Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

cfxpy login and double underlink hyperlink [Solved]


  • This topic is locked This topic is locked

#1
agsmith

agsmith

    Member

  • Member
  • PipPip
  • 20 posts
Hi,
This morning when I went on the net I noticed that random words on posts in a forum were appearing blue or green and doubleunderlined.

The past few web search results I have clicked have opened the intended page, but a log-in box appears asking me to login with cfxpy.

Sometimes a box pops up and even follows my mouse around...in the bottom of the box says ads by resultslink.com. Sometimes when i click a link a new tab pops up with an ad, while in the original tab the webpage is loading.

Hovering over the word didn't seem to show anything dodgy so I tried clicking on one and it showed as cxpfy.com then went through to some search page I'd never heard of before. These links are now appearing on every web page I visit.

I have scanned with AVG 2012 which found nothing, and with Malware Bytes anti malware all of which found nothing. I scanned with ad-aware antivirus which found 42 threats. I cleaned the threats, but the double underlined links still appear.

Many thanks,
Amanda

_________________________________________________________________________

OTL logfile created on: 6/2/2013 10:12:30 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Amanda\Downloads
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16576)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.86 Gb Available Physical Memory | 43.01% Memory free
3.98 Gb Paging File | 2.45 Gb Available in Paging File | 61.54% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 127.42 Gb Free Space | 54.72% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 14.87 Gb Free Space | 99.15% Space Free | Partition Type: NTFS
Drive E: | 4.02 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: AMANDA-PC | User Name: Amanda | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/06/02 22:10:45 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Amanda\Downloads\OTL.exe
PRC - [2013/05/21 22:49:08 | 000,920,472 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2013/05/10 00:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/04/21 21:43:52 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
PRC - [2013/04/05 12:59:08 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
PRC - [2013/04/05 12:58:26 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
PRC - [2013/04/05 12:58:14 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
PRC - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2013/04/04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2013/03/18 03:25:46 | 001,236,336 | ---- | M] (Lavasoft Limited) -- C:\Program Files\Ad-Aware Antivirus\AdAwareService.exe
PRC - [2013/03/18 03:25:44 | 018,828,128 | ---- | M] (Lavasoft Limited) -- C:\Program Files\Ad-Aware Antivirus\AdAware.exe
PRC - [2013/01/27 11:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\NisSrv.exe
PRC - [2013/01/27 11:11:46 | 000,284,304 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MpCmdRun.exe
PRC - [2013/01/27 11:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2013/01/27 11:11:06 | 000,947,152 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/12/24 16:40:49 | 000,295,072 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2012/11/29 20:31:04 | 000,038,608 | ---- | M] () -- C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
PRC - [2012/11/22 19:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2012/11/08 15:14:16 | 000,122,032 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe
PRC - [2012/11/08 15:02:28 | 000,015,552 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe
PRC - [2012/11/08 15:01:30 | 001,516,680 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\Seagate Dashboard 2.0\DBAgent.exe
PRC - [2012/09/20 05:39:12 | 003,677,000 | ---- | M] (GFI Software) -- C:\Program Files\Ad-Aware Antivirus\SBAMSvc.exe
PRC - [2011/02/24 22:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011/02/11 15:19:26 | 002,760,192 | ---- | M] () -- C:\ProgramData\Boxtools\Toolbox.exe
PRC - [2009/10/14 13:36:56 | 002,793,304 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
PRC - [2009/10/14 13:34:18 | 000,560,472 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
PRC - [2009/10/07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
PRC - [2006/10/30 16:59:34 | 000,024,576 | ---- | M] () -- C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe
PRC - [2006/09/20 08:35:26 | 000,020,480 | ---- | M] () -- C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe


========== Modules (No Company Name) ==========

MOD - [2013/05/21 22:48:51 | 003,128,728 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2013/05/15 13:19:09 | 001,838,080 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\2743fdfcb695f6e9b1c3c4a7759ff4e8\Microsoft.VisualBasic.ni.dll
MOD - [2013/05/14 23:39:27 | 000,982,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\233661f3a2b632e9553915c8639637d0\System.Configuration.ni.dll
MOD - [2013/05/14 23:39:25 | 013,199,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\153143f74d840484b510d8cf5187796b\System.Windows.Forms.ni.dll
MOD - [2013/05/14 23:39:24 | 007,069,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\2f9e0112e10f9e70d3430d0be9863976\System.Core.ni.dll
MOD - [2013/01/09 14:11:56 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\5ea93652e4752c75bc6fbb195b4eb864\System.Runtime.Remoting.ni.dll
MOD - [2013/01/09 13:53:19 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\43cd41484df96d15df949eb17dd88152\System.Xml.ni.dll
MOD - [2013/01/09 13:53:04 | 001,667,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\b573c6a62bb88df0ee2af59b6a8ca910\System.Drawing.ni.dll
MOD - [2013/01/09 13:52:43 | 009,094,656 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\15872842e3e63ddf0f720f406706198e\System.ni.dll
MOD - [2013/01/09 13:52:34 | 014,412,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3f95a6d480ed1ebe45cf27b770ba94ed\mscorlib.ni.dll
MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/02/11 15:19:26 | 002,760,192 | ---- | M] () -- C:\ProgramData\Boxtools\Toolbox.exe
MOD - [2009/10/14 13:36:56 | 002,793,304 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
MOD - [2009/10/14 13:34:18 | 000,560,472 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
MOD - [2006/10/30 16:59:34 | 000,024,576 | ---- | M] () -- C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe
MOD - [2006/09/20 08:35:26 | 000,020,480 | ---- | M] () -- C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe


========== Services (SafeList) ==========

SRV - [2013/05/27 22:14:12 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/05/21 22:49:07 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/05/10 00:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2013/03/18 03:25:46 | 001,236,336 | ---- | M] (Lavasoft Limited) [Auto | Running] -- C:\Program Files\Ad-Aware Antivirus\AdAwareService.exe -- (Ad-Aware Service)
SRV - [2013/01/27 11:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2013/01/27 11:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/11/29 20:31:04 | 000,038,608 | ---- | M] () [Auto | Running] -- C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
SRV - [2012/11/08 15:02:28 | 000,015,552 | ---- | M] (Seagate Technology LLC) [Auto | Running] -- C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe -- (Seagate Dashboard Services)
SRV - [2012/09/20 05:39:12 | 003,677,000 | ---- | M] (GFI Software) [Auto | Running] -- C:\Program Files\Ad-Aware Antivirus\SBAMSvc.exe -- (SBAMSvc)
SRV - [2012/01/18 13:39:36 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2009/10/07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2009/07/13 18:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 18:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/13 18:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc)
DRV - [2013/06/01 23:15:23 | 000,013,560 | ---- | M] (GFI Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\gfibto.sys -- (gfibto)
DRV - [2013/04/04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2013/02/06 07:42:10 | 000,083,864 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus)
DRV - [2013/02/06 07:42:08 | 000,181,784 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudmdm.sys -- (ssudmdm)
DRV - [2013/01/20 15:59:04 | 000,100,328 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2012/08/23 07:44:32 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2012/08/23 07:40:25 | 000,049,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 05:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 05:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 05:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 02:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/20 02:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 02:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/01/26 19:09:02 | 000,050,704 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\npf.sys -- (npf)
DRV - [2009/10/07 08:49:40 | 006,756,632 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\lvuvc.sys -- (LVUVC)
DRV - [2009/10/07 01:46:36 | 000,025,752 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LVPr2Mon.sys -- (LVPr2Mon)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearc...=1205633631&ir=
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{261BF077-CC89-DEEC-7E88-2EFCD80DED85}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}: "URL" = http://start.mysearc...=1205633631&ir=

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearc...=1205633631&ir=
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 6C 89 E9 01 61 E1 CC 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {CFF4DB9B-135F-47c0-9269-B4C6572FD61A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE10SR
IE - HKCU\..\SearchScopes\{261BF077-CC89-DEEC-7E88-2EFCD80DED85}: "URL" = http://mystart.incre...6OyPOusVBy&i=26
IE - HKCU\..\SearchScopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}: "URL" = Playbryte-fa-v/search/redirect/?type=default&user_id=c18afa3d-61d3-4623-ab93-983c29f94669&query={searchTerms}
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://start.mysearc...=1205633631&ir=
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.order.1: "Mysearchdial"
FF - prefs.js..browser.search.searchEnginesURL: "http://www.google.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com"
FF - prefs.js..extensions.enabledAddons: playbryte_ext%40playbryte.com:1.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - prefs.js..keyword.URL: "http://www.google.co...ient&gfns=1&q="
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Amanda\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Amanda\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Amanda\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Amanda\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Amanda\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Amanda\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Amanda\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\vitzo.com/VDownloader: C:\Program Files\VDownloader\Addons\npVDownloader.dll (Vitzo)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\VDownloader\Addons\FireFox [2013/05/04 16:10:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2012/12/24 16:41:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2012/12/24 16:41:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/06/01 23:18:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/05/23 13:47:29 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/06/01 23:18:19 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/05/23 13:47:29 | 000,000,000 | ---D | M]

[2012/05/01 13:05:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Amanda\AppData\Roaming\Mozilla\Extensions
[2013/06/02 00:01:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\ojvdid29.default\extensions
[2013/03/10 20:45:27 | 000,000,000 | ---D | M] (PlayBryte) -- C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\ojvdid29.default\extensions\[email protected]
[2013/06/01 22:45:29 | 001,382,101 | ---- | M] () (No name found) -- C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\ojvdid29.default\extensions\[email protected]
[2013/05/01 13:13:57 | 000,002,545 | ---- | M] () -- C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\ojvdid29.default\searchplugins\aol-search.xml
[2013/05/03 23:05:01 | 000,002,403 | ---- | M] () -- C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\ojvdid29.default\searchplugins\Mysearchdial.xml
[2012/04/29 16:44:49 | 000,002,519 | ---- | M] () -- C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\ojvdid29.default\searchplugins\Search_Results.xml
[2013/05/21 22:49:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2013/05/21 22:49:09 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2012/08/05 12:04:35 | 000,002,361 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml

========== Chrome ==========


O1 HOSTS File: ([2009/06/10 14:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4 - HKLM..\Run: [Ad-Aware Antivirus] C:\Program Files\Ad-Aware Antivirus\AdAwareLauncher.exe (Lavasoft Limited)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DBAgent] C:\Program Files\Seagate\Seagate Dashboard 2.0\DBAgent.exe (Seagate Technology LLC)
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe File not found
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [VDownloader] C:\Program Files\VDownloader\VDownloader.exe (Vitzo)
O4 - HKLM..\Run: [WrtMon.exe] C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe ()
O4 - HKCU..\Run: [ApplePhotoStreams] C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKCU..\Run: [Boxoft Tools] C:\ProgramData\Boxtools\Boxofttoolbox.exe ()
O4 - HKCU..\Run: [com.apple.dav.bookmarks.daemon] C:\Program Files\Common Files\Apple\Internet Services\BookmarkDAV_client.exe (Apple Inc.)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Amanda\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - HKCU..\Run: [Uploader] C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe (Seagate Technology LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.21.2)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.21.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BF80001F-6CD9-455A-9000-A7CB56B0F665}: DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/06/02 16:16:48 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{C080BBD6-6C21-442E-BE29-10C1933B1C07}
[2013/06/01 23:54:16 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2013/06/01 23:36:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2013/06/01 23:32:13 | 000,000,000 | ---D | C] -- C:\Users\Amanda\Desktop\Computer Health
[2013/06/01 23:29:35 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Roaming\LavasoftStatistics
[2013/06/01 23:29:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Ad-Aware Antivirus
[2013/06/01 23:21:14 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Roaming\Codec Pack Packages
[2013/06/01 23:19:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus
[2013/06/01 23:19:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft
[2013/06/01 23:19:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid
[2013/06/01 23:19:35 | 000,000,000 | ---D | C] -- C:\Program Files\Ad-Aware Antivirus
[2013/06/01 23:19:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow
[2013/06/01 23:19:21 | 000,000,000 | ---D | C] -- C:\Program Files\Xvid
[2013/06/01 23:19:21 | 000,000,000 | ---D | C] -- C:\Program Files\ffdshow
[2013/06/01 23:19:17 | 000,000,000 | ---D | C] -- C:\Program Files\DivX
[2013/06/01 23:19:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
[2013/06/01 23:19:05 | 000,000,000 | ---D | C] -- C:\Program Files\DSP-worx
[2013/06/01 23:19:05 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX
[2013/06/01 23:19:04 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Roaming\LavFilters
[2013/06/01 23:19:04 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Roaming\CDXReader
[2013/06/01 23:18:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Downloaded Installations
[2013/06/01 23:18:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Symantec
[2013/06/01 23:18:04 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2013/06/01 23:17:57 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NSS
[2013/06/01 23:17:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Scan
[2013/06/01 23:17:57 | 000,000,000 | ---D | C] -- C:\Program Files\Norton Security Scan
[2013/06/01 23:17:57 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NSS\0400000.030
[2013/06/01 23:17:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
[2013/06/01 23:17:36 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
[2013/06/01 23:17:36 | 000,000,000 | ---D | C] -- C:\Program Files\NortonInstaller
[2013/06/01 23:17:20 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Roaming\DSite
[2013/06/01 23:15:24 | 000,044,424 | ---- | C] (GFI Software) -- C:\Windows\System32\sbbd.exe
[2013/06/01 23:15:24 | 000,013,560 | ---- | C] (GFI Software) -- C:\Windows\System32\drivers\gfibto.sys
[2013/06/01 23:15:21 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Roaming\Ad-Aware Antivirus
[2013/06/01 17:31:30 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{1B67C954-CED6-4830-BF68-596BE6CA7590}
[2013/05/31 00:20:50 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{1144C19B-1209-4506-A04D-5ED3D63B5098}
[2013/05/30 12:20:26 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{F5C46E3E-0DB8-4FC0-ACB5-2F9D3E52FB86}
[2013/05/30 00:03:55 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{39909FA6-1950-491F-A425-4BA2C5AE1C7D}
[2013/05/29 12:03:31 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{8A6F0F7E-5666-4D41-9F49-302489830EAD}
[2013/05/28 13:48:55 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{A9F5D360-1DFD-4EDA-BEA7-D6870999D1F1}
[2013/05/27 23:33:54 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{458CA5A4-6547-4973-899A-22E79CDFC053}
[2013/05/27 11:33:27 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{AEE8D952-DE68-46C2-AABF-299695EB60F3}
[2013/05/25 13:42:55 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{D359C8A9-13C2-49C7-93CB-FE5E2F53CBD4}
[2013/05/24 12:06:30 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{23034A7D-52C0-4AE3-8FC5-B6A5F276DA99}
[2013/05/23 13:47:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013/05/23 13:47:00 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2013/05/23 13:25:31 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{DA2AF7E6-0590-46C1-8C18-28C9FF83CFB0}
[2013/05/22 12:25:55 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{922683DF-B812-4ADA-AB58-33DFE3FFE3D7}
[2013/05/21 22:48:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
[2013/05/21 22:48:06 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2013/05/21 20:58:02 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{124474E7-63E6-4CC4-B1E8-CCCEFA5B06A2}
[2013/05/20 21:21:47 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{9EEDE4C4-DDBB-4E31-A9DE-CDDB3C92277F}
[2013/05/20 13:35:58 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{55D2BA2B-905C-4368-8225-B814447E96D3}
[2013/05/19 21:18:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/05/19 21:17:24 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013/05/19 21:17:22 | 000,000,000 | ---D | C] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013/05/19 12:22:22 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{A878D055-F9D1-4B17-BB5E-0F1F7A1CEB12}
[2013/05/18 14:01:49 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{AA5902BD-EC2F-4AFE-B231-F064C4A4AC1E}
[2013/05/17 21:17:35 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{2787E9A9-8D37-4377-8C67-1EA0826136A5}
[2013/05/16 12:38:46 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{94517B3D-83E8-4396-B334-160B8355DFB2}
[2013/05/16 00:17:54 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\Lexar Media
[2013/05/15 12:58:38 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{E9222793-7352-493F-97DB-09D4F2BAEE10}
[2013/05/14 14:08:40 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{F2269C77-DE8D-4C3C-9ACE-1BC508C3B26A}
[2013/05/13 13:16:34 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{805C8F25-C16E-49E8-8390-3CB1A813AE4D}
[2013/05/13 00:01:48 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{66BA18CB-D7E0-4010-814D-E10912BFC07A}
[2013/05/09 23:28:11 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{665F9030-2FD4-4080-8545-985C1AD20CAA}
[2013/05/09 13:15:19 | 000,000,000 | ---D | C] -- C:\Users\Amanda\Desktop\Vegas
[2013/05/09 11:27:47 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{8BC6857C-D197-4861-AE5E-3A4C1652D310}
[2013/05/08 12:53:41 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{8DB0E25A-F3F9-4FF5-AA5A-BF75FF3A0EA7}
[2013/05/07 00:43:06 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{79B01522-EA0A-42D7-B730-3B5C8932C7BB}
[2013/05/06 21:35:21 | 000,000,000 | ---D | C] -- C:\Users\Amanda\Desktop\From phone
[2013/05/06 12:42:35 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{476A774B-7B94-4EFD-B92E-8352A5D36131}
[2013/05/04 14:32:57 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{61C115DA-67B5-4081-A311-493D197C9D83}
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/06/02 22:17:00 | 000,000,290 | ---- | M] () -- C:\Windows\tasks\DSite.job
[2013/06/02 22:12:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/06/02 21:59:01 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/02 21:53:12 | 000,013,440 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/02 21:53:12 | 000,013,440 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/02 21:46:14 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/02 21:46:10 | 000,000,378 | -H-- | M] () -- C:\Windows\tasks\WxDFastUpdaterTask{BFEFFC0C-520A-4271-BB59-16FAFD04159C}.job
[2013/06/02 21:45:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/06/02 21:45:49 | 000,000,000 | ---- | M] () -- C:\Windows\System32\drivers\lvuvc.hs
[2013/06/02 21:45:45 | 1602,097,152 | -HS- | M] () -- C:\hiberfil.sys
[2013/06/02 16:26:01 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1000443104-1969732642-3790898716-1000UA.job
[2013/06/02 13:53:07 | 000,000,442 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Amanda.job
[2013/06/02 13:52:22 | 000,351,000 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/06/02 13:40:22 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1000443104-1969732642-3790898716-1000UA.job
[2013/06/01 23:19:05 | 000,001,786 | ---- | M] () -- C:\Windows\unins000.dat
[2013/06/01 23:19:01 | 000,715,038 | ---- | M] () -- C:\Windows\unins000.exe
[2013/06/01 23:15:23 | 000,044,424 | ---- | M] (GFI Software) -- C:\Windows\System32\sbbd.exe
[2013/06/01 23:15:23 | 000,013,560 | ---- | M] (GFI Software) -- C:\Windows\System32\drivers\gfibto.sys
[2013/05/29 14:19:00 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1000443104-1969732642-3790898716-1000Core.job
[2013/05/28 21:26:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1000443104-1969732642-3790898716-1000Core.job
[2013/05/21 00:11:27 | 000,669,432 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/05/21 00:11:27 | 000,125,514 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/05/20 23:54:15 | 000,032,467 | ---- | M] () -- C:\Users\Amanda\Desktop\XCEL vs Team.pdf
[2013/05/09 12:18:10 | 000,141,170 | ---- | M] () -- C:\Users\Amanda\Desktop\Weekly-Hourly-Planner.pdf
[2013/05/04 15:41:04 | 000,240,300 | ---- | M] () -- C:\Users\Amanda\Desktop\new rubric student evaluation session AMANDA.pdf
[2013/05/03 23:04:28 | 000,621,310 | ---- | M] () -- C:\Users\Amanda\AppData\Local\mysearchdial.crx
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/06/01 23:19:35 | 000,153,088 | ---- | C] () -- C:\Windows\System32\xvid.ax
[2013/06/01 23:19:34 | 000,645,632 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2013/06/01 23:19:34 | 000,240,640 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2013/06/01 23:19:25 | 000,079,360 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2013/06/01 23:19:05 | 000,216,064 | ---- | C] ( ) -- C:\Windows\System32\lagarith.dll
[2013/06/01 23:19:04 | 000,715,038 | ---- | C] () -- C:\Windows\unins000.exe
[2013/06/01 23:19:04 | 000,001,786 | ---- | C] () -- C:\Windows\unins000.dat
[2013/06/01 23:18:15 | 000,000,442 | -H-- | C] () -- C:\Windows\tasks\Norton Security Scan for Amanda.job
[2013/06/01 23:17:57 | 000,000,172 | ---- | C] () -- C:\Windows\System32\drivers\NSS\0400000.030\isolate.ini
[2013/06/01 23:17:25 | 000,000,290 | ---- | C] () -- C:\Windows\tasks\DSite.job
[2013/05/21 22:48:14 | 000,000,886 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/21 22:48:12 | 000,000,882 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/20 23:54:18 | 000,032,467 | ---- | C] () -- C:\Users\Amanda\Desktop\XCEL vs Team.pdf
[2013/05/09 12:18:10 | 000,141,170 | ---- | C] () -- C:\Users\Amanda\Desktop\Weekly-Hourly-Planner.pdf
[2013/05/04 15:41:02 | 000,240,300 | ---- | C] () -- C:\Users\Amanda\Desktop\new rubric student evaluation session AMANDA.pdf
[2013/05/03 23:04:49 | 000,621,310 | ---- | C] () -- C:\Users\Amanda\AppData\Local\mysearchdial.crx
[2012/12/24 16:37:46 | 000,444,283 | ---- | C] () -- C:\Program Files\Common Files\WinPcapNmap.exe
[2012/12/02 15:56:23 | 000,011,776 | ---- | C] () -- C:\Windows\System32\pmsbfn32.dll
[2012/11/29 22:33:28 | 000,000,502 | ---- | C] () -- C:\Windows\System32\CNCMFP34.INI
[2012/05/20 23:56:17 | 000,003,584 | ---- | C] () -- C:\Users\Amanda\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/04/29 17:10:00 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2012/01/19 01:48:06 | 000,088,688 | ---- | C] () -- C:\Windows\System32\cpwmon2k.dll
[2012/01/18 23:31:27 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2012/01/18 23:30:27 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2012/01/18 13:45:01 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2012/01/16 14:29:05 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll

========== ZeroAccess Check ==========

[2009/07/13 21:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/02/26 21:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 05:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/13 18:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/04/04 21:37:20 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\.oit
[2013/06/02 13:51:01 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Ad-Aware Antivirus
[2012/11/20 12:38:41 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Audacity
[2012/08/05 12:04:30 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Babylon
[2012/12/02 17:43:56 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Canon
[2013/06/01 23:19:11 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\CDXReader
[2013/06/01 23:21:14 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Codec Pack Packages
[2012/01/23 01:00:23 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\com.essexreddevelopment.mergepdfmac
[2012/12/11 22:35:17 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\ConverterLite
[2013/06/01 23:17:20 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\DSite
[2013/05/15 13:05:34 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\FileAssociationManager
[2013/06/01 23:19:12 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\LavFilters
[2012/01/16 14:37:21 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Leadertech
[2012/12/02 18:11:41 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\NewSoft
[2012/12/24 16:37:38 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\OpenCandy
[2012/12/09 19:59:17 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Pavtube
[2012/08/18 20:43:57 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\RIFT
[2012/11/30 00:17:33 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Seagate
[2013/03/21 23:37:12 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Unity
[2013/05/10 00:56:57 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\VDownloader
[2013/02/19 23:00:45 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



< End of report >
  • 0

Advertisements


#2
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts
Hello and welcome to Geeks to Go. I am sorry that you are having troubles with your computer and will try my best to help you. I know that being infected is very frustrating, but I will be here to help you through the whole process of cleaning. Removing malware can be difficult and complicated and will most likely take many steps, so please stick with me until I have declared your computer clean. I always recommend printing my instructions before following them in case you cannot keep this webpage open. Please be sure to alway follow all steps exactly as they are written and let me know what happens each time. Stop and ask if something unexpected happens or if you are unsure of how to proceed.

Please respect my volunteered time and stay with me until I declare your computer clean. If you are going to be delayed for a while, please let me know.

I am reviewing your logs and will a post a fix soon.
  • 0

#3
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts
Hi agsmith,

You seem to be running two anti-viruses: Microsoft Security Essentials and Ad-Aware. This will actually reduce the security of your system and cause instability. I would recommend that you keep MSE and remove Ad-Aware. Please uninstall your choice from the Program and Features menu of the Control Panel.

Let's get started.

Step 1: Run OTL fix.

Please be aware that this fix will delete your temporary files. If the virus has "hidden" any of your files, please do not run the fix, but stop and let me know.

Start OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :Commands
    [createrestorepoint]
    
    :OTL
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearc...=1205633631&ir=
    IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
    IE - HKLM\..\SearchScopes\{261BF077-CC89-DEEC-7E88-2EFCD80DED85}: "URL" = http://dts.search-re...q={searchTerms}
    IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}: "URL" = http://start.mysearc...=1205633631&ir=
    
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearc...=1205633631&ir=
    IE - HKCU\..\SearchScopes,DefaultScope = {CFF4DB9B-135F-47c0-9269-B4C6572FD61A}
    IE - HKCU\..\SearchScopes\{261BF077-CC89-DEEC-7E88-2EFCD80DED85}: "URL" = http://mystart.incre...6OyPOusVBy&i=26
    IE - HKCU\..\SearchScopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}: "URL" = Playbryte-fa-v/search/redirect/?type=default&user_id=c18afa3d-61d3-4623-ab93-983c29f94669&query={searchTerms}
    IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://start.mysearc...=1205633631&ir=
    
    FF - prefs.js..browser.search.order.1: "Mysearchdial"
    FF - prefs.js..extensions.enabledAddons: playbryte_ext%40playbryte.com:1.1
    
    [2013/03/10 20:45:27 | 000,000,000 | ---D | M] (PlayBryte) -- C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\ojvdid29.default\extensions\[email protected]
    [2013/05/03 23:05:01 | 000,002,403 | ---- | M] () -- C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\ojvdid29.default\searchplugins\Mysearchdial.xml
    [2012/04/29 16:44:49 | 000,002,519 | ---- | M] () -- C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\ojvdid29.default\searchplugins\Search_Results.xml
    [2012/08/05 12:04:35 | 000,002,361 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
    
    [2013/05/03 23:04:28 | 000,621,310 | ---- | M] () -- C:\Users\Amanda\AppData\Local\mysearchdial.crx
    
    [2012/08/05 12:04:30 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Babylon
    [2012/12/24 16:37:38 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\OpenCandy
    
    :Commands
    [emptytemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered.
  • Post the log it produces in your next reply.

Step 2: Run adwCleaner.

Download AdwCleaner from here to your desktop
Run AdwCleaner and select Delete

Posted Image

Once done it will ask to reboot, allow this
On reboot a log will be produced at C:\ADWCleaner[XX].txt please attach that

Step 3: Run aswMBR.

Download aswMBR.exe to your desktop.
Double click the aswMBR.exe to run it Click the "Scan" button to start scan

Posted Image

On completion of the scan click save log, save it to your desktop and post in your next reply

Posted Image

Step 4: Upload file to VT.

Please go to VirusTotal and upload the following file. Send the link of the results page to me.

C:\Windows\System32\drivers\lvuvc.hs

Things I need in your next reply:
  • OTL fix log
  • adwCleaner log
  • aswMBR log
  • Virus Total link
  • How is your computer running now? Any more ads?

  • 0

#4
agsmith

agsmith

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Thank you once again.

Here are the results you wanted:

OTL fix log
All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{261BF077-CC89-DEEC-7E88-2EFCD80DED85}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{261BF077-CC89-DEEC-7E88-2EFCD80DED85}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}\ not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{261BF077-CC89-DEEC-7E88-2EFCD80DED85}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{261BF077-CC89-DEEC-7E88-2EFCD80DED85}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}\ not found.
Prefs.js: "Mysearchdial" removed from browser.search.order.1
Prefs.js: playbryte_ext%40playbryte.com:1.1 removed from extensions.enabledAddons
Folder C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\ojvdid29.default\extensions\[email protected]\ not found.
C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\ojvdid29.default\searchplugins\Mysearchdial.xml moved successfully.
C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\ojvdid29.default\searchplugins\Search_Results.xml moved successfully.
C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml moved successfully.
C:\Users\Amanda\AppData\Local\mysearchdial.crx moved successfully.
C:\Users\Amanda\AppData\Roaming\Babylon folder moved successfully.
C:\Users\Amanda\AppData\Roaming\OpenCandy\9942C626063F4518843BFD189AEB37D9 folder moved successfully.
C:\Users\Amanda\AppData\Roaming\OpenCandy folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Amanda
->Temp folder emptied: 107411092 bytes
->Temporary Internet Files folder emptied: 13367 bytes
->Java cache emptied: 46941370 bytes
->FireFox cache emptied: 234383375 bytes
->Flash cache emptied: 66124 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 57616 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 149048 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 371.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 06032013_115844

Files\Folders moved on Reboot...
C:\Users\Amanda\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
File move failed. C:\Windows\temp\logishrd\LVPrcInj01.dll scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


Virus Total link
https://www.virustot...2b855/analysis/

How is your computer running now? Any more ads?
Not sure about this one...i will post this reply and then plunk around on the computer and let you know in a following post.



Amanda


aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-06-03 12:12:46
-----------------------------
12:12:46.653 OS Version: Windows 6.1.7601 Service Pack 1
12:12:46.653 Number of processors: 2 586 0xF0D
12:12:46.655 ComputerName: AMANDA-PC UserName: Amanda
12:12:47.106 Initialize success
12:12:50.123 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
12:12:50.130 Disk 0 Vendor: Hitachi_HDP725025GLA380 GM2OA5BA Size: 238418MB BusType: 3
12:12:50.137 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-4
12:12:50.143 Disk 1 Vendor: WDC_WD2500KS-00MJB0 02.01C03 Size: 238475MB BusType: 3
12:12:50.345 Disk 1 MBR read successfully
12:12:50.351 Disk 1 MBR scan
12:12:50.358 Disk 1 Windows XP default MBR code
12:12:50.364 Disk 1 Partition - 00 0F Extended LBA 238464 MB offset 16065
12:12:50.372 Disk 1 Partition 1 00 07 HPFS/NTFS NTFS 238464 MB offset 16128
12:12:50.391 Disk 1 scanning sectors +488392065
12:12:50.487 Disk 1 scanning C:\Windows\system32\drivers
12:13:06.044 Service scanning
12:13:13.214 Service MpKsld2d2bf39 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1E35AA93-EE21-4A41-AC88-97B32561044E}\MpKsld2d2bf39.sys **LOCKED** 32
12:13:21.862 Modules scanning
12:13:28.210 Disk 1 trace - called modules:
12:13:28.236 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS halmacpi.dll pciide.sys PCIIDEX.SYS atapi.sys intelppm.sys
12:13:28.243 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0x8563bac8]
12:13:28.250 3 CLASSPNP.SYS[8840459e] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP3T0L0-4[0x8555d030]
12:13:28.257 Scan finished successfully
12:14:05.783 Disk 1 MBR has been saved successfully to "C:\Users\Amanda\Desktop\MBR.dat"
12:14:05.814 The log file has been saved successfully to "C:\Users\Amanda\Desktop\aswMBR.txt"

Attached Files


  • 0

#5
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts
Hi,

Just wanted to let you know that I am looking into your logs and will post some more instructions soon. Let me know if the ads are gone :).
  • 0

#6
agsmith

agsmith

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Thank you very much! The computer seems to be running better and I haven't come across the links thus far...

I look forward to the next step.

Amanda
  • 0

#7
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts
You have an interesting MBR on your computer that I would like to analyze further. You should have a file on your desktop named "MBR.dat." Could you please zip this file and upload it to your next post, or upload to a site such as Dropbox and send me a share link?


Let move on now and sweep for remnants.

Step 1: Run SecurityCheck

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Step 2: Run MBAM.

  • Please open MBAM and make sure the definitions are updated.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

Step 3: Run online scan.

Run ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

  • Please go here then click on: Posted Image

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: Posted Image
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is Not checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: Posted Image
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically. The scan may take several hours.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: Posted Image
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.
Note: Do not forget to re-enable your Anti-Virus application after running the above scan!

Things I need in your next reply:
  • File attachment
  • SecurityCheck log
  • MBAM log
  • ESET log
  • Any outstanding problems?

  • 0

#8
agsmith

agsmith

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Thank you, I will be doing this as soon as I return home from work in about 7 hours...
  • 0

#9
agsmith

agsmith

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Security check results:
Results of screen317's Security Check version 0.99.64
Windows 7 Service Pack 1 x86 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
avast! Antivirus
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.75.0.1300
CCleaner
Java 7 Update 21
Adobe Flash Player 11.7.700.202
Adobe Reader 10.1.7 Adobe Reader out of Date!
Mozilla Firefox (21.0)
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
AVAST Software Avast AvastSvc.exe
AVAST Software Avast AvastUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````


Nothing found through MBAM but here's the log:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.06.05.11

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16576
Amanda :: AMANDA-PC [administrator]

6/5/2013 9:12:48 PM
mbam-log-2013-06-05 (21-12-48).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 210112
Time elapsed: 10 minute(s), 22 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

ESET Log:
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=8c7c96ae217b0a459cfbf4945347a500
# engine=14007
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2013-06-06 07:04:43
# local_time=2013-06-06 12:04:43 (-0700, US Mountain Standard Time)
# country="United States"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=774 16777213 85 91 128221 146290555 0 0
# compatibility_mode=5893 16776574 100 94 15243442 122047074 0 0
# scanned=126838
# found=5
# cleaned=0
# scan_time=5789
sh=9F82BB5DC8D4EC6B8B2BB47CB6C329B8AF1C14CE ft=1 fh=c92ed1f3ca58c043 vn="a variant of Win32/InstallCore.AZ application" ac=I fn="C:\Users\Amanda\AppData\Roaming\Codec Pack Packages\uninstaller.exe"
sh=5BAFD51453714E4815F80C01DA03F9DEF0CDE8C9 ft=1 fh=5b92e1356f69874e vn="Win32/DownloadAdmin.E application" ac=I fn="C:\Users\Amanda\Downloads\cbsidlm-tr1_8-MP3_Clipper_and_Joiner-SEO2-10861012.exe"
sh=BA116F1CEE1F8CF9B7CD039069981DBFEF44A550 ft=1 fh=750a9487b2a5c3d2 vn="a variant of Win32/Bundled.Toolbar.Ask.C application" ac=I fn="C:\Users\Amanda\Downloads\CuteWriter.exe"
sh=9A4A9E863CE02BF931CDE167C54158848EF2211B ft=1 fh=51d0a7262b751a32 vn="a variant of Win32/Toolbar.SearchSuite application" ac=I fn="C:\Users\Amanda\Downloads\jZipV1.exe"
sh=8F6779ECA98DA8A372B4034A1DF103CE57E4C0D8 ft=0 fh=0000000000000000 vn="a variant of Win32/Bundled.Toolbar.Ask.C application" ac=I fn="C:\Windows\Installer\58334.msi"


Files Detected: 0
(No malicious items detected)

(end)



No outstanding problems...infact, the computer seems to be running better so I was surprised there was more you wanted to check out.

Attached Files

  • Attached File  MBR.zip   548bytes   107 downloads

  • 0

#10
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts

Did you install AVAST? You are currently shown as having two anti-viruses, Microsoft Security Essentials and AVAST. As I said before, having 2 AVs will cause you computer to be slower and less secure. Please let me know which one you would like to keep and I will help you remove the other.

No outstanding problems...infact, the computer seems to be running better so I was surprised there was more you wanted to check out.



We like to run a scan at the end to catch any leftovers. As you can see, ESET caught some of the installers that the adware originally came from. Let's get rid of the last little bit with the fix below. ESET also indicated that a program called Codec Pack Packages came with some extras nasties, so I would recommend uninstalling it.



Start OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :Commands
    [createrestorepint]
    
    :Files
    C:\Users\Amanda\Downloads\cbsidlm-tr1_8-MP3_Clipper_and_Joiner-SEO2-10861012.exe
    C:\Users\Amanda\Downloads\CuteWriter.exe
    C:\Users\Amanda\Downloads\jZipV1.exe
    C:\Windows\Installer\58334.msi
  • Then click the Run Fix button at the top
  • Let the program run unhindered.
  • Post the log it produces in your next reply. The log should be saved in C:\_OTL\MovedFiles and should be named with numbers describing the date and time it was run.
Finally, did you install Windows 7 on this computer as an upgrade from XP? Also, do you know that your computer uses an extended partition, which is not very common?

  • 0

Advertisements


#11
agsmith

agsmith

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Ok, here is the OTL log:
========== COMMANDS ==========
Error: Unable to interpret <[createrestorepint]> in the current context!
========== FILES ==========
C:\Users\Amanda\Downloads\cbsidlm-tr1_8-MP3_Clipper_and_Joiner-SEO2-10861012.exe moved successfully.
C:\Users\Amanda\Downloads\CuteWriter.exe moved successfully.
C:\Users\Amanda\Downloads\jZipV1.exe moved successfully.
C:\Windows\Installer\58334.msi moved successfully.

OTL by OldTimer - Version 3.2.69.0 log created on 06062013_114437

I uninstalled Avast i just have to restart my computer. The OTL above was run without restarting my computer following the Avast uninstall. Also, since i had Avast when I ran the fix in which you suggested running OTL, then AdwCleaner, then aswMBR, etc., should i now go back to that step and follow it?

I have also uninstalled Codec Pack Packages.

To answer your question, yes, I upgraded to Windows 7. What is this extended partition of which you speak?
  • 0

#12
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts

I uninstalled Avast i just have to restart my computer. The OTL above was run without restarting my computer following the Avast uninstall. Also, since i had Avast when I ran the fix in which you suggested running OTL, then AdwCleaner, then aswMBR, etc., should i now go back to that step and follow it?


No need to do that. Just open OTL and click on the "Quick Scan" button, and post the log for me. I will make sure that AVAST uninstalled cleanly so that you won't have problems with it in the future.


To answer your question, yes, I upgraded to Windows 7. What is this extended partition of which you speak?


Extended partitions are a special type of partition on a hard drive that allow you to divide up a single partition into several partitions, to get around the normal 4 partition limit. We don't see them very often and it seems like it is unnecessary in your case because you don't appear to have more than maybe 2 partitions. However, if it isn't broke, no need to fix it.

Is your computer running well now?
  • 0

#13
agsmith

agsmith

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Sounds good...yes, the computer is running much better. None of the original problems that caused me to seek your help in the first place.

How would I know if the partition is causing problems; if it is infact "broke" and needing fixing??

Here is the OTL file. It is very long!

OTL logfile created on: 6/7/2013 11:40:00 AM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Amanda\Desktop\Computer Health
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16576)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 1.04 Gb Available Physical Memory | 52.37% Memory free
3.98 Gb Paging File | 2.34 Gb Available in Paging File | 58.72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 125.87 Gb Free Space | 54.05% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 14.87 Gb Free Space | 99.15% Space Free | Partition Type: NTFS
Drive E: | 4.02 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive H: | 465.76 Gb Total Space | 150.68 Gb Free Space | 32.35% Space Free | Partition Type: NTFS

Computer Name: AMANDA-PC | User Name: Amanda | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/06/02 22:10:45 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Amanda\Desktop\Computer Health\OTL.exe
PRC - [2013/05/21 22:49:08 | 000,920,472 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2013/05/10 00:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/04/21 21:43:52 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
PRC - [2013/04/05 12:59:08 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
PRC - [2013/04/05 12:58:26 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
PRC - [2013/04/05 12:58:14 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
PRC - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2013/04/04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2013/03/27 22:09:30 | 000,879,104 | ---- | M] (Vitzo) -- C:\Program Files\VDownloader\VDownloader.exe
PRC - [2013/01/27 11:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\NisSrv.exe
PRC - [2013/01/27 11:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2013/01/27 11:11:06 | 000,947,152 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/12/24 16:40:49 | 000,295,072 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2012/11/29 20:31:04 | 000,038,608 | ---- | M] () -- C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
PRC - [2012/11/22 19:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2012/11/08 15:14:16 | 000,122,032 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe
PRC - [2012/11/08 15:02:28 | 000,015,552 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe
PRC - [2012/11/08 15:01:30 | 001,516,680 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\Seagate Dashboard 2.0\DBAgent.exe
PRC - [2011/02/24 22:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011/02/11 15:19:26 | 002,760,192 | ---- | M] () -- C:\ProgramData\Boxtools\Toolbox.exe
PRC - [2009/10/14 13:36:56 | 002,793,304 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
PRC - [2009/10/14 13:34:18 | 000,560,472 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
PRC - [2009/10/07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
PRC - [2006/10/30 16:59:34 | 000,024,576 | ---- | M] () -- C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe
PRC - [2006/09/20 08:35:26 | 000,020,480 | ---- | M] () -- C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe


========== Modules (No Company Name) ==========

MOD - [2013/05/21 22:48:51 | 003,128,728 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2013/05/15 13:19:09 | 001,838,080 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\2743fdfcb695f6e9b1c3c4a7759ff4e8\Microsoft.VisualBasic.ni.dll
MOD - [2013/05/15 13:18:03 | 000,401,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\990123c5701a26f1d724150839811bce\System.Xml.Linq.ni.dll
MOD - [2013/05/15 13:16:53 | 002,297,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\3c2ed368e1f3889997dfb42a5ca77284\System.Core.ni.dll
MOD - [2013/05/15 12:59:49 | 014,340,608 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\af525b4bec3b9941b7be8ffbf813da80\PresentationFramework.ni.dll
MOD - [2013/05/15 12:59:27 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\30e3a21202000677d0a9270572251477\System.Windows.Forms.ni.dll
MOD - [2013/05/15 12:59:11 | 012,237,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7eac0dbe9aa20b55e37235f8ee030e6b\PresentationCore.ni.dll
MOD - [2013/05/15 12:58:49 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\716959df79685a1eae0fc14275a32b0f\WindowsBase.ni.dll
MOD - [2013/05/15 12:58:38 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\764f15e86c82662e977bd418bd6318c1\System.Configuration.ni.dll
MOD - [2013/05/14 23:39:27 | 000,982,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\233661f3a2b632e9553915c8639637d0\System.Configuration.ni.dll
MOD - [2013/05/14 23:39:25 | 013,199,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\153143f74d840484b510d8cf5187796b\System.Windows.Forms.ni.dll
MOD - [2013/05/14 23:39:24 | 007,069,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\2f9e0112e10f9e70d3430d0be9863976\System.Core.ni.dll
MOD - [2013/03/27 22:07:48 | 000,065,536 | ---- | M] () -- C:\Program Files\VDownloader\Core.XmlSerializers.dll
MOD - [2013/03/27 22:07:44 | 000,009,216 | ---- | M] () -- C:\Program Files\VDownloader\AutoupdateLibrary.dll
MOD - [2013/03/27 22:07:34 | 000,010,752 | ---- | M] () -- C:\Program Files\VDownloader\WebBrowserWithProxy.dll
MOD - [2013/02/13 21:14:04 | 000,240,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\78967b28f748b8807eaa97c1cb454adc\WindowsFormsIntegration.ni.dll
MOD - [2013/02/13 21:12:31 | 000,593,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\1505fb78e94fbe5ee73563a5e10ecead\System.Messaging.ni.dll
MOD - [2013/02/13 20:40:04 | 001,840,640 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\64cf6c356be66bb17c4667d6d8aa467b\System.Web.Services.ni.dll
MOD - [2013/02/13 20:40:02 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll
MOD - [2013/01/09 21:55:37 | 000,220,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\5baea82888a13fa558004b24e3b107cf\CustomMarshalers.ni.dll
MOD - [2013/01/09 20:36:59 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7d20811a7ce7cc589153648cbb1ce5c\PresentationFramework.Aero.ni.dll
MOD - [2013/01/09 20:36:21 | 006,611,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\dd20416f723ee13ffb4173ec1afc4ec4\System.Data.ni.dll
MOD - [2013/01/09 20:35:45 | 000,039,424 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\2f32b665b25e874e0222f7be18b0161f\PresentationCFFRasterizer.ni.dll
MOD - [2013/01/09 20:35:35 | 001,592,832 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll
MOD - [2013/01/09 20:35:30 | 000,060,928 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\23da92e38ffc0bbf6673adb1892aa0f4\UIAutomationProvider.ni.dll
MOD - [2013/01/09 20:35:30 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\d908c91e24616e6b8d38c9da61038b25\Accessibility.ni.dll
MOD - [2013/01/09 20:35:04 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll
MOD - [2013/01/09 20:34:57 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll
MOD - [2013/01/09 20:34:41 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll
MOD - [2013/01/09 14:11:56 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\5ea93652e4752c75bc6fbb195b4eb864\System.Runtime.Remoting.ni.dll
MOD - [2013/01/09 13:53:19 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\43cd41484df96d15df949eb17dd88152\System.Xml.ni.dll
MOD - [2013/01/09 13:53:04 | 001,667,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\b573c6a62bb88df0ee2af59b6a8ca910\System.Drawing.ni.dll
MOD - [2013/01/09 13:52:43 | 009,094,656 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\15872842e3e63ddf0f720f406706198e\System.ni.dll
MOD - [2013/01/09 13:52:34 | 014,412,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3f95a6d480ed1ebe45cf27b770ba94ed\mscorlib.ni.dll
MOD - [2012/02/10 16:31:41 | 005,283,840 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/02/11 15:19:26 | 002,760,192 | ---- | M] () -- C:\ProgramData\Boxtools\Toolbox.exe
MOD - [2010/11/04 18:58:05 | 002,927,616 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2010/11/04 18:57:39 | 000,069,120 | ---- | M] () -- C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
MOD - [2009/10/14 13:36:56 | 002,793,304 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
MOD - [2009/10/14 13:34:18 | 000,560,472 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
MOD - [2006/10/30 16:59:34 | 000,024,576 | ---- | M] () -- C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe
MOD - [2006/09/20 08:35:26 | 000,020,480 | ---- | M] () -- C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe


========== Services (SafeList) ==========

SRV - [2013/05/27 22:14:12 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/05/21 22:49:07 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/05/10 00:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2013/01/27 11:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2013/01/27 11:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/11/29 20:31:04 | 000,038,608 | ---- | M] () [Auto | Running] -- C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
SRV - [2012/11/08 15:02:28 | 000,015,552 | ---- | M] (Seagate Technology LLC) [Auto | Running] -- C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe -- (Seagate Dashboard Services)
SRV - [2012/01/18 13:39:36 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2009/10/07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2009/07/13 18:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 18:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/13 18:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc)
DRV - [2013/06/01 23:15:23 | 000,013,560 | ---- | M] (GFI Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\gfibto.sys -- (gfibto)
DRV - [2013/04/04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2013/02/06 07:42:10 | 000,083,864 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus)
DRV - [2013/02/06 07:42:08 | 000,181,784 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudmdm.sys -- (ssudmdm)
DRV - [2013/01/20 15:59:04 | 000,100,328 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2012/08/23 07:44:32 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2012/08/23 07:40:25 | 000,049,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 05:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 05:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 05:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 02:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/20 02:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 02:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/01/26 19:09:02 | 000,050,704 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\npf.sys -- (npf)
DRV - [2009/10/07 08:49:40 | 006,756,632 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\lvuvc.sys -- (LVUVC)
DRV - [2009/10/07 01:46:36 | 000,025,752 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LVPr2Mon.sys -- (LVPr2Mon)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 6C 89 E9 01 61 E1 CC 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE10SR
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.searchEnginesURL: "http://www.google.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - prefs.js..keyword.URL: "http://www.google.co...ient&gfns=1&q="
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Amanda\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Amanda\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Amanda\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Amanda\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Amanda\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Amanda\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Amanda\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\vitzo.com/VDownloader: C:\Program Files\VDownloader\Addons\npVDownloader.dll (Vitzo)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\VDownloader\Addons\FireFox [2013/05/04 16:10:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2012/12/24 16:41:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2012/12/24 16:41:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/06/01 23:18:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/05/23 13:47:29 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/06/01 23:18:19 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/05/23 13:47:29 | 000,000,000 | ---D | M]

[2012/05/01 13:05:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Amanda\AppData\Roaming\Mozilla\Extensions
[2013/06/05 11:57:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\ojvdid29.default\extensions
[2013/06/05 11:57:05 | 001,382,186 | ---- | M] () (No name found) -- C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\ojvdid29.default\extensions\[email protected]
[2013/05/01 13:13:57 | 000,002,545 | ---- | M] () -- C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\ojvdid29.default\searchplugins\aol-search.xml
[2013/05/21 22:49:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2013/05/21 22:49:09 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

========== Chrome ==========


O1 HOSTS File: ([2009/06/10 14:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DBAgent] C:\Program Files\Seagate\Seagate Dashboard 2.0\DBAgent.exe (Seagate Technology LLC)
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe File not found
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [VDownloader] C:\Program Files\VDownloader\VDownloader.exe (Vitzo)
O4 - HKLM..\Run: [WrtMon.exe] C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe ()
O4 - HKCU..\Run: [ApplePhotoStreams] C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKCU..\Run: [Boxoft Tools] C:\ProgramData\Boxtools\Boxofttoolbox.exe ()
O4 - HKCU..\Run: [com.apple.dav.bookmarks.daemon] C:\Program Files\Common Files\Apple\Internet Services\BookmarkDAV_client.exe (Apple Inc.)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Amanda\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - HKCU..\Run: [Uploader] C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe (Seagate Technology LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.21.2)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.21.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BF80001F-6CD9-455A-9000-A7CB56B0F665}: DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2012/04/22 17:39:24 | 000,000,030 | ---- | M] () - H:\Autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/06/06 23:51:33 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{D5449EF6-08D5-4672-9853-2CCDA8FE28CD}
[2013/06/06 11:51:03 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{8B9A5DB0-1A46-4DA2-AE06-5F0D8953EE6C}
[2013/06/05 23:50:38 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{8570DE9A-9E01-409A-B409-A3ABC4759B0B}
[2013/06/05 22:07:43 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2013/06/05 22:07:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/06/05 22:05:45 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013/06/05 22:05:44 | 000,000,000 | ---D | C] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013/06/05 11:50:11 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{00F13A5E-0EB6-4CD4-8BDB-5CEB84D05572}
[2013/06/04 12:45:33 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{5E128A50-67B3-4DE2-8337-5C18189A75EB}
[2013/06/03 23:43:25 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{E08ACF48-E11C-4D9D-9854-0FCE9511C11D}
[2013/06/03 12:27:48 | 000,229,648 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2013/06/03 12:26:06 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2013/06/03 12:25:26 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2013/06/03 11:58:44 | 000,000,000 | ---D | C] -- C:\_OTL
[2013/06/03 11:42:45 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{C58650A2-328F-4095-9814-92FD0C3C791E}
[2013/06/02 16:16:48 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{C080BBD6-6C21-442E-BE29-10C1933B1C07}
[2013/06/01 23:54:16 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2013/06/01 23:36:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2013/06/01 23:32:13 | 000,000,000 | ---D | C] -- C:\Users\Amanda\Desktop\Computer Health
[2013/06/01 23:29:35 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Roaming\LavasoftStatistics
[2013/06/01 23:19:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid
[2013/06/01 23:19:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow
[2013/06/01 23:19:21 | 000,000,000 | ---D | C] -- C:\Program Files\Xvid
[2013/06/01 23:19:21 | 000,000,000 | ---D | C] -- C:\Program Files\ffdshow
[2013/06/01 23:19:17 | 000,000,000 | ---D | C] -- C:\Program Files\DivX
[2013/06/01 23:19:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
[2013/06/01 23:19:05 | 000,000,000 | ---D | C] -- C:\Program Files\DSP-worx
[2013/06/01 23:19:05 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX
[2013/06/01 23:19:04 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Roaming\LavFilters
[2013/06/01 23:19:04 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Roaming\CDXReader
[2013/06/01 23:18:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Downloaded Installations
[2013/06/01 23:18:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Symantec
[2013/06/01 23:18:04 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2013/06/01 23:17:57 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NSS
[2013/06/01 23:17:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Scan
[2013/06/01 23:17:57 | 000,000,000 | ---D | C] -- C:\Program Files\Norton Security Scan
[2013/06/01 23:17:57 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NSS\0400000.030
[2013/06/01 23:17:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
[2013/06/01 23:17:36 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
[2013/06/01 23:17:36 | 000,000,000 | ---D | C] -- C:\Program Files\NortonInstaller
[2013/06/01 23:17:20 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Roaming\DSite
[2013/06/01 23:15:24 | 000,044,424 | ---- | C] (GFI Software) -- C:\Windows\System32\sbbd.exe
[2013/06/01 23:15:24 | 000,013,560 | ---- | C] (GFI Software) -- C:\Windows\System32\drivers\gfibto.sys
[2013/06/01 17:31:30 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{1B67C954-CED6-4830-BF68-596BE6CA7590}
[2013/05/31 00:20:50 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{1144C19B-1209-4506-A04D-5ED3D63B5098}
[2013/05/30 12:20:26 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{F5C46E3E-0DB8-4FC0-ACB5-2F9D3E52FB86}
[2013/05/30 00:03:55 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{39909FA6-1950-491F-A425-4BA2C5AE1C7D}
[2013/05/29 12:03:31 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{8A6F0F7E-5666-4D41-9F49-302489830EAD}
[2013/05/28 13:48:55 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{A9F5D360-1DFD-4EDA-BEA7-D6870999D1F1}
[2013/05/27 23:33:54 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{458CA5A4-6547-4973-899A-22E79CDFC053}
[2013/05/27 11:33:27 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{AEE8D952-DE68-46C2-AABF-299695EB60F3}
[2013/05/25 13:42:55 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{D359C8A9-13C2-49C7-93CB-FE5E2F53CBD4}
[2013/05/24 12:06:30 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{23034A7D-52C0-4AE3-8FC5-B6A5F276DA99}
[2013/05/23 13:47:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013/05/23 13:47:00 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2013/05/23 13:25:31 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{DA2AF7E6-0590-46C1-8C18-28C9FF83CFB0}
[2013/05/22 12:25:55 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{922683DF-B812-4ADA-AB58-33DFE3FFE3D7}
[2013/05/21 22:48:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
[2013/05/21 22:48:06 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2013/05/21 20:58:02 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{124474E7-63E6-4CC4-B1E8-CCCEFA5B06A2}
[2013/05/20 21:21:47 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{9EEDE4C4-DDBB-4E31-A9DE-CDDB3C92277F}
[2013/05/20 13:35:58 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{55D2BA2B-905C-4368-8225-B814447E96D3}
[2013/05/19 12:22:22 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{A878D055-F9D1-4B17-BB5E-0F1F7A1CEB12}
[2013/05/18 14:01:49 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{AA5902BD-EC2F-4AFE-B231-F064C4A4AC1E}
[2013/05/17 21:17:35 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{2787E9A9-8D37-4377-8C67-1EA0826136A5}
[2013/05/16 12:38:46 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{94517B3D-83E8-4396-B334-160B8355DFB2}
[2013/05/16 00:17:54 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\Lexar Media
[2013/05/15 12:58:38 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{E9222793-7352-493F-97DB-09D4F2BAEE10}
[2013/05/14 14:08:40 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{F2269C77-DE8D-4C3C-9ACE-1BC508C3B26A}
[2013/05/13 13:16:34 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{805C8F25-C16E-49E8-8390-3CB1A813AE4D}
[2013/05/13 00:01:48 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{66BA18CB-D7E0-4010-814D-E10912BFC07A}
[2013/05/09 23:28:11 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{665F9030-2FD4-4080-8545-985C1AD20CAA}
[2013/05/09 13:15:19 | 000,000,000 | ---D | C] -- C:\Users\Amanda\Desktop\Vegas
[2013/05/09 11:27:47 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{8BC6857C-D197-4861-AE5E-3A4C1652D310}
[2013/05/08 12:53:41 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{8DB0E25A-F3F9-4FF5-AA5A-BF75FF3A0EA7}

========== Files - Modified Within 30 Days ==========

[2013/06/07 11:44:12 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1000443104-1969732642-3790898716-1000UA.job
[2013/06/07 11:39:15 | 000,000,408 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Amanda.job
[2013/06/07 11:39:10 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/07 11:39:08 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1000443104-1969732642-3790898716-1000UA.job
[2013/06/07 11:39:07 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/06/07 11:39:07 | 000,000,290 | ---- | M] () -- C:\Windows\tasks\DSite.job
[2013/06/07 11:39:00 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/06/07 11:39:00 | 000,000,000 | ---- | M] () -- C:\Windows\System32\drivers\lvuvc.hs
[2013/06/06 22:59:09 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/06 21:26:01 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1000443104-1969732642-3790898716-1000Core.job
[2013/06/06 21:19:59 | 000,013,440 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/06 21:19:59 | 000,013,440 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/06 21:14:14 | 000,000,378 | -H-- | M] () -- C:\Windows\tasks\WxDFastUpdaterTask{BFEFFC0C-520A-4271-BB59-16FAFD04159C}.job
[2013/06/06 21:12:32 | 1602,097,152 | -HS- | M] () -- C:\hiberfil.sys
[2013/06/06 14:19:00 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1000443104-1969732642-3790898716-1000Core.job
[2013/06/05 20:58:11 | 000,000,548 | ---- | M] () -- C:\Users\Amanda\Desktop\MBR.zip
[2013/06/03 12:27:48 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2013/06/03 12:14:05 | 000,000,512 | ---- | M] () -- C:\Users\Amanda\Desktop\MBR.dat
[2013/06/02 13:52:22 | 000,351,000 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/06/01 23:19:05 | 000,001,786 | ---- | M] () -- C:\Windows\unins000.dat
[2013/06/01 23:19:01 | 000,715,038 | ---- | M] () -- C:\Windows\unins000.exe
[2013/06/01 23:15:23 | 000,044,424 | ---- | M] (GFI Software) -- C:\Windows\System32\sbbd.exe
[2013/06/01 23:15:23 | 000,013,560 | ---- | M] (GFI Software) -- C:\Windows\System32\drivers\gfibto.sys
[2013/05/21 00:11:27 | 000,669,432 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/05/21 00:11:27 | 000,125,514 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/05/20 23:54:15 | 000,032,467 | ---- | M] () -- C:\Users\Amanda\Desktop\XCEL vs Team.pdf
[2013/05/09 12:18:10 | 000,141,170 | ---- | M] () -- C:\Users\Amanda\Desktop\Weekly-Hourly-Planner.pdf
[2013/05/09 01:58:28 | 000,229,648 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe

========== Files Created - No Company Name ==========

[2013/06/05 20:58:11 | 000,000,548 | ---- | C] () -- C:\Users\Amanda\Desktop\MBR.zip
[2013/06/03 12:14:05 | 000,000,512 | ---- | C] () -- C:\Users\Amanda\Desktop\MBR.dat
[2013/06/01 23:19:35 | 000,153,088 | ---- | C] () -- C:\Windows\System32\xvid.ax
[2013/06/01 23:19:34 | 000,645,632 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2013/06/01 23:19:34 | 000,240,640 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2013/06/01 23:19:25 | 000,079,360 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2013/06/01 23:19:05 | 000,216,064 | ---- | C] ( ) -- C:\Windows\System32\lagarith.dll
[2013/06/01 23:19:04 | 000,715,038 | ---- | C] () -- C:\Windows\unins000.exe
[2013/06/01 23:19:04 | 000,001,786 | ---- | C] () -- C:\Windows\unins000.dat
[2013/06/01 23:18:15 | 000,000,408 | -H-- | C] () -- C:\Windows\tasks\Norton Security Scan for Amanda.job
[2013/06/01 23:17:57 | 000,000,172 | ---- | C] () -- C:\Windows\System32\drivers\NSS\0400000.030\isolate.ini
[2013/06/01 23:17:25 | 000,000,290 | ---- | C] () -- C:\Windows\tasks\DSite.job
[2013/05/21 22:48:14 | 000,000,886 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/21 22:48:12 | 000,000,882 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/20 23:54:18 | 000,032,467 | ---- | C] () -- C:\Users\Amanda\Desktop\XCEL vs Team.pdf
[2013/05/09 12:18:10 | 000,141,170 | ---- | C] () -- C:\Users\Amanda\Desktop\Weekly-Hourly-Planner.pdf
[2012/12/24 16:37:46 | 000,444,283 | ---- | C] () -- C:\Program Files\Common Files\WinPcapNmap.exe
[2012/12/02 15:56:23 | 000,011,776 | ---- | C] () -- C:\Windows\System32\pmsbfn32.dll
[2012/11/29 22:33:28 | 000,000,502 | ---- | C] () -- C:\Windows\System32\CNCMFP34.INI
[2012/05/20 23:56:17 | 000,003,584 | ---- | C] () -- C:\Users\Amanda\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/04/29 17:10:00 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2012/01/19 01:48:06 | 000,088,688 | ---- | C] () -- C:\Windows\System32\cpwmon2k.dll
[2012/01/18 23:31:27 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2012/01/18 23:30:27 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2012/01/18 13:45:01 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2012/01/16 14:29:05 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll

========== ZeroAccess Check ==========

[2009/07/13 21:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/02/26 21:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 05:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/13 18:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/04/04 21:37:20 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\.oit
[2012/11/20 12:38:41 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Audacity
[2012/12/02 17:43:56 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Canon
[2013/06/01 23:19:11 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\CDXReader
[2012/01/23 01:00:23 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\com.essexreddevelopment.mergepdfmac
[2012/12/11 22:35:17 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\ConverterLite
[2013/06/01 23:17:20 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\DSite
[2013/05/15 13:05:34 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\FileAssociationManager
[2013/06/01 23:19:12 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\LavFilters
[2012/01/16 14:37:21 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Leadertech
[2012/12/02 18:11:41 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\NewSoft
[2012/12/09 19:59:17 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Pavtube
[2012/08/18 20:43:57 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\RIFT
[2012/11/30 00:17:33 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Seagate
[2013/03/21 23:37:12 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Unity
[2013/06/06 22:50:03 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\VDownloader
[2013/02/19 23:00:45 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



< End of report >
  • 0

#14
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts
Ok, please download and run the two removal tools below to get rid of some old AV remnants on your computer.

Avast Removal Tool - Please run in Safe Mode. Instructions are here.

VIPRE Removal Tool


Then please run a fresh scan and we'll make sure they did the job. Please click "Use SafeList" in the "Extra Registry" box and use the "Run Scan" button this time. You should get two logs: OTL.txt and Extras.txt. Please post them both.

How would I know if the partition is causing problems; if it is infact "broke" and needing fixing??




You would know...your computer wouldn't boot or you couldn't access all of your hard drive.
  • 0

#15
agsmith

agsmith

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Ok, the logs:
OTL.txt
OTL logfile created on: 6/8/2013 1:58:01 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Amanda\Desktop\Computer Health
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16576)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.94 Gb Available Physical Memory | 47.27% Memory free
3.98 Gb Paging File | 2.74 Gb Available in Paging File | 68.76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 129.83 Gb Free Space | 55.75% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 14.87 Gb Free Space | 99.15% Space Free | Partition Type: NTFS
Drive E: | 4.02 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: AMANDA-PC | User Name: Amanda | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/06/02 22:10:45 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Amanda\Desktop\Computer Health\OTL.exe
PRC - [2013/05/21 22:49:08 | 000,920,472 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2013/05/10 00:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/04/21 21:43:52 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
PRC - [2013/04/05 12:59:08 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
PRC - [2013/04/05 12:58:26 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
PRC - [2013/04/05 12:58:14 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
PRC - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2013/04/04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2013/01/27 11:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\NisSrv.exe
PRC - [2013/01/27 11:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2013/01/27 11:11:06 | 000,947,152 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/12/24 16:40:49 | 000,295,072 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2012/11/29 20:31:04 | 000,038,608 | ---- | M] () -- C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
PRC - [2012/11/22 19:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2012/11/08 15:14:16 | 000,122,032 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe
PRC - [2012/11/08 15:02:28 | 000,015,552 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe
PRC - [2012/11/08 15:01:30 | 001,516,680 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\Seagate Dashboard 2.0\DBAgent.exe
PRC - [2011/02/24 22:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011/02/11 15:19:26 | 002,760,192 | ---- | M] () -- C:\ProgramData\Boxtools\Toolbox.exe
PRC - [2009/10/14 13:36:56 | 002,793,304 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
PRC - [2009/10/14 13:34:18 | 000,560,472 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
PRC - [2009/10/07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
PRC - [2006/10/30 16:59:34 | 000,024,576 | ---- | M] () -- C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe
PRC - [2006/09/20 08:35:26 | 000,020,480 | ---- | M] () -- C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe


========== Modules (No Company Name) ==========

MOD - [2013/05/21 22:48:51 | 003,128,728 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2013/05/15 13:19:09 | 001,838,080 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualBas#\2743fdfcb695f6e9b1c3c4a7759ff4e8\Microsoft.VisualBasic.ni.dll
MOD - [2013/05/14 23:39:27 | 000,982,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\233661f3a2b632e9553915c8639637d0\System.Configuration.ni.dll
MOD - [2013/05/14 23:39:25 | 013,199,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\153143f74d840484b510d8cf5187796b\System.Windows.Forms.ni.dll
MOD - [2013/05/14 23:39:24 | 007,069,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\2f9e0112e10f9e70d3430d0be9863976\System.Core.ni.dll
MOD - [2013/01/09 14:11:56 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\5ea93652e4752c75bc6fbb195b4eb864\System.Runtime.Remoting.ni.dll
MOD - [2013/01/09 13:53:19 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\43cd41484df96d15df949eb17dd88152\System.Xml.ni.dll
MOD - [2013/01/09 13:53:04 | 001,667,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\b573c6a62bb88df0ee2af59b6a8ca910\System.Drawing.ni.dll
MOD - [2013/01/09 13:52:43 | 009,094,656 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\15872842e3e63ddf0f720f406706198e\System.ni.dll
MOD - [2013/01/09 13:52:34 | 014,412,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3f95a6d480ed1ebe45cf27b770ba94ed\mscorlib.ni.dll
MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/02/11 15:19:26 | 002,760,192 | ---- | M] () -- C:\ProgramData\Boxtools\Toolbox.exe
MOD - [2009/10/14 13:36:56 | 002,793,304 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
MOD - [2009/10/14 13:34:18 | 000,560,472 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
MOD - [2006/10/30 16:59:34 | 000,024,576 | ---- | M] () -- C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe
MOD - [2006/09/20 08:35:26 | 000,020,480 | ---- | M] () -- C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe


========== Services (SafeList) ==========

SRV - [2013/05/27 22:14:12 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/05/21 22:49:07 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/05/10 00:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2013/01/27 11:11:46 | 000,295,232 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2013/01/27 11:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/11/29 20:31:04 | 000,038,608 | ---- | M] () [Auto | Running] -- C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
SRV - [2012/11/08 15:02:28 | 000,015,552 | ---- | M] (Seagate Technology LLC) [Auto | Running] -- C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe -- (Seagate Dashboard Services)
SRV - [2012/01/18 13:39:36 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2009/10/07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2009/07/13 18:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 18:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/13 18:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc)
DRV - [2013/06/01 23:15:23 | 000,013,560 | ---- | M] (GFI Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\gfibto.sys -- (gfibto)
DRV - [2013/04/04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2013/02/06 07:42:10 | 000,083,864 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus)
DRV - [2013/02/06 07:42:08 | 000,181,784 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudmdm.sys -- (ssudmdm)
DRV - [2013/01/20 15:59:04 | 000,100,328 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2012/08/23 07:44:32 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2012/08/23 07:40:25 | 000,049,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 05:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 05:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 05:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 02:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/20 02:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 02:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/01/26 19:09:02 | 000,050,704 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\npf.sys -- (npf)
DRV - [2009/10/07 08:49:40 | 006,756,632 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\lvuvc.sys -- (LVUVC)
DRV - [2009/10/07 01:46:36 | 000,025,752 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LVPr2Mon.sys -- (LVPr2Mon)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 6C 89 E9 01 61 E1 CC 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE10SR
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.searchEnginesURL: "http://www.google.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - prefs.js..keyword.URL: "http://www.google.co...ient&gfns=1&q="
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Amanda\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Amanda\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\vitzo.com/VDownloader: C:\Program Files\VDownloader\Addons\npVDownloader.dll (Vitzo)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\VDownloader\Addons\FireFox [2013/05/04 16:10:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2012/12/24 16:41:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2012/12/24 16:41:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/06/01 23:18:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/05/23 13:47:29 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/06/01 23:18:19 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/05/23 13:47:29 | 000,000,000 | ---D | M]

[2012/05/01 13:05:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Amanda\AppData\Roaming\Mozilla\Extensions
[2013/06/05 11:57:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\ojvdid29.default\extensions
[2013/06/05 11:57:05 | 001,382,186 | ---- | M] () (No name found) -- C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\ojvdid29.default\extensions\[email protected]
[2013/05/01 13:13:57 | 000,002,545 | ---- | M] () -- C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\ojvdid29.default\searchplugins\aol-search.xml
[2013/05/21 22:49:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2013/05/21 22:49:09 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

========== Chrome ==========


O1 HOSTS File: ([2009/06/10 14:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DBAgent] C:\Program Files\Seagate\Seagate Dashboard 2.0\DBAgent.exe (Seagate Technology LLC)
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe File not found
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [VDownloader] C:\Program Files\VDownloader\VDownloader.exe (Vitzo)
O4 - HKLM..\Run: [WrtMon.exe] C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe ()
O4 - HKCU..\Run: [ApplePhotoStreams] C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKCU..\Run: [Boxoft Tools] C:\ProgramData\Boxtools\Boxofttoolbox.exe ()
O4 - HKCU..\Run: [com.apple.dav.bookmarks.daemon] C:\Program Files\Common Files\Apple\Internet Services\BookmarkDAV_client.exe (Apple Inc.)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Amanda\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - HKCU..\Run: [Uploader] C:\Program Files\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe (Seagate Technology LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.21.2)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.21.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BF80001F-6CD9-455A-9000-A7CB56B0F665}: DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/06/08 13:56:34 | 000,000,000 | ---D | C] -- C:\Temp
[2013/06/08 13:47:46 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{573B59C3-B5D2-4F0C-A1E4-AD9681CEA0CE}
[2013/06/08 00:04:00 | 000,000,000 | ---D | C] -- C:\Users\Amanda\Desktop\how to back up phone - Google Search_files
[2013/06/07 23:52:15 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{77D3BF00-43D6-4C94-B0A3-7DBE98E9DFE1}
[2013/06/07 22:51:34 | 000,000,000 | ---D | C] -- C:\Users\Amanda\Desktop\Life Ideas
[2013/06/06 23:51:33 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{D5449EF6-08D5-4672-9853-2CCDA8FE28CD}
[2013/06/06 11:51:03 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{8B9A5DB0-1A46-4DA2-AE06-5F0D8953EE6C}
[2013/06/05 23:50:38 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{8570DE9A-9E01-409A-B409-A3ABC4759B0B}
[2013/06/05 22:07:43 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2013/06/05 22:07:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/06/05 22:05:45 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013/06/05 22:05:44 | 000,000,000 | ---D | C] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013/06/05 11:50:11 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{00F13A5E-0EB6-4CD4-8BDB-5CEB84D05572}
[2013/06/04 12:45:33 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{5E128A50-67B3-4DE2-8337-5C18189A75EB}
[2013/06/03 23:43:25 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{E08ACF48-E11C-4D9D-9854-0FCE9511C11D}
[2013/06/03 12:25:26 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2013/06/03 11:58:44 | 000,000,000 | ---D | C] -- C:\_OTL
[2013/06/03 11:42:45 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{C58650A2-328F-4095-9814-92FD0C3C791E}
[2013/06/02 16:16:48 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{C080BBD6-6C21-442E-BE29-10C1933B1C07}
[2013/06/01 23:54:16 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2013/06/01 23:36:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2013/06/01 23:32:13 | 000,000,000 | ---D | C] -- C:\Users\Amanda\Desktop\Computer Health
[2013/06/01 23:29:35 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Roaming\LavasoftStatistics
[2013/06/01 23:19:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xvid
[2013/06/01 23:19:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow
[2013/06/01 23:19:21 | 000,000,000 | ---D | C] -- C:\Program Files\Xvid
[2013/06/01 23:19:21 | 000,000,000 | ---D | C] -- C:\Program Files\ffdshow
[2013/06/01 23:19:17 | 000,000,000 | ---D | C] -- C:\Program Files\DivX
[2013/06/01 23:19:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
[2013/06/01 23:19:05 | 000,000,000 | ---D | C] -- C:\Program Files\DSP-worx
[2013/06/01 23:19:05 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX
[2013/06/01 23:19:04 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Roaming\LavFilters
[2013/06/01 23:19:04 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Roaming\CDXReader
[2013/06/01 23:18:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Downloaded Installations
[2013/06/01 23:18:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Symantec
[2013/06/01 23:18:04 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2013/06/01 23:17:57 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NSS
[2013/06/01 23:17:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Scan
[2013/06/01 23:17:57 | 000,000,000 | ---D | C] -- C:\Program Files\Norton Security Scan
[2013/06/01 23:17:57 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NSS\0400000.030
[2013/06/01 23:17:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
[2013/06/01 23:17:36 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
[2013/06/01 23:17:36 | 000,000,000 | ---D | C] -- C:\Program Files\NortonInstaller
[2013/06/01 23:17:20 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Roaming\DSite
[2013/06/01 23:15:24 | 000,044,424 | ---- | C] (GFI Software) -- C:\Windows\System32\sbbd.exe
[2013/06/01 23:15:24 | 000,013,560 | ---- | C] (GFI Software) -- C:\Windows\System32\drivers\gfibto.sys
[2013/06/01 17:31:30 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{1B67C954-CED6-4830-BF68-596BE6CA7590}
[2013/05/31 00:20:50 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{1144C19B-1209-4506-A04D-5ED3D63B5098}
[2013/05/30 12:20:26 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{F5C46E3E-0DB8-4FC0-ACB5-2F9D3E52FB86}
[2013/05/30 00:03:55 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{39909FA6-1950-491F-A425-4BA2C5AE1C7D}
[2013/05/29 12:03:31 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{8A6F0F7E-5666-4D41-9F49-302489830EAD}
[2013/05/28 13:48:55 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{A9F5D360-1DFD-4EDA-BEA7-D6870999D1F1}
[2013/05/27 23:33:54 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{458CA5A4-6547-4973-899A-22E79CDFC053}
[2013/05/27 11:33:27 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{AEE8D952-DE68-46C2-AABF-299695EB60F3}
[2013/05/25 13:42:55 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{D359C8A9-13C2-49C7-93CB-FE5E2F53CBD4}
[2013/05/24 12:06:30 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{23034A7D-52C0-4AE3-8FC5-B6A5F276DA99}
[2013/05/23 13:47:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013/05/23 13:47:00 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2013/05/23 13:25:31 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{DA2AF7E6-0590-46C1-8C18-28C9FF83CFB0}
[2013/05/22 12:25:55 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{922683DF-B812-4ADA-AB58-33DFE3FFE3D7}
[2013/05/21 22:48:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
[2013/05/21 22:48:06 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2013/05/21 20:58:02 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{124474E7-63E6-4CC4-B1E8-CCCEFA5B06A2}
[2013/05/20 21:21:47 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{9EEDE4C4-DDBB-4E31-A9DE-CDDB3C92277F}
[2013/05/20 13:35:58 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{55D2BA2B-905C-4368-8225-B814447E96D3}
[2013/05/19 12:22:22 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{A878D055-F9D1-4B17-BB5E-0F1F7A1CEB12}
[2013/05/18 14:01:49 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{AA5902BD-EC2F-4AFE-B231-F064C4A4AC1E}
[2013/05/17 21:17:35 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{2787E9A9-8D37-4377-8C67-1EA0826136A5}
[2013/05/16 12:38:46 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{94517B3D-83E8-4396-B334-160B8355DFB2}
[2013/05/16 00:17:54 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\Lexar Media
[2013/05/15 12:58:38 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{E9222793-7352-493F-97DB-09D4F2BAEE10}
[2013/05/14 23:40:27 | 002,706,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013/05/14 23:40:25 | 002,877,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013/05/14 23:40:25 | 000,039,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013/05/14 23:40:24 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013/05/14 23:40:24 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2013/05/14 23:40:23 | 000,493,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013/05/14 23:40:23 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2013/05/14 23:40:23 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RegisterIEPKEYs.exe
[2013/05/14 23:40:23 | 000,042,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2013/05/14 23:40:23 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2013/05/14 21:13:17 | 000,040,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wwanprotdim.dll
[2013/05/14 21:13:16 | 002,347,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2013/05/14 21:13:12 | 000,218,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxgmms1.sys
[2013/05/14 21:13:07 | 001,796,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\authui.dll
[2013/05/14 21:13:07 | 000,101,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\consent.exe
[2013/05/14 14:08:40 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{F2269C77-DE8D-4C3C-9ACE-1BC508C3B26A}
[2013/05/13 13:16:34 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{805C8F25-C16E-49E8-8390-3CB1A813AE4D}
[2013/05/13 00:01:48 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{66BA18CB-D7E0-4010-814D-E10912BFC07A}
[2013/05/09 23:28:11 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\{665F9030-2FD4-4080-8545-985C1AD20CAA}

========== Files - Modified Within 30 Days ==========

[2013/06/08 14:02:45 | 000,013,440 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/08 14:02:45 | 000,013,440 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/08 13:59:03 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/08 13:55:52 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/08 13:55:51 | 000,000,378 | -H-- | M] () -- C:\Windows\tasks\WxDFastUpdaterTask{BFEFFC0C-520A-4271-BB59-16FAFD04159C}.job
[2013/06/08 13:55:24 | 000,000,000 | ---- | M] () -- C:\Windows\System32\drivers\lvuvc.hs
[2013/06/08 13:55:23 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/06/08 13:55:19 | 1602,097,152 | -HS- | M] () -- C:\hiberfil.sys
[2013/06/08 13:54:36 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2013/06/08 08:34:59 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1000443104-1969732642-3790898716-1000UA.job
[2013/06/08 08:34:57 | 000,000,290 | ---- | M] () -- C:\Windows\tasks\DSite.job
[2013/06/08 08:12:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/06/08 00:04:02 | 000,307,698 | ---- | M] () -- C:\Users\Amanda\Desktop\how to back up phone - Google Search.htm
[2013/06/07 14:19:00 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1000443104-1969732642-3790898716-1000Core.job
[2013/06/07 13:19:16 | 000,000,408 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Amanda.job
[2013/06/02 13:52:22 | 000,351,000 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/06/01 23:19:05 | 000,001,786 | ---- | M] () -- C:\Windows\unins000.dat
[2013/06/01 23:19:01 | 000,715,038 | ---- | M] () -- C:\Windows\unins000.exe
[2013/06/01 23:15:23 | 000,044,424 | ---- | M] (GFI Software) -- C:\Windows\System32\sbbd.exe
[2013/06/01 23:15:23 | 000,013,560 | ---- | M] (GFI Software) -- C:\Windows\System32\drivers\gfibto.sys
[2013/05/27 22:14:11 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2013/05/27 22:14:11 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/05/21 00:11:27 | 000,669,432 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/05/21 00:11:27 | 000,125,514 | ---- | M] () -- C:\Windows\System32\perfc009.dat

========== Files Created - No Company Name ==========

[2013/06/08 00:03:59 | 000,307,698 | ---- | C] () -- C:\Users\Amanda\Desktop\how to back up phone - Google Search.htm
[2013/06/01 23:19:35 | 000,153,088 | ---- | C] () -- C:\Windows\System32\xvid.ax
[2013/06/01 23:19:34 | 000,645,632 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2013/06/01 23:19:34 | 000,240,640 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2013/06/01 23:19:25 | 000,079,360 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2013/06/01 23:19:05 | 000,216,064 | ---- | C] ( ) -- C:\Windows\System32\lagarith.dll
[2013/06/01 23:19:04 | 000,715,038 | ---- | C] () -- C:\Windows\unins000.exe
[2013/06/01 23:19:04 | 000,001,786 | ---- | C] () -- C:\Windows\unins000.dat
[2013/06/01 23:18:15 | 000,000,408 | -H-- | C] () -- C:\Windows\tasks\Norton Security Scan for Amanda.job
[2013/06/01 23:17:57 | 000,000,172 | ---- | C] () -- C:\Windows\System32\drivers\NSS\0400000.030\isolate.ini
[2013/06/01 23:17:25 | 000,000,290 | ---- | C] () -- C:\Windows\tasks\DSite.job
[2013/05/21 22:48:14 | 000,000,886 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/21 22:48:12 | 000,000,882 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/24 16:37:46 | 000,444,283 | ---- | C] () -- C:\Program Files\Common Files\WinPcapNmap.exe
[2012/12/02 15:56:23 | 000,011,776 | ---- | C] () -- C:\Windows\System32\pmsbfn32.dll
[2012/11/29 22:33:28 | 000,000,502 | ---- | C] () -- C:\Windows\System32\CNCMFP34.INI
[2012/05/20 23:56:17 | 000,003,584 | ---- | C] () -- C:\Users\Amanda\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/04/29 17:10:00 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2012/01/19 01:48:06 | 000,088,688 | ---- | C] () -- C:\Windows\System32\cpwmon2k.dll
[2012/01/18 23:31:27 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2012/01/18 23:30:27 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2012/01/18 13:45:01 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2012/01/16 14:29:05 | 000,140,288 | ---- | C] () -- C:\Windows\System32\igfxtvcx.dll

========== ZeroAccess Check ==========

[2009/07/13 21:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/02/26 21:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 05:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/13 18:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >


Extras.txt
OTL Extras logfile created on: 6/8/2013 1:58:02 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Amanda\Desktop\Computer Health
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16576)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.94 Gb Available Physical Memory | 47.27% Memory free
3.98 Gb Paging File | 2.74 Gb Available in Paging File | 68.76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 129.83 Gb Free Space | 55.75% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 14.87 Gb Free Space | 99.15% Space Free | Partition Type: NTFS
Drive E: | 4.02 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: AMANDA-PC | User Name: Amanda | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{24F5AB87-A7EC-424D-BEF9-84BDCFF0CB75}" = lport=139 | protocol=6 | dir=in | app=system |
"{3559DCC7-716C-431E-A319-6D322C75F04B}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{374214F2-4D0E-480F-B2B6-AB1123C4DE51}" = lport=137 | protocol=17 | dir=in | app=system |
"{4D12CDE8-FB9F-4C48-AAE8-F3A8A1F2A826}" = lport=445 | protocol=6 | dir=in | app=system |
"{75484368-E40A-4FD6-B598-2655BB899806}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{89FC3091-D8EC-49F5-A047-4A764F62D6E1}" = rport=139 | protocol=6 | dir=out | app=system |
"{8E680941-53F2-419D-BEA8-E1B3F0114A4E}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{B45E7F45-7750-4AF6-8FBD-98BB469014A0}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E10FE239-3FAD-4D04-915A-3F3ECCD1E2C9}" = rport=445 | protocol=6 | dir=out | app=system |
"{E60DEE99-7B95-4D99-B3DD-9550F65B5AF2}" = rport=138 | protocol=17 | dir=out | app=system |
"{E81C8A24-60BC-4BD6-B3A2-AAC9D61B7798}" = lport=138 | protocol=17 | dir=in | app=system |
"{F592662D-83FF-457E-B5E2-BCAEFA2CFD08}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |
"{F8FF39AA-72FD-4B20-AB47-A4A2655F5B14}" = rport=137 | protocol=17 | dir=out | app=system |
"{FC070BFB-9F45-4CCA-AA78-ABA922D067CE}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{15DBC039-A04D-44D3-93E9-00D4DA823189}" = protocol=58 | dir=out | [email protected],-28546 |
"{21440973-2EF8-42FE-91C7-D3CC0AA80308}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{2B114ABF-0D23-4A3E-9124-35F6EA5089EA}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{34D4B198-7699-4E4C-8E81-EFDCF37EFC49}" = protocol=58 | dir=in | [email protected],-28545 |
"{40C2BF53-E5EB-4968-998A-339ADC8CAEA6}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
"{4C17E2B3-210C-431F-9FDD-A9187C876F68}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{6BB73E7D-0F1C-456F-8643-6B2348E4CE74}" = protocol=6 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
"{8A71C2E0-D8A4-4CE0-A66A-11D5622CBA0D}" = dir=in | app=c:\users\amanda\appdata\local\facebook\video\skype\facebookvideocalling.exe |
"{9B9A2219-7BAC-40E0-BC4A-56C24AF7E0D0}" = protocol=17 | dir=in | app=c:\users\amanda\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{BCBCE504-3A96-41D3-8CBF-8E2DBF26FB10}" = protocol=6 | dir=in | app=c:\users\amanda\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{CAB2010B-5E2B-4542-B589-584C363A1F59}" = protocol=1 | dir=in | [email protected],-28543 |
"{D219CC93-3B30-41DB-9F22-512ABE76A802}" = protocol=17 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
"{EFDB304A-B3B8-40C6-AB48-9B0F08784A8C}" = protocol=1 | dir=out | [email protected],-28544 |
"{F0C0CA57-60D8-4817-AAF1-8F5B3EB46353}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{FA795FBE-53DE-44F5-9619-B09BBF368D0C}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{FB7E2958-9512-44A9-976B-14D3CD2F961A}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"TCP Query User{3C9322CF-263E-4E7E-B931-2984029FCB20}C:\program files\seagate\seagate dashboard 2.0\dashboard.exe" = protocol=6 | dir=in | app=c:\program files\seagate\seagate dashboard 2.0\dashboard.exe |
"UDP Query User{ED4DB5F5-1F69-4AA2-BA4C-3FE91F4E28AA}C:\program files\seagate\seagate dashboard 2.0\dashboard.exe" = protocol=17 | dir=in | app=c:\program files\seagate\seagate dashboard 2.0\dashboard.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1C3DA126-D523-4089-BCCA-FA46FE34D6F8}" = Google Drive
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{247C5DDA-FFD7-44E0-8BF7-79BC80A0BF87}" = Windows Live Family Safety
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 21
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2D6E3D97-1FDF-4993-AC75-72F59EC445C5}" = Windows Live Family Safety
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{390DD8BB-BB57-4942-A029-2D913E4E9D74}" = Microsoft Security Client
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{43C423D9-E6D6-4607-ADC9-EBB54F690C57}" = Seagate Dashboard 2.0
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support
"{6767DFEE-8909-453A-B553-C7693912B2EB}" = Canon MF Toolbox 4.9.1.1.mf09
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{82BF2C5E-79A7-4A13-B508-D5E64A5B141E}" = Uninstall Helper
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{87AEED05-C717-47bc-93BB-F8E527D2690F}" = Canon D400-450
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91FD46D2-4FB7-4A51-8637-556E1BE1DB7C}" = iTunes
"{925F1DB6-E86E-4378-9091-D1F68B0583C9}" = iCloud
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{9489EB15-6BEE-CF1F-2636-CD0B0619DB83}" = Batch PDF Merger
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98613C99-1399-416C-A07C-1EE1C585D872}" = SeaTools for Windows
"{9A781940-AC41-4D5E-8E1E-76A04B916FB9}" = Carbon
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0087DDE-69D0-11E2-AD57-43CA6188709B}" = Adobe AIR
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A6AC699F-8315-40CA-8F70-E917494978AB}" = VirtualDJ Home FREE
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A7E19604-93AF-4611-8C9F-CE509C2B286E}_is1" = VDownloader 3.9.1421
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.7)
"{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}" = RealDownloader
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B4EE51E6-2C80-4B04-BDE0-ED4E87BEFECD}_is1" = Pavtube Video Converter Ver 3.7.3.1865
"{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime
"{B92C5909-1D37-4C51-8397-A28BB28E5DC3}" = Facebook Video Calling 1.2.0.287
"{C27BC2A2-30DD-4014-B22E-63EB0DB572F9}" = Logitech Webcam Software
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D2D6B9EB-C6DC-4DAA-B4DE-BB7D9735E7DA}" = Presto! PageManager 7.15.35
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E14ADE0E-75F3-4A46-87E5-26692DD626EC}" = Apple Mobile Device Support
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F59AC46C-10C3-4023-882C-4212A92283B3}_is1" = Lagarith Lossless Codec (1.3.27)
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Boxoft Mp3 to WAV Converter (freeware)_is1" = Boxoft Mp3 to WAV Converter (freeware)
"CCFinderAppId_is1" = CCFinder
"CCleaner" = CCleaner
"com.essexreddevelopment.mergepdfmac" = Batch PDF Merger
"ConverterLite" = ConverterLite 1.6.2
"CutePDF Writer Installation" = CutePDF Writer 3.0
"DivX Setup" = DivX Setup
"ESET Online Scanner" = ESET Online Scanner v3
"ffdshow_is1" = ffdshow v1.1.4399 [2012-03-22]
"FileAssociationManager" = File Association Manager 0.1
"HDMI" = Intel® Graphics Media Accelerator Driver
"LameACM" = Lame ACM MP3 Codec
"Logitech Vid" = Logitech Vid HD
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 21.0 (x86 en-US)" = Mozilla Firefox 21.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP3 Clipper and Joiner_is1" = Uninstall Mp3 Clipper and Joiner
"NSS" = Norton Security Scan
"RealPlayer 16.0" = RealPlayer
"Softdiv MP3 to WAV Converter_is1" = Softdiv MP3 to WAV Converter 3.0
"Total Video Converter 3.71_is1" = Total Video Converter 3.71 100812
"TVWiz" = Intel® TV Wizard
"Uninstall Helper 2.0.1.0" = Uninstall Helper
"UnzipLite" = UnzipLite 0.2
"WinLiveSuite" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.1.1
"Xvid Video Codec 1.3.2" = Xvid Video Codec
"YTdetect" = Yahoo! Detect

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"DSite" = Update for Codec Pack
"UnityWebPlayer" = Unity Web Player
"VisualBee for Microsoft PowerPoint" = VisualBee for Microsoft PowerPoint

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 6/7/2013 5:19:01 PM | Computer Name = Amanda-PC | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 17

Error - 6/7/2013 5:19:01 PM | Computer Name = Amanda-PC | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 18

Error - 6/7/2013 5:19:01 PM | Computer Name = Amanda-PC | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 19

Error - 6/7/2013 5:19:01 PM | Computer Name = Amanda-PC | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 20

Error - 6/7/2013 5:19:04 PM | Computer Name = Amanda-PC | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 21

Error - 6/7/2013 5:19:04 PM | Computer Name = Amanda-PC | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 22

Error - 6/7/2013 5:19:04 PM | Computer Name = Amanda-PC | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 23

Error - 6/7/2013 5:19:04 PM | Computer Name = Amanda-PC | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 24

Error - 6/8/2013 5:56:41 AM | Computer Name = Amanda-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\Seagate\Seagate
Dashboard 2.0\NBVSSTool_x64.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 6/8/2013 5:59:25 AM | Computer Name = Amanda-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}\recordingmanager.exe".
Dependent
Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

[ System Events ]
Error - 6/8/2013 4:53:29 PM | Computer Name = Amanda-PC | Source = Service Control Manager | ID = 7001
Description = The DNS Client service depends on the NetIO Legacy TDI Support Driver
service which failed to start because of the following error: %%31

Error - 6/8/2013 4:53:29 PM | Computer Name = Amanda-PC | Source = Service Control Manager | ID = 7001
Description = The TCP/IP NetBIOS Helper service depends on the Ancillary Function
Driver for Winsock service which failed to start because of the following error:
%%31

Error - 6/8/2013 4:53:29 PM | Computer Name = Amanda-PC | Source = Service Control Manager | ID = 7001
Description = The Network Store Interface Service service depends on the NSI proxy
service driver. service which failed to start because of the following error: %%31

Error - 6/8/2013 4:53:29 PM | Computer Name = Amanda-PC | Source = Service Control Manager | ID = 7001
Description = The Workstation service depends on the Network Store Interface Service
service which failed to start because of the following error: %%1068

Error - 6/8/2013 4:53:29 PM | Computer Name = Amanda-PC | Source = Service Control Manager | ID = 7001
Description = The IP Helper service depends on the Network Store Interface Service
service which failed to start because of the following error: %%1068

Error - 6/8/2013 4:53:29 PM | Computer Name = Amanda-PC | Source = Service Control Manager | ID = 7001
Description = The SMB MiniRedirector Wrapper and Engine service depends on the Redirected
Buffering Sub Sysytem service which failed to start because of the following error:
%%31

Error - 6/8/2013 4:53:29 PM | Computer Name = Amanda-PC | Source = Service Control Manager | ID = 7001
Description = The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector
Wrapper and Engine service which failed to start because of the following error:
%%1068

Error - 6/8/2013 4:53:29 PM | Computer Name = Amanda-PC | Source = Service Control Manager | ID = 7001
Description = The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector
Wrapper and Engine service which failed to start because of the following error:
%%1068

Error - 6/8/2013 4:53:29 PM | Computer Name = Amanda-PC | Source = Service Control Manager | ID = 7001
Description = The Network Location Awareness service depends on the Network Store
Interface Service service which failed to start because of the following error:
%%1068

Error - 6/8/2013 4:53:29 PM | Computer Name = Amanda-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD CSC DfsC discache MpFilter NetBIOS NetBT nsiproxy Psched rdbss spldr tdx Wanarpv6 WfpLwf


< End of report >
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP