google\Chrome\Application\27.0.1453.116\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2013-07-11 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-04 13:02] . 2013-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-05 16:45] . 2013-07-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-05 16:45] . 2013-07-07 c:\windows\Tasks\HPCeeScheduleForJimAngehr.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-05-09 08:58 133840 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2012-07-21 1425408] . ——- Supplementary Scan ——- . uStart Page = hxxp://www.bing.com uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Open with WordPerfect - c:\program files (x86)\WordPerfect Office X3\Programs\WPLauncher.hta TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\JimAngehr\AppData\Roaming\Mozilla\Firefox\Profiles\7zcy930i.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/search/search?q={searchTerms}&s_it=webpickaol-ff&s_qt=sb&tb_uuid=D1E32A0EB1E84CB199BF9D10246EAD1B&tb_oid=25-04-2013&tb_mrud=26-04-2013 FF - prefs.js: browser.startup.homepage - google.com FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q= FF - ExtSQL: 2013-07-07 18:56; [removed]; c:\program files\AVAST Software\Avast\WebRep\FF FF - user.js: extentions.y2layers.installId - 637d194c-2b91-4bea-ae27-c028e609b56d FF - user.js: extentions.y2layers.defaultEnableAppsList - DropDownDeals,buzzdock,YontooNewOffers FF - user.js: extensions.autoDisableScopes - 14 FF - user.js: network.protocol-handler.warn-external.dnupdate - false . - - - - ORPHANS REMOVED - - - - . HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-DefaultTab - c:\users\JimAngehr\AppData\Roaming\DefaultTab\DefaultTab\uninstalldt.exe AddRemove-Fast Free Converter - c:\program files (x86)\Fast Free Converter\uninstall.exe AddRemove-{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} - c:\users\JimAngehr\AppData\Local\SwvUpdater\Updater.exe AddRemove-{B8019B54-F9BE-490A-9619-6D06F18F129F} - c:\program files (x86)\InstallShield Installation Information\{B8019B54-F9BE-490A-9619-6D06F18F129F}\setup.exe AddRemove-{C3F3165C-74D3-6FDB-3274-14FDA8698CFA} - c:\programdata\BBRowsE2savve\uninstall.exe AddRemove-{E5B7E1B4-21FC-6765-A3D7-BA0416DC6AF7} - c:\programdata\EybooikBBriowsue\uninstall.exe AddRemove-DownloadTerms - c:\users\JimAngehr\AppData\Local\DownloadTerms\uninst.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) @SACL=(02 0000) . Completion time: 2013-07-11 09:30:15 ComboFix-quarantined-files.txt 2013-07-11 13:30 . Pre-Run: 539,621,339,136 bytes free Post-Run: 539,559,854,080 bytes free . - - End Of File - - 0C251E54CFA823943EB6B6FD38E276E6 5FB38429D5D77768867C76DCBDB35194
by the way, the pop up just came up when I woke the computer up from screensaver. I googled the message it gives me and found it's by something called "My PCBackup" which I then found in my computer's task manager, start up tab. I disabled it from the task manager/start up menu. Now how to get rid of it?
Add-/remove programms

Click on start–>control panel.

Vista/7: Open Programs and Features
XP: Open add/remove programs

Search for and remove the following programs

MyPC Backup
DefaultTab
NexGen Media Player


Close the window.

Run combofix again and post up the log.
ComboFix 13-07-12.01 - JimAngehr 07/12/2013 14:36:38.2.2 - x64 Microsoft Windows 8 6.2.9200.0.1252.1.1033.18.3554.2376 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2013-06-12 to 2013-07-12 ))))))))))))))))))))))))))))))) . . 2013-07-12 18:47 . 2013-07-12 18:47 ——– d—–w- c:\users\James\AppData\Local\temp 2013-07-12 18:47 . 2013-07-12 18:47 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-07-10 22:01 . 2013-04-10 22:35 1617920 —-a-w- c:\program files\Windows Journal\NBDoc.DLL 2013-07-10 22:01 . 2013-04-10 22:35 2035200 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll 2013-07-10 22:01 . 2013-04-10 22:35 1272320 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2013-07-10 22:01 . 2013-04-10 22:35 1318912 —-a-w- c:\program files\Windows Journal\JNWDRV.dll 2013-07-10 22:01 . 2013-04-10 22:35 1306112 —-a-w- c:\program files\Windows Journal\JNTFiltr.dll 2013-07-10 22:01 . 2013-04-11 04:12 1029632 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\Ink\journal.dll 2013-07-10 22:01 . 2013-04-11 04:12 1413632 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\Ink\InkObj.dll 2013-07-10 21:53 . 2013-07-10 21:53 ——– d—–w- C:\_OTL 2013-07-08 20:17 . 2013-07-08 20:17 ——– d—–w- c:\programdata\Malwarebytes 2013-07-07 22:56 . 2013-07-07 22:56 378944 —-a-w- c:\windows\system32\drivers\aswSP.sys 2013-07-07 22:56 . 2013-05-09 08:59 72016 —-a-w- c:\windows\system32\drivers\aswRdr2.sys 2013-07-07 22:56 . 2013-05-09 08:59 64288 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2013-07-07 22:56 . 2013-05-09 08:59 33400 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2013-07-07 22:56 . 2013-07-07 22:56 189936 —-a-w- c:\windows\system32\drivers\aswVmm.sys 2013-07-07 22:56 . 2013-07-07 22:56 1030952 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2013-07-07 22:56 . 2013-05-09 08:59 65336 —-a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-07-07 22:56 . 2013-05-09 08:59 80816 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-07-07 22:55 . 2013-05-09 08:58 41664 —-a-w- c:\windows\avastSS.scr 2013-07-07 10:12 . 2013-06-12 03:08 9552976 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8B905977-F17E-4550-B398-F782F419DF0B}\mpengine.dll 2013-07-04 12:33 . 2013-07-04 12:33 237744 —-a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10209.bin 2013-07-04 11:43 . 2013-05-15 22:35 144384 —-a-w- c:\windows\system32\tssdisai.dll 2013-06-23 13:01 . 2013-06-23 13:02 ——– d—–w- c:\users\JimAngehr\AppData\Local\Adobe 2013-06-18 11:47 . 2013-07-10 21:54 ——– d—–w- c:\users\JimAngehr\AppData\Roaming\DefaultTab 2013-06-18 11:46 . 2013-07-12 17:07 ——– d—–w- c:\program files (x86)\MyPC Backup 2013-06-16 13:11 . 2013-05-30 23:24 1257472 —-a-w- c:\windows\system32\kernel32.dll 2013-06-16 13:10 . 2013-05-23 23:01 1300992 —-a-w- c:\windows\system32\gdi32.dll 2013-06-16 13:10 . 2013-05-23 22:27 1022464 —-a-w- c:\windows\SysWow64\gdi32.dll 2013-06-16 13:10 . 2013-05-15 02:25 888320 —-a-w- c:\windows\system32\autochk.exe 2013-06-16 13:10 . 2013-05-15 02:25 542208 —-a-w- c:\windows\system32\untfs.dll 2013-06-16 13:10 . 2013-05-15 02:24 793088 —-a-w- c:\windows\SysWow64\autochk.exe 2013-06-16 13:10 . 2013-05-15 02:24 482816 —-a-w- c:\windows\SysWow64\untfs.dll 2013-06-15 12:17 . 2013-05-04 06:57 17408 —-a-w- c:\windows\system32\muifontsetup.dll 2013-06-15 12:17 . 2013-05-04 04:58 34304 —-a-w- c:\windows\SysWow64\wuapp.exe 2013-06-15 12:17 . 2013-05-04 04:57 18432 —-a-w- c:\windows\SysWow64\npmproxy.dll 2013-06-15 12:17 . 2013-05-04 04:57 14336 —-a-w- c:\windows\SysWow64\muifontsetup.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-07-10 22:08 . 2012-12-15 22:44 78185248 —-a-w- c:\windows\system32\MRT.exe 2013-06-27 22:04 . 2013-02-11 14:29 78200 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-27 22:04 . 2013-02-11 14:29 693112 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-05-15 22:37 . 2013-06-12 11:09 44032 —-a-w- c:\windows\SysWow64\UXInit.dll 2013-05-15 22:35 . 2013-06-12 11:09 53760 —-a-w- c:\windows\system32\UXInit.dll 2013-05-15 16:32 . 2012-07-26 08:13 22240 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2013-05-14 13:14 . 2013-06-12 11:09 2706432 —-a-w- c:\windows\system32\mshtml.tlb 2013-05-14 09:23 . 2013-06-12 11:09 2706432 —-a-w- c:\windows\SysWow64\mshtml.tlb 2013-05-09 08:58 . 2012-11-02 01:52 287840 —-a-w- c:\windows\system32\aswBoot.exe 2013-05-04 07:45 . 2013-06-12 11:10 2233600 —-a-w- c:\windows\system32\drivers\tcpip.sys 2013-05-02 15:29 . 2012-12-21 21:51 278800 ——w- c:\windows\system32\MpSigStub.exe 2013-04-28 22:28 . 2013-06-12 11:09 915968 —-a-w- c:\windows\system32\uxtheme.dll 2013-04-27 05:20 . 2013-06-12 11:10 733184 —-a-w- c:\windows\system32\win32spl.dll 2013-04-23 23:13 . 2013-06-12 11:10 1013248 —-a-w- c:\windows\SysWow64\certutil.exe 2013-04-23 23:12 . 2013-06-12 11:10 1569792 —-a-w- c:\windows\SysWow64\crypt32.dll 2013-04-23 23:12 . 2013-06-12 11:10 109056 —-a-w- c:\windows\SysWow64\cryptnet.dll 2013-04-23 22:56 . 2013-06-12 11:10 1255936 —-a-w- c:\windows\system32\certutil.exe 2013-04-23 22:55 . 2013-06-12 11:10 1889280 —-a-w- c:\windows\system32\crypt32.dll 2013-04-23 22:55 . 2013-06-12 11:10 68096 —-a-w- c:\windows\system32\cryptsvc.dll 2013-04-23 22:55 . 2013-06-12 11:10 141312 —-a-w- c:\windows\system32\cryptnet.dll 2013-04-22 23:16 . 2013-03-16 13:26 17536 —-a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin 2013-04-16 02:34 . 2013-05-15 16:36 1455368 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Spotify Web Helper"="c:\users\JimAngehr\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2013-07-07 1104384] "Spotify"="c:\users\JimAngehr\AppData\Roaming\Spotify\Spotify.exe" [2013-07-07 4640768] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-08-08 642216] "CLVirtualDrive"="c:\program files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" [2012-07-26 491320] "RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2012-03-29 91432] "HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2012-07-09 580512] "HP CoolSense"="c:\program files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe" [2011-08-26 1342008] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "QuickFinder Scheduler"="c:\program files (x86)\WordPerfect Office X3\Programs\QFSCHD130.EXE" [2007-01-03 83568] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968] . c:\users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-24 27776968] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "EnableUIADesktopToggle"= 0 (0x0) "EnableCursorSuppression"= 1 (0x1) "ConsentPromptBehaviorUser"= 3 (0x3) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer"=wdmaud.drv . R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x] R3 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x] R3 SmbDrv;SmbDrv;c:\windows\System32\drivers\Smb_driver_AMDASF.sys;c:\windows\SYSNATIVE\drivers\Smb_driver_AMDASF.sys [x] R3 SmbDrvI;SmbDrvI;c:\windows\System32\drivers\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\drivers\Smb_driver_Intel.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\System32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] S0 amd_sata;amd_sata;c:\windows\System32\drivers\amd_sata.sys;c:\windows\SYSNATIVE\drivers\amd_sata.sys [x] S0 amd_xata;amd_xata;c:\windows\System32\drivers\amd_xata.sys;c:\windows\SYSNATIVE\drivers\amd_xata.sys [x] S0 aswRvrt;aswRvrt; [x] S0 aswVmm;aswVmm; [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 CLVirtualDrive;CLVirtualDrive;c:\windows\system32\DRIVERS\CLVirtualDrive.sys;c:\windows\SYSNATIVE\DRIVERS\CLVirtualDrive.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x] S2 APXACC;AppEx Networks Accelerator LWF;c:\windows\system32\DRIVERS\appexDrv.sys;c:\windows\SYSNATIVE\DRIVERS\appexDrv.sys [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x] S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x] S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [x] S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x] S2 lxeb_device;lxeb_device;c:\windows\system32\lxebcoms.exe;c:\windows\SYSNATIVE\lxebcoms.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW86.sys;c:\windows\SYSNATIVE\drivers\AtihdW86.sys [x] S3 RSP2STOR;Realtek PCIE CardReader Driver - P2;c:\windows\system32\DRIVERS\RtsP2Stor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsP2Stor.sys [x] S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x] S3 WirelessButtonDriver;HP Wireless Button Driver Service;c:\windows\System32\drivers\WirelessButtonDriver64.sys;c:\windows\SYSNATIVE\drivers\WirelessButtonDriver64.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] apphost REG_MULTI_SZ apphostsvc iissvcs REG_MULTI_SZ w3svc was . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-07-12 01:06 1173456 —-a-w- c:\program files (x86)\Google\Chrome\Application\28.0.1500.71\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2013-07-12 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-04 13:02] . 2013-07-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-05 16:45] . 2013-07-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-05 16:45] . 2013-07-07 c:\windows\Tasks\HPCeeScheduleForJimAngehr.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-05-09 08:58 133840 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2012-07-21 1425408] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] . ——- Supplementary Scan ——- . uStart Page = hxxp://www.bing.com uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Open with WordPerfect - c:\program files (x86)\WordPerfect Office X3\Programs\WPLauncher.hta TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\JimAngehr\AppData\Roaming\Mozilla\Firefox\Profiles\7zcy930i.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/search/search?q={searchTerms}&s_it=webpickaol-ff&s_qt=sb&tb_uuid=D1E32A0EB1E84CB199BF9D10246EAD1B&tb_oid=25-04-2013&tb_mrud=26-04-2013 FF - prefs.js: browser.startup.homepage - google.com FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q= FF - ExtSQL: 2013-07-07 18:56; [removed]; c:\program files\AVAST Software\Avast\WebRep\FF FF - user.js: extentions.y2layers.installId - 637d194c-2b91-4bea-ae27-c028e609b56d FF - user.js: extentions.y2layers.defaultEnableAppsList - DropDownDeals,buzzdock,YontooNewOffers FF - user.js: extensions.autoDisableScopes - 14 FF - user.js: network.protocol-handler.warn-external.dnupdate - false . - - - - ORPHANS REMOVED - - - - . AddRemove-Fast Free Converter - c:\program files (x86)\Fast Free Converter\uninstall.exe AddRemove-{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} - c:\users\JimAngehr\AppData\Local\SwvUpdater\Updater.exe AddRemove-{B8019B54-F9BE-490A-9619-6D06F18F129F} - c:\program files (x86)\InstallShield Installation Information\{B8019B54-F9BE-490A-9619-6D06F18F129F}\setup.exe AddRemove-{C3F3165C-74D3-6FDB-3274-14FDA8698CFA} - c:\programdata\BBRowsE2savve\uninstall.exe AddRemove-{E5B7E1B4-21FC-6765-A3D7-BA0416DC6AF7} - c:\programdata\EybooikBBriowsue\uninstall.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) @SACL=(02 0000) . Completion time: 2013-07-12 15:04:30 ComboFix-quarantined-files.txt 2013-07-12 19:04 ComboFix2.txt 2013-07-11 13:30 . Pre-Run: 538,867,605,504 bytes free Post-Run: 538,622,083,072 bytes free . - - End Of File - - C8C5E279D34C8497927545C9327B3F50 5FB38429D5D77768867C76DCBDB35194
1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Download the attached CFScript.txt and save it to the location where Combofix is.


[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Attachments:

Computer is running a lot faster these days, thank you! ComboFix 13-07-12.01 - JimAngehr 07/13/2013 8:14.3.2 - x64 Microsoft Windows 8 6.2.9200.0.1252.1.1033.18.3554.2160 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\JimAngehr\Desktop\CFScript.txt AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\MyPC Backup c:\program files (x86)\MyPC Backup\aff.conf c:\program files (x86)\MyPC Backup\mypcbackup.ico c:\users\JimAngehr\AppData\Roaming\DefaultTab . . ((((((((((((((((((((((((( Files Created from 2013-06-13 to 2013-07-13 ))))))))))))))))))))))))))))))) . . 2013-07-13 12:24 . 2013-07-13 12:24 ——– d—–w- c:\users\James\AppData\Local\temp 2013-07-13 12:24 . 2013-07-13 12:24 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-07-11 13:30 . 2013-07-13 12:26 ——– d—–w- c:\users\JimAngehr\AppData\Local\temp 2013-07-10 22:01 . 2013-04-10 22:35 1617920 —-a-w- c:\program files\Windows Journal\NBDoc.DLL 2013-07-10 22:01 . 2013-04-10 22:35 2035200 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll 2013-07-10 22:01 . 2013-04-10 22:35 1272320 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2013-07-10 22:01 . 2013-04-10 22:35 1318912 —-a-w- c:\program files\Windows Journal\JNWDRV.dll 2013-07-10 22:01 . 2013-04-10 22:35 1306112 —-a-w- c:\program files\Windows Journal\JNTFiltr.dll 2013-07-10 22:01 . 2013-04-11 04:12 1029632 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\Ink\journal.dll 2013-07-10 22:01 . 2013-04-11 04:12 1413632 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\Ink\InkObj.dll 2013-07-10 21:53 . 2013-07-10 21:53 ——– d—–w- C:\_OTL 2013-07-08 20:17 . 2013-07-08 20:17 ——– d—–w- c:\programdata\Malwarebytes 2013-07-07 22:56 . 2013-07-07 22:56 378944 —-a-w- c:\windows\system32\drivers\aswSP.sys 2013-07-07 22:56 . 2013-05-09 08:59 72016 —-a-w- c:\windows\system32\drivers\aswRdr2.sys 2013-07-07 22:56 . 2013-05-09 08:59 64288 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2013-07-07 22:56 . 2013-05-09 08:59 33400 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2013-07-07 22:56 . 2013-07-07 22:56 189936 —-a-w- c:\windows\system32\drivers\aswVmm.sys 2013-07-07 22:56 . 2013-07-07 22:56 1030952 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2013-07-07 22:56 . 2013-05-09 08:59 65336 —-a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-07-07 22:56 . 2013-05-09 08:59 80816 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-07-07 22:55 . 2013-05-09 08:58 41664 —-a-w- c:\windows\avastSS.scr 2013-07-07 10:12 . 2013-06-12 03:08 9552976 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8B905977-F17E-4550-B398-F782F419DF0B}\mpengine.dll 2013-07-04 12:33 . 2013-07-04 12:33 237744 —-a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10209.bin 2013-07-04 11:43 . 2013-05-15 22:35 144384 —-a-w- c:\windows\system32\tssdisai.dll 2013-06-23 13:01 . 2013-06-23 13:02 ——– d—–w- c:\users\JimAngehr\AppData\Local\Adobe 2013-06-16 13:11 . 2013-05-30 23:24 1257472 —-a-w- c:\windows\system32\kernel32.dll 2013-06-16 13:10 . 2013-05-23 23:01 1300992 —-a-w- c:\windows\system32\gdi32.dll 2013-06-16 13:10 . 2013-05-23 22:27 1022464 —-a-w- c:\windows\SysWow64\gdi32.dll 2013-06-16 13:10 . 2013-05-15 02:25 888320 —-a-w- c:\windows\system32\autochk.exe 2013-06-16 13:10 . 2013-05-15 02:25 542208 —-a-w- c:\windows\system32\untfs.dll 2013-06-16 13:10 . 2013-05-15 02:24 793088 —-a-w- c:\windows\SysWow64\autochk.exe 2013-06-16 13:10 . 2013-05-15 02:24 482816 —-a-w- c:\windows\SysWow64\untfs.dll 2013-06-15 12:17 . 2013-05-04 06:57 17408 —-a-w- c:\windows\system32\muifontsetup.dll 2013-06-15 12:17 . 2013-05-04 04:58 34304 —-a-w- c:\windows\SysWow64\wuapp.exe 2013-06-15 12:17 . 2013-05-04 04:57 18432 —-a-w- c:\windows\SysWow64\npmproxy.dll 2013-06-15 12:17 . 2013-05-04 04:57 14336 —-a-w- c:\windows\SysWow64\muifontsetup.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-07-10 22:08 . 2012-12-15 22:44 78185248 —-a-w- c:\windows\system32\MRT.exe 2013-06-27 22:04 . 2013-02-11 14:29 78200 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-27 22:04 . 2013-02-11 14:29 693112 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-05-15 22:37 . 2013-06-12 11:09 44032 —-a-w- c:\windows\SysWow64\UXInit.dll 2013-05-15 22:35 . 2013-06-12 11:09 53760 —-a-w- c:\windows\system32\UXInit.dll 2013-05-15 16:32 . 2012-07-26 08:13 22240 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2013-05-14 13:14 . 2013-06-12 11:09 2706432 —-a-w- c:\windows\system32\mshtml.tlb 2013-05-14 09:23 . 2013-06-12 11:09 2706432 —-a-w- c:\windows\SysWow64\mshtml.tlb 2013-05-09 08:58 . 2012-11-02 01:52 287840 —-a-w- c:\windows\system32\aswBoot.exe 2013-05-04 07:45 . 2013-06-12 11:10 2233600 —-a-w- c:\windows\system32\drivers\tcpip.sys 2013-05-02 15:29 . 2012-12-21 21:51 278800 ——w- c:\windows\system32\MpSigStub.exe 2013-04-28 22:28 . 2013-06-12 11:09 915968 —-a-w- c:\windows\system32\uxtheme.dll 2013-04-27 05:20 . 2013-06-12 11:10 733184 —-a-w- c:\windows\system32\win32spl.dll 2013-04-23 23:13 . 2013-06-12 11:10 1013248 —-a-w- c:\windows\SysWow64\certutil.exe 2013-04-23 23:12 . 2013-06-12 11:10 1569792 —-a-w- c:\windows\SysWow64\crypt32.dll 2013-04-23 23:12 . 2013-06-12 11:10 109056 —-a-w- c:\windows\SysWow64\cryptnet.dll 2013-04-23 22:56 . 2013-06-12 11:10 1255936 —-a-w- c:\windows\system32\certutil.exe 2013-04-23 22:55 . 2013-06-12 11:10 1889280 —-a-w- c:\windows\system32\crypt32.dll 2013-04-23 22:55 . 2013-06-12 11:10 68096 —-a-w- c:\windows\system32\cryptsvc.dll 2013-04-23 22:55 . 2013-06-12 11:10 141312 —-a-w- c:\windows\system32\cryptnet.dll 2013-04-22 23:16 . 2013-03-16 13:26 17536 —-a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin 2013-04-16 02:34 . 2013-05-15 16:36 1455368 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Spotify Web Helper"="c:\users\JimAngehr\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2013-07-07 1104384] "Spotify"="c:\users\JimAngehr\AppData\Roaming\Spotify\Spotify.exe" [2013-07-07 4640768] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-08-08 642216] "CLVirtualDrive"="c:\program files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" [2012-07-26 491320] "RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2012-03-29 91432] "HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2012-07-09 580512] "HP CoolSense"="c:\program files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe" [2011-08-26 1342008] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "QuickFinder Scheduler"="c:\program files (x86)\WordPerfect Office X3\Programs\QFSCHD130.EXE" [2007-01-03 83568] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968] . c:\users\JimAngehr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-24 27776968] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "EnableUIADesktopToggle"= 0 (0x0) "EnableCursorSuppression"= 1 (0x1) "ConsentPromptBehaviorUser"= 3 (0x3) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer"=wdmaud.drv . R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x] R3 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x] R3 SmbDrv;SmbDrv;c:\windows\System32\drivers\Smb_driver_AMDASF.sys;c:\windows\SYSNATIVE\drivers\Smb_driver_AMDASF.sys [x] R3 SmbDrvI;SmbDrvI;c:\windows\System32\drivers\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\drivers\Smb_driver_Intel.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\System32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] S0 amd_sata;amd_sata;c:\windows\System32\drivers\amd_sata.sys;c:\windows\SYSNATIVE\drivers\amd_sata.sys [x] S0 amd_xata;amd_xata;c:\windows\System32\drivers\amd_xata.sys;c:\windows\SYSNATIVE\drivers\amd_xata.sys [x] S0 aswRvrt;aswRvrt; [x] S0 aswVmm;aswVmm; [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 CLVirtualDrive;CLVirtualDrive;c:\windows\system32\DRIVERS\CLVirtualDrive.sys;c:\windows\SYSNATIVE\DRIVERS\CLVirtualDrive.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x] S2 APXACC;AppEx Networks Accelerator LWF;c:\windows\system32\DRIVERS\appexDrv.sys;c:\windows\SYSNATIVE\DRIVERS\appexDrv.sys [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x] S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x] S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [x] S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x] S2 lxeb_device;lxeb_device;c:\windows\system32\lxebcoms.exe;c:\windows\SYSNATIVE\lxebcoms.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW86.sys;c:\windows\SYSNATIVE\drivers\AtihdW86.sys [x] S3 RSP2STOR;Realtek PCIE CardReader Driver - P2;c:\windows\system32\DRIVERS\RtsP2Stor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsP2Stor.sys [x] S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x] S3 WirelessButtonDriver;HP Wireless Button Driver Service;c:\windows\System32\drivers\WirelessButtonDriver64.sys;c:\windows\SYSNATIVE\drivers\WirelessButtonDriver64.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] apphost REG_MULTI_SZ apphostsvc iissvcs REG_MULTI_SZ w3svc was . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-07-12 01:06 1173456 —-a-w- c:\program files (x86)\Google\Chrome\Application\28.0.1500.71\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2013-07-13 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-04 13:02] . 2013-07-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-05 16:45] . 2013-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-05 16:45] . 2013-07-07 c:\windows\Tasks\HPCeeScheduleForJimAngehr.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-05-09 08:58 133840 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 —-a-w- c:\users\JimAngehr\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2012-07-21 1425408] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] . ——- Supplementary Scan ——- . uStart Page = hxxp://www.bing.com uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Open with WordPerfect - c:\program files (x86)\WordPerfect Office X3\Programs\WPLauncher.hta TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\JimAngehr\AppData\Roaming\Mozilla\Firefox\Profiles\7zcy930i.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/search/search?q={searchTerms}&s_it=webpickaol-ff&s_qt=sb&tb_uuid=D1E32A0EB1E84CB199BF9D10246EAD1B&tb_oid=25-04-2013&tb_mrud=26-04-2013 FF - prefs.js: browser.startup.homepage - google.com FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q= FF - ExtSQL: 2013-07-07 18:56; [removed]; c:\program files\AVAST Software\Avast\WebRep\FF . - - - - ORPHANS REMOVED - - - - . AddRemove-Fast Free Converter - c:\program files (x86)\Fast Free Converter\uninstall.exe AddRemove-{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} - c:\users\JimAngehr\AppData\Local\SwvUpdater\Updater.exe AddRemove-{B8019B54-F9BE-490A-9619-6D06F18F129F} - c:\program files (x86)\InstallShield Installation Information\{B8019B54-F9BE-490A-9619-6D06F18F129F}\setup.exe AddRemove-{C3F3165C-74D3-6FDB-3274-14FDA8698CFA} - c:\programdata\BBRowsE2savve\uninstall.exe AddRemove-{E5B7E1B4-21FC-6765-A3D7-BA0416DC6AF7} - c:\programdata\EybooikBBriowsue\uninstall.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) @SACL=(02 0000) . Completion time: 2013-07-13 08:45:48 ComboFix-quarantined-files.txt 2013-07-13 12:45 ComboFix2.txt 2013-07-12 19:04 ComboFix3.txt 2013-07-11 13:30 . Pre-Run: 538,724,352,000 bytes free Post-Run: 538,618,707,968 bytes free . - - End Of File - - 210422CB18D46F9E549563986C905C56 5FB38429D5D77768867C76DCBDB35194
Looks good!

Please go to here to run the online scannner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.
Ran the scan and it seemed to find a lot of stuff. Incidentally, it seems only to run online on internet explorer, otherwise you have to download a copy of the scanner onto the computer. I went to use internet explorer when I was given that message, and found that my internet explorer does not work at all (we never use it). It goes to the bing home page, but then you can't go anywhere else - you type in an address into the address bar, hit enter and nothing happens. C:\Program Files (x86)\TornTV.com\uninst.exe Win32/Adware.1ClickDownload.J application C:\Program Files (x86)\Yontoo\YontooIEClient.dll a variant of Win32/Adware.Yontoo.A application C:\Program Files (x86)\Yontoo\YontooLayers.crx JS/Adware.Yontoo.A application C:\ProgramData\Tarma Installer\{68F250EA-9638-4DCF-96C4-D68CC340EC48}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application C:\Users\All Users\Tarma Installer\{68F250EA-9638-4DCF-96C4-D68CC340EC48}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application C:\Users\All Users\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0\background.html JS/Adware.Yontoo.A application C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0\yl.js JS/Adware.Yontoo.A application C:\Users\JimAngehr\Downloads\Firefox_Setup.exe a variant of Win32/Adware.iBryte.G application C:\Users\JimAngehr\Downloads\GoogleChromeExtensionUpdate_m5.exe multiple threats C:\Users\JimAngehr\Downloads\GoogleChromeExtensionUpdate_m6.exe multiple threats C:\Users\JimAngehr\Downloads\JazzPlanet)Miles_Davis-The_Complete_Live_at_the_Plugged_Nickel_19658CD_UF_SPG (1).exe multiple threats C:\Users\JimAngehr\Downloads\JazzPlanet)Miles_Davis-The_Complete_Live_at_the_Plugged_Nickel_19658CD_UF_SPG.exe multiple threats C:\Users\JimAngehr\Downloads\Miles_Davis_-_Complete_at_the_Plugged_Nickel_(8CD)_(1995).exe multiple threats C:\Windows\WinSxS\amd64_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.2.9200.20521_none_2ea2287def6db600\sdbinst.exe probably unknown STEALTH.POLY.CRYPT.TSR.DRIVER virus C:\_OTL\MovedFiles\07102013_175356\C_ProgramData\BBRowsE2savve\5179416ce7628.dll a variant of Win32/Adware.MultiPlug.I application C:\_OTL\MovedFiles\07102013_175356\C_ProgramData\EybooikBBriowsue\5179419ef2e8c.dll a variant of Win32/Adware.MultiPlug.I application C:\_OTL\MovedFiles\07102013_175356\C_Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\anokniebcoameopaknmpbhaaoedjajik\1\5179416ce73ca7.54540579.js Win32/Adware.MultiPlug.H application C:\_OTL\MovedFiles\07102013_175356\C_Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\niieikgjphnahhnnmdheblakpelnfgaj\1\5179419ef2c4a9.81363360.js Win32/Adware.MultiPlug.H application
Combofix´s Add-Remove Programs.txt

  • Hit the Windows- and the R-key simultanously..
  • Copy the following command into the text field:
  • C:\Qoobox\Add-Remove Programs.txt
  • Hit OK.
  • A textfile will open, please post up its content.
4 Elements II Adobe Acrobat 4.0 Adobe Flash Player 11 Plugin Adobe Shockwave Player 11.6 AMD VISION Engine Control Center Apple Application Support Apple Software Update avast! Free Antivirus BBRowsE2savve Bejeweled 3 BibleWorks 5 BitTorrent Build-a-lot 4 - Power Source Catalyst Control Center - Branding Catalyst Control Center Graphics Previews Common Catalyst Control Center InstallProxy Catalyst Control Center Localization All CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish Chuzzle Deluxe Cradle Of Egypt Collector's Edition Cradle of Rome 2 CyberLink LabelPrint CyberLink Media Suite 10 CyberLink PhotoDirector CyberLink Power2Go 8 CyberLink PowerDirector 10 CyberLink PowerDVD CyberLink YouCam D3DX10 Download Updater (AOL Inc.) Dropbox EybooikBBriowsue Farm Frenzy Fast Free Converter FATE: The Cursed King Final Drive Fury FLAC 1.2.1b (remove only) FlatOut 2 Google Chrome Google Update Helper Governor of Poker 2 Premium Edition Hewlett-Packard ACLM.NET v1.2.0.0 Hoyle Card Games HP Connected Music (Meridian - installer) HP CoolSense HP Customer Experience Enhancements HP Documentation HP Games HP MyRoom HP Quick Launch HP Recovery Manager HP Software Framework HP Support Assistant HP Utility Center HP Wireless Button Driver IDT Audio Java 7 Update 13 Java Auto Updater Jewel Match 3 John Deere Drive Green Luxor Evolved Mahjongg Dimensions Deluxe: Tiles in Time Microsoft Office Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Excel MUI (English) 2007 Microsoft Office Home and Student 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft VC9 runtime libraries Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 Mortimer Beckett and the Crimson Thief Premium Edition Mozilla Firefox 22.0 (x86 en-US) Mozilla Maintenance Service MSVCRT Mystery P.I. - Curious Case of Counterfeit Cove Peggle Nights Penguins! Polar Bowler Polar Golfer Price Check by AOL Qualcomm Atheros Driver Installation Program QuickTime Realtek Ethernet Controller Driver Realtek PCIE Card Reader Roads of Rome 3 Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687309) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition Software Version Updater Spotify swMSM Tales of Lagoona TornTV Update for 2007 Microsoft Office System (KB967642) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Update Installer for WildTangent Games App Vacation Quest™ - Australia WildTangent Games WildTangent Games App Windows Live Communications Platform Windows Live Essentials Windows Live Installer Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources Windows Migration Assistant WordPerfect Office X3 Zoombinis Mountain Rescue™ Zuma's Revenge
Add-/remove programms

Click on start–>control panel.

Vista/7: Open Programs and Features
XP: Open add/remove programs

Search for and remove the following programs

BBRowsE2savve
EybooikBBriowsue
Price Check by AOL
swMSM
TornTV


Close the window.



Fix with OTL

Please double-click OTL.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :FILES
    C:\Program Files (x86)\TornTV.com
    C:\Program Files (x86)\Yontoo
    C:\ProgramData\Tarma Installer\{68F250EA-9638-4DCF-96C4-D68CC340EC48}
    C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
    C:\Users\All Users\Tarma Installer\{68F250EA-9638-4DCF-96C4-D68CC340EC48}
    C:\Users\All Users\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
    C:\Users\JimAngehr\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc\1.0.2_0
    C:\Users\JimAngehr\Downloads\Firefox_Setup.exe
    C:\Users\JimAngehr\Downloads\GoogleChromeExtensionUpdate_m5.exe
    C:\Users\JimAngehr\Downloads\GoogleChromeExtensionUpdate_m6.exe
    C:\Users\JimAngehr\Downloads\JazzPlanet)Miles_Davis-The_Complete_Live_at_the_Plugged_Nickel_19658CD_UF_SPG (1).exe
    C:\Users\JimAngehr\Downloads\JazzPlanet)Miles_Davis-The_Complete_Live_at_the_Plugged_Nickel_19658CD_UF_SPG.exe
    C:\Users\JimAngehr\Downloads\Miles_Davis_-_Complete_at_the_Plugged_Nickel_(8CD)_(1995).exe
    C:\Windows\WinSxS\amd64_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.2.9200.20521_none_2ea2287def6db600\sdbinst.exe
    :commands
    [emptytemp]

  • Return to OTL, right click in the "Custom Scans/Fixes" section and choose Paste.
  • Click the red Run Fix button.
  • OTL may ask to reboot the machine. Please do so.
  • If OTL did not reboot the machine, click OK and the log will open. Post the contents of the log in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.

    Also post a new OTL log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI