He gave me the items (this was a virtual transaction) and i sent him payment. After everything is done, i went to the bathroom, came back and everything was gone. He logged onto my account took everything he just gave me and still has the payment i sent him.
The only way he could possibly get my account information is if i was keylogged. During our entire conversation i was logging onto my bank account, logging onto paypal and other things, i immediatly changed my passwords using a laptop i have but am still afraid he got ahold of other information. i have the link for the website if it helps anyone.
I've run malwarebytes and security essentials and neither found anything.
heres my OTL log
OTL logfile created on: 11/11/2013 5:03:02 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Juan\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16721)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
15.90 Gb Total Physical Memory | 12.90 Gb Available Physical Memory | 81.14% Memory free
31.80 Gb Paging File | 28.66 Gb Available in Paging File | 90.13% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 119.14 Gb Total Space | 23.16 Gb Free Space | 19.44% Space Free | Partition Type: NTFS
Drive E: | 100.00 Mb Total Space | 71.42 Mb Free Space | 71.42% Space Free | Partition Type: NTFS
Drive F: | 465.66 Gb Total Space | 263.78 Gb Free Space | 56.65% Space Free | Partition Type: NTFS
Computer Name: JUANSBEAST | User Name: Juan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/11/11 17:02:33 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Juan\Desktop\OTL.exe
PRC - [2013/11/11 16:44:52 | 000,033,818 | ---- | M] (Microsoft Corporation) -- C:\Users\Juan\AppData\Local\Temp\RegSvcs.exe
PRC - [2013/11/05 23:57:43 | 000,174,504 | ---- | M] (Oracle Corporation) -- C:\Program Files (x86)\Java\jre7\bin\java.exe
PRC - [2013/10/10 13:57:30 | 001,141,328 | ---- | M] (BitTorrent Inc.) -- C:\Users\Juan\AppData\Roaming\uTorrent\uTorrent.exe
PRC - [2013/10/08 19:02:45 | 000,844,752 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2012/08/08 17:17:52 | 003,101,056 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetSvcHelp.exe
PRC - [2012/07/16 21:01:20 | 000,658,080 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\AI Suite II\Remote GO!\AsDLNAServerReal.exe
PRC - [2012/07/12 16:36:06 | 003,984,032 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\AI Suite II\Remote GO!\AssistTools\WiFi GO! Server.exe
PRC - [2012/03/13 11:34:12 | 002,935,424 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
PRC - [2012/02/02 14:20:32 | 000,889,984 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetiCtrlTray.exe
PRC - [2011/09/08 20:29:12 | 001,112,704 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
========== Modules (No Company Name) ==========
MOD - [2013/11/11 16:59:44 | 000,143,872 | ---- | M] () -- C:\Users\Juan\AppData\Local\Temp\BridJExtractedLibraries6657907933462954121\bridj.dll
MOD - [2013/11/11 16:59:44 | 000,056,510 | ---- | M] () -- C:\Users\Juan\AppData\Local\Temp\JNativeHook_4697570738310298803.dll
MOD - [2013/11/11 16:59:44 | 000,048,128 | ---- | M] () -- C:\Users\Juan\AppData\Local\Temp\BridJExtractedLibraries6657907933462954121\OpenIMAJGrabber.dll
MOD - [2013/10/11 21:29:01 | 001,670,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\f4e49f5f51d2fa5e6190464468dff4d3\Microsoft.VisualBasic.ni.dll
MOD - [2013/10/11 21:28:52 | 001,051,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\9a1bc983c28c695729b3e46acdc6933e\System.Management.ni.dll
MOD - [2013/10/11 21:28:32 | 000,220,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\de6ee26de5e4f343509de7e92ab48ba6\CustomMarshalers.ni.dll
MOD - [2013/10/11 19:54:41 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ef0a534be135cd8f0d99d938d8b1814a\System.Windows.Forms.ni.dll
MOD - [2013/10/11 19:54:36 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5aa44bce7933e4de09d935848f868a4b\System.Drawing.ni.dll
MOD - [2013/10/11 19:54:23 | 005,464,064 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\09db78d6068543df01862a023aca785a\System.Xml.ni.dll
MOD - [2013/10/11 19:54:21 | 000,978,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\29f3ae8d313e62b4daed1107ccd29f9f\System.Configuration.ni.dll
MOD - [2013/10/11 19:54:20 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5d22a30e587e2cac106b81fb351e7c08\System.ni.dll
MOD - [2013/10/11 19:54:16 | 011,499,520 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9a6c1b7af18b4d5a91dc7f8d6617522f\mscorlib.ni.dll
MOD - [2013/10/08 19:02:43 | 000,415,184 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppgooglenaclpluginchrome.dll
MOD - [2013/10/08 19:02:42 | 013,584,336 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll
MOD - [2013/10/08 19:02:41 | 004,055,504 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll
MOD - [2013/10/08 19:01:50 | 000,698,832 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\libglesv2.dll
MOD - [2013/10/08 19:01:49 | 000,099,792 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\libegl.dll
MOD - [2013/10/08 19:01:47 | 001,604,560 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ffmpegsumo.dll
MOD - [2012/08/15 13:42:40 | 000,786,432 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\func.dll
MOD - [2012/07/31 14:21:32 | 000,152,064 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\gep.dll
MOD - [2012/06/22 12:32:10 | 000,184,320 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\Remote GO!\AssistTools\DLCapPP.dll
MOD - [2012/05/02 17:04:30 | 000,233,472 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\Remote GO!\AssistTools\AudioProjection.dll
MOD - [2012/04/25 13:47:54 | 000,659,456 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\Remote GO!\AssistTools\PhoneCtrlAPI.dll
MOD - [2012/04/20 15:24:08 | 000,716,800 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\Remote GO!\AssistTools\WiMoveHelp.dll
MOD - [2012/01/12 15:44:02 | 000,475,136 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\Remote GO!\AssistTools\WiFiGO_HookKey.dll
MOD - [2011/08/09 13:52:50 | 000,425,984 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\Remote GO!\AssistTools\awiscale.dll
MOD - [2010/12/14 16:46:32 | 000,067,584 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\Remote GO!\AssistTools\CoreAudioCap.dll
MOD - [2010/11/04 20:57:39 | 000,069,120 | ---- | M] () -- C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
MOD - [2010/10/05 07:22:50 | 000,253,952 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\pngio.dll
MOD - [2009/08/12 19:15:52 | 000,253,952 | ---- | M] () -- C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\pngio.dll
========== Services (SafeList) ==========
SRV:64bit: - [2013/06/20 20:33:08 | 000,366,600 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2013/06/20 20:33:08 | 000,023,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2013/05/27 00:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2012/09/27 20:38:16 | 000,239,616 | ---- | M] (AMD) [Disabled | Stopped] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2013/10/30 14:25:56 | 000,566,696 | ---- | M] (Valve Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2013/10/15 14:43:22 | 001,475,744 | ---- | M] (ASUSTeK Computer Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.10\AsusFanControlService.exe -- (AsusFanControlService)
SRV - [2013/10/15 14:24:08 | 000,951,936 | ---- | M] (ASUSTeK Computer Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe -- (asHmComSvc)
SRV - [2013/10/15 14:24:08 | 000,920,736 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe -- (asComSvc)
SRV - [2013/10/15 14:24:08 | 000,149,120 | ---- | M] (ASUSTeK Computer Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe -- (AsSysCtrlService)
SRV - [2013/09/05 10:34:30 | 000,171,680 | R--- | M] (Skype Technologies) [Disabled | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/09/05 09:04:00 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/06/12 19:11:22 | 000,303,952 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\Linksys WUSB6300\WifiSvc.exe -- (WSWUSB6300)
SRV - [2012/09/20 09:00:18 | 000,036,864 | ---- | M] () [Disabled | Stopped] -- C:\Windows\runSW.exe -- (RunSwUSB)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - File not found [Kernel | Disabled | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys -- (AODDriver4.2)
DRV:64bit: - [2013/10/10 17:01:04 | 000,564,824 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2013/06/24 12:36:12 | 000,420,608 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\asmtxhci.sys -- (asmtxhci)
DRV:64bit: - [2013/06/24 12:36:12 | 000,140,032 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\asmthub3.sys -- (asmthub3)
DRV:64bit: - [2013/06/18 21:50:08 | 000,139,616 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2013/03/25 18:18:48 | 002,345,544 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTWlanU.sys -- (RtlWlanu)
DRV:64bit: - [2013/03/25 18:18:48 | 002,345,544 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RTWlanU.sys -- (RTL8192cu)
DRV:64bit: - [2012/09/27 21:21:20 | 010,697,216 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012/09/27 20:12:52 | 000,460,288 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012/08/28 19:27:24 | 000,058,536 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2012/06/12 21:00:48 | 000,726,160 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2012/05/31 10:06:14 | 000,032,400 | ---- | M] (NT Kernel Resources) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ndisrd.sys -- (ndisrd)
DRV:64bit: - [2012/05/14 01:12:30 | 000,096,896 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2012/04/11 08:40:58 | 000,082,560 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV:64bit: - [2012/04/11 08:40:58 | 000,042,624 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV:64bit: - [2012/03/01 01:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/03/29 08:15:00 | 001,254,464 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AE2500w764.sys -- (Linksys_adapter_H)
DRV:64bit: - [2011/03/11 01:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 01:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 08:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 06:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009/07/13 20:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE10SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.0: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://www.google.com/
CHR - Extension: Google Docs = C:\Users\Juan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\Juan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: James White = C:\Users\Juan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkeidgmehkdjmpjodpjkepolokanalkm\3_0\
CHR - Extension: YouTube = C:\Users\Juan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\Juan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Autocomplete = on = C:\Users\Juan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecpgkdflcnofdbbkiggklcfmgbnbabhh\1.0_0\
CHR - Extension: Google Wallet = C:\Users\Juan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0\
CHR - Extension: Gmail = C:\Users\Juan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WindowsUpdate] C:\Users\Juan\FTZOH\ZEv7G22d.vbe ()
O4 - HKCU..\Run: [File] C:\Program Files (x86)\Java\jre7\bin\javaw.exe (Oracle Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4D208E76-EC1A-48FF-BCA0-F861D2BC1919}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{613F64F0-B4E6-4AA4-87E5-D5CBBCB1688C}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CA2B03EA-D667-4DB6-815B-6213AA7590C7}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E1E2AB26-47A4-493C-97CA-221B5901B027}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O22:64bit: - SharedTaskScheduler: {F791A188-699D-4FD4-955A-EB59E89B1907} - Theme Resource Changer - \Program Files\Theme Resource Changer\ThemeResourceChanger.dll ()
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{8ab44677-31f7-11e3-92cc-a644df85a930}\Shell - "" = AutoRun
O33 - MountPoints2\{8ab44677-31f7-11e3-92cc-a644df85a930}\Shell\AutoRun\command - "" = D:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/11/11 17:02:33 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Juan\Desktop\OTL.exe
[2013/11/11 16:51:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2013/11/11 16:51:57 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2013/11/11 16:44:48 | 000,000,000 | -H-D | C] -- C:\Users\Juan\FTZOH
[2013/11/11 10:37:35 | 000,000,000 | ---D | C] -- C:\Users\Juan\Desktop\pic_files
[2013/11/11 10:30:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VS Revo Group
[2013/11/11 10:30:56 | 000,000,000 | ---D | C] -- C:\Users\Juan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
[2013/11/11 10:30:49 | 002,623,656 | ---- | C] (VS Revo Group Ltd.) -- C:\Users\Juan\Desktop\revosetup.exe
[2013/11/11 10:27:36 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013/11/10 14:46:30 | 004,121,952 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Juan\Desktop\tdsskiller.exe
[2013/11/10 14:44:28 | 000,000,000 | ---D | C] -- C:\Users\Juan\AppData\Roaming\Malwarebytes
[2013/11/10 14:36:26 | 000,000,000 | ---D | C] -- C:\Users\Juan\Desktop\SF_10-11-2013
[2013/11/10 01:58:11 | 000,000,000 | ---D | C] -- C:\Users\Juan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft BlueScreenView
[2013/11/10 01:58:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NirSoft
[2013/11/08 14:38:56 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2013/11/07 21:49:25 | 000,000,000 | ---D | C] -- C:\Users\Juan\AppData\Roaming\Skype
[2013/11/07 21:49:23 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2013/11/07 21:49:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013/11/07 21:49:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2013/11/07 21:49:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2013/11/06 12:51:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\dumps
[2013/11/06 12:51:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2013/11/06 12:51:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Steam
[2013/11/06 12:51:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
[2013/11/06 00:43:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VLC Amigo Setup
[2013/11/06 00:43:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VLC Amigo Setup
[2013/11/06 00:00:40 | 000,000,000 | ---D | C] -- C:\Users\Juan\jagexcache5
[2013/11/06 00:00:40 | 000,000,000 | ---D | C] -- C:\Users\Juan\jagexcache4
[2013/11/06 00:00:40 | 000,000,000 | ---D | C] -- C:\Users\Juan\jagexcache3
[2013/11/06 00:00:40 | 000,000,000 | ---D | C] -- C:\Users\Juan\jagexcache2
[2013/11/06 00:00:40 | 000,000,000 | ---D | C] -- C:\Users\Juan\jagexcache1
[2013/11/05 23:58:46 | 000,000,000 | ---D | C] -- C:\Users\Juan\jagexcache
[2013/11/05 23:58:36 | 000,000,000 | ---D | C] -- C:\Users\Juan\AppData\Roaming\.tribot
[2013/11/05 23:58:35 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2013/11/05 23:58:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
[2013/11/05 23:57:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2013/11/05 23:57:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2013/11/05 23:57:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2013/11/05 23:57:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2013/11/05 23:57:34 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2013/10/16 16:41:38 | 000,000,000 | ---D | C] -- C:\Users\Juan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Theme Resource Changer X64 v1.0
[2013/10/16 16:41:33 | 000,000,000 | ---D | C] -- C:\Program Files\Theme Resource Changer
[2013/10/16 16:37:51 | 000,000,000 | ---D | C] -- C:\Users\Juan\Desktop\black seven original
[2013/10/16 16:37:51 | 000,000,000 | ---D | C] -- C:\Users\Juan\Desktop\black blue 4
[2013/10/16 16:27:11 | 000,000,000 | ---D | C] -- C:\Users\Juan\Desktop\windows 7 themes alien tech (red)
[2013/10/15 18:38:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Square Enix
[2013/10/15 18:31:46 | 000,430,080 | ---- | C] (Realtek) -- C:\Windows\SwUSB.exe
[2013/10/15 18:31:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Linksys WUSB6300
[2013/10/15 15:19:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ASM104xUSB3
[2013/10/15 15:04:57 | 000,000,000 | ---D | C] -- C:\ProgramData\ASUS OC Profiles
[2013/10/15 14:48:23 | 000,046,152 | ---- | C] (MCCI Corporation) -- C:\Windows\SysWow64\drivers\ASUSFILTER.sys
[2013/10/15 14:48:23 | 000,000,000 | ---D | C] -- C:\Program Files\ASUS
[2013/10/15 14:45:37 | 000,032,400 | ---- | C] (NT Kernel Resources) -- C:\Windows\SysNative\drivers\ndisrd.sys
[2013/10/15 14:43:49 | 000,014,848 | ---- | C] (ASUSTek Computer Inc.) -- C:\Windows\SysWow64\drivers\AiChargerPlus.sys
[2013/10/15 14:38:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
[2013/10/15 14:30:57 | 000,726,160 | ---- | C] (Realtek ) -- C:\Windows\SysNative\drivers\Rt64win7.sys
[2013/10/15 14:30:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek
[2013/10/15 14:24:37 | 000,184,320 | ---- | C] (ASUSTeK) -- C:\Windows\SysWow64\drivers\UpdateHelper.dll
[2013/10/15 14:24:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
[2013/10/15 14:24:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2013/10/15 14:24:13 | 000,000,000 | ---D | C] -- C:\ProgramData\ASUS
[2013/10/15 14:24:08 | 000,028,672 | ---- | C] (ASUSTek Computer Inc.) -- C:\Windows\SysWow64\AsIO.dll
[2013/10/15 14:24:08 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\drivers\MFDLL
[2013/10/15 14:24:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ASUS
[2013/10/13 17:59:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
[2013/10/13 17:57:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Ubisoft
[2013/10/13 17:57:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2013/10/13 17:57:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
[2013/10/13 17:55:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Activision
[2013/10/13 17:55:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GOG.com
[2013/10/13 14:41:42 | 000,240,248 | ---- | C] (CACE Technologies) -- C:\Windows\SysWow64\wpcap.dll
[2013/10/13 14:41:42 | 000,088,704 | ---- | C] (CACE Technologies) -- C:\Windows\SysWow64\packet.dll
[2013/10/13 14:41:42 | 000,068,224 | ---- | C] (CACE Technologies) -- C:\Windows\SysWow64\WanPacket.dll
[2013/10/13 14:41:42 | 000,040,464 | ---- | C] (CACE Technologies) -- C:\Windows\SysNative\drivers\npf.sys
[2013/10/10 13:57:28 | 000,844,752 | ---- | C] (Google Inc.) -- C:\Users\Juan\AppData\Roaming\mhost.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Juan\AppData\Roaming\*.tmp files -> C:\Users\Juan\AppData\Roaming\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/11/11 17:04:29 | 000,047,860 | ---- | M] () -- C:\Users\Juan\AppData\Roaming\user
[2013/11/11 17:02:33 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Juan\Desktop\OTL.exe
[2013/11/11 16:59:43 | 001,576,359 | ---- | M] () -- C:\Users\Juan\AppData\Roaming\File.jar
[2013/11/11 16:59:21 | 000,157,240 | ---- | M] () -- C:\Users\Juan\Desktop\JavaRa-2.3.zip
[2013/11/11 16:52:53 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2013/11/11 16:33:00 | 000,000,043 | ---- | M] () -- C:\Users\Juan\jagex_cl_oldschool_LIVE.dat
[2013/11/11 16:33:00 | 000,000,000 | R--- | M] () -- C:\Users\Juan\random.dat
[2013/11/11 16:31:08 | 001,590,880 | ---- | M] () -- C:\Users\Juan\jbytstvjz.jar
[2013/11/11 16:14:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/11/11 15:35:00 | 000,040,508 | ---- | M] () -- C:\Users\Juan\Desktop\amazon.png
[2013/11/11 13:35:34 | 001,590,880 | ---- | M] () -- C:\Users\Juan\rutyqyi.jar
[2013/11/11 13:34:25 | 001,590,880 | ---- | M] () -- C:\Users\Juan\osshytnks.jar
[2013/11/11 13:20:08 | 000,231,708 | ---- | M] () -- C:\Users\Juan\onbsgsna.jar
[2013/11/11 13:15:50 | 000,173,281 | ---- | M] () -- C:\Users\Juan\KWKMV
[2013/11/11 13:03:26 | 000,231,708 | ---- | M] () -- C:\Users\Juan\xopjvgjxw.jar
[2013/11/11 13:02:56 | 000,231,708 | ---- | M] () -- C:\Users\Juan\vembasibipg.jar
[2013/11/11 13:02:38 | 000,231,708 | ---- | M] () -- C:\Users\Juan\rpzaqtvm.jar
[2013/11/11 13:02:29 | 000,231,708 | ---- | M] () -- C:\Users\Juan\swbzigv.jar
[2013/11/11 12:02:00 | 000,026,982 | ---- | M] () -- C:\Users\Juan\Desktop\[HorribleSubs] Magi S2 - 06 [720p].mkv.torrent
[2013/11/11 11:03:12 | 000,048,621 | ---- | M] () -- C:\Users\Juan\Desktop\TRiBot.jar
[2013/11/11 10:37:43 | 002,430,774 | ---- | M] () -- C:\Users\Juan\Desktop\photo.JPG
[2013/11/11 10:37:35 | 000,289,859 | ---- | M] () -- C:\Users\Juan\Desktop\pic.htm
[2013/11/11 10:30:56 | 000,001,306 | ---- | M] () -- C:\Users\Juan\Desktop\Revo Uninstaller.lnk
[2013/11/11 10:30:50 | 002,623,656 | ---- | M] (VS Revo Group Ltd.) -- C:\Users\Juan\Desktop\revosetup.exe
[2013/11/11 10:22:07 | 000,056,268 | ---- | M] () -- C:\Users\Juan\Desktop\nov.png
[2013/11/11 10:21:07 | 000,067,137 | ---- | M] () -- C:\Users\Juan\Desktop\oct.png
[2013/11/11 07:38:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/11/11 03:23:01 | 000,014,416 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/11/11 03:23:01 | 000,014,416 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/11/11 03:20:04 | 000,726,316 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/11/11 03:20:04 | 000,623,940 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/11/11 03:20:04 | 000,106,316 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/11/11 03:15:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/11/11 03:15:55 | 4216,602,622 | -HS- | M] () -- C:\hiberfil.sys
[2013/11/10 19:32:05 | 000,021,504 | ---- | M] () -- C:\Users\Juan\YMQGIX
[2013/11/10 19:32:04 | 001,523,353 | ---- | M] () -- C:\Users\Juan\5Prg.vbe
[2013/11/10 19:31:49 | 000,237,124 | ---- | M] () -- C:\Users\Juan\VZYQC
[2013/11/10 19:31:47 | 000,466,952 | ---- | M] () -- C:\Users\Juan\VBEBE
[2013/11/10 19:30:46 | 000,236,445 | -H-- | M] () -- C:\Users\Juan\HWBJD
[2013/11/10 14:46:37 | 004,121,952 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Juan\Desktop\tdsskiller.exe
[2013/11/10 14:39:14 | 000,354,614 | ---- | M] () -- C:\Users\Juan\Desktop\magepker.rar
[2013/11/10 14:35:19 | 000,000,000 | ---- | M] () -- C:\Windows\Path.idx
[2013/11/10 14:35:09 | 000,221,159 | ---- | M] () -- C:\Users\Juan\Desktop\SF_Diagnostic_Tool.zip
[2013/11/10 14:30:15 | 001,048,576 | ---- | M] () -- C:\Windows\PE_Rom.dll
[2013/11/10 12:14:40 | 000,147,955 | ---- | M] () -- C:\Users\Juan\Desktop\pp trans.png
[2013/11/10 11:29:25 | 000,008,389 | ---- | M] () -- C:\Users\Juan\Desktop\Grave Digger.zip
[2013/11/10 11:28:56 | 000,006,827 | ---- | M] () -- C:\Users\Juan\Desktop\DG's BONER .rar
[2013/11/10 01:58:03 | 000,141,480 | ---- | M] () -- C:\Users\Juan\Desktop\bluescreenview_setup.exe
[2013/11/10 01:45:06 | 000,025,685 | ---- | M] () -- C:\Users\Juan\Desktop\[HorribleSubs] One Piece - 620 [720p].mkv.torrent
[2013/11/09 15:33:56 | 000,017,574 | ---- | M] () -- C:\Users\Juan\Desktop\The Wolverine 2013 Unleashed Extended BDRip 720p x264 10bit AAC 5.1-MZON3.torrent
[2013/11/07 23:51:57 | 000,000,043 | ---- | M] () -- C:\Users\Juan\jagex_cl_runescape_LIVE.dat
[2013/11/07 21:49:23 | 000,002,697 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2013/11/06 12:51:25 | 000,000,955 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk
[2013/11/06 01:01:31 | 000,038,154 | ---- | M] () -- C:\Users\Juan\Desktop\AIOMagic2.1.zip
[2013/10/20 14:38:06 | 001,442,775 | ---- | M] () -- C:\Users\Juan\Desktop\ravelry_colors_on_black_by_deepbluerenegade-d4v68dz.jpg
[2013/10/16 15:18:43 | 000,002,221 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013/10/15 15:05:45 | 005,379,904 | ---- | M] () -- C:\Windows\PE_File.dll
[2013/10/15 14:30:03 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\1043_ASUSTeK_M5A97 R2.0.alu
[2013/10/12 20:49:13 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Juan\AppData\Roaming\*.tmp files -> C:\Users\Juan\AppData\Roaming\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/11/11 16:59:20 | 000,157,240 | ---- | C] () -- C:\Users\Juan\Desktop\JavaRa-2.3.zip
[2013/11/11 16:52:53 | 000,001,945 | ---- | C] () -- C:\Windows\epplauncher.mif
[2013/11/11 16:52:00 | 000,002,155 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2013/11/11 16:31:06 | 001,590,880 | ---- | C] () -- C:\Users\Juan\jbytstvjz.jar
[2013/11/11 14:11:56 | 000,040,508 | ---- | C] () -- C:\Users\Juan\Desktop\amazon.png
[2013/11/11 13:35:31 | 001,590,880 | ---- | C] () -- C:\Users\Juan\rutyqyi.jar
[2013/11/11 13:34:22 | 001,590,880 | ---- | C] () -- C:\Users\Juan\osshytnks.jar
[2013/11/11 13:20:07 | 000,231,708 | ---- | C] () -- C:\Users\Juan\onbsgsna.jar
[2013/11/11 13:16:22 | 000,047,490 | ---- | C] () -- C:\Users\Juan\AppData\Roaming\user
[2013/11/11 13:15:50 | 000,173,281 | ---- | C] () -- C:\Users\Juan\KWKMV
[2013/11/11 13:15:47 | 001,523,353 | ---- | C] () -- C:\Users\Juan\5Prg.vbe
[2013/11/11 13:15:47 | 000,466,952 | ---- | C] () -- C:\Users\Juan\VBEBE
[2013/11/11 13:15:47 | 000,237,124 | ---- | C] () -- C:\Users\Juan\VZYQC
[2013/11/11 13:15:47 | 000,236,445 | -H-- | C] () -- C:\Users\Juan\HWBJD
[2013/11/11 13:15:47 | 000,021,504 | ---- | C] () -- C:\Users\Juan\YMQGIX
[2013/11/11 13:03:25 | 000,231,708 | ---- | C] () -- C:\Users\Juan\xopjvgjxw.jar
[2013/11/11 13:02:55 | 000,231,708 | ---- | C] () -- C:\Users\Juan\vembasibipg.jar
[2013/11/11 13:02:37 | 000,231,708 | ---- | C] () -- C:\Users\Juan\rpzaqtvm.jar
[2013/11/11 13:02:30 | 001,576,359 | ---- | C] () -- C:\Users\Juan\AppData\Roaming\File.jar
[2013/11/11 13:02:29 | 000,231,708 | ---- | C] () -- C:\Users\Juan\swbzigv.jar
[2013/11/11 12:02:00 | 000,026,982 | ---- | C] () -- C:\Users\Juan\Desktop\[HorribleSubs] Magi S2 - 06 [720p].mkv.torrent
[2013/11/11 11:03:12 | 000,048,621 | ---- | C] () -- C:\Users\Juan\Desktop\TRiBot.jar
[2013/11/11 10:37:42 | 002,430,774 | ---- | C] () -- C:\Users\Juan\Desktop\photo.JPG
[2013/11/11 10:37:34 | 000,289,859 | ---- | C] () -- C:\Users\Juan\Desktop\pic.htm
[2013/11/11 10:30:56 | 000,001,306 | ---- | C] () -- C:\Users\Juan\Desktop\Revo Uninstaller.lnk
[2013/11/11 10:22:07 | 000,056,268 | ---- | C] () -- C:\Users\Juan\Desktop\nov.png
[2013/11/11 10:21:07 | 000,067,137 | ---- | C] () -- C:\Users\Juan\Desktop\oct.png
[2013/11/10 14:39:13 | 000,354,614 | ---- | C] () -- C:\Users\Juan\Desktop\magepker.rar
[2013/11/10 14:35:08 | 000,221,159 | ---- | C] () -- C:\Users\Juan\Desktop\SF_Diagnostic_Tool.zip
[2013/11/10 12:14:40 | 000,147,955 | ---- | C] () -- C:\Users\Juan\Desktop\pp trans.png
[2013/11/10 11:29:24 | 000,008,389 | ---- | C] () -- C:\Users\Juan\Desktop\Grave Digger.zip
[2013/11/10 11:28:56 | 000,006,827 | ---- | C] () -- C:\Users\Juan\Desktop\DG's BONER .rar
[2013/11/10 01:58:02 | 000,141,480 | ---- | C] () -- C:\Users\Juan\Desktop\bluescreenview_setup.exe
[2013/11/10 01:45:06 | 000,025,685 | ---- | C] () -- C:\Users\Juan\Desktop\[HorribleSubs] One Piece - 620 [720p].mkv.torrent
[2013/11/09 15:33:56 | 000,017,574 | ---- | C] () -- C:\Users\Juan\Desktop\The Wolverine 2013 Unleashed Extended BDRip 720p x264 10bit AAC 5.1-MZON3.torrent
[2013/11/07 23:51:57 | 000,000,043 | ---- | C] () -- C:\Users\Juan\jagex_cl_runescape_LIVE.dat
[2013/11/07 21:49:23 | 000,002,697 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2013/11/06 12:51:25 | 000,000,955 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk
[2013/11/06 01:01:31 | 000,038,154 | ---- | C] () -- C:\Users\Juan\Desktop\AIOMagic2.1.zip
[2013/11/05 23:58:46 | 000,000,043 | ---- | C] () -- C:\Users\Juan\jagex_cl_oldschool_LIVE.dat
[2013/11/05 23:58:46 | 000,000,000 | R--- | C] () -- C:\Users\Juan\random.dat
[2013/10/20 14:38:06 | 001,442,775 | ---- | C] () -- C:\Users\Juan\Desktop\ravelry_colors_on_black_by_deepbluerenegade-d4v68dz.jpg
[2013/10/15 18:31:46 | 000,036,864 | ---- | C] () -- C:\Windows\runSW.exe
[2013/10/15 14:30:03 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\1043_ASUSTeK_M5A97 R2.0.alu
[2013/10/15 14:26:43 | 000,000,000 | ---- | C] () -- C:\Windows\Path.idx
[2013/10/15 14:26:19 | 005,379,904 | ---- | C] () -- C:\Windows\PE_File.dll
[2013/10/15 14:25:44 | 001,048,576 | ---- | C] () -- C:\Windows\PE_Rom.dll
[2013/10/15 14:25:02 | 000,014,464 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsUpIO.sys
[2013/10/15 14:24:08 | 000,015,232 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2013/10/15 14:24:08 | 000,011,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2013/10/15 14:24:08 | 000,010,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2013/10/13 14:41:42 | 000,053,299 | ---- | C] () -- C:\Windows\SysWow64\pthreadVC.dll
[2013/10/12 20:49:13 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2013/10/11 20:17:49 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2013/10/10 14:46:50 | 000,000,037 | -HS- | C] () -- C:\Users\Juan\AppData\Local\70149b02515b3bb20dd492.47983420
[2013/10/10 14:18:15 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2013/10/10 14:06:06 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2013/10/10 14:06:05 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2013/10/10 14:06:05 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2012/05/02 13:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
========== ZeroAccess Check ==========
[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/07/25 21:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/25 20:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 20:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 07:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 20:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013/11/11 12:49:59 | 000,000,000 | ---D | M] -- C:\Users\Juan\AppData\Roaming\.tribot
[2013/11/11 17:03:21 | 000,000,000 | ---D | M] -- C:\Users\Juan\AppData\Roaming\uTorrent
========== Purity Check ==========
< End of report >
heres extras;
OTL Extras logfile created on: 11/11/2013 5:03:02 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Juan\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16721)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
15.90 Gb Total Physical Memory | 12.90 Gb Available Physical Memory | 81.14% Memory free
31.80 Gb Paging File | 28.66 Gb Available in Paging File | 90.13% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 119.14 Gb Total Space | 23.16 Gb Free Space | 19.44% Space Free | Partition Type: NTFS
Drive E: | 100.00 Mb Total Space | 71.42 Mb Free Space | 71.42% Space Free | Partition Type: NTFS
Drive F: | 465.66 Gb Total Space | 263.78 Gb Free Space | 56.65% Space Free | Partition Type: NTFS
Computer Name: JUANSBEAST | User Name: Juan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe:*:Enabled:Windows Messanger -- (Google Inc.)
"C:\Users\Juan\AppData\Roaming\mhost.exe" = C:\Users\Juan\AppData\Roaming\mhost.exe:*:Enabled:Windows Messanger -- (Google Inc.)
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe:*:Enabled:Windows Messanger -- (Google Inc.)
"C:\Users\Juan\AppData\Roaming\mhost.exe" = C:\Users\Juan\AppData\Roaming\mhost.exe:*:Enabled:Windows Messanger -- (Google Inc.)
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{06C0A6F4-5A13-48AD-A21C-AD4920B888C4}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0A618B61-E9B7-4893-AD0F-01A2746F203B}" = lport=139 | protocol=6 | dir=in | app=system |
"{3B7988C3-DF5C-4DCE-A1D7-1EAECB99E239}" = rport=137 | protocol=17 | dir=out | app=system |
"{53566748-CD9F-4BA2-A4E0-DA0F4144FCCC}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{66973355-ECC7-415F-95F6-1957628A2660}" = lport=445 | protocol=6 | dir=in | app=system |
"{674C2532-FC6F-4914-8CB9-2A3F4F17E26B}" = rport=138 | protocol=17 | dir=out | app=system |
"{6B06CC53-E105-433E-8F53-31B849E7EC19}" = lport=138 | protocol=17 | dir=in | app=system |
"{74BD21F8-0506-468D-9E2F-74A97A5D0BAF}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{77F7BF35-66E8-44DA-8A27-D6ABC849F147}" = lport=137 | protocol=17 | dir=in | app=system |
"{87CBBC2E-680F-49EF-BD47-6D5D3175D72E}" = lport=1900 | protocol=17 | dir=in | name=upnp udp 1900 |
"{881EBFBD-28AF-490F-AC4B-3C26197573A8}" = lport=2869 | protocol=6 | dir=in | name=upnp tcp 2869 |
"{933B70E7-1DC8-462D-885D-A84B73507E76}" = lport=1900 | protocol=17 | dir=in | name=upnp udp 1900 |
"{9769318A-33E8-49DF-9FC1-798FF8388155}" = rport=139 | protocol=6 | dir=out | app=system |
"{B745DF66-B779-4EEA-8B05-1B2377A835C7}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{CA267103-7FCD-4BF7-8469-36F068E3144B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{CF98D177-AE2B-4732-8CB5-73786FF527AB}" = lport=2869 | protocol=6 | dir=in | name=upnp tcp 2869 |
"{E579A228-0318-4A30-A86C-BE324866336D}" = rport=445 | protocol=6 | dir=out | app=system |
"{FD28A52B-72BF-45A3-8258-8D5A5F715CFC}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{015151CB-2A5E-4EB1-A4DD-1F67696C8495}" = protocol=6 | dir=in | app=c:\program files (x86)\gog.com\assassins creed\assassinscreed_dx9.exe |
"{0321378E-8AE2-478A-ABE2-82E0EE11A8EB}" = protocol=17 | dir=in | app=f:\nba2k14.exe |
"{03E92173-8782-4BC0-98F4-FE1783F6799E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\nmrih\sdk\bin\hammer.bat |
"{056AB43A-940E-4191-84F9-0C278C0A69BD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0E58454A-40B9-4001-AF02-5419CB5FA014}" = protocol=17 | dir=in | app=c:\program files (x86)\asus\ai suite ii\ai suite ii.exe |
"{0F25FBEE-3EDD-475D-8222-FCAB5398EB48}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{1273FBC4-F4CD-4D91-A267-E2DFA4D1F222}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{1E6545C6-F56B-46F1-9490-563708208B4D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1FD41054-3F48-44B0-8DB9-075170625A76}" = protocol=1 | dir=out | [email protected],-28544 |
"{261398B8-0A49-47C2-A7B1-ECCB83F7DE53}" = protocol=6 | dir=in | app=c:\users\juan\appdata\roaming\utorrent\utorrent.exe |
"{2DCC0396-DA7B-480A-9A17-CD6772D55517}" = protocol=17 | dir=in | app=c:\users\juan\appdata\roaming\utorrent\utorrent.exe |
"{2F05B4BB-A66A-40D8-8F21-811F0D0E03D1}" = protocol=6 | dir=in | app=f:\sftk.exe |
"{36276097-EFE1-496C-A26C-90B311D28026}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{3D1E02C8-9745-448F-8BBC-E5A7FA18F7C0}" = protocol=17 | dir=in | app=c:\program files (x86)\asus\ai suite ii\remote go!\assisttools\wifi go! server.exe |
"{416DF442-C95C-494E-8F61-772B45E42CC5}" = protocol=6 | dir=in | app=c:\program files (x86)\gog.com\assassins creed\assassinscreed_dx10.exe |
"{454EC845-558F-4D0B-8799-D8D91FB7D4D0}" = protocol=17 | dir=in | app=f:\sftk.exe |
"{4905889A-EE11-474D-899E-235D5D8F7AAA}" = protocol=6 | dir=in | app=c:\program files (x86)\asus\ai suite ii\remote go!\assisttools\wifi go! server.exe |
"{545A2362-A766-4342-A830-5EE3FE9CEDF9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{5BC361E3-16A2-4C13-AE59-59D073D4F67D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\nmrih\sdk\bin\hammer.bat |
"{760F5A38-AA76-4DE6-84FC-8C5DAA56E6AA}" = protocol=6 | dir=in | app=c:\program files (x86)\asus\ai suite ii\ai suite ii.exe |
"{921B1E5C-7294-4250-B40B-8EAF55CFFDA6}" = protocol=1 | dir=in | [email protected],-28543 |
"{9227FFE7-B8BB-48A6-92E1-E84F54AC5EC7}" = protocol=17 | dir=in | app=c:\program files (x86)\gog.com\assassins creed\assassinscreed_dx10.exe |
"{984C0EFB-55E7-4E92-8F73-5C0C8134CD55}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{A2560FF9-26C3-41B5-A341-9DEE98F25AC8}" = protocol=58 | dir=in | [email protected],-28545 |
"{B2E0670A-BF06-4A93-86FE-114288AFCAD4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{B54118E1-4236-4203-A67B-0DB350A12F99}" = protocol=58 | dir=out | [email protected],-28546 |
"{B6AA1B6C-535E-4C96-93E2-170913CE9526}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{BC197E71-9F77-42E4-9648-F0F90BFFB245}" = protocol=17 | dir=in | app=c:\program files (x86)\gog.com\assassins creed\assassinscreed_dx9.exe |
"{DF743245-CD16-41D8-87C3-97AE31C4A440}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\nmrih\sdk\hl2.exe |
"{E17EAB91-7D18-4ED8-A5CD-302CC86481E3}" = protocol=6 | dir=in | app=f:\nba2k14.exe |
"{FB36C229-07DF-42F8-BB09-B19FAD8B127A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\nmrih\sdk\hl2.exe |
"TCP Query User{D86DD831-FFFF-4286-AE22-405AF8759E0D}C:\users\juan\appdata\roaming\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\users\juan\appdata\roaming\utorrent\utorrent.exe |
"UDP Query User{7233CD37-3184-463E-A780-3AD401F11759}C:\users\juan\appdata\roaming\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\users\juan\appdata\roaming\utorrent\utorrent.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0407893F-352C-B182-E04A-A8C3333DA29B}" = AMD Drag and Drop Transcoding
"{0DCAB5DD-CC69-271A-CF03-F2BD6B60BD8A}" = AMD Media Foundation Decoders
"{27726449-83B8-428D-92DE-101346C1E15C}" = Microsoft Security Client
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{504184A2-1B0E-5D93-603A-517E93E7EDB3}" = AMD Accelerated Video Transcoding
"{5DDB9EF7-1BC0-C9C1-9829-6B9CF68AC357}" = AMD Catalyst Install Manager
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Theme Resource Changer X64 v1.0" = Theme Resource Changer X64 v1.0
"WinRAR archiver" = WinRAR 5.00 (64-bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{141B8BA9-BFFD-4635-AF64-078E31010EC3}_is1" = FINAL FANTASY VII
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{26A24AE4-039D-4CA4-87B4-2F83217045FF}" = Java 7 Update 45
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.10
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B9ADF8D-9160-418A-97DD-5E636AE9E652}_is1" = original theme
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A80CEA4E-74C1-4F9F-806B-E1D9AFC01768}" = inSSIDer 3
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.05)
"{AD492C53-49D3-30A1-837C-16E039DEC8C9}" = Google Chrome
"{C094F1A2-5EDF-4550-AE67-5FC1F4D2186F}" = Linksys Dual Band Wireless-AC USB Adapter
"{CB2E4D17-10DA-4368-AA26-ED63BF57C177}" = VLC Amigo Setup
"{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX
"{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}" = Asmedia ASM104x USB 3.0 Host Controller Driver
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"ASIO4ALL" = ASIO4ALL
"Assassin's Creed_is1" = Assassin's Creed
"Call of Duty: Black Ops_is1" = Call of Duty: Black Ops
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"NirSoft BlueScreenView" = NirSoft BlueScreenView
"Revo Uninstaller" = Revo Uninstaller 1.95
"SpeedFan" = SpeedFan (remove only)
"Steam App 224260" = No More Room in [bleep]
"VLC media player" = VLC media player 2.1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 11/10/2013 6:37:24 PM | Computer Name = JuansBeast | Source = Application Hang | ID = 1002
Description = The program java.exe version 7.0.450.18 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 1118 Start Time:
01cede54a6b1fa74 Termination Time: 38 Application Path: C:\Program Files (x86)\Java\jre7\bin\java.exe
Report
Id: aa3f605b-4a58-11e3-8c33-60a44c5ad54f
Error - 11/10/2013 6:41:04 PM | Computer Name = JuansBeast | Source = Application Error | ID = 1000
Description = Faulting application name: TurboVHelp.exe, version: 1.0.1.36, time
stamp: 0x00000000 Faulting module name: KERNELBASE.dll, version: 6.1.7601.18229,
time stamp: 0x51fb1116 Exception code: 0x0eedfade Fault offset: 0x0000c41f Faulting
process id: 0xbe0 Faulting application start time: 0x01cede65eed91eaa Faulting application
path: C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe Faulting
module path: C:\Windows\syswow64\KERNELBASE.dll Report Id: 2e42827b-4a59-11e3-af9e-60a44c5ad54f
Error - 11/10/2013 6:41:08 PM | Computer Name = JuansBeast | Source = Application Error | ID = 1000
Description = Faulting application name: EPUHelp.exe, version: 1.0.0.31, time stamp:
0x00000000 Faulting module name: KERNELBASE.dll, version: 6.1.7601.18229, time stamp:
0x51fb1116 Exception code: 0x0eedfade Fault offset: 0x0000c41f Faulting process id:
0xa98 Faulting application start time: 0x01cede65f2216fbc Faulting application path:
C:\Program Files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe Faulting module path: C:\Windows\syswow64\KERNELBASE.dll
Report
Id: 303902a6-4a59-11e3-af9e-60a44c5ad54f
Error - 11/10/2013 6:41:14 PM | Computer Name = JuansBeast | Source = Application Error | ID = 1000
Description = Faulting application name: AI Suite II.exe, version: 2.0.0.0, time
stamp: 0x00000000 Faulting module name: KERNELBASE.dll, version: 6.1.7601.18229,
time stamp: 0x51fb1116 Exception code: 0x0eedfade Fault offset: 0x0000c41f Faulting
process id: 0xd4c Faulting application start time: 0x01cede65f3f943e5 Faulting application
path: C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe Faulting module path:
C:\Windows\syswow64\KERNELBASE.dll Report Id: 33c82a2e-4a59-11e3-af9e-60a44c5ad54f
Error - 11/11/2013 8:38:05 AM | Computer Name = JuansBeast | Source = Application Error | ID = 1000
Description = Faulting application name: TurboVHelp.exe, version: 1.0.1.36, time
stamp: 0x00000000 Faulting module name: KERNELBASE.dll, version: 6.1.7601.18229,
time stamp: 0x51fb1116 Exception code: 0x0eedfade Fault offset: 0x0000c41f Faulting
process id: 0xba4 Faulting application start time: 0x01cededadc42d8b7 Faulting application
path: C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe Faulting
module path: C:\Windows\syswow64\KERNELBASE.dll Report Id: 1bbb5088-4ace-11e3-91d5-60a44c5ad54f
Error - 11/11/2013 8:38:07 AM | Computer Name = JuansBeast | Source = Application Error | ID = 1000
Description = Faulting application name: EPUHelp.exe, version: 1.0.0.31, time stamp:
0x00000000 Faulting module name: KERNELBASE.dll, version: 6.1.7601.18229, time stamp:
0x51fb1116 Exception code: 0x0eedfade Fault offset: 0x0000c41f Faulting process id:
0xc58 Faulting application start time: 0x01cededadf58ee14 Faulting application path:
C:\Program Files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe Faulting module path: C:\Windows\syswow64\KERNELBASE.dll
Report
Id: 1d3f8537-4ace-11e3-91d5-60a44c5ad54f
Error - 11/11/2013 8:38:14 AM | Computer Name = JuansBeast | Source = Application Error | ID = 1000
Description = Faulting application name: AI Suite II.exe, version: 2.0.0.0, time
stamp: 0x00000000 Faulting module name: KERNELBASE.dll, version: 6.1.7601.18229,
time stamp: 0x51fb1116 Exception code: 0x0eedfade Fault offset: 0x0000c41f Faulting
process id: 0xcac Faulting application start time: 0x01cededae26464be Faulting application
path: C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe Faulting module path:
C:\Windows\syswow64\KERNELBASE.dll Report Id: 21a8bc40-4ace-11e3-91d5-60a44c5ad54f
Error - 11/11/2013 11:24:36 AM | Computer Name = JuansBeast | Source = Application Error | ID = 1000
Description = Faulting application name: Setup.exe_ASUS AI Suite II, version: 2.0.1.0,
time stamp: 0x506a8088 Faulting module name: KERNELBASE.dll, version: 6.1.7601.18229,
time stamp: 0x51fb1116 Exception code: 0x0eedfade Fault offset: 0x0000c41f Faulting
process id: 0xf94 Faulting application start time: 0x01cedef2201c6f7f Faulting application
path: C:\ProgramData\ASUS\AI Suite II\Setup.exe Faulting module path: C:\Windows\syswow64\KERNELBASE.dll
Report
Id: 5f65f734-4ae5-11e3-91d5-60a44c5ad54f
Error - 11/11/2013 11:24:43 AM | Computer Name = JuansBeast | Source = Application Error | ID = 1000
Description = Faulting application name: Setup.exe_ASUS AI Suite II, version: 2.0.1.0,
time stamp: 0x506a8088 Faulting module name: KERNELBASE.dll, version: 6.1.7601.18229,
time stamp: 0x51fb1116 Exception code: 0x0eedfade Fault offset: 0x0000c41f Faulting
process id: 0x1348 Faulting application start time: 0x01cedef22493896c Faulting application
path: C:\ProgramData\ASUS\AI Suite II\Setup.exe Faulting module path: C:\Windows\syswow64\KERNELBASE.dll
Report
Id: 63381c27-4ae5-11e3-91d5-60a44c5ad54f
Error - 11/11/2013 11:32:28 AM | Computer Name = JuansBeast | Source = Application Error | ID = 1000
Description = Faulting application name: Setup.exe_ASUS AI Suite II, version: 2.0.1.0,
time stamp: 0x506a8088 Faulting module name: KERNELBASE.dll, version: 6.1.7601.18229,
time stamp: 0x51fb1116 Exception code: 0x0eedfade Fault offset: 0x0000c41f Faulting
process id: 0x93c Faulting application start time: 0x01cedef339a99e01 Faulting application
path: C:\ProgramData\ASUS\AI Suite II\Setup.exe Faulting module path: C:\Windows\syswow64\KERNELBASE.dll
Report
Id: 78bb9a25-4ae6-11e3-91d5-60a44c5ad54f
[ System Events ]
Error - 11/10/2013 3:28:52 PM | Computer Name = JuansBeast | Source = DCOM | ID = 10005
Description =
Error - 11/10/2013 3:28:52 PM | Computer Name = JuansBeast | Source = DCOM | ID = 10005
Description =
Error - 11/10/2013 3:28:52 PM | Computer Name = JuansBeast | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 11/10/2013 3:28:52 PM | Computer Name = JuansBeast | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 11/10/2013 3:28:52 PM | Computer Name = JuansBeast | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 11/10/2013 3:28:52 PM | Computer Name = JuansBeast | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 11/10/2013 3:28:52 PM | Computer Name = JuansBeast | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 11/10/2013 3:28:52 PM | Computer Name = JuansBeast | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 11/10/2013 3:28:52 PM | Computer Name = JuansBeast | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 11/10/2013 3:28:52 PM | Computer Name = JuansBeast | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
< End of report >
any help would be greatly appreciated thanks.