Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - x_breath_x

Pages: [1] 2 3 4
1
Tech Clinic / nativemessaging on chrome
« on: January 27, 2014, 06:20:50 PM »

the only thing ive installed was the things you told me to. i downloaded the avg one i didnt realise mcafee wasnt deleted yet.



2
Tech Clinic / nativemessaging on chrome
« on: January 20, 2014, 12:40:34 PM »
# AdwCleaner v3.016 - Report created 23/12/2013 at 21:59:59

# Updated 23/12/2013 by Xplode

# Operating System : Windows 7 Starter Service Pack 1 (32 bits)

# Username : Kaila - JOHN

# Running from : C:\\Users\\Kaila\\Downloads\\adwcleaner.exe

# Option : Scan

 

***** [ Services ] *****

 

 

***** [ Files / Folders ] *****

 

File Found : C:\\Users\\Kaila\\AppData\\Local\\funmoods-speeddial.crx

File Found : C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Local Storage\\hxxp_app.mam.conduit.com_0.localstorage

File Found : C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Local Storage\\hxxp_app.mam.conduit.com_0.localstorage-journal

File Found : C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Local Storage\\hxxp_facebook.conduitapps.com_0.localstorage

File Found : C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Local Storage\\hxxp_facebook.conduitapps.com_0.localstorage-journal

File Found : C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\user data\\default\\local storage\\hxxp_pricegong.conduitapps.com_0.localstorage

File Found : C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\user data\\default\\local storage\\hxxp_pricegong.conduitapps.com_0.localstorage-journal

File Found : C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Local Storage\\hxxp_search.conduit.com_0.localstorage

File Found : C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Local Storage\\hxxp_search.conduit.com_0.localstorage-journal

File Found : C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Local Storage\\hxxp_storage.conduit.com_0.localstorage

File Found : C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Local Storage\\hxxp_storage.conduit.com_0.localstorage-journal

File Found : C:\\Users\\Kaila\\AppData\\Local\\Temp\\Uninstall.exe

File Found : C:\\Windows\\System32\\Tasks\\BackgroundContainer Startup Task

Folder Found : C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\cflheckfmhopnialghigdlggahiomebp

Folder Found C:\\Program Files\\AVG Secure Search

Folder Found C:\\Program Files\\Common Files\\AVG Secure Search

Folder Found C:\\Program Files\\Conduit

Folder Found C:\\Program Files\\Free Offers from Freeze.com

Folder Found C:\\Program Files\\Search Results Toolbar

Folder Found C:\\Program Files\\sweetpacks bundle uninstaller

Folder Found C:\\Program Files\\TidyNetwork

Folder Found C:\\Program Files\\uTorrentControl_v6

Folder Found C:\\Program Files\\Wajam

Folder Found C:\\Program Files\\Zoomex

Folder Found C:\\ProgramData\\apn

Folder Found C:\\ProgramData\\Ask

Folder Found C:\\ProgramData\\boost_interprocess

Folder Found C:\\ProgramData\\clsoft ltd

Folder Found C:\\ProgramData\\Conduit

Folder Found C:\\ProgramData\\Premium

Folder Found C:\\Users\\Kaila\\AppData\\Local\\Conduit

Folder Found C:\\Users\\Kaila\\AppData\\Local\\NativeMessaging

Folder Found C:\\Users\\Kaila\\AppData\\Local\\Searchprotect

Folder Found C:\\Users\\Kaila\\AppData\\Local\\strongvault

Folder Found C:\\Users\\Kaila\\AppData\\Local\\SwvUpdater

Folder Found C:\\Users\\Kaila\\AppData\\Local\\TidyNetwork

Folder Found C:\\Users\\Kaila\\AppData\\Local\\Wajam

Folder Found C:\\Users\\Kaila\\AppData\\Local\\WhiteListing

Folder Found C:\\Users\\Kaila\\AppData\\LocalLow\\Conduit

Folder Found C:\\Users\\Kaila\\AppData\\LocalLow\\ilividtoolbarguid

Folder Found C:\\Users\\Kaila\\AppData\\LocalLow\\searchresultstb

Folder Found C:\\Users\\Kaila\\AppData\\LocalLow\\uTorrentControl_v6

Folder Found C:\\Users\\Kaila\\AppData\\Roaming\\DefaultTab

Folder Found C:\\Users\\Kaila\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Wajam

Folder Found C:\\Users\\Kaila\\AppData\\Roaming\\OpenCandy

Folder Found C:\\Users\\Kaila\\Documents\\optimizer pro

 

***** [ Shortcuts ] *****

 

 

***** [ Registry ] *****

 

Key Found : HKCU\\Software\\APN DTX

Key Found : HKCU\\Software\\APN PIP

Key Found : HKCU\\Software\\AppDataLow\\{1146AC44-2F03-4431-B4FD-889BC837521F}

Key Found : HKCU\\Software\\AppDataLow\\Software\\BackgroundContainer

Key Found : HKCU\\Software\\AppDataLow\\Software\\Conduit

Key Found : HKCU\\Software\\AppDataLow\\Software\\ConduitSearchScopes

Key Found : HKCU\\Software\\AppDataLow\\Software\\ilividtoolbarguid

Key Found : HKCU\\Software\\AppDataLow\\Software\\SmartBar

Key Found : HKCU\\Software\\AppDataLow\\Software\\uTorrentControl_v6

Key Found : HKCU\\Software\\AppDataLow\\SProtector

Key Found : HKCU\\Software\\AppDataLow\\Toolbar

Key Found : HKCU\\Software\\Google\\Chrome\\Extensions\\cflheckfmhopnialghigdlggahiomebp

Key Found : HKCU\\Software\\ilivid

Key Found : HKCU\\Software\\ilividtoolbarguid

Key Found : HKCU\\Software\\IM

Key Found : HKCU\\Software\\Imesh

Key Found : HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{006EE092-9658-4FD6-BD8E-A21A348E59F5}

Key Found : HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{95B7759C-8C7F-4BF1-B163-73684A933233}

Key Found : HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}

Key Found : HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}

Key Found : HKCU\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{EEE6C360-6118-11DC-9C72-001320C79847}

Key Found : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{474597C5-AB09-49D6-A4D5-2E8D7341384E}

Key Found : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{96F454EA-9D38-474F-B504-56193E00C1A5}

Key Found : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{EF99BD32-C1FB-11D2-892F-0090271D4F88}

Key Found : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{02478D38-C3F9-4EFB-9B51-7695ECA05670}

Key Found : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{96F454EA-9D38-474F-B504-56193E00C1A5}

Key Found : HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{DEDAF650-12B8-48F5-A843-BBA100716106}

Key Found : HKCU\\Software\\PrivitizeVPNInstallDates

Key Found : HKCU\\Software\\StartSearch

Key Found : HKCU\\Software\\visualbee

Key Found : HKCU\\Software\\Wajam

Key Found : HKLM\\Software\\{1146AC44-2F03-4431-B4FD-889BC837521F}

Key Found : HKLM\\Software\\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}

Key Found : HKLM\\Software\\{6791A2F3-FC80-475C-A002-C014AF797E9C}

Key Found : HKLM\\SOFTWARE\\Classes\\AppID\\{09C554C3-109B-483C-A06B-F14172F1A947}

Key Found : HKLM\\SOFTWARE\\Classes\\AppID\\{0A18A436-2A7A-49F3-A488-30538A2F6323}

Key Found : HKLM\\SOFTWARE\\Classes\\AppID\\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}

Key Found : HKLM\\SOFTWARE\\Classes\\AppID\\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}

Key Found : HKLM\\SOFTWARE\\Classes\\AppID\\{72D89EBF-0C5D-4190-91FD-398E45F1D007}

Key Found : HKLM\\SOFTWARE\\Classes\\AppID\\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}

Key Found : HKLM\\SOFTWARE\\Classes\\AppID\\{B12E99ED-69BD-437C-86BE-C862B9E5444D}

Key Found : HKLM\\SOFTWARE\\Classes\\AppID\\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}

Key Found : HKLM\\SOFTWARE\\Classes\\AppID\\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}

Key Found : HKLM\\SOFTWARE\\Classes\\AppID\\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}

Key Found : HKLM\\SOFTWARE\\Classes\\AppID\\{EA28B360-05E0-4F93-8150-02891F1D8D3C}

Key Found : HKLM\\SOFTWARE\\Classes\\AppID\\escort.DLL

Key Found : HKLM\\SOFTWARE\\Classes\\AppID\\escortApp.DLL

Key Found : HKLM\\SOFTWARE\\Classes\\AppID\\escortEng.DLL

Key Found : HKLM\\SOFTWARE\\Classes\\AppID\\escorTlbr.DLL

Key Found : HKLM\\SOFTWARE\\Classes\\AppID\\esrv.EXE

Key Found : HKLM\\SOFTWARE\\Classes\\AppID\\priam_bho.DLL

Key Found : HKLM\\SOFTWARE\\Classes\\AppID\\ScriptHelper.EXE

Key Found : HKLM\\SOFTWARE\\Classes\\Applications\\ilividsetup.exe

Key Found : HKLM\\SOFTWARE\\Classes\\CLSID\\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}

Key Found : HKLM\\SOFTWARE\\Classes\\CLSID\\{058F0E48-61CA-4964-9FBA-1978A1BB060D}

Key Found : HKLM\\SOFTWARE\\Classes\\CLSID\\{18F33C35-8EF2-40D7-8BA4-932B0121B472}

Key Found : HKLM\\SOFTWARE\\Classes\\CLSID\\{3BF72F68-72D8-461D-A884-329D936C5581}

Key Found : HKLM\\SOFTWARE\\Classes\\CLSID\\{3C471948-F874-49F5-B338-4F214A2EE0B1}

Key Found : HKLM\\SOFTWARE\\Classes\\CLSID\\{408CFAD9-8F13-4747-8EC7-770A339C7237}

Key Found : HKLM\\SOFTWARE\\Classes\\CLSID\\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}

Key Found : HKLM\\SOFTWARE\\Classes\\CLSID\\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5}

Key Found : HKLM\\SOFTWARE\\Classes\\CLSID\\{78E9D883-93CD-4072-BEF3-38EE581E2839}

Key Found : HKLM\\SOFTWARE\\Classes\\CLSID\\{83AC1413-FCE4-4A46-9DD5-4F31F306E71F}

Key Found : HKLM\\SOFTWARE\\Classes\\CLSID\\{94496571-6AC5-4836-82D5-D46260C44B17}

Key Found : HKLM\\SOFTWARE\\Classes\\CLSID\\{96F454EA-9D38-474F-B504-56193E00C1A5}

Key Found : HKLM\\SOFTWARE\\Classes\\CLSID\\{BC9FD17D-30F6-4464-9E53-596A90AFF023}

Key Found : HKLM\\SOFTWARE\\Classes\\CLSID\\{CD90659F-D5B2-4104-9504-7CA36E6532DF}

Key Found : HKLM\\SOFTWARE\\Classes\\CLSID\\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}

Key Found : HKLM\\SOFTWARE\\Classes\\CLSID\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}

Key Found : HKLM\\SOFTWARE\\Classes\\Interface\\{03E2A1F3-4402-4121-8B35-733216D61217}

Key Found : HKLM\\SOFTWARE\\Classes\\Interface\\{23C70BCA-6E23-4A65-AD2E-1389062074F1}

Key Found : HKLM\\SOFTWARE\\Classes\\Interface\\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}

Key Found : HKLM\\SOFTWARE\\Classes\\Interface\\{295CACB4-51F5-46FD-914E-C72BAAE1B672}

Key Found : HKLM\\SOFTWARE\\Classes\\Interface\\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}

Key Found : HKLM\\SOFTWARE\\Classes\\Interface\\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}

Key Found : HKLM\\SOFTWARE\\Classes\\Interface\\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}

Key Found : HKLM\\SOFTWARE\\Classes\\Interface\\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}

Key Found : HKLM\\SOFTWARE\\Classes\\Interface\\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}

Key Found : HKLM\\SOFTWARE\\Classes\\Interface\\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}

Key Found : HKLM\\SOFTWARE\\Classes\\Interface\\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}

Key Found : HKLM\\SOFTWARE\\Classes\\Interface\\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}

Key Found : HKLM\\SOFTWARE\\Classes\\Interface\\{C0585B2F-74D7-4734-88DE-6C150C5D4036}

Key Found : HKLM\\SOFTWARE\\Classes\\Interface\\{CA17D76B-F91D-4659-A7FD-A9F7ED375CDD}

Key Found : HKLM\\SOFTWARE\\Classes\\Interface\\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}

Key Found : HKLM\\SOFTWARE\\Classes\\Interface\\{EF0588D6-1621-4A75-B8BE-F4BC34794136}

Key Found : HKLM\\SOFTWARE\\Classes\\Toolbar.CT3289075

Key Found : HKLM\\SOFTWARE\\Classes\\TypeLib\\{07CAC314-E962-4F78-89AB-DD002F2490EE}

Key Found : HKLM\\SOFTWARE\\Classes\\TypeLib\\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}

Key Found : HKLM\\SOFTWARE\\Classes\\TypeLib\\{13ABD093-D46F-40DF-A608-47E162EC799D}

Key Found : HKLM\\SOFTWARE\\Classes\\TypeLib\\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}

Key Found : HKLM\\SOFTWARE\\Classes\\TypeLib\\{C4C4F1F4-3074-4CB6-9FB8-0A64273166F0}

Key Found : HKLM\\SOFTWARE\\Classes\\wajam.WajamBHO

Key Found : HKLM\\SOFTWARE\\Classes\\wajam.WajamBHO.1

Key Found : HKLM\\SOFTWARE\\Classes\\wajam.WajamDownloader

Key Found : HKLM\\SOFTWARE\\Classes\\wajam.WajamDownloader.1

Key Found : HKLM\\Software\\Conduit

Key Found : HKLM\\Software\\DataMngr

Key Found : HKLM\\Software\\Default Tab

Key Found : HKLM\\Software\\DefaultTab

Key Found : HKLM\\Software\\Freeze.com

Key Found : HKLM\\SOFTWARE\\Google\\Chrome\\Extensions\\cflheckfmhopnialghigdlggahiomebp

Key Found : HKLM\\SOFTWARE\\Google\\Chrome\\Extensions\\jpmbfleldcgkldadpdinhjjopdfpjfjp

Key Found : HKLM\\SOFTWARE\\Google\\Chrome\\Extensions\\mkndcbhcgphcfkkddanakjiepeknbgle

Key Found : HKLM\\SOFTWARE\\Google\\Chrome\\Extensions\\ogccgbmabaphcakpiclgcnmcnimhokcj

Key Found : HKLM\\Software\\iLividSRTB

Key Found : HKLM\\Software\\InstallIQ

Key Found : HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Low Rights\\ElevationPolicy\\{0ABE0FED-50E7-4E42-A125-57C0A11DBCDE}

Key Found : HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Low Rights\\ElevationPolicy\\{40C4727E-CA10-431C-997A-7E5F3583984C}

Key Found : HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Low Rights\\ElevationPolicy\\{D4214893-FDA6-4492-B57C-F79ED236F3B9}

Key Found : HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\SearchScopes\\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}

Key Found : HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\SearchScopes\\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}

Key Found : HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\SearchScopes\\{EEE6C360-6118-11DC-9C72-001320C79847}

Key Found : HKLM\\SOFTWARE\\Microsoft\\Tracing\\adawarebp_rasapi32

Key Found : HKLM\\SOFTWARE\\Microsoft\\Tracing\\adawarebp_rasmancs

Key Found : HKLM\\SOFTWARE\\Microsoft\\Tracing\\ApnSetup_RASAPI32

Key Found : HKLM\\SOFTWARE\\Microsoft\\Tracing\\ApnSetup_RASMANCS

Key Found : HKLM\\SOFTWARE\\Microsoft\\Tracing\\au__rasapi32

Key Found : HKLM\\SOFTWARE\\Microsoft\\Tracing\\au__rasmancs

Key Found : HKLM\\SOFTWARE\\Microsoft\\Tracing\\BingBar_RASMANCS

Key Found : HKLM\\SOFTWARE\\Microsoft\\Tracing\\iLivid_RASAPI32

Key Found : HKLM\\SOFTWARE\\Microsoft\\Tracing\\iLivid_RASMANCS

Key Found : HKLM\\SOFTWARE\\Microsoft\\Tracing\\iLividMediaBar_RASAPI32

Key Found : HKLM\\SOFTWARE\\Microsoft\\Tracing\\iLividMediaBar_RASMANCS

Key Found : HKLM\\SOFTWARE\\Microsoft\\Tracing\\iLividSetup_RASAPI32

Key Found : HKLM\\SOFTWARE\\Microsoft\\Tracing\\iLividSetup_RASMANCS

Key Found : HKLM\\SOFTWARE\\Microsoft\\Tracing\\privitizevpn_1_rasapi32

Key Found : HKLM\\SOFTWARE\\Microsoft\\Tracing\\privitizevpn_1_rasmancs

Key Found : HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\bitguard.exe

Key Found : HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\bprotect.exe

Key Found : HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\browserdefender.exe

Key Found : HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\browserprotect.exe

Key Found : HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Plain\\BackgroundContainer Startup Task

Key Found : HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A47317B1-D902-43B8-BF89-D1F5ED2018BB}

Key Found : HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{A47317B1-D902-43B8-BF89-D1F5ED2018BB}

Key Found : HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{02478D38-C3F9-4EFB-9B51-7695ECA05670}

Key Found : HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{96F454EA-9D38-474F-B504-56193E00C1A5}

Key Found : HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}

Key Found : HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Ext\\PreApproved\\{02478D38-C3F9-4EFB-9B51-7695ECA05670}

Key Found : HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Ext\\PreApproved\\{7C3B01BC-53A5-48A0-A43B-0C67731134B9}

Key Found : HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Ext\\PreApproved\\{CD90659F-D5B2-4104-9504-7CA36E6532DF}

Key Found : HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Ext\\PreApproved\\{EF99BD32-C1FB-11D2-892F-0090271D4F88}

Key Found : HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Installer\\UserData\\S-1-5-18\\Components\\08121C32A9C319F4CB0C11FF059552A4

Key Found : HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Search Results Toolbar

Key Found : HKLM\\Software\\SearchProtect

Key Found : HKLM\\Software\\SP Global

Key Found : HKLM\\Software\\SProtector

Key Found : HKLM\\Software\\uTorrentControl_v6

Key Found : HKLM\\Software\\visualbee

Key Found : HKLM\\Software\\Wajam

Key Found : HKLM\\SYSTEM\\CurrentControlSet\\Services\\Eventlog\\Application\\WajamUpdater

Value Found : HKCU\\Software\\Microsoft\\Internet Explorer\\Main [Backup.old.Start Page]

Value Found : HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser [{96F454EA-9D38-474F-B504-56193E00C1A5}]

Value Found : HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar\\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]

Value Found : HKCU\\Software\\Microsoft\\Internet Explorer\\URLSearchHooks [{96F454EA-9D38-474F-B504-56193E00C1A5}]

Value Found : HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Toolbar [{96F454EA-9D38-474F-B504-56193E00C1A5}]

Value Found : HKLM\\SOFTWARE\\Mozilla\\Firefox\\Extensions [{3C5F0F00-683D-4847-89C8-E7AF64FD1CFB}]

Value Found : HKLM\\SYSTEM\\ControlSet001\\Control\\Session Manager\\AppCertDlls [x64]

Value Found : HKLM\\SYSTEM\\ControlSet002\\Control\\Session Manager\\AppCertDlls [x64]

Value Found : HKLM\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\AppCertDlls [x64]

 

***** [ Browsers ] *****

 

-\\\\ Internet Explorer v10.0.9200.16750

 



 

-\\\\ Google Chrome v

 

[ File : C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\preferences ]

 

Found : homepage

Found : search_url

Found : suggest_url

Found : keyword

Found : urls_to_restore_on_startup

Found : homepage

Found : search_url

Found : urls_to_restore_on_startup

Found : homepage

Found : search_url

Found : suggest_url

Found : urls_to_restore_on_startup

 

*************************

 

AdwCleaner[R0].txt - [17028 octets] - [23/12/2013 21:59:59]

 

########## EOF - C:\\AdwCleaner\\AdwCleaner[R0].txt - [17089 octets] ##########

3
Tech Clinic / nativemessaging on chrome
« on: January 20, 2014, 12:37:45 PM »

oh i didnt see the part about posting the adw log here whats the log going to be called? i closed it out earlier.



4
Tech Clinic / nativemessaging on chrome
« on: January 20, 2014, 12:34:28 PM »

here is the second log


 


 


OTL logfile created on: 1/20/2014 11:12:13 AM - Run 2

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Users\\Kaila\\Desktop

 Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 9.10.9200.16750)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

 

1013.09 Mb Total Physical Memory | 127.41 Mb Available Physical Memory | 12.58% Memory free

1.99 Gb Paging File | 0.86 Gb Available in Paging File | 43.26% Paging File free

Paging file location(s): ?:\\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files

Drive C: | 219.79 Gb Total Space | 137.92 Gb Free Space | 62.75% Space Free | Partition Type: NTFS

 

Computer Name: JOHN | User Name: Kaila | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Processes (SafeList) ==========

 

PRC - [2014/01/18 12:20:39 | 000,302,961 | ---- | M] () -- C:\\Program Files\\Hosts_Anti_Adwares_PUPs\\HOSTS_Anti-Adware_main.exe

PRC - [2014/01/17 20:38:56 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Kaila\\Desktop\\OTL.exe

PRC - [2013/12/20 19:14:09 | 003,764,024 | ---- | M] (AVAST Software) -- C:\\Program Files\\AVAST Software\\Avast\\AvastUI.exe

PRC - [2013/12/20 19:14:09 | 000,050,344 | ---- | M] (AVAST Software) -- C:\\Program Files\\AVAST Software\\Avast\\AvastSvc.exe

PRC - [2013/02/05 12:10:48 | 000,581,624 | ---- | M] (NTI Corporation) -- C:\\Program Files\\NTI\\NTI Backup Now EZ\\BackupNowEZtray.exe

PRC - [2013/02/05 12:10:46 | 000,046,072 | ---- | M] (NTI Corporation) -- C:\\Program Files\\NTI\\NTI Backup Now EZ\\BackupNowEZSvr.exe

PRC - [2012/11/22 20:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\\Windows\\System32\\taskhost.exe

PRC - [2012/10/02 12:45:22 | 000,120,728 | ---- | M] () -- C:\\Program Files\\Motorola Mobility\\Motorola Device Manager\\MotoHelperService.exe

PRC - [2012/10/02 12:41:02 | 000,694,168 | ---- | M] () -- C:\\Program Files\\Motorola Mobility\\Motorola Device Manager\\MotoHelperAgent.exe

PRC - [2011/10/18 16:32:30 | 000,150,856 | ---- | M] (McAfee, Inc.) -- C:\\Program Files\\Common Files\\mcafee\\systemcore\\mfevtps.exe

PRC - [2011/10/18 16:28:34 | 000,160,608 | ---- | M] (McAfee, Inc.) -- C:\\Program Files\\Common Files\\mcafee\\systemcore\\mfefire.exe

PRC - [2011/09/02 16:06:38 | 000,065,657 | ---- | M] (Motorola) -- C:\\Program Files\\Motorola\\MotForwardDaemon\\ForwardDaemon.exe

PRC - [2011/02/24 23:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\\Windows\\explorer.exe

PRC - [2010/11/12 00:24:10 | 001,602,344 | ---- | M] (ELAN Microelectronics Corp.) -- C:\\Program Files\\Elantech\\ETDCtrlHelper.exe

PRC - [2010/11/12 00:24:08 | 001,812,264 | ---- | M] (ELAN Microelectronics Corp.) -- C:\\Program Files\\Elantech\\ETDCtrl.exe

PRC - [2010/08/10 03:06:16 | 000,975,952 | ---- | M] (Dritek System Inc.) -- C:\\Program Files\\Launch Manager\\LManager.exe

PRC - [2010/08/10 03:06:16 | 000,321,104 | ---- | M] (Dritek System Inc.) -- C:\\Program Files\\Launch Manager\\dsiwmis.exe

PRC - [2010/08/10 03:06:16 | 000,305,744 | ---- | M] (Dritek System Inc.) -- C:\\Program Files\\Launch Manager\\LMworker.exe

PRC - [2010/06/11 16:28:06 | 000,715,296 | ---- | M] (Acer Incorporated) -- C:\\Program Files\\Acer\\Acer ePower Management\\ePowerTray.exe

PRC - [2010/06/11 16:28:02 | 000,735,776 | ---- | M] (Acer Incorporated) -- C:\\Program Files\\Acer\\Acer ePower Management\\ePowerSvc.exe

PRC - [2010/06/11 16:27:54 | 000,469,536 | ---- | M] (Acer Incorporated) -- C:\\Program Files\\Acer\\Acer ePower Management\\ePowerEvent.exe

PRC - [2010/03/11 00:11:56 | 000,407,920 | ---- | M] (Egis Technology Inc.) -- C:\\Program Files\\EgisTec IPS\\PmmUpdate.exe

PRC - [2010/03/11 00:11:42 | 000,201,584 | ---- | M] (Egis Technology Inc.) -- C:\\Program Files\\EgisTec IPS\\EgisUpdate.exe

PRC - [2010/01/29 18:52:58 | 000,260,640 | ---- | M] (Acer Incorporated) -- C:\\Program Files\\Acer\\Acer VCM\\RS_Service.exe

PRC - [2010/01/08 07:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) -- C:\\Program Files\\Acer\\Registration\\GREGsvc.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2014/01/18 12:20:39 | 000,302,961 | ---- | M] () -- C:\\Program Files\\Hosts_Anti_Adwares_PUPs\\HOSTS_Anti-Adware_main.exe

MOD - [2013/12/20 19:14:12 | 019,336,120 | ---- | M] () -- C:\\Program Files\\AVAST Software\\Avast\\libcef.dll

MOD - [2013/12/03 20:48:04 | 000,399,312 | ---- | M] () -- C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\Application\\31.0.1650.63\\ppGoogleNaClPluginChrome.dll

MOD - [2013/12/03 20:48:02 | 004,055,504 | ---- | M] () -- C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\Application\\31.0.1650.63\\pdf.dll

MOD - [2013/12/03 20:47:11 | 000,702,416 | ---- | M] () -- C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\Application\\31.0.1650.63\\libglesv2.dll

MOD - [2013/12/03 20:47:11 | 000,099,792 | ---- | M] () -- C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\Application\\31.0.1650.63\\libegl.dll

MOD - [2013/12/03 20:47:08 | 001,619,408 | ---- | M] () -- C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\Application\\31.0.1650.63\\ffmpegsumo.dll

MOD - [2013/02/05 12:11:18 | 000,465,824 | ---- | M] () -- C:\\Program Files\\NTI\\NTI Backup Now EZ\\sqlite3.dll

MOD - [2012/10/02 12:41:02 | 000,694,168 | ---- | M] () -- C:\\Program Files\\Motorola Mobility\\Motorola Device Manager\\MotoHelperAgent.exe

MOD - [2012/08/27 23:33:32 | 000,087,912 | ---- | M] () -- C:\\Program Files\\Common Files\\Apple\\Apple Application Support\\zlib1.dll

MOD - [2012/08/27 23:33:08 | 001,242,512 | ---- | M] () -- C:\\Program Files\\Common Files\\Apple\\Apple Application Support\\libxml2.dll

MOD - [2009/05/20 00:02:04 | 000,072,200 | ---- | M] () -- C:\\Program Files\\Launch Manager\\CdDirIo.dll

 

 

========== Services (SafeList) ==========

 

SRV - File not found [Auto | Stopped] -- C:\\Program Files\\Common Files\\AVG Secure Search\\vToolbarUpdater\\17.0.1\\ToolbarUpdater.exe -- (vToolbarUpdater17.0.1)

SRV - [2014/01/18 12:20:37 | 000,285,795 | ---- | M] () [Auto | Stopped] -- C:\\Program Files\\Hosts_Anti_Adwares_PUPs\\HOSTS_Anti-Adware.exe -- (HOSTS Anti-PUPs)

SRV - [2013/12/20 19:14:09 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\\Program Files\\AVAST Software\\Avast\\AvastSvc.exe -- (avast! Antivirus)

SRV - [2013/12/13 19:20:00 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\\Windows\\System32\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2013/05/26 22:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)

SRV - [2013/02/05 12:10:46 | 000,046,072 | ---- | M] (NTI Corporation) [Auto | Running] -- C:\\Program Files\\NTI\\NTI Backup Now EZ\\BackupNowEZSvr.exe -- (NTI BackupNowEZSvr)

SRV - [2012/10/02 12:45:22 | 000,120,728 | ---- | M] () [Auto | Running] -- C:\\Program Files\\Motorola Mobility\\Motorola Device Manager\\MotoHelperService.exe -- (Motorola Device Manager)

SRV - [2011/10/18 16:32:30 | 000,150,856 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\\Program Files\\Common Files\\mcafee\\systemcore\\mfevtps.exe -- (mfevtp)

SRV - [2011/10/18 16:28:34 | 000,160,608 | ---- | M] () [Auto | Running] -- C:\\Program Files\\Common Files\\McAfee\\SystemCore\\\\mfefire.exe -- (mfefire)

SRV - [2011/10/18 16:28:18 | 000,166,288 | ---- | M] () [Auto | Stopped] -- C:\\Program Files\\Common Files\\McAfee\\SystemCore\\\\mcshield.exe -- (McShield)

SRV - [2011/09/02 16:06:38 | 000,065,657 | ---- | M] (Motorola) [Auto | Running] -- C:\\Program Files\\Motorola\\MotForwardDaemon\\ForwardDaemon.exe -- (PST Service)

SRV - [2010/10/12 11:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\\Program Files\\WildTangent Games\\App\\GamesAppService.exe -- (GamesAppService)

SRV - [2010/08/10 03:06:16 | 000,321,104 | ---- | M] (Dritek System Inc.) [Auto | Running] -- C:\\Program Files\\Launch Manager\\dsiwmis.exe -- (DsiWMIService)

SRV - [2010/06/11 16:28:02 | 000,735,776 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\\Program Files\\Acer\\Acer ePower Management\\ePowerSvc.exe -- (ePowerSvc)

SRV - [2010/05/26 21:41:06 | 000,305,520 | ---- | M] (Egis Technology Inc.) [On_Demand | Stopped] -- C:\\Program Files\\EgisTec MyWinLocker\\x86\\MWLService.exe -- (MWLService)

SRV - [2010/01/29 18:52:58 | 000,260,640 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\\Program Files\\Acer\\Acer VCM\\RS_Service.exe -- (RS_Service)

SRV - [2010/01/28 18:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto | Stopped] -- C:\\Program Files\\Acer\\Acer Updater\\UpdaterService.exe -- (Updater Service)

SRV - [2010/01/08 07:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\\Program Files\\Acer\\Registration\\GREGsvc.exe -- (GREGService)

 

 

========== Driver Services (SafeList) ==========

 

DRV - File not found [Kernel | System | Stopped] -- C:\\Windows\\system32\\drivers\\SBREdrv.sys -- (SBRE)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\\DRIVERS\\motusbdevice.sys -- (motusbdevice)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\\DRIVERS\\Motousbnet.sys -- (Motousbnet)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\\DRIVERS\\motswch.sys -- (MotoSwitchService)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\\DRIVERS\\motccgpfl.sys -- (motccgpfl)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\\DRIVERS\\motccgp.sys -- (motccgp)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\\DRIVERS\\motfilt.sys -- (BTCFilterService)

DRV - [2013/12/20 19:14:56 | 000,064,168 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- C:\\Windows\\System32\\drivers\\aswstm.sys -- (aswStm)

DRV - [2013/12/20 19:14:16 | 000,775,952 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\\Windows\\System32\\drivers\\aswSnx.sys -- (aswSnx)

DRV - [2013/12/20 19:14:16 | 000,410,528 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\\Windows\\System32\\drivers\\aswSP.sys -- (aswSP)

DRV - [2013/12/20 19:14:16 | 000,180,248 | ---- | M] () [Kernel | Boot | Running] -- C:\\Windows\\System32\\drivers\\aswVmm.sys -- (aswVmm)

DRV - [2013/12/20 19:14:16 | 000,079,720 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\\Windows\\System32\\drivers\\aswRdr2.sys -- (aswRdr)

DRV - [2013/12/20 19:14:16 | 000,067,824 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\\Windows\\System32\\drivers\\aswMonFlt.sys -- (aswMonFlt)

DRV - [2013/12/20 19:14:16 | 000,049,944 | ---- | M] () [Kernel | Boot | Running] -- C:\\Windows\\System32\\drivers\\aswRvrt.sys -- (aswRvrt)

DRV - [2012/08/23 08:44:32 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\rdpvideominiport.sys -- (RdpVideoMiniport)

DRV - [2012/08/23 08:40:25 | 000,049,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\TsUsbFlt.sys -- (TsUsbFlt)

DRV - [2012/03/26 16:50:12 | 000,018,432 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\netaapl.sys -- (Netaapl)

DRV - [2011/10/15 15:16:16 | 000,464,176 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\\Windows\\System32\\drivers\\mfehidk.sys -- (mfehidk)

DRV - [2011/10/15 15:16:16 | 000,338,176 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\System32\\drivers\\mfefirek.sys -- (mfefirek)

DRV - [2011/10/15 15:16:16 | 000,180,816 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\System32\\drivers\\mfeavfk.sys -- (mfeavfk)

DRV - [2011/10/15 15:16:16 | 000,165,680 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\\Windows\\System32\\drivers\\mfewfpk.sys -- (mfewfpk)

DRV - [2011/10/15 15:16:16 | 000,121,256 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\mfeapfk.sys -- (mfeapfk)

DRV - [2011/10/15 15:16:16 | 000,087,656 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\mferkdet.sys -- (mferkdet)

DRV - [2011/10/15 15:16:16 | 000,064,880 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\\Windows\\System32\\drivers\\mfenlfk.sys -- (mfenlfk)

DRV - [2011/10/15 15:16:16 | 000,059,456 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\mfebopk.sys -- (mfebopk)

DRV - [2011/10/15 15:16:16 | 000,057,600 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\cfwids.sys -- (cfwids)

DRV - [2010/12/03 00:30:44 | 000,025,600 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\nx6000.sys -- (MSHUSBVideo)

DRV - [2010/11/20 03:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\winusb.sys -- (WinUsb)

DRV - [2010/08/24 03:55:52 | 000,068,208 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\L1C62x86.sys -- (L1C)

DRV - [2010/07/15 15:57:36 | 001,906,024 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\System32\\drivers\\athr.sys -- (athr)

DRV - [2010/06/17 00:50:38 | 000,082,768 | ---- | M] (ENE Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\EUCR6SK.sys -- (EUCR)

DRV - [2009/07/13 17:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\System32\\drivers\\vwifimp.sys -- (vwifimp)

DRV - [2009/07/13 17:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\serial.sys -- (Serial)

DRV - [2009/06/02 21:15:40 | 000,060,976 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\\Windows\\System32\\drivers\\mwlPSDVDisk.sys -- (mwlPSDVDisk)

DRV - [2009/06/02 21:15:38 | 000,016,432 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\\Windows\\System32\\drivers\\mwlPSDNserv.sys -- (mwlPSDNServ)

DRV - [2009/06/02 21:15:34 | 000,018,992 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\\Windows\\System32\\drivers\\mwlPSDFilter.sys -- (mwlPSDFilter)

DRV - [2008/05/06 17:06:00 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\wdcsam.sys -- (WDC_SAM)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLM\\..\\SearchScopes,Backup.Old.DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKLM\\..\\SearchScopes,DefaultScope = 

IE - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\\..\\SearchScopes\\{507E350E-949D-BB7D-314C-7539CF247C38}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox

 

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Default_Page_URL = http://www.google.com\'>http://www.google.com

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Search Bar = www.bing.com

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Search Page = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = http://www.google.com\'>http://www.google.com

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Search,Default_Search_URL = http://www.google.com\'>http://www.google.com

IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Search,SearchAssistant = http://www.google.com\'>http://www.google.com

IE - HKCU\\..\\SearchScopes,Backup.Old.DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKCU\\..\\SearchScopes,DefaultScope = 

IE - HKCU\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://www.bing.com/search\'>http://www.bing.com/search

IE - HKCU\\..\\SearchScopes\\{18E7AACF-9B3E-46E8-8382-BAB463727B5E}: \"URL\" = http://search.yahoo.com/search?p=\'>http://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=10743

IE - HKCU\\..\\SearchScopes\\{50349BBE-F1B2-4659-B85A-16401AF9064C}: \"URL\" = http://search.findwide.com/serp?guid=\'>http://search.findwide.com/serp?guid={FAD49E06-D413-4B08-8349-8A71DBFA0C8C}&action=default_search&serpv=22&k={searchTerms}

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = 192.168.*.*

 

 

========== FireFox ==========

 

FF - HKLM\\Software\\MozillaPlugins\\@Apple.com/iTunes,version=:  File not found

FF - HKLM\\Software\\MozillaPlugins\\@Apple.com/iTunes,version=1.0: C:\\Program Files\\iTunes\\Mozilla Plugins\\npitunes.dll ()

FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.51.2: C:\\Program Files\\Java\\jre7\\bin\\dtplugin\\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.51.2: C:\\Program Files\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@Microsoft.com/NpCtrl,version=1.0: c:\\Program Files\\Microsoft Silverlight\\5.1.20913.0\\npctrl.dll ( Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/WLPG,version=15.4.3502.0922: C:\\Program Files\\Windows Live\\Photo Gallery\\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/WLPG,version=15.4.3508.1109: C:\\Program Files\\Windows Live\\Photo Gallery\\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@videolan.org/vlc,version=2.0.0: C:\\Program Files\\VideoLAN\\VLC\\npvlc.dll (VideoLAN)

FF - HKLM\\Software\\MozillaPlugins\\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\\Program Files\\WildTangent Games\\App\\BrowserIntegration\\Registered\\4\\NP_wtapp.dll ()

FF - HKCU\\Software\\MozillaPlugins\\@Skype Limited.com/Facebook Video Calling Plugin: C:\\Users\\Kaila\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll (Skype Limited)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\Kaila\\AppData\\Local\\Google\\Update\\1.3.22.3\\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\Kaila\\AppData\\Local\\Google\\Update\\1.3.22.3\\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\\Program Files\\Common Files\\McAfee\\SystemCore [2012/09/02 00:16:21 | 000,000,000 | ---D | M]

 

[2013/12/13 16:03:38 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Kaila\\AppData\\Roaming\\mozilla\\Firefox\\extensions

[2013/12/05 15:07:08 | 000,000,000 | ---D | M] (uTorrentControl_v6) -- C:\\Users\\Kaila\\AppData\\Roaming\\mozilla\\Firefox\\extensions\\{96f454ea-9d38-474f-b504-56193e00c1a5}

[2013/12/31 22:07:34 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files\\Mozilla Firefox\\extensions

 

========== Chrome  ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},


CHR - plugin: Shockwave Flash (Enabled) = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\Application\\31.0.1650.63\\PepperFlash\\pepflashplayer.dll

CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\Application\\31.0.1650.63\\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Disabled) = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\Application\\31.0.1650.63\\pdf.dll

CHR - plugin: npDefaultTabSearch plugin (Enabled) = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\kdidombaedgpfiiedeimiebkmbilgmlc\\1.1.14_0\\plugins/npDefaultTabSearch.dll

CHR - plugin: Adobe Acrobat (Enabled) = C:\\Program Files\\Adobe\\Reader 9.0\\Reader\\Browser\\nppdf32.dll

CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\\Program Files\\Java\\jre6\\bin\\new_plugin\\npdeployJava1.dll

CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\\Program Files\\Java\\jre6\\bin\\new_plugin\\npjp2.dll

CHR - plugin: AVG SiteSafety plugin (Enabled) = C:\\Program Files\\Common Files\\AVG Secure Search\\SiteSafetyInstaller\\13.2.0\\\\npsitesafety.dll

CHR - plugin: VLC Web Plugin (Enabled) = C:\\Program Files\\VideoLAN\\VLC\\npvlc.dll

CHR - plugin: WildTangent Games App V2 Presence Detector (Enabled) = C:\\Program Files\\WildTangent Games\\App\\BrowserIntegration\\Registered\\2\\NP_wtapp.dll

CHR - plugin: Windows Live Photo Gallery (Enabled) = C:\\Program Files\\Windows Live\\Photo Gallery\\NPWLPG.dll

CHR - plugin: iTunes Application Detector (Enabled) = C:\\Program Files\\iTunes\\Mozilla Plugins\\npitunes.dll

CHR - plugin: Google Update (Enabled) = C:\\Users\\Kaila\\AppData\\Local\\Google\\Update\\1.3.21.135\\npGoogleUpdate3.dll

CHR - plugin: Silverlight Plug-In (Enabled) = c:\\Program Files\\Microsoft Silverlight\\5.1.20125.0\\npctrl.dll

CHR - Extension: Dark Vibe = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dkckeanhmkjaechlhllmapjaaglgpcbj\\1.1_0\\

CHR - Extension: ShopAtHome.com extension = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlmebkoiahbppacaicbgncnjhbpdfkcc\\7.1.0.16_0\\

CHR - Extension: avast! Online Security = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\gomekmidlodglbbmalcneegieacbdmki\\9.0.2013.75_0\\

CHR - Extension: No name found = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\njkkjobcechefaoknodniidfjapgfoco\\2.2.7_0\\

CHR - Extension: Google Wallet = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda\\0.0.6.0_0\\

CHR - Extension: Bitdefender QuickScan = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pdnkcidphdcakpkheohlhocaicfamjie\\0.9.9.131_0\\

CHR - Extension: Dark Vibe = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dkckeanhmkjaechlhllmapjaaglgpcbj\\1.1_0\\

CHR - Extension: ShopAtHome.com extension = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlmebkoiahbppacaicbgncnjhbpdfkcc\\7.1.0.16_0\\

CHR - Extension: avast! Online Security = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\gomekmidlodglbbmalcneegieacbdmki\\9.0.2013.75_0\\

CHR - Extension: No name found = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\njkkjobcechefaoknodniidfjapgfoco\\2.2.7_0\\

CHR - Extension: Google Wallet = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda\\0.0.6.0_0\\

CHR - Extension: Bitdefender QuickScan = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pdnkcidphdcakpkheohlhocaicfamjie\\0.9.9.131_0\\

 

O1 HOSTS File: ([2014/01/19 10:21:03 | 000,039,784 | ---- | M]) - C:\\Windows\\System32\\drivers\\etc\\hosts

O1 - Hosts: 127.0.0.1 08sr.combineads.info # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 08srvr.combineads.info # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 12srvr.combineads.info # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 2010-fr.com # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 2012-new.biz # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 212link.com # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 2319825.ourtoolbar.com # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 24h00business.com # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 a.adorika.net # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 a.ad-sys.com # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 a.daasafterdusk.com # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 ad.adn360.com # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 adeartss.eu # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 adesoeasy.eu # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 adf.girldatesforfree.net # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 adm.soft365.com # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 adomicileavail.googlepages.com # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 ads7.complexadveising.com # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 ads.adplxmd.com # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 ads.aff.co # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 ads.alpha00001.com # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 ads.cloud4ads.com # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 ads.eorezo.com # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 ads.hooqy.com # hosts anti-adware / pups

O1 - Hosts: 127.0.0.1 ads.pornerbros.com # hosts anti-adware / pups

O1 - Hosts: 661 more lines...

O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\\PROGRA~1\\mcafee\\msk\\mskapbho.dll File not found

O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)

O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\\Program Files\\Common Files\\mcafee\\systemcore\\ScriptSn.20120112163500.dll (McAfee, Inc.)

O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\\Program Files\\AVAST Software\\Avast\\aswWebRepIE.dll (AVAST Software)

O2 - BHO: (Tidy Network) - {D8A98206-1249-3EBA-FB18-4ADF7ED746FD} - C:\\Program Files\\TidyNetwork\\petn.dll File not found

O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)

O3 - HKLM\\..\\Toolbar: (no name) - {45177936-603b-4261-8d42-df6f7091d5d0} - No CLSID value found.

O3 - HKLM\\..\\Toolbar: (avast! Online Security) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\\Program Files\\AVAST Software\\Avast\\aswWebRepIE.dll (AVAST Software)

O3 - HKLM\\..\\Toolbar: (no name) - 10 - No CLSID value found.

O3 - HKLM\\..\\Toolbar: (no name) - Locked - No CLSID value found.

O4 - HKLM..\\Run: [Acer ePower Management] C:\\Program Files\\Acer\\Acer ePower Management\\ePowerTray.exe (Acer Incorporated)

O4 - HKLM..\\Run: [APSDaemon] C:\\Program Files\\Common Files\\Apple\\Apple Application Support\\APSDaemon.exe (Apple Inc.)

O4 - HKLM..\\Run: [AvastUI.exe] C:\\Program Files\\AVAST Software\\Avast\\AvastUI.exe (AVAST Software)

O4 - HKLM..\\Run: [BackupNowEZtray] C:\\Program Files\\NTI\\NTI Backup Now EZ\\BackupNowEZtray.exe (NTI Corporation)

O4 - HKLM..\\Run: [EgisTecPMMUpdate] C:\\Program Files\\EgisTec IPS\\PmmUpdate.exe (Egis Technology Inc.)

O4 - HKLM..\\Run: [EgisUpdate] C:\\Program Files\\EgisTec IPS\\EgisUpdate.exe (Egis Technology Inc.)

O4 - HKLM..\\Run: [ETDCtrl] C:\\Program Files\\Elantech\\ETDCtrl.exe (ELAN Microelectronics Corp.)

O4 - HKLM..\\Run: [HOSTS Anti-Adware_PUPs] C:\\Program Files\\Hosts_Anti_Adwares_PUPs\\HOSTS_Anti-Adware_main.exe ()

O4 - HKLM..\\Run: [LManager] C:\\Program Files\\Launch Manager\\LManager.exe (Dritek System Inc.)

O4 - HKLM..\\Run: [ROC_roc_ssl_v12] \"C:\\Program Files\\AVG Secure Search\\ROC_roc_ssl_v12.exe\" / /PROMPT /CMPID=roc_ssl_v12 File not found

O4 - HKCU..\\Run: [Facebook Update] C:\\Users\\Kaila\\AppData\\Local\\Facebook\\Update\\FacebookUpdate.exe (Facebook Inc.)

O4 - HKCU..\\Run: [uTorrent] C:\\Users\\Kaila\\AppData\\Roaming\\uTorrent\\uTorrent.exe (BitTorrent Inc.)

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorAdmin = 5

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3

O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145

O9 - Extra Button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\\Program Files\\Paltalk Messenger\\paltalk.exe (AVM Software Inc.)

O13 - gopher Prefix: missing




O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters: DhcpNameServer = 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{15EAC838-19E9-4FA3-B6AC-CE7E9B30E965}: DhcpNameServer = 172.26.38.1 172.26.38.2

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{A81087B2-589B-456F-8D51-F5A5BADAE6F1}: DhcpNameServer = 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B74E8B87-E008-4422-BD86-86D613D27F22}: DhcpNameServer = 192.168.1.1

O18 - Protocol\\Handler\\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\\Program Files\\Windows Live\\Messenger\\msgrapp.dll File not found

O18 - Protocol\\Handler\\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\\Program Files\\Windows Live\\Messenger\\msgrapp.dll File not found

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\System32\\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\\Windows\\System32\\SystemPropertiesPerformance.exe (Microsoft Corporation)

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2009/06/10 15:42:20 | 000,000,024 | ---- | M] () - C:\\autoexec.bat -- [ NTFS ]

O33 - MountPoints2\\{c001a154-d848-11e0-b3a4-1c7508b345b6}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{c001a154-d848-11e0-b3a4-1c7508b345b6}\\Shell\\AutoRun\\command - \"\" = \"D:\\WD SmartWare.exe\" autoplay=true

O33 - MountPoints2\\{fed23421-ccaf-11e2-a2ff-889ffa0527f7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{fed23421-ccaf-11e2-a2ff-889ffa0527f7}\\Shell\\AutoRun\\command - \"\" = D:\\MotoCastSetup.exe -a

O34 - HKLM BootExecute: (autocheck autochk *)

O35 - HKLM\\..comfile [open] -- \"%1\" %*

O35 - HKLM\\..exefile [open] -- \"%1\" %*

O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\\\Windows: (ServerDll=sxssrv,4)

 

========== Files/Folders - Created Within 30 Days ==========

 

[2014/01/20 09:32:14 | 000,000,000 | ---D | C] -- C:\\Windows\\ERUNT

[2014/01/20 09:22:01 | 001,037,068 | ---- | C] (Thisisu) -- C:\\Users\\Kaila\\Desktop\\JRT.exe

[2014/01/19 11:01:42 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Elaborate Bytes

[2014/01/19 11:01:41 | 000,000,000 | ---D | C] -- C:\\Program Files\\Elaborate Bytes

[2014/01/18 12:20:34 | 000,000,000 | ---D | C] -- C:\\Program Files\\Hosts_Anti_Adwares_PUPs

[2014/01/17 20:38:20 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Kaila\\Desktop\\OTL.exe

[2014/01/17 20:28:12 | 000,000,000 | ---D | C] -- C:\\Users\\Kaila\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Chrome Apps

[2014/01/17 19:48:32 | 000,264,616 | ---- | C] (Oracle Corporation) -- C:\\Windows\\System32\\javaws.exe

[2014/01/17 19:48:04 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\\Windows\\System32\\javaw.exe

[2014/01/17 19:48:04 | 000,174,504 | ---- | C] (Oracle Corporation) -- C:\\Windows\\System32\\java.exe

[2014/01/17 19:48:04 | 000,094,632 | ---- | C] (Oracle Corporation) -- C:\\Windows\\System32\\WindowsAccessBridge.dll

[2014/01/17 19:48:04 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Java

[2014/01/14 21:45:27 | 002,349,056 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\System32\\win32k.sys

[2014/01/14 21:45:24 | 000,240,576 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\System32\\drivers\\netio.sys

[2014/01/14 21:45:21 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\System32\\drivers\\usbport.sys

[2014/01/14 21:45:18 | 000,006,016 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\System32\\drivers\\usbd.sys

[2014/01/12 19:52:53 | 000,000,000 | ---D | C] -- C:\\Users\\Kaila\\Desktop\\Movies

[2014/01/08 16:28:48 | 000,000,000 | ---D | C] -- C:\\Users\\Kaila\\Desktop\\Insanity Workout

[2013/12/31 22:07:34 | 000,000,000 | ---D | C] -- C:\\Program Files\\Mozilla Firefox

[2013/12/23 22:30:56 | 000,000,000 | ---D | C] -- C:\\Program Files\\ToniArts

[2013/12/23 22:30:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\EasyCleaner

[2013/12/23 21:59:23 | 000,000,000 | ---D | C] -- C:\\AdwCleaner

 

========== Files - Modified Within 30 Days ==========

 

[2014/01/20 11:09:02 | 000,000,908 | ---- | M] () -- C:\\Windows\\tasks\\GoogleUpdateTaskUserS-1-5-21-2509488165-3742344647-2209741551-1000UA.job

[2014/01/20 11:03:03 | 000,000,928 | ---- | M] () -- C:\\Windows\\tasks\\FacebookUpdateTaskUserS-1-5-21-2509488165-3742344647-2209741551-1000UA.job

[2014/01/20 11:03:01 | 000,000,906 | ---- | M] () -- C:\\Windows\\tasks\\FacebookUpdateTaskUserS-1-5-21-2509488165-3742344647-2209741551-1000Core.job

[2014/01/20 10:28:01 | 000,000,830 | ---- | M] () -- C:\\Windows\\tasks\\Adobe Flash Player Updater.job

[2014/01/20 09:23:07 | 001,037,068 | ---- | M] (Thisisu) -- C:\\Users\\Kaila\\Desktop\\JRT.exe

[2014/01/20 09:14:36 | 000,067,584 | --S- | M] () -- C:\\Windows\\bootstat.dat

[2014/01/19 15:09:01 | 000,000,856 | ---- | M] () -- C:\\Windows\\tasks\\GoogleUpdateTaskUserS-1-5-21-2509488165-3742344647-2209741551-1000Core.job

[2014/01/19 11:05:57 | 000,001,176 | ---- | M] () -- C:\\Users\\Public\\Desktop\\Virtual CloneDrive.lnk

[2014/01/19 11:04:01 | 2561,570,792 | ---- | M] () -- C:\\Users\\Kaila\\Desktop\\X17-58996.iso

[2014/01/19 10:46:22 | 001,640,984 | ---- | M] () -- C:\\Users\\Kaila\\Desktop\\SetupVirtualCloneDrive5470.exe

[2014/01/19 10:29:53 | 000,009,696 | -H-- | M] () -- C:\\Windows\\System32\\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

[2014/01/19 10:29:53 | 000,009,696 | -H-- | M] () -- C:\\Windows\\System32\\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

[2014/01/19 10:21:20 | 000,000,350 | ---- | M] () -- C:\\Windows\\tasks\\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job

[2014/01/19 10:21:03 | 000,039,784 | ---- | M] () -- C:\\Windows\\System32\\drivers\\etc\\hosts

[2014/01/19 10:20:39 | 796,729,344 | -HS- | M] () -- C:\\hiberfil.sys

[2014/01/18 12:03:16 | 001,236,282 | ---- | M] () -- C:\\Users\\Kaila\\Desktop\\adwcleaner.exe

[2014/01/17 20:38:56 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Kaila\\Desktop\\OTL.exe

[2014/01/17 20:27:10 | 000,002,326 | ---- | M] () -- C:\\Users\\Kaila\\Desktop\\Chrome App Launcher.lnk

[2014/01/17 16:02:03 | 000,259,112 | ---- | M] () -- C:\\Windows\\System32\\FNTCACHE.DAT

 

========== Files Created - No Company Name ==========

 

[2014/01/19 11:05:57 | 000,001,176 | ---- | C] () -- C:\\Users\\Public\\Desktop\\Virtual CloneDrive.lnk

[2014/01/19 10:51:18 | 2561,570,792 | ---- | C] () -- C:\\Users\\Kaila\\Desktop\\X17-58996.iso

[2014/01/19 10:46:07 | 001,640,984 | ---- | C] () -- C:\\Users\\Kaila\\Desktop\\SetupVirtualCloneDrive5470.exe

[2014/01/18 12:02:22 | 001,236,282 | ---- | C] () -- C:\\Users\\Kaila\\Desktop\\adwcleaner.exe

[2014/01/17 20:27:10 | 000,002,326 | ---- | C] () -- C:\\Users\\Kaila\\Desktop\\Chrome App Launcher.lnk

[2013/12/20 19:14:29 | 000,180,248 | ---- | C] () -- C:\\Windows\\System32\\drivers\\aswVmm.sys

[2013/12/20 19:14:28 | 000,049,944 | ---- | C] () -- C:\\Windows\\System32\\drivers\\aswRvrt.sys

[2013/12/11 20:20:46 | 000,000,218 | ---- | C] () -- C:\\Users\\Kaila\\AppData\\Local\\recently-used.xbel

[2013/09/09 10:22:27 | 000,000,258 | RHS- | C] () -- C:\\Users\\Kaila\\ntuser.pol

[2013/01/18 19:54:27 | 000,001,415 | ---- | C] () -- C:\\Windows\\wininit.ini

[2012/06/12 18:47:43 | 000,007,598 | ---- | C] () -- C:\\Users\\Kaila\\AppData\\Local\\Resmon.ResmonCfg

 

========== ZeroAccess Check ==========

 

[2009/07/13 22:42:31 | 000,000,227 | RHS- | M] () -- C:\\Windows\\assembly\\Desktop.ini

 

[HKEY_CURRENT_USER\\Software\\Classes\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32]

 

[HKEY_CURRENT_USER\\Software\\Classes\\clsid\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\InProcServer32]

 

[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32]

\"\" = %SystemRoot%\\system32\\shell32.dll -- [2013/07/25 19:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)

\"ThreadingModel\" = Apartment

 

[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\\InProcServer32]

\"\" = %systemroot%\\system32\\wbem\\fastprox.dll -- [2010/11/20 06:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)

\"ThreadingModel\" = Free

 

[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\\InProcServer32]

\"\" = %systemroot%\\system32\\wbem\\wbemess.dll -- [2009/07/13 19:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)

\"ThreadingModel\" = Both

 

========== Alternate Data Streams ==========

 

@Alternate Data Stream - 119 bytes -> C:\\ProgramData\\TEMP:5C321E34

 

< End of report >

5
Tech Clinic / nativemessaging on chrome
« on: January 20, 2014, 12:11:19 PM »

the nativemessaging on chrome fixed with the first option you had me do. here is the log for the junkware removal tool.


 


 



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Junkware Removal Tool (JRT) by Thisisu

Version: 6.1.0 (01.07.2014:1)

OS: Windows 7 Starter x86

Ran by Kaila on Mon 01/20/2014 at  9:32:30.75

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

 

 

 

~~~ Services

 

 

 

~~~ Registry Values

 

Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\\\sbregrebootcleaner

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\\\Start Page

Successfully repaired: [Registry Value] HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\Internet Explorer\\Main\\\\Start Page

Successfully repaired: [Registry Value] HKEY_USERS\\S-1-5-18\\Software\\Microsoft\\Internet Explorer\\Main\\\\Start Page

Successfully repaired: [Registry Value] HKEY_USERS\\S-1-5-19\\Software\\Microsoft\\Internet Explorer\\Main\\\\Start Page

Successfully repaired: [Registry Value] HKEY_USERS\\S-1-5-20\\Software\\Microsoft\\Internet Explorer\\Main\\\\Start Page

Successfully repaired: [Registry Value] HKEY_USERS\\S-1-5-21-2509488165-3742344647-2209741551-1000\\Software\\Microsoft\\Internet Explorer\\Main\\\\Start Page

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\\\DisplayName

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\\\URL

 

 

 

~~~ Registry Keys

 

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\\dynconie.dynconieobject

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\\dynconie.dynconieobject.1

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\\Interface\\{2830488C-079B-45C2-88B6-AFE4EAA2DF85}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\\TypeLib\\{781CA792-9B6E-400B-B36F-15C097D2CA54}

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\InternetRegistry\\REGISTRY\\USER\\S-1-5-21-2509488165-3742344647-2209741551-1000\\Software\\sweetim

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\strongvaultapp_rasapi32

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\strongvaultapp_rasmancs

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{2ED3B46A-A91C-47C9-92D7-3EF05BB5429B}

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{6F47C78D-F91C-4A9E-9641-012D759138CA}

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\{C8D1C99A-92F2-4AB8-9162-0449E1743972}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{45470599-8237-486D-87B5-E89CD6AED154}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{45177936-603b-4261-8d42-df6f7091d5d0}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\\CLSID\\{45177936-603b-4261-8d42-df6f7091d5d0}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Low Rights\\ElevationPolicy\\{45177936-603b-4261-8d42-df6f7091d5d0}

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{45470599-8237-486D-87B5-E89CD6AED154}

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\\CLSID\\{45470599-8237-486D-87B5-E89CD6AED154}

 

 

 

~~~ Files

 

 

 

~~~ Folders

 

Successfully deleted: [Folder] \"C:\\Users\\Kaila\\AppData\\Roaming\\mywordtool\"

Successfully deleted: [Folder] \"C:\\Users\\Kaila\\appdata\\local\\cre\"

Successfully deleted: [Folder] \"C:\\Users\\Kaila\\appdata\\local\\stronghold_llc\"

Successfully deleted: [Folder] \"C:\\Users\\Kaila\\appdata\\locallow\\datamngr\"

Successfully deleted: [Folder] \"C:\\Windows\\system32\\ai_recyclebin\"

Successfully deleted: [Empty Folder] C:\\Users\\Kaila\\appdata\\local\\{097547FC-824E-47C8-A0CA-F420BCF1F6BB}

Successfully deleted: [Empty Folder] C:\\Users\\Kaila\\appdata\\local\\{23903FD9-325A-4987-9406-868768C67A16}

Successfully deleted: [Empty Folder] C:\\Users\\Kaila\\appdata\\local\\{A55F3603-DB32-45B8-BC55-D04A110A6A38}

Successfully deleted: [Empty Folder] C:\\Users\\Kaila\\appdata\\local\\{C808FF1A-DE48-4778-B563-B9540E9C1CFE}

 

 

 

~~~ Event Viewer Logs were cleared

 

 

 

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Scan was completed on Mon 01/20/2014 at  9:42:19.88

End of JRT log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 


6
Tech Clinic / nativemessaging on chrome
« on: January 17, 2014, 10:10:40 PM »

hey sorry about my last topic. i had the computer traded. i just figured itd be easier. however this computer has some slike problems. i dont know why maybe its something ive downloaded.


 


the hijackthis didnt work agan so ive done a scan with otl.


here is the otl.txt first and then extras.txt


 


 


 


 


OTL logfile created on: 1/17/2014 8:40:40 PM - Run 1

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Users\\Kaila\\Desktop

 Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 9.10.9200.16750)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

 

1013.09 Mb Total Physical Memory | 531.36 Mb Available Physical Memory | 52.45% Memory free

3.10 Gb Paging File | 1.08 Gb Available in Paging File | 35.01% Paging File free

Paging file location(s): ?:\\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files

Drive C: | 219.79 Gb Total Space | 163.52 Gb Free Space | 74.40% Space Free | Partition Type: NTFS

 

Computer Name: JOHN | User Name: Kaila | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Processes (SafeList) ==========

 

PRC - [2014/01/17 20:38:56 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Kaila\\Desktop\\OTL.exe

PRC - [2013/12/20 19:14:09 | 003,764,024 | ---- | M] (AVAST Software) -- C:\\Program Files\\AVAST Software\\Avast\\AvastUI.exe

PRC - [2013/12/20 19:14:09 | 000,050,344 | ---- | M] (AVAST Software) -- C:\\Program Files\\AVAST Software\\Avast\\AvastSvc.exe

PRC - [2013/09/27 21:41:39 | 001,734,680 | ---- | M] (AVG Secure Search) -- C:\\Program Files\\Common Files\\AVG Secure Search\\vToolbarUpdater\\17.0.1\\ToolbarUpdater.exe

PRC - [2013/02/05 12:10:48 | 000,581,624 | ---- | M] (NTI Corporation) -- C:\\Program Files\\NTI\\NTI Backup Now EZ\\BackupNowEZtray.exe

PRC - [2013/02/05 12:10:46 | 000,046,072 | ---- | M] (NTI Corporation) -- C:\\Program Files\\NTI\\NTI Backup Now EZ\\BackupNowEZSvr.exe

PRC - [2012/11/22 20:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\\Windows\\System32\\taskhost.exe

PRC - [2012/10/02 12:45:22 | 000,120,728 | ---- | M] () -- C:\\Program Files\\Motorola Mobility\\Motorola Device Manager\\MotoHelperService.exe

PRC - [2012/10/02 12:41:02 | 000,694,168 | ---- | M] () -- C:\\Program Files\\Motorola Mobility\\Motorola Device Manager\\MotoHelperAgent.exe

PRC - [2011/10/18 16:32:30 | 000,150,856 | ---- | M] (McAfee, Inc.) -- C:\\Program Files\\Common Files\\mcafee\\systemcore\\mfevtps.exe

PRC - [2011/10/18 16:28:34 | 000,160,608 | ---- | M] (McAfee, Inc.) -- C:\\Program Files\\Common Files\\mcafee\\systemcore\\mfefire.exe

PRC - [2011/09/02 16:06:38 | 000,065,657 | ---- | M] (Motorola) -- C:\\Program Files\\Motorola\\MotForwardDaemon\\ForwardDaemon.exe

PRC - [2011/02/24 23:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\\Windows\\explorer.exe

PRC - [2010/11/12 00:24:10 | 001,602,344 | ---- | M] (ELAN Microelectronics Corp.) -- C:\\Program Files\\Elantech\\ETDCtrlHelper.exe

PRC - [2010/11/12 00:24:08 | 001,812,264 | ---- | M] (ELAN Microelectronics Corp.) -- C:\\Program Files\\Elantech\\ETDCtrl.exe

PRC - [2010/08/10 03:06:16 | 000,975,952 | ---- | M] (Dritek System Inc.) -- C:\\Program Files\\Launch Manager\\LManager.exe

PRC - [2010/08/10 03:06:16 | 000,321,104 | ---- | M] (Dritek System Inc.) -- C:\\Program Files\\Launch Manager\\dsiwmis.exe

PRC - [2010/08/10 03:06:16 | 000,305,744 | ---- | M] (Dritek System Inc.) -- C:\\Program Files\\Launch Manager\\LMworker.exe

PRC - [2010/06/11 16:28:06 | 000,715,296 | ---- | M] (Acer Incorporated) -- C:\\Program Files\\Acer\\Acer ePower Management\\ePowerTray.exe

PRC - [2010/06/11 16:28:02 | 000,735,776 | ---- | M] (Acer Incorporated) -- C:\\Program Files\\Acer\\Acer ePower Management\\ePowerSvc.exe

PRC - [2010/06/11 16:27:54 | 000,469,536 | ---- | M] (Acer Incorporated) -- C:\\Program Files\\Acer\\Acer ePower Management\\ePowerEvent.exe

PRC - [2010/03/11 00:11:56 | 000,407,920 | ---- | M] (Egis Technology Inc.) -- C:\\Program Files\\EgisTec IPS\\PmmUpdate.exe

PRC - [2010/03/11 00:11:42 | 000,201,584 | ---- | M] (Egis Technology Inc.) -- C:\\Program Files\\EgisTec IPS\\EgisUpdate.exe

PRC - [2010/01/29 18:52:58 | 000,260,640 | ---- | M] (Acer Incorporated) -- C:\\Program Files\\Acer\\Acer VCM\\RS_Service.exe

PRC - [2010/01/28 18:27:36 | 000,243,232 | ---- | M] (Acer Group) -- C:\\Program Files\\Acer\\Acer Updater\\UpdaterService.exe

PRC - [2010/01/08 07:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) -- C:\\Program Files\\Acer\\Registration\\GREGsvc.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2013/12/20 19:14:12 | 019,336,120 | ---- | M] () -- C:\\Program Files\\AVAST Software\\Avast\\libcef.dll

MOD - [2013/02/05 12:11:18 | 000,465,824 | ---- | M] () -- C:\\Program Files\\NTI\\NTI Backup Now EZ\\sqlite3.dll

MOD - [2012/10/02 12:41:02 | 000,694,168 | ---- | M] () -- C:\\Program Files\\Motorola Mobility\\Motorola Device Manager\\MotoHelperAgent.exe

MOD - [2012/08/27 23:33:32 | 000,087,912 | ---- | M] () -- C:\\Program Files\\Common Files\\Apple\\Apple Application Support\\zlib1.dll

MOD - [2012/08/27 23:33:08 | 001,242,512 | ---- | M] () -- C:\\Program Files\\Common Files\\Apple\\Apple Application Support\\libxml2.dll

MOD - [2009/05/20 00:02:04 | 000,072,200 | ---- | M] () -- C:\\Program Files\\Launch Manager\\CdDirIo.dll

 

 

========== Services (SafeList) ==========

 

SRV - [2013/12/20 19:14:09 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\\Program Files\\AVAST Software\\Avast\\AvastSvc.exe -- (avast! Antivirus)

SRV - [2013/12/13 19:20:00 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\\Windows\\System32\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2013/09/27 21:41:39 | 001,734,680 | ---- | M] (AVG Secure Search) [Auto | Running] -- C:\\Program Files\\Common Files\\AVG Secure Search\\vToolbarUpdater\\17.0.1\\ToolbarUpdater.exe -- (vToolbarUpdater17.0.1)

SRV - [2013/05/26 22:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)

SRV - [2013/02/05 12:10:46 | 000,046,072 | ---- | M] (NTI Corporation) [Auto | Running] -- C:\\Program Files\\NTI\\NTI Backup Now EZ\\BackupNowEZSvr.exe -- (NTI BackupNowEZSvr)

SRV - [2012/10/02 12:45:22 | 000,120,728 | ---- | M] () [Auto | Running] -- C:\\Program Files\\Motorola Mobility\\Motorola Device Manager\\MotoHelperService.exe -- (Motorola Device Manager)

SRV - [2011/10/18 16:32:30 | 000,150,856 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\\Program Files\\Common Files\\mcafee\\systemcore\\mfevtps.exe -- (mfevtp)

SRV - [2011/10/18 16:28:34 | 000,160,608 | ---- | M] () [Auto | Running] -- C:\\Program Files\\Common Files\\McAfee\\SystemCore\\\\mfefire.exe -- (mfefire)

SRV - [2011/10/18 16:28:18 | 000,166,288 | ---- | M] () [Auto | Stopped] -- C:\\Program Files\\Common Files\\McAfee\\SystemCore\\\\mcshield.exe -- (McShield)

SRV - [2011/09/02 16:06:38 | 000,065,657 | ---- | M] (Motorola) [Auto | Running] -- C:\\Program Files\\Motorola\\MotForwardDaemon\\ForwardDaemon.exe -- (PST Service)

SRV - [2010/10/12 11:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\\Program Files\\WildTangent Games\\App\\GamesAppService.exe -- (GamesAppService)

SRV - [2010/08/10 03:06:16 | 000,321,104 | ---- | M] (Dritek System Inc.) [Auto | Running] -- C:\\Program Files\\Launch Manager\\dsiwmis.exe -- (DsiWMIService)

SRV - [2010/06/11 16:28:02 | 000,735,776 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\\Program Files\\Acer\\Acer ePower Management\\ePowerSvc.exe -- (ePowerSvc)

SRV - [2010/05/26 21:41:06 | 000,305,520 | ---- | M] (Egis Technology Inc.) [On_Demand | Stopped] -- C:\\Program Files\\EgisTec MyWinLocker\\x86\\MWLService.exe -- (MWLService)

SRV - [2010/01/29 18:52:58 | 000,260,640 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\\Program Files\\Acer\\Acer VCM\\RS_Service.exe -- (RS_Service)

SRV - [2010/01/28 18:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto | Running] -- C:\\Program Files\\Acer\\Acer Updater\\UpdaterService.exe -- (Updater Service)

SRV - [2010/01/08 07:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\\Program Files\\Acer\\Registration\\GREGsvc.exe -- (GREGService)

 

 

========== Driver Services (SafeList) ==========

 

DRV - File not found [Kernel | System | Stopped] -- C:\\Windows\\system32\\drivers\\SBREdrv.sys -- (SBRE)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\\DRIVERS\\motusbdevice.sys -- (motusbdevice)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\\DRIVERS\\Motousbnet.sys -- (Motousbnet)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\\DRIVERS\\motswch.sys -- (MotoSwitchService)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\\DRIVERS\\motccgpfl.sys -- (motccgpfl)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\\DRIVERS\\motccgp.sys -- (motccgp)

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\\DRIVERS\\motfilt.sys -- (BTCFilterService)

DRV - [2013/12/20 19:14:56 | 000,064,168 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- C:\\Windows\\System32\\drivers\\aswstm.sys -- (aswStm)

DRV - [2013/12/20 19:14:16 | 000,775,952 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\\Windows\\System32\\drivers\\aswSnx.sys -- (aswSnx)

DRV - [2013/12/20 19:14:16 | 000,410,528 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\\Windows\\System32\\drivers\\aswSP.sys -- (aswSP)

DRV - [2013/12/20 19:14:16 | 000,180,248 | ---- | M] () [Kernel | Boot | Running] -- C:\\Windows\\System32\\drivers\\aswVmm.sys -- (aswVmm)

DRV - [2013/12/20 19:14:16 | 000,079,720 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\\Windows\\System32\\drivers\\aswRdr2.sys -- (aswRdr)

DRV - [2013/12/20 19:14:16 | 000,067,824 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\\Windows\\System32\\drivers\\aswMonFlt.sys -- (aswMonFlt)

DRV - [2013/12/20 19:14:16 | 000,049,944 | ---- | M] () [Kernel | Boot | Running] -- C:\\Windows\\System32\\drivers\\aswRvrt.sys -- (aswRvrt)

DRV - [2012/08/23 08:44:32 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\rdpvideominiport.sys -- (RdpVideoMiniport)

DRV - [2012/08/23 08:40:25 | 000,049,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\TsUsbFlt.sys -- (TsUsbFlt)

DRV - [2012/03/26 16:50:12 | 000,018,432 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\netaapl.sys -- (Netaapl)

DRV - [2011/10/15 15:16:16 | 000,464,176 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\\Windows\\System32\\drivers\\mfehidk.sys -- (mfehidk)

DRV - [2011/10/15 15:16:16 | 000,338,176 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\System32\\drivers\\mfefirek.sys -- (mfefirek)

DRV - [2011/10/15 15:16:16 | 000,180,816 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\System32\\drivers\\mfeavfk.sys -- (mfeavfk)

DRV - [2011/10/15 15:16:16 | 000,165,680 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\\Windows\\System32\\drivers\\mfewfpk.sys -- (mfewfpk)

DRV - [2011/10/15 15:16:16 | 000,121,256 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\mfeapfk.sys -- (mfeapfk)

DRV - [2011/10/15 15:16:16 | 000,087,656 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\mferkdet.sys -- (mferkdet)

DRV - [2011/10/15 15:16:16 | 000,064,880 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\\Windows\\System32\\drivers\\mfenlfk.sys -- (mfenlfk)

DRV - [2011/10/15 15:16:16 | 000,059,456 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\mfebopk.sys -- (mfebopk)

DRV - [2011/10/15 15:16:16 | 000,057,600 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\cfwids.sys -- (cfwids)

DRV - [2010/12/03 00:30:44 | 000,025,600 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\nx6000.sys -- (MSHUSBVideo)

DRV - [2010/11/20 03:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\winusb.sys -- (WinUsb)

DRV - [2010/08/24 03:55:52 | 000,068,208 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\L1C62x86.sys -- (L1C)

DRV - [2010/07/15 15:57:36 | 001,906,024 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\System32\\drivers\\athr.sys -- (athr)

DRV - [2010/06/17 00:50:38 | 000,082,768 | ---- | M] (ENE Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\EUCR6SK.sys -- (EUCR)

DRV - [2009/07/13 17:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\System32\\drivers\\vwifimp.sys -- (vwifimp)

DRV - [2009/06/02 21:15:40 | 000,060,976 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\\Windows\\System32\\drivers\\mwlPSDVDisk.sys -- (mwlPSDVDisk)

DRV - [2009/06/02 21:15:38 | 000,016,432 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\\Windows\\System32\\drivers\\mwlPSDNserv.sys -- (mwlPSDNServ)

DRV - [2009/06/02 21:15:34 | 000,018,992 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\\Windows\\System32\\drivers\\mwlPSDFilter.sys -- (mwlPSDFilter)

DRV - [2008/05/06 17:06:00 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\\Windows\\System32\\drivers\\wdcsam.sys -- (WDC_SAM)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLM\\..\\SearchScopes,Backup.Old.DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKLM\\..\\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKLM\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://start.funmoods.com/results.php?f=4&q=\'>http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1Qzuzzzzzy0F0F0AtDyDtByB0FyBtA0ByE0EtN0D0Tzu0CtByEyDtN1L2XzutBtFtCtFtCtFtAtCtB&cr=672521081

IE - HKLM\\..\\SearchScopes\\{507E350E-949D-BB7D-314C-7539CF247C38}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox



IE - HKLM\\..\\SearchScopes\\{EEE6C360-6118-11DC-9C72-001320C79847}: \"URL\" = http://search.sweetim.com/search.asp?src=6&q=\'>http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10005

 

 

IE - HKU\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

 

IE - HKU\\S-1-5-18\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

 

 

 

IE - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Backup.Old.Start Page = http://acer.msn.com\'>http://acer.msn.com

IE - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Default_Page_URL = http://search.findwide.com/?guid=\'>http://search.findwide.com/?guid={FAD49E06-D413-4B08-8349-8A71DBFA0C8C}&serpv=22

IE - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Search Bar = www.bing.com

IE - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Search Page = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR

IE - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = http://www.buenosearch.com/?babsrc=HP_def&mntrId=AC9F929FFA0527F7&affID=115076&tsp=5114\'>http://www.buenosearch.com/?babsrc=HP_def&mntrId=AC9F929FFA0527F7&affID=115076&tsp=5114



IE - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000\\..\\URLSearchHook: {96f454ea-9d38-474f-b504-56193e00c1a5} - SOFTWARE\\Classes\\CLSID\\{96f454ea-9d38-474f-b504-56193e00c1a5}\\InprocServer32 File not found

IE - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000\\..\\SearchScopes,Backup.Old.DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000\\..\\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}


IE - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000\\..\\SearchScopes\\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: \"URL\" = http://start.funmoods.com/results.php?f=4&q=\'>http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1Qzuzzzzzy0F0F0AtDyDtByB0FyBtA0ByE0EtN0D0Tzu0CtByEyDtN1L2XzutBtFtCtFtCtFtAtCtB&cr=672521081

IE - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000\\..\\SearchScopes\\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: \"URL\" = http://www.buenosearch.com/?q=\'>http://www.buenosearch.com/?q={searchTerms}&babsrc=SP_def&mntrId=AC9F929FFA0527F7&affID=115076&tsp=5114

IE - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000\\..\\SearchScopes\\{18E7AACF-9B3E-46E8-8382-BAB463727B5E}: \"URL\" = http://search.yahoo.com/search?p=\'>http://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=10743

IE - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000\\..\\SearchScopes\\{2ED3B46A-A91C-47C9-92D7-3EF05BB5429B}: \"URL\" = http://www.mysearchresults.com/search?c=2652&t=01&q=\'>http://www.mysearchresults.com/search?c=2652&t=01&q={searchTerms}

IE - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000\\..\\SearchScopes\\{50349BBE-F1B2-4659-B85A-16401AF9064C}: \"URL\" = http://search.findwide.com/serp?guid=\'>http://search.findwide.com/serp?guid={FAD49E06-D413-4B08-8349-8A71DBFA0C8C}&action=default_search&serpv=22&k={searchTerms}

IE - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000\\..\\SearchScopes\\{6F47C78D-F91C-4A9E-9641-012D759138CA}: \"URL\" = http://search.conduit.com/ResultsExt.aspx?q=\'>http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3289075&CUI=UN29404707102509210&UM=2

IE - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000\\..\\SearchScopes\\{95B7759C-8C7F-4BF1-B163-73684A933233}: \"URL\" = http://isearch.avg.com/search?cid=\'>http://isearch.avg.com/search?cid={93571EB7-16F3-4270-AB3A-4EAC59A4339E}&mid=d70f5103086f47d0a7d443d6bce1ce04-b15497609ebbdddff297f5f09ac63dcb18fcd1a3&lang=en&ds=ft011&pr=sa&d=2012-10-14 16:15:50&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms}




IE - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000\\..\\SearchScopes\\{EEE6C360-6118-11DC-9C72-001320C79847}: \"URL\" = http://search.sweetim.com/search.asp?src=6&q=\'>http://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010000.10005

IE - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

IE - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = 192.168.*.*

 

 

========== FireFox ==========

 

FF - HKLM\\Software\\MozillaPlugins\\@Apple.com/iTunes,version=:  File not found

FF - HKLM\\Software\\MozillaPlugins\\@Apple.com/iTunes,version=1.0: C:\\Program Files\\iTunes\\Mozilla Plugins\\npitunes.dll ()

FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.51.2: C:\\Program Files\\Java\\jre7\\bin\\dtplugin\\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.51.2: C:\\Program Files\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@Microsoft.com/NpCtrl,version=1.0: c:\\Program Files\\Microsoft Silverlight\\5.1.20913.0\\npctrl.dll ( Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/WLPG,version=15.4.3502.0922: C:\\Program Files\\Windows Live\\Photo Gallery\\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/WLPG,version=15.4.3508.1109: C:\\Program Files\\Windows Live\\Photo Gallery\\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@videolan.org/vlc,version=2.0.0: C:\\Program Files\\VideoLAN\\VLC\\npvlc.dll (VideoLAN)

FF - HKLM\\Software\\MozillaPlugins\\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\\Program Files\\WildTangent Games\\App\\BrowserIntegration\\Registered\\4\\NP_wtapp.dll ()

FF - HKCU\\Software\\MozillaPlugins\\@Skype Limited.com/Facebook Video Calling Plugin: C:\\Users\\Kaila\\AppData\\Local\\Facebook\\Video\\Skype\\npFacebookVideoCalling.dll (Skype Limited)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\Kaila\\AppData\\Local\\Google\\Update\\1.3.22.3\\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\Kaila\\AppData\\Local\\Google\\Update\\1.3.22.3\\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\\Program Files\\Common Files\\McAfee\\SystemCore [2012/09/02 00:16:21 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\{3C5F0F00-683D-4847-89C8-E7AF64FD1CFB}: C:\\Program Files\\PremierOpinion

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files\\Babylon\\Babylon-Pro\\Utils\\[email protected]

 

[2013/12/13 16:03:38 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Kaila\\AppData\\Roaming\\mozilla\\Firefox\\extensions

[2013/12/05 15:07:08 | 000,000,000 | ---D | M] (uTorrentControl_v6) -- C:\\Users\\Kaila\\AppData\\Roaming\\mozilla\\Firefox\\extensions\\{96f454ea-9d38-474f-b504-56193e00c1a5}

[2013/12/31 22:07:34 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files\\Mozilla Firefox\\extensions

 

========== Chrome  ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},


CHR - plugin: Shockwave Flash (Enabled) = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\Application\\31.0.1650.63\\PepperFlash\\pepflashplayer.dll

CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\Application\\31.0.1650.63\\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Disabled) = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\Application\\31.0.1650.63\\pdf.dll

CHR - plugin: npDefaultTabSearch plugin (Enabled) = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\kdidombaedgpfiiedeimiebkmbilgmlc\\1.1.14_0\\plugins/npDefaultTabSearch.dll

CHR - plugin: Adobe Acrobat (Enabled) = C:\\Program Files\\Adobe\\Reader 9.0\\Reader\\Browser\\nppdf32.dll

CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\\Program Files\\Java\\jre6\\bin\\new_plugin\\npdeployJava1.dll

CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\\Program Files\\Java\\jre6\\bin\\new_plugin\\npjp2.dll

CHR - plugin: AVG SiteSafety plugin (Enabled) = C:\\Program Files\\Common Files\\AVG Secure Search\\SiteSafetyInstaller\\13.2.0\\\\npsitesafety.dll

CHR - plugin: VLC Web Plugin (Enabled) = C:\\Program Files\\VideoLAN\\VLC\\npvlc.dll

CHR - plugin: WildTangent Games App V2 Presence Detector (Enabled) = C:\\Program Files\\WildTangent Games\\App\\BrowserIntegration\\Registered\\2\\NP_wtapp.dll

CHR - plugin: Windows Live Photo Gallery (Enabled) = C:\\Program Files\\Windows Live\\Photo Gallery\\NPWLPG.dll

CHR - plugin: iTunes Application Detector (Enabled) = C:\\Program Files\\iTunes\\Mozilla Plugins\\npitunes.dll

CHR - plugin: Google Update (Enabled) = C:\\Users\\Kaila\\AppData\\Local\\Google\\Update\\1.3.21.135\\npGoogleUpdate3.dll

CHR - plugin: Silverlight Plug-In (Enabled) = c:\\Program Files\\Microsoft Silverlight\\5.1.20125.0\\npctrl.dll

CHR - Extension: uTorrentControl_v6 = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\cflheckfmhopnialghigdlggahiomebp\\10.26.0.540_0\\

CHR - Extension: uTorrentControl_v6 = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\cflheckfmhopnialghigdlggahiomebp\\10.26.0.540_0\\nativeMessaging\\nmHost

CHR - Extension: Dark Vibe = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dkckeanhmkjaechlhllmapjaaglgpcbj\\1.1_0\\

CHR - Extension: ShopAtHome.com extension = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlmebkoiahbppacaicbgncnjhbpdfkcc\\7.1.0.16_0\\

CHR - Extension: avast! Online Security = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\gomekmidlodglbbmalcneegieacbdmki\\9.0.2011.70_0\\

CHR - Extension: avast! Online Security = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\gomekmidlodglbbmalcneegieacbdmki\\9.0.2013.75_0\\

CHR - Extension: No name found = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\njkkjobcechefaoknodniidfjapgfoco\\2.2.7_0\\

CHR - Extension: Google Wallet = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda\\0.0.6.0_0\\

CHR - Extension: Bitdefender QuickScan = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pdnkcidphdcakpkheohlhocaicfamjie\\0.9.9.131_0\\

CHR - Extension: uTorrentControl_v6 = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\cflheckfmhopnialghigdlggahiomebp\\10.26.0.540_0\\

CHR - Extension: uTorrentControl_v6 = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\cflheckfmhopnialghigdlggahiomebp\\10.26.0.540_0\\nativeMessaging\\nmHost

CHR - Extension: Dark Vibe = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dkckeanhmkjaechlhllmapjaaglgpcbj\\1.1_0\\

CHR - Extension: ShopAtHome.com extension = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dlmebkoiahbppacaicbgncnjhbpdfkcc\\7.1.0.16_0\\

CHR - Extension: avast! Online Security = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\gomekmidlodglbbmalcneegieacbdmki\\9.0.2011.70_0\\

CHR - Extension: avast! Online Security = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\gomekmidlodglbbmalcneegieacbdmki\\9.0.2013.75_0\\

CHR - Extension: No name found = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\njkkjobcechefaoknodniidfjapgfoco\\2.2.7_0\\

CHR - Extension: Google Wallet = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda\\0.0.6.0_0\\

CHR - Extension: Bitdefender QuickScan = C:\\Users\\Kaila\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pdnkcidphdcakpkheohlhocaicfamjie\\0.9.9.131_0\\

 

O1 HOSTS File: ([2009/06/10 15:39:37 | 000,000,824 | ---- | M]) - C:\\Windows\\System32\\drivers\\etc\\hosts

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.

O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\\PROGRA~1\\mcafee\\msk\\mskapbho.dll File not found

O2 - BHO: (Music Box Toolbar (Dist. by iMesh, Inc.)) - {45177936-603b-4261-8d42-df6f7091d5d0} - C:\\PROGRA~1\\MUSICT~1\\Datamngr\\SRTOOL~1\\IE\\searchresultsDx.dll File not found

O2 - BHO: (MyWordTool) - {45470599-8237-486D-87B5-E89CD6AED154} - C:\\Users\\Kaila\\AppData\\Roaming\\MyWordTool\\temp.dat ()

O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)

O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\\Program Files\\Common Files\\mcafee\\systemcore\\ScriptSn.20120112163500.dll (McAfee, Inc.)

O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\\Program Files\\AVAST Software\\Avast\\aswWebRepIE.dll (AVAST Software)

O2 - BHO: (uTorrentControl_v6 Toolbar) - {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\\Program Files\\uTorrentControl_v6\\prxtbuTor.dll File not found

O2 - BHO: (no name) - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - No CLSID value found.

O2 - BHO: (Tidy Network) - {D8A98206-1249-3EBA-FB18-4ADF7ED746FD} - C:\\Program Files\\TidyNetwork\\petn.dll ()

O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)

O3 - HKLM\\..\\Toolbar: (Music Box Toolbar (Dist. by iMesh, Inc.)) - {45177936-603b-4261-8d42-df6f7091d5d0} - C:\\PROGRA~1\\MUSICT~1\\Datamngr\\SRTOOL~1\\IE\\searchresultsDx.dll File not found

O3 - HKLM\\..\\Toolbar: (uTorrentControl_v6 Toolbar) - {96f454ea-9d38-474f-b504-56193e00c1a5} - C:\\Program Files\\uTorrentControl_v6\\prxtbuTor.dll File not found

O3 - HKLM\\..\\Toolbar: (avast! Online Security) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\\Program Files\\AVAST Software\\Avast\\aswWebRepIE.dll (AVAST Software)

O3 - HKLM\\..\\Toolbar: (no name) - 10 - No CLSID value found.

O3 - HKLM\\..\\Toolbar: (no name) - Locked - No CLSID value found.

O3 - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000\\..\\Toolbar\\WebBrowser: (uTorrentControl_v6 Toolbar) - {96F454EA-9D38-474F-B504-56193E00C1A5} - C:\\Program Files\\uTorrentControl_v6\\prxtbuTor.dll File not found

O4 - HKLM..\\Run: [Acer ePower Management] C:\\Program Files\\Acer\\Acer ePower Management\\ePowerTray.exe (Acer Incorporated)

O4 - HKLM..\\Run: [APSDaemon] C:\\Program Files\\Common Files\\Apple\\Apple Application Support\\APSDaemon.exe (Apple Inc.)

O4 - HKLM..\\Run: [AvastUI.exe] C:\\Program Files\\AVAST Software\\Avast\\AvastUI.exe (AVAST Software)

O4 - HKLM..\\Run: [BackupNowEZtray] C:\\Program Files\\NTI\\NTI Backup Now EZ\\BackupNowEZtray.exe (NTI Corporation)

O4 - HKLM..\\Run: [EgisTecPMMUpdate] C:\\Program Files\\EgisTec IPS\\PmmUpdate.exe (Egis Technology Inc.)

O4 - HKLM..\\Run: [EgisUpdate] C:\\Program Files\\EgisTec IPS\\EgisUpdate.exe (Egis Technology Inc.)

O4 - HKLM..\\Run: [ETDCtrl] C:\\Program Files\\Elantech\\ETDCtrl.exe (ELAN Microelectronics Corp.)

O4 - HKLM..\\Run: [LManager] C:\\Program Files\\Launch Manager\\LManager.exe (Dritek System Inc.)

O4 - HKLM..\\Run: [ROC_roc_ssl_v12] \"C:\\Program Files\\AVG Secure Search\\ROC_roc_ssl_v12.exe\" / /PROMPT /CMPID=roc_ssl_v12 File not found

O4 - HKLM..\\Run: [SBRegRebootCleaner] \"C:\\Program Files\\Ad-Aware Antivirus\\SBRC.exe\" File not found

O4 - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000..\\Run: [Facebook Update] C:\\Users\\Kaila\\AppData\\Local\\Facebook\\Update\\FacebookUpdate.exe (Facebook Inc.)

O4 - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000..\\Run: [uTorrent] C:\\Users\\Kaila\\AppData\\Roaming\\uTorrent\\uTorrent.exe (BitTorrent Inc.)

O4 - HKU\\S-1-5-19..\\RunOnce: [mctadmin] C:\\Windows\\System32\\mctadmin.exe (Microsoft Corporation)

O4 - HKU\\S-1-5-20..\\RunOnce: [mctadmin] C:\\Windows\\System32\\mctadmin.exe (Microsoft Corporation)

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorAdmin = 5

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3

O7 - HKU\\S-1-5-21-2509488165-3742344647-2209741551-1000\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 145

O9 - Extra Button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\\Program Files\\Paltalk Messenger\\paltalk.exe (AVM Software Inc.)

O13 - gopher Prefix: missing




O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters: DhcpNameServer = 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{15EAC838-19E9-4FA3-B6AC-CE7E9B30E965}: DhcpNameServer = 172.26.38.1 172.26.38.2

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{A81087B2-589B-456F-8D51-F5A5BADAE6F1}: DhcpNameServer = 192.168.1.1

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{B74E8B87-E008-4422-BD86-86D613D27F22}: DhcpNameServer = 192.168.1.1

O18 - Protocol\\Handler\\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\\Program Files\\Windows Live\\Messenger\\msgrapp.dll File not found

O18 - Protocol\\Handler\\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\\Program Files\\Windows Live\\Messenger\\msgrapp.dll File not found

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\System32\\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\\Windows\\System32\\SystemPropertiesPerformance.exe (Microsoft Corporation)

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O27 - HKLM IFEO\\bitguard.exe: Debugger - C:\\Windows\\System32\\tasklist.exe (Microsoft Corporation)

O27 - HKLM IFEO\\bprotect.exe: Debugger - C:\\Windows\\System32\\tasklist.exe (Microsoft Corporation)

O27 - HKLM IFEO\\browserdefender.exe: Debugger - C:\\Windows\\System32\\tasklist.exe (Microsoft Corporation)

O27 - HKLM IFEO\\browserprotect.exe: Debugger - C:\\Windows\\System32\\tasklist.exe (Microsoft Corporation)

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2009/06/10 15:42:20 | 000,000,024 | ---- | M] () - C:\\autoexec.bat -- [ NTFS ]

O33 - MountPoints2\\{c001a154-d848-11e0-b3a4-1c7508b345b6}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{c001a154-d848-11e0-b3a4-1c7508b345b6}\\Shell\\AutoRun\\command - \"\" = \"D:\\WD SmartWare.exe\" autoplay=true

O33 - MountPoints2\\{fed23421-ccaf-11e2-a2ff-889ffa0527f7}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{fed23421-ccaf-11e2-a2ff-889ffa0527f7}\\Shell\\AutoRun\\command - \"\" = D:\\MotoCastSetup.exe -a

O34 - HKLM BootExecute: (autocheck autochk *)

O35 - HKLM\\..comfile [open] -- \"%1\" %*

O35 - HKLM\\..exefile [open] -- \"%1\" %*

O36 - AppCertDlls: x64 - (c:\\program files\\music toolbar\\datamngr\\x64\\apcrtldr.dll) -  File not found

O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\\\Windows: (ServerDll=sxssrv,4)

 

========== Files/Folders - Created Within 30 Days ==========

 

[2014/01/17 20:38:20 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Kaila\\Desktop\\OTL.exe

[2014/01/17 20:28:12 | 000,000,000 | ---D | C] -- C:\\Users\\Kaila\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Chrome Apps

[2014/01/17 19:48:32 | 000,264,616 | ---- | C] (Oracle Corporation) -- C:\\Windows\\System32\\javaws.exe

[2014/01/17 19:48:04 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\\Windows\\System32\\javaw.exe

[2014/01/17 19:48:04 | 000,174,504 | ---- | C] (Oracle Corporation) -- C:\\Windows\\System32\\java.exe

[2014/01/17 19:48:04 | 000,094,632 | ---- | C] (Oracle Corporation) -- C:\\Windows\\System32\\WindowsAccessBridge.dll

[2014/01/17 19:48:04 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Java

[2014/01/14 21:45:27 | 002,349,056 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\System32\\win32k.sys

[2014/01/14 21:45:24 | 000,240,576 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\System32\\drivers\\netio.sys

[2014/01/14 21:45:21 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\System32\\drivers\\usbport.sys

[2014/01/14 21:45:18 | 000,006,016 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\System32\\drivers\\usbd.sys

[2014/01/12 19:52:53 | 000,000,000 | ---D | C] -- C:\\Users\\Kaila\\Desktop\\Movies

[2014/01/08 16:28:48 | 000,000,000 | ---D | C] -- C:\\Users\\Kaila\\Desktop\\Insanity Workout

[2013/12/31 22:07:57 | 000,000,000 | ---D | C] -- C:\\Users\\Kaila\\AppData\\Roaming\\BabSolution

[2013/12/31 22:07:34 | 000,000,000 | ---D | C] -- C:\\Program Files\\Mozilla Firefox

[2013/12/31 22:07:31 | 000,000,000 | ---D | C] -- C:\\Program Files\\Babylon

[2013/12/23 22:30:56 | 000,000,000 | ---D | C] -- C:\\Program Files\\ToniArts

[2013/12/23 22:30:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\EasyCleaner

[2013/12/23 22:12:21 | 000,000,000 | ---D | C] -- C:\\Users\\Kaila\\AppData\\Roaming\\ParetoLogic

[2013/12/23 22:12:21 | 000,000,000 | ---D | C] -- C:\\Users\\Kaila\\AppData\\Roaming\\DriverCure

[2013/12/23 22:11:51 | 000,000,000 | ---D | C] -- C:\\ProgramData\\ParetoLogic

[2013/12/23 21:59:23 | 000,000,000 | ---D | C] -- C:\\AdwCleaner

[2013/12/20 19:15:36 | 000,000,000 | ---D | C] -- C:\\Users\\Kaila\\AppData\\Roaming\\AVAST Software

[2013/12/20 19:15:16 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Avast

[2013/12/20 19:14:29 | 000,775,952 | ---- | C] (AVAST Software) -- C:\\Windows\\System32\\drivers\\aswSnx.sys

[2013/12/20 19:14:29 | 000,064,168 | ---- | C] (AVAST Software) -- C:\\Windows\\System32\\drivers\\aswstm.sys

[2013/12/20 19:14:28 | 000,410,528 | ---- | C] (AVAST Software) -- C:\\Windows\\System32\\drivers\\aswSP.sys

[2013/12/20 19:14:27 | 000,067,824 | ---- | C] (AVAST Software) -- C:\\Windows\\System32\\drivers\\aswMonFlt.sys

[2013/12/20 19:14:26 | 000,079,720 | ---- | C] (AVAST Software) -- C:\\Windows\\System32\\drivers\\aswRdr2.sys

[2013/12/20 19:14:22 | 000,270,240 | ---- | C] (AVAST Software) -- C:\\Windows\\System32\\aswBoot.exe

[2013/12/20 19:14:14 | 000,043,152 | ---- | C] (AVAST Software) -- C:\\Windows\\avastSS.scr

[2013/12/20 19:12:59 | 000,000,000 | ---D | C] -- C:\\Program Files\\AVAST Software

[2013/12/20 19:09:37 | 000,000,000 | ---D | C] -- C:\\ProgramData\\AVAST Software

[2013/12/20 18:56:08 | 000,000,000 | ---D | C] -- C:\\ProgramData\\GFI Software

[2013/12/20 18:39:55 | 000,000,000 | ---D | C] -- C:\\Users\\Kaila\\AppData\\Roaming\\QuickScan

[2013/12/20 18:27:37 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Licenses

[2013/12/20 18:27:13 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\SpywareBlaster

[2013/12/20 18:27:12 | 001,070,352 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\System32\\MSCOMCTL.OCX

[2013/12/20 18:27:11 | 000,129,872 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\System32\\MSSTDFMT.DLL

[2013/12/20 18:27:04 | 000,000,000 | ---D | C] -- C:\\Program Files\\SpywareBlaster

[2013/12/20 17:11:09 | 000,000,000 | ---D | C] -- C:\\Users\\Kaila\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\HiJackThis

[2013/12/20 17:11:08 | 000,000,000 | ---D | C] -- C:\\Program Files\\Trend Micro

 

========== Files - Modified Within 30 Days ==========

 

[2014/01/17 20:38:56 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Kaila\\Desktop\\OTL.exe

[2014/01/17 20:28:20 | 000,000,830 | ---- | M] () -- C:\\Windows\\tasks\\Adobe Flash Player Updater.job

[2014/01/17 20:27:10 | 000,002,326 | ---- | M] () -- C:\\Users\\Kaila\\Desktop\\Chrome App Launcher.lnk

[2014/01/17 20:09:01 | 000,000,908 | ---- | M] () -- C:\\Windows\\tasks\\GoogleUpdateTaskUserS-1-5-21-2509488165-3742344647-2209741551-1000UA.job

[2014/01/17 20:03:05 | 000,000,928 | ---- | M] () -- C:\\Windows\\tasks\\FacebookUpdateTaskUserS-1-5-21-2509488165-3742344647-2209741551-1000UA.job

[2014/01/17 16:14:20 | 000,009,696 | -H-- | M] () -- C:\\Windows\\System32\\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

[2014/01/17 16:14:20 | 000,009,696 | -H-- | M] () -- C:\\Windows\\System32\\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

[2014/01/17 16:04:48 | 000,000,350 | ---- | M] () -- C:\\Windows\\tasks\\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job

[2014/01/17 16:02:03 | 000,259,112 | ---- | M] () -- C:\\Windows\\System32\\FNTCACHE.DAT

[2014/01/17 16:01:59 | 000,067,584 | --S- | M] () -- C:\\Windows\\bootstat.dat

[2014/01/17 16:00:13 | 796,729,344 | -HS- | M] () -- C:\\hiberfil.sys

[2014/01/17 15:48:39 | 000,000,856 | ---- | M] () -- C:\\Windows\\tasks\\GoogleUpdateTaskUserS-1-5-21-2509488165-3742344647-2209741551-1000Core.job

[2014/01/17 15:32:16 | 000,000,906 | ---- | M] () -- C:\\Windows\\tasks\\FacebookUpdateTaskUserS-1-5-21-2509488165-3742344647-2209741551-1000Core.job

[2013/12/20 19:15:16 | 000,002,087 | ---- | M] () -- C:\\Users\\Public\\Desktop\\avast! Free Antivirus.lnk

[2013/12/20 19:14:56 | 000,064,168 | ---- | M] (AVAST Software) -- C:\\Windows\\System32\\drivers\\aswstm.sys

[2013/12/20 19:14:16 | 000,775,952 | ---- | M] (AVAST Software) -- C:\\Windows\\System32\\drivers\\aswSnx.sys

[2013/12/20 19:14:16 | 000,410,528 | ---- | M] (AVAST Software) -- C:\\Windows\\System32\\drivers\\aswSP.sys

[2013/12/20 19:14:16 | 000,180,248 | ---- | M] () -- C:\\Windows\\System32\\drivers\\aswVmm.sys

[2013/12/20 19:14:16 | 000,079,720 | ---- | M] (AVAST Software) -- C:\\Windows\\System32\\drivers\\aswRdr2.sys

[2013/12/20 19:14:16 | 000,067,824 | ---- | M] (AVAST Software) -- C:\\Windows\\System32\\drivers\\aswMonFlt.sys

[2013/12/20 19:14:16 | 000,049,944 | ---- | M] () -- C:\\Windows\\System32\\drivers\\aswRvrt.sys

[2013/12/20 19:14:14 | 000,270,240 | ---- | M] (AVAST Software) -- C:\\Windows\\System32\\aswBoot.exe

[2013/12/20 19:14:14 | 000,043,152 | ---- | M] (AVAST Software) -- C:\\Windows\\avastSS.scr

[2013/12/20 18:27:14 | 000,001,005 | ---- | M] () -- C:\\Users\\Public\\Desktop\\SpywareBlaster.lnk

[2013/12/20 17:11:10 | 000,002,963 | ---- | M] () -- C:\\Users\\Kaila\\Desktop\\HiJackThis.lnk

[2013/12/18 21:10:01 | 000,094,632 | ---- | M] (Oracle Corporation) -- C:\\Windows\\System32\\WindowsAccessBridge.dll

[2013/12/18 21:04:13 | 000,264,616 | ---- | M] (Oracle Corporation) -- C:\\Windows\\System32\\javaws.exe

[2013/12/18 21:04:09 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\\Windows\\System32\\javaw.exe

[2013/12/18 21:03:46 | 000,174,504 | ---- | M] (Oracle Corporation) -- C:\\Windows\\System32\\java.exe

 

========== Files Created - No Company Name ==========

 

[2014/01/17 20:27:10 | 000,002,326 | ---- | C] () -- C:\\Users\\Kaila\\Desktop\\Chrome App Launcher.lnk

[2013/12/20 19:15:16 | 000,002,087 | ---- | C] () -- C:\\Users\\Public\\Desktop\\avast! Free Antivirus.lnk

[2013/12/20 19:14:29 | 000,180,248 | ---- | C] () -- C:\\Windows\\System32\\drivers\\aswVmm.sys

[2013/12/20 19:14:28 | 000,049,944 | ---- | C] () -- C:\\Windows\\System32\\drivers\\aswRvrt.sys

[2013/12/20 18:27:14 | 000,001,005 | ---- | C] () -- C:\\Users\\Public\\Desktop\\SpywareBlaster.lnk

[2013/12/20 17:11:10 | 000,002,963 | ---- | C] () -- C:\\Users\\Kaila\\Desktop\\HiJackThis.lnk

[2013/12/11 20:20:46 | 000,000,218 | ---- | C] () -- C:\\Users\\Kaila\\AppData\\Local\\recently-used.xbel

[2013/09/09 10:22:27 | 000,000,258 | RHS- | C] () -- C:\\Users\\Kaila\\ntuser.pol

[2013/01/18 19:54:27 | 000,001,415 | ---- | C] () -- C:\\Windows\\wininit.ini

[2012/09/02 00:38:10 | 000,384,844 | ---- | C] () -- C:\\Users\\Kaila\\AppData\\Local\\funmoods-speeddial.crx

[2012/06/12 18:47:43 | 000,007,598 | ---- | C] () -- C:\\Users\\Kaila\\AppData\\Local\\Resmon.ResmonCfg

 

========== ZeroAccess Check ==========

 

[2009/07/13 22:42:31 | 000,000,227 | RHS- | M] () -- C:\\Windows\\assembly\\Desktop.ini

 

[HKEY_CURRENT_USER\\Software\\Classes\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32]

 

[HKEY_CURRENT_USER\\Software\\Classes\\clsid\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\InProcServer32]

 

[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32]

\"\" = %SystemRoot%\\system32\\shell32.dll -- [2013/07/25 19:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)

\"ThreadingModel\" = Apartment

 

[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\\InProcServer32]

\"\" = %systemroot%\\system32\\wbem\\fastprox.dll -- [2010/11/20 06:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)

\"ThreadingModel\" = Free

 

[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\\InProcServer32]

\"\" = %systemroot%\\system32\\wbem\\wbemess.dll -- [2009/07/13 19:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)

\"ThreadingModel\" = Both

 

========== Alternate Data Streams ==========

 

@Alternate Data Stream - 119 bytes -> C:\\ProgramData\\TEMP:5C321E34

 

< End of report >

 

 

 

 

 


OTL Extras logfile created on: 1/17/2014 8:40:40 PM - Run 1

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Users\\Kaila\\Desktop

 Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 9.10.9200.16750)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

 

1013.09 Mb Total Physical Memory | 531.36 Mb Available Physical Memory | 52.45% Memory free

3.10 Gb Paging File | 1.08 Gb Available in Paging File | 35.01% Paging File free

Paging file location(s): ?:\\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files

Drive C: | 219.79 Gb Total Space | 163.52 Gb Free Space | 74.40% Space Free | Partition Type: NTFS

 

Computer Name: JOHN | User Name: Kaila | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Extra Registry (SafeList) ==========

 

 

========== File Associations ==========

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\<extension>]

.cpl [@ = cplfile] -- C:\\Windows\\System32\\control.exe (Microsoft Corporation)

.hlp [@ = hlpfile] -- C:\\Windows\\winhlp32.exe (Microsoft Corporation)

 

========== Shell Spawning ==========

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\<key>\\shell\\[command]\\command]

batfile [open] -- \"%1\" %*

cmdfile [open] -- \"%1\" %*

comfile [open] -- \"%1\" %*

cplfile [cplopen] -- %SystemRoot%\\System32\\control.exe \"%1\",%* (Microsoft Corporation)

exefile [open] -- \"%1\" %*

helpfile [open] -- Reg Error: Key error.

hlpfile [open] -- %SystemRoot%\\winhlp32.exe %1 (Microsoft Corporation)

htmlfile [edit] -- Reg Error: Key error.

htmlfile [print] -- \"%systemroot%\\system32\\rundll32.exe\" \"%systemroot%\\system32\\mshtml.dll\",PrintHTML \"%1\"

inffile [install] -- %SystemRoot%\\System32\\InfDefaultInstall.exe \"%1\" (Microsoft Corporation)

piffile [open] -- \"%1\" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- \"%1\"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- \"%1\" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\\system32\\rundll32.exe %SystemRoot%\\system32\\shell32.dll,OpenAs_RunDLL %1

Directory [AddToPlaylistVLC] -- \"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe\" --started-from-file --playlist-enqueue \"%1\" ()

Directory [cmd] -- cmd.exe /s /k pushd \"%V\" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\\Explorer.exe (Microsoft Corporation)

Directory [PlayWithVLC] -- \"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe\" --started-from-file --no-playlist-enqueue \"%1\" ()

Folder [open] -- %SystemRoot%\\Explorer.exe (Microsoft Corporation)

Folder [explore] -- Reg Error: Value error.

Drive [find] -- %SystemRoot%\\Explorer.exe (Microsoft Corporation)

 

========== Security Center Settings ==========

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center]

\"cval\" = 1

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\Monitoring]

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\Svc]

\"VistaSp1\" = Reg Error: Unknown registry data type -- File not found

\"AntiVirusOverride\" = 0

\"AntiSpywareOverride\" = 0

\"FirewallOverride\" = 0

 

[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\Svc\\Vol]

 

========== Firewall Settings ==========

 

[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\DomainProfile]

\"DisableNotifications\" = 0

\"EnableFirewall\" = 1

 

[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\StandardProfile]

\"DisableNotifications\" = 0

\"EnableFirewall\" = 1

 

[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\PublicProfile]

\"DisableNotifications\" = 0

\"EnableFirewall\" = 1

 

========== Authorized Applications List ==========

 

 

========== Vista Active Open Ports Exception List ==========

 

[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules]

\"{0C0D5611-BF79-4504-946C-D2C37BBAD9E2}\" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | 

\"{3F77DEE7-7879-4485-8CC3-FC4E8F5B907A}\" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\\system32\\svchost.exe | 

\"{88F8B91B-765F-4BEB-9026-010AB2F5BDAE}\" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\\system32\\svchost.exe | 

\"{98ADADB7-9290-423E-9F66-0FAADFD84AF9}\" = lport=2869 | protocol=6 | dir=in | app=system | 

\"{9BCC0A4B-1A53-4D36-8FC3-7639CB1ECFB6}\" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\\system32\\svchost.exe | 

\"{9EDBEE99-0510-4C62-9311-DB05CD5499A8}\" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\\system32\\svchost.exe | 

\"{B999610B-3359-495E-9E94-D049C2BE1731}\" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\\system32\\svchost.exe | 

\"{BBE6E5ED-28B5-4378-8BBB-69869CEDC4FE}\" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | 

\"{BDE53792-1BFF-4EB1-B0F5-FA7289601E06}\" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\\system32\\svchost.exe | 

\"{C911DE0A-C213-468A-812B-007B520CB6A1}\" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | 

\"{EC6E6100-6001-4177-9E89-3739DF412387}\" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\\system32\\svchost.exe | 

\"{F270A3AF-9EF5-4B04-AFD9-CAEB2FCD0117}\" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\\system32\\svchost.exe | 

 

========== Vista Active Application Exception List ==========

 

[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules]

\"{11845A41-0B1E-43E0-92E4-68287683418E}\" = protocol=17 | dir=in | app=c:\\program files\\hp\\hp officejet 6500 e710a-f\\bin\\devicesetup.exe | 

\"{1FBD6AEE-0D94-4004-8D0F-0342910CA692}\" = protocol=17 | dir=in | app=c:\\program files\\common files\\mcafee\\mcsvchost\\mcsvhost.exe | 

\"{26867199-43E4-4660-9287-5D37C939F37F}\" = protocol=6 | dir=in | app=c:\\program files\\yahoo!\\messenger\\yahoomessenger.exe | 

\"{3E8717E2-5523-4E50-90C2-CC7127DCD750}\" = protocol=6 | dir=in | app=c:\\program files\\hp\\hp officejet 6500 e710a-f\\bin\\devicesetup.exe | 

\"{4D77B3C3-169B-4581-BC41-5919857C5391}\" = dir=in | app=c:\\users\\kaila\\appdata\\local\\facebook\\video\\skype\\facebookvideocalling.exe | 

\"{50AA8E9B-636A-489B-8EA5-D9F3F0C36BCB}\" = dir=in | app=c:\\program files\\itunes\\itunes.exe | 

\"{5579B851-31B4-489D-B1AC-2A19DDDB6C9F}\" = protocol=17 | dir=in | app=c:\\program files\\search results toolbar\\datamngr\\srtool~1\\dtuser.exe | 

\"{55F27024-7A86-455F-BBFF-C206C182E4A6}\" = dir=in | app=c:\\program files\\imesh applications\\imesh\\imesh.exe | 

\"{5ACF1ACB-F3F4-494F-B78D-8ADD91664A7B}\" = protocol=6 | dir=in | app=c:\\users\\kaila\\appdata\\local\\temp\\bundlesweetimsetup.exe | 

\"{5BF6070F-4107-479A-9947-197E516892AA}\" = protocol=6 | dir=in | app=c:\\program files\\hp\\hp officejet 6500 e710a-f\\bin\\hpnetworkcommunicator.exe | 

\"{5D957BE7-CC96-4EB5-A649-C4A5DF2DCB49}\" = dir=in | app=c:\\program files\\windows live\\mesh\\moe.exe | 

\"{6060F889-0A7A-4136-AD1E-7C2C91F787BC}\" = protocol=6 | dir=out | svc=upnph

7
Tech Clinic / many problems
« on: January 04, 2014, 05:11:30 PM »

i apologize for taking so long. christmas and everything being hectic. here is the logs.


 


 


OTL.txt---


 


 


 


 


OTL logfile created on: 1/4/2014 3:47:32 PM - Run 1

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Users\\norad\\Desktop

64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

 

4.00 Gb Total Physical Memory | 1.61 Gb Available Physical Memory | 40.32% Memory free

8.19 Gb Paging File | 5.48 Gb Available in Paging File | 66.85% Paging File free

Paging file location(s): ?:\\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)

Drive C: | 284.11 Gb Total Space | 166.72 Gb Free Space | 58.68% Space Free | Partition Type: NTFS

Drive D: | 13.98 Gb Total Space | 2.13 Gb Free Space | 15.21% Space Free | Partition Type: NTFS

Drive E: | 30.02 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

 

Computer Name: NORAD-PC | User Name: norad | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Processes (SafeList) ==========

 

PRC - [2014/01/04 15:46:05 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\norad\\Desktop\\OTL.exe

PRC - [2013/12/16 03:09:22 | 004,180,256 | ---- | M] (Conduit) -- C:\\Program Files (x86)\\SearchProtect\\SearchProtect\\bin\\cltmng.exe

PRC - [2013/12/16 03:09:22 | 002,849,056 | ---- | M] (Conduit) -- C:\\Program Files (x86)\\SearchProtect\\UI\\bin\\cltmngui.exe

PRC - [2013/12/16 03:09:22 | 002,251,552 | ---- | M] (Conduit) -- C:\\Program Files (x86)\\SearchProtect\\Main\\bin\\CltMngSvc.exe

PRC - [2013/12/04 13:46:36 | 000,273,000 | ---- | M] (Highlightly) -- C:\\Program Files (x86)\\Highlightly\\Service\\hlsvc.exe

PRC - [2013/11/11 22:02:14 | 003,478,544 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\\Program Files (x86)\\AVG\\AVG2014\\avgidsagent.exe

PRC - [2013/11/08 18:51:25 | 000,166,352 | ---- | M] (APN LLC.) -- C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\apnmcp.exe

PRC - [2013/11/08 18:51:17 | 001,707,472 | ---- | M] (APN) -- C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\Updater\\TBNotifier.exe

PRC - [2013/11/07 22:03:50 | 004,956,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\\Program Files (x86)\\AVG\\AVG2014\\avgui.exe

PRC - [2013/09/24 01:33:08 | 000,348,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\\Program Files (x86)\\AVG\\AVG2014\\avgwdsvc.exe

PRC - [2008/09/26 04:36:40 | 001,148,200 | ---- | M] (CyberLink Corp.) -- C:\\Program Files (x86)\\Hewlett-Packard\\Media\\DVD\\DVDAgent.exe

PRC - [2008/09/25 20:42:24 | 000,189,736 | ---- | M] (CyberLink) -- C:\\Program Files (x86)\\Hewlett-Packard\\TouchSmart\\Media\\Kernel\\CLML\\CLMLSvc.exe

PRC - [2008/09/25 20:41:44 | 001,152,296 | ---- | M] (CyberLink Corp.) -- C:\\Program Files (x86)\\Hewlett-Packard\\TouchSmart\\Media\\TSMAgent.exe

PRC - [2008/09/23 13:18:52 | 000,365,904 | ---- | M] () -- C:\\Program Files (x86)\\SMINST\\BLService.exe

PRC - [2008/06/19 16:04:50 | 000,014,376 | ---- | M] (Broadcom Corporation.) -- C:\\Program Files\\WIDCOMM\\Bluetooth Software\\BluetoothHeadsetProxy.exe

PRC - [1622/05/04 11:26:22 | 000,999,200 | ---- | M] (Conduit Ltd.) -- C:\\Users\\norad\\AppData\\Local\\NativeMessaging\\CT3306061\\1_0_0_6\\TBMessagingHost.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2013/12/03 20:48:04 | 000,399,312 | ---- | M] () -- C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\Application\\31.0.1650.63\\ppgooglenaclpluginchrome.dll

MOD - [2013/12/03 20:48:03 | 013,586,896 | ---- | M] () -- C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\Application\\31.0.1650.63\\PepperFlash\\pepflashplayer.dll

MOD - [2013/12/03 20:48:02 | 004,055,504 | ---- | M] () -- C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\Application\\31.0.1650.63\\pdf.dll

MOD - [2013/12/03 20:47:08 | 001,619,408 | ---- | M] () -- C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\Application\\31.0.1650.63\\ffmpegsumo.dll

MOD - [2013/10/26 14:47:18 | 000,978,944 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System.Configuration\\f453ecc6bb7fc8d52d61247676944623\\System.Configuration.ni.dll

MOD - [2013/10/18 17:04:46 | 012,434,432 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System.Windows.Forms\\73d9bc894522543b561a0342dac87c06\\System.Windows.Forms.ni.dll

MOD - [2013/10/18 17:03:44 | 014,329,856 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\PresentationFramewo#\\f228cc72a6647716127cd44ca416e6dc\\PresentationFramework.ni.dll

MOD - [2013/10/18 17:03:02 | 012,218,880 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\PresentationCore\\b2482534bee5c520cdfe9c8f7df6a92f\\PresentationCore.ni.dll

MOD - [2013/10/18 17:02:31 | 003,325,440 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\WindowsBase\\c16ade1485996fa4981edc7df436a15b\\WindowsBase.ni.dll

MOD - [2013/08/15 02:45:58 | 000,998,400 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System.Management\\e77e7cdf3072d5a658832b8863ff439e\\System.Management.ni.dll

MOD - [2013/08/15 02:44:54 | 000,771,584 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System.Runtime.Remo#\\b167ef6967ad27503c6ac6aabcef1aff\\System.Runtime.Remoting.ni.dll

MOD - [2013/08/15 02:44:52 | 000,627,712 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System.EnterpriseSe#\\5ba1ebef462c4f9cb1a8fe05c0419d0e\\System.EnterpriseServices.ni.dll

MOD - [2013/08/15 02:44:52 | 000,627,200 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System.Transactions\\9e0ade6fc2bcb5fbd4c8978bf92784a3\\System.Transactions.ni.dll

MOD - [2013/08/15 02:44:52 | 000,280,064 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System.EnterpriseSe#\\5ba1ebef462c4f9cb1a8fe05c0419d0e\\System.EnterpriseServices.Wrapper.dll

MOD - [2013/08/15 02:38:19 | 005,462,016 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System.Xml\\09f5b3f7a363b742a73937e818595597\\System.Xml.ni.dll

MOD - [2013/08/15 02:37:56 | 001,593,344 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System.Drawing\\c0df7e124d8d5e2821fd7d3921d404f7\\System.Drawing.ni.dll

MOD - [2013/08/15 02:37:43 | 006,622,208 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System.Data\\1eff630f4194c74287d1dd4a859693f7\\System.Data.ni.dll

MOD - [2013/08/15 02:36:46 | 007,977,984 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System\\d7153acb7b6ccb5a6a886d6f0ab732b1\\System.ni.dll

MOD - [2013/07/10 02:53:35 | 000,368,128 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\PresentationFramewo#\\af7b745f6a06b800c73f1556553fe331\\PresentationFramework.Aero.ni.dll

MOD - [2013/07/10 02:52:54 | 011,497,984 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\mscorlib\\6a938df70a8b7996a3890b4f34c83906\\mscorlib.ni.dll

MOD - [2011/11/01 23:26:32 | 000,087,912 | ---- | M] () -- C:\\Program Files (x86)\\Common Files\\Apple\\Apple Application Support\\zlib1.dll

MOD - [2011/11/01 23:26:12 | 001,242,472 | ---- | M] () -- C:\\Program Files (x86)\\Common Files\\Apple\\Apple Application Support\\libxml2.dll

MOD - [2009/04/11 00:28:21 | 000,368,640 | ---- | M] () -- C:\\Windows\\SysWOW64\\msjetoledb40.dll

MOD - [2009/04/10 20:04:15 | 000,113,664 | ---- | M] () -- C:\\Windows\\assembly\\GAC_32\\System.EnterpriseServices\\2.0.0.0__b03f5f7f11d50a3a\\System.EnterpriseServices.Wrapper.dll

MOD - [2009/03/29 22:42:19 | 000,261,632 | ---- | M] () -- C:\\Windows\\assembly\\GAC_32\\System.Transactions\\2.0.0.0__b77a5c561934e089\\System.Transactions.dll

MOD - [2009/03/29 22:42:17 | 002,933,760 | ---- | M] () -- C:\\Windows\\assembly\\GAC_32\\System.Data\\2.0.0.0__b77a5c561934e089\\System.Data.dll

MOD - [2008/09/30 17:56:06 | 000,032,768 | ---- | M] () -- C:\\Program Files (x86)\\Hewlett-Packard\\HP Advisor\\Content.XmlSerializers.dll

MOD - [2008/09/30 17:52:02 | 000,007,168 | ---- | M] () -- C:\\Program Files (x86)\\Hewlett-Packard\\HP Advisor\\RemotingClient.dll

MOD - [2008/09/30 17:52:00 | 000,057,344 | ---- | M] () -- C:\\Program Files (x86)\\Hewlett-Packard\\HP Advisor\\Pillars\\PCAlerts\\PCAlertsPillar.dll

MOD - [2008/09/30 17:51:52 | 000,118,784 | ---- | M] () -- C:\\Program Files (x86)\\Hewlett-Packard\\HP Advisor\\ECLibrary.dll

MOD - [2008/09/30 17:51:52 | 000,010,240 | ---- | M] () -- C:\\Program Files (x86)\\Hewlett-Packard\\HP Advisor\\MessagingClients.dll

MOD - [2008/09/30 17:51:36 | 000,040,960 | ---- | M] () -- C:\\Program Files (x86)\\Hewlett-Packard\\HP Advisor\\MessagingServer.dll

MOD - [2008/09/30 17:51:36 | 000,028,672 | ---- | M] () -- C:\\Program Files (x86)\\Hewlett-Packard\\HP Advisor\\MessagingMessages.dll

MOD - [2008/09/30 17:51:36 | 000,005,632 | ---- | M] () -- C:\\Program Files (x86)\\Hewlett-Packard\\HP Advisor\\MessagingInterface.dll

MOD - [2008/09/25 20:42:26 | 000,881,960 | ---- | M] () -- C:\\Program Files (x86)\\Hewlett-Packard\\TouchSmart\\Media\\Kernel\\CLML\\CLMediaLibrary.dll

MOD - [2008/06/29 17:10:18 | 000,028,672 | ---- | M] () -- C:\\Program Files (x86)\\CyberLink\\Shared files\\richvideops.dll

 

 

========== Services (SafeList) ==========

 

SRV:64bit: - [2010/01/21 16:24:56 | 000,130,048 | ---- | M] (WDC) [Auto | Running] -- C:\\Program Files\\Western Digital\\WD SmartWare\\WD Drive Manager\\WDDMService.exe -- (WDDMService)

SRV:64bit: - [2008/09/11 05:53:00 | 000,279,040 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\\Windows\\SysNative\\DriverStore\\FileRepository\\stwrt64.inf_bd5387da\\STacSV64.exe -- (STacSV)

SRV:64bit: - [2008/06/27 09:53:06 | 000,089,088 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\\Windows\\SysNative\\DriverStore\\FileRepository\\stwrt64.inf_bd5387da\\AESTSr64.exe -- (AESTFilters)

SRV:64bit: - [2008/03/18 18:25:40 | 000,023,040 | ---- | M] (Hewlett-Packard Corporation) [Auto | Running] -- C:\\Windows\\SysNative\\Hpservice.exe -- (hpsrv)

SRV:64bit: - [2008/01/20 20:47:32 | 000,383,544 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)

SRV:64bit: - [2007/12/11 14:11:30 | 000,015,872 | ---- | M] (Agere Systems) [Auto | Running] -- C:\\Windows\\SysNative\\agr64svc.exe -- (AgereModemAudio)

SRV - [2013/12/28 12:22:39 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2013/12/16 03:09:22 | 002,251,552 | ---- | M] (Conduit) [Auto | Running] -- C:\\Program Files (x86)\\SearchProtect\\Main\\bin\\CltMngSvc.exe -- (CltMngSvc)

SRV - [2013/12/04 13:46:36 | 000,273,000 | ---- | M] (Highlightly) [Auto | Running] -- C:\\Program Files (x86)\\Highlightly\\Service\\hlsvc.exe -- (hlsvc)

SRV - [2013/11/11 22:02:14 | 003,478,544 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\\Program Files (x86)\\AVG\\AVG2014\\avgidsagent.exe -- (AVGIDSAgent)

SRV - [2013/11/08 18:51:25 | 000,166,352 | ---- | M] (APN LLC.) [Auto | Running] -- C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\apnmcp.exe -- (APNMCP)

SRV - [2013/09/24 01:33:08 | 000,348,008 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\\Program Files (x86)\\AVG\\AVG2014\\avgwdsvc.exe -- (avgwd)

SRV - [2013/06/21 08:53:36 | 000,162,408 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\\Program Files (x86)\\Skype\\Updater\\Updater.exe -- (SkypeUpdate)

SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)

SRV - [2009/06/16 08:58:08 | 000,020,480 | ---- | M] (Memeo) [Auto | Running] -- C:\\Program Files (x86)\\Western Digital\\WD SmartWare\\Front Parlor\\WDSmartWareBackgroundService.exe -- (WDSmartWareBackgroundService)

SRV - [2009/03/29 22:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2008/09/23 13:18:52 | 000,365,904 | ---- | M] () [Auto | Running] -- C:\\Program Files (x86)\\SMINST\\BLService.exe -- (Recovery Service for Windows)

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - [2013/12/04 13:46:36 | 000,058,256 | ---- | M] (Highlightly) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\hlnfd.sys -- (hlnfd)

DRV:64bit: - [2013/11/05 21:55:48 | 000,150,808 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\\Windows\\SysNative\\DRIVERS\\avgdiska.sys -- (Avgdiska)

DRV:64bit: - [2013/11/04 21:52:42 | 000,240,920 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\\Windows\\SysNative\\DRIVERS\\avgidsdrivera.sys -- (AVGIDSDriver)

DRV:64bit: - [2013/10/31 23:00:18 | 000,212,280 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\\Windows\\SysNative\\DRIVERS\\avgldx64.sys -- (Avgldx64)

DRV:64bit: - [2013/10/31 22:49:46 | 000,294,712 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\\Windows\\SysNative\\DRIVERS\\avgloga.sys -- (Avgloga)

DRV:64bit: - [2013/10/24 22:25:58 | 000,194,872 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\\Windows\\SysNative\\DRIVERS\\avgidsha.sys -- (AVGIDSHA)

DRV:64bit: - [2013/10/01 00:52:08 | 000,123,704 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\\Windows\\SysNative\\DRIVERS\\avgmfx64.sys -- (Avgmfx64)

DRV:64bit: - [2013/09/10 00:43:02 | 000,031,544 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\\Windows\\SysNative\\DRIVERS\\avgrkx64.sys -- (Avgrkx64)

DRV:64bit: - [2013/08/01 16:07:06 | 000,251,192 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\\Windows\\SysNative\\DRIVERS\\avgtdia.sys -- (Avgtdia)

DRV:64bit: - [2012/12/13 12:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\Drivers\\usbaapl64.sys -- (USBAAPL64)

DRV:64bit: - [2012/08/21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\GEARAspiWDM.sys -- (GEARAspiWDM)

DRV:64bit: - [2012/02/29 07:52:46 | 000,016,384 | ---- | M] (Microsoft Corporation) [Recognizer | System | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2009/09/30 18:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\DRIVERS\\wpdusb.sys -- (WpdUsb)

DRV:64bit: - [2009/03/31 10:26:20 | 005,430,272 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\NETw5v64.sys -- (NETw5v64)

DRV:64bit: - [2009/02/13 11:02:52 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\DRIVERS\\wdcsam64.sys -- (WDC_SAM)

DRV:64bit: - [2008/09/11 05:54:44 | 000,465,408 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\stwrt64.sys -- (STHDA)

DRV:64bit: - [2008/08/05 21:29:26 | 000,056,352 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nvhda64v.sys -- (NVHDA)

DRV:64bit: - [2008/07/22 09:42:34 | 000,170,496 | ---- | M] (Realtek Corporation                                            ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\Rtlh64.sys -- (RTL8169)

DRV:64bit: - [2008/07/21 04:53:04 | 000,145,496 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\jmcr.sys -- (JMCR)

DRV:64bit: - [2008/06/23 05:54:02 | 000,099,368 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\btwavdt.sys -- (btwavdt)

DRV:64bit: - [2008/06/23 05:54:02 | 000,091,176 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\btwaudio.sys -- (btwaudio)

DRV:64bit: - [2008/06/23 05:54:02 | 000,019,752 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\btwrchid.sys -- (btwrchid)

DRV:64bit: - [2008/04/28 19:55:32 | 000,064,000 | ---- | M] (ENE TECHNOLOGY INC.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\enecir.sys -- (enecir)

DRV:64bit: - [2008/03/27 14:10:56 | 000,026,984 | ---- | M] (Hewlett-Packard Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\DRIVERS\\hpdskflt.sys -- (hpdskflt)

DRV:64bit: - [2008/03/27 14:10:14 | 000,040,296 | ---- | M] (Hewlett-Packard Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\Accelerometer.sys -- (Accelerometer)

DRV:64bit: - [2008/02/29 17:59:32 | 001,252,352 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\agrsm64.sys -- (AgereSoftModem)

DRV:64bit: - [2008/01/20 20:47:25 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\serscan.sys -- (StillCam)

DRV:64bit: - [2008/01/20 20:46:57 | 003,154,432 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\DRIVERS\\NETw3v64.sys -- (NETw3v64)

DRV:64bit: - [2008/01/20 20:46:55 | 000,111,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\DRIVERS\\sdbus.sys -- (sdbus)

DRV:64bit: - [2008/01/18 05:31:30 | 000,320,560 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\SynTP.sys -- (SynTP)

DRV:64bit: - [2007/06/18 18:13:12 | 000,018,432 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\HpqKbFiltr.sys -- (HpqKbFiltr)

DRV:64bit: - [2006/10/03 19:45:36 | 000,273,408 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\DRIVERS\\yk60x64.sys -- (yukonx64)

DRV - [2008/09/26 04:36:34 | 000,027,632 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- C:\\Program Files (x86)\\Hewlett-Packard\\Media\\DVD\\000.fcl -- ({55662437-DA8C-40c0-AADA-2C816A897A49})

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 



IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope = {5D9FA932-8D8C-40EC-9192-A538B6854A52}

IE:64bit: - HKLM\\..\\SearchScopes\\{3CF2481F-854A-41B7-9CDF-7113C60591B3}: \"URL\" = http://www.ask.com/web?q=\'>http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl

IE:64bit: - HKLM\\..\\SearchScopes\\{5D9FA932-8D8C-40EC-9192-A538B6854A52}: \"URL\" = http://search.live.com/results.aspx?q=\'>http://search.live.com/results.aspx?q={searchTerms}&FORM=HPNTDF


IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm


IE - HKLM\\..\\URLSearchHook: {d1b5aad5-d1ae-4b20-88b1-feeaeb4c1ebc} - C:\\Program Files (x86)\\Connect_DLC_5\\prxtbConn.dll (Conduit Ltd.)

IE - HKLM\\..\\SearchScopes,DefaultScope = {3E37E123-445C-4848-8E34-279F96B6BD39}

IE - HKLM\\..\\SearchScopes\\{3CF2481F-854A-41B7-9CDF-7113C60591B3}: \"URL\" = http://www.ask.com/web?q=\'>http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl

IE - HKLM\\..\\SearchScopes\\{5815a829-6908-46b0-8b10-0036b333371e}: \"URL\" = http://search.conduit.com/ResultsExt.aspx?q=\'>http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3309767&CUI=UN11379035163226023&UM=2

IE - HKLM\\..\\SearchScopes\\{5D9FA932-8D8C-40EC-9192-A538B6854A52}: \"URL\" = http://search.live.com/results.aspx?q=\'>http://search.live.com/results.aspx?q={searchTerms}&FORM=HPNTDF

 

 

IE - HKU\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

 

IE - HKU\\S-1-5-18\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

 

 

 

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb\'>http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = http://search.conduit.com/?ctid=CT3306061&octid=EB_ORIGINAL_CTID&SearchSource=61&CUI=UN60480715371022752&UM=2&UP=SPCBA30609-FFB3-46F8-89FC-F54D4DAAD445&S41CIE%C2\'>

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,StartPageCache = 1

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\URLSearchHook: {d1b5aad5-d1ae-4b20-88b1-feeaeb4c1ebc} - C:\\Program Files (x86)\\Connect_DLC_5\\prxtbConn.dll (Conduit Ltd.)

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\URLSearchHook: {D8278076-BC68-4484-9233-6E7F1628B56C} - C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\searchhook.dll (APN LLC.)

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\SearchScopes,DefaultScope = {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\SearchScopes\\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}: \"URL\" = http://search.conduit.com/Results.aspx?ctid=CT3306061&octid=EB_ORIGINAL_CTID&SearchSource=62&CUI=UN60480715371022752&UM=2&UP=SPCBA30609-FFB3-46F8-89FC-F54D4DAAD445&q={searchTerms}&S41CIE

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\SearchScopes\\{3CF2481F-854A-41B7-9CDF-7113C60591B3}: \"URL\" = http://www.ask.com/web?q=\'>http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\SearchScopes\\{3E37E123-445C-4848-8E34-279F96B6BD39}: \"URL\" = http://search.conduit.com/ResultsExt.aspx?q=\'>http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3306061&CUI=UN60480715371022752&UM=2&SSPV=S41CIE

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\SearchScopes\\{5815a829-6908-46b0-8b10-0036b333371e}: \"URL\" = http://search.conduit.com/ResultsExt.aspx?q=\'>http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3309767&CUI=UN11379035163226023&UM=2

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\SearchScopes\\{5D9FA932-8D8C-40EC-9192-A538B6854A52}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&FORM=HPNTDF&pc=HPNTDF&src=IE-SearchBox


IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = *.local

 

========== FireFox ==========

 

FF - prefs.js..CT3309759.browser.search.defaultthis.engineName: \"true\"

FF - prefs.js..browser.search.defaultthis.engineName: \"Swirlz Customized Web Search\"


FF - prefs.js..browser.search.useDBForOrder: true

FF - prefs.js..extensions.enabledAddons: 39e612de-2951-40c2-ab4a-82e121c42778%404e0cecc2-7c67-4374-bc4c-f15656d80ab7.com:0.93.119

FF - prefs.js..extensions.enabledAddons: %7B4cb3c467-0d72-44e6-9237-750b9b8b5ac9%7D:10.23.0.726

FF - prefs.js..extensions.enabledAddons: %7B635abd67-4fe9-1b23-4f01-e679fa7484c1%7D:3.1.0.20130818030116

FF - prefs.js..extensions.enabledAddons: gethighlightly%40gethighlightly.com:1.9.0.0

FF - prefs.js..extensions.enabledAddons: 0c3e9649-324d-4df0-a61e-7ac31aead042%402612bb82-5f8a-49b2-a299-348e707310fc.com:0.93.148

FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:26.0

FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198

FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24

 

 

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_9_900_170.dll File not found

FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_9_900_170.dll ()

FF - HKLM\\Software\\MozillaPlugins\\@Apple.com/iTunes,version=:  File not found

FF - HKLM\\Software\\MozillaPlugins\\@Apple.com/iTunes,version=1.0: C:\\Program Files (x86)\\iTunes\\Mozilla Plugins\\npitunes.dll ()

FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.45.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\dtplugin\\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin: C:\\Program Files (x86)\\Java\\jre7\\bin\\new_plugin\\npjp2.dll File not found

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.45.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@Microsoft.com/NpCtrl,version=1.0: c:\\Program Files (x86)\\Microsoft Silverlight\\5.1.20913.0\\npctrl.dll ( Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/WPF,version=3.5: c:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Windows Presentation Foundation\\NPWPF.dll (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\Adobe Reader: C:\\Program Files (x86)\\Adobe\\Reader 9.0\\Reader\\AIR\\nppdf32.dll (Adobe Systems Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\norad\\AppData\\Local\\Google\\Update\\1.3.22.3\\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\norad\\AppData\\Local\\Google\\Update\\1.3.22.3\\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Hewlett-Packard\\SmartPrint\\QPExtension [2011/01/26 14:27:28 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\[email protected] [2013/12/28 12:57:48 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Thunderbird\\Extensions\\\\[email protected]: C:\\Program Files\\ESET\\ESET NOD32 Antivirus\\Mozilla Thunderbird

FF - HKEY_CURRENT_USER\\software\\mozilla\\Firefox\\EXTENSIONS\\\\{57c20073-e24b-4b2a-aa91-70d1ad526cbf}: C:\\Program Files (x86)\\PassShow\\150.xpi [2013/12/29 15:32:22 | 000,011,866 | ---- | M] ()

FF - HKEY_CURRENT_USER\\software\\mozilla\\Firefox\\EXTENSIONS\\\\{B21F5E31-B8E8-41CD-B74C-168A71A10E49}: C:\\Users\\norad\\AppData\\Local\\GreatArcadeHits\\{B21F5E31-B8E8-41CD-B74C-168A71A10E49}\\ [2013/12/29 15:32:54 | 000,000,000 | ---D | M]

 

[2009/06/07 10:30:08 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Extensions

[2013/12/29 14:00:45 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions

[2010/05/25 18:25:57 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\{20a82645-c095-46ed-80e3-08825760534b}

[2013/12/28 12:25:02 | 000,000,000 | ---D | M] (Swirlz) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\{4cb3c467-0d72-44e6-9237-750b9b8b5ac9}

[2013/08/23 16:34:48 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\{635abd67-4fe9-1b23-4f01-e679fa7484c1}

[2013/12/28 11:41:17 | 000,000,000 | ---D | M] (\"weDownload Manager\") -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\0c3e9649-324d-4df0-a61e-7ac31aead042@2612bb82-5f8a-49b2-a299-348e707310fc.com

[2013/12/28 12:12:33 | 000,000,000 | ---D | M] (\"Plus-HD-1.2\") -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\39e612de-2951-40c2-ab4a-82e121c42778@4e0cecc2-7c67-4374-bc4c-f15656d80ab7.com

[2013/12/29 13:51:22 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\0c3e9649-324d-4df0-a61e-7ac31aead042@2612bb82-5f8a-49b2-a299-348e707310fc.com\\extensionData

[2013/12/29 13:51:22 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\0c3e9649-324d-4df0-a61e-7ac31aead042@2612bb82-5f8a-49b2-a299-348e707310fc.com\\extensionData\\plugins

[2013/12/29 13:51:22 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\0c3e9649-324d-4df0-a61e-7ac31aead042@2612bb82-5f8a-49b2-a299-348e707310fc.com\\extensionData\\userCode

[2013/12/28 11:59:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\39e612de-2951-40c2-ab4a-82e121c42778@4e0cecc2-7c67-4374-bc4c-f15656d80ab7.com\\extensionData

[2013/12/28 11:59:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\39e612de-2951-40c2-ab4a-82e121c42778@4e0cecc2-7c67-4374-bc4c-f15656d80ab7.com\\extensionData\\plugins

[2013/12/28 11:59:11 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\39e612de-2951-40c2-ab4a-82e121c42778@4e0cecc2-7c67-4374-bc4c-f15656d80ab7.com\\extensionData\\userCode

[2013/07/24 17:40:12 | 000,002,546 | ---- | M] () -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\searchplugins\\ask-search.xml

[2013/12/28 11:59:04 | 000,000,975 | ---- | M] () -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\searchplugins\\conduit-search.xml

[2013/12/28 12:25:05 | 000,001,017 | ---- | M] () -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\searchplugins\\conduit.xml

[2013/12/28 12:01:03 | 000,001,368 | ---- | M] () -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\searchplugins\\iminent.xml

[2013/12/28 21:04:18 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions

[2013/12/28 12:57:48 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{AB2CE124-6272-4b12-94A9-7303C7397BD1}

[2013/12/28 12:57:48 | 000,000,000 | ---D | M] () -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\[email protected]

[2013/12/28 12:57:48 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\browser\\extensions

[2013/12/28 12:58:03 | 000,000,000 | ---D | M] (Default) -- C:\\Program Files (x86)\\Mozilla Firefox\\browser\\extensions\\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2013/12/28 12:04:58 | 000,611,224 | ---- | M] (Oracle Corporation) -- C:\\Program Files (x86)\\mozilla firefox\\plugins\\npdeployJava1.dll

 

========== Chrome  ==========

 

CHR - default_search_provider: Conduit Search (Enabled)



CHR - Extension: Highlightly = C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\cmclajginlihohopoeofghddnhpplhom\\1.9.0.0_1\\

CHR - Extension: PassShow = C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dhogjnnleghndloamdkljhnhdchpcijl\\1.150_0\\

CHR - Extension: Connect DLC 5 = C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lipgolpfajiadodbcbljdpmbmbdmfcil\\10.23.0.728_0\\

CHR - Extension: Connect DLC 5 = C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lipgolpfajiadodbcbljdpmbmbdmfcil\\10.23.0.728_0\\nativeMessaging\\nmHost

CHR - Extension: Swirlz = C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lmcedemcahkmaidbipmniofjcocajlgk\\10.24.3.503_0\\

CHR - Extension: Swirlz = C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lmcedemcahkmaidbipmniofjcocajlgk\\10.24.3.503_0\\nativeMessaging\\nmHost

CHR - Extension: Google Wallet = C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda\\0.0.6.0_1\\

 

O1 HOSTS File: ([2006/09/18 15:37:24 | 000,000,761 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\Hosts

O1 - Hosts: 127.0.0.1       localhost

O1 - Hosts: ::1             localhost

O2:64bit: - BHO: (Plus-HD-1.2) - {11111111-1111-1111-1111-110311121155} - C:\\Program Files (x86)\\Plus-HD-1.2\\Plus-HD-1.2-bho64.dll File not found

O2:64bit: - BHO: (weDownload Manager) - {11111111-1111-1111-1111-110311431144} - C:\\Program Files (x86)\\weDownload Manager\\weDownload Manager-bho64.dll File not found

O2:64bit: - BHO: (Ask Toolbar) - {4F524A2D-5637-4300-76A7-7A786E7484D7} - C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\ORJ-V7C\\Passport_x64.dll (APN LLC.)

O2:64bit: - BHO: (Highlightly) - {83F2328D-0D6A-42B4-B0C4-02A929EDD4BE} - C:\\Program Files\\Highlightly\\IE\\HighlightlyClientIE.dll (Highlightly)

O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\\Program Files (x86)\\Hp\\Smart Web Printing\\hpswp_framework.dll (Hewlett-Packard Co.)

O2 - BHO: (PassShow) - {2d661e5b-7d7a-417c-b5b5-6479017bb314} - C:\\Program Files (x86)\\PassShow\\150.dll ()

O2 - BHO: (Ask Toolbar) - {4F524A2D-5637-4300-76A7-7A786E7484D7} - C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\ORJ-V7C\\Passport.dll (APN LLC.)

O2 - BHO: (Highlightly) - {83F2328D-0D6A-42B4-B0C4-02A929EDD4BE} - C:\\Program Files (x86)\\Highlightly\\IE\\HighlightlyClientIE.dll (Highlightly)

O2 - BHO: (GreatArcadeHits Add-on) - {D0C21091-FF8E-432C-9006-0540E81BA9D7} - C:\\Users\\norad\\AppData\\Local\\GreatArcadeHits\\GreatArcadeHitsIE.dll (GreatArcadeHits)

O2 - BHO: (Connect DLC 5 Toolbar) - {d1b5aad5-d1ae-4b20-88b1-feeaeb4c1ebc} - C:\\Program Files (x86)\\Connect_DLC_5\\prxtbConn.dll (Conduit Ltd.)

O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\\Program Files (x86)\\MSN\\Toolbar\\3.0.0541.0\\msneshellx.dll (Microsoft Corp.)

O3:64bit: - HKLM\\..\\Toolbar: (Ask Toolbar) - {4F524A2D-5637-4300-76A7-7A786E7484D7} - C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\ORJ-V7C\\Passport_x64.dll (APN LLC.)

O3 - HKLM\\..\\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\\Program Files (x86)\\MSN\\Toolbar\\3.0.0541.0\\msneshellx.dll (Microsoft Corp.)

O3 - HKLM\\..\\Toolbar: (Ask Toolbar) - {4F524A2D-5637-4300-76A7-7A786E7484D7} - C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\ORJ-V7C\\Passport.dll (APN LLC.)

O3 - HKLM\\..\\Toolbar: (Connect DLC 5 Toolbar) - {d1b5aad5-d1ae-4b20-88b1-feeaeb4c1ebc} - C:\\Program Files (x86)\\Connect_DLC_5\\prxtbConn.dll (Conduit Ltd.)

O3:64bit: - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\Toolbar\\WebBrowser: (Ask Toolbar) - {4F524A2D-5637-4300-76A7-7A786E7484D7} - C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\ORJ-V7C\\Passport_x64.dll (APN LLC.)

O3 - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\Toolbar\\WebBrowser: (Ask Toolbar) - {4F524A2D-5637-4300-76A7-7A786E7484D7} - C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\ORJ-V7C\\Passport.dll (APN LLC.)

O3 - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\Toolbar\\WebBrowser: (Connect DLC 5 Toolbar) - {D1B5AAD5-D1AE-4B20-88B1-FEEAEB4C1EBC} - C:\\Program Files (x86)\\Connect_DLC_5\\prxtbConn.dll (Conduit Ltd.)

O4:64bit: - HKLM..\\Run: [NvCplDaemon] C:\\Windows\\SysNative\\NvCpl.dll (NVIDIA Corporation)

O4:64bit: - HKLM..\\Run: [NvMediaCenter] C:\\Windows\\SysNative\\NvMcTray.dll (NVIDIA Corporation)

O4:64bit: - HKLM..\\Run: [SmartMenu] C:\\Program Files\\Hewlett-Packard\\HP MediaSmart\\SmartMenu.exe (Hewlett-Packard)

O4:64bit: - HKLM..\\Run: [SysTrayApp] C:\\Program Files\\IDT\\WDM\\sttray64.exe (IDT, Inc.)

O4 - HKLM..\\Run: [ApnTBMon] C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\Updater\\TBNotifier.exe (APN)

O4 - HKLM..\\Run: [APSDaemon] C:\\Program Files (x86)\\Common Files\\Apple\\Apple Application Support\\APSDaemon.exe (Apple Inc.)

O4 - HKLM..\\Run: [AVG_UI] C:\\Program Files (x86)\\AVG\\AVG2014\\avgui.exe (AVG Technologies CZ, s.r.o.)

O4 - HKLM..\\Run: [CLMLServer for HP TouchSmart] C:\\Program Files (x86)\\Hewlett-Packard\\TouchSmart\\Media\\Kernel\\CLML\\CLMLSvc.exe (CyberLink)

O4 - HKLM..\\Run: [DVDAgent] C:\\Program Files (x86)\\Hewlett-Packard\\Media\\DVD\\DVDAgent.exe (CyberLink Corp.)

O4 - HKLM..\\Run: [HP Health Check Scheduler] c:\\Program Files (x86)\\Hewlett-Packard\\HP Health Check\\HPHC_Scheduler.exe (Hewlett-Packard)

O4 - HKLM..\\Run: [mobilegeni daemon] \"C:\\Program Files (x86)\\Mobogenie\\DaemonProcess.exe\" File not found

O4 - HKLM..\\Run: [TSMAgent] C:\\Program Files (x86)\\Hewlett-Packard\\TouchSmart\\Media\\TSMAgent.exe (CyberLink Corp.)

O4 - HKLM..\\Run: [UCam_Menu] C:\\Program Files (x86)\\Hewlett-Packard\\Media\\Webcam\\MUITransfer\\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKLM..\\Run: [UpdateLBPShortCut] C:\\Program Files (x86)\\CyberLink\\LabelPrint\\MUITransfer\\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKLM..\\Run: [UpdateP2GoShortCut] C:\\Program Files (x86)\\CyberLink\\Power2Go\\MUITransfer\\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKLM..\\Run: [UpdatePDIRShortCut] C:\\Program Files (x86)\\CyberLink\\PowerDirector\\MUITransfer\\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKLM..\\Run: [UpdatePSTShortCut] C:\\Program Files (x86)\\CyberLink\\DVD Suite\\MUITransfer\\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKU\\S-1-5-19..\\Run: [Sidebar] C:\\Program Files (x86)\\Windows Sidebar\\Sidebar.exe (Microsoft Corporation)

O4 - HKU\\S-1-5-19..\\Run: [WindowsWelcomeCenter] C:\\Windows\\SysWow64\\oobefldr.dll (Microsoft Corporation)

O4 - HKU\\S-1-5-20..\\Run: [Sidebar] C:\\Program Files (x86)\\Windows Sidebar\\Sidebar.exe (Microsoft Corporation)

O4 - HKU\\S-1-5-20..\\Run: [WindowsWelcomeCenter] C:\\Windows\\SysWow64\\oobefldr.dll (Microsoft Corporation)

O4 - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000..\\Run: [AVG-Secure-Search-Update_1213b] C:\\Users\\norad\\AppData\\Roaming\\AVG 1213b Campaign\\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=8fab85a0119147d38b19d16d38c0aeb6-f4a11d3e10dbebc28f3e5788a17788f15546486a /CMPID=1213b File not found

O4 - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000..\\Run: [HP Photosmart 6510 series (NET)] C:\\Program Files\\HP\\HP Photosmart 6510 series\\Bin\\ScanToPCActivationApp.exe (Hewlett-Packard Co.)

O4 - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000..\\Run: [NextLive] C:\\Users\\norad\\AppData\\Roaming\\newnext.me\\nengine.dll (NewNextDotMe)

O4 - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000..\\Run: [WMPNSCFG] C:\\Program Files (x86)\\Windows Media Player\\WMPNSCFG.exe File not found

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktop = 1

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktopChanges = 1

O8:64bit: - Extra context menu item: Send image to &Bluetooth Device... - C:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie_ctx.htm ()

O8:64bit: - Extra context menu item: Send page to &Bluetooth Device... - C:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie.htm ()

O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie_ctx.htm ()

O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie.htm ()

O9:64bit: - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie.htm ()

O9:64bit: - Extra \'Tools\' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie.htm ()

O9 - Extra Button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\\Program Files (x86)\\Hewlett-Packard\\SmartPrint\\smartprintsetup.exe (Hewlett-Packard)

O9 - Extra \'Tools\' menuitem : SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\\Program Files (x86)\\Hewlett-Packard\\SmartPrint\\smartprintsetup.exe (Hewlett-Packard)

O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\\Program Files (x86)\\Hp\\Smart Web Printing\\hpswp_extensions.dll (Hewlett-Packard Co.)

O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\\Program Files (x86)\\Hp\\Smart Web Printing\\hpswp_extensions.dll (Hewlett-Packard Co.)

O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie.htm ()

O9 - Extra \'Tools\' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie.htm ()

O10:64bit: - NameSpace_Catalog5\\Catalog_Entries64\\000000000008 [] - C:\\Program Files\\Bonjour\\mdnsNSP.dll (Apple Inc.)

O10 - NameSpace_Catalog5\\Catalog_Entries\\000000000008 [] - C:\\Program Files (x86)\\Bonjour\\mdnsNSP.dll (Apple Inc.)

O1364bit: - gopher Prefix: missing

O13 - gopher Prefix: missing

O15 - HKU\\.DEFAULT\\..Trusted Ranges: Range1 ([http] in Local intranet)

O15 - HKU\\S-1-5-18\\..Trusted Ranges: Range1 ([http] in Local intranet)

O15 - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..Trusted Ranges: Range1 ([http] in Local intranet)


O16 - DPF: {983A9C21-8207-4B58-BBB8-0EBC3D7C5505} https://unkmail2.unk.edu/dwa8W.cab\'>https://unkmail2.unk.edu/dwa8W.cab (Domino Web Access 8 Control)



O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab\'>http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters: DhcpNameServer = 66.168.128.20 24.205.224.36 68.190.192.35

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{848D19DE-381B-4946-AF29-2D20A8A1E0E7}: DhcpNameServer = 66.168.128.20 24.205.224.36 68.190.192.35

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{BF6E039F-8812-49D9-8155-4B5EDD4B4032}: DhcpNameServer = 74.40.74.40 74.40.74.41 192.168.254.254

O18:64bit: - Protocol\\Handler\\ms-help - No CLSID value found

O18:64bit: - Protocol\\Handler\\ms-itss - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype4com - No CLSID value found

O18 - Protocol\\Handler\\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\Program Files (x86)\\Common Files\\Skype\\Skype4COM.dll (Skype Technologies)

O20:64bit: - AppInit_DLLs: (C:\\PROGRA~2\\SearchProtect\\SearchProtect\\bin\\SPVC64Loader.dll) - C:\\Program Files (x86)\\SearchProtect\\SearchProtect\\bin\\SPVC64Loader.dll (Conduit)

O20:64bit: - AppInit_DLLs: (C:\\PROGRA~2\\OPTIMI~1\\OPTPRO~2.DLL) -  File not found

O20 - AppInit_DLLs: (c:\\progra~2\\searchprotect\\searchprotect\\bin\\spvc32loader.dll) - c:\\Program Files (x86)\\SearchProtect\\SearchProtect\\bin\\SPVC32Loader.dll (Conduit)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysNative\\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\\Windows\\SysWow64\\userinit.exe (Microsoft Corporation)

O24 - Desktop WallPaper: C:\\Users\\norad\\AppData\\Roaming\\Microsoft\\Windows Photo Gallery\\Windows Photo Gallery Wallpaper.jpg

O24 - Desktop BackupWallPaper: C:\\Users\\norad\\AppData\\Roaming\\Microsoft\\Windows Photo Gallery\\Windows Photo Gallery Wallpaper.jpg

O32 - HKLM CDRom: AutoRun - 1

O33 - MountPoints2\\{2e6a7335-2dc0-11de-be65-00247e244745}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{2e6a7335-2dc0-11de-be65-00247e244745}\\Shell\\AutoRun\\command - \"\" = F:\\LaunchU3.exe -a

O33 - MountPoints2\\{30da73e7-f32e-11df-b660-00247e244745}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{30da73e7-f32e-11df-b660-00247e244745}\\Shell\\AutoRun\\command - \"\" = G:\\LaunchU3.exe -a

O33 - MountPoints2\\{d4c18fac-d416-11df-91d0-00247e244745}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{d4c18fac-d416-11df-91d0-00247e244745}\\Shell\\AutoRun\\command - \"\" = \"G:\\WD SmartWare.exe\" autoplay=true

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\\..comfile [open] -- \"%1\" %*

O35:64bit: - HKLM\\..exefile [open] -- \"%1\" %*

O35 - HKLM\\..comfile [open] -- \"%1\" %*

O35 - HKLM\\..exefile [open] -- \"%1\" %*

O37:64bit: - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37:64bit: - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

 

========== Files/Folders - Created Within 30 Days ==========

 

[2014/01/04 15:46:02 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\norad\\Desktop\\OTL.exe

[2013/12/29 19:47:58 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Trend Micro

[2013/12/29 19:47:58 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\HiJackThis

[2013/12/29 15:33:29 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\.android

[2013/12/29 15:33:26 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\cache

[2013/12/29 15:33:23 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Roaming\\newnext.me

[2013/12/29 15:33:22 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\genienext

[2013/12/29 15:33:20 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\Documents\\Mobogenie

[2013/12/29 15:33:20 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\Mobogenie

[2013/12/29 15:32:54 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\GreatArcadeHits

[2013/12/29 15:32:35 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Roaming\\AVG2014

[2013/12/29 15:32:22 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\PassShow

[2013/12/29 15:31:15 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Connect_DLC_5

[2013/12/29 15:30:46 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\AVG

[2013/12/29 15:30:43 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Roaming\\TuneUp Software

[2013/12/29 15:28:08 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\ToniArts

[2013/12/29 15:28:08 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\EasyCleaner

[2013/12/29 15:27:15 | 000,000,000 | -H-D | C] -- C:\\$AVG

[2013/12/29 15:27:15 | 000,000,000 | ---D | C] -- C:\\ProgramData\\AVG2014

[2013/12/29 15:25:03 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\AVG

[2013/12/29 15:22:20 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\MFAData

[2013/12/29 15:22:20 | 000,000,000 | ---D | C] -- C:\\ProgramData\\MFAData

[2013/12/29 15:22:20 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\Avg2014

[2013/12/29 15:16:18 | 000,264,616 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaws.exe

[2013/12/29 15:16:18 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaw.exe

[2013/12/29 15:16:18 | 000,174,504 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\java.exe

[2013/12/29 15:13:51 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Licenses

[2013/12/29 15:13:43 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\SpywareBlaster

[2013/12/29 15:13:39 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\SpywareBlaster

[2013/12/29 15:13:27 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\SearchProtect

[2013/12/29 15:12:11 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\sweetpacks bundle uninstaller

[2013/12/29 15:03:33 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\AskPartnerNetwork

[2013/12/29 15:02:52 | 000,000,000 | ---D | C] -- C:\\ProgramData\\AskPartnerNetwork

[2013/12/29 15:02:52 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\AskPartnerNetwork

[2013/12/29 15:00:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Oracle

[2013/12/29 14:59:27 | 000,096,168 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\WindowsAccessBridge-32.dll

[2013/12/29 14:59:27 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Java

[2013/12/29 03:07:42 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\mshtmled.dll

[2013/12/29 03:07:42 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\mshtmled.dll

[2013/12/29 03:07:38 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ieui.dll

[2013/12/29 03:07:38 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ieui.dll

[2013/12/29 03:07:38 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ieUnatt.exe

[2013/12/29 03:07:38 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ieUnatt.exe

[2013/12/29 03:07:37 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\url.dll

[2013/12/29 03:07:37 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\url.dll

[2013/12/29 03:07:33 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\inetcpl.cpl

[2013/12/29 03:07:33 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\inetcpl.cpl

[2013/12/29 03:07:31 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\msfeeds.dll

[2013/12/29 03:07:30 | 002,334,720 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\jscript9.dll

[2013/12/29 03:07:29 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\jscript.dll

[2013/12/29 03:07:29 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\jscript.dll

[2013/12/29 03:07:29 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\vbscript.dll

[2013/12/28 21:04:19 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Roaming\\Activeris

[2013/12/28 21:00:29 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Roaming\\QuickScan

[2013/12/28 12:57:48 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Mozilla Firefox

[2013/12/28 12:29:59 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Roaming\\Optimizer Pro

[2013/12/28 12:26:43 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\Plus-HD-1.2

[2013/12/28 12:26:02 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Swirlz

[2013/12/28 12:26:02 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Conduit

[2013/12/28 12:25:29 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\NativeMessaging

[2013/12/28 12:25:25 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\Conduit

[2013/12/28 12:25:23 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\CRE

[2013/12/28 12:25:22 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Conduit

[2013/12/28 12:25:07 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Roaming\\SearchProtect

[2013/12/28 12:24:40 | 004,953,944 | ---- | C] (FLVMPlayer                                                  ) -- C:\\Users\\norad\\Desktop\\FLVMPlayer.exe

[2013/12/28 12:24:21 | 000,000,000 | ---D | C] -- C:\\Program Files\\Highlightly

[2013/12/28 12:24:20 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Highlightly

[2013/12/28 12:06:37 | 000,000,000 | ---D | C] -- C:\\Program Files\\Uninstaller

[2013/12/28 12:01:37 | 000,000,000 | ---D | C] -- C:\\Program Files\\Level Quality Watcher

[2013/12/28 11:57:43 | 000,000,000 | ---D | C] -- C:\\c335b1860269ab3a89494966

[2013/12/28 11:56:39 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\SwvUpdater

[2013/12/28 11:53:45 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\SearchProtect

[2013/12/28 11:52:07 | 000,198,656 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\scrrun.dll

[2013/12/28 11:52:07 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\cscript.exe

[2013/12/28 11:52:07 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wshom.ocx

[2013/12/28 11:52:07 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\wshom.ocx

[2013/12/28 11:52:06 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\scrrun.dll

[2013/12/28 11:52:06 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\cscript.exe

[2013/12/28 11:52:06 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\wshcon.dll

[2013/12/28 11:51:45 | 000,079,360 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\imagehlp.dll

[2013/12/28 11:50:53 | 000,374,784 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\SysFxUI.dll

[2013/12/28 11:50:53 | 000,218,112 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\drivers\\portcls.sys

[2013/12/28 11:50:53 | 000,122,368 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\drivers\\drmk.sys

[5 C:\\Users\\norad\\Documents\\*.tmp files -> C:\\Users\\norad\\Documents\\*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[2014/01/04 15:54:34 | 000,000,856 | ---- | M] () -- C:\\Windows\\tasks\\GoogleUpdateTaskUserS-1-5-21-4000507275-1486089171-1974680742-1000Core.job

[2014/01/04 15:46:18 | 000,003,216 | -H-- | M] () -- C:\\Windows\\SysNative\\7

8
Tech Clinic / many problems
« on: January 04, 2014, 05:08:21 PM »

i apologize for taking so long. christmas and everything being hectic. here is the logs.


 


 


OTL.txt---


 


 


 


 


OTL logfile created on: 1/4/2014 3:47:32 PM - Run 1

OTL by OldTimer - Version 3.2.69.0     Folder = C:\\Users\\norad\\Desktop

64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

 

4.00 Gb Total Physical Memory | 1.61 Gb Available Physical Memory | 40.32% Memory free

8.19 Gb Paging File | 5.48 Gb Available in Paging File | 66.85% Paging File free

Paging file location(s): ?:\\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)

Drive C: | 284.11 Gb Total Space | 166.72 Gb Free Space | 58.68% Space Free | Partition Type: NTFS

Drive D: | 13.98 Gb Total Space | 2.13 Gb Free Space | 15.21% Space Free | Partition Type: NTFS

Drive E: | 30.02 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

 

Computer Name: NORAD-PC | User Name: norad | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Processes (SafeList) ==========

 

PRC - [2014/01/04 15:46:05 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\norad\\Desktop\\OTL.exe

PRC - [2013/12/16 03:09:22 | 004,180,256 | ---- | M] (Conduit) -- C:\\Program Files (x86)\\SearchProtect\\SearchProtect\\bin\\cltmng.exe

PRC - [2013/12/16 03:09:22 | 002,849,056 | ---- | M] (Conduit) -- C:\\Program Files (x86)\\SearchProtect\\UI\\bin\\cltmngui.exe

PRC - [2013/12/16 03:09:22 | 002,251,552 | ---- | M] (Conduit) -- C:\\Program Files (x86)\\SearchProtect\\Main\\bin\\CltMngSvc.exe

PRC - [2013/12/04 13:46:36 | 000,273,000 | ---- | M] (Highlightly) -- C:\\Program Files (x86)\\Highlightly\\Service\\hlsvc.exe

PRC - [2013/11/11 22:02:14 | 003,478,544 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\\Program Files (x86)\\AVG\\AVG2014\\avgidsagent.exe

PRC - [2013/11/08 18:51:25 | 000,166,352 | ---- | M] (APN LLC.) -- C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\apnmcp.exe

PRC - [2013/11/08 18:51:17 | 001,707,472 | ---- | M] (APN) -- C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\Updater\\TBNotifier.exe

PRC - [2013/11/07 22:03:50 | 004,956,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\\Program Files (x86)\\AVG\\AVG2014\\avgui.exe

PRC - [2013/09/24 01:33:08 | 000,348,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\\Program Files (x86)\\AVG\\AVG2014\\avgwdsvc.exe

PRC - [2008/09/26 04:36:40 | 001,148,200 | ---- | M] (CyberLink Corp.) -- C:\\Program Files (x86)\\Hewlett-Packard\\Media\\DVD\\DVDAgent.exe

PRC - [2008/09/25 20:42:24 | 000,189,736 | ---- | M] (CyberLink) -- C:\\Program Files (x86)\\Hewlett-Packard\\TouchSmart\\Media\\Kernel\\CLML\\CLMLSvc.exe

PRC - [2008/09/25 20:41:44 | 001,152,296 | ---- | M] (CyberLink Corp.) -- C:\\Program Files (x86)\\Hewlett-Packard\\TouchSmart\\Media\\TSMAgent.exe

PRC - [2008/09/23 13:18:52 | 000,365,904 | ---- | M] () -- C:\\Program Files (x86)\\SMINST\\BLService.exe

PRC - [2008/06/19 16:04:50 | 000,014,376 | ---- | M] (Broadcom Corporation.) -- C:\\Program Files\\WIDCOMM\\Bluetooth Software\\BluetoothHeadsetProxy.exe

PRC - [1622/05/04 11:26:22 | 000,999,200 | ---- | M] (Conduit Ltd.) -- C:\\Users\\norad\\AppData\\Local\\NativeMessaging\\CT3306061\\1_0_0_6\\TBMessagingHost.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2013/12/03 20:48:04 | 000,399,312 | ---- | M] () -- C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\Application\\31.0.1650.63\\ppgooglenaclpluginchrome.dll

MOD - [2013/12/03 20:48:03 | 013,586,896 | ---- | M] () -- C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\Application\\31.0.1650.63\\PepperFlash\\pepflashplayer.dll

MOD - [2013/12/03 20:48:02 | 004,055,504 | ---- | M] () -- C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\Application\\31.0.1650.63\\pdf.dll

MOD - [2013/12/03 20:47:08 | 001,619,408 | ---- | M] () -- C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\Application\\31.0.1650.63\\ffmpegsumo.dll

MOD - [2013/10/26 14:47:18 | 000,978,944 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System.Configuration\\f453ecc6bb7fc8d52d61247676944623\\System.Configuration.ni.dll

MOD - [2013/10/18 17:04:46 | 012,434,432 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System.Windows.Forms\\73d9bc894522543b561a0342dac87c06\\System.Windows.Forms.ni.dll

MOD - [2013/10/18 17:03:44 | 014,329,856 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\PresentationFramewo#\\f228cc72a6647716127cd44ca416e6dc\\PresentationFramework.ni.dll

MOD - [2013/10/18 17:03:02 | 012,218,880 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\PresentationCore\\b2482534bee5c520cdfe9c8f7df6a92f\\PresentationCore.ni.dll

MOD - [2013/10/18 17:02:31 | 003,325,440 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\WindowsBase\\c16ade1485996fa4981edc7df436a15b\\WindowsBase.ni.dll

MOD - [2013/08/15 02:45:58 | 000,998,400 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System.Management\\e77e7cdf3072d5a658832b8863ff439e\\System.Management.ni.dll

MOD - [2013/08/15 02:44:54 | 000,771,584 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System.Runtime.Remo#\\b167ef6967ad27503c6ac6aabcef1aff\\System.Runtime.Remoting.ni.dll

MOD - [2013/08/15 02:44:52 | 000,627,712 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System.EnterpriseSe#\\5ba1ebef462c4f9cb1a8fe05c0419d0e\\System.EnterpriseServices.ni.dll

MOD - [2013/08/15 02:44:52 | 000,627,200 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System.Transactions\\9e0ade6fc2bcb5fbd4c8978bf92784a3\\System.Transactions.ni.dll

MOD - [2013/08/15 02:44:52 | 000,280,064 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System.EnterpriseSe#\\5ba1ebef462c4f9cb1a8fe05c0419d0e\\System.EnterpriseServices.Wrapper.dll

MOD - [2013/08/15 02:38:19 | 005,462,016 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System.Xml\\09f5b3f7a363b742a73937e818595597\\System.Xml.ni.dll

MOD - [2013/08/15 02:37:56 | 001,593,344 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System.Drawing\\c0df7e124d8d5e2821fd7d3921d404f7\\System.Drawing.ni.dll

MOD - [2013/08/15 02:37:43 | 006,622,208 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System.Data\\1eff630f4194c74287d1dd4a859693f7\\System.Data.ni.dll

MOD - [2013/08/15 02:36:46 | 007,977,984 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\System\\d7153acb7b6ccb5a6a886d6f0ab732b1\\System.ni.dll

MOD - [2013/07/10 02:53:35 | 000,368,128 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\PresentationFramewo#\\af7b745f6a06b800c73f1556553fe331\\PresentationFramework.Aero.ni.dll

MOD - [2013/07/10 02:52:54 | 011,497,984 | ---- | M] () -- C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\mscorlib\\6a938df70a8b7996a3890b4f34c83906\\mscorlib.ni.dll

MOD - [2011/11/01 23:26:32 | 000,087,912 | ---- | M] () -- C:\\Program Files (x86)\\Common Files\\Apple\\Apple Application Support\\zlib1.dll

MOD - [2011/11/01 23:26:12 | 001,242,472 | ---- | M] () -- C:\\Program Files (x86)\\Common Files\\Apple\\Apple Application Support\\libxml2.dll

MOD - [2009/04/11 00:28:21 | 000,368,640 | ---- | M] () -- C:\\Windows\\SysWOW64\\msjetoledb40.dll

MOD - [2009/04/10 20:04:15 | 000,113,664 | ---- | M] () -- C:\\Windows\\assembly\\GAC_32\\System.EnterpriseServices\\2.0.0.0__b03f5f7f11d50a3a\\System.EnterpriseServices.Wrapper.dll

MOD - [2009/03/29 22:42:19 | 000,261,632 | ---- | M] () -- C:\\Windows\\assembly\\GAC_32\\System.Transactions\\2.0.0.0__b77a5c561934e089\\System.Transactions.dll

MOD - [2009/03/29 22:42:17 | 002,933,760 | ---- | M] () -- C:\\Windows\\assembly\\GAC_32\\System.Data\\2.0.0.0__b77a5c561934e089\\System.Data.dll

MOD - [2008/09/30 17:56:06 | 000,032,768 | ---- | M] () -- C:\\Program Files (x86)\\Hewlett-Packard\\HP Advisor\\Content.XmlSerializers.dll

MOD - [2008/09/30 17:52:02 | 000,007,168 | ---- | M] () -- C:\\Program Files (x86)\\Hewlett-Packard\\HP Advisor\\RemotingClient.dll

MOD - [2008/09/30 17:52:00 | 000,057,344 | ---- | M] () -- C:\\Program Files (x86)\\Hewlett-Packard\\HP Advisor\\Pillars\\PCAlerts\\PCAlertsPillar.dll

MOD - [2008/09/30 17:51:52 | 000,118,784 | ---- | M] () -- C:\\Program Files (x86)\\Hewlett-Packard\\HP Advisor\\ECLibrary.dll

MOD - [2008/09/30 17:51:52 | 000,010,240 | ---- | M] () -- C:\\Program Files (x86)\\Hewlett-Packard\\HP Advisor\\MessagingClients.dll

MOD - [2008/09/30 17:51:36 | 000,040,960 | ---- | M] () -- C:\\Program Files (x86)\\Hewlett-Packard\\HP Advisor\\MessagingServer.dll

MOD - [2008/09/30 17:51:36 | 000,028,672 | ---- | M] () -- C:\\Program Files (x86)\\Hewlett-Packard\\HP Advisor\\MessagingMessages.dll

MOD - [2008/09/30 17:51:36 | 000,005,632 | ---- | M] () -- C:\\Program Files (x86)\\Hewlett-Packard\\HP Advisor\\MessagingInterface.dll

MOD - [2008/09/25 20:42:26 | 000,881,960 | ---- | M] () -- C:\\Program Files (x86)\\Hewlett-Packard\\TouchSmart\\Media\\Kernel\\CLML\\CLMediaLibrary.dll

MOD - [2008/06/29 17:10:18 | 000,028,672 | ---- | M] () -- C:\\Program Files (x86)\\CyberLink\\Shared files\\richvideops.dll

 

 

========== Services (SafeList) ==========

 

SRV:64bit: - [2010/01/21 16:24:56 | 000,130,048 | ---- | M] (WDC) [Auto | Running] -- C:\\Program Files\\Western Digital\\WD SmartWare\\WD Drive Manager\\WDDMService.exe -- (WDDMService)

SRV:64bit: - [2008/09/11 05:53:00 | 000,279,040 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\\Windows\\SysNative\\DriverStore\\FileRepository\\stwrt64.inf_bd5387da\\STacSV64.exe -- (STacSV)

SRV:64bit: - [2008/06/27 09:53:06 | 000,089,088 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\\Windows\\SysNative\\DriverStore\\FileRepository\\stwrt64.inf_bd5387da\\AESTSr64.exe -- (AESTFilters)

SRV:64bit: - [2008/03/18 18:25:40 | 000,023,040 | ---- | M] (Hewlett-Packard Corporation) [Auto | Running] -- C:\\Windows\\SysNative\\Hpservice.exe -- (hpsrv)

SRV:64bit: - [2008/01/20 20:47:32 | 000,383,544 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)

SRV:64bit: - [2007/12/11 14:11:30 | 000,015,872 | ---- | M] (Agere Systems) [Auto | Running] -- C:\\Windows\\SysNative\\agr64svc.exe -- (AgereModemAudio)

SRV - [2013/12/28 12:22:39 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)

SRV - [2013/12/16 03:09:22 | 002,251,552 | ---- | M] (Conduit) [Auto | Running] -- C:\\Program Files (x86)\\SearchProtect\\Main\\bin\\CltMngSvc.exe -- (CltMngSvc)

SRV - [2013/12/04 13:46:36 | 000,273,000 | ---- | M] (Highlightly) [Auto | Running] -- C:\\Program Files (x86)\\Highlightly\\Service\\hlsvc.exe -- (hlsvc)

SRV - [2013/11/11 22:02:14 | 003,478,544 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\\Program Files (x86)\\AVG\\AVG2014\\avgidsagent.exe -- (AVGIDSAgent)

SRV - [2013/11/08 18:51:25 | 000,166,352 | ---- | M] (APN LLC.) [Auto | Running] -- C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\apnmcp.exe -- (APNMCP)

SRV - [2013/09/24 01:33:08 | 000,348,008 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\\Program Files (x86)\\AVG\\AVG2014\\avgwdsvc.exe -- (avgwd)

SRV - [2013/06/21 08:53:36 | 000,162,408 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\\Program Files (x86)\\Skype\\Updater\\Updater.exe -- (SkypeUpdate)

SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)

SRV - [2009/06/16 08:58:08 | 000,020,480 | ---- | M] (Memeo) [Auto | Running] -- C:\\Program Files (x86)\\Western Digital\\WD SmartWare\\Front Parlor\\WDSmartWareBackgroundService.exe -- (WDSmartWareBackgroundService)

SRV - [2009/03/29 22:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2008/09/23 13:18:52 | 000,365,904 | ---- | M] () [Auto | Running] -- C:\\Program Files (x86)\\SMINST\\BLService.exe -- (Recovery Service for Windows)

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - [2013/12/04 13:46:36 | 000,058,256 | ---- | M] (Highlightly) [Kernel | System | Running] -- C:\\Windows\\SysNative\\drivers\\hlnfd.sys -- (hlnfd)

DRV:64bit: - [2013/11/05 21:55:48 | 000,150,808 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\\Windows\\SysNative\\DRIVERS\\avgdiska.sys -- (Avgdiska)

DRV:64bit: - [2013/11/04 21:52:42 | 000,240,920 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\\Windows\\SysNative\\DRIVERS\\avgidsdrivera.sys -- (AVGIDSDriver)

DRV:64bit: - [2013/10/31 23:00:18 | 000,212,280 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\\Windows\\SysNative\\DRIVERS\\avgldx64.sys -- (Avgldx64)

DRV:64bit: - [2013/10/31 22:49:46 | 000,294,712 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\\Windows\\SysNative\\DRIVERS\\avgloga.sys -- (Avgloga)

DRV:64bit: - [2013/10/24 22:25:58 | 000,194,872 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\\Windows\\SysNative\\DRIVERS\\avgidsha.sys -- (AVGIDSHA)

DRV:64bit: - [2013/10/01 00:52:08 | 000,123,704 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\\Windows\\SysNative\\DRIVERS\\avgmfx64.sys -- (Avgmfx64)

DRV:64bit: - [2013/09/10 00:43:02 | 000,031,544 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\\Windows\\SysNative\\DRIVERS\\avgrkx64.sys -- (Avgrkx64)

DRV:64bit: - [2013/08/01 16:07:06 | 000,251,192 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\\Windows\\SysNative\\DRIVERS\\avgtdia.sys -- (Avgtdia)

DRV:64bit: - [2012/12/13 12:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\Drivers\\usbaapl64.sys -- (USBAAPL64)

DRV:64bit: - [2012/08/21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\GEARAspiWDM.sys -- (GEARAspiWDM)

DRV:64bit: - [2012/02/29 07:52:46 | 000,016,384 | ---- | M] (Microsoft Corporation) [Recognizer | System | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2009/09/30 18:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\DRIVERS\\wpdusb.sys -- (WpdUsb)

DRV:64bit: - [2009/03/31 10:26:20 | 005,430,272 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\NETw5v64.sys -- (NETw5v64)

DRV:64bit: - [2009/02/13 11:02:52 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\DRIVERS\\wdcsam64.sys -- (WDC_SAM)

DRV:64bit: - [2008/09/11 05:54:44 | 000,465,408 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\stwrt64.sys -- (STHDA)

DRV:64bit: - [2008/08/05 21:29:26 | 000,056,352 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\nvhda64v.sys -- (NVHDA)

DRV:64bit: - [2008/07/22 09:42:34 | 000,170,496 | ---- | M] (Realtek Corporation                                            ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\Rtlh64.sys -- (RTL8169)

DRV:64bit: - [2008/07/21 04:53:04 | 000,145,496 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\jmcr.sys -- (JMCR)

DRV:64bit: - [2008/06/23 05:54:02 | 000,099,368 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\btwavdt.sys -- (btwavdt)

DRV:64bit: - [2008/06/23 05:54:02 | 000,091,176 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\btwaudio.sys -- (btwaudio)

DRV:64bit: - [2008/06/23 05:54:02 | 000,019,752 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\btwrchid.sys -- (btwrchid)

DRV:64bit: - [2008/04/28 19:55:32 | 000,064,000 | ---- | M] (ENE TECHNOLOGY INC.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\enecir.sys -- (enecir)

DRV:64bit: - [2008/03/27 14:10:56 | 000,026,984 | ---- | M] (Hewlett-Packard Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\DRIVERS\\hpdskflt.sys -- (hpdskflt)

DRV:64bit: - [2008/03/27 14:10:14 | 000,040,296 | ---- | M] (Hewlett-Packard Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\Accelerometer.sys -- (Accelerometer)

DRV:64bit: - [2008/02/29 17:59:32 | 001,252,352 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\agrsm64.sys -- (AgereSoftModem)

DRV:64bit: - [2008/01/20 20:47:25 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\serscan.sys -- (StillCam)

DRV:64bit: - [2008/01/20 20:46:57 | 003,154,432 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\DRIVERS\\NETw3v64.sys -- (NETw3v64)

DRV:64bit: - [2008/01/20 20:46:55 | 000,111,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\DRIVERS\\sdbus.sys -- (sdbus)

DRV:64bit: - [2008/01/18 05:31:30 | 000,320,560 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\SynTP.sys -- (SynTP)

DRV:64bit: - [2007/06/18 18:13:12 | 000,018,432 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\DRIVERS\\HpqKbFiltr.sys -- (HpqKbFiltr)

DRV:64bit: - [2006/10/03 19:45:36 | 000,273,408 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\DRIVERS\\yk60x64.sys -- (yukonx64)

DRV - [2008/09/26 04:36:34 | 000,027,632 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- C:\\Program Files (x86)\\Hewlett-Packard\\Media\\DVD\\000.fcl -- ({55662437-DA8C-40c0-AADA-2C816A897A49})

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 



IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope = {5D9FA932-8D8C-40EC-9192-A538B6854A52}

IE:64bit: - HKLM\\..\\SearchScopes\\{3CF2481F-854A-41B7-9CDF-7113C60591B3}: \"URL\" = http://www.ask.com/web?q=\'>http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl

IE:64bit: - HKLM\\..\\SearchScopes\\{5D9FA932-8D8C-40EC-9192-A538B6854A52}: \"URL\" = http://search.live.com/results.aspx?q=\'>http://search.live.com/results.aspx?q={searchTerms}&FORM=HPNTDF


IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm


IE - HKLM\\..\\URLSearchHook: {d1b5aad5-d1ae-4b20-88b1-feeaeb4c1ebc} - C:\\Program Files (x86)\\Connect_DLC_5\\prxtbConn.dll (Conduit Ltd.)

IE - HKLM\\..\\SearchScopes,DefaultScope = {3E37E123-445C-4848-8E34-279F96B6BD39}

IE - HKLM\\..\\SearchScopes\\{3CF2481F-854A-41B7-9CDF-7113C60591B3}: \"URL\" = http://www.ask.com/web?q=\'>http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl

IE - HKLM\\..\\SearchScopes\\{5815a829-6908-46b0-8b10-0036b333371e}: \"URL\" = http://search.conduit.com/ResultsExt.aspx?q=\'>http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3309767&CUI=UN11379035163226023&UM=2

IE - HKLM\\..\\SearchScopes\\{5D9FA932-8D8C-40EC-9192-A538B6854A52}: \"URL\" = http://search.live.com/results.aspx?q=\'>http://search.live.com/results.aspx?q={searchTerms}&FORM=HPNTDF

 

 

IE - HKU\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

 

IE - HKU\\S-1-5-18\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

 

 

 

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb\'>http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = http://search.conduit.com/?ctid=CT3306061&octid=EB_ORIGINAL_CTID&SearchSource=61&CUI=UN60480715371022752&UM=2&UP=SPCBA30609-FFB3-46F8-89FC-F54D4DAAD445&S41CIE%C2\'>

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,StartPageCache = 1

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\URLSearchHook: {d1b5aad5-d1ae-4b20-88b1-feeaeb4c1ebc} - C:\\Program Files (x86)\\Connect_DLC_5\\prxtbConn.dll (Conduit Ltd.)

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\URLSearchHook: {D8278076-BC68-4484-9233-6E7F1628B56C} - C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\searchhook.dll (APN LLC.)

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\SearchScopes,DefaultScope = {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\SearchScopes\\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}: \"URL\" = http://search.conduit.com/Results.aspx?ctid=CT3306061&octid=EB_ORIGINAL_CTID&SearchSource=62&CUI=UN60480715371022752&UM=2&UP=SPCBA30609-FFB3-46F8-89FC-F54D4DAAD445&q={searchTerms}&S41CIE

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\SearchScopes\\{3CF2481F-854A-41B7-9CDF-7113C60591B3}: \"URL\" = http://www.ask.com/web?q=\'>http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\SearchScopes\\{3E37E123-445C-4848-8E34-279F96B6BD39}: \"URL\" = http://search.conduit.com/ResultsExt.aspx?q=\'>http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3306061&CUI=UN60480715371022752&UM=2&SSPV=S41CIE

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\SearchScopes\\{5815a829-6908-46b0-8b10-0036b333371e}: \"URL\" = http://search.conduit.com/ResultsExt.aspx?q=\'>http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3309767&CUI=UN11379035163226023&UM=2

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\SearchScopes\\{5D9FA932-8D8C-40EC-9192-A538B6854A52}: \"URL\" = http://www.bing.com/search?q=\'>http://www.bing.com/search?q={searchTerms}&FORM=HPNTDF&pc=HPNTDF&src=IE-SearchBox


IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0

IE - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyOverride\" = *.local

 

========== FireFox ==========

 

FF - prefs.js..CT3309759.browser.search.defaultthis.engineName: \"true\"

FF - prefs.js..browser.search.defaultthis.engineName: \"Swirlz Customized Web Search\"


FF - prefs.js..browser.search.useDBForOrder: true

FF - prefs.js..extensions.enabledAddons: 39e612de-2951-40c2-ab4a-82e121c42778%404e0cecc2-7c67-4374-bc4c-f15656d80ab7.com:0.93.119

FF - prefs.js..extensions.enabledAddons: %7B4cb3c467-0d72-44e6-9237-750b9b8b5ac9%7D:10.23.0.726

FF - prefs.js..extensions.enabledAddons: %7B635abd67-4fe9-1b23-4f01-e679fa7484c1%7D:3.1.0.20130818030116

FF - prefs.js..extensions.enabledAddons: gethighlightly%40gethighlightly.com:1.9.0.0

FF - prefs.js..extensions.enabledAddons: 0c3e9649-324d-4df0-a61e-7ac31aead042%402612bb82-5f8a-49b2-a299-348e707310fc.com:0.93.148

FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:26.0

FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198

FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24

 

 

FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_9_900_170.dll File not found

FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_9_900_170.dll ()

FF - HKLM\\Software\\MozillaPlugins\\@Apple.com/iTunes,version=:  File not found

FF - HKLM\\Software\\MozillaPlugins\\@Apple.com/iTunes,version=1.0: C:\\Program Files (x86)\\iTunes\\Mozilla Plugins\\npitunes.dll ()

FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.45.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\dtplugin\\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin: C:\\Program Files (x86)\\Java\\jre7\\bin\\new_plugin\\npjp2.dll File not found

FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.45.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@Microsoft.com/NpCtrl,version=1.0: c:\\Program Files (x86)\\Microsoft Silverlight\\5.1.20913.0\\npctrl.dll ( Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/WPF,version=3.5: c:\\Windows\\Microsoft.NET\\Framework\\v3.5\\Windows Presentation Foundation\\NPWPF.dll (Microsoft Corporation)

FF - HKLM\\Software\\MozillaPlugins\\Adobe Reader: C:\\Program Files (x86)\\Adobe\\Reader 9.0\\Reader\\AIR\\nppdf32.dll (Adobe Systems Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=3: C:\\Users\\norad\\AppData\\Local\\Google\\Update\\1.3.22.3\\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\\Software\\MozillaPlugins\\@tools.google.com/Google Update;version=9: C:\\Users\\norad\\AppData\\Local\\Google\\Update\\1.3.22.3\\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Hewlett-Packard\\SmartPrint\\QPExtension [2011/01/26 14:27:28 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\[email protected]: C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\[email protected] [2013/12/28 12:57:48 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Thunderbird\\Extensions\\\\[email protected]: C:\\Program Files\\ESET\\ESET NOD32 Antivirus\\Mozilla Thunderbird

FF - HKEY_CURRENT_USER\\software\\mozilla\\Firefox\\EXTENSIONS\\\\{57c20073-e24b-4b2a-aa91-70d1ad526cbf}: C:\\Program Files (x86)\\PassShow\\150.xpi [2013/12/29 15:32:22 | 000,011,866 | ---- | M] ()

FF - HKEY_CURRENT_USER\\software\\mozilla\\Firefox\\EXTENSIONS\\\\{B21F5E31-B8E8-41CD-B74C-168A71A10E49}: C:\\Users\\norad\\AppData\\Local\\GreatArcadeHits\\{B21F5E31-B8E8-41CD-B74C-168A71A10E49}\\ [2013/12/29 15:32:54 | 000,000,000 | ---D | M]

 

[2009/06/07 10:30:08 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Extensions

[2013/12/29 14:00:45 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions

[2010/05/25 18:25:57 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\{20a82645-c095-46ed-80e3-08825760534b}

[2013/12/28 12:25:02 | 000,000,000 | ---D | M] (Swirlz) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\{4cb3c467-0d72-44e6-9237-750b9b8b5ac9}

[2013/08/23 16:34:48 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\{635abd67-4fe9-1b23-4f01-e679fa7484c1}

[2013/12/28 11:41:17 | 000,000,000 | ---D | M] (\"weDownload Manager\") -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\0c3e9649-324d-4df0-a61e-7ac31aead042@2612bb82-5f8a-49b2-a299-348e707310fc.com

[2013/12/28 12:12:33 | 000,000,000 | ---D | M] (\"Plus-HD-1.2\") -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\39e612de-2951-40c2-ab4a-82e121c42778@4e0cecc2-7c67-4374-bc4c-f15656d80ab7.com

[2013/12/29 13:51:22 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\0c3e9649-324d-4df0-a61e-7ac31aead042@2612bb82-5f8a-49b2-a299-348e707310fc.com\\extensionData

[2013/12/29 13:51:22 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\0c3e9649-324d-4df0-a61e-7ac31aead042@2612bb82-5f8a-49b2-a299-348e707310fc.com\\extensionData\\plugins

[2013/12/29 13:51:22 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\0c3e9649-324d-4df0-a61e-7ac31aead042@2612bb82-5f8a-49b2-a299-348e707310fc.com\\extensionData\\userCode

[2013/12/28 11:59:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\39e612de-2951-40c2-ab4a-82e121c42778@4e0cecc2-7c67-4374-bc4c-f15656d80ab7.com\\extensionData

[2013/12/28 11:59:10 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\39e612de-2951-40c2-ab4a-82e121c42778@4e0cecc2-7c67-4374-bc4c-f15656d80ab7.com\\extensionData\\plugins

[2013/12/28 11:59:11 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\extensions\\39e612de-2951-40c2-ab4a-82e121c42778@4e0cecc2-7c67-4374-bc4c-f15656d80ab7.com\\extensionData\\userCode

[2013/07/24 17:40:12 | 000,002,546 | ---- | M] () -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\searchplugins\\ask-search.xml

[2013/12/28 11:59:04 | 000,000,975 | ---- | M] () -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\searchplugins\\conduit-search.xml

[2013/12/28 12:25:05 | 000,001,017 | ---- | M] () -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\searchplugins\\conduit.xml

[2013/12/28 12:01:03 | 000,001,368 | ---- | M] () -- C:\\Users\\norad\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\lf207zuh.default\\searchplugins\\iminent.xml

[2013/12/28 21:04:18 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions

[2013/12/28 12:57:48 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\{AB2CE124-6272-4b12-94A9-7303C7397BD1}

[2013/12/28 12:57:48 | 000,000,000 | ---D | M] () -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions\\[email protected]

[2013/12/28 12:57:48 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\browser\\extensions

[2013/12/28 12:58:03 | 000,000,000 | ---D | M] (Default) -- C:\\Program Files (x86)\\Mozilla Firefox\\browser\\extensions\\{972ce4c6-7e08-4474-a285-3208198ce6fd}

[2013/12/28 12:04:58 | 000,611,224 | ---- | M] (Oracle Corporation) -- C:\\Program Files (x86)\\mozilla firefox\\plugins\\npdeployJava1.dll

 

========== Chrome  ==========

 

CHR - default_search_provider: Conduit Search (Enabled)



CHR - Extension: Highlightly = C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\cmclajginlihohopoeofghddnhpplhom\\1.9.0.0_1\\

CHR - Extension: PassShow = C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\dhogjnnleghndloamdkljhnhdchpcijl\\1.150_0\\

CHR - Extension: Connect DLC 5 = C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lipgolpfajiadodbcbljdpmbmbdmfcil\\10.23.0.728_0\\

CHR - Extension: Connect DLC 5 = C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lipgolpfajiadodbcbljdpmbmbdmfcil\\10.23.0.728_0\\nativeMessaging\\nmHost

CHR - Extension: Swirlz = C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lmcedemcahkmaidbipmniofjcocajlgk\\10.24.3.503_0\\

CHR - Extension: Swirlz = C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\lmcedemcahkmaidbipmniofjcocajlgk\\10.24.3.503_0\\nativeMessaging\\nmHost

CHR - Extension: Google Wallet = C:\\Users\\norad\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda\\0.0.6.0_1\\

 

O1 HOSTS File: ([2006/09/18 15:37:24 | 000,000,761 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\Hosts

O1 - Hosts: 127.0.0.1       localhost

O1 - Hosts: ::1             localhost

O2:64bit: - BHO: (Plus-HD-1.2) - {11111111-1111-1111-1111-110311121155} - C:\\Program Files (x86)\\Plus-HD-1.2\\Plus-HD-1.2-bho64.dll File not found

O2:64bit: - BHO: (weDownload Manager) - {11111111-1111-1111-1111-110311431144} - C:\\Program Files (x86)\\weDownload Manager\\weDownload Manager-bho64.dll File not found

O2:64bit: - BHO: (Ask Toolbar) - {4F524A2D-5637-4300-76A7-7A786E7484D7} - C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\ORJ-V7C\\Passport_x64.dll (APN LLC.)

O2:64bit: - BHO: (Highlightly) - {83F2328D-0D6A-42B4-B0C4-02A929EDD4BE} - C:\\Program Files\\Highlightly\\IE\\HighlightlyClientIE.dll (Highlightly)

O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\\Program Files (x86)\\Hp\\Smart Web Printing\\hpswp_framework.dll (Hewlett-Packard Co.)

O2 - BHO: (PassShow) - {2d661e5b-7d7a-417c-b5b5-6479017bb314} - C:\\Program Files (x86)\\PassShow\\150.dll ()

O2 - BHO: (Ask Toolbar) - {4F524A2D-5637-4300-76A7-7A786E7484D7} - C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\ORJ-V7C\\Passport.dll (APN LLC.)

O2 - BHO: (Highlightly) - {83F2328D-0D6A-42B4-B0C4-02A929EDD4BE} - C:\\Program Files (x86)\\Highlightly\\IE\\HighlightlyClientIE.dll (Highlightly)

O2 - BHO: (GreatArcadeHits Add-on) - {D0C21091-FF8E-432C-9006-0540E81BA9D7} - C:\\Users\\norad\\AppData\\Local\\GreatArcadeHits\\GreatArcadeHitsIE.dll (GreatArcadeHits)

O2 - BHO: (Connect DLC 5 Toolbar) - {d1b5aad5-d1ae-4b20-88b1-feeaeb4c1ebc} - C:\\Program Files (x86)\\Connect_DLC_5\\prxtbConn.dll (Conduit Ltd.)

O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\\Program Files (x86)\\MSN\\Toolbar\\3.0.0541.0\\msneshellx.dll (Microsoft Corp.)

O3:64bit: - HKLM\\..\\Toolbar: (Ask Toolbar) - {4F524A2D-5637-4300-76A7-7A786E7484D7} - C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\ORJ-V7C\\Passport_x64.dll (APN LLC.)

O3 - HKLM\\..\\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\\Program Files (x86)\\MSN\\Toolbar\\3.0.0541.0\\msneshellx.dll (Microsoft Corp.)

O3 - HKLM\\..\\Toolbar: (Ask Toolbar) - {4F524A2D-5637-4300-76A7-7A786E7484D7} - C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\ORJ-V7C\\Passport.dll (APN LLC.)

O3 - HKLM\\..\\Toolbar: (Connect DLC 5 Toolbar) - {d1b5aad5-d1ae-4b20-88b1-feeaeb4c1ebc} - C:\\Program Files (x86)\\Connect_DLC_5\\prxtbConn.dll (Conduit Ltd.)

O3:64bit: - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\Toolbar\\WebBrowser: (Ask Toolbar) - {4F524A2D-5637-4300-76A7-7A786E7484D7} - C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\ORJ-V7C\\Passport_x64.dll (APN LLC.)

O3 - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\Toolbar\\WebBrowser: (Ask Toolbar) - {4F524A2D-5637-4300-76A7-7A786E7484D7} - C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\ORJ-V7C\\Passport.dll (APN LLC.)

O3 - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..\\Toolbar\\WebBrowser: (Connect DLC 5 Toolbar) - {D1B5AAD5-D1AE-4B20-88B1-FEEAEB4C1EBC} - C:\\Program Files (x86)\\Connect_DLC_5\\prxtbConn.dll (Conduit Ltd.)

O4:64bit: - HKLM..\\Run: [NvCplDaemon] C:\\Windows\\SysNative\\NvCpl.dll (NVIDIA Corporation)

O4:64bit: - HKLM..\\Run: [NvMediaCenter] C:\\Windows\\SysNative\\NvMcTray.dll (NVIDIA Corporation)

O4:64bit: - HKLM..\\Run: [SmartMenu] C:\\Program Files\\Hewlett-Packard\\HP MediaSmart\\SmartMenu.exe (Hewlett-Packard)

O4:64bit: - HKLM..\\Run: [SysTrayApp] C:\\Program Files\\IDT\\WDM\\sttray64.exe (IDT, Inc.)

O4 - HKLM..\\Run: [ApnTBMon] C:\\Program Files (x86)\\AskPartnerNetwork\\Toolbar\\Updater\\TBNotifier.exe (APN)

O4 - HKLM..\\Run: [APSDaemon] C:\\Program Files (x86)\\Common Files\\Apple\\Apple Application Support\\APSDaemon.exe (Apple Inc.)

O4 - HKLM..\\Run: [AVG_UI] C:\\Program Files (x86)\\AVG\\AVG2014\\avgui.exe (AVG Technologies CZ, s.r.o.)

O4 - HKLM..\\Run: [CLMLServer for HP TouchSmart] C:\\Program Files (x86)\\Hewlett-Packard\\TouchSmart\\Media\\Kernel\\CLML\\CLMLSvc.exe (CyberLink)

O4 - HKLM..\\Run: [DVDAgent] C:\\Program Files (x86)\\Hewlett-Packard\\Media\\DVD\\DVDAgent.exe (CyberLink Corp.)

O4 - HKLM..\\Run: [HP Health Check Scheduler] c:\\Program Files (x86)\\Hewlett-Packard\\HP Health Check\\HPHC_Scheduler.exe (Hewlett-Packard)

O4 - HKLM..\\Run: [mobilegeni daemon] \"C:\\Program Files (x86)\\Mobogenie\\DaemonProcess.exe\" File not found

O4 - HKLM..\\Run: [TSMAgent] C:\\Program Files (x86)\\Hewlett-Packard\\TouchSmart\\Media\\TSMAgent.exe (CyberLink Corp.)

O4 - HKLM..\\Run: [UCam_Menu] C:\\Program Files (x86)\\Hewlett-Packard\\Media\\Webcam\\MUITransfer\\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKLM..\\Run: [UpdateLBPShortCut] C:\\Program Files (x86)\\CyberLink\\LabelPrint\\MUITransfer\\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKLM..\\Run: [UpdateP2GoShortCut] C:\\Program Files (x86)\\CyberLink\\Power2Go\\MUITransfer\\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKLM..\\Run: [UpdatePDIRShortCut] C:\\Program Files (x86)\\CyberLink\\PowerDirector\\MUITransfer\\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKLM..\\Run: [UpdatePSTShortCut] C:\\Program Files (x86)\\CyberLink\\DVD Suite\\MUITransfer\\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKU\\S-1-5-19..\\Run: [Sidebar] C:\\Program Files (x86)\\Windows Sidebar\\Sidebar.exe (Microsoft Corporation)

O4 - HKU\\S-1-5-19..\\Run: [WindowsWelcomeCenter] C:\\Windows\\SysWow64\\oobefldr.dll (Microsoft Corporation)

O4 - HKU\\S-1-5-20..\\Run: [Sidebar] C:\\Program Files (x86)\\Windows Sidebar\\Sidebar.exe (Microsoft Corporation)

O4 - HKU\\S-1-5-20..\\Run: [WindowsWelcomeCenter] C:\\Windows\\SysWow64\\oobefldr.dll (Microsoft Corporation)

O4 - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000..\\Run: [AVG-Secure-Search-Update_1213b] C:\\Users\\norad\\AppData\\Roaming\\AVG 1213b Campaign\\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=8fab85a0119147d38b19d16d38c0aeb6-f4a11d3e10dbebc28f3e5788a17788f15546486a /CMPID=1213b File not found

O4 - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000..\\Run: [HP Photosmart 6510 series (NET)] C:\\Program Files\\HP\\HP Photosmart 6510 series\\Bin\\ScanToPCActivationApp.exe (Hewlett-Packard Co.)

O4 - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000..\\Run: [NextLive] C:\\Users\\norad\\AppData\\Roaming\\newnext.me\\nengine.dll (NewNextDotMe)

O4 - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000..\\Run: [WMPNSCFG] C:\\Program Files (x86)\\Windows Media Player\\WMPNSCFG.exe File not found

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktop = 1

O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoActiveDesktopChanges = 1

O8:64bit: - Extra context menu item: Send image to &Bluetooth Device... - C:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie_ctx.htm ()

O8:64bit: - Extra context menu item: Send page to &Bluetooth Device... - C:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie.htm ()

O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie_ctx.htm ()

O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie.htm ()

O9:64bit: - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie.htm ()

O9:64bit: - Extra \'Tools\' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie.htm ()

O9 - Extra Button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\\Program Files (x86)\\Hewlett-Packard\\SmartPrint\\smartprintsetup.exe (Hewlett-Packard)

O9 - Extra \'Tools\' menuitem : SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\\Program Files (x86)\\Hewlett-Packard\\SmartPrint\\smartprintsetup.exe (Hewlett-Packard)

O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\\Program Files (x86)\\Hp\\Smart Web Printing\\hpswp_extensions.dll (Hewlett-Packard Co.)

O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\\Program Files (x86)\\Hp\\Smart Web Printing\\hpswp_extensions.dll (Hewlett-Packard Co.)

O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie.htm ()

O9 - Extra \'Tools\' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\\Program Files\\WIDCOMM\\Bluetooth Software\\btsendto_ie.htm ()

O10:64bit: - NameSpace_Catalog5\\Catalog_Entries64\\000000000008 [] - C:\\Program Files\\Bonjour\\mdnsNSP.dll (Apple Inc.)

O10 - NameSpace_Catalog5\\Catalog_Entries\\000000000008 [] - C:\\Program Files (x86)\\Bonjour\\mdnsNSP.dll (Apple Inc.)

O1364bit: - gopher Prefix: missing

O13 - gopher Prefix: missing

O15 - HKU\\.DEFAULT\\..Trusted Ranges: Range1 ([http] in Local intranet)

O15 - HKU\\S-1-5-18\\..Trusted Ranges: Range1 ([http] in Local intranet)

O15 - HKU\\S-1-5-21-4000507275-1486089171-1974680742-1000\\..Trusted Ranges: Range1 ([http] in Local intranet)


O16 - DPF: {983A9C21-8207-4B58-BBB8-0EBC3D7C5505} https://unkmail2.unk.edu/dwa8W.cab\'>https://unkmail2.unk.edu/dwa8W.cab (Domino Web Access 8 Control)



O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab\'>http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters: DhcpNameServer = 66.168.128.20 24.205.224.36 68.190.192.35

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{848D19DE-381B-4946-AF29-2D20A8A1E0E7}: DhcpNameServer = 66.168.128.20 24.205.224.36 68.190.192.35

O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{BF6E039F-8812-49D9-8155-4B5EDD4B4032}: DhcpNameServer = 74.40.74.40 74.40.74.41 192.168.254.254

O18:64bit: - Protocol\\Handler\\ms-help - No CLSID value found

O18:64bit: - Protocol\\Handler\\ms-itss - No CLSID value found

O18:64bit: - Protocol\\Handler\\skype4com - No CLSID value found

O18 - Protocol\\Handler\\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\Program Files (x86)\\Common Files\\Skype\\Skype4COM.dll (Skype Technologies)

O20:64bit: - AppInit_DLLs: (C:\\PROGRA~2\\SearchProtect\\SearchProtect\\bin\\SPVC64Loader.dll) - C:\\Program Files (x86)\\SearchProtect\\SearchProtect\\bin\\SPVC64Loader.dll (Conduit)

O20:64bit: - AppInit_DLLs: (C:\\PROGRA~2\\OPTIMI~1\\OPTPRO~2.DLL) -  File not found

O20 - AppInit_DLLs: (c:\\progra~2\\searchprotect\\searchprotect\\bin\\spvc32loader.dll) - c:\\Program Files (x86)\\SearchProtect\\SearchProtect\\bin\\SPVC32Loader.dll (Conduit)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysNative\\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\\Windows\\SysWow64\\userinit.exe (Microsoft Corporation)

O24 - Desktop WallPaper: C:\\Users\\norad\\AppData\\Roaming\\Microsoft\\Windows Photo Gallery\\Windows Photo Gallery Wallpaper.jpg

O24 - Desktop BackupWallPaper: C:\\Users\\norad\\AppData\\Roaming\\Microsoft\\Windows Photo Gallery\\Windows Photo Gallery Wallpaper.jpg

O32 - HKLM CDRom: AutoRun - 1

O33 - MountPoints2\\{2e6a7335-2dc0-11de-be65-00247e244745}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{2e6a7335-2dc0-11de-be65-00247e244745}\\Shell\\AutoRun\\command - \"\" = F:\\LaunchU3.exe -a

O33 - MountPoints2\\{30da73e7-f32e-11df-b660-00247e244745}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{30da73e7-f32e-11df-b660-00247e244745}\\Shell\\AutoRun\\command - \"\" = G:\\LaunchU3.exe -a

O33 - MountPoints2\\{d4c18fac-d416-11df-91d0-00247e244745}\\Shell - \"\" = AutoRun

O33 - MountPoints2\\{d4c18fac-d416-11df-91d0-00247e244745}\\Shell\\AutoRun\\command - \"\" = \"G:\\WD SmartWare.exe\" autoplay=true

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\\..comfile [open] -- \"%1\" %*

O35:64bit: - HKLM\\..exefile [open] -- \"%1\" %*

O35 - HKLM\\..comfile [open] -- \"%1\" %*

O35 - HKLM\\..exefile [open] -- \"%1\" %*

O37:64bit: - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37:64bit: - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O37 - HKLM\\...com [@ = comfile] -- \"%1\" %*

O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

 

========== Files/Folders - Created Within 30 Days ==========

 

[2014/01/04 15:46:02 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\norad\\Desktop\\OTL.exe

[2013/12/29 19:47:58 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Trend Micro

[2013/12/29 19:47:58 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\HiJackThis

[2013/12/29 15:33:29 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\.android

[2013/12/29 15:33:26 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\cache

[2013/12/29 15:33:23 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Roaming\\newnext.me

[2013/12/29 15:33:22 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\genienext

[2013/12/29 15:33:20 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\Documents\\Mobogenie

[2013/12/29 15:33:20 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\Mobogenie

[2013/12/29 15:32:54 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\GreatArcadeHits

[2013/12/29 15:32:35 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Roaming\\AVG2014

[2013/12/29 15:32:22 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\PassShow

[2013/12/29 15:31:15 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Connect_DLC_5

[2013/12/29 15:30:46 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\AVG

[2013/12/29 15:30:43 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Roaming\\TuneUp Software

[2013/12/29 15:28:08 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\ToniArts

[2013/12/29 15:28:08 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\EasyCleaner

[2013/12/29 15:27:15 | 000,000,000 | -H-D | C] -- C:\\$AVG

[2013/12/29 15:27:15 | 000,000,000 | ---D | C] -- C:\\ProgramData\\AVG2014

[2013/12/29 15:25:03 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\AVG

[2013/12/29 15:22:20 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\MFAData

[2013/12/29 15:22:20 | 000,000,000 | ---D | C] -- C:\\ProgramData\\MFAData

[2013/12/29 15:22:20 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\Avg2014

[2013/12/29 15:16:18 | 000,264,616 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaws.exe

[2013/12/29 15:16:18 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\javaw.exe

[2013/12/29 15:16:18 | 000,174,504 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\java.exe

[2013/12/29 15:13:51 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Licenses

[2013/12/29 15:13:43 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\SpywareBlaster

[2013/12/29 15:13:39 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\SpywareBlaster

[2013/12/29 15:13:27 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\SearchProtect

[2013/12/29 15:12:11 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\sweetpacks bundle uninstaller

[2013/12/29 15:03:33 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\AskPartnerNetwork

[2013/12/29 15:02:52 | 000,000,000 | ---D | C] -- C:\\ProgramData\\AskPartnerNetwork

[2013/12/29 15:02:52 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\AskPartnerNetwork

[2013/12/29 15:00:54 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Oracle

[2013/12/29 14:59:27 | 000,096,168 | ---- | C] (Oracle Corporation) -- C:\\Windows\\SysWow64\\WindowsAccessBridge-32.dll

[2013/12/29 14:59:27 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Java

[2013/12/29 03:07:42 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\mshtmled.dll

[2013/12/29 03:07:42 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\mshtmled.dll

[2013/12/29 03:07:38 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ieui.dll

[2013/12/29 03:07:38 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ieui.dll

[2013/12/29 03:07:38 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\ieUnatt.exe

[2013/12/29 03:07:38 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\ieUnatt.exe

[2013/12/29 03:07:37 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\url.dll

[2013/12/29 03:07:37 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\url.dll

[2013/12/29 03:07:33 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\inetcpl.cpl

[2013/12/29 03:07:33 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\inetcpl.cpl

[2013/12/29 03:07:31 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\msfeeds.dll

[2013/12/29 03:07:30 | 002,334,720 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\jscript9.dll

[2013/12/29 03:07:29 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\jscript.dll

[2013/12/29 03:07:29 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\jscript.dll

[2013/12/29 03:07:29 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\vbscript.dll

[2013/12/28 21:04:19 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Roaming\\Activeris

[2013/12/28 21:00:29 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Roaming\\QuickScan

[2013/12/28 12:57:48 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Mozilla Firefox

[2013/12/28 12:29:59 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Roaming\\Optimizer Pro

[2013/12/28 12:26:43 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\Plus-HD-1.2

[2013/12/28 12:26:02 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Swirlz

[2013/12/28 12:26:02 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Conduit

[2013/12/28 12:25:29 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\NativeMessaging

[2013/12/28 12:25:25 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\Conduit

[2013/12/28 12:25:23 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\CRE

[2013/12/28 12:25:22 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Conduit

[2013/12/28 12:25:07 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Roaming\\SearchProtect

[2013/12/28 12:24:40 | 004,953,944 | ---- | C] (FLVMPlayer                                                  ) -- C:\\Users\\norad\\Desktop\\FLVMPlayer.exe

[2013/12/28 12:24:21 | 000,000,000 | ---D | C] -- C:\\Program Files\\Highlightly

[2013/12/28 12:24:20 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Highlightly

[2013/12/28 12:06:37 | 000,000,000 | ---D | C] -- C:\\Program Files\\Uninstaller

[2013/12/28 12:01:37 | 000,000,000 | ---D | C] -- C:\\Program Files\\Level Quality Watcher

[2013/12/28 11:57:43 | 000,000,000 | ---D | C] -- C:\\c335b1860269ab3a89494966

[2013/12/28 11:56:39 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\SwvUpdater

[2013/12/28 11:53:45 | 000,000,000 | ---D | C] -- C:\\Users\\norad\\AppData\\Local\\SearchProtect

[2013/12/28 11:52:07 | 000,198,656 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\scrrun.dll

[2013/12/28 11:52:07 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\cscript.exe

[2013/12/28 11:52:07 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\wshom.ocx

[2013/12/28 11:52:07 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\wshom.ocx

[2013/12/28 11:52:06 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\scrrun.dll

[2013/12/28 11:52:06 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\cscript.exe

[2013/12/28 11:52:06 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysWow64\\wshcon.dll

[2013/12/28 11:51:45 | 000,079,360 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\imagehlp.dll

[2013/12/28 11:50:53 | 000,374,784 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\SysFxUI.dll

[2013/12/28 11:50:53 | 000,218,112 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\drivers\\portcls.sys

[2013/12/28 11:50:53 | 000,122,368 | ---- | C] (Microsoft Corporation) -- C:\\Windows\\SysNative\\drivers\\drmk.sys

[5 C:\\Users\\norad\\Documents\\*.tmp files -> C:\\Users\\norad\\Documents\\*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[2014/01/04 15:54:34 | 000,000,856 | ---- | M] () -- C:\\Windows\\tasks\\GoogleUpdateTaskUserS-1-5-21-4000507275-1486089171-1974680742-1000Core.job

[2014/01/04 15:46:18 | 000,003,216 | -H-- | M] () -- C:\\Windows\\SysNative\\7

9
Tech Clinic / many problems
« on: December 29, 2013, 09:02:43 PM »

well the first problem im having is my computer says rundll32 is not working when i boot up my computer. the second problem im having is my battery does not work on my laptop. when i unplug my power cord it immediately goes black and shuts down. and last when i try to do a log file it says \'for some reason your system denied write access to the host file. if any hijacked domains are in this file hijackthis may not be able to fix this. if that happens you need to edit the file yourself. to do this click start, run and type: notepad c:\\windows\\system32\\drivers\\etc\\hosts and press enter. find the line(s) hijackthis reports and delete them. save the file as \'hosts\' with quotes and reboot. for vista(which i have) simply , exit hijackthis, right click on the hijackthis icon, choos \'run as administrator\'. but i dont see a run as administrator option. and it does not allow me to get the log file either.



10
Tech Clinic / problem opening files.
« on: July 23, 2012, 05:55:59 AM »
Hey bud any ideas on this? Sorry if you're busy

11
Tech Clinic / problem opening files.
« on: July 10, 2012, 10:19:29 PM »
I didn't install it someone else did. They installed it September 9th 2011. It started happening 2 months ago

12
Tech Clinic / problem opening files.
« on: July 09, 2012, 01:04:01 AM »
Hello. i'm having trouble opening my programs and whatnot on my computer. for some reason just out of the blue all of my icons for everything changed to my icon for "vlc media player" when i right click and select a file to open a specific program it changes my icon on everything. i am only using google chrome because it has an option to go to c drive and it will have its original icon in there where i can open it up, on the desktop though it is still like the rest of the programs. here is my log.







Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:53:02 PM, on 7/8/2012
Platform: Windows 7  (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\mcafee.com\agent\mcagent.exe
C:\Program Files\EgisTec IPS\PmmUpdate.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\igfxext.exe
C:\Program Files\EgisTec IPS\EgisUpdate.exe
C:\Windows\System32\msdt.exe
C:\Windows\System32\sdiagnhost.exe
C:\Windows\system32\conhost.exe
C:\Users\Kaila\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Kaila\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Kaila\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Kaila\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Kaila\Downloads\HijackThis.exe
C:\Users\Kaila\AppData\Local\Google\Chrome\Application\chrome.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll (file missing)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120527171513.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: @C:\Program Files\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [EgisUpdate] "C:\Program Files\EgisTec IPS\EgisUpdate.exe" -d
O4 - HKLM\..\Run: [EgisTecPMMUpdate] "C:\Program Files\EgisTec IPS\PmmUpdate.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Kaila\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Acer\Acer VCM\Skype4COM.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~1\mcafee\msc\mcsniepl.dll
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files\Launch Manager\dsiwmis.exe
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files\WildTangent Games\App\GamesAppService.exe
O23 - Service: GREGService - Acer Incorporated - C:\Program Files\Acer\Registration\GREGsvc.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files\EgisTec MyWinLocker\x86\MWLService.exe
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe
O23 - Service: Updater Service - Acer Group - C:\Program Files\Acer\Acer Updater\UpdaterService.exe

--
End of file - 8953 bytes

13
Tech Clinic / problem opening files.
« on: July 09, 2012, 01:04:00 AM »
Hello. i'm having trouble opening my programs and whatnot on my computer. for some reason just out of the blue all of my icons for everything changed to my icon for "vlc media player" when i right click and select a file to open a specific program it changes my icon on everything. i am only using google chrome because it has an option to go to c drive and it will have its original icon in there where i can open it up, on the desktop though it is still like the rest of the programs. here is my log.







Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:53:02 PM, on 7/8/2012
Platform: Windows 7  (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\mcafee.com\agent\mcagent.exe
C:\Program Files\EgisTec IPS\PmmUpdate.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\igfxext.exe
C:\Program Files\EgisTec IPS\EgisUpdate.exe
C:\Windows\System32\msdt.exe
C:\Windows\System32\sdiagnhost.exe
C:\Windows\system32\conhost.exe
C:\Users\Kaila\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Kaila\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Kaila\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Kaila\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Kaila\Downloads\HijackThis.exe
C:\Users\Kaila\AppData\Local\Google\Chrome\Application\chrome.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll (file missing)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120527171513.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: @C:\Program Files\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [EgisUpdate] "C:\Program Files\EgisTec IPS\EgisUpdate.exe" -d
O4 - HKLM\..\Run: [EgisTecPMMUpdate] "C:\Program Files\EgisTec IPS\PmmUpdate.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Kaila\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Acer\Acer VCM\Skype4COM.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~1\mcafee\msc\mcsniepl.dll
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files\Launch Manager\dsiwmis.exe
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files\WildTangent Games\App\GamesAppService.exe
O23 - Service: GREGService - Acer Incorporated - C:\Program Files\Acer\Registration\GREGsvc.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files\EgisTec MyWinLocker\x86\MWLService.exe
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe
O23 - Service: Updater Service - Acer Group - C:\Program Files\Acer\Acer Updater\UpdaterService.exe

--
End of file - 8953 bytes

14
Tech Clinic / Problem with yahoo messenger
« on: November 29, 2010, 12:30:00 PM »
Everything is running great. thanks a lot for the help.

15
Tech Clinic / Problem with yahoo messenger
« on: November 29, 2010, 01:24:43 AM »
Ok i installed adobe reader and here is the log.






All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\John\Desktop\cmd.bat deleted successfully.
C:\Users\John\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: John
->Temp folder emptied: 25670794 bytes
->Temporary Internet Files folder emptied: 25736169 bytes
->Java cache emptied: 532352 bytes
->Google Chrome cache emptied: 227329329 bytes
->Apple Safari cache emptied: 4585472 bytes
->Flash cache emptied: 1352 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 82809 bytes
RecycleBin emptied: 95836 bytes
 
Total Files Cleaned = 271.00 mb
 
 
[EMPTYFLASH]
 
User: All Users
 
User: Default
 
User: Default User
 
User: John
->Flash cache emptied: 0 bytes
 
User: Public
 
Total Flash Files Cleaned = 0.00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.17.3 log created on 11282010_211357

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

16
Tech Clinic / Problem with yahoo messenger
« on: November 28, 2010, 11:31:22 AM »
OTL logfile created on: 11/28/2010 7:25:05 AM - Run 2
OTL by OldTimer - Version 3.2.17.3     Folder = C:\Users\John\Desktop
 Starter Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
1,013.00 Mb Total Physical Memory | 328.00 Mb Available Physical Memory | 32.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 48.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 136.95 Gb Total Space | 110.71 Gb Free Space | 80.84% Space Free | Partition Type: NTFS
 
Computer Name: JOHN-PC | User Name: John | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2010/11/24 19:03:38 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\John\Desktop\OTL.exe
PRC - [2010/11/10 19:08:04 | 000,724,048 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2010/11/10 19:08:02 | 006,127,184 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2010/10/27 05:15:24 | 001,073,504 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe
PRC - [2010/10/27 05:14:50 | 001,047,904 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgemcx.exe
PRC - [2010/10/25 04:20:16 | 000,173,080 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxext.exe
PRC - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe
PRC - [2010/10/22 04:57:54 | 002,745,696 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe
PRC - [2010/10/22 04:57:38 | 000,652,640 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2010/10/22 04:56:58 | 000,845,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgcsrvx.exe
PRC - [2010/10/22 04:56:56 | 000,647,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe
PRC - [2010/10/22 04:56:48 | 000,745,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgam.exe
PRC - [2010/10/19 03:29:03 | 002,011,944 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
PRC - [2010/10/16 00:40:40 | 000,037,664 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/10/08 10:21:30 | 000,750,920 | ---- | M] (AVG) -- C:\Program Files\AVG\AVG PC Tuneup 2011\BoostSpeed.exe
PRC - [2010/09/22 11:03:38 | 000,249,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2010/08/20 16:00:18 | 002,388,264 | ---- | M] (Apple Inc.) -- C:\Program Files\Safari\Safari.exe
PRC - [2010/06/01 10:17:48 | 005,252,408 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2010/01/08 16:55:43 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2009/12/09 01:19:12 | 008,120,864 | ---- | M] (Realtek Semiconductor) -- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
PRC - [2009/10/30 20:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/10/06 22:49:50 | 001,157,640 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Launch Manager\LManager.exe
PRC - [2009/09/30 13:47:36 | 000,703,008 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
PRC - [2009/09/30 13:47:14 | 000,727,584 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
PRC - [2009/09/30 13:46:28 | 000,469,536 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
PRC - [2009/09/10 04:42:30 | 000,349,480 | ---- | M] (Egis Technology Inc.) -- C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
PRC - [2009/08/28 00:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Registration\GregHSRW.exe
PRC - [2009/08/23 17:30:12 | 000,107,016 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Launch Manager\dsiwmis.exe
PRC - [2009/08/03 20:09:34 | 000,199,464 | ---- | M] (Egis Technology Inc.) -- C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe
PRC - [2009/07/13 16:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/07/13 16:14:15 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2009/07/10 14:18:18 | 000,708,608 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer VCM\AcerVCM.exe
PRC - [2009/07/10 01:54:44 | 000,253,952 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer VCM\RS_Service.exe
PRC - [2009/07/03 17:47:12 | 000,240,160 | ---- | M] (Acer) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe
PRC - [2009/06/04 18:03:32 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009/06/04 18:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/11/09 11:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
 
 
========== Modules (SafeList) ==========
 
MOD - [2010/11/24 19:03:38 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\John\Desktop\OTL.exe
MOD - [2010/08/20 20:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
MOD - [2009/09/30 13:52:10 | 000,215,584 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer ePower Management\SysHook.dll
MOD - [2009/07/13 16:16:15 | 000,099,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sspicli.dll
MOD - [2009/07/13 16:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sechost.dll
MOD - [2009/07/13 16:16:13 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\samcli.dll
MOD - [2009/07/13 16:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\profapi.dll
MOD - [2009/07/13 16:16:03 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\netutils.dll
MOD - [2009/07/13 16:15:35 | 000,288,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\KernelBase.dll
MOD - [2009/07/13 16:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dwmapi.dll
MOD - [2009/07/13 16:15:11 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\devobj.dll
MOD - [2009/07/13 16:15:07 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cryptbase.dll
MOD - [2009/07/13 16:15:02 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cfgmgr32.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - [2010/11/10 19:08:02 | 006,127,184 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2010/10/19 03:29:03 | 002,011,944 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe -- (TeamViewer5)
SRV - [2010/10/16 00:40:40 | 000,037,664 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/10/06 11:31:48 | 000,517,448 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe -- (AVG Security Toolbar Service)
SRV - [2010/09/22 23:21:24 | 001,493,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2010/09/22 15:33:04 | 000,051,040 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2010/09/22 11:03:38 | 000,249,136 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/09/30 13:47:14 | 000,727,584 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe -- (ePowerSvc)
SRV - [2009/09/10 04:42:46 | 000,305,448 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe -- (MWLService)
SRV - [2009/08/28 00:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Registration\GregHSRW.exe -- (Greg_Service)
SRV - [2009/08/23 17:30:12 | 000,107,016 | ---- | M] (Dritek System Inc.) [Auto | Running] -- C:\Program Files\Launch Manager\dsiwmis.exe -- (DsiWMIService)
SRV - [2009/07/13 16:16:21 | 000,185,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wwansvc.dll -- (WwanSvc)
SRV - [2009/07/13 16:16:17 | 000,151,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wbiosrvc.dll -- (WbioSrvc)
SRV - [2009/07/13 16:16:17 | 000,119,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpo.dll -- (Power)
SRV - [2009/07/13 16:16:16 | 000,037,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\themeservice.dll -- (Themes)
SRV - [2009/07/13 16:16:15 | 000,053,760 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sppuinotify.dll -- (sppuinotify)
SRV - [2009/07/13 16:16:13 | 000,043,520 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\System32\RpcEpMap.dll -- (RpcEptMapper)
SRV - [2009/07/13 16:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\pnrpsvc.dll -- (PNRPsvc)
SRV - [2009/07/13 16:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\pnrpsvc.dll -- (p2pimsvc)
SRV - [2009/07/13 16:16:12 | 000,165,376 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\provsvc.dll -- (HomeGroupProvider)
SRV - [2009/07/13 16:16:12 | 000,020,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpauto.dll -- (PNRPAutoReg)
SRV - [2009/07/13 16:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/07/13 16:15:36 | 000,194,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\ListSvc.dll -- (HomeGroupListener)
SRV - [2009/07/13 16:15:21 | 000,797,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2009/07/13 16:15:11 | 000,253,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcore.dll -- (Dhcp)
SRV - [2009/07/13 16:15:10 | 000,218,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\defragsvc.dll -- (defragsvc)
SRV - [2009/07/13 16:14:59 | 000,076,800 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\bdesvc.dll -- (BDESVC)
SRV - [2009/07/13 16:14:58 | 000,088,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AxInstSv.dll -- (AxInstSV) ActiveX Installer (AxInstSV)
SRV - [2009/07/13 16:14:53 | 000,027,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\appidsvc.dll -- (AppIDSvc)
SRV - [2009/07/13 16:14:29 | 003,179,520 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\System32\sppsvc.exe -- (sppsvc)
SRV - [2009/07/10 01:54:44 | 000,253,952 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer VCM\RS_Service.exe -- (RS_Service)
SRV - [2009/07/03 17:47:12 | 000,240,160 | ---- | M] (Acer) [Auto | Running] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV - [2009/06/04 18:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R)
SRV - [2009/05/22 09:02:20 | 000,250,616 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\Acer Games\Acer Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2008/11/09 11:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
 
 
========== Driver Services (SafeList) ==========
 
DRV - [2010/11/09 22:20:58 | 000,299,984 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2010/10/25 04:10:06 | 004,807,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\igdkmd32.sys -- (igfx)
DRV - [2010/09/22 23:21:24 | 000,039,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\fssfltr.sys -- (fssfltr)
DRV - [2010/09/13 16:27:54 | 000,025,680 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2010/09/07 03:48:56 | 000,034,384 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2010/09/07 03:48:54 | 000,249,424 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2010/09/07 03:48:50 | 000,026,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2010/08/19 21:42:38 | 000,123,472 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2010/08/19 21:42:38 | 000,030,288 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2010/08/19 21:42:36 | 000,021,072 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2009/12/10 22:44:02 | 000,133,720 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\ksecpkg.sys -- (KSecPkg)
DRV - [2009/12/09 00:56:48 | 002,975,840 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/11/22 22:30:06 | 000,103,296 | ---- | M] (ENE Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\EUCR6SK.SYS -- (EUCR)
DRV - [2009/11/05 19:53:58 | 001,227,776 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009/10/22 20:27:12 | 000,231,856 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SynTP.sys -- (SynTP)
DRV - [2009/09/03 20:37:44 | 000,054,784 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1C62x86.sys -- (L1C) NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller (NDIS 6.20)
DRV - [2009/07/13 16:26:21 | 000,015,952 | ---- | M] (CMD Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\cmdide.sys -- (cmdide)
DRV - [2009/07/13 16:26:17 | 000,297,552 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adpahci.sys -- (adpahci)
DRV - [2009/07/13 16:26:15 | 000,422,976 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adp94xx.sys -- (adp94xx)
DRV - [2009/07/13 16:26:15 | 000,159,312 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdsbs.sys -- (amdsbs)
DRV - [2009/07/13 16:26:15 | 000,146,512 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adpu320.sys -- (adpu320)
DRV - [2009/07/13 16:26:15 | 000,086,608 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\arcsas.sys -- (arcsas)
DRV - [2009/07/13 16:26:15 | 000,079,952 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdsata.sys -- (amdsata)
DRV - [2009/07/13 16:26:15 | 000,076,368 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\arc.sys -- (arc)
DRV - [2009/07/13 16:26:15 | 000,023,616 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\amdxata.sys -- (amdxata)
DRV - [2009/07/13 16:26:15 | 000,014,400 | ---- | M] (Acer Laboratories Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\aliide.sys -- (aliide)
DRV - [2009/07/13 16:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nvstor.sys -- (nvstor)
DRV - [2009/07/13 16:20:44 | 000,117,312 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nvraid.sys -- (nvraid)
DRV - [2009/07/13 16:20:44 | 000,044,624 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nfrd960.sys -- (nfrd960)
DRV - [2009/07/13 16:20:37 | 000,089,168 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_sas.sys -- (LSI_SAS)
DRV - [2009/07/13 16:20:36 | 000,332,352 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\iaStorV.sys -- (iaStorV)
DRV - [2009/07/13 16:20:36 | 000,235,584 | ---- | M] (LSI Corporation, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\MegaSR.sys -- (MegaSR)
DRV - [2009/07/13 16:20:36 | 000,096,848 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2009/07/13 16:20:36 | 000,095,824 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_fc.sys -- (LSI_FC)
DRV - [2009/07/13 16:20:36 | 000,054,864 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_sas2.sys -- (LSI_SAS2)
DRV - [2009/07/13 16:20:36 | 000,041,040 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\iirsp.sys -- (iirsp)
DRV - [2009/07/13 16:20:36 | 000,030,800 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\megasas.sys -- (megasas)
DRV - [2009/07/13 16:20:36 | 000,013,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\hwpolicy.sys -- (hwpolicy)
DRV - [2009/07/13 16:20:28 | 000,453,712 | ---- | M] (Emulex) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\elxstor.sys -- (elxstor)
DRV - [2009/07/13 16:20:28 | 000,070,720 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\djsvs.sys -- (aic78xx)
DRV - [2009/07/13 16:20:28 | 000,067,152 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\HpSAMD.sys -- (HpSAMD)
DRV - [2009/07/13 16:20:28 | 000,046,160 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\fsdepends.sys -- (FsDepends)
DRV - [2009/07/13 16:19:11 | 000,141,904 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vsmraid.sys -- (vsmraid)
DRV - [2009/07/13 16:19:10 | 000,159,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vhdmp.sys -- (vhdmp)
DRV - [2009/07/13 16:19:10 | 000,032,832 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vdrvroot.sys -- (vdrvroot)
DRV - [2009/07/13 16:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\wimmount.sys -- (WIMMount)
DRV - [2009/07/13 16:19:10 | 000,016,976 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\viaide.sys -- (viaide)
DRV - [2009/07/13 16:19:04 | 001,383,488 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\ql2300.sys -- (ql2300)
DRV - [2009/07/13 16:19:04 | 000,173,648 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\rdyboost.sys -- (rdyboost)
DRV - [2009/07/13 16:19:04 | 000,106,064 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\ql40xx.sys -- (ql40xx)
DRV - [2009/07/13 16:19:04 | 000,077,888 | ---- | M] (Silicon Integrated Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\sisraid4.sys -- (SiSRaid4)
DRV - [2009/07/13 16:19:04 | 000,043,088 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\pcw.sys -- (pcw)
DRV - [2009/07/13 16:19:04 | 000,040,016 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\SiSRaid2.sys -- (SiSRaid2)
DRV - [2009/07/13 16:19:04 | 000,021,072 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\stexstor.sys -- (stexstor)
DRV - [2009/07/13 16:17:54 | 000,369,568 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\cng.sys -- (CNG)
DRV - [2009/07/13 15:57:25 | 000,272,128 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\Brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2009/07/13 15:02:41 | 000,018,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\rdpbus.sys -- (rdpbus)
DRV - [2009/07/13 15:01:41 | 000,007,168 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\RDPREFMP.sys -- (RDPREFMP)
DRV - [2009/07/13 14:55:00 | 000,049,152 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\agilevpn.sys -- (RasAgileVpn) WAN Miniport (IKEv2)
DRV - [2009/07/13 14:53:51 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\wfplwf.sys -- (WfpLwf)
DRV - [2009/07/13 14:52:44 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ndiscap.sys -- (NdisCap)
DRV - [2009/07/13 14:52:04 | 000,048,128 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\vwififlt.sys -- (vwififlt)
DRV - [2009/07/13 14:52:02 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifibus.sys -- (vwifibus)
DRV - [2009/07/13 14:52:00 | 000,163,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\1394ohci.sys -- (1394ohci)
DRV - [2009/07/13 14:51:35 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\umpass.sys -- (UmPass)
DRV - [2009/07/13 14:51:08 | 000,004,096 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mshidkmdf.sys -- (mshidkmdf)
DRV - [2009/07/13 14:46:55 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\MTConfig.sys -- (MTConfig)
DRV - [2009/07/13 14:45:26 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\system32\DRIVERS\CompositeBus.sys -- (CompositeBus)
DRV - [2009/07/13 14:36:52 | 000,050,176 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\appid.sys -- (AppID)
DRV - [2009/07/13 14:33:50 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | Unknown | Stopped] -- C:\Windows\System32\drivers\scfilter.sys -- (scfilter)
DRV - [2009/07/13 14:24:05 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\discache.sys -- (discache)
DRV - [2009/07/13 14:16:36 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\acpipmi.sys -- (AcpiPmi)
DRV - [2009/07/13 14:11:04 | 000,052,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdppm.sys -- (AmdPPM)
DRV - [2009/07/13 13:54:14 | 000,026,624 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009/07/13 13:53:33 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrUsbMdm.sys -- (BrUsbMdm)
DRV - [2009/07/13 13:53:33 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrUsbSer.sys -- (BrUsbSer)
DRV - [2009/07/13 13:53:32 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrSerWdm.sys -- (BrSerWdm)
DRV - [2009/07/13 13:53:28 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\BrFiltLo.sys -- (BrFiltLo)
DRV - [2009/07/13 13:53:28 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\BrFiltUp.sys -- (BrFiltUp)
DRV - [2009/07/13 13:02:49 | 000,229,888 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\b57nd60x.sys -- (b57nd60x)
DRV - [2009/07/13 13:02:48 | 003,100,160 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\evbdx.sys -- (ebdrv)
DRV - [2009/07/13 13:02:48 | 000,430,080 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\bxvbdx.sys -- (b06bdrv)
DRV - [2009/06/04 17:43:16 | 000,330,264 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\iaStor.sys -- (iaStor)
DRV - [2009/06/02 02:15:40 | 000,060,976 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV - [2009/06/02 02:15:38 | 000,016,432 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV - [2009/06/02 02:15:34 | 000,018,992 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\System32\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV - [2009/04/01 12:00:36 | 002,661,368 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BCMWL6.SYS -- (BCM43XX)
DRV - [2009/03/25 18:14:34 | 000,021,000 | ---- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] -- C:\Windows\system32\DRIVERS\DKbFltr.sys -- (DKbFltr)
DRV - [2005/10/19 13:37:14 | 000,077,056 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nwusbser.sys -- (NWUSBPort)
DRV - [2005/10/19 13:37:14 | 000,077,056 | ---- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nwusbmdm.sys -- (NWUSBModem)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=ao532h&r=27b50410t145l0434wwm5w4522s22s
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = SOCKS=122.221.37.69:8754
 
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/11/24 09:05:55 | 000,000,000 | ---D | M]
 
 
O1 HOSTS File: ([2010/10/30 03:06:04 | 000,623,384 | ---- | M]) - C:\Windows\System32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1  localhost
O1 - Hosts: 127.0.0.1  fr.a2dfp.net #[server down?]
O1 - Hosts: 127.0.0.1  m.fr.a2dfp.net #[server down?]
O1 - Hosts: 127.0.0.1  ad.a8.net #[server down?]
O1 - Hosts: 127.0.0.1  asy.a8ww.net
O1 - Hosts: 127.0.0.1  abcstats.com
O1 - Hosts: 127.0.0.1  a.abv.bg
O1 - Hosts: 127.0.0.1  adserver.abv.bg
O1 - Hosts: 127.0.0.1  adv.abv.bg
O1 - Hosts: 127.0.0.1  bimg.abv.bg
O1 - Hosts: 127.0.0.1  ca.abv.bg
O1 - Hosts: 127.0.0.1  www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1  track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1  accuserveadsystem.com
O1 - Hosts: 127.0.0.1  www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1  achmedia.com
O1 - Hosts: 127.0.0.1  aconti.net
O1 - Hosts: 127.0.0.1  secure.aconti.net
O1 - Hosts: 127.0.0.1  www.aconti.net #[Dialer.Aconti]
O1 - Hosts: 127.0.0.1  ads.active.com
O1 - Hosts: 127.0.0.1  am1.activemeter.com
O1 - Hosts: 127.0.0.1  www.activemeter.com #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1  ads.activepower.net
O1 - Hosts: 127.0.0.1  stat.active24stats.nl #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1  ad2games.com
O1 - Hosts: 16450 more lines...
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (@C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [Acer Assist Launcher] C:\Program Files\Acer\Acer Assist\launcher.exe ()
O4 - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [EgisTecLiveUpdate] C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mwlDaemon] C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Yahoo! Messenger] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll (Google Inc.)
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.165.131.12 209.165.131.13
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\Windows\System32\livessp.dll (Microsoft Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 12:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2010/11/25 09:35:16 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\Yahoo!
[2010/11/25 09:34:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Yahoo! Companion
[2010/11/25 09:34:44 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Roaming\Yahoo!
[2010/11/25 09:06:51 | 000,000,000 | ---D | C] -- C:\Windows\System32\x64
[2010/11/24 19:03:26 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Users\John\Desktop\OTL.exe
[2010/11/23 20:48:01 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Roaming\AVG
[2010/11/23 20:45:58 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2010/11/23 20:34:43 | 000,000,000 | -H-D | C] -- C:\$AVG
[2010/11/23 08:54:05 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/11/22 20:13:52 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Roaming\AVG10
[2010/11/22 20:11:26 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2010/11/22 20:11:08 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Security Toolbar
[2010/11/22 20:08:32 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG10
[2010/11/22 20:08:32 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\AVG
[2010/11/22 20:07:16 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2010/11/22 20:00:04 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2010/11/20 09:05:12 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Roaming\Malwarebytes
[2010/11/20 09:05:08 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/11/20 09:05:05 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/11/20 09:05:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/11/20 09:05:03 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/11/17 14:43:40 | 000,000,000 | ---D | C] -- C:\ProgramData\SPC
[2010/11/17 14:43:40 | 000,000,000 | ---D | C] -- C:\Program Files\My-Proxy
[2010/11/12 11:01:00 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/11/12 11:00:59 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/11/12 10:56:39 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010/11/09 22:20:58 | 000,299,984 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgtdix.sys
[2010/11/09 03:01:15 | 000,000,000 | ---D | C] -- C:\2053a214323017d2c3
[2010/11/08 14:11:16 | 000,000,000 | ---D | C] -- C:\Windows\Yahoo Games 0wner
[2010/11/04 18:33:26 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\cache
[2010/11/04 09:08:33 | 000,000,000 | ---D | C] -- C:\Program Files\Full Tilt Poker
[2010/11/02 09:12:00 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\BuildAGadget Content
[2010/10/29 10:01:27 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
 
========== Files - Modified Within 30 Days ==========
 
[2010/11/28 07:19:00 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2935929734-532949898-3470623150-1000UA.job
[2010/11/28 07:08:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/27 18:33:43 | 000,009,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/27 18:33:43 | 000,009,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/27 18:31:54 | 100,372,435 | ---- | M] () -- C:\Windows\System32\drivers\AVG\incavi.avm
[2010/11/27 18:28:07 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/27 18:26:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/11/27 18:25:58 | 796,831,744 | -HS- | M] () -- C:\hiberfil.sys
[2010/11/26 16:48:16 | 000,000,214 | ---- | M] () -- C:\Windows\wininit.ini
[2010/11/26 16:47:21 | 000,001,133 | ---- | M] () -- C:\Users\John\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2010/11/26 16:47:21 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Yahoo! Messenger.lnk
[2010/11/25 12:19:01 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2935929734-532949898-3470623150-1000Core.job
[2010/11/25 10:38:18 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2010/11/25 10:38:18 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/11/25 08:54:16 | 000,624,178 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/11/25 08:54:16 | 000,106,522 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/11/24 19:03:38 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Users\John\Desktop\OTL.exe
[2010/11/24 09:06:22 | 000,000,846 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2011.lnk
[2010/11/23 20:45:54 | 000,001,163 | ---- | M] () -- C:\Users\John\Application Data\Microsoft\Internet Explorer\Quick Launch\AVG PC Tuneup 2011.lnk
[2010/11/23 20:45:54 | 000,001,139 | ---- | M] () -- C:\Users\John\Desktop\AVG PC Tuneup 2011.lnk
[2010/11/23 08:54:06 | 000,002,959 | ---- | M] () -- C:\Users\John\Desktop\HiJackThis.lnk
[2010/11/20 09:05:08 | 000,000,983 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/12 11:02:00 | 000,001,757 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/11/12 10:51:31 | 000,002,503 | ---- | M] () -- C:\Users\John\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2010/11/10 12:15:42 | 000,002,273 | ---- | M] () -- C:\Users\John\Desktop\Google Chrome.lnk
[2010/11/09 22:20:58 | 000,299,984 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgtdix.sys
[2010/11/04 14:54:19 | 000,001,025 | ---- | M] () -- C:\Users\Public\Desktop\Full Tilt Poker.lnk
[2010/11/01 16:54:41 | 000,004,041 | ---- | M] () -- C:\Windows\ProxyChecker.INI
[2010/10/30 03:06:04 | 000,623,384 | ---- | M] () -- C:\Windows\System32\drivers\etc\HOSTS
 
========== Files Created - No Company Name ==========
 
[2010/11/27 18:31:54 | 100,372,435 | ---- | C] () -- C:\Windows\System32\drivers\AVG\incavi.avm
[2010/11/26 16:47:21 | 000,001,133 | ---- | C] () -- C:\Users\John\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk
[2010/11/26 16:47:21 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Yahoo! Messenger.lnk
[2010/11/25 10:38:42 | 000,151,552 | ---- | C] () -- C:\Windows\System\yacsui.dll
[2010/11/25 10:38:18 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2010/11/25 10:38:18 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2010/11/23 20:45:54 | 000,001,163 | ---- | C] () -- C:\Users\John\Application Data\Microsoft\Internet Explorer\Quick Launch\AVG PC Tuneup 2011.lnk
[2010/11/23 20:45:54 | 000,001,139 | ---- | C] () -- C:\Users\John\Desktop\AVG PC Tuneup 2011.lnk
[2010/11/23 08:54:06 | 000,002,959 | ---- | C] () -- C:\Users\John\Desktop\HiJackThis.lnk
[2010/11/22 20:10:32 | 000,000,846 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2011.lnk
[2010/11/20 09:05:08 | 000,000,983 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/12 11:02:00 | 000,001,757 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2010/11/10 12:15:42 | 000,002,273 | ---- | C] () -- C:\Users\John\Desktop\Google Chrome.lnk
[2010/11/10 12:14:16 | 000,000,904 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2935929734-532949898-3470623150-1000UA.job
[2010/11/10 12:14:15 | 000,000,852 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2935929734-532949898-3470623150-1000Core.job
[2010/11/04 14:54:19 | 000,001,025 | ---- | C] () -- C:\Users\Public\Desktop\Full Tilt Poker.lnk
[2010/11/01 16:54:41 | 000,004,041 | ---- | C] () -- C:\Windows\ProxyChecker.INI
[2010/04/27 09:12:12 | 000,000,214 | ---- | C] () -- C:\Windows\wininit.ini
[2010/04/26 23:24:08 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/03/13 00:21:57 | 000,626,688 | ---- | C] () -- C:\Windows\Image.dll
[2010/03/13 00:21:57 | 000,000,323 | ---- | C] () -- C:\Windows\PidList.ini
[2010/01/08 16:34:41 | 000,356,352 | ---- | C] () -- C:\Windows\EMCRI_E.dll
[2009/08/03 14:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/07/13 14:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 14:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
 
========== LOP Check ==========
 
[2010/04/27 08:10:32 | 000,000,000 | ---D | M] -- C:\Users\John\AppData\Roaming\Acer
[2010/11/23 20:50:24 | 000,000,000 | ---D | M] -- C:\Users\John\AppData\Roaming\AVG
[2010/11/22 20:13:52 | 000,000,000 | ---D | M] -- C:\Users\John\AppData\Roaming\AVG10
[2010/04/27 08:10:30 | 000,000,000 | ---D | M] -- C:\Users\John\AppData\Roaming\Leadertech
[2010/10/22 13:17:13 | 000,000,000 | ---D | M] -- C:\Users\John\AppData\Roaming\TeamViewer
[2010/04/27 10:25:30 | 000,000,000 | ---D | M] -- C:\Users\John\AppData\Roaming\WildTangent
[2009/07/13 19:53:46 | 000,020,724 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:0B4227B4

< End of report >

17
Tech Clinic / Problem with yahoo messenger
« on: November 27, 2010, 10:34:48 PM »
its saying the file cannot be found, i think i deleted the file using mbam

18
Tech Clinic / Problem with yahoo messenger
« on: November 26, 2010, 06:43:42 PM »
hey my yahoo messenger is working now, those viruses i deleted with mbam must have fixed it

19
Tech Clinic / Problem with yahoo messenger
« on: November 26, 2010, 05:11:45 PM »
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 5195

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

11/26/2010 1:05:32 PM
mbam-log-2010-11-26 (13-05-32).txt

Scan type: Quick scan
Objects scanned: 140064
Time elapsed: 11 minute(s), 26 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\UO8KTAT1GY (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\6BTOP2GA8A (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\Tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job (Trojan.Downloader) -> Quarantined and deleted successfully.

20
Tech Clinic / Problem with yahoo messenger
« on: November 25, 2010, 01:02:14 PM »
Hey i also noticed my computer does not want to update things, we can probably work on that next. but that might be whats taking a toll on my yahoo messenger.

Just thought i would add that.

Pages: [1] 2 3 4