This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Oyodomo.com Redirect [Closed]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OK, you are correct! Sorry my bad!

Files\Folders moved on Reboot…
File\Folder C:\Users\Mark Hudson\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found!
File\Folder C:\Users\Mark Hudson\AppData\Local\Temp\MMDUtl.log not found!
C:\Users\Mark Hudson\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…

OTL RUN AFTER FIX

OTL logfile created on: 8/1/2013 10:44:18 PM - Run 5
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Mark Hudson\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.73 Gb Total Physical Memory | 0.47 Gb Available Physical Memory | 26.89% Memory free
3.46 Gb Paging File | 1.73 Gb Available in Paging File | 49.98% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 284.99 Gb Total Space | 199.38 Gb Free Space | 69.96% Space Free | Partition Type: NTFS
Drive E: | 982.13 Mb Total Space | 842.88 Mb Free Space | 85.82% Space Free | Partition Type: FAT

Computer Name: MARKHUDSON-PC | User Name: Mark Hudson | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Mark Hudson\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Microsoft Corp.)
PRC - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
PRC - C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Neat\exec\NeatStartupService.exe (The Neat Company)
PRC - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LMworker.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
PRC - C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\83cfe0422e7e54f3f00107c15a63f1b4\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\6da2afd0e57708d41892d9d3e32ba5a3\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\f3770f9a13d7516e4c03f23dbd319cba\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\4572de8445038600e4552429b18fbe32\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\7546a01feb9d477570b883eec56cc673\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\112f6448b7434699af4bcc05f25ce12b\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\64b92e2a22bb8c1e86486bd22828acc5\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\c1c41a9e1a25999e74defafecb2aa0bc\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\89445d5b924ad94744d00f1b6cd2285d\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a01e07e47ecdd94ae099e8c4bf650516\mscorlib.ni.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (Live Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
SRV:64bit: - (ePowerSvc) – C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (CxAudMsg) – C:\Windows\SysNative\CxAudMsg64.exe (Conexant Systems Inc.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (BingDesktopUpdate) – C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Microsoft Corp.)
SRV - (NAV) – C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccSvcHst.exe (Symantec Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Neat Startup Service) – C:\Program Files (x86)\Neat\exec\NeatStartupService.exe (The Neat Company)
SRV - (RealNetworks Downloader Resolver Service) – C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (UWS HiPriv Services) – C:\Program Files (x86)\UltiDev\Web Server\UWS.HighPrivilegeUtilities.exe (UltiDev LLC)
SRV - (UltiDev Web Server Pro) – C:\Program Files (x86)\UltiDev\Web Server\UltiDev.WebServer.Monitor.exe (UltiDev LLC)
SRV - (UWS LoPriv Services) – C:\Program Files (x86)\UltiDev\Web Server\UWS.LowPrivilegeUtilities.exe (UltiDev LLC)
SRV - (DsiWMIService) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (NSL) – C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe (Symantec Corporation)
SRV - (HP DS Service) – C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe (Hewlett-Packard Company)
SRV - (HP LaserJet Service) – C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
SRV - (GamesAppService) – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (EgisTec Ticket Service) – C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe (Egis Technology Inc. )
SRV - (NOBU) – C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (RS_Service) – C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
SRV - (GREGService) – C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symds64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symnets.sys (Symantec Corporation)
DRV:64bit: - (ccSet_NAV) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\ccsetx64.sys (Symantec Corporation)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\ironx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (tapklink) – C:\Windows\SysNative\drivers\tapklink.sys (Faveset LLC)
DRV:64bit: - (HPFXBULKLEDM) – C:\Windows\SysNative\drivers\hppdbulkio.sys (Hewlett Packard)
DRV:64bit: - (mwlPSDVDisk) – C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDFilter) – C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDNServ) – C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:64bit: - (CnxtHdAudService) – C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (L1C) – C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\VirusDefs\20130801.021\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\VirusDefs\20130801.021\eng64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\IPSDefs\20130801.001\IDSviA64.sys (Symantec Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (lowpp) – C:\Windows\SysWOW64\drivers\lowpp.sys (Lowrance Electronics, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.arcpointlabs.com/south-san-antonio
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {E9DB9E7B-A275-41D1-8158-D0423FBEBDEB}
IE - HKCU\..\SearchScopes\{E9DB9E7B-A275-41D1-8158-D0423FBEBDEB}: "URL" = http://www.google.com/cse?cx=partner-pub-3…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}:10.15.0.62
FF - prefs.js..extensions.enabledAddons: {739df940-c5ee-4bab-9d7e-270894ae687a}:10.14.380.14
FF - prefs.js..browser.startup.homepage: "http://www.google.com/cse?cx=partner-pub-3540673482024757:xbhdw8hkfz5&ie;=ISO-8859-1&q;=&sa;=Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/cse?cx=partner-pub-3540673482024757:xbhdw8hkfz5&ie;=ISO-8859-1&q;=&sa;=Search"
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@citrixonline.com/appdetectorplugin: C:\Users\Mark Hudson\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Mark Hudson\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Mark Hudson\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\PROGRAM FILES\UPDATER BY SWEETPACKS\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{203FB6B2-2E1E-4474-863B-4C483ECCE78E}: C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_1.2.0.6\coFFNST\ [2011/08/19 14:23:32 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2012/12/22 11:14:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2012/12/22 11:14:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\IPSFFPlgn\ [2013/04/23 00:02:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/05/13 10:22:09 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 11.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013/05/13 10:22:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 11.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins

[2013/07/18 10:40:36 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Extensions
[2011/06/23 10:48:22 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013/07/30 09:47:36 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions
[2013/07/18 10:40:37 | 000,000,000 | —D | M] (TopArcadeHits) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{0113D088-8ED1-468C-B225-585A9C53B5E3}
[2013/07/30 09:47:32 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}
[2013/07/24 10:13:09 | 000,001,793 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\Bing.xml
[2013/03/27 23:15:47 | 000,002,356 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\startnow.xml
[2012/10/19 10:38:22 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
File not found (No name found) – C:\USERS\MARK HUDSON\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\QJ5BZ23M.DEFAULT\EXTENSIONS\{739DF940-C5EE-4BAB-9D7E-270894AE687A}
[2011/12/21 02:24:52 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/12/20 23:30:41 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/12/20 23:30:41 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter}
CHR - homepage: http://google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.72\gcswf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7896_0\npSkypeChromePlugin.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: TopArcadeHits = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdgdlcjhlbaphcjmagicjhhgfnkiihp\1.0.0_0\
CHR - Extension: RealDownloader = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0\
CHR - Extension: Skype Extension = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7896_0\

O1 HOSTS File: ([2013/07/29 23:24:08 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll File not found
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Norton Safe Web Lite BHO) - {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Safe Web Lite) - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Safe Web Lite) - {30CEEEA2-3742-40E4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe (Microsoft Corp.)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKCU..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: hostpilot.com ([ARCpoint] https in Local intranet)
O16 - DPF: {42B182F9-3F08-484E-9913-07193A5D36A9} http://192.168.2.119/web/WebClient.cab (WebClient Control)
O16 - DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} http://www.gunbroker.com/WebResource.axd?d…230999680000000 (Image Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://labcorp.webex.com/client/WBXclient-…ng/ieatgpc1.cab (GpcContainer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F22A54D-AEDC-4C91-AD17-7CB0657B12F0}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5BFF0016-01B7-4FE7-8946-570FA6A6F5DC}: DhcpNameServer = 192.168.2.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AF9E37F2-B89B-4AA7-BFEE-EEB3BF7AD7F4}: DhcpNameServer = [removed]
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/08/01 22:11:14 | 000,000,000 | —D | C] – C:\_OTL
[2013/07/30 09:57:10 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/07/30 09:41:07 | 000,562,042 | —- | C] (Oleg N. Scherbakov) – C:\Users\Mark Hudson\Desktop\JRT.exe
[2013/07/29 23:24:25 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/07/29 22:41:44 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/07/29 22:41:44 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/07/29 22:41:44 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/07/29 22:37:43 | 000,000,000 | —D | C] – C:\Qoobox
[2013/07/29 22:35:26 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/07/29 22:33:22 | 005,095,176 | R— | C] (Swearware) – C:\Users\Mark Hudson\Desktop\ComboFix.exe
[2013/07/29 21:24:21 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/07/29 21:07:52 | 002,237,968 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Mark Hudson\Desktop\tdsskiller.exe
[2013/07/29 21:01:26 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\Documents\Virus Removal
[2013/07/29 18:28:10 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Mark Hudson\Desktop\aswMBR.exe
[2013/07/28 20:36:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013/07/28 11:50:07 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Mark Hudson\Desktop\OTL.exe
[2013/07/24 11:21:34 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Roaming\Malwarebytes
[2013/07/24 11:21:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/07/24 11:21:04 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/07/24 11:21:01 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/07/24 11:21:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/07/24 11:20:21 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Local\Programs
[2013/07/23 16:52:42 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Local\NPE
[2013/07/18 15:09:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealZeal Soft
[2013/07/18 15:08:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\RZPPTCodec
[2013/07/18 15:08:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\RealZeal Soft
[2013/07/18 10:48:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIViewer
[2013/07/18 10:48:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\AIViewer
[2013/07/18 10:26:26 | 000,033,792 | —- | C] (IncrediMail, Ltd.) – C:\Windows\SysNative\ImHttpComm.dll
[2013/07/11 14:35:32 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/07/11 14:35:31 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/07/11 14:35:29 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/07/11 14:35:29 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/07/11 14:35:28 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/07/11 14:35:28 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/07/11 14:35:28 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/07/11 14:35:28 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/07/11 14:35:28 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/07/11 14:35:28 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/07/11 14:35:28 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/07/11 14:35:24 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/07/11 14:35:23 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/07/11 14:35:23 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/07/11 14:35:21 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/07/11 11:00:42 | 000,624,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qedit.dll
[2013/07/11 11:00:42 | 000,509,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qedit.dll
[2013/07/11 11:00:40 | 001,887,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/07/11 11:00:39 | 001,620,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/07/11 10:59:26 | 001,643,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/08/01 22:48:02 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/08/01 22:45:27 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/01 22:45:27 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/01 22:36:41 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/01 22:36:29 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/01 22:36:20 | 1392,693,248 | -HS- | M] () – C:\hiberfil.sys
[2013/08/01 16:35:01 | 000,000,932 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1681885816-2431122675-287609382-1001UA.job
[2013/08/01 16:34:01 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/01 16:23:25 | 000,002,403 | —- | M] () – C:\Users\Mark Hudson\Desktop\Google Chrome.lnk
[2013/08/01 10:35:02 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1681885816-2431122675-287609382-1001Core.job
[2013/07/31 21:18:35 | 000,797,524 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/07/31 21:18:35 | 000,674,654 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/07/31 21:18:35 | 000,125,872 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/07/30 09:41:28 | 000,562,042 | —- | M] (Oleg N. Scherbakov) – C:\Users\Mark Hudson\Desktop\JRT.exe
[2013/07/30 09:39:20 | 000,666,633 | —- | M] () – C:\Users\Mark Hudson\Desktop\adwcleaner.exe
[2013/07/29 23:24:08 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/07/29 22:33:42 | 005,095,176 | R— | M] (Swearware) – C:\Users\Mark Hudson\Desktop\ComboFix.exe
[2013/07/29 21:24:05 | 415,597,301 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/07/29 21:08:13 | 002,237,968 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Mark Hudson\Desktop\tdsskiller.exe
[2013/07/29 18:57:11 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Mark Hudson\Desktop\aswMBR.exe
[2013/07/28 20:36:42 | 000,002,216 | —- | M] () – C:\Users\Public\Desktop\Google Earth.lnk
[2013/07/28 12:47:01 | 000,001,023 | —- | M] () – C:\Users\Mark Hudson\Desktop\OTL - Shortcut.lnk
[2013/07/28 11:50:18 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Mark Hudson\Desktop\OTL.exe
[2013/07/27 10:07:40 | 000,609,104 | —- | M] () – C:\Users\Mark Hudson\Documents\AnalyticalTox130727.pdf
[2013/07/27 10:06:01 | 000,609,104 | —- | M] () – C:\Users\Mark Hudson\Documents\AnalyticalTox.pdf
[2013/07/24 11:21:11 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/07/23 10:27:00 | 000,020,992 | —- | M] () – C:\Users\Mark Hudson\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/22 12:20:29 | 000,000,358 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\LoginSetting.xml
[2013/07/22 12:20:29 | 000,000,139 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\GeneralSetting.xml
[2013/07/22 12:10:02 | 000,000,018 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\LocationSetting.xml
[2013/07/18 15:09:18 | 000,002,805 | —- | M] () – C:\Users\Public\Desktop\RZ PowerPoint Converter.lnk
[2013/07/18 15:04:05 | 026,710,528 | —- | M] () – C:\Users\Mark Hudson\Desktop\RZPowerPointConverter.msi
[2013/07/18 10:48:21 | 000,000,947 | —- | M] () – C:\Users\Public\Desktop\AI Viewer.lnk
[2013/07/18 10:41:08 | 000,000,258 | RHS- | M] () – C:\Users\Mark Hudson\ntuser.pol
[2013/07/16 22:01:33 | 000,001,732 | —- | M] () – C:\Users\Mark Hudson\Desktop\DvrClient.cfg
[2013/07/16 09:50:52 | 000,006,087 | —- | M] () – C:\Users\Mark Hudson\Desktop\Price List 1307 - Shortcut.lnk
[2013/07/15 15:01:01 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/07/15 15:01:01 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/07/11 15:37:03 | 000,417,408 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/07/30 09:39:15 | 000,666,633 | —- | C] () – C:\Users\Mark Hudson\Desktop\adwcleaner.exe
[2013/07/29 22:41:44 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/07/29 22:41:44 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/07/29 22:41:44 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/07/29 22:41:44 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/07/29 22:41:44 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/07/29 21:24:05 | 415,597,301 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/07/28 20:36:41 | 000,002,216 | —- | C] () – C:\Users\Public\Desktop\Google Earth.lnk
[2013/07/28 12:47:01 | 000,001,023 | —- | C] () – C:\Users\Mark Hudson\Desktop\OTL - Shortcut.lnk
[2013/07/27 10:07:38 | 000,609,104 | —- | C] () – C:\Users\Mark Hudson\Documents\AnalyticalTox130727.pdf
[2013/07/27 10:05:57 | 000,609,104 | —- | C] () – C:\Users\Mark Hudson\Documents\AnalyticalTox.pdf
[2013/07/24 11:21:11 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/07/18 15:30:50 | 000,020,992 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/18 15:09:15 | 000,002,805 | —- | C] () – C:\Users\Public\Desktop\RZ PowerPoint Converter.lnk
[2013/07/18 15:04:30 | 026,710,528 | —- | C] () – C:\Users\Mark Hudson\Desktop\RZPowerPointConverter.msi
[2013/07/18 10:48:21 | 000,000,947 | —- | C] () – C:\Users\Public\Desktop\AI Viewer.lnk
[2013/07/18 10:41:08 | 000,000,258 | RHS- | C] () – C:\Users\Mark Hudson\ntuser.pol
[2013/07/18 10:26:26 | 001,645,360 | —- | C] () – C:\Windows\SysNative\dmwu.exe
[2013/07/16 09:50:52 | 000,006,087 | —- | C] () – C:\Users\Mark Hudson\Desktop\Price List 1307 - Shortcut.lnk
[2013/05/22 20:43:52 | 000,030,568 | —- | C] () – C:\Windows\MusiccityDownload.exe
[2013/05/22 20:43:48 | 000,974,848 | —- | C] () – C:\Windows\SysWow64\cis-2.4.dll
[2013/05/22 20:43:48 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2013/05/22 20:43:48 | 000,065,536 | —- | C] () – C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2013/05/22 20:43:48 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\issacapi_se-2.3.dll
[2013/04/19 10:44:01 | 000,000,358 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\LoginSetting.xml
[2012/10/02 09:00:38 | 000,000,000 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\bibstats
[2012/09/07 08:12:25 | 000,001,940 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2012/07/23 13:22:39 | 000,000,094 | —- | C] () – C:\Windows\brpcfx.ini
[2012/07/23 13:22:38 | 000,000,242 | —- | C] () – C:\Windows\Brpfx04a.ini
[2012/07/23 13:20:41 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\BrMuSNMP.dll
[2012/07/23 13:20:39 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2012/07/23 13:20:39 | 000,000,000 | —- | C] () – C:\Windows\brdfxspd.dat
[2012/06/10 21:12:47 | 000,004,096 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\keyfile3.drm
[2012/03/27 22:35:43 | 000,000,139 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\GeneralSetting.xml
[2012/03/27 22:34:52 | 000,000,018 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\LocationSetting.xml
[2012/02/19 17:31:33 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2012/02/09 18:20:06 | 000,102,912 | —- | C] () – C:\Windows\agent_x64.exe
[2011/11/17 15:12:42 | 000,000,247 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\kclientgui.ini
[2011/10/10 12:41:33 | 000,000,426 | —- | C] () – C:\Windows\BRWMARK.INI
[2011/10/10 12:41:33 | 000,000,034 | —- | C] () – C:\Windows\SysWow64\BD7220.DAT
[2011/07/29 11:01:50 | 000,007,598 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\Resmon.ResmonCfg

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 00:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/26 23:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 22:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

< End of report >
Doesn't seem right to me. The ones that I want to remove don't seem to go away. Let's try it again.

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\PROGRAM FILES\UPDATER BY SWEETPACKS\FIREFOX
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\Program Files\Updater By SweetPacks\Firefox
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\Program Files\Updater By SweetPacks\Firefox
    [2013/05/05 12:54:18 | 000,001,096 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\search-spin-customized-web-search.xml
    O2 - BHO: (FreePriceAlerts) - {A7C0A55C-300E-4193-8FB5-5DB8E6533D35} - C:\Program Files (x86)\FreePriceAlerts\vbobho.dll (FreePriceAlerts.com)
    
    :Commands
    [EMPTYTEMP]
    [CLEARALLRESTOREPOINTS]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post Fix OTL log as well as a new OTL log by rerunning it after reboot without custom scans script.
OK,

2nd attempt. I think I got it right.

Mark

All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E9E3331-D360-4f87-8803-52DE43566502}\ not found.
File C:\Program Files\Updater By SweetPacks\Firefox not found.
Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E9E3331-D360-4f87-8803-52DE43566502}\ not found.
File C:\Program Files\Updater By SweetPacks\Firefox not found.
File C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\search-spin-customized-web-search.xml not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7C0A55C-300E-4193-8FB5-5DB8E6533D35}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7C0A55C-300E-4193-8FB5-5DB8E6533D35}\ not found.
File C:\Program Files (x86)\FreePriceAlerts\vbobho.dll not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Mark Hudson
->Temp folder emptied: 24031 bytes
->Temporary Internet Files folder emptied: 4863273 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 135579402 bytes
->Flash cache emptied: 12982 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 540996 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 5222356 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 42287446 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 180.00 mb

Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.69.0 log created on 08022013_092610

Files\Folders moved on Reboot…
C:\Users\Mark Hudson\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Mark Hudson\AppData\Local\Temp\MMDUtl.log moved successfully.
C:\Users\Mark Hudson\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
File move failed. C:\Windows\temp\dsiwmis.log scheduled to be moved on reboot.
File move failed. C:\Windows\temp\LMutilps.log scheduled to be moved on reboot.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…





OTL logfile created on: 8/2/2013 9:43:58 AM - Run 6
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Mark Hudson\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.73 Gb Total Physical Memory | 0.68 Gb Available Physical Memory | 39.48% Memory free
3.46 Gb Paging File | 1.86 Gb Available in Paging File | 53.73% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 284.99 Gb Total Space | 204.93 Gb Free Space | 71.91% Space Free | Partition Type: NTFS
Drive E: | 982.13 Mb Total Space | 842.88 Mb Free Space | 85.82% Space Free | Partition Type: FAT

Computer Name: MARKHUDSON-PC | User Name: Mark Hudson | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Mark Hudson\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Microsoft Corp.)
PRC - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
PRC - C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Neat\exec\NeatStartupService.exe (The Neat Company)
PRC - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LMworker.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
PRC - C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\83cfe0422e7e54f3f00107c15a63f1b4\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\6da2afd0e57708d41892d9d3e32ba5a3\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\f3770f9a13d7516e4c03f23dbd319cba\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\4572de8445038600e4552429b18fbe32\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\7546a01feb9d477570b883eec56cc673\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\112f6448b7434699af4bcc05f25ce12b\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\64b92e2a22bb8c1e86486bd22828acc5\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\c1c41a9e1a25999e74defafecb2aa0bc\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\89445d5b924ad94744d00f1b6cd2285d\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a01e07e47ecdd94ae099e8c4bf650516\mscorlib.ni.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (Live Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
SRV:64bit: - (ePowerSvc) – C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (CxAudMsg) – C:\Windows\SysNative\CxAudMsg64.exe (Conexant Systems Inc.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (BingDesktopUpdate) – C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Microsoft Corp.)
SRV - (NAV) – C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccSvcHst.exe (Symantec Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Neat Startup Service) – C:\Program Files (x86)\Neat\exec\NeatStartupService.exe (The Neat Company)
SRV - (RealNetworks Downloader Resolver Service) – C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (UWS HiPriv Services) – C:\Program Files (x86)\UltiDev\Web Server\UWS.HighPrivilegeUtilities.exe (UltiDev LLC)
SRV - (UltiDev Web Server Pro) – C:\Program Files (x86)\UltiDev\Web Server\UltiDev.WebServer.Monitor.exe (UltiDev LLC)
SRV - (UWS LoPriv Services) – C:\Program Files (x86)\UltiDev\Web Server\UWS.LowPrivilegeUtilities.exe (UltiDev LLC)
SRV - (DsiWMIService) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (NSL) – C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe (Symantec Corporation)
SRV - (HP DS Service) – C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe (Hewlett-Packard Company)
SRV - (HP LaserJet Service) – C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
SRV - (GamesAppService) – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (EgisTec Ticket Service) – C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe (Egis Technology Inc. )
SRV - (NOBU) – C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (RS_Service) – C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
SRV - (GREGService) – C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symds64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symnets.sys (Symantec Corporation)
DRV:64bit: - (ccSet_NAV) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\ccsetx64.sys (Symantec Corporation)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\ironx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (tapklink) – C:\Windows\SysNative\drivers\tapklink.sys (Faveset LLC)
DRV:64bit: - (HPFXBULKLEDM) – C:\Windows\SysNative\drivers\hppdbulkio.sys (Hewlett Packard)
DRV:64bit: - (mwlPSDVDisk) – C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDFilter) – C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDNServ) – C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:64bit: - (CnxtHdAudService) – C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (L1C) – C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\VirusDefs\20130801.034\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\VirusDefs\20130801.034\eng64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\IPSDefs\20130801.001\IDSviA64.sys (Symantec Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (lowpp) – C:\Windows\SysWOW64\drivers\lowpp.sys (Lowrance Electronics, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.arcpointlabs.com/south-san-antonio
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {E9DB9E7B-A275-41D1-8158-D0423FBEBDEB}
IE - HKCU\..\SearchScopes\{E9DB9E7B-A275-41D1-8158-D0423FBEBDEB}: "URL" = http://www.google.com/cse?cx=partner-pub-3…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}:10.15.0.62
FF - prefs.js..extensions.enabledAddons: {739df940-c5ee-4bab-9d7e-270894ae687a}:10.14.380.14
FF - prefs.js..browser.startup.homepage: "http://www.google.com/cse?cx=partner-pub-3540673482024757:xbhdw8hkfz5&ie;=ISO-8859-1&q;=&sa;=Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/cse?cx=partner-pub-3540673482024757:xbhdw8hkfz5&ie;=ISO-8859-1&q;=&sa;=Search"
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@citrixonline.com/appdetectorplugin: C:\Users\Mark Hudson\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Mark Hudson\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Mark Hudson\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\PROGRAM FILES\UPDATER BY SWEETPACKS\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{203FB6B2-2E1E-4474-863B-4C483ECCE78E}: C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_1.2.0.6\coFFNST\ [2011/08/19 14:23:32 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2012/12/22 11:14:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2012/12/22 11:14:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\IPSFFPlgn\ [2013/04/23 00:02:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/05/13 10:22:09 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 11.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013/05/13 10:22:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 11.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins

[2013/07/18 10:40:36 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Extensions
[2011/06/23 10:48:22 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013/07/30 09:47:36 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions
[2013/07/18 10:40:37 | 000,000,000 | —D | M] (TopArcadeHits) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{0113D088-8ED1-468C-B225-585A9C53B5E3}
[2013/07/30 09:47:32 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}
[2013/07/24 10:13:09 | 000,001,793 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\Bing.xml
[2013/03/27 23:15:47 | 000,002,356 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\startnow.xml
[2012/10/19 10:38:22 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
File not found (No name found) – C:\USERS\MARK HUDSON\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\QJ5BZ23M.DEFAULT\EXTENSIONS\{739DF940-C5EE-4BAB-9D7E-270894AE687A}
[2011/12/21 02:24:52 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/12/20 23:30:41 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/12/20 23:30:41 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter}
CHR - homepage: http://google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.72\gcswf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7896_0\npSkypeChromePlugin.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: TopArcadeHits = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdgdlcjhlbaphcjmagicjhhgfnkiihp\1.0.0_0\
CHR - Extension: RealDownloader = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0\
CHR - Extension: Skype Extension = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7896_0\

O1 HOSTS File: ([2013/07/29 23:24:08 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll File not found
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Norton Safe Web Lite BHO) - {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Safe Web Lite) - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Safe Web Lite) - {30CEEEA2-3742-40E4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe (Microsoft Corp.)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKCU..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: hostpilot.com ([ARCpoint] https in Local intranet)
O16 - DPF: {42B182F9-3F08-484E-9913-07193A5D36A9} http://192.168.2.119/web/WebClient.cab (WebClient Control)
O16 - DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} http://www.gunbroker.com/WebResource.axd?d…230999680000000 (Image Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://labcorp.webex.com/client/WBXclient-…ng/ieatgpc1.cab (GpcContainer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F22A54D-AEDC-4C91-AD17-7CB0657B12F0}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5BFF0016-01B7-4FE7-8946-570FA6A6F5DC}: DhcpNameServer = 192.168.2.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AF9E37F2-B89B-4AA7-BFEE-EEB3BF7AD7F4}: DhcpNameServer = [removed]
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/08/01 22:11:14 | 000,000,000 | —D | C] – C:\_OTL
[2013/07/30 09:57:10 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/07/30 09:41:07 | 000,562,042 | —- | C] (Oleg N. Scherbakov) – C:\Users\Mark Hudson\Desktop\JRT.exe
[2013/07/29 23:24:25 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/07/29 22:41:44 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/07/29 22:41:44 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/07/29 22:41:44 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/07/29 22:37:43 | 000,000,000 | —D | C] – C:\Qoobox
[2013/07/29 22:35:26 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/07/29 22:33:22 | 005,095,176 | R— | C] (Swearware) – C:\Users\Mark Hudson\Desktop\ComboFix.exe
[2013/07/29 21:24:21 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/07/29 21:07:52 | 002,237,968 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Mark Hudson\Desktop\tdsskiller.exe
[2013/07/29 21:01:26 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\Documents\Virus Removal
[2013/07/29 18:28:10 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Mark Hudson\Desktop\aswMBR.exe
[2013/07/28 20:36:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013/07/28 11:50:07 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Mark Hudson\Desktop\OTL.exe
[2013/07/24 11:21:34 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Roaming\Malwarebytes
[2013/07/24 11:21:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/07/24 11:21:04 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/07/24 11:21:01 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/07/24 11:21:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/07/24 11:20:21 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Local\Programs
[2013/07/23 16:52:42 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Local\NPE
[2013/07/18 15:09:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealZeal Soft
[2013/07/18 15:08:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\RZPPTCodec
[2013/07/18 15:08:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\RealZeal Soft
[2013/07/18 10:48:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIViewer
[2013/07/18 10:48:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\AIViewer
[2013/07/18 10:26:26 | 000,033,792 | —- | C] (IncrediMail, Ltd.) – C:\Windows\SysNative\ImHttpComm.dll
[2013/07/11 14:35:32 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/07/11 14:35:31 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/07/11 14:35:29 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/07/11 14:35:29 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/07/11 14:35:28 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/07/11 14:35:28 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/07/11 14:35:28 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/07/11 14:35:28 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/07/11 14:35:28 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/07/11 14:35:28 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/07/11 14:35:28 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/07/11 14:35:24 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/07/11 14:35:23 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/07/11 14:35:23 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/07/11 14:35:21 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/07/11 11:00:42 | 000,624,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qedit.dll
[2013/07/11 11:00:42 | 000,509,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qedit.dll
[2013/07/11 11:00:40 | 001,887,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/07/11 11:00:39 | 001,620,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/07/11 10:59:26 | 001,643,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll

========== Files - Modified Within 30 Days ==========

[2013/08/02 09:48:05 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/08/02 09:45:10 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/02 09:45:10 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/02 09:36:56 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/02 09:36:43 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/02 09:36:38 | 1392,693,248 | -HS- | M] () – C:\hiberfil.sys
[2013/08/02 09:35:00 | 000,000,932 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1681885816-2431122675-287609382-1001UA.job
[2013/08/02 09:34:06 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/01 16:23:25 | 000,002,403 | —- | M] () – C:\Users\Mark Hudson\Desktop\Google Chrome.lnk
[2013/08/01 10:35:02 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1681885816-2431122675-287609382-1001Core.job
[2013/07/31 21:18:35 | 000,797,524 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/07/31 21:18:35 | 000,674,654 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/07/31 21:18:35 | 000,125,872 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/07/30 09:41:28 | 000,562,042 | —- | M] (Oleg N. Scherbakov) – C:\Users\Mark Hudson\Desktop\JRT.exe
[2013/07/30 09:39:20 | 000,666,633 | —- | M] () – C:\Users\Mark Hudson\Desktop\adwcleaner.exe
[2013/07/29 23:24:08 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/07/29 22:33:42 | 005,095,176 | R— | M] (Swearware) – C:\Users\Mark Hudson\Desktop\ComboFix.exe
[2013/07/29 21:24:05 | 415,597,301 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/07/29 21:08:13 | 002,237,968 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Mark Hudson\Desktop\tdsskiller.exe
[2013/07/29 18:57:11 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Mark Hudson\Desktop\aswMBR.exe
[2013/07/28 20:36:42 | 000,002,216 | —- | M] () – C:\Users\Public\Desktop\Google Earth.lnk
[2013/07/28 12:47:01 | 000,001,023 | —- | M] () – C:\Users\Mark Hudson\Desktop\OTL - Shortcut.lnk
[2013/07/28 11:50:18 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Mark Hudson\Desktop\OTL.exe
[2013/07/27 10:07:40 | 000,609,104 | —- | M] () – C:\Users\Mark Hudson\Documents\AnalyticalTox130727.pdf
[2013/07/27 10:06:01 | 000,609,104 | —- | M] () – C:\Users\Mark Hudson\Documents\AnalyticalTox.pdf
[2013/07/24 11:21:11 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/07/23 10:27:00 | 000,020,992 | —- | M] () – C:\Users\Mark Hudson\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/22 12:20:29 | 000,000,358 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\LoginSetting.xml
[2013/07/22 12:20:29 | 000,000,139 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\GeneralSetting.xml
[2013/07/22 12:10:02 | 000,000,018 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\LocationSetting.xml
[2013/07/18 15:09:18 | 000,002,805 | —- | M] () – C:\Users\Public\Desktop\RZ PowerPoint Converter.lnk
[2013/07/18 15:04:05 | 026,710,528 | —- | M] () – C:\Users\Mark Hudson\Desktop\RZPowerPointConverter.msi
[2013/07/18 10:48:21 | 000,000,947 | —- | M] () – C:\Users\Public\Desktop\AI Viewer.lnk
[2013/07/18 10:41:08 | 000,000,258 | RHS- | M] () – C:\Users\Mark Hudson\ntuser.pol
[2013/07/16 22:01:33 | 000,001,732 | —- | M] () – C:\Users\Mark Hudson\Desktop\DvrClient.cfg
[2013/07/16 09:50:52 | 000,006,087 | —- | M] () – C:\Users\Mark Hudson\Desktop\Price List 1307 - Shortcut.lnk
[2013/07/15 15:01:01 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/07/15 15:01:01 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/07/11 15:37:03 | 000,417,408 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2013/07/30 09:39:15 | 000,666,633 | —- | C] () – C:\Users\Mark Hudson\Desktop\adwcleaner.exe
[2013/07/29 22:41:44 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/07/29 22:41:44 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/07/29 22:41:44 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/07/29 22:41:44 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/07/29 22:41:44 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/07/29 21:24:05 | 415,597,301 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/07/28 20:36:41 | 000,002,216 | —- | C] () – C:\Users\Public\Desktop\Google Earth.lnk
[2013/07/28 12:47:01 | 000,001,023 | —- | C] () – C:\Users\Mark Hudson\Desktop\OTL - Shortcut.lnk
[2013/07/27 10:07:38 | 000,609,104 | —- | C] () – C:\Users\Mark Hudson\Documents\AnalyticalTox130727.pdf
[2013/07/27 10:05:57 | 000,609,104 | —- | C] () – C:\Users\Mark Hudson\Documents\AnalyticalTox.pdf
[2013/07/24 11:21:11 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/07/18 15:30:50 | 000,020,992 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/18 15:09:15 | 000,002,805 | —- | C] () – C:\Users\Public\Desktop\RZ PowerPoint Converter.lnk
[2013/07/18 15:04:30 | 026,710,528 | —- | C] () – C:\Users\Mark Hudson\Desktop\RZPowerPointConverter.msi
[2013/07/18 10:48:21 | 000,000,947 | —- | C] () – C:\Users\Public\Desktop\AI Viewer.lnk
[2013/07/18 10:41:08 | 000,000,258 | RHS- | C] () – C:\Users\Mark Hudson\ntuser.pol
[2013/07/18 10:26:26 | 001,645,360 | —- | C] () – C:\Windows\SysNative\dmwu.exe
[2013/07/16 09:50:52 | 000,006,087 | —- | C] () – C:\Users\Mark Hudson\Desktop\Price List 1307 - Shortcut.lnk
[2013/05/22 20:43:52 | 000,030,568 | —- | C] () – C:\Windows\MusiccityDownload.exe
[2013/05/22 20:43:48 | 000,974,848 | —- | C] () – C:\Windows\SysWow64\cis-2.4.dll
[2013/05/22 20:43:48 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2013/05/22 20:43:48 | 000,065,536 | —- | C] () – C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2013/05/22 20:43:48 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\issacapi_se-2.3.dll
[2013/04/19 10:44:01 | 000,000,358 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\LoginSetting.xml
[2012/10/02 09:00:38 | 000,000,000 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\bibstats
[2012/09/07 08:12:25 | 000,001,940 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2012/07/23 13:22:39 | 000,000,094 | —- | C] () – C:\Windows\brpcfx.ini
[2012/07/23 13:22:38 | 000,000,242 | —- | C] () – C:\Windows\Brpfx04a.ini
[2012/07/23 13:20:41 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\BrMuSNMP.dll
[2012/07/23 13:20:39 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2012/07/23 13:20:39 | 000,000,000 | —- | C] () – C:\Windows\brdfxspd.dat
[2012/06/10 21:12:47 | 000,004,096 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\keyfile3.drm
[2012/03/27 22:35:43 | 000,000,139 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\GeneralSetting.xml
[2012/03/27 22:34:52 | 000,000,018 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\LocationSetting.xml
[2012/02/19 17:31:33 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2012/02/09 18:20:06 | 000,102,912 | —- | C] () – C:\Windows\agent_x64.exe
[2011/11/17 15:12:42 | 000,000,247 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\kclientgui.ini
[2011/10/10 12:41:33 | 000,000,426 | —- | C] () – C:\Windows\BRWMARK.INI
[2011/10/10 12:41:33 | 000,000,034 | —- | C] () – C:\Windows\SysWow64\BD7220.DAT
[2011/07/29 11:01:50 | 000,007,598 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\Resmon.ResmonCfg

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 00:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/26 23:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 22:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/01/14 20:09:30 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Canon
[2013/08/02 09:41:11 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Clip Art Collection
[2011/07/07 11:59:23 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/12/27 10:20:46 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\IrfanView
[2013/08/02 09:19:00 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\MyPhoneExplorer
[2012/02/09 18:34:40 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Neat
[2012/02/09 18:34:19 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Nuance
[2011/07/07 12:14:06 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\PDF Writer
[2013/06/21 22:35:09 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\PPTRemote
[2013/06/26 21:04:03 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Samsung
[2012/05/12 16:13:42 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\SmartDraw
[2012/03/08 16:15:55 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\TaxCut
[2011/06/23 10:48:11 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Thunderbird
[2012/10/06 09:42:48 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Tific
[2012/03/21 09:50:21 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\WeatherBug
[2012/11/15 16:13:55 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\webex
[2012/03/27 10:14:31 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Winff

========== Purity Check ==========



< End of report >
Something wrong with the script. I'm creating a little different script for you this time. Not your fault. You did it correctly this time. :)


Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\PROGRAM FILES\UPDATER BY SWEETPACKS\FIREFOX
    CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
    
    :Commands
    [REBOOT]
    [CREATERESTOREPOINT]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post Fix OTL log as well as a new OTL log by rerunning it after reboot without custom scans script.
Thanks, just a heads-up. I will not be able to run the fix and reply until Monday. Catch up with you then. Have a good weekend. Mark
OK, Ran the Fix but it did not generate a log, just a pop up to reboot.

Did run the OTL Scan again and it is below.

OTL logfile created on: 8/6/2013 10:51:05 PM - Run 7
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Mark Hudson\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.73 Gb Total Physical Memory | 0.80 Gb Available Physical Memory | 46.00% Memory free
3.46 Gb Paging File | 1.88 Gb Available in Paging File | 54.22% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 284.99 Gb Total Space | 206.13 Gb Free Space | 72.33% Space Free | Partition Type: NTFS
Drive E: | 982.13 Mb Total Space | 842.88 Mb Free Space | 85.82% Space Free | Partition Type: FAT

Computer Name: MARKHUDSON-PC | User Name: Mark Hudson | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Mark Hudson\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Microsoft Corp.)
PRC - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
PRC - C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Neat\exec\NeatStartupService.exe (The Neat Company)
PRC - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LMworker.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
PRC - C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\83cfe0422e7e54f3f00107c15a63f1b4\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\6da2afd0e57708d41892d9d3e32ba5a3\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\f3770f9a13d7516e4c03f23dbd319cba\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\4572de8445038600e4552429b18fbe32\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\7546a01feb9d477570b883eec56cc673\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\112f6448b7434699af4bcc05f25ce12b\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\64b92e2a22bb8c1e86486bd22828acc5\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\c1c41a9e1a25999e74defafecb2aa0bc\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\89445d5b924ad94744d00f1b6cd2285d\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a01e07e47ecdd94ae099e8c4bf650516\mscorlib.ni.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (Live Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
SRV:64bit: - (ePowerSvc) – C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (CxAudMsg) – C:\Windows\SysNative\CxAudMsg64.exe (Conexant Systems Inc.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (BingDesktopUpdate) – C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Microsoft Corp.)
SRV - (NAV) – C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ccSvcHst.exe (Symantec Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Neat Startup Service) – C:\Program Files (x86)\Neat\exec\NeatStartupService.exe (The Neat Company)
SRV - (RealNetworks Downloader Resolver Service) – C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (UWS HiPriv Services) – C:\Program Files (x86)\UltiDev\Web Server\UWS.HighPrivilegeUtilities.exe (UltiDev LLC)
SRV - (UltiDev Web Server Pro) – C:\Program Files (x86)\UltiDev\Web Server\UltiDev.WebServer.Monitor.exe (UltiDev LLC)
SRV - (UWS LoPriv Services) – C:\Program Files (x86)\UltiDev\Web Server\UWS.LowPrivilegeUtilities.exe (UltiDev LLC)
SRV - (DsiWMIService) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (NSL) – C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe (Symantec Corporation)
SRV - (HP DS Service) – C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe (Hewlett-Packard Company)
SRV - (HP LaserJet Service) – C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
SRV - (GamesAppService) – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (EgisTec Ticket Service) – C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe (Egis Technology Inc. )
SRV - (NOBU) – C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (RS_Service) – C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
SRV - (GREGService) – C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SymEFA) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symds64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SymNetS) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\symnets.sys (Symantec Corporation)
DRV:64bit: - (ccSet_NAV) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\ccsetx64.sys (Symantec Corporation)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (SymIRON) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\ironx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) – C:\Windows\SysNative\drivers\NAVx64\1404000.028\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (tapklink) – C:\Windows\SysNative\drivers\tapklink.sys (Faveset LLC)
DRV:64bit: - (HPFXBULKLEDM) – C:\Windows\SysNative\drivers\hppdbulkio.sys (Hewlett Packard)
DRV:64bit: - (mwlPSDVDisk) – C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDFilter) – C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDNServ) – C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:64bit: - (CnxtHdAudService) – C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (L1C) – C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\VirusDefs\20130806.002\ex64.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\VirusDefs\20130806.002\eng64.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\Definitions\IPSDefs\20130804.001\IDSviA64.sys (Symantec Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (lowpp) – C:\Windows\SysWOW64\drivers\lowpp.sys (Lowrance Electronics, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.arcpointlabs.com/south-san-antonio
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {E9DB9E7B-A275-41D1-8158-D0423FBEBDEB}
IE - HKCU\..\SearchScopes\{E9DB9E7B-A275-41D1-8158-D0423FBEBDEB}: "URL" = http://www.google.com/cse?cx=partner-pub-3…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: {fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}:10.15.0.62
FF - prefs.js..extensions.enabledAddons: {739df940-c5ee-4bab-9d7e-270894ae687a}:10.14.380.14
FF - prefs.js..browser.startup.homepage: "http://www.google.com/cse?cx=partner-pub-3540673482024757:xbhdw8hkfz5&ie;=ISO-8859-1&q;=&sa;=Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/cse?cx=partner-pub-3540673482024757:xbhdw8hkfz5&ie;=ISO-8859-1&q;=&sa;=Search"
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@citrixonline.com/appdetectorplugin: C:\Users\Mark Hudson\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Mark Hudson\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Mark Hudson\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8E9E3331-D360-4f87-8803-52DE43566502}: C:\PROGRAM FILES\UPDATER BY SWEETPACKS\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{203FB6B2-2E1E-4474-863B-4C483ECCE78E}: C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_1.2.0.6\coFFNST\ [2011/08/19 14:23:32 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2012/12/22 11:14:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2012/12/22 11:14:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.1.0.24\IPSFFPlgn\ [2013/04/23 00:02:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/05/13 10:22:09 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 11.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013/05/13 10:22:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 11.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins

[2013/07/18 10:40:36 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Extensions
[2011/06/23 10:48:22 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013/07/30 09:47:36 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions
[2013/07/18 10:40:37 | 000,000,000 | —D | M] (TopArcadeHits) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{0113D088-8ED1-468C-B225-585A9C53B5E3}
[2013/07/30 09:47:32 | 000,000,000 | —D | M] (No name found) – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\extensions\{fe02a3ef-6cd5-4dc6-8cf4-f3bcac60bc7c}
[2013/07/24 10:13:09 | 000,001,793 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\Bing.xml
[2013/03/27 23:15:47 | 000,002,356 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\Mozilla\Firefox\Profiles\qj5bz23m.default\searchplugins\startnow.xml
[2012/10/19 10:38:22 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
File not found (No name found) – C:\USERS\MARK HUDSON\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\QJ5BZ23M.DEFAULT\EXTENSIONS\{739DF940-C5EE-4BAB-9D7E-270894AE687A}
[2011/12/21 02:24:52 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/12/20 23:30:41 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/12/20 23:30:41 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter}
CHR - homepage: http://google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.95\gcswf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\Application\28.0.1500.95\pdf.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7896_0\npSkypeChromePlugin.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Mark Hudson\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: TopArcadeHits = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdgdlcjhlbaphcjmagicjhhgfnkiihp\1.0.0_0\
CHR - Extension: RealDownloader = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0\
CHR - Extension: Skype Extension = C:\Users\Mark Hudson\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7896_0\

O1 HOSTS File: ([2013/07/29 23:24:08 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll File not found
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton AntiVirus\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Norton Safe Web Lite BHO) - {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Safe Web Lite) - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Safe Web Lite) - {30CEEEA2-3742-40E4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe (Microsoft Corp.)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKCU..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: hostpilot.com ([ARCpoint] https in Local intranet)
O16 - DPF: {42B182F9-3F08-484E-9913-07193A5D36A9} http://192.168.2.119/web/WebClient.cab (WebClient Control)
O16 - DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} http://www.gunbroker.com/WebResource.axd?d…230999680000000 (Image Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://labcorp.webex.com/client/WBXclient-…ng/ieatgpc1.cab (GpcContainer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F22A54D-AEDC-4C91-AD17-7CB0657B12F0}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5BFF0016-01B7-4FE7-8946-570FA6A6F5DC}: DhcpNameServer = 192.168.2.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AF9E37F2-B89B-4AA7-BFEE-EEB3BF7AD7F4}: DhcpNameServer = [removed]
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/08/01 22:11:14 | 000,000,000 | —D | C] – C:\_OTL
[2013/07/30 09:57:10 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/07/30 09:41:07 | 000,562,042 | —- | C] (Oleg N. Scherbakov) – C:\Users\Mark Hudson\Desktop\JRT.exe
[2013/07/29 23:24:25 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/07/29 22:41:44 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/07/29 22:41:44 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/07/29 22:41:44 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/07/29 22:37:43 | 000,000,000 | —D | C] – C:\Qoobox
[2013/07/29 22:35:26 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/07/29 22:33:22 | 005,095,176 | R— | C] (Swearware) – C:\Users\Mark Hudson\Desktop\ComboFix.exe
[2013/07/29 21:24:21 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/07/29 21:07:52 | 002,237,968 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Mark Hudson\Desktop\tdsskiller.exe
[2013/07/29 21:01:26 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\Documents\Virus Removal
[2013/07/29 18:28:10 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Mark Hudson\Desktop\aswMBR.exe
[2013/07/28 20:36:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013/07/28 11:50:07 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Mark Hudson\Desktop\OTL.exe
[2013/07/24 11:21:34 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Roaming\Malwarebytes
[2013/07/24 11:21:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/07/24 11:21:04 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/07/24 11:21:01 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/07/24 11:21:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/07/24 11:20:21 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Local\Programs
[2013/07/23 16:52:42 | 000,000,000 | —D | C] – C:\Users\Mark Hudson\AppData\Local\NPE
[2013/07/18 15:09:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealZeal Soft
[2013/07/18 15:08:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\RZPPTCodec
[2013/07/18 15:08:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\RealZeal Soft
[2013/07/18 10:48:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIViewer
[2013/07/18 10:48:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\AIViewer
[2013/07/18 10:26:26 | 000,033,792 | —- | C] (IncrediMail, Ltd.) – C:\Windows\SysNative\ImHttpComm.dll
[2013/07/11 14:35:32 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/07/11 14:35:31 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/07/11 14:35:29 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/07/11 14:35:29 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/07/11 14:35:28 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/07/11 14:35:28 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/07/11 14:35:28 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/07/11 14:35:28 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/07/11 14:35:28 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/07/11 14:35:28 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/07/11 14:35:28 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/07/11 14:35:24 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/07/11 14:35:23 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/07/11 14:35:23 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/07/11 14:35:21 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/07/11 11:00:42 | 000,624,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qedit.dll
[2013/07/11 11:00:42 | 000,509,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qedit.dll
[2013/07/11 11:00:40 | 001,887,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/07/11 11:00:39 | 001,620,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/07/11 10:59:26 | 001,643,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll

========== Files - Modified Within 30 Days ==========

[2013/08/06 22:50:45 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/06 22:50:45 | 000,016,976 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/06 22:48:13 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/08/06 22:42:40 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/06 22:42:27 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/06 22:42:15 | 1392,693,248 | -HS- | M] () – C:\hiberfil.sys
[2013/08/06 22:35:11 | 000,000,932 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1681885816-2431122675-287609382-1001UA.job
[2013/08/06 22:34:02 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/05 10:35:06 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1681885816-2431122675-287609382-1001Core.job
[2013/08/01 16:23:25 | 000,002,403 | —- | M] () – C:\Users\Mark Hudson\Desktop\Google Chrome.lnk
[2013/07/31 21:18:35 | 000,797,524 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/07/31 21:18:35 | 000,674,654 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/07/31 21:18:35 | 000,125,872 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/07/30 09:41:28 | 000,562,042 | —- | M] (Oleg N. Scherbakov) – C:\Users\Mark Hudson\Desktop\JRT.exe
[2013/07/30 09:39:20 | 000,666,633 | —- | M] () – C:\Users\Mark Hudson\Desktop\adwcleaner.exe
[2013/07/29 23:24:08 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/07/29 22:33:42 | 005,095,176 | R— | M] (Swearware) – C:\Users\Mark Hudson\Desktop\ComboFix.exe
[2013/07/29 21:24:05 | 415,597,301 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/07/29 21:08:13 | 002,237,968 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Mark Hudson\Desktop\tdsskiller.exe
[2013/07/29 18:57:11 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Mark Hudson\Desktop\aswMBR.exe
[2013/07/28 20:36:42 | 000,002,216 | —- | M] () – C:\Users\Public\Desktop\Google Earth.lnk
[2013/07/28 12:47:01 | 000,001,023 | —- | M] () – C:\Users\Mark Hudson\Desktop\OTL - Shortcut.lnk
[2013/07/28 11:50:18 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Mark Hudson\Desktop\OTL.exe
[2013/07/27 10:07:40 | 000,609,104 | —- | M] () – C:\Users\Mark Hudson\Documents\AnalyticalTox130727.pdf
[2013/07/27 10:06:01 | 000,609,104 | —- | M] () – C:\Users\Mark Hudson\Documents\AnalyticalTox.pdf
[2013/07/24 11:21:11 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/07/23 10:27:00 | 000,020,992 | —- | M] () – C:\Users\Mark Hudson\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/22 12:20:29 | 000,000,358 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\LoginSetting.xml
[2013/07/22 12:20:29 | 000,000,139 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\GeneralSetting.xml
[2013/07/22 12:10:02 | 000,000,018 | —- | M] () – C:\Users\Mark Hudson\AppData\Roaming\LocationSetting.xml
[2013/07/18 15:09:18 | 000,002,805 | —- | M] () – C:\Users\Public\Desktop\RZ PowerPoint Converter.lnk
[2013/07/18 15:04:05 | 026,710,528 | —- | M] () – C:\Users\Mark Hudson\Desktop\RZPowerPointConverter.msi
[2013/07/18 10:48:21 | 000,000,947 | —- | M] () – C:\Users\Public\Desktop\AI Viewer.lnk
[2013/07/18 10:41:08 | 000,000,258 | RHS- | M] () – C:\Users\Mark Hudson\ntuser.pol
[2013/07/16 22:01:33 | 000,001,732 | —- | M] () – C:\Users\Mark Hudson\Desktop\DvrClient.cfg
[2013/07/16 09:50:52 | 000,006,087 | —- | M] () – C:\Users\Mark Hudson\Desktop\Price List 1307 - Shortcut.lnk
[2013/07/15 15:01:01 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/07/15 15:01:01 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/07/11 15:37:03 | 000,417,408 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2013/07/30 09:39:15 | 000,666,633 | —- | C] () – C:\Users\Mark Hudson\Desktop\adwcleaner.exe
[2013/07/29 22:41:44 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/07/29 22:41:44 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/07/29 22:41:44 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/07/29 22:41:44 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/07/29 22:41:44 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/07/29 21:24:05 | 415,597,301 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/07/28 20:36:41 | 000,002,216 | —- | C] () – C:\Users\Public\Desktop\Google Earth.lnk
[2013/07/28 12:47:01 | 000,001,023 | —- | C] () – C:\Users\Mark Hudson\Desktop\OTL - Shortcut.lnk
[2013/07/27 10:07:38 | 000,609,104 | —- | C] () – C:\Users\Mark Hudson\Documents\AnalyticalTox130727.pdf
[2013/07/27 10:05:57 | 000,609,104 | —- | C] () – C:\Users\Mark Hudson\Documents\AnalyticalTox.pdf
[2013/07/24 11:21:11 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/07/18 15:30:50 | 000,020,992 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/18 15:09:15 | 000,002,805 | —- | C] () – C:\Users\Public\Desktop\RZ PowerPoint Converter.lnk
[2013/07/18 15:04:30 | 026,710,528 | —- | C] () – C:\Users\Mark Hudson\Desktop\RZPowerPointConverter.msi
[2013/07/18 10:48:21 | 000,000,947 | —- | C] () – C:\Users\Public\Desktop\AI Viewer.lnk
[2013/07/18 10:41:08 | 000,000,258 | RHS- | C] () – C:\Users\Mark Hudson\ntuser.pol
[2013/07/18 10:26:26 | 001,645,360 | —- | C] () – C:\Windows\SysNative\dmwu.exe
[2013/07/16 09:50:52 | 000,006,087 | —- | C] () – C:\Users\Mark Hudson\Desktop\Price List 1307 - Shortcut.lnk
[2013/05/22 20:43:52 | 000,030,568 | —- | C] () – C:\Windows\MusiccityDownload.exe
[2013/05/22 20:43:48 | 000,974,848 | —- | C] () – C:\Windows\SysWow64\cis-2.4.dll
[2013/05/22 20:43:48 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2013/05/22 20:43:48 | 000,065,536 | —- | C] () – C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2013/05/22 20:43:48 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\issacapi_se-2.3.dll
[2013/04/19 10:44:01 | 000,000,358 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\LoginSetting.xml
[2012/10/02 09:00:38 | 000,000,000 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\bibstats
[2012/09/07 08:12:25 | 000,001,940 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2012/07/23 13:22:39 | 000,000,094 | —- | C] () – C:\Windows\brpcfx.ini
[2012/07/23 13:22:38 | 000,000,242 | —- | C] () – C:\Windows\Brpfx04a.ini
[2012/07/23 13:20:41 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\BrMuSNMP.dll
[2012/07/23 13:20:39 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2012/07/23 13:20:39 | 000,000,000 | —- | C] () – C:\Windows\brdfxspd.dat
[2012/06/10 21:12:47 | 000,004,096 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\keyfile3.drm
[2012/03/27 22:35:43 | 000,000,139 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\GeneralSetting.xml
[2012/03/27 22:34:52 | 000,000,018 | —- | C] () – C:\Users\Mark Hudson\AppData\Roaming\LocationSetting.xml
[2012/02/19 17:31:33 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2012/02/09 18:20:06 | 000,102,912 | —- | C] () – C:\Windows\agent_x64.exe
[2011/11/17 15:12:42 | 000,000,247 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\kclientgui.ini
[2011/10/10 12:41:33 | 000,000,426 | —- | C] () – C:\Windows\BRWMARK.INI
[2011/10/10 12:41:33 | 000,000,034 | —- | C] () – C:\Windows\SysWow64\BD7220.DAT
[2011/07/29 11:01:50 | 000,007,598 | —- | C] () – C:\Users\Mark Hudson\AppData\Local\Resmon.ResmonCfg

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 00:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/26 23:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 22:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/01/14 20:09:30 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Canon
[2013/08/06 22:35:37 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Clip Art Collection
[2011/07/07 11:59:23 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/12/27 10:20:46 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\IrfanView
[2013/08/02 09:19:00 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\MyPhoneExplorer
[2012/02/09 18:34:40 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Neat
[2012/02/09 18:34:19 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Nuance
[2011/07/07 12:14:06 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\PDF Writer
[2013/06/21 22:35:09 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\PPTRemote
[2013/06/26 21:04:03 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Samsung
[2012/05/12 16:13:42 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\SmartDraw
[2012/03/08 16:15:55 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\TaxCut
[2011/06/23 10:48:11 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Thunderbird
[2012/10/06 09:42:48 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Tific
[2012/03/21 09:50:21 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\WeatherBug
[2012/11/15 16:13:55 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\webex
[2012/03/27 10:14:31 | 000,000,000 | —D | M] – C:\Users\Mark Hudson\AppData\Roaming\Winff

========== Purity Check ==========



< End of report >
Please uninstall the following Programs using the Add/Remove Programs utility if they exist.
Updater By SweetPacks 2.0.0.608

Detailed steps below :-
On the Windows Vista/7 taskbar:
Click Start > Control Panel.
In the Control Panel window, double-click Programs and Features.

===================================================

Please download Malwarebytes Anti-Rootkit from here Malwarebytes : Malwarebytes Anti-Rootkit and save it to your desktop.

  • Double click the mbar.zip file to open it, then 'Extract all files'.
  • Double click the mbar folder to open it, then double click mbar.exe to start the tool.

Check for Updates, then Scan your system for malware

If malware is found, do NOT press the Cleanup button yet. Click EXIT.

I'd like to see the log first so I can see what it sees. You'll find the log in that mbar folder as MBAR-log-***.txt . Please attach that to your next reply.

===================================================

On your next reply please post :
MBAR log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI