This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Odoyomo removal need help please [Solved]

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello all,

Need help removing odoyomo on moms PC. I think it's the reason her PC is running so crappy with a lot of pop up ads and redirecting to other websites.

I read the sticky's and here are the results of OTL and Hijackthis

OTL logfile created on: 8/9/2013 7:42:23 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Loretta\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.96 Gb Total Physical Memory | 1.50 Gb Available Physical Memory | 50.52% Memory free
5.92 Gb Paging File | 4.13 Gb Available in Paging File | 69.70% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.66 Gb Total Space | 423.78 Gb Free Space | 91.01% Space Free | Partition Type: NTFS
Drive E: | 15.22 Gb Total Space | 7.78 Gb Free Space | 51.12% Space Free | Partition Type: FAT32

Computer Name: LORETTA-PC | User Name: Loretta | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Loretta\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Users\Loretta\AppData\Local\Smartbar\Application\SnapDo.exe (Smartbar)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicator.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicatorCom.exe (Hewlett-Packard Co.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ControlCenter4\BrCcUxSys.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\ControlCenter4\BrCtrlCntr.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (Nuance Communications, Inc.)
PRC - C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe ()
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\stacsv.exe (IDT, Inc.)
PRC - C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe ()
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
PRC - C:\Program Files\Common Files\PX Storage Engine\VxBlockServer.exe (Sonic Solutions)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - c:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.dll ()
MOD - C:\Windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll ()
MOD - C:\Windows\assembly\GAC\Microsoft.VisualStudio.OLE.Interop\7.1.40304.0__b03f5f7f11d50a3a\Microsoft.VisualStudio.OLE.Interop.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__84542ff99aed6a4d\Interop.SHDocVw.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\a7a3ebc76a454af37918211506e81e31\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\de6ee26de5e4f343509de7e92ab48ba6\CustomMarshalers.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\eee76321ef8c5639946ed9ccc488d360\System.Web.Services.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\dcc781ebbddf98a9cf6dd4f3b17f1063\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\178644ab40108f3becd8b91049a254c3\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\bfa7a95284aec941f4b03bae0debe07c\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\32066405eb9ab14056b2af3115d2a6de\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\9e24b9ffd816c0c90efc4d3fc9fd745f\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\187c13e8967097d2ed1e5f123e7d890a\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9a6c1b7af18b4d5a91dc7f8d6617522f\mscorlib.ni.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.Utilities.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.SideBySide.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.ProcessDownMonitor.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.NetSeer.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Resources.AutomaticUpdates.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Personalization.BusinessLogic.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.EventManager.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.GUI.Multimedia.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.GUI.Multimedia.Loader.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\MACTrackBarLib.dll ()
MOD - C:\Users\Loretta\AppData\Local\Smartbar\Application\AxInterop.WMPLib.dll ()
MOD - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\wincfi39.dll ()
MOD - C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll ()
MOD - C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe ()
MOD - C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe ()
MOD - C:\Program Files\Brother\BrUtilities\BrLogAPI.dll ()


========== Services (SafeList) ==========

SRV - (BrowserDefendert) – C:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe ()
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (DefaultTabUpdate) – C:\Users\Loretta\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (NIS) – C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe (Symantec Corporation)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (DefaultTabSearch) – C:\Program Files\DefaultTab\DefaultTabSearch.exe ()
SRV - (PDFProFiltSrvPP) – C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe (Nuance Communications, Inc.)
SRV - (BrYNSvc) – C:\Program Files\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
SRV - (RoxWatch12) – C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe (Sonic Solutions)
SRV - (RoxMediaDB12) – C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe (Sonic Solutions)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (Avglogx) – C:\Windows\System32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130809.003\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130809.003\NAVENG.SYS (Symantec Corporation)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20130808.001\IDSvix86.sys (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\System32\drivers\NIS\1404000.028\symefa.sys (Symantec Corporation)
DRV - (SymDS) – C:\Windows\System32\drivers\NIS\1404000.028\symds.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\NIS\1404000.028\srtsp.sys (Symantec Corporation)
DRV - (SymNetS) – C:\Windows\System32\drivers\NIS\1404000.028\symnets.sys (Symantec Corporation)
DRV - (ccSet_NIS) – C:\Windows\System32\drivers\NIS\1404000.028\ccsetx86.sys (Symantec Corporation)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (SRTSPX) – C:\Windows\System32\drivers\NIS\1404000.028\srtspx.sys (Symantec Corporation)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (SymIRON) – C:\Windows\System32\drivers\NIS\1404000.028\ironx86.sys (Symantec Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (itecir) – C:\Windows\System32\drivers\itecir.sys (ITE Tech. Inc. )
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (WSDPrintDevice) – C:\Windows\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (k57nd60x) – C:\Windows\System32\drivers\k57nd60x.sys (Broadcom Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0DC13E05-3380-46D0-B1D8-4FE1CE0C55B3}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www1.delta-search.com/?babsrc=HP_ss…57&tsp=4963
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D0 C5 89 65 AA 87 CE 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{0BE8708C-DF24-41CD-B0A7-FA5017ADE058}: "URL" = http://search.conduit.com/Results.aspx?cti…q={searchTerms}
IE - HKCU\..\SearchScopes\{0DC13E05-3380-46D0-B1D8-4FE1CE0C55B3}: "URL" = http://search.conduit.com/ResultsExt.aspx?…421133&UM=2
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www1.delta-search.com/?q={searchTer…57&tsp=4963
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://nortonsafe.search.ask.com/web?q={SE…d&qsrc=2869
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{7D4F1959-3F72-49d5-8E59-F02F8AA6815D}: C:\Program Files\Updater By SweetPacks\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\IPSFFPlgn\ [2013/07/02 10:23:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\coFFPlgn\ [2013/08/09 19:00:38 | 000,000,000 | —D | M]

[2013/07/14 08:28:49 | 000,000,000 | —D | M] (No name found) – C:\Users\Loretta\AppData\Roaming\Mozilla\Extensions
[2013/08/02 22:41:30 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (SelectionLinks) - {1C8501DD-5580-48AB-B25C-6D5DBE835A6A} - C:\Program Files\OApps\SelectionLinks.dll (SelectionLinks)
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (DefaultTab Browser Helper) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Loretta\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll (Search Results LLC.)
O2 - BHO: (TopArcadeHits Games) - {A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} - C:\Users\Loretta\AppData\Local\TopArcadeHits\Toparcadehits.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter4] C:\Program Files\ControlCenter4\BrCcBoot.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [CPMonitor] C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe ()
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\Nuance\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDF5 Registry Controller] C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDFHook] C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PPort12reminder] C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe (Sonic Solutions)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe (Microsoft® Corporation)
O4 - HKCU..\Run: [Browser Infrastructure Helper] C:\Users\Loretta\AppData\Local\Smartbar\Application\SnapDo.exe (Smartbar)
O4 - HKCU..\Run: [HP Officejet 6600 (NET)] C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - HKCU..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: cinemanow.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: cinemanow.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: qflix.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: roxio.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: sonic.com ([redirect] http in Trusted sites)
O15 - HKCU\..Trusted Domains: sonic.com ([redirect2] http in Trusted sites)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{27E46421-718C-4440-9642-64B07C9AE1DB}: DhcpNameServer = 192.168.1.1 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7E1A25BB-B83F-48B6-BCA8-11A2410C5A66}: DhcpNameServer = 192.168.1.1
O20 - AppInit_DLLs: (c:\progra~2\browse~1\261519~1.190\{c16c1~1\browse~1.dll) - c:\ProgramData\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/08/09 19:34:18 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Loretta\Desktop\OTL.exe
[2013/08/08 10:42:45 | 000,000,000 | —D | C] – C:\ProgramData\Visan
[2013/08/08 10:42:45 | 000,000,000 | —D | C] – C:\ProgramData\HP Photo Creations
[2013/08/08 10:42:45 | 000,000,000 | —D | C] – C:\Program Files\HP Photo Creations
[2013/08/08 10:42:32 | 000,000,000 | —D | C] – C:\Windows\Hewlett-Packard
[2013/08/02 22:41:39 | 000,000,000 | —D | C] – C:\Windows\System32\Extensions
[2013/08/02 22:41:38 | 000,000,000 | —D | C] – C:\Windows\System32\searchplugins
[2013/08/02 22:41:37 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender
[2013/08/02 22:41:30 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/08/02 22:41:29 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Delta
[2013/08/02 22:41:23 | 000,000,000 | —D | C] – C:\ProgramData\BrowserDefender
[2013/08/02 22:40:47 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\BabSolution
[2013/08/02 22:40:27 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TopArcadeHits
[2013/08/02 22:40:20 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Local\TopArcadeHits
[2013/08/02 22:39:34 | 000,000,000 | —D | C] – C:\ProgramData\Babylon
[2013/08/02 22:39:33 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Babylon
[2013/07/30 09:54:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/07/23 08:04:55 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Local\Conduit
[2013/07/23 08:03:06 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Local\CRE
[2013/07/23 08:03:05 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2013/07/23 08:02:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OtShot
[2013/07/23 08:01:56 | 000,000,000 | —D | C] – C:\Program Files\OtShot
[2013/07/23 08:01:03 | 000,000,000 | —D | C] – C:\ProgramData\ZalmanInstaller_52330
[2013/07/20 01:51:00 | 000,246,072 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avglogx.sys
[2013/07/20 01:50:56 | 000,208,184 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidsdriverx.sys
[2013/07/20 01:50:56 | 000,060,216 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidshx.sys
[2013/07/20 01:50:50 | 000,171,320 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2013/07/18 10:10:09 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/07/17 07:05:20 | 001,247,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/07/17 06:53:17 | 000,745,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/07/17 06:53:17 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/07/17 06:53:17 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/07/17 06:53:16 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/07/17 06:53:16 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/07/17 06:53:16 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/07/17 06:53:16 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/07/17 06:53:16 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/07/17 06:53:16 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/07/17 06:53:15 | 000,493,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/07/17 06:53:14 | 002,706,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/07/17 06:53:14 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/07/17 06:53:14 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/07/17 06:53:14 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/07/17 06:53:14 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/07/17 06:53:14 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/07/17 06:53:14 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/07/17 06:53:14 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/07/17 06:53:13 | 002,877,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/07/17 06:53:13 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/07/17 06:53:13 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/07/17 06:53:13 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/07/17 06:53:13 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/07/17 06:53:12 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/07/17 06:53:12 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/07/17 06:53:12 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/07/17 06:53:12 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/07/17 06:53:12 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/07/17 06:53:12 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/07/17 06:53:12 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/07/17 06:53:12 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/07/17 06:53:12 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/07/17 06:53:11 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/07/17 06:53:11 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/07/17 06:53:11 | 000,242,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/07/17 06:53:11 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/07/17 06:51:43 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/07/17 06:51:43 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/07/17 06:51:43 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/07/17 06:51:42 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/07/17 06:51:42 | 001,080,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/07/17 06:51:42 | 000,604,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/07/17 06:51:42 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/07/17 06:51:42 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/07/17 06:51:42 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/07/17 06:51:42 | 000,207,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/07/17 06:51:42 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/07/17 06:51:41 | 003,419,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/07/17 06:51:41 | 001,988,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/07/17 06:51:41 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/07/17 06:51:41 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/07/14 08:32:35 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Local\Smartbar
[2013/07/14 08:28:49 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Mozilla

========== Files - Modified Within 30 Days ==========

[2013/08/09 19:34:18 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Loretta\Desktop\OTL.exe
[2013/08/09 19:32:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/08/09 19:08:09 | 000,013,440 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/09 19:08:09 | 000,013,440 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/09 19:01:02 | 000,001,914 | —- | M] () – C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Officejet 6600 (Network).lnk
[2013/08/09 19:00:28 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/09 19:00:25 | 2383,589,376 | -HS- | M] () – C:\hiberfil.sys
[2013/08/09 07:01:38 | 000,000,272 | —- | M] () – C:\Windows\tasks\TopArcadeHits.job
[2013/08/08 10:43:02 | 000,000,328 | —- | M] () – C:\Users\Loretta\Desktop\HP Printer Diagnostic Tools.url
[2013/08/08 10:42:48 | 000,001,953 | —- | M] () – C:\Users\Public\Desktop\HP Photo Creations.lnk
[2013/08/08 10:35:39 | 000,015,872 | —- | M] () – C:\Users\Loretta\Documents\Red Hat List.xlr
[2013/08/08 10:35:39 | 000,006,398 | —- | M] () – C:\Users\Loretta\AppData\Roaming\wklnhst.dat
[2013/08/04 16:40:55 | 000,017,920 | —- | M] () – C:\Users\Loretta\Documents\Sew Classy Ladies.xlr
[2013/07/30 09:54:01 | 000,000,935 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/07/30 08:40:03 | 000,000,009 | —- | M] () – C:\END
[2013/07/29 19:21:38 | 000,000,131 | —- | M] () – C:\Users\Loretta\Desktop\Jordan River Arts Council.url
[2013/07/26 11:43:34 | 000,624,178 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/07/26 11:43:34 | 000,106,522 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/07/26 08:45:39 | 000,000,202 | —- | M] () – C:\Users\Loretta\Desktop\How To Make a TV Tray Ironing Board American Quilting.url
[2013/07/20 01:51:00 | 000,246,072 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avglogx.sys
[2013/07/20 01:50:56 | 000,208,184 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidsdriverx.sys
[2013/07/20 01:50:56 | 000,060,216 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidshx.sys
[2013/07/20 01:50:50 | 000,171,320 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2013/07/18 10:10:04 | 300,800,352 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/07/17 06:53:17 | 000,745,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/07/17 06:53:17 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/07/17 06:53:17 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/07/17 06:53:16 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/07/17 06:53:16 | 000,158,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/07/17 06:53:16 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/07/17 06:53:16 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/07/17 06:53:16 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/07/17 06:53:16 | 000,039,424 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/07/17 06:53:15 | 000,493,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/07/17 06:53:14 | 002,706,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/07/17 06:53:14 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/07/17 06:53:14 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/07/17 06:53:14 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/07/17 06:53:14 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/07/17 06:53:14 | 000,041,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/07/17 06:53:14 | 000,038,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/07/17 06:53:14 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/07/17 06:53:13 | 002,877,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/07/17 06:53:13 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/07/17 06:53:13 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/07/17 06:53:13 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/07/17 06:53:13 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/07/17 06:53:12 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/07/17 06:53:12 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/07/17 06:53:12 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/07/17 06:53:12 | 000,357,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/07/17 06:53:12 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/07/17 06:53:12 | 000,226,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/07/17 06:53:12 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/07/17 06:53:12 | 000,042,496 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/07/17 06:53:12 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/07/17 06:53:12 | 000,025,185 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2013/07/17 06:53:11 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/07/17 06:53:11 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/07/17 06:53:11 | 000,242,200 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/07/17 06:53:11 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/07/17 06:51:43 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/07/17 06:51:43 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/07/17 06:51:43 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/07/17 06:51:42 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/07/17 06:51:42 | 001,080,832 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/07/17 06:51:42 | 000,604,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/07/17 06:51:42 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/07/17 06:51:42 | 000,249,856 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/07/17 06:51:42 | 000,220,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/07/17 06:51:42 | 000,207,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/07/17 06:51:42 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/07/17 06:51:41 | 003,419,136 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/07/17 06:51:41 | 001,988,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/07/17 06:51:41 | 000,293,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/07/17 06:51:41 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/07/16 12:45:04 | 000,013,889 | —- | M] () – C:\Users\Loretta\Desktop\Ron Feroni Amm. Schedule - Shortcut.lnk
[2013/07/16 12:43:03 | 000,005,064 | —- | M] () – C:\Users\Loretta\Desktop\Jenny Amortization Schedule - Shortcut.lnk
[2013/07/16 12:35:45 | 000,100,864 | —- | M] () – C:\Users\Loretta\Documents\Ron Feroni Amm. Schedule.xlr

========== Files Created - No Company Name ==========

[2013/08/08 10:43:02 | 000,000,328 | —- | C] () – C:\Users\Loretta\Desktop\HP Printer Diagnostic Tools.url
[2013/08/08 10:42:47 | 000,001,953 | —- | C] () – C:\Users\Public\Desktop\HP Photo Creations.lnk
[2013/08/02 22:40:20 | 000,000,272 | —- | C] () – C:\Windows\tasks\TopArcadeHits.job
[2013/07/29 19:21:38 | 000,000,131 | —- | C] () – C:\Users\Loretta\Desktop\Jordan River Arts Council.url
[2013/07/26 08:45:39 | 000,000,202 | —- | C] () – C:\Users\Loretta\Desktop\How To Make a TV Tray Ironing Board American Quilting.url
[2013/07/23 08:02:00 | 000,000,953 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OtShot.lnk
[2013/07/23 08:01:54 | 000,000,009 | —- | C] () – C:\END
[2013/07/18 10:10:04 | 300,800,352 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/07/17 06:53:12 | 000,025,185 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2013/07/16 12:45:04 | 000,013,889 | —- | C] () – C:\Users\Loretta\Desktop\Ron Feroni Amm. Schedule - Shortcut.lnk
[2013/07/16 12:43:03 | 000,005,064 | —- | C] () – C:\Users\Loretta\Desktop\Jenny Amortization Schedule - Shortcut.lnk
[2013/07/16 12:35:45 | 000,100,864 | —- | C] () – C:\Users\Loretta\Documents\Ron Feroni Amm. Schedule.xlr
[2013/07/14 08:33:03 | 000,002,441 | —- | C] () – C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
[2013/07/11 10:12:34 | 000,185,682 | —- | C] () – C:\Users\Loretta\Documents\beadsample.pdf
[2013/07/10 09:33:30 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2013/06/30 18:15:40 | 001,167,152 | —- | C] () – C:\Windows\System32\dmwu.exe
[2013/06/30 18:15:40 | 000,027,136 | —- | C] () – C:\Windows\System32\ImHttpComm.dll
[2013/06/22 09:40:08 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2013/06/17 07:16:10 | 000,000,258 | RHS- | C] () – C:\Users\Loretta\ntuser.pol
[2013/06/16 08:04:03 | 000,000,246 | —- | C] () – C:\Windows\Brpfx04a.ini
[2013/06/16 08:04:03 | 000,000,093 | —- | C] () – C:\Windows\brpcfx.ini
[2013/06/16 08:02:11 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2013/06/16 08:02:11 | 000,000,000 | —- | C] () – C:\Windows\brdfxspd.dat
[2013/06/16 08:01:51 | 000,045,056 | —- | C] () – C:\Windows\System32\BRTCPCON.DLL
[2013/06/16 08:01:44 | 000,000,114 | —- | C] () – C:\Windows\System32\BRLMW03A.INI
[2013/06/16 08:01:43 | 000,000,050 | —- | C] () – C:\Windows\System32\BRADM10A.DAT
[2013/06/14 10:00:59 | 000,006,398 | —- | C] () – C:\Users\Loretta\AppData\Roaming\wklnhst.dat

========== ZeroAccess Check ==========

[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 21:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/06/12 17:28:42 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\AVG2013
[2013/08/02 22:40:48 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\BabSolution
[2013/08/02 22:39:33 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\Babylon
[2013/06/16 08:08:46 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\ControlCenter4
[2013/06/17 07:16:03 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\DefaultTab
[2013/08/02 22:41:54 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\Delta
[2013/06/21 08:36:07 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\Nuance
[2013/06/22 11:10:42 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\Simple Star
[2013/06/16 08:25:00 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\Template
[2013/06/12 17:27:59 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\TuneUp Software
[2013/07/23 16:36:40 | 000,000,000 | —D | M] – C:\Users\Loretta\AppData\Roaming\Webfoot

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2009/07/13 22:07:10 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_22d6d5b5cba907ce\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 17:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011/02/26 01:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011/02/26 01:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009/08/03 01:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 01:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 02:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_05c8dd40d4f56065\explorer.exe.mui

< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2013/08/08 10:24:19 | 000,158,654 | —- | M] () MD5=9050FDD6250BCC84B9477F30576235D0 – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf

< MD5 for: IEXPLORE.EXE >
[2013/03/04 00:49:09 | 000,672,928 | —- | M] (Microsoft Corporation) MD5=050A612C1CE0C7095CAD64EA32C570DB – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21484_none_b3cf7f6d9f39f5d6\iexplore.exe
[2009/07/13 21:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_b346f9b4861b55c2\iexplore.exe
[2013/07/17 06:53:17 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Program Files\Internet Explorer\iexplore.exe
[2013/07/17 06:53:17 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_ba672fa865e3902d\iexplore.exe
[2013/05/28 23:32:47 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=33E62E4EFC2ACA8EC63A8926F26D3889 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20606_none_b1da3f12e114fd0b\iexplore.exe
[2013/03/02 01:06:58 | 000,672,912 | —- | M] (Microsoft Corporation) MD5=58D926F3B2113BF849162C9C26FE21DC – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17267_none_b35e817286096d08\iexplore.exe
[2013/06/12 18:02:32 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=67EE46FD4D3B56531C5DD1BDC149275A – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16490_none_b0e94f59c845c389\iexplore.exe
[2010/11/20 08:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_b5780d7c8309d95c\iexplore.exe
[2013/05/28 22:24:32 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=EE12BA876C4190532A4085994BA9B616 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16496_none_b0ef5115c8405b93\iexplore.exe

< MD5 for: IEXPLORE.EXE.19544.DMP >
[2013/07/11 17:41:04 | 013,387,483 | —- | M] () MD5=BDB174B67D56BF6DA781572E56AB4E07 – C:\ProgramData\Norton\LocalDumps\iexplore.exe.19544.dmp
[2013/07/11 17:41:04 | 013,387,483 | —- | M] () MD5=BDB174B67D56BF6DA781572E56AB4E07 – C:\Users\All Users\Norton\LocalDumps\iexplore.exe.19544.dmp

< MD5 for: IEXPLORE.EXE.45228.DMP >
[2013/07/12 18:03:26 | 010,334,576 | —- | M] () MD5=1A1EEE7B36352ABBD6C09C41EC843BBC – C:\ProgramData\Norton\LocalDumps\iexplore.exe.45228.dmp
[2013/07/12 18:03:26 | 010,334,576 | —- | M] () MD5=1A1EEE7B36352ABBD6C09C41EC843BBC – C:\Users\All Users\Norton\LocalDumps\iexplore.exe.45228.dmp

< MD5 for: IEXPLORE.EXE.6788.DMP >
[2013/07/09 10:31:29 | 015,286,239 | —- | M] () MD5=D4300796817F0E8038BF6BFA027F072D – C:\ProgramData\Norton\LocalDumps\iexplore.exe.6788.dmp
[2013/07/09 10:31:29 | 015,286,239 | —- | M] () MD5=D4300796817F0E8038BF6BFA027F072D – C:\Users\All Users\Norton\LocalDumps\iexplore.exe.6788.dmp

< MD5 for: IEXPLORE.EXE.6880.DMP >
[2013/07/13 08:54:10 | 014,912,863 | —- | M] () MD5=60EAA715FD59502433C72B8B3AB12350 – C:\ProgramData\Norton\LocalDumps\iexplore.exe.6880.dmp
[2013/07/13 08:54:10 | 014,912,863 | —- | M] () MD5=60EAA715FD59502433C72B8B3AB12350 – C:\Users\All Users\Norton\LocalDumps\iexplore.exe.6880.dmp

< MD5 for: IEXPLORE.EXE.MUI >
[2013/06/12 18:02:32 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_aae2948effb95a30\iexplore.exe.mui
[2013/07/17 06:53:17 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/07/17 06:53:17 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_b41defe19d893548\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_acf38f2bbdc896a9\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_af24a2f3bab71a43\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-908C99F8.PF >
[2013/08/09 19:39:50 | 000,327,084 | —- | M] () MD5=AFCC2AB2DFCF2770A44F8B7A6C9CCDDE – C:\Windows\Prefetch\IEXPLORE.EXE-908C99F8.pf

< MD5 for: SERVICES >
[2009/06/10 17:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\System32\drivers\etc\services
[2009/06/10 17:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services

< MD5 for: SERVICES.CFG >
[2012/09/23 20:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2013/05/11 06:37:26 | 000,558,990 | —- | M] () MD5=FE8FB005031C2574E990DAC1F9F5ACF8 – C:\Program Files\Adobe\Reader 11.0\Reader\Services\Services.cfg

< MD5 for: SERVICES.EXE >
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 22:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\System32\en-US\services.exe.mui
[2009/07/13 22:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 00:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 17:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2009/06/10 17:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof

< MD5 for: SERVICES.MSC >
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 16:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 16:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2009/07/13 22:05:00 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_94da67ab3e358f3a\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2009/10/28 02:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 01:52:08 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009/07/13 21:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 08:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\System32\en-US\winlogon.exe.mui
[2010/11/20 08:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_ccfffb7662588b45\winlogon.exe.mui
[2009/07/13 22:05:28 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=DB61D28A59DEE68F77811B291D83AD1B – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_cacee7ae656a07ab\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2009/07/13 22:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\System32\wbem\en-US\winlogon.mfl
[2009/07/13 22:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_2891397980a26140\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 16:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\System32\wbem\winlogon.mof
[2009/07/13 16:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2013/07/30 08:40:03 | 000,000,009 | —- | M] () – C:\END
[2013/08/09 19:00:25 | 2383,589,376 | -HS- | M] () – C:\hiberfil.sys
[2013/08/09 19:00:27 | 3178,119,168 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 00:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 17:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/13 21:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2010/11/20 08:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2013/06/13 21:32:23 | 000,001,718 | -HS- | M] () – C:\Users\Loretta\AppData\Roaming\Microsoft\LastFlashConfig.wfc

< %PROGRAMFILES%\*.* >
[2009/07/14 00:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is 7CE6-B0F3
Directory of C:\
07/14/2009 12:53 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/14/2009 12:53 AM Application Data [C:\ProgramData]
07/14/2009 12:53 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:53 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:53 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:53 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:53 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/14/2009 12:53 AM All Users [C:\ProgramData]
07/14/2009 12:53 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/14/2009 12:53 AM Application Data [C:\ProgramData]
07/14/2009 12:53 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:53 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:53 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:53 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:53 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/14/2009 12:53 AM Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009 12:53 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009 12:53 AM Local Settings [C:\Users\Default\AppData\Local]
07/14/2009 12:53 AM My Documents [C:\Users\Default\Documents]
07/14/2009 12:53 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009 12:53 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009 12:53 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009 12:53 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009 12:53 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009 12:53 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/14/2009 12:53 AM Application Data [C:\Users\Default\AppData\Local]
07/14/2009 12:53 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009 12:53 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/14/2009 12:53 AM My Music [C:\Users\Default\Music]
07/14/2009 12:53 AM My Pictures [C:\Users\Default\Pictures]
07/14/2009 12:53 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Loretta
06/12/2013 11:42 AM Application Data [C:\Users\Loretta\AppData\Roaming]
06/12/2013 11:42 AM Cookies [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Cookies]
06/12/2013 11:42 AM Local Settings [C:\Users\Loretta\AppData\Local]
06/12/2013 11:42 AM My Documents [C:\Users\Loretta\Documents]
06/12/2013 11:42 AM NetHood [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
06/12/2013 11:42 AM PrintHood [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
06/12/2013 11:42 AM Recent [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Recent]
06/12/2013 11:42 AM SendTo [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\SendTo]
06/12/2013 11:42 AM Start Menu [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu]
06/12/2013 11:42 AM Templates [C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Loretta\AppData\Local
06/12/2013 11:42 AM Application Data [C:\Users\Loretta\AppData\Local]
06/12/2013 11:42 AM History [C:\Users\Loretta\AppData\Local\Microsoft\Windows\History]
06/12/2013 11:42 AM Temporary Internet Files [C:\Users\Loretta\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Loretta\Documents
06/12/2013 11:42 AM My Music [C:\Users\Loretta\Music]
06/12/2013 11:42 AM My Pictures [C:\Users\Loretta\Pictures]
06/12/2013 11:42 AM My Videos [C:\Users\Loretta\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/14/2009 12:53 AM My Music [C:\Users\Public\Music]
07/14/2009 12:53 AM My Pictures [C:\Users\Public\Pictures]
07/14/2009 12:53 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
50 Dir(s) 454,924,165,120 bytes free

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/07/01 08:44:27 | 000,000,221 | -HS- | M] () – C:\Users\Loretta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2013/06/30 18:14:16 | 014,391,552 | —- | M] (PortableApps.com) – C:\Users\Loretta\Desktop\Java_Portable_6_Update_21_online.paf.exe
[2013/08/09 19:34:18 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Loretta\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-07-30 12:16:00

< End of report >


OTL Extras logfile created on: 8/9/2013 7:42:23 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Loretta\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.96 Gb Total Physical Memory | 1.50 Gb Available Physical Memory | 50.52% Memory free
5.92 Gb Paging File | 4.13 Gb Available in Paging File | 69.70% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.66 Gb Total Space | 423.78 Gb Free Space | 91.01% Space Free | Partition Type: NTFS
Drive E: | 15.22 Gb Total Space | 7.78 Gb Free Space | 51.12% Space Free | Partition Type: FAT32

Computer Name: LORETTA-PC | User Name: Loretta | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1894FFB7-A6D5-4AC2-AAA8-42D418D764A4}" = rport=139 | protocol=6 | dir=out | app=system |
"{2C657A39-E52A-4A14-BAC9-3EEAA45F8A12}" = lport=138 | protocol=17 | dir=in | app=system |
"{41DFD525-7C64-41D4-BFD9-3660D2C85860}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{425796E2-1AAE-41E5-AB9A-EA75645CB509}" = rport=138 | protocol=17 | dir=out | app=system |
"{513D9BEA-AD10-4BAF-BAB8-77C7A8D465B8}" = rport=137 | protocol=17 | dir=out | app=system |
"{62D281E4-D831-4BF1-BE92-A99A65282637}" = rport=10243 | protocol=6 | dir=out | app=system |
"{6CD42493-1EF6-43D7-B50D-1DF355E30D08}" = lport=54925 | protocol=17 | dir=in | name=brothernetwork scanner |
"{7A2F1CAF-DBA6-4791-A199-A730F8BEA4B0}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{871A53E1-4D92-492F-9457-12224D5DE252}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8CE39DB7-A350-4612-8488-DE8EDAAF5250}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8ED38666-4850-479B-AEEA-AADF035EF766}" = lport=10243 | protocol=6 | dir=in | app=system |
"{987C655D-D66E-4D98-A2F4-8F7500045958}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{A4018DBA-E080-49F0-B486-2BE8F32A5D82}" = lport=139 | protocol=6 | dir=in | app=system |
"{B394B97B-5AA4-4F13-A4A4-D7518A316167}" = lport=445 | protocol=6 | dir=in | app=system |
"{B60B8E3A-0396-44CD-95BF-573D27CCAE79}" = lport=137 | protocol=17 | dir=in | app=system |
"{B96D9383-03DD-4544-8869-F7F3BCDD4C30}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BF297E4C-DE8D-4537-A231-24B294119128}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C3AA2E97-B80A-444C-98C9-C125D00885AA}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C527D3C6-0702-469F-9152-0D357128C0D3}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D0B352E6-2364-4505-8764-7F45632289AC}" = rport=445 | protocol=6 | dir=out | app=system |
"{DDEAA578-8AF7-47FE-B52C-DFA267E26E21}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F66AFD4C-F9B5-4360-98A6-BEEEAD6F8872}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0F666FD2-289E-416E-B139-BD171AD9FB5D}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{127C3BC8-ED71-4655-A7F6-283A02558615}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{1317069A-5991-40A0-9389-94970D7B7235}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\faxapplications.exe |
"{15435D13-6475-4157-A66D-5B24267362E5}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{1E6C5FF1-ABD6-486F-8D7E-F65927F7CE52}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{229C45D9-8172-4491-B95E-4D5C1CFB040A}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{22C377B8-13C0-4496-9CF1-972E209E45EF}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |
"{23277C90-1C73-424E-8AA4-C5998DDFEC06}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{2ACDB7D9-6500-471D-BDAA-944148C674C6}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{2CE71CFE-2854-4228-998B-B369DFF2849B}" = protocol=58 | dir=in | app=system |
"{3172D551-9D80-4182-AD6C-B8466E74033D}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |
"{32135573-E09F-4B51-8D51-B62BEF688ABF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{346AA804-C9D6-4FCB-AB80-F3823B6C6C85}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{39194AE6-9A98-4859-99AB-AA04D4197BCB}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\devicesetup.exe |
"{3A5EA713-6DC1-4E74-8BB9-9519FE74E058}" = protocol=6 | dir=in | app=c:\program files\brother\brmfl10f\faxrx.exe |
"{3DAEABA0-FCEB-4DC3-8434-1E55D8DA00A2}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{4C2EB6A6-FBCA-449F-A78A-5D9C4AEC46AF}" = protocol=6 | dir=in | app=c:\program files\cinemanow\cinemanow media manager\cinemanowshell.exe |
"{4FEA18AA-8354-4C5E-A971-2CCB423BE4C0}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{53A4A855-15C6-43A6-AE64-DBF37665085B}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{55B1EA45-FEF7-4531-8750-37B9C472F7D9}" = protocol=6 | dir=out | app=system |
"{61396B30-F3D9-4EEB-AFF0-C552591370B4}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{65F25203-1058-4299-9E34-E06178172D05}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{6B0D6EB4-1019-4A79-A115-BC3ADD396348}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{6B928B52-7491-41D1-B94F-6F3CE3BD1982}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{7104BAD8-D279-428F-9C96-922BC997D180}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{7B8684A6-C679-4F5F-9C17-6E76A0760A88}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{854BB967-1694-4E92-A442-0638F60D1CC0}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\hpnetworkcommunicatorcom.exe |
"{86CCB421-4F7C-4CB9-B866-A3378D764442}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{8E9B26A3-1AF1-4CCA-B0E6-396C4B4BAE60}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{97CF8045-10F8-4AA5-95E8-B0D6ED81CB4C}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |
"{99E5F008-ED5C-4DF0-B056-808CEB68FC4B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{9CAAB97E-455F-46C9-93C0-DA0F677A0893}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{A0CB0F3C-64B3-46BD-B160-0AEF85365A98}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{A4895B36-8D1B-4888-BB89-1EF7128EE014}" = protocol=17 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{ABC86008-28FD-499D-90CC-A4A07E6C8968}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{B09A9610-A1CD-4003-A84F-9E256876DD5C}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{BC580EF0-D16E-4978-8008-2FE2A7EF6806}" = protocol=17 | dir=in | app=c:\program files\cinemanow\cinemanow media manager\cinemanowshell.exe |
"{BEDDDBC8-ADEA-430D-864A-44F5FBF2ABA5}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{C0510044-2C49-47CD-B923-A179287B8BAA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C520FFC1-6EAB-4761-98AE-99EC13E4F427}" = protocol=6 | dir=in | app=c:\windows\system32\arfc\wrtc.exe |
"{C71223B2-937D-4873-B344-6AC3372FE2A4}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{C9E95C4B-4615-4294-B073-821206175F37}" = protocol=17 | dir=in | app=c:\users\loretta\desktop\roxio 2010\venue\venue.exe |
"{CC758F91-2595-4C26-BDD0-67AE2BD6993C}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{CC82C465-8625-4310-A2B4-61EFCBDF2258}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |
"{CD573553-FE1E-4D8F-99CC-4A91542141D7}" = protocol=17 | dir=in | app=c:\program files\brother\brmfl10f\faxrx.exe |
"{CE2EB273-A950-48C3-9898-5652649F19F9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D2793B46-EC1E-4025-ABD8-11ADD49E88B8}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\sendafax.exe |
"{DA89B402-CB9F-4092-9C02-0EFB48DD23D3}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\digitalwizards.exe |
"{DEE873D0-026D-4C96-87D6-5A6B364A4715}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\hpnetworkcommunicator.exe |
"{F860F1D1-7368-49B8-88F5-428E97406277}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{FB880303-7D70-467A-9547-888873C45F66}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{FFF37DEE-814D-47C1-8548-EE29CDEE74A1}" = protocol=6 | dir=in | app=c:\users\loretta\desktop\roxio 2010\venue\venue.exe |
"TCP Query User{5C226E5B-EA6B-4D77-AE93-721124A412C7}C:\users\loretta\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\loretta\appdata\local\akamai\netsession_win.exe |
"TCP Query User{AF439155-057D-4B03-8B48-FDFE42ACB722}C:\users\loretta\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\loretta\appdata\local\akamai\netsession_win.exe |
"UDP Query User{57819D21-91B0-431C-B236-CCD129B2A175}C:\users\loretta\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\loretta\appdata\local\akamai\netsession_win.exe |
"UDP Query User{9386D33D-7DC6-4D39-82BB-AA20C7529380}C:\users\loretta\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\loretta\appdata\local\akamai\netsession_win.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01001202-823E-46CD-A70E-BEE818F97169}" = Microsoft Encarta Encyclopedia Standard 2002
"{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}" = Scansoft PDF Professional
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25
"{28656860-4728-433C-8AD4-D1A930437BC8}" = Nuance PDF Viewer Plus
"{2B818257-E6C7-4841-8C29-C5C9A982BCE5}" = RICOH Media Driver ver.2.07.01.00
"{2FA81482-5570-4CF0-9A10-D61D2F164916}" = HP Officejet 6600 Help
"{329D7F73-3786-452C-88FA-A333DBFE160B}" = HP Officejet 6600 Product Improvement Study
"{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}" = Brother MFL-Pro Suite MFC-7860DW
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{415FA9AD-DA10-4ABE-97B6-5051D4795C90}" = HP FWUpdateEDO2
"{4333CA76-5C11-4D7C-AA07-C429D1C6B142}" = Snap.Do
"{43CD257A-4F32-4BDE-9B3D-14E6E10C8307}" = Roxio Creator 2010
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{4D0AAB66-E604-4E82-A5AF-01AB97CB506D}" = Roxio Creator 2010 Content
"{539067D5-E3E8-4592-9169-358EFC40982B}" = The Ultimate 25 Game Pack
"{5491453D-8C3E-4785-AC5C-E9A4DABF378A}" = Roxio Venue
"{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}" = Roxio BackOnTrack
"{5FF27D65-35E5-4855-B7ED-59BCFBC85776}" = AVG 2013
"{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}" = Roxio File Backup
"{65A79175-3C4C-41F4-92AF-BA1DDDBA0626}" = Roxio Burn Manager CDB
"{6C0A559F-8583-4B5A-8B50-20BEE15D8E64}" = Nuance PaperPort 12
"{6EF2FDAB-7FBF-4AB9-92CD-594BDDB6A56B}" = PaperPort Image Printer
"{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}" = HP Update
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{733CDF24-0A93-426E-AA89-DF281EB54793}" = Roxio CinePlayer
"{74DC8A26-4E05-40B6-AD11-C9428A1AE150}" = Roxio Creator 2010
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{86DDDAAD-AEB9-42E5-BE01-0E8FABD2BB29}" = Roxio Video Capture USB
"{89A15676-78AE-4D51-BF5B-DEE3E0D46C94}" = Roxio Creator 2010
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{906C01EE-B242-4197-AE85-6C506E1B869B}" = Roxio Burn Manager
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9A00EC4E-27E1-42C4-98DD-662F32AC8870}" = Roxio CinePlayer Decoder Pack
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A121EEDE-C68F-461D-91AA-D48BA226AF1C}" = Roxio Activation Module
"{A1B7B9B3-E1D2-41CA-9B4A-F18DC2710704}" = Microsoft Works 6.0
"{A33E7B0C-B99C-4EC9-B702-8A328B161AF9}" = Roxio Burn
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.03)
"{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime
"{BD3DCAB0-3FE5-44FB-90DA-EFB0A2CD1387}" = Works Synchronization
"{C3A439E4-7303-491F-A678-CEA36A87D517}" = Microsoft Works Suite Add-in for Microsoft Word
"{C4C4BECF-764C-406D-A1AD-F73611B0F668}" = HP Officejet 6600 Basic Device Software
"{C769A271-7E1C-48F9-B331-474600DD4C06}" = Microsoft Picture It! Photo 2002
"{CA6BCA2F-EDEB-408F-850B-31404BE16A61}" = I.R.I.S. OCR
"{CBBB226E-2289-4D29-8E5C-1331E7D71ED9}" = AVG 2013
"{DC19E750-988B-4005-A355-85EF66055EFE}" = Works Suite OS Pack
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"AVG" = AVG 2013
"DefaultTab" = DefaultTab
"HP Photo Creations" = HP Photo Creations
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NIS" = Norton Internet Security
"Roxio PhotoShow" = Roxio PhotoShow
"Shockwave" = Shockwave
"sl-apl" = SelectionLinks
"Vivitar Experience Image Manager" = Vivitar Experience Image Manager

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{C1C3E833-420E-4D78-9BA7-86AEBB272384}" = TopArcadeHits
"Akamai" = Akamai NetSession Interface

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 8/7/2013 4:42:21 PM | Computer Name = Loretta-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\HP\HP Officejet
6600\DriverStore\Pipeline\amd64\hpinkins5D12.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 8/8/2013 12:30:14 AM | Computer Name = Loretta-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\HP\HP Officejet
6600\DriverStore\Pipeline\amd64\hpinkins5D12.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 8/8/2013 10:24:51 AM | Computer Name = Loretta-PC | Source = MsiInstaller | ID = 11706
Description =

Error - 8/8/2013 2:04:39 PM | Computer Name = Loretta-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 10.0.9200.16635 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 462c Start
Time: 01ce9460acbd2233 Termination Time: 60 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id:

Error - 8/9/2013 6:09:20 AM | Computer Name = Loretta-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 10.0.9200.16635 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 5ee4 Start
Time: 01ce94e8546f499c Termination Time: 15 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id:

Error - 8/9/2013 6:27:00 PM | Computer Name = Loretta-PC | Source = Application Error | ID = 1000
Description = Faulting application name: DefaultTabSearch.exe, version: 0.0.0.0,
time stamp: 0x511246e7 Faulting module name: DefaultTabSearch.exe, version: 0.0.0.0,
time stamp: 0x511246e7 Exception code: 0xc0000005 Fault offset: 0x00002c60 Faulting
process id: 0x204 Faulting application start time: 0x01ce954f858cb65b Faulting application
path: C:\Program Files\DefaultTab\DefaultTabSearch.exe Faulting module path: C:\Program
Files\DefaultTab\DefaultTabSearch.exe Report Id: ce937380-0142-11e3-bc69-0021708f4a89

Error - 8/9/2013 6:27:50 PM | Computer Name = Loretta-PC | Source = MsiInstaller | ID = 11706
Description =

Error - 8/9/2013 7:01:19 PM | Computer Name = Loretta-PC | Source = MsiInstaller | ID = 11706
Description =

Error - 8/9/2013 7:02:28 PM | Computer Name = Loretta-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 10.0.9200.16635 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 1534 Start
Time: 01ce95546769a417 Termination Time: 8 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id:

Error - 8/9/2013 7:46:28 PM | Computer Name = Loretta-PC | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2013/08/09 19:46:28.849]: [00004120]: SendSKeySettingToDevice::
Snmp Load Error[0] To[192.168.0.141]

[ Media Center Events ]
Error - 7/7/2013 6:25:29 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 6:25:29 PM - Error connecting to the internet. 6:25:29 PM - Unable
to contact server..

Error - 7/7/2013 6:25:44 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 6:25:35 PM - Error connecting to the internet. 6:25:35 PM - Unable
to contact server..

Error - 7/7/2013 7:25:48 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 7:25:48 PM - Error connecting to the internet. 7:25:48 PM - Unable
to contact server..

Error - 7/7/2013 7:25:54 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 7:25:53 PM - Error connecting to the internet. 7:25:53 PM - Unable
to contact server..

Error - 7/7/2013 8:30:07 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 8:30:07 PM - Error connecting to the internet. 8:30:07 PM - Unable
to contact server..

Error - 7/7/2013 8:30:14 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 8:30:12 PM - Error connecting to the internet. 8:30:12 PM - Unable
to contact server..

Error - 7/8/2013 10:18:38 AM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 10:18:38 AM - Error connecting to the internet. 10:18:38 AM - Unable
to contact server..

Error - 7/8/2013 10:18:48 AM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 10:18:43 AM - Error connecting to the internet. 10:18:43 AM - Unable
to contact server..

Error - 7/29/2013 10:18:54 AM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 10:18:54 AM - Error connecting to the internet. 10:18:54 AM - Unable
to contact server..

Error - 7/29/2013 7:14:32 PM | Computer Name = Loretta-PC | Source = MCUpdate | ID = 0
Description = 10:19:17 AM - Error connecting to the internet. 10:19:17 AM - Unable
to contact server..

[ System Events ]
Error - 8/9/2013 6:57:43 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 8/9/2013 6:57:43 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 8/9/2013 6:57:45 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 8/9/2013 6:57:45 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 8/9/2013 6:57:45 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 8/9/2013 6:57:45 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 8/9/2013 6:57:45 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 8/9/2013 6:57:45 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 8/9/2013 7:01:04 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Roxio
Hard Drive Watcher 12 service to connect.

Error - 8/9/2013 7:01:04 PM | Computer Name = Loretta-PC | Source = Service Control Manager | ID = 7023
Description = The Power service terminated with the following error: %%4203


< End of report >


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:11:15 PM, on 8/9/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16635)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Nuance\PaperPort\pptd40nt.exe
C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
C:\Program Files\ControlCenter4\BrCtrlCntr.exe
C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe
C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files\ControlCenter4\BrCcUxSys.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe
C:\Users\Loretta\AppData\Local\Smartbar\Application\SnapDo.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Windows\system32\RunDll32.exe
C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicatorCom.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicator.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Common Files\PX Storage Engine\VxBlockServer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Loretta\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HelloWorldBHO - {1C8501DD-5580-48AB-B25C-6D5DBE835A6A} - C:\Program Files\OApps\SelectionLinks.dll
O2 - BHO: Snap.DoEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - mscoree.dll (file missing)
O2 - BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: DefaultTabBHO - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Loretta\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll
O2 - BHO: TopArcadeHits Games - {A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} - C:\Users\Loretta\AppData\Local\TopArcadeHits\Toparcadehits.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll
O3 - Toolbar: Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\Nuance\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\Nuance\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [PPort12reminder] "C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [PDFHook] C:\Program Files\Nuance\PDF Viewer Plus\pdfpro5hook.exe
O4 - HKLM\..\Run: [PDF5 Registry Controller] C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe
O4 - HKLM\..\Run: [ControlCenter4] C:\Program Files\ControlCenter4\BrCcBoot.exe /autorun
O4 - HKLM\..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe"
O4 - HKLM\..\Run: [CPMonitor] "C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe"
O4 - HKLM\..\Run: [Desktop Disc Tool] "C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
O4 - HKCU\..\Run: [HP Officejet 6600 (NET)] "C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe" -deviceID "CN32S6RHF705RN:NW" -scfn "HP Officejet 6600 (NET)" -AutoStart 1
O4 - HKCU\..\Run: [Browser Infrastructure Helper] C:\Users\Loretta\AppData\Local\Smartbar\Application\SnapDo.exe startup
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Startup: Monitor Ink Alerts - HP Officejet 6600 (Network).lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.cinemanow.com
O15 - Trusted Zone: http://*.qflix.com
O15 - Trusted Zone: http://*.roxio.com
O15 - Trusted Zone: http://redirect.sonic.com
O15 - Trusted Zone: http://redirect2.sonic.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - AppInit_DLLs: c:\progra~2\browse~1\261519~1.190\{c16c1~1\browse~1.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\aestsrv.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files\Browny02\BrYNSvc.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
O23 - Service: PDFProFiltSrvPP - Nuance Communications, Inc. - C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe
O23 - Service: RoxMediaDB12 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\STacSV.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 10595 bytes
Hi roman623,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Copy and Paste logs directly into the reply window. DO NOT attach the logs unless specifically instructed to do so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Important Note for Vista and Windows 7 & 8 users:

These tools MUST be run from the executable.(.exe) every time you run them with Admin Rights (Right click, choose "Run as Administrator")

Please stay with this topic until I let you know that your system appears to be "All Clear"

=========================

[external image: Posted Image] Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Right click SecurityCheck.exe, select "Run as Administrator" and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
=========================

[external image: Posted Image] AdwCleaner

Download AdwCleaner to your desktop.

Right click and select "Run as Administrator".
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
=========================

[external image: Posted Image] Reboot

=========================

[external image: Posted Image] aswMBR

Download aswMBR.exe and save it to your desktop.

Right click and select "Run as Administrator".
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
=========================

[external image: Posted Image] Re-run OTL (it should be located on your desktop).

Windows Vista and Windows 7 & 8 users Right Click and select "Run as Administrator" on the icon to run it.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt. (No Extras.txt will be produced)
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
=========================

In your next post please provide the following:
  • checkup.txt
  • AdwCleaner[S1].txt
  • aswMBR.txt
  • attach MBR.zip
  • New OTL.txt
  • What symptoms are you experiencing?
I think I did everything right. Symptoms are slow web page loading, all kinds of pop up ads in middle and sides of screen, and just overall slow PC.

Results of screen317's Security Check version 0.99.72
Windows 7 Service Pack 1 x86 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
AVG AntiVirus Free Edition 2013
Norton Internet Security
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Java 7 Update 25
Adobe Reader XI
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
AVG avgwdsvc.exe
AVG avgrsx.exe
AVG avgnsx.exe
AVG avgemc.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 2%
````````````````````End of Log``````````````````````

AdwCleaner


# AdwCleaner v2.306 - Logfile created 08/10/2013 at 17:59:37
# Updated 19/07/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (32 bits)
# User : Loretta - LORETTA-PC
# Boot Mode : Normal
# Running from : C:\Users\Loretta\Desktop\AdwCleaner.exe
# Option [Delete]


***** [Services] *****

Stopped & Deleted : BrowserDefendert
Stopped & Deleted : DefaultTabSearch
Stopped & Deleted : DefaultTabUpdate

***** [Files / Folders] *****

Deleted on reboot : C:\ProgramData\BrowserDefender
File Deleted : C:\END
File Deleted : C:\Windows\system32\dmwu.exe
File Deleted : C:\Windows\system32\ImhxxpComm.dll
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\DefaultTab
Folder Deleted : C:\Program Files\OApps
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\Users\Loretta\AppData\Local\Conduit
Folder Deleted : C:\Users\Loretta\AppData\Local\Smartbar
Folder Deleted : C:\Users\Loretta\AppData\Local\SwvUpdater
Folder Deleted : C:\Users\Loretta\AppData\Local\Temp\AirInstaller
Folder Deleted : C:\Users\Loretta\AppData\Local\Temp\delta
Folder Deleted : C:\Users\Loretta\AppData\Local\Temp\Smartbar
Folder Deleted : C:\Users\Loretta\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Loretta\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Loretta\AppData\LocalLow\Smartbar
Folder Deleted : C:\Users\Loretta\AppData\Roaming\BabSolution
Folder Deleted : C:\Users\Loretta\AppData\Roaming\Babylon
Folder Deleted : C:\Users\Loretta\AppData\Roaming\DefaultTab
Folder Deleted : C:\Users\Loretta\AppData\Roaming\delta
Folder Deleted : C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender

***** [Registry] *****

Data Deleted : HKLM\..\Windows [AppInit_DLLs] = c:\progra~2\browse~1\261519~1.190\{c16c1~1\browse~1.dll
Key Deleted : HKCU\Software\5c558bdfe63cba42
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\DefaultTab
Key Deleted : HKCU\Software\AppDataLow\Software\LyricsContainer
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\Default Tab
Key Deleted : HKCU\Software\DefaultTab
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF6B0594-6008-4327-93E5-608AD710A6FA}
Key Deleted : HKCU\Software\SmartBar
Key Deleted : HKCU\Software\SmartbarBackup
Key Deleted : HKCU\Software\SmartbarLog
Key Deleted : HKCU\Software\WNLT
Key Deleted : HKLM\SOFTWARE\5c558bdfe63cba42
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\DefaultTabBHO.DLL
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowser
Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowser.1
Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX
Key Deleted : HKLM\SOFTWARE\Classes\DefaultTabBHO.DefaultTabBrowserActiveX.1
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.BandObjectAttribute
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.BHO
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.DockingPanel
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.IESmartBar
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.IESmartBarBandObject
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.SmartbarDisplayState
Key Deleted : HKLM\SOFTWARE\Classes\IESmartBar.SmartbarMenuForm
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3289847
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3298566
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3304782
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\Default Tab
Key Deleted : HKLM\Software\DefaultTab
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WajamUpdater_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DefaultTab
Key Deleted : HKLM\Software\Tarma Installer
Key Deleted : HKLM\Software\WNLT
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Browser Infrastructure Helper]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]

***** [Internet Browsers] *****

-\\ Internet Explorer v10.0.9200.16635

[OK] Registry is clean.

*************************

AdwCleaner[R1].txt - [10876 octets] - [10/08/2013 17:58:26]
AdwCleaner[S1].txt - [10498 octets] - [10/08/2013 17:59:37]

########## EOF - C:\AdwCleaner[S1].txt - [10559 octets] ##########


aswMBR


aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-08-10 19:17:44
—————————–
19:17:44.825 OS Version: Windows 6.1.7601 Service Pack 1
19:17:44.825 Number of processors: 2 586 0xF0D
19:17:44.825 ComputerName: LORETTA-PC UserName: Loretta
19:17:50.815 Initialize success
19:18:19.067 AVAST engine defs: 13081001
19:18:35.275 The log file has been saved successfully to "C:\Users\Loretta\Desktop\PC FIX STUFF\aswMBR.txt"


aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-08-10 19:17:44
—————————–
19:17:44.825 OS Version: Windows 6.1.7601 Service Pack 1
19:17:44.825 Number of processors: 2 586 0xF0D
19:17:44.825 ComputerName: LORETTA-PC UserName: Loretta
19:17:50.815 Initialize success
19:18:19.067 AVAST engine defs: 13081001
19:18:35.275 The log file has been saved successfully to "C:\Users\Loretta\Desktop\PC FIX STUFF\aswMBR.txt"
19:18:46.229 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
19:18:46.229 Disk 0 Vendor: WDC_WD5000BPVT-22HXZT3 01.01A01 Size: 476940MB BusType: 11
19:18:46.838 Disk 0 MBR read successfully
19:18:46.838 Disk 0 MBR scan
19:18:46.853 Disk 0 Windows 7 default MBR code
19:18:46.853 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
19:18:46.869 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 476838 MB offset 206848
19:18:46.869 Disk 0 scanning sectors +976771072
19:18:46.947 Disk 0 scanning C:\Windows\system32\drivers
19:19:00.691 Service scanning
19:19:38.630 Modules scanning
19:19:53.621 Disk 0 trace - called modules:
19:19:53.653 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS halmacpi.dll PCIIDEX.SYS msahci.sys
19:19:53.668 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86388030]
19:19:53.684 3 CLASSPNP.SYS[8b7a359e] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x862a9908]
19:19:56.149 AVAST engine scan C:\Windows
19:20:01.281 AVAST engine scan C:\Windows\system32
19:25:02.112 AVAST engine scan C:\Windows\system32\drivers
19:25:27.446 AVAST engine scan C:\Users\Loretta
19:28:56.440 File: C:\Users\Loretta\AppData\Local\Temp\setup.exe **INFECTED** Win32:Adware-gen [Adw]
19:36:52.865 AVAST engine scan C:\ProgramData
19:38:50.473 Scan finished successfully
19:39:22.625 Disk 0 MBR has been saved successfully to "C:\Users\Loretta\Desktop\PC FIX STUFF\MBR.dat"
19:39:22.625 The log file has been saved successfully to "C:\Users\Loretta\Desktop\PC FIX STUFF\aswMBR.txt"


OTL.txt

OTL logfile created on: 8/10/2013 7:41:28 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Loretta\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.96 Gb Total Physical Memory | 1.69 Gb Available Physical Memory | 57.18% Memory free
5.92 Gb Paging File | 4.68 Gb Available in Paging File | 79.10% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.66 Gb Total Space | 424.29 Gb Free Space | 91.12% Space Free | Partition Type: NTFS

Computer Name: LORETTA-PC | User Name: Loretta | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Loretta\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicatorCom.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Free Download Manager\fdm.exe (FreeDownloadManager.ORG)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ControlCenter4\BrCcUxSys.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\ControlCenter4\BrCtrlCntr.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (Nuance Communications, Inc.)
PRC - C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe ()
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\stacsv.exe (IDT, Inc.)
PRC - C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe ()
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
PRC - C:\Program Files\Common Files\PX Storage Engine\VxBlockServer.exe (Sonic Solutions)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\wincfi39.dll ()
MOD - C:\Program Files\Free Download Manager\fdmbtsupp.dll ()
MOD - C:\Program Files\Free Download Manager\iefdm2.dll ()
MOD - C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe ()
MOD - C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe ()
MOD - C:\Program Files\Brother\BrUtilities\BrLogAPI.dll ()


========== Services (SafeList) ==========

SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (NIS) – C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe (Symantec Corporation)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (PDFProFiltSrvPP) – C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe (Nuance Communications, Inc.)
SRV - (BrYNSvc) – C:\Program Files\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
SRV - (RoxWatch12) – C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe (Sonic Solutions)
SRV - (RoxMediaDB12) – C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe (Sonic Solutions)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (aswMBR) – C:\Users\Loretta\AppData\Local\Temp\aswMBR.sys File not found
DRV - (Avglogx) – C:\Windows\System32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130810.005\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130810.005\NAVENG.SYS (Symantec Corporation)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20130809.001\IDSvix86.sys (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\System32\drivers\NIS\1404000.028\symefa.sys (Symantec Corporation)
DRV - (SymDS) – C:\Windows\System32\drivers\NIS\1404000.028\symds.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\NIS\1404000.028\srtsp.sys (Symantec Corporation)
DRV - (SymNetS) – C:\Windows\System32\drivers\NIS\1404000.028\symnets.sys (Symantec Corporation)
DRV - (ccSet_NIS) – C:\Windows\System32\drivers\NIS\1404000.028\ccsetx86.sys (Symantec Corporation)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (SRTSPX) – C:\Windows\System32\drivers\NIS\1404000.028\srtspx.sys (Symantec Corporation)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (SymIRON) – C:\Windows\System32\drivers\NIS\1404000.028\ironx86.sys (Symantec Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (itecir) – C:\Windows\System32\drivers\itecir.sys (ITE Tech. Inc. )
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (WSDPrintDevice) – C:\Windows\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (k57nd60x) – C:\Windows\System32\drivers\k57nd60x.sys (Broadcom Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D0 C5 89 65 AA 87 CE 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{0BE8708C-DF24-41CD-B0A7-FA5017ADE058}: "URL" = http://search.conduit.com/Results.aspx?cti…q={searchTerms}
IE - HKCU\..\SearchScopes\{0DC13E05-3380-46D0-B1D8-4FE1CE0C55B3}: "URL" = http://search.conduit.com/ResultsExt.aspx?…421133&UM=2
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{7D4F1959-3F72-49d5-8E59-F02F8AA6815D}: C:\Program Files\Updater By SweetPacks\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\IPSFFPlgn\ [2013/07/02 10:23:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\coFFPlgn\ [2013/08/10 19:16:17 | 000,000,000 | —D | M]

[2013/07/14 08:28:49 | 000,000,000 | —D | M] (No name found) – C:\Users\Loretta\AppData\Roaming\Mozilla\Extensions
[2013/08/02 22:41:30 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (SelectionLinks) - {1C8501DD-5580-48AB-B25C-6D5DBE835A6A} - C:\Program Files\OApps\SelectionLinks.dll File not found
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (TopArcadeHits Games) - {A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} - C:\Users\Loretta\AppData\Local\TopArcadeHits\Toparcadehits.dll ()
O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter4] C:\Program Files\ControlCenter4\BrCcBoot.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [CPMonitor] C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe ()
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\Nuance\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDF5 Registry Controller] C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDFHook] C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PPort12reminder] C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe (Sonic Solutions)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe (Microsoft® Corporation)
O4 - HKCU..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe (FreeDownloadManager.ORG)
O4 - HKCU..\Run: [HP Officejet 6600 (NET)] C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - HKCU..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm ()
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: cinemanow.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: cinemanow.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: qflix.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: roxio.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: sonic.com ([redirect] http in Trusted sites)
O15 - HKCU\..Trusted Domains: sonic.com ([redirect2] http in Trusted sites)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{27E46421-718C-4440-9642-64B07C9AE1DB}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7E1A25BB-B83F-48B6-BCA8-11A2410C5A66}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/08/10 18:20:27 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Loretta\Desktop\aswMBR.exe
[2013/08/10 17:44:37 | 000,000,000 | —D | C] – C:\Users\Loretta\Desktop\PC FIX STUFF
[2013/08/09 23:04:10 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Free Download Manager
[2013/08/09 23:04:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Download Manager
[2013/08/09 23:04:01 | 000,000,000 | —D | C] – C:\Program Files\Free Download Manager
[2013/08/09 20:05:42 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Loretta\Desktop\HiJackThis.exe
[2013/08/09 19:34:18 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Loretta\Desktop\OTL.exe
[2013/08/08 10:42:45 | 000,000,000 | —D | C] – C:\ProgramData\Visan
[2013/08/08 10:42:45 | 000,000,000 | —D | C] – C:\ProgramData\HP Photo Creations
[2013/08/08 10:42:45 | 000,000,000 | —D | C] – C:\Program Files\HP Photo Creations
[2013/08/08 10:42:32 | 000,000,000 | —D | C] – C:\Windows\Hewlett-Packard
[2013/08/02 22:41:39 | 000,000,000 | —D | C] – C:\Windows\System32\Extensions
[2013/08/02 22:41:38 | 000,000,000 | —D | C] – C:\Windows\System32\searchplugins
[2013/08/02 22:41:30 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/08/02 22:41:23 | 000,000,000 | —D | C] – C:\ProgramData\BrowserDefender
[2013/08/02 22:40:27 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TopArcadeHits
[2013/08/02 22:40:20 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Local\TopArcadeHits
[2013/07/30 09:54:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/07/23 08:03:06 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Local\CRE
[2013/07/23 08:02:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OtShot
[2013/07/23 08:01:56 | 000,000,000 | —D | C] – C:\Program Files\OtShot
[2013/07/23 08:01:03 | 000,000,000 | —D | C] – C:\ProgramData\ZalmanInstaller_52330
[2013/07/20 01:51:00 | 000,246,072 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avglogx.sys
[2013/07/20 01:50:56 | 000,208,184 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidsdriverx.sys
[2013/07/20 01:50:56 | 000,060,216 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidshx.sys
[2013/07/20 01:50:50 | 000,171,320 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2013/07/18 10:10:09 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/07/17 07:05:20 | 001,247,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/07/17 06:53:17 | 000,745,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/07/17 06:53:17 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/07/17 06:53:17 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/07/17 06:53:16 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/07/17 06:53:16 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/07/17 06:53:16 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/07/17 06:53:16 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/07/17 06:53:16 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/07/17 06:53:16 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/07/17 06:53:15 | 000,493,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/07/17 06:53:14 | 002,706,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/07/17 06:53:14 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/07/17 06:53:14 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/07/17 06:53:14 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/07/17 06:53:14 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/07/17 06:53:14 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/07/17 06:53:14 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/07/17 06:53:14 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/07/17 06:53:13 | 002,877,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/07/17 06:53:13 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/07/17 06:53:13 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/07/17 06:53:13 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/07/17 06:53:13 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/07/17 06:53:12 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/07/17 06:53:12 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/07/17 06:53:12 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/07/17 06:53:12 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/07/17 06:53:12 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/07/17 06:53:12 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/07/17 06:53:12 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/07/17 06:53:12 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/07/17 06:53:12 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/07/17 06:53:11 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/07/17 06:53:11 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/07/17 06:53:11 | 000,242,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/07/17 06:53:11 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/07/17 06:51:43 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/07/17 06:51:43 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/07/17 06:51:43 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/07/17 06:51:42 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/07/17 06:51:42 | 001,080,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/07/17 06:51:42 | 000,604,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/07/17 06:51:42 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/07/17 06:51:42 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/07/17 06:51:42 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/07/17 06:51:42 | 000,207,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/07/17 06:51:42 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/07/17 06:51:41 | 003,419,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/07/17 06:51:41 | 001,988,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/07/17 06:51:41 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/07/17 06:51:41 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/07/14 08:28:49 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Mozilla

========== Files - Modified Within 30 Days ==========

[2013/08/10 19:32:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/08/10 19:23:42 | 000,013,440 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/10 19:23:42 | 000,013,440 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/10 19:17:25 | 000,001,914 | —- | M] () – C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Officejet 6600 (Network).lnk
[2013/08/10 19:15:57 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/10 19:15:55 | 2383,589,376 | -HS- | M] () – C:\hiberfil.sys
[2013/08/10 19:15:50 | 331,249,904 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/08/10 19:00:35 | 000,000,272 | —- | M] () – C:\Windows\tasks\TopArcadeHits.job
[2013/08/10 18:19:35 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Loretta\Desktop\aswMBR.exe
[2013/08/10 18:00:02 | 000,000,098 | —- | M] () – C:\Windows\DeleteOnReboot.bat
[2013/08/10 17:52:29 | 000,666,633 | —- | M] () – C:\Users\Loretta\Desktop\AdwCleaner.exe
[2013/08/10 17:37:55 | 000,891,115 | —- | M] () – C:\Users\Loretta\Desktop\SecurityCheck.exe
[2013/08/09 23:04:07 | 000,001,029 | —- | M] () – C:\Users\Loretta\Desktop\Free Download Manager.lnk
[2013/08/09 20:06:54 | 000,625,664 | —- | M] () – C:\Users\Loretta\Desktop\dds.scr
[2013/08/09 20:05:42 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Loretta\Desktop\HiJackThis.exe
[2013/08/09 19:34:18 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Loretta\Desktop\OTL.exe
[2013/08/08 10:43:02 | 000,000,328 | —- | M] () – C:\Users\Loretta\Desktop\HP Printer Diagnostic Tools.url
[2013/08/08 10:42:48 | 000,001,953 | —- | M] () – C:\Users\Public\Desktop\HP Photo Creations.lnk
[2013/08/08 10:35:39 | 000,015,872 | —- | M] () – C:\Users\Loretta\Documents\Red Hat List.xlr
[2013/08/08 10:35:39 | 000,006,398 | —- | M] () – C:\Users\Loretta\AppData\Roaming\wklnhst.dat
[2013/08/04 16:40:55 | 000,017,920 | —- | M] () – C:\Users\Loretta\Documents\Sew Classy Ladies.xlr
[2013/07/30 09:54:01 | 000,000,935 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/07/29 19:21:38 | 000,000,131 | —- | M] () – C:\Users\Loretta\Desktop\Jordan River Arts Council.url
[2013/07/26 11:43:34 | 000,624,178 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/07/26 11:43:34 | 000,106,522 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/07/26 08:45:39 | 000,000,202 | —- | M] () – C:\Users\Loretta\Desktop\How To Make a TV Tray Ironing Board American Quilting.url
[2013/07/20 01:51:00 | 000,246,072 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avglogx.sys
[2013/07/20 01:50:56 | 000,208,184 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidsdriverx.sys
[2013/07/20 01:50:56 | 000,060,216 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidshx.sys
[2013/07/20 01:50:50 | 000,171,320 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2013/07/17 06:53:17 | 000,745,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/07/17 06:53:17 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/07/17 06:53:17 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/07/17 06:53:16 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/07/17 06:53:16 | 000,158,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/07/17 06:53:16 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/07/17 06:53:16 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/07/17 06:53:16 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/07/17 06:53:16 | 000,039,424 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/07/17 06:53:15 | 000,493,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/07/17 06:53:14 | 002,706,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/07/17 06:53:14 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/07/17 06:53:14 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/07/17 06:53:14 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/07/17 06:53:14 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/07/17 06:53:14 | 000,041,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/07/17 06:53:14 | 000,038,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/07/17 06:53:14 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/07/17 06:53:13 | 002,877,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/07/17 06:53:13 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/07/17 06:53:13 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/07/17 06:53:13 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/07/17 06:53:13 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/07/17 06:53:12 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/07/17 06:53:12 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/07/17 06:53:12 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/07/17 06:53:12 | 000,357,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/07/17 06:53:12 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/07/17 06:53:12 | 000,226,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/07/17 06:53:12 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/07/17 06:53:12 | 000,042,496 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/07/17 06:53:12 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/07/17 06:53:12 | 000,025,185 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2013/07/17 06:53:11 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/07/17 06:53:11 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/07/17 06:53:11 | 000,242,200 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/07/17 06:53:11 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/07/17 06:51:43 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/07/17 06:51:43 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/07/17 06:51:43 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/07/17 06:51:42 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/07/17 06:51:42 | 001,080,832 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/07/17 06:51:42 | 000,604,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/07/17 06:51:42 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/07/17 06:51:42 | 000,249,856 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/07/17 06:51:42 | 000,220,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/07/17 06:51:42 | 000,207,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/07/17 06:51:42 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/07/17 06:51:41 | 003,419,136 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/07/17 06:51:41 | 001,988,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/07/17 06:51:41 | 000,293,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/07/17 06:51:41 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/07/16 12:45:04 | 000,013,889 | —- | M] () – C:\Users\Loretta\Desktop\Ron Feroni Amm. Schedule - Shortcut.lnk
[2013/07/16 12:43:03 | 000,005,064 | —- | M] () – C:\Users\Loretta\Desktop\Jenny Amortization Schedule - Shortcut.lnk
[2013/07/16 12:35:45 | 000,100,864 | —- | M] () – C:\Users\Loretta\Documents\Ron Feroni Amm. Schedule.xlr

========== Files Created - No Company Name ==========

[2013/08/10 17:59:47 | 000,000,098 | —- | C] () – C:\Windows\DeleteOnReboot.bat
[2013/08/10 17:52:16 | 000,666,633 | —- | C] () – C:\Users\Loretta\Desktop\AdwCleaner.exe
[2013/08/10 17:37:33 | 000,891,115 | —- | C] () – C:\Users\Loretta\Desktop\SecurityCheck.exe
[2013/08/09 23:04:06 | 000,001,029 | —- | C] () – C:\Users\Loretta\Desktop\Free Download Manager.lnk
[2013/08/09 20:06:54 | 000,625,664 | —- | C] () – C:\Users\Loretta\Desktop\dds.scr
[2013/08/08 10:43:02 | 000,000,328 | —- | C] () – C:\Users\Loretta\Desktop\HP Printer Diagnostic Tools.url
[2013/08/08 10:42:47 | 000,001,953 | —- | C] () – C:\Users\Public\Desktop\HP Photo Creations.lnk
[2013/08/02 22:40:20 | 000,000,272 | —- | C] () – C:\Windows\tasks\TopArcadeHits.job
[2013/07/29 19:21:38 | 000,000,131 | —- | C] () – C:\Users\Loretta\Desktop\Jordan River Arts Council.url
[2013/07/26 08:45:39 | 000,000,202 | —- | C] () – C:\Users\Loretta\Desktop\How To Make a TV Tray Ironing Board American Quilting.url
[2013/07/23 08:02:00 | 000,000,953 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OtShot.lnk
[2013/07/18 10:10:04 | 331,249,904 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/07/17 06:53:12 | 000,025,185 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2013/07/16 12:45:04 | 000,013,889 | —- | C] () – C:\Users\Loretta\Desktop\Ron Feroni Amm. Schedule - Shortcut.lnk
[2013/07/16 12:43:03 | 000,005,064 | —- | C] () – C:\Users\Loretta\Desktop\Jenny Amortization Schedule - Shortcut.lnk
[2013/07/16 12:35:45 | 000,100,864 | —- | C] () – C:\Users\Loretta\Documents\Ron Feroni Amm. Schedule.xlr
[2013/07/14 08:33:03 | 000,002,441 | —- | C] () – C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
[2013/07/10 09:33:30 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2013/06/22 09:40:08 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2013/06/17 07:16:10 | 000,000,258 | RHS- | C] () – C:\Users\Loretta\ntuser.pol
[2013/06/16 08:04:03 | 000,000,246 | —- | C] () – C:\Windows\Brpfx04a.ini
[2013/06/16 08:04:03 | 000,000,093 | —- | C] () – C:\Windows\brpcfx.ini
[2013/06/16 08:02:11 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2013/06/16 08:02:11 | 000,000,000 | —- | C] () – C:\Windows\brdfxspd.dat
[2013/06/16 08:01:51 | 000,045,056 | —- | C] () – C:\Windows\System32\BRTCPCON.DLL
[2013/06/16 08:01:44 | 000,000,114 | —- | C] () – C:\Windows\System32\BRLMW03A.INI
[2013/06/16 08:01:43 | 000,000,050 | —- | C] () – C:\Windows\System32\BRADM10A.DAT
[2013/06/14 10:00:59 | 000,006,398 | —- | C] () – C:\Users\Loretta\AppData\Roaming\wklnhst.dat

========== ZeroAccess Check ==========

[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 21:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >

Attachments:

Hi roman623,

[external image: Posted Image] Run OTL.exe

Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snapdo.com/?publisher=SnapdoGO…Date=14/07/2013
    IE - HKCU\..\SearchScopes\{0BE8708C-DF24-41CD-B0A7-FA5017ADE058}: "URL" = http://search.conduit.com/Results.aspx?cti…q={searchTerms}
    IE - HKCU\..\SearchScopes\{0DC13E05-3380-46D0-B1D8-4FE1CE0C55B3}: "URL" = http://search.conduit.com/ResultsExt.aspx?…421133&UM=2
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{7D4F1959-3F72-49d5-8E59-F02F8AA6815D}: C:\Program Files\Updater By SweetPacks\Firefox
    O2 - BHO: (SelectionLinks) - {1C8501DD-5580-48AB-B25C-6D5DBE835A6A} - C:\Program Files\OApps\SelectionLinks.dll File not found
    O2 - BHO: (TopArcadeHits Games) - {A7A9D7E7-E0C0-4202-9F13-6A06BD073CDA} - C:\Users\Loretta\AppData\Local\TopArcadeHits\Toparcadehits.dll ()
    O15 - HKCU\..Trusted Domains: cinemanow.com ([]http in Trusted sites)
    O15 - HKCU\..Trusted Domains: cinemanow.com ([]https in Trusted sites)
    O15 - HKCU\..Trusted Domains: qflix.com ([]http in Trusted sites)
    O15 - HKCU\..Trusted Domains: roxio.com ([]http in Trusted sites)
    O15 - HKCU\..Trusted Domains: sonic.com ([redirect] http in Trusted sites)
    O15 - HKCU\..Trusted Domains: sonic.com ([redirect2] http in Trusted sites)
    [2013/08/02 22:40:27 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TopArcadeHits
    [2013/08/02 22:40:20 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Local\TopArcadeHits
    [2013/08/10 19:00:35 | 000,000,272 | —- | M] () – C:\Windows\tasks\TopArcadeHits.job
    
    :Files
    C:\Users\Loretta\AppData\Local\Temp\setup.exe
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptyjava]
    [emptyflash]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
=========================

[external image: Posted Image] Junkware Removal Tool

Please download Junkware Removal Tool to your desktop.

Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Shut down your protection software now to avoid potential conflicts.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
=========================

[external image: Posted Image] Then re-run OTL and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

=========================

In your next post please provide the following:
  • OTL fix log
  • JRT.txt
  • Fresh OTL.txt
I cannot find the fix log from OTL.




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.4.1 (08.10.2013:1)
OS: Windows 7 Home Premium x86
Ran by [removed] on Sat 08/10/2013 at 22:19:29.92
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\free download manager
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL\\Default
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\searchURL\\Default



~~~ Registry Keys

Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1BB8B3AE-757D-443F-B3A4-0629E709B0D9}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}



~~~ Files

Successfully deleted: [File] C:\Windows\system32\tasks\browserdefendert
Successfully deleted: [File] C:\Windows\system32\tasks\epupdater



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\browserdefender"
Successfully deleted: [Folder] "C:\Program Files\otshot"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 08/10/2013 at 22:22:05.63
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


OTL logfile created on: 8/10/2013 10:24:26 PM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Loretta\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.96 Gb Total Physical Memory | 2.03 Gb Available Physical Memory | 68.46% Memory free
5.92 Gb Paging File | 4.82 Gb Available in Paging File | 81.38% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.66 Gb Total Space | 424.06 Gb Free Space | 91.07% Space Free | Partition Type: NTFS

Computer Name: LORETTA-PC | User Name: Loretta | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Loretta\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\AVG\AVG2013\avgcfgex.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicator.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicatorCom.exe (Hewlett-Packard Co.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ControlCenter4\BrCcUxSys.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\ControlCenter4\BrCtrlCntr.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (Nuance Communications, Inc.)
PRC - C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe ()
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\stacsv.exe (IDT, Inc.)
PRC - C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe ()
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
PRC - C:\Program Files\Common Files\PX Storage Engine\VxBlockServer.exe (Sonic Solutions)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\wincfi39.dll ()
MOD - C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe ()
MOD - C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe ()
MOD - C:\Program Files\Brother\BrUtilities\BrLogAPI.dll ()


========== Services (SafeList) ==========

SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (NIS) – C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe (Symantec Corporation)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (PDFProFiltSrvPP) – C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe (Nuance Communications, Inc.)
SRV - (BrYNSvc) – C:\Program Files\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
SRV - (RoxWatch12) – C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe (Sonic Solutions)
SRV - (RoxMediaDB12) – C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe (Sonic Solutions)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (Avglogx) – C:\Windows\System32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130810.005\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130810.005\NAVENG.SYS (Symantec Corporation)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20130809.001\IDSvix86.sys (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\System32\drivers\NIS\1404000.028\symefa.sys (Symantec Corporation)
DRV - (SymDS) – C:\Windows\System32\drivers\NIS\1404000.028\symds.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\NIS\1404000.028\srtsp.sys (Symantec Corporation)
DRV - (SymNetS) – C:\Windows\System32\drivers\NIS\1404000.028\symnets.sys (Symantec Corporation)
DRV - (ccSet_NIS) – C:\Windows\System32\drivers\NIS\1404000.028\ccsetx86.sys (Symantec Corporation)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (SRTSPX) – C:\Windows\System32\drivers\NIS\1404000.028\srtspx.sys (Symantec Corporation)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (SymIRON) – C:\Windows\System32\drivers\NIS\1404000.028\ironx86.sys (Symantec Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (itecir) – C:\Windows\System32\drivers\itecir.sys (ITE Tech. Inc. )
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (WSDPrintDevice) – C:\Windows\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (k57nd60x) – C:\Windows\System32\drivers\k57nd60x.sys (Broadcom Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D0 C5 89 65 AA 87 CE 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\IPSFFPlgn\ [2013/07/02 10:23:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\coFFPlgn\ [2013/08/10 22:08:32 | 000,000,000 | —D | M]

[2013/07/14 08:28:49 | 000,000,000 | —D | M] (No name found) – C:\Users\Loretta\AppData\Roaming\Mozilla\Extensions
[2013/08/02 22:41:30 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter4] C:\Program Files\ControlCenter4\BrCcBoot.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [CPMonitor] C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe ()
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\Nuance\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDF5 Registry Controller] C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDFHook] C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PPort12reminder] C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe (Sonic Solutions)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe (Microsoft® Corporation)
O4 - HKCU..\Run: [HP Officejet 6600 (NET)] C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - HKCU..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm ()
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{27E46421-718C-4440-9642-64B07C9AE1DB}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7E1A25BB-B83F-48B6-BCA8-11A2410C5A66}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/08/10 22:19:27 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/08/10 22:11:18 | 000,958,418 | —- | C] (Oleg N. Scherbakov) – C:\Users\Loretta\Desktop\JRT.exe
[2013/08/10 22:05:38 | 000,000,000 | —D | C] – C:\_OTL
[2013/08/10 18:20:27 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Loretta\Desktop\aswMBR.exe
[2013/08/10 17:44:37 | 000,000,000 | —D | C] – C:\Users\Loretta\Desktop\PC FIX STUFF
[2013/08/09 23:04:10 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Free Download Manager
[2013/08/09 23:04:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Download Manager
[2013/08/09 23:04:01 | 000,000,000 | —D | C] – C:\Program Files\Free Download Manager
[2013/08/09 20:05:42 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Loretta\Desktop\HiJackThis.exe
[2013/08/09 19:34:18 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Loretta\Desktop\OTL.exe
[2013/08/08 10:42:45 | 000,000,000 | —D | C] – C:\ProgramData\Visan
[2013/08/08 10:42:45 | 000,000,000 | —D | C] – C:\ProgramData\HP Photo Creations
[2013/08/08 10:42:45 | 000,000,000 | —D | C] – C:\Program Files\HP Photo Creations
[2013/08/08 10:42:32 | 000,000,000 | —D | C] – C:\Windows\Hewlett-Packard
[2013/08/02 22:41:39 | 000,000,000 | —D | C] – C:\Windows\System32\Extensions
[2013/08/02 22:41:38 | 000,000,000 | —D | C] – C:\Windows\System32\searchplugins
[2013/08/02 22:41:30 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/07/30 09:54:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/07/23 08:03:06 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Local\CRE
[2013/07/23 08:02:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OtShot
[2013/07/23 08:01:03 | 000,000,000 | —D | C] – C:\ProgramData\ZalmanInstaller_52330
[2013/07/20 01:51:00 | 000,246,072 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avglogx.sys
[2013/07/20 01:50:56 | 000,208,184 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidsdriverx.sys
[2013/07/20 01:50:56 | 000,060,216 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidshx.sys
[2013/07/20 01:50:50 | 000,171,320 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2013/07/18 10:10:09 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/07/17 07:05:20 | 001,247,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/07/17 06:53:17 | 000,745,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/07/17 06:53:17 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/07/17 06:53:17 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/07/17 06:53:16 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/07/17 06:53:16 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/07/17 06:53:16 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/07/17 06:53:16 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/07/17 06:53:16 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/07/17 06:53:16 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/07/17 06:53:15 | 000,493,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/07/17 06:53:14 | 002,706,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/07/17 06:53:14 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/07/17 06:53:14 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/07/17 06:53:14 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/07/17 06:53:14 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/07/17 06:53:14 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/07/17 06:53:14 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/07/17 06:53:14 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/07/17 06:53:13 | 002,877,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/07/17 06:53:13 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/07/17 06:53:13 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/07/17 06:53:13 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/07/17 06:53:13 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/07/17 06:53:12 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/07/17 06:53:12 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/07/17 06:53:12 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/07/17 06:53:12 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/07/17 06:53:12 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/07/17 06:53:12 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/07/17 06:53:12 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/07/17 06:53:12 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/07/17 06:53:12 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/07/17 06:53:11 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/07/17 06:53:11 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/07/17 06:53:11 | 000,242,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/07/17 06:53:11 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/07/17 06:51:43 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/07/17 06:51:43 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/07/17 06:51:43 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/07/17 06:51:42 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/07/17 06:51:42 | 001,080,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/07/17 06:51:42 | 000,604,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/07/17 06:51:42 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/07/17 06:51:42 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/07/17 06:51:42 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/07/17 06:51:42 | 000,207,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/07/17 06:51:42 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/07/17 06:51:41 | 003,419,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/07/17 06:51:41 | 001,988,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/07/17 06:51:41 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/07/17 06:51:41 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/07/14 08:28:49 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Mozilla

========== Files - Modified Within 30 Days ==========

[2013/08/10 22:16:06 | 000,013,440 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/10 22:16:06 | 000,013,440 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/10 22:11:19 | 000,958,418 | —- | M] (Oleg N. Scherbakov) – C:\Users\Loretta\Desktop\JRT.exe
[2013/08/10 22:08:47 | 000,001,914 | —- | M] () – C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Officejet 6600 (Network).lnk
[2013/08/10 22:08:27 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/10 22:08:23 | 2383,589,376 | -HS- | M] () – C:\hiberfil.sys
[2013/08/10 19:32:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/08/10 19:15:50 | 331,249,904 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/08/10 18:19:35 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Loretta\Desktop\aswMBR.exe
[2013/08/10 18:00:02 | 000,000,098 | —- | M] () – C:\Windows\DeleteOnReboot.bat
[2013/08/10 17:52:29 | 000,666,633 | —- | M] () – C:\Users\Loretta\Desktop\AdwCleaner.exe
[2013/08/10 17:37:55 | 000,891,115 | —- | M] () – C:\Users\Loretta\Desktop\SecurityCheck.exe
[2013/08/09 23:04:07 | 000,001,029 | —- | M] () – C:\Users\Loretta\Desktop\Free Download Manager.lnk
[2013/08/09 20:06:54 | 000,625,664 | —- | M] () – C:\Users\Loretta\Desktop\dds.scr
[2013/08/09 20:05:42 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Loretta\Desktop\HiJackThis.exe
[2013/08/09 19:34:18 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Loretta\Desktop\OTL.exe
[2013/08/08 10:43:02 | 000,000,328 | —- | M] () – C:\Users\Loretta\Desktop\HP Printer Diagnostic Tools.url
[2013/08/08 10:42:48 | 000,001,953 | —- | M] () – C:\Users\Public\Desktop\HP Photo Creations.lnk
[2013/08/08 10:35:39 | 000,015,872 | —- | M] () – C:\Users\Loretta\Documents\Red Hat List.xlr
[2013/08/08 10:35:39 | 000,006,398 | —- | M] () – C:\Users\Loretta\AppData\Roaming\wklnhst.dat
[2013/08/04 16:40:55 | 000,017,920 | —- | M] () – C:\Users\Loretta\Documents\Sew Classy Ladies.xlr
[2013/07/30 09:54:01 | 000,000,935 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/07/29 19:21:38 | 000,000,131 | —- | M] () – C:\Users\Loretta\Desktop\Jordan River Arts Council.url
[2013/07/26 11:43:34 | 000,624,178 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/07/26 11:43:34 | 000,106,522 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/07/26 08:45:39 | 000,000,202 | —- | M] () – C:\Users\Loretta\Desktop\How To Make a TV Tray Ironing Board American Quilting.url
[2013/07/20 01:51:00 | 000,246,072 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avglogx.sys
[2013/07/20 01:50:56 | 000,208,184 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidsdriverx.sys
[2013/07/20 01:50:56 | 000,060,216 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidshx.sys
[2013/07/20 01:50:50 | 000,171,320 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2013/07/17 06:53:17 | 000,745,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/07/17 06:53:17 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/07/17 06:53:17 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/07/17 06:53:16 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/07/17 06:53:16 | 000,158,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/07/17 06:53:16 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/07/17 06:53:16 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/07/17 06:53:16 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/07/17 06:53:16 | 000,039,424 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/07/17 06:53:15 | 000,493,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/07/17 06:53:14 | 002,706,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/07/17 06:53:14 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/07/17 06:53:14 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/07/17 06:53:14 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/07/17 06:53:14 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/07/17 06:53:14 | 000,041,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/07/17 06:53:14 | 000,038,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/07/17 06:53:14 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/07/17 06:53:13 | 002,877,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/07/17 06:53:13 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/07/17 06:53:13 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/07/17 06:53:13 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/07/17 06:53:13 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/07/17 06:53:12 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/07/17 06:53:12 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/07/17 06:53:12 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/07/17 06:53:12 | 000,357,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/07/17 06:53:12 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/07/17 06:53:12 | 000,226,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/07/17 06:53:12 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/07/17 06:53:12 | 000,042,496 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/07/17 06:53:12 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/07/17 06:53:12 | 000,025,185 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2013/07/17 06:53:11 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/07/17 06:53:11 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/07/17 06:53:11 | 000,242,200 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/07/17 06:53:11 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/07/17 06:51:43 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/07/17 06:51:43 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/07/17 06:51:43 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/07/17 06:51:42 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/07/17 06:51:42 | 001,080,832 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/07/17 06:51:42 | 000,604,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/07/17 06:51:42 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/07/17 06:51:42 | 000,249,856 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/07/17 06:51:42 | 000,220,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/07/17 06:51:42 | 000,207,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/07/17 06:51:42 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/07/17 06:51:41 | 003,419,136 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/07/17 06:51:41 | 001,988,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/07/17 06:51:41 | 000,293,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/07/17 06:51:41 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/07/16 12:45:04 | 000,013,889 | —- | M] () – C:\Users\Loretta\Desktop\Ron Feroni Amm. Schedule - Shortcut.lnk
[2013/07/16 12:43:03 | 000,005,064 | —- | M] () – C:\Users\Loretta\Desktop\Jenny Amortization Schedule - Shortcut.lnk
[2013/07/16 12:35:45 | 000,100,864 | —- | M] () – C:\Users\Loretta\Documents\Ron Feroni Amm. Schedule.xlr

========== Files Created - No Company Name ==========

[2013/08/10 17:59:47 | 000,000,098 | —- | C] () – C:\Windows\DeleteOnReboot.bat
[2013/08/10 17:52:16 | 000,666,633 | —- | C] () – C:\Users\Loretta\Desktop\AdwCleaner.exe
[2013/08/10 17:37:33 | 000,891,115 | —- | C] () – C:\Users\Loretta\Desktop\SecurityCheck.exe
[2013/08/09 23:04:06 | 000,001,029 | —- | C] () – C:\Users\Loretta\Desktop\Free Download Manager.lnk
[2013/08/09 20:06:54 | 000,625,664 | —- | C] () – C:\Users\Loretta\Desktop\dds.scr
[2013/08/08 10:43:02 | 000,000,328 | —- | C] () – C:\Users\Loretta\Desktop\HP Printer Diagnostic Tools.url
[2013/08/08 10:42:47 | 000,001,953 | —- | C] () – C:\Users\Public\Desktop\HP Photo Creations.lnk
[2013/07/29 19:21:38 | 000,000,131 | —- | C] () – C:\Users\Loretta\Desktop\Jordan River Arts Council.url
[2013/07/26 08:45:39 | 000,000,202 | —- | C] () – C:\Users\Loretta\Desktop\How To Make a TV Tray Ironing Board American Quilting.url
[2013/07/23 08:02:00 | 000,000,953 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OtShot.lnk
[2013/07/18 10:10:04 | 331,249,904 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/07/17 06:53:12 | 000,025,185 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2013/07/16 12:45:04 | 000,013,889 | —- | C] () – C:\Users\Loretta\Desktop\Ron Feroni Amm. Schedule - Shortcut.lnk
[2013/07/16 12:43:03 | 000,005,064 | —- | C] () – C:\Users\Loretta\Desktop\Jenny Amortization Schedule - Shortcut.lnk
[2013/07/16 12:35:45 | 000,100,864 | —- | C] () – C:\Users\Loretta\Documents\Ron Feroni Amm. Schedule.xlr
[2013/07/14 08:33:03 | 000,002,441 | —- | C] () – C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
[2013/07/10 09:33:30 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2013/06/22 09:40:08 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2013/06/17 07:16:10 | 000,000,258 | RHS- | C] () – C:\Users\Loretta\ntuser.pol
[2013/06/16 08:04:03 | 000,000,246 | —- | C] () – C:\Windows\Brpfx04a.ini
[2013/06/16 08:04:03 | 000,000,093 | —- | C] () – C:\Windows\brpcfx.ini
[2013/06/16 08:02:11 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2013/06/16 08:02:11 | 000,000,000 | —- | C] () – C:\Windows\brdfxspd.dat
[2013/06/16 08:01:51 | 000,045,056 | —- | C] () – C:\Windows\System32\BRTCPCON.DLL
[2013/06/16 08:01:44 | 000,000,114 | —- | C] () – C:\Windows\System32\BRLMW03A.INI
[2013/06/16 08:01:43 | 000,000,050 | —- | C] () – C:\Windows\System32\BRADM10A.DAT
[2013/06/14 10:00:59 | 000,006,398 | —- | C] () – C:\Users\Loretta\AppData\Roaming\wklnhst.dat

========== ZeroAccess Check ==========

[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 21:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >
Hi roman623,

[external image: Posted Image] Run OTL.exe

Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    [2013/08/09 23:04:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Download Manager
    [2013/08/09 23:04:01 | 000,000,000 | —D | C] – C:\Program Files\Free Download Manager
    [2013/08/09 23:04:06 | 000,001,029 | —- | C] () – C:\Users\Loretta\Desktop\Free Download Manager.lnk
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
=========================

[external image: Posted Image] ComboFix

Refer to the ComboFix User's Guide

  • Download ComboFix from the following location:

    Link

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.
    ———————————————————————————————
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

=========================

In your next post please provide the following:
  • OTL.txt
  • ComboFix.txt
  • How is the computer running?
PC is running AWESOME! Can't thank you and Whatthetech enough! ComboFix 13-08-11.02 - Loretta 08/11/2013 7:54.1.2 - x86 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3031.2075 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} SP: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664} SP: Norton Internet Security *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Loretta\AppData\Local\assembly\tmp . . ((((((((((((((((((((((((( Files Created from 2013-07-11 to 2013-08-11 ))))))))))))))))))))))))))))))) . . 2013-08-11 12:00 . 2013-08-11 12:00 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-08-11 02:19 . 2013-08-11 02:19 ——– d—–w- c:\windows\ERUNT 2013-08-11 02:05 . 2013-08-11 02:05 ——– d—–w- C:\_OTL 2013-08-10 21:59 . 2013-08-10 22:00 98 —-a-w- c:\windows\DeleteOnReboot.bat 2013-08-10 03:04 . 2013-08-11 02:59 ——– d—–w- c:\users\Loretta\AppData\Roaming\Free Download Manager 2013-08-08 14:42 . 2013-08-08 14:42 ——– d—–w- c:\program files\HP Photo Creations 2013-08-08 14:42 . 2013-08-08 14:42 ——– d—–w- c:\programdata\HP Photo Creations 2013-08-08 14:42 . 2013-08-08 14:42 ——– d—–w- c:\programdata\Visan 2013-08-08 14:42 . 2013-08-08 14:42 ——– d—–w- c:\windows\Hewlett-Packard 2013-08-03 02:41 . 2013-08-03 02:41 ——– d—–w- c:\windows\system32\Extensions 2013-08-03 02:41 . 2013-08-03 02:41 ——– d—–w- c:\windows\system32\searchplugins 2013-07-23 12:03 . 2013-07-30 12:38 ——– d—–w- c:\users\Loretta\AppData\Local\CRE 2013-07-23 12:01 . 2013-07-23 12:02 ——– d—–w- c:\programdata\ZalmanInstaller_52330 2013-07-20 05:51 . 2013-07-20 05:51 246072 —-a-w- c:\windows\system32\drivers\avglogx.sys 2013-07-20 05:50 . 2013-07-20 05:50 60216 —-a-w- c:\windows\system32\drivers\avgidshx.sys 2013-07-20 05:50 . 2013-07-20 05:50 208184 —-a-w- c:\windows\system32\drivers\avgidsdriverx.sys 2013-07-20 05:50 . 2013-07-20 05:50 171320 —-a-w- c:\windows\system32\drivers\avgldx86.sys 2013-07-17 11:05 . 2013-04-09 23:34 1247744 —-a-w- c:\windows\system32\DWrite.dll 2013-07-17 11:05 . 2013-04-17 07:02 1230336 —-a-w- c:\windows\system32\WindowsCodecs.dll 2013-07-17 10:51 . 2013-07-17 10:51 9728 —ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-07-30 00:26 . 2013-06-14 01:51 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll 2013-07-30 00:26 . 2013-06-14 01:51 2876528 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2013-07-30 00:15 . 2013-06-14 01:50 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2013-07-30 00:15 . 2013-06-14 01:50 539984 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2013-07-10 05:32 . 2013-07-10 05:32 39224 —-a-w- c:\windows\system32\drivers\avgrkx86.sys 2013-07-09 12:23 . 2013-07-09 12:23 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll 2013-07-09 12:22 . 2013-07-09 12:22 2876528 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll 2013-07-09 12:21 . 2013-07-09 12:21 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2013-07-09 12:21 . 2013-07-09 12:21 539984 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll 2013-07-02 14:22 . 2013-07-02 14:22 142496 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2013-07-01 05:45 . 2013-07-01 05:45 96568 —-a-w- c:\windows\system32\drivers\avgmfx86.sys 2013-06-23 18:05 . 2013-06-23 18:05 94632 —-a-w- c:\windows\system32\WindowsAccessBridge.dll 2013-06-23 18:05 . 2013-06-17 12:30 867240 —-a-w- c:\windows\system32\npDeployJava1.dll 2013-06-23 18:05 . 2013-06-17 11:17 789416 —-a-w- c:\windows\system32\deployJava1.dll 2013-06-18 13:22 . 2009-07-14 02:05 152576 —-a-w- c:\windows\system32\msclmd.dll 2013-06-14 12:31 . 2013-06-14 12:31 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-06-14 12:31 . 2013-06-14 12:31 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2013-06-05 03:05 . 2013-07-09 22:09 2347520 —-a-w- c:\windows\system32\win32k.sys 2013-06-04 04:53 . 2013-07-09 22:15 509440 —-a-w- c:\windows\system32\qedit.dll 2013-05-23 05:25 . 2013-07-02 14:22 934488 —-a-w- c:\windows\system32\drivers\NIS\1404000.028\symefa.sys 2013-05-21 05:02 . 2013-07-02 14:22 367704 —-a-w- c:\windows\system32\drivers\NIS\1404000.028\symds.sys 2013-05-16 05:02 . 2013-07-02 14:22 603224 —-a-w- c:\windows\system32\drivers\NIS\1404000.028\srtsp.sys 2013-05-14 05:49 . 2013-06-12 20:41 7016152 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D0AA4302-CF23-4E97-8F72-8A451BF06E9D}\mpengine.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2009-05-05 222496] "HP Officejet 6600 (NET)"="c:\program files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe" [2012-10-17 1837672] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-06-29 458844] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2009-06-19 249856] "AVG_UI"="c:\program files\AVG\AVG2013\avgui.exe" [2013-07-01 4411440] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-11 137752] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-11 171032] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 172568] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-05-11 958576] "IndexSearch"="c:\program files\Nuance\PaperPort\IndexSearch.exe" [2010-03-09 46368] "PaperPort PTD"="c:\program files\Nuance\PaperPort\pptd40nt.exe" [2010-03-09 29984] "PPort12reminder"="c:\program files\Nuance\PaperPort\Ereg\Ereg.exe" [2010-02-09 328992] "PDFHook"="c:\program files\Nuance\PDF Viewer Plus\pdfpro5hook.exe" [2010-03-06 636192] "PDF5 Registry Controller"="c:\program files\Nuance\PDF Viewer Plus\RegistryController.exe" [2010-03-05 62752] "ControlCenter4"="c:\program files\ControlCenter4\BrCcBoot.exe" [2010-10-26 139264] "BrStsMon00"="c:\program files\Browny02\Brother\BrStMonW.exe" [2010-06-10 2621440] "WorksFUD"="c:\program files\Microsoft Works\wkfud.exe" [2001-10-06 24576] "Microsoft Works Portfolio"="c:\program files\Microsoft Works\WksSb.exe" [2007-06-20 1099104] "Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-17 28738] "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe" [2009-07-24 240112] "CPMonitor"="c:\users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe" [2009-07-21 84464] "Desktop Disc Tool"="c:\users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe" [2009-06-23 494064] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2011-10-28 49208] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2013-06-18 280576] . c:\users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Monitor Ink Alerts - HP Officejet 6600 (Network).lnk - c:\windows\system32\RunDll32.exe "c:\program files\HP\HP Officejet 6600\bin\HPStatusBL.dll",RunDLLEntry SERIALNUMBER=CN32S6RHF705RN;CONNECTION=NW;MONITOR=1; [2009-7-13 44544] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE -b -l [2001-2-13 83360] Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2001-8-7 24633] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Akamai NetSession Interface] 2013-06-05 05:01 4489472 —-a-w- c:\users\Loretta\AppData\Local\Akamai\netsession_win.exe . R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2013\avgidsagent.exe [2013-07-04 4939312] R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe [2009-07-24 219632] R3 BrYNSvc;BrYNSvc;c:\program files\Browny02\BrYNSvc.exe [2010-01-25 245760] R3 RoxMediaDB12;RoxMediaDB12;c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe [2009-07-24 1116656] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2013-06-12 1343400] S0 AVGIDSHX;AVGIDSHX;c:\windows\system32\DRIVERS\avgidshx.sys [2013-07-20 60216] S0 Avglogx;AVG Logging Driver;c:\windows\system32\DRIVERS\avglogx.sys [2013-07-20 246072] S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2013-07-10 39224] S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1404000.028\SYMDS.SYS [2013-05-21 367704] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1404000.028\SYMEFA.SYS [2013-05-23 934488] S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdriverx.sys [2013-07-20 208184] S1 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\avgidsshimx.sys [2013-03-01 22328] S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2013-07-20 171320] S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2013-03-21 182072] S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx86.sys [2013-05-21 1002072] S1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NIS\1404000.028\ccSetx86.sys [2013-04-16 134744] S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20130809.001\IDSvix86.sys [2013-06-29 386720] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1404000.028\Ironx86.SYS [2012-07-28 175264] S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\system32\drivers\NIS\1404000.028\SYMNETS.SYS [2013-04-25 339544] S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\aestsrv.exe [2009-03-02 81920] S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2013\avgwdsvc.exe [2013-07-23 283136] S2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe [2013-05-21 144368] S2 PDFProFiltSrvPP;PDFProFiltSrvPP;c:\program files\Nuance\PaperPort\PDFProFiltSrvPP.exe [2010-03-09 144672] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-07-02 106656] S3 k57nd60x;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2009-07-13 229888] . . Contents of the 'Scheduled Tasks' folder . 2013-08-11 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-14 12:31] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.yahoo.com/ uInternet Settings,ProxyOverride = uSearchAssistant = IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm TCP: DhcpNameServer = 192.168.1.254 . - - - - ORPHANS REMOVED - - - - . MSConfigStartUp-OtShot - c:\program files\OtShot\otshot.exe AddRemove-Free Download Manager_is1 - c:\program files\Free Download Manager\unins000.exe AddRemove-sl-apl - c:\program files\OApps\sl-apl_uninstall.exe AddRemove-{C1C3E833-420E-4D78-9BA7-86AEBB272384} - c:\users\Loretta\AppData\Local\TopArcadeHits\uninstaller.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS] "ImagePath"="\"c:\program files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\20.4.0.40\diMaster.dll\" /prefetch:1" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-08-11 08:02:14 ComboFix-quarantined-files.txt 2013-08-11 12:02 . Pre-Run: 455,775,612,928 bytes free Post-Run: 455,302,066,176 bytes free . - - End Of File - - CE6E44DA360E59DC45D2E0FC89D3FB57 A36C5E4F47E84449FF07ED3517B43A31 All processes killed ========== OTL ========== C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Download Manager folder moved successfully. C:\Program Files\Free Download Manager\Skins\old style folder moved successfully. C:\Program Files\Free Download Manager\Skins folder moved successfully. C:\Program Files\Free Download Manager\Server folder moved successfully. C:\Program Files\Free Download Manager\Plugins folder moved successfully. C:\Program Files\Free Download Manager\Language folder moved successfully. C:\Program Files\Free Download Manager\Help folder moved successfully. C:\Program Files\Free Download Manager\Firefox\extension\components folder moved successfully. C:\Program Files\Free Download Manager\Firefox\extension\chrome\content folder moved successfully. C:\Program Files\Free Download Manager\Firefox\extension\chrome folder moved successfully. C:\Program Files\Free Download Manager\Firefox\extension folder moved successfully. C:\Program Files\Free Download Manager\Firefox folder moved successfully. C:\Program Files\Free Download Manager\Archive\7-zip\Formats folder moved successfully. C:\Program Files\Free Download Manager\Archive\7-zip\Codecs folder moved successfully. C:\Program Files\Free Download Manager\Archive\7-zip folder moved successfully. C:\Program Files\Free Download Manager\Archive folder moved successfully. Folder move failed. C:\Program Files\Free Download Manager scheduled to be moved on reboot. C:\Users\Loretta\Desktop\Free Download Manager.lnk moved successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Loretta ->Temp folder emptied: 457832087 bytes ->Temporary Internet Files folder emptied: 221411536 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 492 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 91744062 bytes RecycleBin emptied: 467194 bytes Total Files Cleaned = 736.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 08112013_073758 Files\Folders moved on Reboot… C:\Program Files\Free Download Manager folder moved successfully. C:\Users\Loretta\AppData\Local\Temp\Low\JavaDeployReg.log moved successfully. C:\Users\Loretta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully. C:\Users\Loretta\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully. PendingFileRenameOperations files… Registry entries deleted on Reboot…
Hi roman623,

[external image: Posted Image] Malwarebytes' Anti-Malware

Please download Malwarebytes' Anti-Malware to your desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • At the end, be sure a check-mark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
=========================

[external image: Posted Image] ESET Online Scanner

*Note:
  • It is recommended to disable on-board antivirus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
  • Please don't go surfing while your resident protection is disabled!
  • Once the scan is finished remember to re-enable your antivirus along with your anti-spyware programs.
** You need to run your browser with Administrator Rights, to do so right click your browsers short cut and select "Run as Administrator".

= = = = = = = = = = = = = = = = = = = =

Go here to run ESET Online Scanner

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notification Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.
=========================

In your next post please provide the following:
  • MBAM log
  • ESET's log.txt
  • How's the computer running, any symptoms?
Computer is running great. No symptoms that I can see. Malwarebytes Anti-Malware (Trial) 1.75.0.1300 www.malwarebytes.org Database version: v2013.08.11.04 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16635 Loretta :: LORETTA-PC [administrator] Protection: Enabled 8/11/2013 12:37:50 PM mbam-log-2013-08-11 (12-37-50).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 213665 Time elapsed: 5 minute(s), 9 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 6 C:\Users\Loretta\Downloads\Internet_Explorer_Setup (1).exe (PUP.Optional.IBryte.A) -> Quarantined and deleted successfully. C:\Users\Loretta\Downloads\Internet_Explorer_Setup.exe (PUP.Optional.Ibryte) -> Quarantined and deleted successfully. C:\Users\Loretta\Downloads\online-video-accelerator_setup.exe (PUP.Downware) -> Quarantined and deleted successfully. C:\Users\Loretta\Downloads\Player_Setup.exe (PUP.Adware.Domalq) -> Quarantined and deleted successfully. C:\Users\Loretta\Downloads\Setup (1).exe (PUP.Optional.Solimba) -> Quarantined and deleted successfully. C:\Users\Loretta\Downloads\Setup.exe (PUP.Optional.Solimba) -> Quarantined and deleted successfully. (end) ESET.Log C:\Users\Loretta\Documents\Saved From Old Hard Drive\Downloads\AVGAnti-VirusFreeEdition.exe a variant of Win32/OpenInstall application C:\Users\Loretta\Documents\Saved From Old Hard Drive\Downloads\SoftonicDownloader_for_skype.exe Win32/SoftonicDownloader.A application C:\Users\Loretta\Documents\Saved From Old Hard Drive\Downloads\Unconfirmed 386786.crdownload multiple threats C:\Users\Loretta\Documents\Saved From Old Hard Drive\Downloads\windows media player.exe Win32/Toolbar.Zugo application C:\_OTL\MovedFiles\08102013_220538\C_Users\Loretta\AppData\Local\Temp\setup.exe a variant of Win32/AirAdInstaller.A application
Hi roman623,

[external image: Posted Image] Run OTL.exe

Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Files
    C:\Users\Loretta\Documents\Saved From Old Hard Drive\Downloads\AVGAnti-VirusFreeEdition.exe
    C:\Users\Loretta\Documents\Saved From Old Hard Drive\Downloads\SoftonicDownloader_for_skype.exe
    C:\Users\Loretta\Documents\Saved From Old Hard Drive\Downloads\Unconfirmed 386786.crdownload
    C:\Users\Loretta\Documents\Saved From Old Hard Drive\Downloads\windows media player.exe 
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then re-run OTL and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
=========================

In your next post please provide the following:
  • OTL.txt
  • Any remaining issues?
Computer is running flawlessly.

OTL logfile created on: 8/12/2013 6:14:28 AM - Run 5
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Loretta\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16635)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.96 Gb Total Physical Memory | 1.86 Gb Available Physical Memory | 62.99% Memory free
5.92 Gb Paging File | 4.72 Gb Available in Paging File | 79.70% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.66 Gb Total Space | 425.55 Gb Free Space | 91.39% Space Free | Partition Type: NTFS

Computer Name: LORETTA-PC | User Name: Loretta | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Loretta\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicator.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicatorCom.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Adobe\Reader 11.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ControlCenter4\BrCcUxSys.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\ControlCenter4\BrCtrlCntr.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (Nuance Communications, Inc.)
PRC - C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe ()
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\stacsv.exe (IDT, Inc.)
PRC - C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe ()
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
PRC - C:\Program Files\Common Files\PX Storage Engine\VxBlockServer.exe (Sonic Solutions)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Microsoft Works\WksSb.exe (Microsoft® Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\wincfi39.dll ()
MOD - C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe ()
MOD - C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe ()
MOD - C:\Program Files\Brother\BrUtilities\BrLogAPI.dll ()


========== Services (SafeList) ==========

SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (NIS) – C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe (Symantec Corporation)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (PDFProFiltSrvPP) – C:\Program Files\Nuance\PaperPort\PDFProFiltSrvPP.exe (Nuance Communications, Inc.)
SRV - (BrYNSvc) – C:\Program Files\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
SRV - (RoxWatch12) – C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe (Sonic Solutions)
SRV - (RoxMediaDB12) – C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe (Sonic Solutions)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7f2308f435f2c4c1\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (catchme) – C:\Users\Loretta\AppData\Local\Temp\catchme.sys File not found
DRV - (Avglogx) – C:\Windows\System32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130811.006\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20130811.006\NAVENG.SYS (Symantec Corporation)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20130809.001\IDSvix86.sys (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\System32\drivers\NIS\1404000.028\symefa.sys (Symantec Corporation)
DRV - (SymDS) – C:\Windows\System32\drivers\NIS\1404000.028\symds.sys (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx86.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\NIS\1404000.028\srtsp.sys (Symantec Corporation)
DRV - (SymNetS) – C:\Windows\System32\drivers\NIS\1404000.028\symnets.sys (Symantec Corporation)
DRV - (ccSet_NIS) – C:\Windows\System32\drivers\NIS\1404000.028\ccsetx86.sys (Symantec Corporation)
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (SRTSPX) – C:\Windows\System32\drivers\NIS\1404000.028\srtspx.sys (Symantec Corporation)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (SymIRON) – C:\Windows\System32\drivers\NIS\1404000.028\ironx86.sys (Symantec Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (itecir) – C:\Windows\System32\drivers\itecir.sys (ITE Tech. Inc. )
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (WSDPrintDevice) – C:\Windows\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (k57nd60x) – C:\Windows\System32\drivers\k57nd60x.sys (Broadcom Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D0 C5 89 65 AA 87 CE 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\IPSFFPlgn\ [2013/07/02 10:23:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\coFFPlgn\ [2013/08/12 06:06:45 | 000,000,000 | —D | M]

[2013/07/14 08:28:49 | 000,000,000 | —D | M] (No name found) – C:\Users\Loretta\AppData\Roaming\Mozilla\Extensions
[2013/08/02 22:41:30 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Viewer Plus\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll File not found
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter4] C:\Program Files\ControlCenter4\BrCcBoot.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [CPMonitor] C:\Users\Loretta\Desktop\Roxio 2010\5.0\CPMonitor.exe ()
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Users\Loretta\Desktop\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\Nuance\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDF5 Registry Controller] C:\Program Files\Nuance\PDF Viewer Plus\RegistryController.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDFHook] C:\Program Files\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PPort12reminder] C:\Program Files\Nuance\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe (Sonic Solutions)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe (Microsoft® Corporation)
O4 - HKCU..\Run: [HP Officejet 6600 (NET)] C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - HKCU..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm File not found
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm File not found
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm File not found
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm File not found
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{27E46421-718C-4440-9642-64B07C9AE1DB}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7E1A25BB-B83F-48B6-BCA8-11A2410C5A66}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/08/11 12:54:09 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2013/08/11 12:36:23 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Malwarebytes
[2013/08/11 12:36:12 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/08/11 12:36:11 | 000,022,856 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2013/08/11 12:36:11 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2013/08/11 12:34:25 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Local\Programs
[2013/08/11 12:33:44 | 010,285,040 | —- | C] (Malwarebytes Corporation ) – C:\Users\Loretta\Desktop\mbam-setup-1.75.0.1300.exe
[2013/08/11 08:02:17 | 000,000,000 | —D | C] – C:\Windows\temp
[2013/08/11 08:01:42 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/08/11 07:53:01 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/08/11 07:53:01 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/08/11 07:53:01 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/08/11 07:50:34 | 000,000,000 | —D | C] – C:\Qoobox
[2013/08/11 07:49:55 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/08/11 07:49:37 | 005,104,749 | R— | C] (Swearware) – C:\Users\Loretta\Desktop\ComboFix.exe
[2013/08/10 22:19:27 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/08/10 22:11:18 | 000,958,418 | —- | C] (Oleg N. Scherbakov) – C:\Users\Loretta\Desktop\JRT.exe
[2013/08/10 22:05:38 | 000,000,000 | —D | C] – C:\_OTL
[2013/08/10 18:20:27 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Loretta\Desktop\aswMBR.exe
[2013/08/09 23:04:10 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Free Download Manager
[2013/08/09 20:05:42 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Loretta\Desktop\HiJackThis.exe
[2013/08/09 19:34:18 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Loretta\Desktop\OTL.exe
[2013/08/08 10:42:45 | 000,000,000 | —D | C] – C:\ProgramData\Visan
[2013/08/08 10:42:45 | 000,000,000 | —D | C] – C:\ProgramData\HP Photo Creations
[2013/08/08 10:42:45 | 000,000,000 | —D | C] – C:\Program Files\HP Photo Creations
[2013/08/08 10:42:32 | 000,000,000 | —D | C] – C:\Windows\Hewlett-Packard
[2013/08/02 22:41:39 | 000,000,000 | —D | C] – C:\Windows\System32\Extensions
[2013/08/02 22:41:38 | 000,000,000 | —D | C] – C:\Windows\System32\searchplugins
[2013/08/02 22:41:30 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/07/30 09:54:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/07/23 08:03:06 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Local\CRE
[2013/07/23 08:02:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OtShot
[2013/07/23 08:01:03 | 000,000,000 | —D | C] – C:\ProgramData\ZalmanInstaller_52330
[2013/07/20 01:51:00 | 000,246,072 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avglogx.sys
[2013/07/20 01:50:56 | 000,208,184 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidsdriverx.sys
[2013/07/20 01:50:56 | 000,060,216 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidshx.sys
[2013/07/20 01:50:50 | 000,171,320 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2013/07/18 10:10:09 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/07/17 07:05:20 | 001,247,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/07/17 06:53:17 | 000,745,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/07/17 06:53:17 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/07/17 06:53:17 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/07/17 06:53:16 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/07/17 06:53:16 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/07/17 06:53:16 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/07/17 06:53:16 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/07/17 06:53:16 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/07/17 06:53:16 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/07/17 06:53:15 | 000,493,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/07/17 06:53:14 | 002,706,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/07/17 06:53:14 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/07/17 06:53:14 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/07/17 06:53:14 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/07/17 06:53:14 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/07/17 06:53:14 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/07/17 06:53:14 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/07/17 06:53:14 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/07/17 06:53:13 | 002,877,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/07/17 06:53:13 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/07/17 06:53:13 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/07/17 06:53:13 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/07/17 06:53:13 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/07/17 06:53:12 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/07/17 06:53:12 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/07/17 06:53:12 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/07/17 06:53:12 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/07/17 06:53:12 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/07/17 06:53:12 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/07/17 06:53:12 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/07/17 06:53:12 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/07/17 06:53:12 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/07/17 06:53:11 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/07/17 06:53:11 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/07/17 06:53:11 | 000,242,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/07/17 06:53:11 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/07/17 06:51:43 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/07/17 06:51:43 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/07/17 06:51:43 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/07/17 06:51:42 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/07/17 06:51:42 | 001,080,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/07/17 06:51:42 | 000,604,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/07/17 06:51:42 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/07/17 06:51:42 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/07/17 06:51:42 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/07/17 06:51:42 | 000,207,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/07/17 06:51:42 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/07/17 06:51:41 | 003,419,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/07/17 06:51:41 | 001,988,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/07/17 06:51:41 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/07/17 06:51:41 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/07/14 08:28:49 | 000,000,000 | —D | C] – C:\Users\Loretta\AppData\Roaming\Mozilla

========== Files - Modified Within 30 Days ==========

[2013/08/12 06:14:23 | 000,013,440 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/12 06:14:23 | 000,013,440 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/12 06:13:50 | 000,001,914 | —- | M] () – C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Officejet 6600 (Network).lnk
[2013/08/12 06:06:38 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/12 06:06:36 | 2383,589,376 | -HS- | M] () – C:\hiberfil.sys
[2013/08/11 21:32:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/08/11 12:36:14 | 000,001,071 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/08/11 12:33:44 | 010,285,040 | —- | M] (Malwarebytes Corporation ) – C:\Users\Loretta\Desktop\mbam-setup-1.75.0.1300.exe
[2013/08/11 07:49:44 | 005,104,749 | R— | M] (Swearware) – C:\Users\Loretta\Desktop\ComboFix.exe
[2013/08/10 22:11:19 | 000,958,418 | —- | M] (Oleg N. Scherbakov) – C:\Users\Loretta\Desktop\JRT.exe
[2013/08/10 19:15:50 | 331,249,904 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/08/10 18:19:35 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Loretta\Desktop\aswMBR.exe
[2013/08/10 18:00:02 | 000,000,098 | —- | M] () – C:\Windows\DeleteOnReboot.bat
[2013/08/10 17:52:29 | 000,666,633 | —- | M] () – C:\Users\Loretta\Desktop\AdwCleaner.exe
[2013/08/10 17:37:55 | 000,891,115 | —- | M] () – C:\Users\Loretta\Desktop\SecurityCheck.exe
[2013/08/09 20:06:54 | 000,625,664 | —- | M] () – C:\Users\Loretta\Desktop\dds.scr
[2013/08/09 20:05:42 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Loretta\Desktop\HiJackThis.exe
[2013/08/09 19:34:18 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Loretta\Desktop\OTL.exe
[2013/08/08 10:43:02 | 000,000,328 | —- | M] () – C:\Users\Loretta\Desktop\HP Printer Diagnostic Tools.url
[2013/08/08 10:42:48 | 000,001,953 | —- | M] () – C:\Users\Public\Desktop\HP Photo Creations.lnk
[2013/08/08 10:35:39 | 000,015,872 | —- | M] () – C:\Users\Loretta\Documents\Red Hat List.xlr
[2013/08/08 10:35:39 | 000,006,398 | —- | M] () – C:\Users\Loretta\AppData\Roaming\wklnhst.dat
[2013/08/04 16:40:55 | 000,017,920 | —- | M] () – C:\Users\Loretta\Documents\Sew Classy Ladies.xlr
[2013/07/30 09:54:01 | 000,000,935 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/07/29 19:21:38 | 000,000,131 | —- | M] () – C:\Users\Loretta\Desktop\Jordan River Arts Council.url
[2013/07/26 11:43:34 | 000,624,178 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/07/26 11:43:34 | 000,106,522 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/07/26 08:45:39 | 000,000,202 | —- | M] () – C:\Users\Loretta\Desktop\How To Make a TV Tray Ironing Board American Quilting.url
[2013/07/20 01:51:00 | 000,246,072 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avglogx.sys
[2013/07/20 01:50:56 | 000,208,184 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidsdriverx.sys
[2013/07/20 01:50:56 | 000,060,216 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgidshx.sys
[2013/07/20 01:50:50 | 000,171,320 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2013/07/17 06:53:17 | 000,745,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/07/17 06:53:17 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/07/17 06:53:17 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/07/17 06:53:16 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/07/17 06:53:16 | 000,158,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/07/17 06:53:16 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/07/17 06:53:16 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/07/17 06:53:16 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/07/17 06:53:16 | 000,039,424 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/07/17 06:53:15 | 000,493,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/07/17 06:53:14 | 002,706,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/07/17 06:53:14 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/07/17 06:53:14 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/07/17 06:53:14 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/07/17 06:53:14 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/07/17 06:53:14 | 000,041,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/07/17 06:53:14 | 000,038,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/07/17 06:53:14 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/07/17 06:53:13 | 002,877,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/07/17 06:53:13 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/07/17 06:53:13 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/07/17 06:53:13 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/07/17 06:53:13 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/07/17 06:53:12 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/07/17 06:53:12 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/07/17 06:53:12 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/07/17 06:53:12 | 000,357,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/07/17 06:53:12 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/07/17 06:53:12 | 000,226,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/07/17 06:53:12 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/07/17 06:53:12 | 000,042,496 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/07/17 06:53:12 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/07/17 06:53:12 | 000,025,185 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2013/07/17 06:53:11 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/07/17 06:53:11 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/07/17 06:53:11 | 000,242,200 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/07/17 06:53:11 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/07/17 06:51:43 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/07/17 06:51:43 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/07/17 06:51:43 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/07/17 06:51:43 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/07/17 06:51:43 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/07/17 06:51:43 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/07/17 06:51:42 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/07/17 06:51:42 | 001,080,832 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/07/17 06:51:42 | 000,604,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/07/17 06:51:42 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/07/17 06:51:42 | 000,249,856 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/07/17 06:51:42 | 000,220,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/07/17 06:51:42 | 000,207,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/07/17 06:51:42 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/07/17 06:51:41 | 003,419,136 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/07/17 06:51:41 | 001,988,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/07/17 06:51:41 | 000,293,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/07/17 06:51:41 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/07/16 12:45:04 | 000,013,889 | —- | M] () – C:\Users\Loretta\Desktop\Ron Feroni Amm. Schedule - Shortcut.lnk
[2013/07/16 12:43:03 | 000,005,064 | —- | M] () – C:\Users\Loretta\Desktop\Jenny Amortization Schedule - Shortcut.lnk
[2013/07/16 12:35:45 | 000,100,864 | —- | M] () – C:\Users\Loretta\Documents\Ron Feroni Amm. Schedule.xlr

========== Files Created - No Company Name ==========

[2013/08/11 12:36:13 | 000,001,071 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/08/11 07:53:01 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/08/11 07:53:01 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/08/11 07:53:01 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/08/11 07:53:01 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/08/11 07:53:01 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/08/10 17:59:47 | 000,000,098 | —- | C] () – C:\Windows\DeleteOnReboot.bat
[2013/08/10 17:52:16 | 000,666,633 | —- | C] () – C:\Users\Loretta\Desktop\AdwCleaner.exe
[2013/08/10 17:37:33 | 000,891,115 | —- | C] () – C:\Users\Loretta\Desktop\SecurityCheck.exe
[2013/08/09 20:06:54 | 000,625,664 | —- | C] () – C:\Users\Loretta\Desktop\dds.scr
[2013/08/08 10:43:02 | 000,000,328 | —- | C] () – C:\Users\Loretta\Desktop\HP Printer Diagnostic Tools.url
[2013/08/08 10:42:47 | 000,001,953 | —- | C] () – C:\Users\Public\Desktop\HP Photo Creations.lnk
[2013/07/29 19:21:38 | 000,000,131 | —- | C] () – C:\Users\Loretta\Desktop\Jordan River Arts Council.url
[2013/07/26 08:45:39 | 000,000,202 | —- | C] () – C:\Users\Loretta\Desktop\How To Make a TV Tray Ironing Board American Quilting.url
[2013/07/23 08:02:00 | 000,000,953 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OtShot.lnk
[2013/07/18 10:10:04 | 331,249,904 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/07/17 06:53:12 | 000,025,185 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2013/07/16 12:45:04 | 000,013,889 | —- | C] () – C:\Users\Loretta\Desktop\Ron Feroni Amm. Schedule - Shortcut.lnk
[2013/07/16 12:43:03 | 000,005,064 | —- | C] () – C:\Users\Loretta\Desktop\Jenny Amortization Schedule - Shortcut.lnk
[2013/07/16 12:35:45 | 000,100,864 | —- | C] () – C:\Users\Loretta\Documents\Ron Feroni Amm. Schedule.xlr
[2013/07/14 08:33:03 | 000,002,441 | —- | C] () – C:\Users\Loretta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
[2013/07/10 09:33:30 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2013/06/22 09:40:08 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2013/06/17 07:16:10 | 000,000,258 | RHS- | C] () – C:\Users\Loretta\ntuser.pol
[2013/06/16 08:04:03 | 000,000,246 | —- | C] () – C:\Windows\Brpfx04a.ini
[2013/06/16 08:04:03 | 000,000,093 | —- | C] () – C:\Windows\brpcfx.ini
[2013/06/16 08:02:11 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2013/06/16 08:02:11 | 000,000,000 | —- | C] () – C:\Windows\brdfxspd.dat
[2013/06/16 08:01:51 | 000,045,056 | —- | C] () – C:\Windows\System32\BRTCPCON.DLL
[2013/06/16 08:01:44 | 000,000,114 | —- | C] () – C:\Windows\System32\BRLMW03A.INI
[2013/06/16 08:01:43 | 000,000,050 | —- | C] () – C:\Windows\System32\BRADM10A.DAT
[2013/06/14 10:00:59 | 000,006,398 | —- | C] () – C:\Users\Loretta\AppData\Roaming\wklnhst.dat

========== ZeroAccess Check ==========

[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 21:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >
Hi roman623,

One last fix, then we can clean-up and send you on your way. Post the OTL fix log if one is generated. It is not necessary to run a full OTL scan.

=========================

[external image: Posted Image] Run OTL.exe

Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm File not found
    O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm File not found
    O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm File not found
    O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm File not found
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
=========================

In your next post please provide the following:
  • OTL fix log (if generated)
OCD, On last power-up after running the previous fix/scan(not the one I'm posting now, the one before this one) the computer went to desktop but many of the start menu items would not load and I could not do anything. I could move the cursor arrow but could not click on anything. When I brought the cursor arrow over the task bar at bottom of screen it changed to the circle showing that something was working in the background. Tried ctl-alt-del to no avail. Had to hold down power button to turn off computer. It's restarted fine since that one incident but just wanted to let you know. Here is the latest fix log from OTL. All processes killed ========== OTL ========== Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download all with Free Download Manager\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download selected with Free Download Manager\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download video with Free Download Manager\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download with Free Download Manager\ deleted successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Loretta ->Temp folder emptied: 4326 bytes ->Temporary Internet Files folder emptied: 12963976 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 922 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 9858 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 12.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 08122013_171101 Files\Folders moved on Reboot… PendingFileRenameOperations files… Registry entries deleted on Reboot…
Hi roman623,

Unfortunately, computers can be temperamental at times. We have removed all the malware. I would continue to monitor the situation and if the problem re-appears it might warrant running some additional diagnostic tools. I will keep the thread open for a few days in case we need to address that issue.

=========================

Your log appears to be clean. :thumbup:

We have a few items to take care of before we get to the All Clean Speech.

=========================

[external image: Posted Image] Uninstall Combofix

The following will implement important cleanup procedures as well as reset System Restore points:

Click on the Start button [external image: Posted Image] and then in the Search field enter combofix /uninstall, as shown in the image below with the blue arrow.
Please note that there is a space between combofix and /uninstall.

[external image: Posted Image]

Once you have typed this in, press Enter on your keyboard. A Open File security warning will appear asking if you are sure you want to run ComboFix. Please click on the Run button to start the program.

ComboFix will now uninstall itself from your computer and remove any backups and quarantined files. When it has finished you will be greeted by a dialog box stating that ComboFix has been uninstalled.

=========================

[external image: Posted Image] Clean up with OTL:
  • Right-click OTL.exe select "Run as Administrator" to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
=========================

[external image: Posted Image] You can now delete any tools and/or logs remaining on your desktop.

=========================

[external image: Posted Image] Disable Java in Web Browsers

There is a vulnerability with regards to Java and web browsers. Therefore, we recommend to disable java in web browsers.
More information can be found here: http://www.techsupportforum.com/forums/f50…ers-683721.html

  • Click on the Start button and then click on the Control Panel option.
  • In the Control Panel Search enter Java Control Panel.
  • Click on the Java icon to open the Java Control Panel.
[external image: Posted Image]

Disable Java through the Java Control Panel

  • In the Java Control Panel, click on the Security tab.
  • Deselect the check box for Enable Java content in the browser. This will disable the Java plug-in in the browser.
  • Click Apply. When the Windows User Account Control (UAC) dialog appears, allow permissions to make the changes.
  • Click OK in the Java Plug-in confirmation window.
  • Restart the browser for changes to take effect.
[external image: Posted Image]

=========================

With the above items taken care of let's move on to the All Clean part of the process.

The following procedures are recommendations for helping to keep your system running smoothly. If you are currently satisfied with how your system is running some or all of these may not pertain to you. Impliment what you need.

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.

Here are some tips to reduce the potential for spyware infection in the future:

Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
Make your Mozilla Firefox more secure - This can be done by adding these add-ons:
Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

Free Anti-Virus
  • Avast Free Antivirus
  • Avira Free Antivirus 2013
  • PC Tools AntiVirus Free
  • Ad-Aware Free Antivirus +
Free Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. A tutorial on firewalls can be found here.
  • Online Armor Free
  • Agnitum Outpost Firewall Free
  • Comodo Firewall
Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
I cannot thank you enough for your time and effort. I will absolutely be donating to this site. Again THANK YOU! I do have one final question. This is my mothers laptop. She currently is using AVG(free version) and Norton Security. Are these fine or should I have her use one of the antivirus programs in the last post? THANKS, Ron

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI