Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Infested; IE11 pops up multiple times, cannot scan using normal tools

IE11 popups dllhost.ex

  • This topic is locked This topic is locked

#1
geofri

geofri

    Member

  • Member
  • PipPip
  • 20 posts

I have been asked to exorcise this computer for a friend. Malwarebytes ran for 6 hours never completing its task. I tried ComboFix and Rkill. Below is the OTL log and the extras log. Any help would be greatly appreciated.

 

OTL logfile created on: 6/9/2014 4:20:57 PM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\The Myers\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17041)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
3.97 Gb Total Physical Memory | 2.95 Gb Available Physical Memory | 74.38% Memory free
7.93 Gb Paging File | 6.95 Gb Available in Paging File | 87.59% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 911.88 Gb Total Space | 845.94 Gb Free Space | 92.77% Space Free | Partition Type: NTFS
Drive H: | 7.53 Gb Total Space | 7.34 Gb Free Space | 97.47% Space Free | Partition Type: FAT32
 
Computer Name: THEMYERS-PC | User Name: The Myers | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/06/09 16:09:08 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\The Myers\Desktop\OTL.com
 
 
========== Modules (No Company Name) ==========
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2014/03/06 04:29:14 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013/05/27 01:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2010/09/22 21:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/01/28 19:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto | Stopped] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV - [2014/05/14 15:07:08 | 000,067,584 | ---- | M] (PasswordBox, Inc.) [Auto | Stopped] -- C:\Program Files (x86)\PasswordBox\pbbtnService.exe -- (PasswordBox)
SRV - [2014/05/14 00:57:21 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/05/13 14:23:04 | 003,644,432 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2014/05/13 14:15:28 | 000,292,424 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe -- (avgwd)
SRV - [2014/05/12 10:40:38 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/05/08 18:28:21 | 001,801,752 | ---- | M] (AVG Secure Search) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.5\ToolbarUpdater.exe -- (vToolbarUpdater18.1.5)
SRV - [2014/02/13 19:58:00 | 000,176,624 | ---- | M] (Coupons.com Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Coupons\CouponPrinterService.exe -- (CouponPrinterService)
SRV - [2014/01/10 16:06:48 | 001,435,680 | R--- | M] (Fitbit, Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe -- (Fitbit Connect)
SRV - [2013/12/21 02:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/10/23 09:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Users\The Myers\Desktop\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/09/11 22:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/04/23 03:48:17 | 003,574,624 | ---- | M] (TeamViewer GmbH) [Auto | Stopped] -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)
SRV - [2010/04/03 19:01:24 | 000,246,520 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2010/01/15 17:08:38 | 000,935,208 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2010/01/08 09:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto | Stopped] -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe -- (GREGService)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/04 22:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014/05/13 14:20:26 | 000,235,800 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Stopped] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2014/05/13 14:20:06 | 000,273,176 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:64bit: - [2014/05/13 14:06:06 | 000,323,352 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgloga.sys -- (Avgloga)
DRV:64bit: - [2014/05/13 14:05:40 | 000,191,768 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA)
DRV:64bit: - [2014/05/13 14:05:08 | 000,152,344 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Stopped] -- C:\Windows\SysNative\drivers\avgdiska.sys -- (Avgdiska)
DRV:64bit: - [2014/05/13 14:05:06 | 000,130,328 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:64bit: - [2014/05/13 14:04:56 | 000,236,312 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Stopped] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
DRV:64bit: - [2014/05/13 14:04:30 | 000,031,512 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:64bit: - [2014/05/08 18:28:21 | 000,050,464 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/02/14 03:42:36 | 000,028,160 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgx64diag.sys -- (UsbDiag)
DRV:64bit: - [2011/02/14 03:42:30 | 000,034,816 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgx64modem.sys -- (USBModem)
DRV:64bit: - [2011/02/14 03:42:28 | 000,017,920 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgx64bus.sys -- (usbbus)
DRV:64bit: - [2011/02/11 19:16:38 | 010,628,640 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/08/10 23:40:06 | 001,014,624 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)
DRV:64bit: - [2009/12/09 05:39:52 | 000,537,624 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 16:35:02 | 000,281,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1y60x64.sys -- (e1yexpress)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/25 16:13:10 | 000,138,752 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IntcHdmi.sys -- (IntcHdmiAddService)
DRV:64bit: - [2009/03/18 16:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearc...r=246922190&ir=
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\URLSearchHook: {bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d} - C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\..\URLSearchHook: {bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d} - C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{2EFE2B5A-6024-44AD-98EA-770F3E7E8BD4}: "URL" = http://search.condui...&ctid=CT3106518
IE - HKCU\..\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}: "URL" = http://mysearch.avg.com/search?cid={64481CF2-594D-4994-B320-1C5F4894F676}&mid=3d2ea970080b47d0afd4294607f26d34-1231171661c17a7a500f40b64c2cd56f282a994d&lang=en&ds=AVG&pr=fr&d=2013-08-27 08:05:55&v=17.1.3.3&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://start.mysearc...r=246922190&ir=
IE - HKCU\..\SearchScopes\{FB689C36-6BE7-4010-BB7F-7868996F0B6B}: "URL" = http://search.condui...q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://mysearch.avg....8:05:55&sap=hp"
FF - prefs.js..extensions.enabledAddons: avg%40toolbar:18.1.5.515
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:29.0.1
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.5\\npsitesafety.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\The Myers\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515 [2014/05/08 18:28:32 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\PasswordBox\Firefox [2013/11/21 20:22:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014/05/12 10:40:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2014/05/17 15:53:29 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014/05/12 10:40:34 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2014/05/17 15:53:29 | 000,000,000 | ---D | M]
 
[2011/08/14 11:53:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\The Myers\AppData\Roaming\Mozilla\Extensions
[2014/06/09 06:38:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions
[2013/12/30 20:41:00 | 000,000,000 | ---D | M] (mysearchdial.com) -- C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\[email protected]
[2013/05/24 11:06:39 | 000,005,341 | ---- | M] () (No name found) -- C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\[email protected]
[2014/03/17 15:42:35 | 000,353,958 | ---- | M] () (No name found) -- C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}.xpi
[2014/01/24 08:52:30 | 000,009,594 | ---- | M] () -- C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\searchplugins\ask-web-search.xml
[2014/05/09 05:39:04 | 000,003,816 | ---- | M] () -- C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\searchplugins\avg-secure-search.xml
[2013/12/30 20:41:07 | 000,002,397 | ---- | M] () -- C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\searchplugins\Mysearchdial.xml
[2014/01/26 09:47:11 | 000,002,862 | ---- | M] () -- C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\searchplugins\web-search.xml
[2014/05/12 10:40:34 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/05/12 10:40:39 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2014/05/08 18:28:32 | 000,000,000 | ---D | M] (AVG SafeGuard toolbar) -- C:\PROGRAMDATA\AVG SAFEGUARD TOOLBAR\FIREFOXEXT\18.1.5.515
[2011/04/14 14:01:38 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll
 
========== Chrome  ==========
 
CHR - default_search_provider: Mysearchdial ()
CHR - default_search_provider: search_url = 
CHR - default_search_provider: suggest_url = 
CHR - Extension: No name found = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: No name found = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: No name found = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.3.2.101_0\
CHR - Extension: No name found = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\18.1.5.515_0\
CHR - Extension: No name found = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: No name found = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
 
O1 HOSTS File: ([2014/06/09 06:38:55 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O2:64bit: - BHO: (Plus-HD-5.0) - {11111111-1111-1111-1111-110411771118} - C:\Program Files (x86)\Plus-HD-5.0\Plus-HD-5.0-bho64.dll File not found
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (PasswordBox Helper) - {5DB69B97-934B-451D-94DB-32EF802A01CD} - C:\Program Files (x86)\PasswordBox\Application\pbbtn.dll (PasswordBox, Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.5.515\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
O2 - BHO: (Tucows Downloads Toolbar) - {bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d} - C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll (Conduit Ltd.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.5.515\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
O3 - HKLM\..\Toolbar: (Tucows Downloads Toolbar) - {bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d} - C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Tucows Downloads Toolbar) - {BDE6F3A2-2CE8-4430-94E0-CD4CE39EEB0D} - C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [ArcadeMovieService] C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe ()
O4 - HKLM..\Run: [MDS_Menu] C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe ()
O4 - HKCU..\Run: [Rebuk] "C:\Users\The Myers\AppData\Roaming\Apyseqa\agagatn.exe" File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O13 - gopher Prefix: missing
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455}  (ExentInf Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BC9B8ECA-8D3A-463C-A441-D44690C56727}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D486644F-BB99-42A1-B100-CA2FD71C5866}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.5\ViProtocol.dll (AVG Secure Search)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/06/09 16:20:18 | 005,205,664 | R--- | C] (Swearware) -- C:\Users\The Myers\Desktop\ComboFix.exe
[2014/06/09 16:20:00 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\The Myers\Desktop\OTL.com
[2014/06/09 16:18:15 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2014/06/09 15:43:41 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2014/06/09 07:21:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2014/06/09 06:21:03 | 000,000,000 | ---D | C] -- C:\ComboFix
[2014/06/07 09:43:27 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2014/06/07 09:43:27 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2014/06/07 09:43:27 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2014/06/07 09:43:20 | 000,000,000 | ---D | C] -- C:\Qoobox
[2014/06/07 09:42:32 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2014/06/07 05:44:57 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Uhsuugu
[2014/06/07 01:45:29 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Uzirakw
[2014/06/06 13:48:50 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Kecaula
[2014/06/06 09:46:50 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Apyseqa
[2014/06/06 01:51:38 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Moumopik
[2014/06/05 21:47:27 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Emhycao
[2014/06/05 17:50:36 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Zunyonh
[2014/06/05 13:08:03 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Sezuliol
[2014/06/04 21:43:04 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Yvydok
[2014/06/03 21:10:13 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Wiicpo
[2014/06/03 07:37:32 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Local\ElevatedDiagnostics
[2014/06/03 01:47:38 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Yludnuc
[2014/06/02 21:45:49 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Yrulzefi
[2014/06/02 20:14:42 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Ynosvidi
[2014/06/02 18:28:45 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Gaxueb
[2014/06/02 17:17:08 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Suuxevo
[2014/06/02 16:16:36 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Tabuold
[2014/06/02 16:12:11 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Yhaskyal
[2014/06/02 07:48:35 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Wyogun
[2014/06/02 07:48:30 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Quyshe
[2014/06/02 07:48:30 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Loyqruz
[2014/06/02 07:48:17 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Xowiuwri
[2014/06/01 09:40:55 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Alirez
[2014/06/01 05:40:32 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Ytboirnu
[2014/06/01 04:10:26 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Paesoss
[2014/05/14 03:05:14 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2014/05/14 03:05:14 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2014/05/14 03:04:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2014/05/14 00:23:08 | 000,477,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll
[2014/05/14 00:23:08 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll
[2014/05/14 00:22:45 | 001,460,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2014/05/14 00:22:44 | 005,550,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2014/05/14 00:22:44 | 003,969,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2014/05/14 00:22:44 | 003,914,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2014/05/14 00:22:44 | 000,722,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\objsel.dll
[2014/05/14 00:22:44 | 000,455,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe
[2014/05/14 00:22:42 | 000,538,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\objsel.dll
[2014/05/14 00:22:42 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2014/05/14 00:22:41 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cngprovider.dll
[2014/05/14 00:22:41 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\adprovider.dll
[2014/05/14 00:22:41 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cngprovider.dll
[2014/05/14 00:22:41 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\adprovider.dll
[2014/05/14 00:22:41 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dimsroam.dll
[2014/05/14 00:22:41 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dimsroam.dll
[2014/05/14 00:22:40 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2014/05/14 00:22:40 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\capiprovider.dll
[2014/05/14 00:22:40 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dpapiprovider.dll
[2014/05/14 00:22:40 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\capiprovider.dll
[2014/05/14 00:22:40 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dpapiprovider.dll
[2014/05/14 00:22:40 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wincredprovider.dll
[2014/05/14 00:22:40 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wincredprovider.dll
[2014/05/14 00:22:40 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2014/05/14 00:22:40 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2014/05/13 14:20:26 | 000,235,800 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgldx64.sys
[2014/05/13 14:20:06 | 000,273,176 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgtdia.sys
[2014/05/13 14:06:06 | 000,323,352 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgloga.sys
[2014/05/13 14:05:40 | 000,191,768 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsha.sys
[2014/05/13 14:05:08 | 000,152,344 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgdiska.sys
[2014/05/13 14:05:06 | 000,130,328 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgmfx64.sys
[2014/05/13 14:04:56 | 000,236,312 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys
[2014/05/13 14:04:30 | 000,031,512 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgrkx64.sys
[2014/05/12 10:40:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
 
========== Files - Modified Within 30 Days ==========
 
[2014/06/09 16:17:52 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/06/09 16:17:50 | 3193,835,520 | -HS- | M] () -- C:\hiberfil.sys
[2014/06/09 16:09:08 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\The Myers\Desktop\OTL.com
[2014/06/09 16:05:36 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/06/09 16:00:33 | 000,000,824 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 271640114.job
[2014/06/09 16:00:32 | 000,000,824 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 3849768352.job
[2014/06/09 16:00:31 | 000,000,828 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 2113702981.job
[2014/06/09 16:00:30 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 1679535995.job
[2014/06/09 16:00:30 | 000,000,826 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 3223429417.job
[2014/06/09 16:00:28 | 000,000,828 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 3483887649.job
[2014/06/09 16:00:27 | 000,000,826 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 75785538.job
[2014/06/09 16:00:26 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 1949422797.job
[2014/06/09 16:00:24 | 000,000,824 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 2900589214.job
[2014/06/09 16:00:22 | 000,000,826 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 2925848665.job
[2014/06/09 16:00:22 | 000,000,824 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 3908467978.job
[2014/06/09 16:00:22 | 000,000,824 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 1518819644.job
[2014/06/09 16:00:21 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 1440003018.job
[2014/06/09 16:00:21 | 000,000,828 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 2843776151.job
[2014/06/09 16:00:21 | 000,000,824 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 793415054.job
[2014/06/09 16:00:21 | 000,000,824 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 419072211.job
[2014/06/09 16:00:19 | 000,000,828 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 1749706860.job
[2014/06/09 15:25:08 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/06/09 14:35:27 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/06/09 07:39:11 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/06/09 07:39:11 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/06/09 07:21:02 | 000,000,969 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2014.lnk
[2014/06/09 06:48:44 | 000,003,408 | ---- | M] () -- C:\bootsqm.dat
[2014/06/09 06:38:55 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2014/06/09 06:18:26 | 005,205,664 | R--- | M] (Swearware) -- C:\Users\The Myers\Desktop\ComboFix.exe
[2014/06/07 09:43:40 | 000,782,510 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/06/07 09:43:40 | 000,662,400 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/06/07 09:43:40 | 000,122,268 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/06/02 13:22:59 | 000,349,912 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/06/02 07:04:47 | 000,457,116 | ---- | M] () -- C:\Users\The Myers\Documents\img006.jpg
[2014/06/02 07:02:20 | 000,455,758 | ---- | M] () -- C:\Users\The Myers\Documents\img005.jpg
[2014/05/30 08:18:55 | 000,068,782 | ---- | M] () -- C:\Users\The Myers\AppData\Local\erwbobfb
[2014/05/30 08:14:52 | 000,000,000 | ---- | M] () -- C:\Users\The Myers\AppData\Roaming\SharedSettings.ccs
[2014/05/22 03:36:28 | 000,002,187 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/05/19 10:37:37 | 000,000,826 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014/05/14 08:40:43 | 000,000,258 | RHS- | M] () -- C:\Users\The Myers\ntuser.pol
[2014/05/14 00:57:21 | 000,692,400 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2014/05/14 00:57:21 | 000,070,832 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2014/05/13 14:20:26 | 000,235,800 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgldx64.sys
[2014/05/13 14:20:06 | 000,273,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgtdia.sys
[2014/05/13 14:06:06 | 000,323,352 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgloga.sys
[2014/05/13 14:05:40 | 000,191,768 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsha.sys
[2014/05/13 14:05:08 | 000,152,344 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgdiska.sys
[2014/05/13 14:05:06 | 000,130,328 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgmfx64.sys
[2014/05/13 14:04:56 | 000,236,312 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys
[2014/05/13 14:04:30 | 000,031,512 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgrkx64.sys
 
========== Files Created - No Company Name ==========
 
[2014/06/09 07:21:02 | 000,000,969 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2014.lnk
[2014/06/09 06:48:44 | 000,003,408 | ---- | C] () -- C:\bootsqm.dat
[2014/06/07 09:43:27 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2014/06/07 09:43:27 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2014/06/07 09:43:27 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2014/06/07 09:43:27 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2014/06/07 09:43:27 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2014/06/07 05:44:57 | 000,000,824 | ---- | C] () -- C:\Windows\tasks\Security Center Update - 3908467978.job
[2014/06/07 01:45:29 | 000,000,824 | ---- | C] () -- C:\Windows\tasks\Security Center Update - 1518819644.job
[2014/06/06 13:48:52 | 000,000,826 | ---- | C] () -- C:\Windows\tasks\Security Center Update - 3223429417.job
[2014/06/06 09:46:52 | 000,000,828 | ---- | C] () -- C:\Windows\tasks\Security Center Update - 2113702981.job
[2014/06/06 01:51:38 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Security Center Update - 1949422797.job
[2014/06/05 21:47:29 | 000,000,824 | ---- | C] () -- C:\Windows\tasks\Security Center Update - 271640114.job
[2014/06/05 17:50:37 | 000,000,828 | ---- | C] () -- C:\Windows\tasks\Security Center Update - 3483887649.job
[2014/06/05 13:08:04 | 000,000,828 | ---- | C] () -- C:\Windows\tasks\Security Center Update - 2843776151.job
[2014/06/04 21:43:07 | 000,000,824 | ---- | C] () -- C:\Windows\tasks\Security Center Update - 793415054.job
[2014/06/03 21:10:13 | 000,000,824 | ---- | C] () -- C:\Windows\tasks\Security Center Update - 3849768352.job
[2014/06/03 01:47:40 | 000,000,826 | ---- | C] () -- C:\Windows\tasks\Security Center Update - 75785538.job
[2014/06/02 21:45:50 | 000,000,828 | ---- | C] () -- C:\Windows\tasks\Security Center Update - 1749706860.job
[2014/06/02 20:14:49 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Security Center Update - 1679535995.job
[2014/06/02 18:28:47 | 000,000,824 | ---- | C] () -- C:\Windows\tasks\Security Center Update - 2900589214.job
[2014/06/02 17:17:09 | 000,000,826 | ---- | C] () -- C:\Windows\tasks\Security Center Update - 2925848665.job
[2014/06/02 16:16:43 | 000,000,824 | ---- | C] () -- C:\Windows\tasks\Security Center Update - 419072211.job
[2014/06/02 16:12:11 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Security Center Update - 1440003018.job
[2014/06/02 13:22:44 | 000,349,912 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/06/02 07:04:47 | 000,457,116 | ---- | C] () -- C:\Users\The Myers\Documents\img006.jpg
[2014/06/02 07:02:19 | 000,455,758 | ---- | C] () -- C:\Users\The Myers\Documents\img005.jpg
[2014/05/30 08:18:55 | 000,068,782 | ---- | C] () -- C:\Users\The Myers\AppData\Local\erwbobfb
[2014/05/30 08:14:52 | 000,000,000 | ---- | C] () -- C:\Users\The Myers\AppData\Roaming\SharedSettings.ccs
[2014/02/25 04:02:42 | 000,774,632 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013/12/30 21:40:01 | 000,000,030 | ---- | C] () -- C:\Users\The Myers\AppData\Roaming\WB.CFG
[2013/08/09 08:10:36 | 000,000,000 | ---- | C] () -- C:\Users\The Myers\acrobat.exe
[2013/06/25 18:37:34 | 000,000,258 | RHS- | C] () -- C:\Users\The Myers\ntuser.pol
[2013/05/27 09:26:48 | 000,003,737 | ---- | C] () -- C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
[2013/04/07 17:43:28 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat
[2012/11/19 03:33:32 | 000,065,656 | ---- | C] () -- C:\Windows\SysWow64\bdmpegv.dll
[2012/11/19 03:33:30 | 000,022,640 | ---- | C] () -- C:\Windows\SysWow64\bdmjpeg.dll
[2012/02/05 16:50:26 | 000,000,779 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
 
========== ZeroAccess Check ==========
 
[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/03/24 22:43:12 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/03/24 22:09:54 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 21:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 08:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 21:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
< End of report >
 

OTL Extras logfile created on: 6/9/2014 4:20:57 PM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\The Myers\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17041)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
3.97 Gb Total Physical Memory | 2.95 Gb Available Physical Memory | 74.38% Memory free
7.93 Gb Paging File | 6.95 Gb Available in Paging File | 87.59% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 911.88 Gb Total Space | 845.94 Gb Free Space | 92.77% Space Free | Partition Type: NTFS
Drive H: | 7.53 Gb Total Space | 7.34 Gb Free Space | 97.47% Space Free | Partition Type: FAT32
 
Computer Name: THEMYERS-PC | User Name: The Myers | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{09151C03-35A6-4E2F-A591-B159649513A4}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{16EC3392-5F27-472B-9B0E-1CB31877D2BB}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{1B1F64CA-F895-4699-9001-94B80DA8DAF7}" = rport=137 | protocol=17 | dir=out | app=system | 
"{1EF0E3BE-9F24-40A9-A9E9-FDA2433B2CF7}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{37242044-C29B-40AD-AEF1-6CB7B0EECF31}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{38B840E3-7C63-4732-98FE-0A59A7083EA1}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{4A212A11-1665-40BA-A106-170D36D79CC7}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{5BED8EA6-3F56-4403-A7B7-9565152DBDE0}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{5C4523B2-77B1-4ACF-A608-6D3463D8D45D}" = lport=445 | protocol=6 | dir=in | app=system | 
"{5E09327C-915D-4567-9E41-539439A0D436}" = lport=138 | protocol=17 | dir=in | app=system | 
"{854F0355-9121-426A-9606-C452E0E6D311}" = rport=138 | protocol=17 | dir=out | app=system | 
"{91A3040B-94C6-4F99-9613-8198F79A3306}" = lport=137 | protocol=17 | dir=in | app=system | 
"{954FF445-FE24-4EAE-9AB9-A367A0EFB722}" = lport=139 | protocol=6 | dir=in | app=system | 
"{A9A5BC5A-93D6-4F53-9FE9-6595ADFA4379}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{AA09BF83-29DC-48B4-835F-7846B5822AB3}" = rport=139 | protocol=6 | dir=out | app=system | 
"{B8E2A74C-76BF-4BA4-8B94-F089DA5CD5EE}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{BD9F322E-4D46-4173-9178-1155D7224A23}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | 
"{C062955D-77E3-40B4-907F-29C61A361895}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 | 
"{C534B2BC-4DD7-4AFE-AE4D-68E09366F40A}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{C80ACD64-D5A5-4610-8888-55445FA75957}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{D8D70D05-D8E5-40AE-AFF0-B5490EEE2F61}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{E632A1FA-49B3-4CE5-B3D4-11460A822A36}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | 
"{ED1B48CA-F13E-4F16-80F5-8E232BF4BFD3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{FDEC8B82-C507-46E4-BFCD-E13A585DA8C5}" = rport=445 | protocol=6 | dir=out | app=system | 
"{FEABEF51-75A2-4025-99EF-431E2F04286D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{07EAC846-DE46-4A5E-95F8-57A742618F3C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{1071E15F-ADE3-4669-9901-0368A2408014}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe | 
"{15844F51-45F6-48E8-A812-962408136A47}" = protocol=58 | dir=out | [email protected],-28546 | 
"{1C4BB884-0EBE-4104-B382-937F4EF4CAE1}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe | 
"{1D1B4186-9B61-43F7-AA23-B2EC72A5E2A8}" = dir=in | app=c:\users\the myers\desktop\phone\skype.exe | 
"{2E80A141-2425-4A2E-B45F-7B041F52E393}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgmfapx.exe | 
"{3119D8D4-4AF8-466B-A35C-40419CA5C109}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | 
"{31CCDF9F-D9A6-4E2A-960E-6050ADEEC31C}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgnsa.exe | 
"{381B5F10-DB11-4E75-A512-0F9BF7421C96}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{3C917F9E-2B42-489B-BD5F-9256BFC90450}" = protocol=1 | dir=in | [email protected],-28543 | 
"{42F55D21-8D85-4FCA-A952-044176764123}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{43456046-C43E-4777-B5E0-92D13EF5BFA4}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{46EA5B1E-2D25-4444-82CA-F31BD69EFC33}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe | 
"{4B3E308A-4ED6-403E-8A41-72048AFB2003}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{4DD06242-EF92-4B11-B71B-979C9136C8E5}" = dir=in | app=c:\program files (x86)\acer arcade deluxe\acer arcade deluxe\acer arcade deluxe.exe | 
"{59A01EBA-EFAE-49EF-A6B9-F0FC4FF257B3}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgmfapx.exe | 
"{5B30FCBC-7792-41ED-B0AF-DEC806D1A192}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe | 
"{63F30319-40D9-430A-A21B-4AE7C29A334B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{65FE8EB5-10A7-4120-8805-D3CC0EECDC8C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{69BEBABE-2058-4636-AD8A-9D085A9886CF}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgdiagex.exe | 
"{6D9DB6E6-4A5D-40C6-988B-10BFB7DA7E03}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{8C55D4A8-DC9C-49CC-975C-8D200C3865CD}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | 
"{9E964263-678C-48C0-8FD0-7F2EC8BCBA81}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe | 
"{A30A438A-6AB8-43BF-9691-97A80F46F5AE}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgemca.exe | 
"{BD15E345-1490-4883-9906-4B0DBAEE5127}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{BD29FCCF-E6E9-4170-9DAC-BDD21AC9F428}" = dir=in | app=c:\program files (x86)\acer arcade deluxe\homemedia\homemedia.exe | 
"{C29BE491-2802-47BE-928F-0ABFE878B6E9}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{C3160318-9CAB-478E-BB25-842E59898B8D}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | 
"{C8BC1FE1-6E40-431D-9F7D-6426346466F7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{C9E92C14-8FF1-438F-96DB-ED35B0F2D535}" = protocol=6 | dir=out | app=system | 
"{D55B2822-B5FC-43AE-A6B1-37F1DF1EDA22}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{DA0938E2-3227-4D75-8ED4-5A96682458CD}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgmfapx.exe | 
"{DCDE9950-122C-4F77-BC06-3C39A465E74B}" = protocol=1 | dir=out | [email protected],-28544 | 
"{E0A22CF7-AA39-4D69-8FA9-EFE271722D34}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe | 
"{E4621069-157F-42A8-9B52-82EA7B29DFE2}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgmfapx.exe | 
"{E4E49425-F243-46E9-A295-2DB6417AA949}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgemca.exe | 
"{E589AB45-32DA-431C-B60C-CDD55C693E71}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{E86364EA-C93E-4EAC-A530-9585EAA9375E}" = protocol=58 | dir=in | [email protected],-28545 | 
"{EA294CBA-7F38-42BF-9B45-DCDE1B2F90E5}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgdiagex.exe | 
"{EF0E9AA1-E5CA-4210-A06E-12DC7A2D7396}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | 
"{F757F2EC-A2FE-4F13-B6D0-533F2F06AFED}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | 
"{F8035BF3-89B3-4055-BA1D-A6F458B2FCC7}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{F89251D2-9F43-464F-96DB-19A98C78DC22}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgnsa.exe | 
"TCP Query User{03699D1F-1F30-44CE-BCFE-EF89231303C7}C:\programdata\kingsisle entertainment\pirate101\bin\pirate.exe" = protocol=6 | dir=in | app=c:\programdata\kingsisle entertainment\pirate101\bin\pirate.exe | 
"TCP Query User{2EE21EFA-B4B4-4622-A2CB-6A2ED38C74C5}C:\users\the myers\desktop\stuff\phone\skype.exe" = protocol=6 | dir=in | app=c:\users\the myers\desktop\stuff\phone\skype.exe | 
"TCP Query User{5F64AA87-ED34-434A-83B7-BFC968B06A1C}C:\program files (x86)\opera\opera.exe" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe | 
"TCP Query User{6C65666A-F4C9-4B79-BE78-66A652C1589E}C:\program files (x86)\java\jre7\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe | 
"TCP Query User{D525A65E-2261-479A-8D5F-798B2BF5EDDB}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe | 
"UDP Query User{0AE26817-F2E6-418F-890A-C085FAAEF1F7}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe | 
"UDP Query User{35AD0855-FF81-4F16-A17A-7F9D4705A0E0}C:\program files (x86)\java\jre7\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe | 
"UDP Query User{826F092C-D594-4F7D-AC93-D4CE915A4D09}C:\programdata\kingsisle entertainment\pirate101\bin\pirate.exe" = protocol=17 | dir=in | app=c:\programdata\kingsisle entertainment\pirate101\bin\pirate.exe | 
"UDP Query User{D7E2F072-B2BB-4988-9AF2-98C895AA5F68}C:\users\the myers\desktop\stuff\phone\skype.exe" = protocol=17 | dir=in | app=c:\users\the myers\desktop\stuff\phone\skype.exe | 
"UDP Query User{EA846064-04DC-4EC3-8EAF-92CE00FF6431}C:\program files (x86)\opera\opera.exe" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{21B133D6-5979-47F0-BE1C-F6A6B304693F}" = Visual Studio 2010 x64 Redistributables
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4FD80311-508F-42C3-A004-4CC8D08231F5}" = AVG 2013
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.03
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C775E70-A791-4DA8-BCC3-6AB7136F4484}" = Visual Studio 2012 x64 Redistributables
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{CB21CD89-A4D3-4240-9AAA-55DCE7F3D076}" = AVG 2014
"{CFF43477-05A9-466C-8399-A2C151D82CA0}" = AVG 2014
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"AVG" = AVG 2014
"CCleaner" = CCleaner
"EPSON WorkForce 500 Series" = EPSON WorkForce 500 Series Printer Uninstall
"HDMI" = Intel® Graphics Media Accelerator Driver
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0ca6db69-1557-428e-b75f-3f479f9a48bf}" = Nero 9 Essentials
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20400DBD-E6DB-45B8-9B6B-1DD7033818EC}" = Nero InfoTool Help
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2348B586-C9AE-46CE-936C-A68E9426E214}" = Nero StartSmart Help
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"{26A24AE4-039D-4CA4-87B4-2F83217009FF}" = Java 7 Update 9
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33CF58F5-48D8-4575-83D6-96F574E4D83A}" = Nero DriveSpeed
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{4968622A-4D3F-489E-9ACE-5FEC4CC0BDE3}" = MediaShow Espresso
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4D43D635-6FDA-4FA5-AA9B-23CF73D058EA}" = Nero StartSmart OEM
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.11
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{662140BE-138C-4DC1-B4CD-B62C6C855A25}" = Pirate101
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6A7C2B2E-36A3-4EF5-96C6-708CD090A3AD}" = Fitbit Connect
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{83202942-84B3-4C50-8622-B8C0AA2D2885}" = Nero Express Help
"{869200DB-287A-4DC0-B02B-2B6787FBCD4C}" = Nero DiscSpeed
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}" = Visual Studio 2012 x86 Redistributables
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.07)
"{B03954CC-E130-4E57-BC83-869978685902}" = LG United Mobile Drivers
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{B618B8E1-FB71-4237-8361-C3EA3EF15EF7}" = ASPCA Reminder by We-Care.com v4.1.18.1
"{B906C11A-D193-4143-9FA7-E2EE8A5A8F21}" = Acer Arcade Movie
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C81A2FE0-3574-00A9-CED4-BDAA334CBE8E}" = Nero Online Upgrade
"{CC019E3F-59D2-4486-8D4B-878105B62A71}" = Nero DiscSpeed Help
"{CCF298AF-9CE1-4B26-B251-486E98A34789}" = Windows 7 USB/DVD Download Tool
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D4C4A751-F7F3-4DCA-B825-9AC391BFFC3F}" = Google+ Auto Backup
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E0B19DF7-B1C7-4937-82C4-0E4B1E346965}" = eBay Worldwide
"{E5C7D048-F9B4-4219-B323-8BDB01A2563D}" = Nero DriveSpeed Help
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4041DCE-3FE1-4E18-8A9E-9DE65231EE36}" = Nero ControlCenter
"{FBCDFD61-7DCF-4E71-9226-873BA0053139}" = Nero InfoTool
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"7-Zip" = 7-Zip 4.65
"Acer Game Console" = Acer Game Console
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 13 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 13 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"AVG SafeGuard toolbar" = AVG SafeGuard toolbar
"Bandicam" = Bandicam
"BandiMPEG1" = Bandisoft MPEG-1 Decoder
"Coupon Printer for Windows5.0.0.7" = Coupon Printer for Windows
"DMUninstaller" = DMUninstaller
"EPSON Scanner" = EPSON Scan
"Google Chrome" = Google Chrome
"Hotkey Utility" = Hotkey Utility
"Identity Card" = Identity Card
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade Deluxe
"IrfanView" = IrfanView (remove only)
"LS-C4DC987A-47E2-487C-9F63-7E1DB5F88FC3_is1" = Lazesoft Recover My Password version 2.0 Home Edition
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Mozilla Firefox 29.0.1 (x86 en-US)" = Mozilla Firefox 29.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"Opera 12.16.1860" = Opera 12.16
"TeamViewer 8" = TeamViewer 8
"Tucows_Downloads Toolbar" = Tucows Downloads Toolbar
"UBCD4Win_is1" = UBCD4Win 3.60
"VzInHomeAgent" = Vz In-Home Agent
"WildTangent acer Master Uninstall" = Acer Games
"WinLiveSuite" = Windows Live Essentials
"WT088295" = Agatha Christie - Death on the Nile
"WT088300" = Bejeweled 2 Deluxe
"WT088310" = Build-a-lot 2
"WT088312" = Chuzzle Deluxe
"WT088318" = Diner Dash 2 Restaurant Rescue
"WT088350" = Jewel Quest Solitaire 2
"WT088364" = Plants vs. Zombies
"WT088373" = Blackhawk Striker 2
"WT088393" = Dora's Carnival Adventure
"WT088413" = FATE
"WT088445" = John Deere Drive Green
"WT088449" = Penguins!
"WT088453" = Polar Bowler
"WT088457" = Polar Golfer
"WT088517" = Zuma's Revenge
"WT088553" = Virtual Villagers 4 - The Tree of Life
"WT088649" = 18 Wheels of Steel - American Long Haul
"WT088653" = Jewel Quest - Heritage
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"UnityWebPlayer" = Unity Web Player
"Virtual Families Packages" = Virtual Families Packages
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 3/11/2014 7:16:41 AM | Computer Name = TheMyers-PC | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 27.0.1.5156, time
 stamp: 0x52fc0faa  Faulting module name: xul.dll, version: 27.0.1.5156, time stamp:
 0x52fc0f79  Exception code: 0xc0000005  Fault offset: 0x001560c7  Faulting process id:
 0xcc0  Faulting application start time: 0x01cf3d1adb1d7b6f  Faulting application path:
 C:\Program Files (x86)\Mozilla Firefox\firefox.exe  Faulting module path: C:\Program
 Files (x86)\Mozilla Firefox\xul.dll  Report Id: 9e8775a2-a90e-11e3-a04b-f80f411684c7
 
Error - 3/12/2014 8:02:48 AM | Computer Name = TheMyers-PC | Source = MsiInstaller | ID = 11706
Description = 
 
Error - 3/20/2014 7:13:16 AM | Computer Name = TheMyers-PC | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 27.0.1.5156, time
 stamp: 0x52fc0faa  Faulting module name: xul.dll, version: 27.0.1.5156, time stamp:
 0x52fc0f79  Exception code: 0xc0000005  Fault offset: 0x001560c7  Faulting process id:
 0x128c  Faulting application start time: 0x01cf442d0fcb292e  Faulting application path:
 C:\Program Files (x86)\Mozilla Firefox\firefox.exe  Faulting module path: C:\Program
 Files (x86)\Mozilla Firefox\xul.dll  Report Id: a210a434-b020-11e3-a3bb-f80f411684c7
 
Error - 3/28/2014 11:45:37 AM | Computer Name = TheMyers-PC | Source = Application Hang | ID = 1002
Description = The program mbam.exe version 1.75.0.1 stopped interacting with Windows
 and was closed. To see if more information about the problem is available, check
 the problem history in the Action Center control panel.    Process ID: 137c    Start Time:
 01cf4a9c1bf9a420    Termination Time: 0    Application Path: C:\Program Files (x86)\Malwarebytes'
 Anti-Malware\mbam.exe    Report Id: e8cc0f9c-b68f-11e3-80c6-f80f411684c7  
 
Error - 4/9/2014 1:57:54 PM | Computer Name = TheMyers-PC | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 28.0.0.5186, time
 stamp: 0x53240e37  Faulting module name: xul.dll, version: 28.0.0.5186, time stamp:
 0x53240e04  Exception code: 0xc0000005  Fault offset: 0x00184729  Faulting process id:
 0x1434  Faulting application start time: 0x01cf541c98971bb9  Faulting application path:
 C:\Program Files (x86)\Mozilla Firefox\firefox.exe  Faulting module path: C:\Program
 Files (x86)\Mozilla Firefox\xul.dll  Report Id: 791a0fd6-c010-11e3-a076-f80f411684c7
 
Error - 4/21/2014 9:24:57 AM | Computer Name = TheMyers-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Explorer.EXE, version: 6.1.7601.17567, 
time stamp: 0x4d672ee4  Faulting module name: msi.dll, version: 5.0.7601.17807, time
 stamp: 0x4f80321a  Exception code: 0xc0000005  Fault offset: 0x00000000001ec1e6  Faulting
 process id: 0x4a4  Faulting application start time: 0x01cf570df46ae8f5  Faulting application
 path: C:\Windows\Explorer.EXE  Faulting module path: C:\Windows\system32\msi.dll  Report
 Id: 5463b68f-c958-11e3-9a13-f80f411684c7
 
Error - 4/28/2014 6:29:19 AM | Computer Name = TheMyers-PC | Source = MsiInstaller | ID = 11706
Description = 
 
Error - 5/3/2014 7:00:54 AM | Computer Name = TheMyers-PC | Source = MsiInstaller | ID = 11706
Description = 
 
Error - 5/17/2014 3:53:00 PM | Computer Name = TheMyers-PC | Source = MsiInstaller | ID = 1024
Description = 
 
Error - 5/19/2014 9:55:19 AM | Computer Name = TheMyers-PC | Source = MsiInstaller | ID = 11706
Description = 
 
[ System Events ]
Error - 6/9/2014 5:08:11 PM | Computer Name = TheMyers-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
 to start because of the following error:   %%1068
 
Error - 6/9/2014 5:08:23 PM | Computer Name = TheMyers-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
 to start because of the following error:   %%1068
 
Error - 6/9/2014 5:08:23 PM | Computer Name = TheMyers-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
 to start because of the following error:   %%1068
 
Error - 6/9/2014 5:08:23 PM | Computer Name = TheMyers-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
 to start because of the following error:   %%1068
 
Error - 6/9/2014 5:09:23 PM | Computer Name = TheMyers-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
 to start because of the following error:   %%1068
 
Error - 6/9/2014 5:09:23 PM | Computer Name = TheMyers-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
 to start because of the following error:   %%1068
 
Error - 6/9/2014 5:09:23 PM | Computer Name = TheMyers-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
 to start because of the following error:   %%1068
 
Error - 6/9/2014 5:09:35 PM | Computer Name = TheMyers-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
 to start because of the following error:   %%1068
 
Error - 6/9/2014 5:09:35 PM | Computer Name = TheMyers-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
 to start because of the following error:   %%1068
 
Error - 6/9/2014 5:09:35 PM | Computer Name = TheMyers-PC | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
 to start because of the following error:   %%1068
 
 
< End of report >
 
 

  • 0

Advertisements


#2
tom982

tom982

    Member 1K

  • Member
  • PipPipPipPip
  • 1,183 posts
Hello geofri and :welcome:

My name is Tom and I am going to be helping you with your malware removal. Please note that, as I am currently still in training, all of my posts have to be reviewed by my instructor prior to me posting them.

Before we continue, I would like you to read the following text:
  • Some of my instructions may be carried out in safe mode, where you will not have access to GeeksToGo, I suggest you save or print my instructions for later reference
  • Please do not attach your logs to your post, instead I would like you to copy and paste the contents into your post
  • Please do NOT use any other tools, fixes or scripts unless instructed to do so by myself. Not only could this damage your system, but it will make it harder for me to fix your problem
  • If you do not understand any of my instructions, then feel free to ask me and I will explain in further detail
  • Please be patient. Malware removal is a long process and requires many steps, if you stick with me, I'll help you get through this
  • Stay with me until I deem your computer clean. A lack of symptoms does not always mean that the system is clean
  • Please make sure you have read and understood my instructions before continuing with them, spelling errors in the scripts etc. could cause adverse effects to your system
  • If you do not hear a reply from me in 36 hours, then simply post "bump" on the thread
  • Please note that the forum is very busy and if I don't hear from you within three days this thread will be closed
I will submit my fix now and get back to you as soon as possible :)

Tom
  • 0

#3
geofri

geofri

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts

Gotcha Tom thanks.


  • 0

#4
tom982

tom982

    Member 1K

  • Member
  • PipPipPipPip
  • 1,183 posts
Hi geofri,

Using Step 2 of this tutorial, can you reset your Chrome settings please?

https://support.goog...765944?hl=en-GB

Uninstall Software
  • Click on the Start Start%20Orb.jpg button and select Control Panel
  • Click on Programs then click on Uninstall a program
  • You will now see a list of your installed software, double click on the following one by one to uninstall them:
    • Yontoo 1.10.03

  • Once you have done this, reboot your computer
OTL Fix
  • Run OTL.
  • Copy (Ctrl+C) and Paste (Ctrl+V) all of the following text into the Custom Scans/Fixes box:


    :Commands
    [CREATERESTOREPOINT]
    
    :OTL
    O2:64bit: - BHO: (Plus-HD-5.0) - {11111111-1111-1111-1111-110411771118} - C:\Program Files (x86)\Plus-HD-5.0\Plus-HD-5.0-bho64.dll File not found
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4 - HKCU..\Run: [Rebuk] "C:\Users\The Myers\AppData\Roaming\Apyseqa\agagatn.exe" File not found
    O13 - gopher Prefix: missing
    [2014/06/07 05:44:57 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Uhsuugu
    [2014/06/07 01:45:29 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Uzirakw
    [2014/06/06 13:48:50 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Kecaula
    [2014/06/06 09:46:50 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Apyseqa
    [2014/06/06 01:51:38 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Moumopik
    [2014/06/05 21:47:27 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Emhycao
    [2014/06/05 17:50:36 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Zunyonh
    [2014/06/05 13:08:03 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Sezuliol
    [2014/06/04 21:43:04 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Yvydok
    [2014/06/03 21:10:13 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Wiicpo
    [2014/06/03 01:47:38 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Yludnuc
    [2014/06/02 21:45:49 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Yrulzefi
    [2014/06/02 20:14:42 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Ynosvidi
    [2014/06/02 18:28:45 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Gaxueb
    [2014/06/02 17:17:08 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Suuxevo
    [2014/06/02 16:16:36 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Tabuold
    [2014/06/02 16:12:11 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Yhaskyal
    [2014/06/02 07:48:35 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Wyogun
    [2014/06/02 07:48:30 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Quyshe
    [2014/06/02 07:48:30 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Loyqruz
    [2014/06/02 07:48:17 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Xowiuwri
    [2014/06/01 09:40:55 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Alirez
    [2014/06/01 05:40:32 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Ytboirnu
    [2014/06/01 04:10:26 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Roaming\Paesoss
    [2014/06/09 16:00:33 | 000,000,824 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 271640114.job
    [2014/06/09 16:00:32 | 000,000,824 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 3849768352.job
    [2014/06/09 16:00:31 | 000,000,828 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 2113702981.job
    [2014/06/09 16:00:30 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 1679535995.job
    [2014/06/09 16:00:30 | 000,000,826 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 3223429417.job
    [2014/06/09 16:00:28 | 000,000,828 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 3483887649.job
    [2014/06/09 16:00:27 | 000,000,826 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 75785538.job
    [2014/06/09 16:00:26 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 1949422797.job
    [2014/06/09 16:00:24 | 000,000,824 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 2900589214.job
    [2014/06/09 16:00:22 | 000,000,826 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 2925848665.job
    [2014/06/09 16:00:22 | 000,000,824 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 3908467978.job
    [2014/06/09 16:00:22 | 000,000,824 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 1518819644.job
    [2014/06/09 16:00:21 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 1440003018.job
    [2014/06/09 16:00:21 | 000,000,828 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 2843776151.job
    [2014/06/09 16:00:21 | 000,000,824 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 793415054.job
    [2014/06/09 16:00:21 | 000,000,824 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 419072211.job
    [2014/06/09 16:00:19 | 000,000,828 | ---- | M] () -- C:\Windows\tasks\Security Center Update - 1749706860.job
    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearc...r=246922190&ir=
    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKCU\..\URLSearchHook: {bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d} - C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll (Conduit Ltd.)
    IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
    IE - HKCU\..\SearchScopes\{2EFE2B5A-6024-44AD-98EA-770F3E7E8BD4}: "URL" = http://search.condui...&ctid=CT3106518
    IE - HKCU\..\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}: "URL" = http://mysearch.avg.com/search?cid={64481CF2-594D-4994-B320-1C5F4894F676}&mid=3d2ea970080b47d0afd4294607f26d34-1231171661c17a7a500f40b64c2cd56f282a994d&lang=en&ds=AVG&pr=fr&d=2013-08-27 08:05:55&v=17.1.3.3&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
    IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://start.mysearc...r=246922190&ir=
    IE - HKCU\..\SearchScopes\{FB689C36-6BE7-4010-BB7F-7868996F0B6B}: "URL" = http://search.condui...q={searchTerms}
    FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
    FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
    FF - prefs.js..browser.startup.homepage: "http://mysearch.avg....8:05:55&sap=hp"
    FF - prefs.js..extensions.enabledAddons: avg%40toolbar:18.1.5.515
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515 [2014/05/08 18:28:32 | 000,000,000 | ---D | M]
    [2014/01/24 08:52:30 | 000,009,594 | ---- | M] () -- C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\searchplugins\ask-web-search.xml
    [2014/05/09 05:39:04 | 000,003,816 | ---- | M] () -- C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\searchplugins\avg-secure-search.xml
    [2013/12/30 20:41:07 | 000,002,397 | ---- | M] () -- C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\searchplugins\Mysearchdial.xml
    [2014/01/26 09:47:11 | 000,002,862 | ---- | M] () -- C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\searchplugins\web-search.xml
    [2014/05/08 18:28:32 | 000,000,000 | ---D | M] (AVG SafeGuard toolbar) -- C:\PROGRAMDATA\AVG SAFEGUARD TOOLBAR\FIREFOXEXT\18.1.5.515
    O2 - BHO: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.5.515\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
    O2 - BHO: (Tucows Downloads Toolbar) - {bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d} - C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.5.515\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
    O3 - HKLM\..\Toolbar: (Tucows Downloads Toolbar) - {bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d} - C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (Tucows Downloads Toolbar) - {BDE6F3A2-2CE8-4430-94E0-CD4CE39EEB0D} - C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll (Conduit Ltd.)
    O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe ()
    O4 - HKCU..\Run: [Rebuk] "C:\Users\The Myers\AppData\Roaming\Apyseqa\agagatn.exe" File not found
    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearc...r=246922190&ir=
    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKCU\..\URLSearchHook: {bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d} - C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll (Conduit Ltd.)
    IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
    IE - HKCU\..\SearchScopes\{2EFE2B5A-6024-44AD-98EA-770F3E7E8BD4}: "URL" = http://search.condui...&ctid=CT3106518
    IE - HKCU\..\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}: "URL" = http://mysearch.avg.com/search?cid={64481CF2-594D-4994-B320-1C5F4894F676}&mid=3d2ea970080b47d0afd4294607f26d34-1231171661c17a7a500f40b64c2cd56f282a994d&lang=en&ds=AVG&pr=fr&d=2013-08-27 08:05:55&v=17.1.3.3&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
    IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://start.mysearc...r=246922190&ir=
    IE - HKCU\..\SearchScopes\{FB689C36-6BE7-4010-BB7F-7868996F0B6B}: "URL" = http://search.condui...q={searchTerms}
    FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
    FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
    FF - prefs.js..browser.startup.homepage: "http://mysearch.avg....8:05:55&sap=hp"
    FF - prefs.js..extensions.enabledAddons: avg%40toolbar:18.1.5.515
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515 [2014/05/08 18:28:32 | 000,000,000 | ---D | M]
    [2014/01/24 08:52:30 | 000,009,594 | ---- | M] () -- C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\searchplugins\ask-web-search.xml
    [2014/05/09 05:39:04 | 000,003,816 | ---- | M] () -- C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\searchplugins\avg-secure-search.xml
    [2013/12/30 20:41:07 | 000,002,397 | ---- | M] () -- C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\searchplugins\Mysearchdial.xml
    [2014/01/26 09:47:11 | 000,002,862 | ---- | M] () -- C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\searchplugins\web-search.xml
    [2014/05/08 18:28:32 | 000,000,000 | ---D | M] (AVG SafeGuard toolbar) -- C:\PROGRAMDATA\AVG SAFEGUARD TOOLBAR\FIREFOXEXT\18.1.5.515
    O2 - BHO: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.5.515\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
    O2 - BHO: (Tucows Downloads Toolbar) - {bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d} - C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.5.515\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
    O3 - HKLM\..\Toolbar: (Tucows Downloads Toolbar) - {bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d} - C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (Tucows Downloads Toolbar) - {BDE6F3A2-2CE8-4430-94E0-CD4CE39EEB0D} - C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll (Conduit Ltd.)
    O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe ()
    O4 - HKCU..\Run: [Rebuk] "C:\Users\The Myers\AppData\Roaming\Apyseqa\agagatn.exe" File not found
    
    :Files
    C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
    C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
    C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
    C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
    C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
    C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
    C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
    C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
    
    :Commands
    [EMPTYTEMP]
    
  • Click the Run Fix button.
  • After your computer has rebooted, run OTL and click Quick Scan.
  • Copy and paste the contents of the log that it produces into your next post.
AdwCleaner

Please download AdwCleaner (by Xplode) from the link below and save it to your Desktop:

Download Mirror #1
  • Right-click on AdwCleaner.exe and select Run as administrator.
  • Click Scan and let the scan run.
  • When it finishes, click Clean, following the on screen prompts
  • After your computer reboots, a log will open. Please Copy (Ctrl+C) and Paste (Ctrl+V) this into your next post.
Note: The log can also be found in here: C:\AdwCleaner\

OTL
  • Run OTL by double-clicking on it.
  • Click Quick Scan to start OTL.
  • When OTL finishes scanning, a logs, OTL.txt will open.
  • Copy (Ctrl+C) and Paste (Ctrl+V) the contents of this log into your next post please.
When you have done all this, let me know if you are still seeing the ads as well as posting back all of the logs :)

Tom
  • 0

#5
tom982

tom982

    Member 1K

  • Member
  • PipPipPipPip
  • 1,183 posts
Oops, it appears I pasted my fix over the text I wrote out! In addition to the instructions above, I would like to know if you use TeamViewer and LogMeIn? As these are remote control programs it's bad if you didn't know they were installed - I suspect you're aware of these, but I wanted to check just to be safe.

I also see you've run ComboFix, can you post the log please? It's located in C:\ComboFix.txt
  • 0

#6
geofri

geofri

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts

Hello Tom and thanks for your quick replies. I am posting from the infected computer so I hope all goes well. 

I successfully reset chrome settings.

Error uninstalling Yontoo- "uninstaller not found possibly because program was already uninstalled. Do you want to remove it from the list?" I agreed.

I ran OTL with the custom fix you supplied successfully. Will post log below.

I ran AdwCleaner and ran into several issues including the IE popups and not responding messages more than once. Also received a message from AVG that it has "detected high memory usage from Internet Explorer (2 gig) and suggested I shut it down although it was not visibly running.

I am aware of the remote programs installed which are used by the owner for Minecraft gameplay.

I ran OTL quick scan successfully and that log too will be posted below.

The ComboFix log for the scan I ran before we spoke is also posted below. A very strange occurrence in Windows Explorer when trying to access this log. The C: drive replicated itself in explorer every time I clicked on the Combofix folder. I know I was only looking for the .txt file but I did not expect to see a folder for Combofix there at all. I had run the program more than once after running Malwarebytes so I am not sure how valid the log is.

 

 

ComboFix 14-06-09.01 - The Myers 06/09/2014   6:24.2.2 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.4061.821 [GMT -4:00]
Running from: H:\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome.manifest
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\api.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\api\asyncDB.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\api\background.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\api\browserAction.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\api\contextMenu.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\api\dbManager.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\api\dom_bg.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\api\fileManager.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\api\firefox.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\api\firefoxNotifications.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\api\firefoxOmnibox.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\api\message.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\api\pageAction.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\api\request.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\api\tabs.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\api\webRequest.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\api\windowsMessagingHandler.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\background.html
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\baseObject.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\browser.xul
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\addressBarChangeObserver.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\console.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\consts.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\delegate.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\extensionDataStore.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\folderIOWrapper.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\httpObserver.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\IDBWrapper.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\installer.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\logFile.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\prefs.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\progressListenerObserver.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\registry.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\reloadObserver.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\reports.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\requestObject.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\searchSettings.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\uninstallObserver.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\updateManager.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\utils.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\core\xhr.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\dialog.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\ffCoreFilesIndex.txt
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\main.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\options.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\options.xul
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\platformVersion.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\chrome\content\search_dialog.xul
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\defaults\preferences\prefs.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\manifest.xml
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins.json
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\1_base.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\102_dealply_m.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\104_jollywallet_m.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\119_similar_web_m.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\123_intext_adv_m.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\13_CrossriderAppUtils.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\14_CrossriderUtils.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\155_ibario_pops_m.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\16_FFAppAPIWrapper.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\17_jQuery.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\177_crossriderDashboard.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\178_revizer_ws_dynamic_m.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\180_bpo_serp_m.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\182_openUrl.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\183_tabsWrapper.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\190_pops_5_m.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\191_ciuvo_m.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\195_icm_convertmedia_m.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\207_dbWrapper.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\21_debug.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\217_similar_products_m.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\22_resources.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\220_icm_base_m.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\221_icm_downloads_m.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\223_imonomy_m.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\226_set_campaign_id_m.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\246_setup.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\28_initializer.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\4_jquery_1_7_1.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\47_resources_background.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\64_appApiMessage.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\7_hooks.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\72_appApiValidation.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\78_CrossriderInfo.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\9_search_engine_hook.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\91_monetizationLoader.js.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\plugins\98_omniCommands.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\userCode\background.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\extensionData\userCode\extension.js
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\install.rdf
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\locale\en-US\translations.dtd
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\skin\button1.png
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\skin\button2.png
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\skin\button3.png
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\skin\button4.png
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\skin\button5.png
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\skin\crossrider_statusbar.png
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\skin\icon128.png
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\skin\icon16.png
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\skin\icon24.png
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\skin\icon48.png
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\skin\panelarrow-up.png
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\skin\popup.html
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\skin\skin.css
c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\8c6c8c15-21d7-4f62-8a57-202aee8f7fb3@6567ba21-e435-4eb0-838d-8395b2265c30.com\skin\update.css
c:\users\The Myers\AppData\Roaming\Tinaym
c:\users\The Myers\AppData\Roaming\Tinaym\ratiu.exe
.
.
(((((((((((((((((((((((((   Files Created from 2014-05-09 to 2014-06-09  )))))))))))))))))))))))))))))))
.
.
2014-06-09 10:38 . 2014-06-09 10:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-06-07 09:44 . 2014-06-07 09:44 -------- d-----w- c:\users\The Myers\AppData\Roaming\Uhsuugu
2014-06-07 05:45 . 2014-06-07 05:45 -------- d-----w- c:\users\The Myers\AppData\Roaming\Uzirakw
2014-06-06 17:48 . 2014-06-06 17:48 -------- d-----w- c:\users\The Myers\AppData\Roaming\Kecaula
2014-06-06 17:47 . 2014-06-07 21:23 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{08AEF997-A236-4352-B632-CC03E180B6AA}\offreg.dll
2014-06-06 14:36 . 2014-05-20 05:18 10702536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{08AEF997-A236-4352-B632-CC03E180B6AA}\mpengine.dll
2014-06-06 13:46 . 2014-06-06 13:46 -------- d-----w- c:\users\The Myers\AppData\Roaming\Apyseqa
2014-06-06 05:51 . 2014-06-06 05:51 -------- d-----w- c:\users\The Myers\AppData\Roaming\Moumopik
2014-06-06 01:47 . 2014-06-06 01:47 -------- d-----w- c:\users\The Myers\AppData\Roaming\Emhycao
2014-06-05 21:50 . 2014-06-05 21:50 -------- d-----w- c:\users\The Myers\AppData\Roaming\Zunyonh
2014-06-05 17:08 . 2014-06-05 17:08 -------- d-----w- c:\users\The Myers\AppData\Roaming\Sezuliol
2014-06-05 01:43 . 2014-06-05 01:43 -------- d-----w- c:\users\The Myers\AppData\Roaming\Yvydok
2014-06-04 20:27 . 2014-03-31 13:35 270496 ------w- c:\windows\system32\MpSigStub.exe
2014-06-04 01:10 . 2014-06-04 01:10 -------- d-----w- c:\users\The Myers\AppData\Roaming\Wiicpo
2014-06-03 11:37 . 2014-06-03 11:46 -------- d-----w- c:\users\The Myers\AppData\Local\ElevatedDiagnostics
2014-06-03 05:47 . 2014-06-03 05:47 -------- d-----w- c:\users\The Myers\AppData\Roaming\Yludnuc
2014-06-03 01:45 . 2014-06-03 01:45 -------- d-----w- c:\users\The Myers\AppData\Roaming\Yrulzefi
2014-06-03 00:14 . 2014-06-03 00:14 -------- d-----w- c:\users\The Myers\AppData\Roaming\Ynosvidi
2014-06-02 22:28 . 2014-06-02 22:28 -------- d-----w- c:\users\The Myers\AppData\Roaming\Gaxueb
2014-06-02 21:17 . 2014-06-02 21:17 -------- d-----w- c:\users\The Myers\AppData\Roaming\Suuxevo
2014-06-02 20:16 . 2014-06-02 20:16 -------- d-----w- c:\users\The Myers\AppData\Roaming\Tabuold
2014-06-02 20:12 . 2014-06-02 20:12 -------- d-----w- c:\users\The Myers\AppData\Roaming\Yhaskyal
2014-06-02 11:48 . 2014-06-02 11:48 -------- d-----w- c:\users\The Myers\AppData\Roaming\Wyogun
2014-06-02 11:48 . 2014-06-02 19:51 -------- d-----w- c:\users\The Myers\AppData\Roaming\Loyqruz
2014-06-02 11:48 . 2014-06-02 11:48 -------- d-----w- c:\users\The Myers\AppData\Roaming\Quyshe
2014-06-02 11:48 . 2014-06-02 11:48 -------- d-----w- c:\users\The Myers\AppData\Roaming\Xowiuwri
2014-06-01 13:40 . 2014-06-02 19:51 -------- d-----w- c:\users\The Myers\AppData\Roaming\Alirez
2014-06-01 09:40 . 2014-06-02 19:51 -------- d-----w- c:\users\The Myers\AppData\Roaming\Ytboirnu
2014-06-01 08:10 . 2014-06-02 19:54 -------- d-----w- c:\users\The Myers\AppData\Roaming\Paesoss
2014-05-14 07:05 . 2014-05-06 04:40 23544320 ----a-w- c:\windows\system32\mshtml.dll
2014-05-14 07:05 . 2014-05-06 03:00 84992 ----a-w- c:\windows\system32\mshtmled.dll
2014-05-14 07:05 . 2014-05-06 04:17 2724864 ----a-w- c:\windows\system32\mshtml.tlb
2014-05-14 07:05 . 2014-05-06 03:07 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
2014-05-14 04:23 . 2014-03-25 02:43 14175744 ----a-w- c:\windows\system32\shell32.dll
2014-05-14 04:23 . 2014-05-09 06:14 477184 ----a-w- c:\windows\system32\aepdu.dll
2014-05-14 04:23 . 2014-05-09 06:11 424448 ----a-w- c:\windows\system32\aeinv.dll
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-14 07:01 . 2011-08-14 13:14 93223848 ----a-w- c:\windows\system32\MRT.exe
2014-05-14 04:57 . 2012-08-20 10:47 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-05-14 04:57 . 2011-08-16 22:41 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-05-08 22:28 . 2013-05-04 00:49 50464 ----a-w- c:\windows\system32\drivers\avgtpx64.sys
2014-04-15 06:34 . 2014-04-15 06:34 1070232 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d}"= "c:\program files (x86)\Tucows_Downloads\prxtbTuco.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2014-05-08 22:28 3592728 ----a-w- c:\program files (x86)\AVG SafeGuard toolbar\18.1.5.515\AVG SafeGuard toolbar_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d}]
2011-05-09 08:49 176936 ----a-w- c:\program files (x86)\Tucows_Downloads\prxtbTuco.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d}"= "c:\program files (x86)\Tucows_Downloads\prxtbTuco.dll" [2011-05-09 176936]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files (x86)\AVG SafeGuard toolbar\18.1.5.515\AVG SafeGuard toolbar_toolbar.dll" [2014-05-08 3592728]
.
[HKEY_CLASSES_ROOT\clsid\{bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d}]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zagoerwyb"="c:\users\The Myers\AppData\Roaming\Yhaskyal\zuydgo.exe" [2012-08-25 310784]
"Ulebcaqeezra"="c:\users\The Myers\AppData\Roaming\Xowiuwri\atucmo.exe" [2012-07-17 324608]
"Rebuk"="c:\users\The Myers\AppData\Roaming\Apyseqa\agagatn.exe" [2012-12-11 280576]
"Aclyqoofh"="c:\users\The Myers\AppData\Roaming\Yvydok\cocyuse.exe" [2014-02-07 317952]
"Veziytfiy"="c:\users\The Myers\AppData\Roaming\Yrulzefi\uxcuh.exe" [2012-03-16 310784]
"Tuogowvesikout"="c:\users\The Myers\AppData\Roaming\Sezuliol\mawye.exe" [2013-03-02 286867]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Hotkey Utility"="c:\program files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe" [2010-08-04 611872]
"MDS_Menu"="c:\program files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"ArcadeMovieService"="c:\program files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe" [2010-06-30 124136]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"vProt"="c:\program files (x86)\AVG SafeGuard toolbar\vprot.exe" [2014-05-08 2561560]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\users\The Myers\Desktop\Updater\Updater.exe;c:\users\The Myers\Desktop\Updater\Updater.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys;c:\windows\SYSNATIVE\drivers\avgtpx64.sys [x]
S2 CouponPrinterService;Coupon Printer Service;c:\program files (x86)\Coupons\CouponPrinterService.exe;c:\program files (x86)\Coupons\CouponPrinterService.exe [x]
S2 Fitbit Connect;Fitbit Connect Service;c:\program files (x86)\Fitbit Connect\FitbitConnectService.exe;c:\program files (x86)\Fitbit Connect\FitbitConnectService.exe [x]
S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe;c:\program files (x86)\Acer\Registration\GREGsvc.exe [x]
S2 PasswordBox;PasswordBox;c:\program files (x86)\PasswordBox\pbbtnService.exe;c:\program files (x86)\PasswordBox\pbbtnService.exe [x]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x]
S2 vToolbarUpdater18.1.5;vToolbarUpdater18.1.5;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.5\ToolbarUpdater.exe;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.5\ToolbarUpdater.exe [x]
S3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1y60x64.sys [x]
S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys;c:\windows\SYSNATIVE\drivers\IntcHdmi.sys [x]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-05-22 07:26 1091912 ----a-w- c:\program files (x86)\Google\Chrome\Application\35.0.1916.114\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-06-09 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-20 04:57]
.
2014-06-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-10-01 15:51]
.
2014-06-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-10-01 15:51]
.
2014-06-09 c:\windows\Tasks\Security Center Update - 1440003018.job
- c:\users\The Myers\AppData\Roaming\Yhaskyal\zuydgo.exe [2012-08-25 20:55]
.
2014-06-09 c:\windows\Tasks\Security Center Update - 1518819644.job
- c:\users\The Myers\AppData\Roaming\Uzirakw\isedd.exe [2014-05-07 21:14]
.
2014-06-09 c:\windows\Tasks\Security Center Update - 1679535995.job
- c:\users\The Myers\AppData\Roaming\Ynosvidi\ihequf.exe [2013-04-01 06:19]
.
2014-06-09 c:\windows\Tasks\Security Center Update - 1749706860.job
- c:\users\The Myers\AppData\Roaming\Yrulzefi\uxcuh.exe [2012-03-16 12:13]
.
2014-06-09 c:\windows\Tasks\Security Center Update - 1949422797.job
- c:\users\The Myers\AppData\Roaming\Moumopik\qetela.exe [2012-02-19 22:48]
.
2014-06-09 c:\windows\Tasks\Security Center Update - 2113702981.job
- c:\users\The Myers\AppData\Roaming\Apyseqa\agagatn.exe [2012-12-11 20:22]
.
2014-06-09 c:\windows\Tasks\Security Center Update - 271640114.job
- c:\users\The Myers\AppData\Roaming\Emhycao\aphoc.exe [2013-11-13 12:01]
.
2014-06-09 c:\windows\Tasks\Security Center Update - 2843776151.job
- c:\users\The Myers\AppData\Roaming\Sezuliol\mawye.exe [2013-03-02 12:03]
.
2014-06-09 c:\windows\Tasks\Security Center Update - 2900589214.job
- c:\users\The Myers\AppData\Roaming\Gaxueb\qopevey.exe [2014-05-03 10:26]
.
2014-06-09 c:\windows\Tasks\Security Center Update - 2925848665.job
- c:\users\The Myers\AppData\Roaming\Suuxevo\zoxuyz.exe [2012-08-19 10:14]
.
2014-06-09 c:\windows\Tasks\Security Center Update - 3223429417.job
- c:\users\The Myers\AppData\Roaming\Kecaula\kugieq.exe [2012-08-27 14:43]
.
2014-06-09 c:\windows\Tasks\Security Center Update - 3483887649.job
- c:\users\The Myers\AppData\Roaming\Zunyonh\ykqyfyi.exe [2013-05-26 12:28]
.
2014-06-09 c:\windows\Tasks\Security Center Update - 3849768352.job
- c:\users\The Myers\AppData\Roaming\Wiicpo\ecurmef.exe [2013-04-01 14:38]
.
2014-06-09 c:\windows\Tasks\Security Center Update - 3908467978.job
- c:\users\The Myers\AppData\Roaming\Uhsuugu\yxomg.exe [2013-09-24 21:33]
.
2014-06-09 c:\windows\Tasks\Security Center Update - 419072211.job
- c:\users\The Myers\AppData\Roaming\Tabuold\xudif.exe [2012-12-22 03:59]
.
2014-06-09 c:\windows\Tasks\Security Center Update - 75785538.job
- c:\users\The Myers\AppData\Roaming\Yludnuc\igvuyb.exe [2013-06-05 09:05]
.
2014-06-09 c:\windows\Tasks\Security Center Update - 793415054.job
- c:\users\The Myers\AppData\Roaming\Yvydok\cocyuse.exe [2014-02-07 16:52]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{11111111-1111-1111-1111-110411771118}]
c:\program files (x86)\Plus-HD-5.0\Plus-HD-5.0-bho64.dll [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-20 7981088]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-11 162328]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-11 386584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 417304]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.5\ViProtocol.dll
FF - ProfilePath - c:\users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://mysearch.avg.com?pid=safeguard&sg=0&cid=%7B99b185cd-9200-43fe-af12-5cf91e57efe0%7D&mid=3d2ea970080b47d0afd4294607f26d34-1231171661c17a7a500f40b64c2cd56f282a994d&ds=AVG&coid=&cmpid=&v=17.3.2.101&lang=en&pr=fr&d=2013-08-27%2008%3A05%3A55&sap=hp
FF - user.js: extensions.mysearchdial.hmpg - true
FF - user.js: extensions.mysearchdial.hmpgUrl - hxxp://start.mysearchdial.com/?f=1&a=dnldstr0101&cd=2XzuyEtN2Y1L1Qzu0FzztD0FyEtCtCyCzzyE0CyB0DyCtAtAtN0D0Tzu0SyBtAtDtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=246922190&ir=
FF - user.js: extensions.mysearchdial.dfltSrch - true
FF - user.js: extensions.mysearchdial.srchPrvdr - Mysearchdial
FF - user.js: extensions.mysearchdial.dnsErr - true
FF - user.js: extensions.mysearchdial_i.newTab - false
FF - user.js: extensions.mysearchdial.newTabUrl - hxxp://start.mysearchdial.com/?f=2&a=dnldstr0101&cd=2XzuyEtN2Y1L1Qzu0FzztD0FyEtCtCyCzzyE0CyB0DyCtAtAtN0D0Tzu0SyBtAtDtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=246922190&ir=
FF - user.js: extensions.mysearchdial.tlbrSrchUrl - hxxp://start.mysearchdial.com/?f=3&a=dnldstr0101&cd=2XzuyEtN2Y1L1Qzu0FzztD0FyEtCtCyCzzyE0CyB0DyCtAtAtN0D0Tzu0SyBtAtDtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R&cr=246922190&ir=&q=
FF - user.js: extensions.mysearchdial.id - F80F411684C7D633
FF - user.js: extensions.mysearchdial.instlDay - 16069
FF - user.js: extensions.mysearchdial.vrsn - 1.8.21.0
FF - user.js: extensions.mysearchdial.vrsni - 1.8.21.0
FF - user.js: extensions.mysearchdial_i.vrsnTs - 1.8.21.019:40
FF - user.js: extensions.mysearchdial.prtnrId - mysearchdial
FF - user.js: extensions.mysearchdial.prdct - mysearchdial
FF - user.js: extensions.mysearchdial.aflt - dnldstr0101
FF - user.js: extensions.mysearchdial_i.smplGrp - none
FF - user.js: extensions.mysearchdial.tlbrId - base
FF - user.js: extensions.mysearchdial.instlRef - 
FF - user.js: extensions.mysearchdial.dfltLng - 
FF - user.js: extensions.mysearchdial.appId - {CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}
FF - user.js: extensions.mysearchdial.excTlbr - false
FF - user.js: extensions.mysearchdial_i.hmpg - true
FF - user.js: extensions.mysearchdial.cr - 246922190
FF - user.js: extensions.mysearchdial.cd - 2XzuyEtN2Y1L1Qzu0FzztD0FyEtCtCyCzzyE0CyB0DyCtAtAtN0D0Tzu0SyBtAtDtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R
FF - user.js: extensions.irmysearch.aflt - dnldstr0101
FF - user.js: extensions.irmysearch.instlRef - 
FF - user.js: extensions.irmysearch.cr - 246922190
FF - user.js: extensions.irmysearch.cd - 2XzuyEtN2Y1L1Qzu0FzztD0FyEtCtCyCzzyE0CyB0DyCtAtAtN0D0Tzu0SyBtAtDtN1L2XzutBtFtBtFtCyEtFtCtAyBzytN1L1CzutCyD1B1P1R
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-Suunyxengovurat - c:\users\The Myers\AppData\Roaming\Tinaym\ratiu.exe
WebBrowser-{BDE6F3A2-2CE8-4430-94E0-CD4CE39EEB0D} - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.13"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2014-06-09  06:40:57
ComboFix-quarantined-files.txt  2014-06-09 10:40
ComboFix2.txt  2014-06-07 14:36
.
Pre-Run: 908,192,296,960 bytes free
Post-Run: 908,645,691,392 bytes free
.
- - End Of File - - B7FC4A1B67DE882075F2AB570EB1CC48
 

All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== OTL ==========
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411771118}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110411771118}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Rebuk deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
C:\Users\The Myers\AppData\Roaming\Uhsuugu folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Uzirakw folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Kecaula folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Apyseqa folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Moumopik folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Emhycao folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Zunyonh folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Sezuliol folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Yvydok folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Wiicpo folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Yludnuc folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Yrulzefi folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Ynosvidi folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Gaxueb folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Suuxevo folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Tabuold folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Yhaskyal folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Wyogun folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Quyshe folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Loyqruz folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Xowiuwri folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Alirez folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Ytboirnu folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Paesoss folder moved successfully.
C:\Windows\Tasks\Security Center Update - 271640114.job moved successfully.
C:\Windows\Tasks\Security Center Update - 3849768352.job moved successfully.
C:\Windows\Tasks\Security Center Update - 2113702981.job moved successfully.
C:\Windows\Tasks\Security Center Update - 1679535995.job moved successfully.
C:\Windows\Tasks\Security Center Update - 3223429417.job moved successfully.
C:\Windows\Tasks\Security Center Update - 3483887649.job moved successfully.
C:\Windows\Tasks\Security Center Update - 75785538.job moved successfully.
C:\Windows\Tasks\Security Center Update - 1949422797.job moved successfully.
C:\Windows\Tasks\Security Center Update - 2900589214.job moved successfully.
C:\Windows\Tasks\Security Center Update - 2925848665.job moved successfully.
C:\Windows\Tasks\Security Center Update - 3908467978.job moved successfully.
C:\Windows\Tasks\Security Center Update - 1518819644.job moved successfully.
C:\Windows\Tasks\Security Center Update - 1440003018.job moved successfully.
C:\Windows\Tasks\Security Center Update - 2843776151.job moved successfully.
C:\Windows\Tasks\Security Center Update - 793415054.job moved successfully.
C:\Windows\Tasks\Security Center Update - 419072211.job moved successfully.
C:\Windows\Tasks\Security Center Update - 1749706860.job moved successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d}\ deleted successfully.
C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll moved successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2EFE2B5A-6024-44AD-98EA-770F3E7E8BD4}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EFE2B5A-6024-44AD-98EA-770F3E7E8BD4}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{FB689C36-6BE7-4010-BB7F-7868996F0B6B}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB689C36-6BE7-4010-BB7F-7868996F0B6B}\ not found.
Prefs.js: "AVG Secure Search" removed from browser.search.defaultenginename
Prefs.js: "AVG Secure Search" removed from browser.search.selectedEngine
Prefs.js: "http://mysearch.avg.....8:05:55&sap=hp" removed from browser.startup.homepage
Prefs.js: avg%40toolbar:18.1.5.515 removed from extensions.enabledAddons
Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar deleted successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\skin folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\zh-tw folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\zh-cn folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\tr folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\th folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\sv folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\sr folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\sk folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\ru folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\ro folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\pt-br folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\pt folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\pl folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\nl folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\nb folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\ms folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\ko folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\ja folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\it folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\id folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\hu folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\hi folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\fr folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\fi folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\es-es folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\es folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\en folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\el folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\de folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\da folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\cs folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale\af folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules\locale folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\modules folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\locale\en-US folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\locale folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\components folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515\chrome folder moved successfully.
C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515 folder moved successfully.
C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\searchplugins\ask-web-search.xml moved successfully.
C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\searchplugins\avg-secure-search.xml moved successfully.
C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\searchplugins\Mysearchdial.xml moved successfully.
C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\searchplugins\web-search.xml moved successfully.
Folder C:\PROGRAMDATA\AVG SAFEGUARD TOOLBAR\FIREFOXEXT\18.1.5.515\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.
C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.5.515\AVG SafeGuard toolbar_toolbar.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d}\ not found.
File C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.
File C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.5.515\AVG SafeGuard toolbar_toolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d}\ not found.
File C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BDE6F3A2-2CE8-4430-94E0-CD4CE39EEB0D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDE6F3A2-2CE8-4430-94E0-CD4CE39EEB0D}\ not found.
File C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\vProt deleted successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Rebuk not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d}\ not found.
File C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2EFE2B5A-6024-44AD-98EA-770F3E7E8BD4}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EFE2B5A-6024-44AD-98EA-770F3E7E8BD4}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{FB689C36-6BE7-4010-BB7F-7868996F0B6B}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB689C36-6BE7-4010-BB7F-7868996F0B6B}\ not found.
Prefs.js: "AVG Secure Search" removed from browser.search.defaultenginename
Prefs.js: "AVG Secure Search" removed from browser.search.selectedEngine
Prefs.js: "http://mysearch.avg.....8:05:55&sap=hp" removed from browser.startup.homepage
Prefs.js: avg%40toolbar:18.1.5.515 removed from extensions.enabledAddons
Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar not found.
File C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.1.5.515 not found.
File C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\searchplugins\ask-web-search.xml not found.
File C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\searchplugins\avg-secure-search.xml not found.
File C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\searchplugins\Mysearchdial.xml not found.
File C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\searchplugins\web-search.xml not found.
Folder C:\PROGRAMDATA\AVG SAFEGUARD TOOLBAR\FIREFOXEXT\18.1.5.515\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.
File C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.5.515\AVG SafeGuard toolbar_toolbar.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d}\ not found.
File C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{95B7759C-8C7F-4BF1-B163-73684A933233} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.
File C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.5.515\AVG SafeGuard toolbar_toolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bde6f3a2-2ce8-4430-94e0-cd4ce39eeb0d}\ not found.
File C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BDE6F3A2-2CE8-4430-94E0-CD4CE39EEB0D} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDE6F3A2-2CE8-4430-94E0-CD4CE39EEB0D}\ not found.
File C:\Program Files (x86)\Tucows_Downloads\prxtbTuco.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\vProt not found.
File C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Rebuk not found.
========== FILES ==========
File\Folder C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo not found.
File\Folder C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo not found.
File\Folder C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf not found.
File\Folder C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf not found.
File\Folder C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof not found.
File\Folder C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof not found.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\zh_TW folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\zh_CN folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\vi folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\uk folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\tr folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\th folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\sv folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\sr folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\sl folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\sk folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\ru folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\ro folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\pt_PT folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\pt_BR folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\pl folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\nl folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\nb folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\lv folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\lt folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\ko folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\ja folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\it folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\id folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\hu folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\hr folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\hi folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\fr folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\fil folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\fi folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\et folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\es_419 folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\es folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\en_GB folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\en folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\el folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\de folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\da folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\cs folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\ca folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales\bg folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\_locales folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\images folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\html folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\css folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1 folder moved successfully.
C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda folder moved successfully.
File\Folder C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia not found.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56468 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Public
->Temp folder emptied: 0 bytes
 
User: The Myers
->Temp folder emptied: 381904733 bytes
->Temporary Internet Files folder emptied: 11410200497 bytes
->Java cache emptied: 31996 bytes
->FireFox cache emptied: 187195495 bytes
->Google Chrome cache emptied: 819568 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 296656 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3262290 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 118428 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 11,429.00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 06102014_163322
 
Files\Folders moved on Reboot...
File\Folder C:\Users\The Myers\AppData\Local\Temp\fla186F.tmp not found!
File\Folder C:\Users\The Myers\AppData\Local\Temp\fla1CB4.tmp not found!
File\Folder C:\Users\The Myers\AppData\Local\Temp\fla1F8C.tmp not found!
File\Folder C:\Users\The Myers\AppData\Local\Temp\fla4141.tmp not found!
File\Folder C:\Users\The Myers\AppData\Local\Temp\fla58A.tmp not found!
File\Folder C:\Users\The Myers\AppData\Local\Temp\fla71CA.tmp not found!
File\Folder C:\Users\The Myers\AppData\Local\Temp\fla761B.tmp not found!
File\Folder C:\Users\The Myers\AppData\Local\Temp\fla7DAA.tmp not found!
File\Folder C:\Users\The Myers\AppData\Local\Temp\fla97B8.tmp not found!
File\Folder C:\Users\The Myers\AppData\Local\Temp\flaB144.tmp not found!
File\Folder C:\Users\The Myers\AppData\Local\Temp\flaC11B.tmp not found!
File\Folder C:\Users\The Myers\AppData\Local\Temp\flaCCBE.tmp not found!
File\Folder C:\Users\The Myers\AppData\Local\Temp\flaD8BC.tmp not found!
File\Folder C:\Users\The Myers\AppData\Local\Temp\flaDAAD.tmp not found!
File\Folder C:\Users\The Myers\AppData\Local\Temp\flaF8C7.tmp not found!
C:\Users\The Myers\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{9B1D066B-72F4-4048-AE3C-C74DA1073855}.tmp not found!
File\Folder C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{EB4FB83E-95E4-4F55-ADD9-BF583DD512B8}.tmp not found!
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X056MIC9\AdDisplayTrackerServlet[4].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X056MIC9\AdDisplayTrackerServlet[5].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X056MIC9\AdDisplayTrackerServlet[6].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X056MIC9\AdDisplayTrackerServlet[7].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X056MIC9\AdDisplayTrackerServlet[8].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X056MIC9\AdDisplayTrackerServlet[9].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X056MIC9\B8130998[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X056MIC9\B8130998[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X056MIC9\chinese-airline-rejects-air-hostess-job-applicants-based-on-looks[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X056MIC9\clk[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X056MIC9\ddc[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X056MIC9\fontawesome-webfont[1].eot moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X056MIC9\fv2[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X056MIC9\hgtv[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X056MIC9\id_sync[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X056MIC9\p-01-0VIaSjnOLg[3].gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X056MIC9\rt=ifr[4].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X056MIC9\SPug[1].txt moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X056MIC9\usermatch[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X056MIC9\visitormatch[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U0J60MRV\16731[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U0J60MRV\518037754_2[1].mp4 moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U0J60MRV\AdDisplayTrackerServletB1XRRY81.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U0J60MRV\AdDisplayTrackerServlet[10].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U0J60MRV\AdDisplayTrackerServlet[9].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U0J60MRV\ads[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U0J60MRV\ad[6].gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U0J60MRV\ad[7].gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U0J60MRV\cfbc[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U0J60MRV\emily[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U0J60MRV\hgtv[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U0J60MRV\postmessageRelay[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U0J60MRV\s2[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U0J60MRV\s2[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U0J60MRV\ttj[5].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U0J60MRV\ttj[6].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8XA7MSS\1@x01[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8XA7MSS\1@x01[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8XA7MSS\365738[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8XA7MSS\adDDP7VYBC.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8XA7MSS\adHZGLS932.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8XA7MSS\adJFGUTF53.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8XA7MSS\adOQEMOAF8.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8XA7MSS\click[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8XA7MSS\fhs[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8XA7MSS\groupm[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8XA7MSS\if7A2YKU2Y.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8XA7MSS\ifLY9YPYX3.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8XA7MSS\jquery-migrate.min[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8XA7MSS\jquery.anythingslider.min[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8XA7MSS\load[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8XA7MSS\nav[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8XA7MSS\p-01-0VIaSjnOLgDEG4YDBE.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8XA7MSS\postmessageRelay[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8XA7MSS\s2[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O8XA7MSS\user_sync[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\;subTagID=100;subTagName=;clickTrack=;impactTrack=;referrer=;showName=;showLen=;cb=441054876[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\ad6BBK666R.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\ad9FFTNYGX.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\adD2OJ4YL7.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\AdDisplayTrackerServlet65QUAE3K.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\AdDisplayTrackerServletCCDH4LCU.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\AdDisplayTrackerServletHEA5OP0X.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\AdDisplayTrackerServletXX7L4HY1.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\AdDisplayTrackerServlet[10].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\AdDisplayTrackerServlet[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\AdDisplayTrackerServlet[6].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\AdDisplayTrackerServlet[7].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\AdDisplayTrackerServlet[9].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\adFKBX3MPX.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\adP1OTX640.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\adTag[3].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\adTag[4].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\beacon[6].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\engine04V3OHI9.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\engineSH5257H7.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\if7Q9KW5SU.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\ifAETE2SLW.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\ifLKBI7NN9.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\is-your-pet-a-member-of-the-family-build-them-a-bed[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\i[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\px[4].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\rt=ifr[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\s2[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\socket[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYDVRVXY\SPug[1].txt moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J09HP47J\1459236-756c7690-342d-4930-88a5-fde42856d960[1].mp4 moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J09HP47J\AdDisplayTrackerServlet[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J09HP47J\AdDisplayTrackerServlet[3].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J09HP47J\AdDisplayTrackerServlet[6].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J09HP47J\AdDisplayTrackerServlet[7].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J09HP47J\AdDisplayTrackerServlet[8].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J09HP47J\adi[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J09HP47J\adPE2LUERT.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J09HP47J\adT6XTB0UI.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J09HP47J\bct[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J09HP47J\c92rD_x0V1LslSFt3-QEpgRV2F9RPTaqyJ4QibDfkzM[1].woff moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J09HP47J\cj2hUnSRBhwmSPr9kS5899kZXW4sYc4BjuAIFc1SXII[1].woff moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J09HP47J\fo[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J09HP47J\MTP_ySUJH_bn48VBG8sNSnhCUOGz7vYGh680lGh-uXM[1].woff moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J09HP47J\px[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J09HP47J\QQt14e8dY39u-eYBZmppwTqR_3kx9_hJXbbyU8S6IN0[1].woff moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J09HP47J\swfobject[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J09HP47J\V80PAcvrynR[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J09HP47J\V80PAcvrynR[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J09HP47J\widgets[2].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IQ8YYVKC\AdDisplayTrackerServletD01DIJ8A.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IQ8YYVKC\AdDisplayTrackerServletTP69H542.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IQ8YYVKC\AdDisplayTrackerServlet[5].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IQ8YYVKC\AdDisplayTrackerServlet[7].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IQ8YYVKC\AdDisplayTrackerServlet[8].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IQ8YYVKC\ads[3].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IQ8YYVKC\ads[4].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IQ8YYVKC\ad[1].gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IQ8YYVKC\ad[2].gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IQ8YYVKC\ad[5].gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IQ8YYVKC\beacon[5].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IQ8YYVKC\click[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IQ8YYVKC\disaster-bedroom-gets-vanilla-ices-four-star-treatment[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IQ8YYVKC\fastbutton[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IQ8YYVKC\if[3].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IQ8YYVKC\if[5].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IQ8YYVKC\if[6].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IQ8YYVKC\slot92132[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IQ8YYVKC\videos[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\16731[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\AdDisplayTrackerServlet[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\AdDisplayTrackerServlet[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\AdDisplayTrackerServlet[6].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\adometry-post4[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\engine[7].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\ff2[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\fontawesome-webfont[1].woff moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\fontawesome-webfont[2].woff moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\food-videos[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\ggv2[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\ifBA864MH7.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\ifJBYK38MN.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\jquery.anythingslider.video.min[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\jquery.fancybox-1.3.4.pack[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\jquery.mousewheel-3.0.4.pack[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\ODelI1aHBYDBqgeIAH2zlBM0YzuT7MdOe03otPbuUS0[2].woff moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\prettyPhoto[1].css moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\print_plugin[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\px[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\rt=ifr[3].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\rt=ifr[4].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\rt=ifr[5].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\rt=ifr[6].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\sandbox[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\swfobject[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\theme[2].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HMELON99\toadOcfmlt9b38dHJxOBGFkQc6VGVFSmCnC_l7QZG60[2].woff moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H8XLPXPV\0AKsP294HTD-nvJgucYTaIbN6UDyHWBl620a-IRfuBk[1].woff moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H8XLPXPV\365738[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H8XLPXPV\AdDisplayTrackerServlet[3].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H8XLPXPV\adL1U1LQKP.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H8XLPXPV\adLRAG22KP.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H8XLPXPV\ads[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H8XLPXPV\beacon[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H8XLPXPV\handshake[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H8XLPXPV\ifCW12WAJF.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H8XLPXPV\load[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H8XLPXPV\playerd7a1e907[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H8XLPXPV\rpassback[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H8XLPXPV\s2[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H8XLPXPV\showad[4].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H8XLPXPV\tweet_button.1401325387[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEGPW35S\;ord=4377218362417214058[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEGPW35S\adoapn_AppNexusDemoActionTag_1[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEGPW35S\adoapn_AppNexusDemoActionTag_1[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEGPW35S\adYCE1BKFA.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEGPW35S\ddc[9].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEGPW35S\engine[6].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEGPW35S\fontawesome-webfont[1].ttf moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEGPW35S\gaQja7BpYuqOJmzNAYJnK-TgZ2FRamE3QnBZdXFPSm16TkFZSm5LLVRnZ2FRamE3QnBZdXFPSm1[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEGPW35S\HORRZ31D.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEGPW35S\if2UFGLZC3.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEGPW35S\iframe[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEGPW35S\impsc[6].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEGPW35S\PlayerSeed[3].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEGPW35S\rt=ifr[8].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEGPW35S\s2[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEGPW35S\thn-tryout-workout-landing-ym[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FEGPW35S\YHU7OWY8.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D37X2Y3L\1TLWCBI3.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D37X2Y3L\AdDisplayTrackerServlet[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D37X2Y3L\AdDisplayTrackerServlet[3].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D37X2Y3L\AdDisplayTrackerServlet[5].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D37X2Y3L\adGAHT6XS2.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D37X2Y3L\ba[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D37X2Y3L\beacon[6].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D37X2Y3L\beacon[7].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D37X2Y3L\display[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D37X2Y3L\ff2[3].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D37X2Y3L\if1BVB3B33.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D37X2Y3L\if2WFZEYOR.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D37X2Y3L\jquery.min[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D37X2Y3L\like_box[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D37X2Y3L\load[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D37X2Y3L\m[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D37X2Y3L\s-BiyweUPV0v-yRb-cjciBsxEYwM7FgeyaSgU71cLG0[1].woff moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D37X2Y3L\SPug[1].txt moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D37X2Y3L\ttEQ760LK2.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D37X2Y3L\user_sync[4].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\1${CACHEBUSTER}@x96[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\1523170400@x23[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\7971[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\@x23[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\ab[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\ads[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\adTAILSER4.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\css[4].css moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\emily[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\ifLOH31SG5.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\ifMVUBHHCI.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\iframe[3].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\i[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\likeGTB07FG2.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\p-01-0VIaSjnOLg[7].gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\pixel[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\px[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\px[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\visitormatch[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\x71[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BO0KRB0D\Zd2E9abXLFGSr9G3YK2MsFzqCfRpIA3W6ypxnPISCPA[1].woff moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\1430064977@x23[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\4651[5].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\ad843X7QO1.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\AdDisplayTrackerServlet[8].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\adHIBA6KRA.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\ads[4].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\anythingslider[1].css moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\bjqs-1.3[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\comment-reply.min[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\engine[6].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\e[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\ff2[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\ff2[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\if2BVQSVSO.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\jquery.prettyPhoto[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\jquery[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\p-01-0VIaSjnOLg[8].gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\ping[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\pinit[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\post-widget[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\px[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\site+compare+georgia+catastrophic+health+insurance[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\site-131608[2].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\validate[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\visitormatch[3].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BF1U94DG\ZAPSegments@x96[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B93WS7VM\3qPfgRJhy_o6IWGjH-pPcw[1].eot moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B93WS7VM\;ord=7583843694700443048[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B93WS7VM\AdDisplayTrackerServlet[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B93WS7VM\AdDisplayTrackerServlet[8].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B93WS7VM\AdDisplayTrackerServlet[9].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B93WS7VM\ads[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B93WS7VM\B8060717[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B93WS7VM\ddc[10].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B93WS7VM\EFpQQyG9GqCrobXxL-KRMQFhaRv2pGgT5Kf0An0s4MM[1].woff moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B93WS7VM\fastbutton[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B93WS7VM\if3BQX49KP.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B93WS7VM\like[6].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B93WS7VM\pixel[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B93WS7VM\quant[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B93WS7VM\remodeling[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B93WS7VM\t2tv5[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B93WS7VM\validate[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AKLI6SC2\1107200014@x96[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AKLI6SC2\3PDPHandler[3].gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AKLI6SC2\ad13V0VZZ3.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AKLI6SC2\ads[3].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AKLI6SC2\ads[4].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AKLI6SC2\beacon[9].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AKLI6SC2\ca[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AKLI6SC2\ca[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AKLI6SC2\data[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AKLI6SC2\display[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AKLI6SC2\if9533MQTW.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AKLI6SC2\ifHB42PNYV.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AKLI6SC2\XUI2CXGB.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6J50DRU9\AdDisplayTrackerServlet[7].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6J50DRU9\AdDisplayTrackerServlet[8].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6J50DRU9\AdDisplayTrackerServlet[9].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6J50DRU9\clk[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6J50DRU9\css[3].css moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6J50DRU9\data[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6J50DRU9\engine[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6J50DRU9\if[4].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6J50DRU9\if[6].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6J50DRU9\impsc[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6J50DRU9\ping[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6J50DRU9\rt=ifr[6].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6J50DRU9\show[3].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6J50DRU9\show[4].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6J50DRU9\speak-up-for-kids-mental-health[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NU9Y69I\11735505104@x95[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NU9Y69I\1@x92[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NU9Y69I\4651[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NU9Y69I\ad23WV3CVQ.gif moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NU9Y69I\adi[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NU9Y69I\adometry-post4[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NU9Y69I\ads[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NU9Y69I\bjqs[1].css moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NU9Y69I\cc_af[2].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NU9Y69I\fontawesome-webfont[1].eot moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NU9Y69I\ifWT7WZE8K.htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NU9Y69I\jquery.fancybox-1.3.4[1].css moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NU9Y69I\kmn_sa[3].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NU9Y69I\load[1].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NU9Y69I\load[1].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NU9Y69I\load[2].js moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NU9Y69I\px[2].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NU9Y69I\px[3].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NU9Y69I\rt=ifr[7].htm moved successfully.
C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NU9Y69I\style[3].css moved successfully.
File move failed. C:\Users\The Myers\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat scheduled to be moved on reboot.
File move failed. C:\Windows\temp\avg_secure_search.log scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat scheduled to be moved on reboot.
 
PendingFileRenameOperations files...
 
Registry entries deleted on Reboot...

OTL logfile created on: 6/10/2014 7:01:59 PM - Run 2
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\The Myers\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17041)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
3.97 Gb Total Physical Memory | 2.38 Gb Available Physical Memory | 59.91% Memory free
7.93 Gb Paging File | 6.21 Gb Available in Paging File | 78.26% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 911.88 Gb Total Space | 858.64 Gb Free Space | 94.16% Space Free | Partition Type: NTFS
 
Computer Name: THEMYERS-PC | User Name: The Myers | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/06/09 16:09:08 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\The Myers\Desktop\OTL.com
PRC - [2014/05/14 15:07:08 | 000,067,584 | ---- | M] (PasswordBox, Inc.) -- C:\Program Files (x86)\PasswordBox\pbbtnService.exe
PRC - [2014/05/13 19:40:56 | 000,860,488 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014/05/13 14:23:04 | 003,644,432 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
PRC - [2014/05/13 14:18:32 | 005,181,456 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgui.exe
PRC - [2014/05/13 14:15:28 | 000,292,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
PRC - [2014/01/10 16:06:48 | 001,435,680 | R--- | M] (Fitbit, Inc.) -- C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe
PRC - [2013/12/21 02:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/04/23 03:48:17 | 003,574,624 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
PRC - [2010/08/04 08:40:12 | 000,611,872 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
PRC - [2010/06/29 22:26:30 | 000,124,136 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe
PRC - [2010/01/28 19:27:36 | 000,243,232 | ---- | M] (Acer Group) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe
PRC - [2010/01/08 09:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
PRC - [2009/06/04 22:03:32 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009/06/04 22:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/05/13 19:40:54 | 000,414,536 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ppgooglenaclpluginchrome.dll
MOD - [2014/05/13 19:40:50 | 004,217,672 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\pdf.dll
MOD - [2014/05/13 19:40:45 | 000,716,616 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\libglesv2.dll
MOD - [2014/05/13 19:40:44 | 000,126,280 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\libegl.dll
MOD - [2014/05/13 19:40:43 | 001,732,424 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ffmpegsumo.dll
MOD - [2010/08/04 08:40:12 | 000,611,872 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
MOD - [2010/08/04 05:47:32 | 000,144,896 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyHook.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2014/03/06 04:29:14 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013/05/27 01:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2010/09/22 21:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/01/28 19:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto | Running] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV - [2014/05/14 15:07:08 | 000,067,584 | ---- | M] (PasswordBox, Inc.) [Auto | Running] -- C:\Program Files (x86)\PasswordBox\pbbtnService.exe -- (PasswordBox)
SRV - [2014/05/14 00:57:21 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/05/13 14:23:04 | 003,644,432 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2014/05/13 14:15:28 | 000,292,424 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe -- (avgwd)
SRV - [2014/05/12 10:40:38 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/02/13 19:58:00 | 000,176,624 | ---- | M] (Coupons.com Inc.) [Auto | Running] -- C:\Program Files (x86)\Coupons\CouponPrinterService.exe -- (CouponPrinterService)
SRV - [2014/01/10 16:06:48 | 001,435,680 | R--- | M] (Fitbit, Inc.) [Auto | Running] -- C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe -- (Fitbit Connect)
SRV - [2013/12/21 02:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/09/11 22:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/04/23 03:48:17 | 003,574,624 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)
SRV - [2010/04/03 19:01:24 | 000,246,520 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2010/01/15 17:08:38 | 000,935,208 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2010/01/08 09:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe -- (GREGService)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/04 22:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014/05/13 14:20:26 | 000,235,800 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2014/05/13 14:20:06 | 000,273,176 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:64bit: - [2014/05/13 14:06:06 | 000,323,352 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgloga.sys -- (Avgloga)
DRV:64bit: - [2014/05/13 14:05:40 | 000,191,768 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA)
DRV:64bit: - [2014/05/13 14:05:08 | 000,152,344 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgdiska.sys -- (Avgdiska)
DRV:64bit: - [2014/05/13 14:05:06 | 000,130,328 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:64bit: - [2014/05/13 14:04:56 | 000,236,312 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
DRV:64bit: - [2014/05/13 14:04:30 | 000,031,512 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:64bit: - [2014/05/08 18:28:21 | 000,050,464 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/02/14 03:42:36 | 000,028,160 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgx64diag.sys -- (UsbDiag)
DRV:64bit: - [2011/02/14 03:42:30 | 000,034,816 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgx64modem.sys -- (USBModem)
DRV:64bit: - [2011/02/14 03:42:28 | 000,017,920 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgx64bus.sys -- (usbbus)
DRV:64bit: - [2011/02/11 19:16:38 | 010,628,640 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/08/10 23:40:06 | 001,014,624 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)
DRV:64bit: - [2009/12/09 05:39:52 | 000,537,624 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 16:35:02 | 000,281,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1y60x64.sys -- (e1yexpress)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/25 16:13:10 | 000,138,752 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcHdmi.sys -- (IntcHdmiAddService)
DRV:64bit: - [2009/03/18 16:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = 
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = 
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = 
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://mysearch.avg....8:05:55&sap=hp"
FF - prefs.js..extensions.enabledAddons: 
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:29.0.1
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\The Myers\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\PasswordBox\Firefox [2013/11/21 20:22:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014/05/12 10:40:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2014/05/17 15:53:29 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014/05/12 10:40:34 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2014/05/17 15:53:29 | 000,000,000 | ---D | M]
 
[2011/08/14 11:53:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\The Myers\AppData\Roaming\Mozilla\Extensions
[2014/06/10 18:42:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions
[2013/05/24 11:06:39 | 000,005,341 | ---- | M] () (No name found) -- C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\[email protected]
[2014/05/12 10:40:34 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/05/12 10:40:39 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
File not found (No name found) -- C:\PROGRAMDATA\AVG SAFEGUARD TOOLBAR\FIREFOXEXT\18.1.5.515
[2011/04/14 14:01:38 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - plugin: Error reading preferences file
CHR - Extension: Google Docs = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.6_0\
CHR - Extension: Google Drive = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Google Voice Search Hotword (Beta) = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5019_1\
CHR - Extension: YouTube = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Google Wallet = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
 
O1 HOSTS File: ([2014/06/09 06:38:55 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (PasswordBox Helper) - {5DB69B97-934B-451D-94DB-32EF802A01CD} - C:\Program Files (x86)\PasswordBox\Application\pbbtn.dll (PasswordBox, Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [ArcadeMovieService] C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe ()
O4 - HKLM..\Run: [MDS_Menu] C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455}  (ExentInf Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BC9B8ECA-8D3A-463C-A441-D44690C56727}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D486644F-BB99-42A1-B100-CA2FD71C5866}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/06/10 18:23:30 | 000,536,576 | ---- | C] (SQLite Development Team) -- C:\Windows\SysWow64\sqlite3.dll
[2014/06/10 18:22:24 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/06/10 16:33:22 | 000,000,000 | ---D | C] -- C:\_OTL
[2014/06/10 07:29:53 | 000,000,000 | -HSD | C] -- C:\found.000
[2014/06/10 07:22:35 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2014/06/09 17:48:29 | 000,000,000 | --SD | C] -- C:\ComboFix
[2014/06/09 16:20:18 | 005,205,664 | R--- | C] (Swearware) -- C:\Users\The Myers\Desktop\ComboFix.exe
[2014/06/09 16:20:00 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\The Myers\Desktop\OTL.com
[2014/06/09 07:21:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2014/06/07 09:43:27 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2014/06/07 09:43:27 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2014/06/07 09:43:27 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2014/06/07 09:43:20 | 000,000,000 | ---D | C] -- C:\Qoobox
[2014/06/07 09:42:32 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2014/06/03 07:37:32 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Local\ElevatedDiagnostics
[2014/05/14 03:04:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2014/05/13 14:20:26 | 000,235,800 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgldx64.sys
[2014/05/13 14:20:06 | 000,273,176 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgtdia.sys
[2014/05/13 14:06:06 | 000,323,352 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgloga.sys
[2014/05/13 14:05:40 | 000,191,768 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsha.sys
[2014/05/13 14:05:08 | 000,152,344 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgdiska.sys
[2014/05/13 14:05:06 | 000,130,328 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgmfx64.sys
[2014/05/13 14:04:56 | 000,236,312 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys
[2014/05/13 14:04:30 | 000,031,512 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgrkx64.sys
[2014/05/12 10:40:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
 
========== Files - Modified Within 30 Days ==========
 
[2014/06/10 19:07:44 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/06/10 19:07:43 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/06/10 18:59:59 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/06/10 18:59:41 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/06/10 18:59:40 | 3193,835,520 | -HS- | M] () -- C:\hiberfil.sys
[2014/06/10 18:57:42 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/06/10 18:25:00 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/06/09 17:49:18 | 000,184,320 | R--- | M] () -- C:\Windows\MBR.exe
[2014/06/09 16:09:08 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\The Myers\Desktop\OTL.com
[2014/06/09 07:21:02 | 000,000,969 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2014.lnk
[2014/06/09 06:38:55 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2014/06/09 06:18:26 | 005,205,664 | R--- | M] (Swearware) -- C:\Users\The Myers\Desktop\ComboFix.exe
[2014/06/07 09:43:40 | 000,782,510 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/06/07 09:43:40 | 000,662,400 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/06/07 09:43:40 | 000,122,268 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/06/02 13:22:59 | 000,349,912 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/06/02 07:04:47 | 000,457,116 | ---- | M] () -- C:\Users\The Myers\Documents\img006.jpg
[2014/06/02 07:02:20 | 000,455,758 | ---- | M] () -- C:\Users\The Myers\Documents\img005.jpg
[2014/05/30 08:18:55 | 000,068,782 | ---- | M] () -- C:\Users\The Myers\AppData\Local\erwbobfb
[2014/05/30 08:14:52 | 000,000,000 | ---- | M] () -- C:\Users\The Myers\AppData\Roaming\SharedSettings.ccs
[2014/05/22 03:36:28 | 000,002,187 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/05/19 10:37:37 | 000,000,826 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014/05/14 08:40:43 | 000,000,258 | RHS- | M] () -- C:\Users\The Myers\ntuser.pol
[2014/05/13 14:20:26 | 000,235,800 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgldx64.sys
[2014/05/13 14:20:06 | 000,273,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgtdia.sys
[2014/05/13 14:06:06 | 000,323,352 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgloga.sys
[2014/05/13 14:05:40 | 000,191,768 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsha.sys
[2014/05/13 14:05:08 | 000,152,344 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgdiska.sys
[2014/05/13 14:05:06 | 000,130,328 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgmfx64.sys
[2014/05/13 14:04:56 | 000,236,312 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys
[2014/05/13 14:04:30 | 000,031,512 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgrkx64.sys
 
========== Files Created - No Company Name ==========
 
[2014/06/09 07:21:02 | 000,000,969 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2014.lnk
[2014/06/07 09:43:27 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2014/06/07 09:43:27 | 000,184,320 | R--- | C] () -- C:\Windows\MBR.exe
[2014/06/07 09:43:27 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2014/06/07 09:43:27 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2014/06/07 09:43:27 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2014/06/02 13:22:44 | 000,349,912 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/06/02 07:04:47 | 000,457,116 | ---- | C] () -- C:\Users\The Myers\Documents\img006.jpg
[2014/06/02 07:02:19 | 000,455,758 | ---- | C] () -- C:\Users\The Myers\Documents\img005.jpg
[2014/05/30 08:18:55 | 000,068,782 | ---- | C] () -- C:\Users\The Myers\AppData\Local\erwbobfb
[2014/05/30 08:14:52 | 000,000,000 | ---- | C] () -- C:\Users\The Myers\AppData\Roaming\SharedSettings.ccs
[2014/02/25 04:02:42 | 000,774,632 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013/12/30 21:40:01 | 000,000,030 | ---- | C] () -- C:\Users\The Myers\AppData\Roaming\WB.CFG
[2013/08/09 08:10:36 | 000,000,000 | ---- | C] () -- C:\Users\The Myers\acrobat.exe
[2013/06/25 18:37:34 | 000,000,258 | RHS- | C] () -- C:\Users\The Myers\ntuser.pol
[2013/05/27 09:26:48 | 000,003,737 | ---- | C] () -- C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
[2013/04/07 17:43:28 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat
[2012/11/19 03:33:32 | 000,065,656 | ---- | C] () -- C:\Windows\SysWow64\bdmpegv.dll
[2012/11/19 03:33:30 | 000,022,640 | ---- | C] () -- C:\Windows\SysWow64\bdmjpeg.dll
[2012/02/05 16:50:26 | 000,000,779 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
 
========== ZeroAccess Check ==========
 
[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/03/24 22:43:12 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/03/24 22:09:54 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 21:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 08:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 21:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2013/04/07 17:43:18 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\0F0C1V0V1L1C2Z2Y1T1I0F1T1H1L1I1L1P1B
[2013/09/20 09:09:54 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\AVG2014
[2013/03/16 15:59:55 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\BANDISOFT
[2011/08/14 13:04:36 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1
[2011/08/18 09:05:19 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\EPSON
[2013/10/07 21:06:25 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\IrfanView
[2011/08/13 17:22:48 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\OEM
[2011/08/14 12:00:20 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\Opera
[2012/10/14 08:19:02 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\TuneUp Software
[2012/10/28 14:45:15 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\Unity
[2011/08/14 13:30:14 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\WildTangent
 
========== Purity Check ==========
 
 
 
< End of report >
 
Thanks again for your help.
 
geofri

  • 0

#7
tom982

tom982

    Member 1K

  • Member
  • PipPipPipPip
  • 1,183 posts
Hi geofri,

The ComboFix log for the scan I ran before we spoke is also posted below. A very strange occurrence in Windows Explorer when trying to access this log. The C: drive replicated itself in explorer every time I clicked on the Combofix folder. I know I was only looking for the .txt file but I did not expect to see a folder for Combofix there at all. I had run the program more than once after running Malwarebytes so I am not sure how valid the log is.


Yeah this is a clever little trick Combofix uses with a specially crafted desktop.ini file inside that folder, which stops people accessing it; it's nothing to worry about. We'll be removing ComboFix when this is all finished anyway :)

Are you still having any problems with ads showing? Our work isn't done yet but your logs look a lot better now!

Tom
  • 0

#8
geofri

geofri

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts

Tom-

Glad the logs look better but the computer is still ailing. Still getting the popups and extremely slow....  and the AVG memory usage message.  Hope to hear from you soon. Thanks for all you do.

 

Geofri


  • 0

#9
tom982

tom982

    Member 1K

  • Member
  • PipPipPipPip
  • 1,183 posts
Hi geofri,

There's one file I can't identify so I'd like you to upload it to VirusTotal so we can see if it's malicious or not:

Virus Total

I'm unsure on these file(s) so let's double check them with Virus Total:
  • Go to VirusTotal
  • Click Browse
  • Navigate to the following file, select it, then press OK
    • C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\[email protected]
  • Then click the send.png button
  • If you receive a message saying the File has already been analyzed, click Reanalyze file now.
  • Once it has finished scanning, copy and paste the results into your next post
Are you seeing popups in every browser?

Tom
  • 0

#10
geofri

geofri

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts

Good morning Tom

Using Google chrome I get no popups through Chrome itself...it is IE that pops up even when I did not initiate the program. AVG giving the excessive usage message (over 2gb) as I write this. Here are the results from VirusTotal for the file in question.

 

Antivirus Result Update Ad-Aware Trojan.JS.Agent.JES 20140615 BitDefender Trojan.JS.Agent.JES 20140615 CAT-QuickHeal JS/Tracur.H 20140615 Comodo UnclassifiedMalware 20140615 ESET-NOD32 Win32/TrojanDownloader.Tracur.V 20140615 Emsisoft Trojan.JS.Agent.JES (B) 20140615 F-Secure Trojan.JS.Agent.JES 20140615 GData Trojan.JS.Agent.JES 20140615 Ikarus Trojan.JS.Agent 20140615 MicroWorld-eScan Trojan.JS.Agent.JES 20140615 Microsoft Trojan:JS/Tracur.H 20140615 Qihoo-360 Win32/Trojan.Downloader.814 20140615 Symantec Trojan.Malscript 20140615 TrendMicro JS_TRACUR.IOK 20140615 TrendMicro-HouseCall JS_TRACUR.IOK 20140615 nProtect Trojan.JS.Agent.JES 20140615 AVG   20140615 AegisLab   20140615 Agnitum   20140614 AhnLab-V3   20140615 AntiVir   20140615 Antiy-AVL   20140611 Avast   20140615 Baidu-International   20140615 Bkav   20140614 ByteHero   20140615 CMC   20140615 ClamAV   20140615 Commtouch   20140615 DrWeb   20140615 F-Prot   20140615 Fortinet   20140615 Jiangmin   20140615 K7AntiVirus   20140613 K7GW   20140613 Kaspersky   20140615 Kingsoft   20140615 Malwarebytes   20140615 McAfee   20140615 McAfee-GW-Edition   20140614 NANO-Antivirus   20140615 Norman   20140615 Panda   20140615 Rising   20140615 SUPERAntiSpyware   20140614 Sophos   20140615 Tencent   20140615 TheHacker   20140612 TotalDefense   20140615 VBA32   20140613 VIPRE   20140615 ViRobot   20140615 Zillya   20140614 Zoner   20140613

 

Thanks again.

 

geofri


  • 0

Advertisements


#11
geofri

geofri

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts

PS Sorry about the formatting of that last post- thats not how it appeared before I hit post! Hope you can read it.

 

geofri


  • 0

#12
tom982

tom982

    Member 1K

  • Member
  • PipPipPipPip
  • 1,183 posts
Hi geofri,

It's no problem, I can see it's definitely malicious. Let's remove it:

OTL Fix
  • Run OTL.
  • Copy (Ctrl+C) and Paste (Ctrl+V) all of the following text into the Custom Scans/Fixes box:


    :Files
    C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\[email protected]
    dir "C:\Users\The Myers\AppData\Roaming\0F0C1V0V1L1C2Z2Y1T1I0F1T1H1L1I1L1P1B" /s /a /c
    
  • Click the Run Fix button.
  • After your computer has rebooted, run OTL and click Quick Scan.
  • Copy and paste the contents of the log that it produces into your next post.
Scan with JRT:

Please download Junkware Removal Tool to your desktop.

Alternate download is here.

Note: Temp' disable/shut down your protection software now to avoid potential conflicts, how to do so can be read here.
  • Right-click on on JRT.exe and select Run as Administrator to launch the application >> follow the on-screen prompt.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
Note: Reboot your machine and ensure all disabled security software is now enabled etc.

OTL
  • Run OTL by double-clicking on it.
  • Click Quick Scan to start OTL.
  • When OTL finishes scanning, a logs, OTL.txt will open.
  • Copy (Ctrl+C) and Paste (Ctrl+V) the contents of this log into your next post please.
Tom
  • 0

#13
geofri

geofri

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts

Tom

Been a busy week. Will get on it tonight!

geofri


  • 0

#14
tom982

tom982

    Member 1K

  • Member
  • PipPipPipPip
  • 1,183 posts

No problem! Thanks for letting me know.


  • 0

#15
geofri

geofri

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts

Tom

Tried my best to complete the tasks listed above. Ran OTL with the fix given with no problem and will post that log. JRT was a different matter. It begins fine and creates a restore point and never returns. No log available. I was patient like you said but I think something is stopping its completion. Still getting the IE popups and a\two new symptoms...Windows Media Player popping up and playing its own library of videos. After a while Windows states it has encountered an error and will search for a solution to the problem.Ugh.

Thanks again for all you do.

geofri

 

========== FILES ==========
C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions\[email protected] moved successfully.
< dir "C:\Users\The Myers\AppData\Roaming\0F0C1V0V1L1C2Z2Y1T1I0F1T1H1L1I1L1P1B" /s /a /c >
 Volume in drive C is Acer
 Volume Serial Number is D211-D633
 Directory of C:\Users\The Myers\AppData\Roaming\0F0C1V0V1L1C2Z2Y1T1I0F1T1H1L1I1L1P1B
04/07/2013  05:43 PM    <DIR>          .
04/07/2013  05:43 PM    <DIR>          ..
06/09/2014  09:44 AM    <DIR>          Virtual Families Packages
               0 File(s)              0 bytes
 Directory of C:\Users\The Myers\AppData\Roaming\0F0C1V0V1L1C2Z2Y1T1I0F1T1H1L1I1L1P1B\Virtual Families Packages
06/09/2014  09:44 AM    <DIR>          .
06/09/2014  09:44 AM    <DIR>          ..
               0 File(s)              0 bytes
     Total Files Listed:
               0 File(s)              0 bytes
               5 Dir(s)  916,578,787,328 bytes free
C:\Users\The Myers\Desktop\cmd.bat deleted successfully.
C:\Users\The Myers\Desktop\cmd.txt deleted successfully.
 
OTL by OldTimer - Version 3.2.69.0 log created on 06222014_091820
 

OTL logfile created on: 6/27/2014 6:23:41 AM - Run 3
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\The Myers\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17126)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
3.97 Gb Total Physical Memory | 2.52 Gb Available Physical Memory | 63.55% Memory free
7.93 Gb Paging File | 6.16 Gb Available in Paging File | 77.70% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 911.88 Gb Total Space | 855.46 Gb Free Space | 93.81% Space Free | Partition Type: NTFS
 
Computer Name: THEMYERS-PC | User Name: The Myers | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/06/09 16:09:08 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\The Myers\Desktop\OTL.com
PRC - [2014/06/05 09:58:39 | 000,860,488 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014/05/14 15:07:08 | 000,067,584 | ---- | M] (PasswordBox, Inc.) -- C:\Program Files (x86)\PasswordBox\pbbtnService.exe
PRC - [2014/05/13 14:23:04 | 003,644,432 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
PRC - [2014/05/13 14:18:32 | 005,181,456 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgui.exe
PRC - [2014/05/13 14:15:28 | 000,292,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
PRC - [2014/01/10 16:06:48 | 001,435,680 | R--- | M] (Fitbit, Inc.) -- C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe
PRC - [2013/12/21 02:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/04/23 03:48:17 | 003,574,624 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
PRC - [2012/07/03 10:04:58 | 000,507,312 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
PRC - [2010/08/04 08:40:12 | 000,611,872 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
PRC - [2010/06/29 22:26:30 | 000,124,136 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe
PRC - [2010/01/28 19:27:36 | 000,243,232 | ---- | M] (Acer Group) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe
PRC - [2010/01/08 09:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
PRC - [2009/06/04 22:03:32 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009/06/04 22:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/06/05 09:58:38 | 000,414,536 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\ppgooglenaclpluginchrome.dll
MOD - [2014/06/05 09:58:36 | 004,217,672 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\pdf.dll
MOD - [2014/06/05 09:58:32 | 000,716,616 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\libglesv2.dll
MOD - [2014/06/05 09:58:31 | 000,126,280 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\libegl.dll
MOD - [2014/06/05 09:58:30 | 001,732,424 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\ffmpegsumo.dll
MOD - [2010/08/04 08:40:12 | 000,611,872 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
MOD - [2010/08/04 05:47:32 | 000,144,896 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyHook.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2014/05/30 05:21:05 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013/05/27 01:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2010/09/22 21:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/01/28 19:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto | Running] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV - [2014/06/23 09:45:23 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/05/14 15:07:08 | 000,067,584 | ---- | M] (PasswordBox, Inc.) [Auto | Running] -- C:\Program Files (x86)\PasswordBox\pbbtnService.exe -- (PasswordBox)
SRV - [2014/05/14 00:57:21 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/05/13 14:23:04 | 003,644,432 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2014/05/13 14:15:28 | 000,292,424 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe -- (avgwd)
SRV - [2014/02/13 19:58:00 | 000,176,624 | ---- | M] (Coupons.com Inc.) [Auto | Running] -- C:\Program Files (x86)\Coupons\CouponPrinterService.exe -- (CouponPrinterService)
SRV - [2014/01/10 16:06:48 | 001,435,680 | R--- | M] (Fitbit, Inc.) [Auto | Running] -- C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe -- (Fitbit Connect)
SRV - [2013/12/21 02:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/09/11 22:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/04/23 03:48:17 | 003,574,624 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)
SRV - [2010/04/03 19:01:24 | 000,246,520 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2010/01/15 17:08:38 | 000,935,208 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2010/01/08 09:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe -- (GREGService)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/04 22:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014/05/13 14:20:26 | 000,235,800 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2014/05/13 14:20:06 | 000,273,176 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:64bit: - [2014/05/13 14:06:06 | 000,323,352 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgloga.sys -- (Avgloga)
DRV:64bit: - [2014/05/13 14:05:40 | 000,191,768 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA)
DRV:64bit: - [2014/05/13 14:05:08 | 000,152,344 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgdiska.sys -- (Avgdiska)
DRV:64bit: - [2014/05/13 14:05:06 | 000,130,328 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:64bit: - [2014/05/13 14:04:56 | 000,236,312 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
DRV:64bit: - [2014/05/13 14:04:30 | 000,031,512 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:64bit: - [2014/05/08 18:28:21 | 000,050,464 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/02/14 03:42:36 | 000,028,160 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgx64diag.sys -- (UsbDiag)
DRV:64bit: - [2011/02/14 03:42:30 | 000,034,816 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgx64modem.sys -- (USBModem)
DRV:64bit: - [2011/02/14 03:42:28 | 000,017,920 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgx64bus.sys -- (usbbus)
DRV:64bit: - [2011/02/11 19:16:38 | 010,628,640 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/08/10 23:40:06 | 001,014,624 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)
DRV:64bit: - [2009/12/09 05:39:52 | 000,537,624 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 16:35:02 | 000,281,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1y60x64.sys -- (e1yexpress)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/25 16:13:10 | 000,138,752 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcHdmi.sys -- (IntcHdmiAddService)
DRV:64bit: - [2009/03/18 16:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = 
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = 
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://mysearch.avg....8:05:55&sap=hp"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:30.0
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\The Myers\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\PasswordBox\Firefox [2013/11/21 20:22:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 30.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014/06/23 09:45:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 30.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2014/06/23 09:45:04 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 30.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014/06/23 09:45:00 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 30.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2014/06/23 09:45:04 | 000,000,000 | ---D | M]
 
[2011/08/14 11:53:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\The Myers\AppData\Roaming\Mozilla\Extensions
[2014/06/22 09:18:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\The Myers\AppData\Roaming\Mozilla\Firefox\Profiles\s0415uw4.default-1353594358513\extensions
[2014/06/23 09:44:58 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/06/23 09:45:26 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011/04/14 14:01:38 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - plugin: Error reading preferences file
CHR - Extension: Google Docs = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.6_0\
CHR - Extension: Google Drive = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Google Voice Search Hotword (Beta) = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5019_1\
CHR - Extension: YouTube = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Google Wallet = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Users\The Myers\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
 
O1 HOSTS File: ([2014/06/09 06:38:55 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (PasswordBox Helper) - {5DB69B97-934B-451D-94DB-32EF802A01CD} - C:\Program Files (x86)\PasswordBox\Application\pbbtn.dll (PasswordBox, Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [ArcadeMovieService] C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe ()
O4 - HKLM..\Run: [MDS_Menu] C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKCU..\RunOnce: [Application Restart #0] C:\Program Files (x86)\Windows Media Player\setup_wm.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455}  (ExentInf Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BC9B8ECA-8D3A-463C-A441-D44690C56727}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D486644F-BB99-42A1-B100-CA2FD71C5866}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/06/23 09:44:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2014/06/22 09:27:35 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2014/06/22 09:25:23 | 001,016,261 | ---- | C] (Thisisu) -- C:\Users\The Myers\Desktop\JRT.exe
[2014/06/22 09:19:32 | 000,000,000 | ---D | C] -- C:\Users\The Myers\Desktop\Scans
[2014/06/10 18:23:30 | 000,536,576 | ---- | C] (SQLite Development Team) -- C:\Windows\SysWow64\sqlite3.dll
[2014/06/10 18:22:24 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/06/10 16:33:22 | 000,000,000 | ---D | C] -- C:\_OTL
[2014/06/10 07:29:53 | 000,000,000 | -HSD | C] -- C:\found.000
[2014/06/10 07:22:35 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2014/06/09 17:48:29 | 000,000,000 | --SD | C] -- C:\ComboFix
[2014/06/09 16:20:18 | 005,205,664 | R--- | C] (Swearware) -- C:\Users\The Myers\Desktop\ComboFix.exe
[2014/06/09 16:20:00 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\The Myers\Desktop\OTL.com
[2014/06/09 07:21:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2014/06/07 09:43:27 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2014/06/07 09:43:27 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2014/06/07 09:43:27 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2014/06/07 09:43:20 | 000,000,000 | ---D | C] -- C:\Qoobox
[2014/06/07 09:42:32 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2014/06/03 07:37:32 | 000,000,000 | ---D | C] -- C:\Users\The Myers\AppData\Local\ElevatedDiagnostics
 
========== Files - Modified Within 30 Days ==========
 
[2014/06/27 05:57:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/06/27 05:31:00 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/06/26 12:31:00 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/06/25 09:37:55 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/06/25 09:37:55 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/06/25 09:30:21 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/06/25 09:30:12 | 384,224,754 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2014/06/25 09:30:12 | 3193,835,520 | -HS- | M] () -- C:\hiberfil.sys
[2014/06/22 09:25:27 | 001,016,261 | ---- | M] (Thisisu) -- C:\Users\The Myers\Desktop\JRT.exe
[2014/06/12 18:27:17 | 000,002,187 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/06/09 17:49:18 | 000,184,320 | R--- | M] () -- C:\Windows\MBR.exe
[2014/06/09 16:09:08 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\The Myers\Desktop\OTL.com
[2014/06/09 07:21:02 | 000,000,969 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2014.lnk
[2014/06/09 06:38:55 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2014/06/09 06:18:26 | 005,205,664 | R--- | M] (Swearware) -- C:\Users\The Myers\Desktop\ComboFix.exe
[2014/06/07 09:43:40 | 000,782,510 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/06/07 09:43:40 | 000,662,400 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/06/07 09:43:40 | 000,122,268 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/06/02 13:22:59 | 000,349,912 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/06/02 07:04:47 | 000,457,116 | ---- | M] () -- C:\Users\The Myers\Documents\img006.jpg
[2014/06/02 07:02:20 | 000,455,758 | ---- | M] () -- C:\Users\The Myers\Documents\img005.jpg
[2014/05/30 08:18:55 | 000,068,782 | ---- | M] () -- C:\Users\The Myers\AppData\Local\erwbobfb
[2014/05/30 08:14:52 | 000,000,000 | ---- | M] () -- C:\Users\The Myers\AppData\Roaming\SharedSettings.ccs
 
========== Files Created - No Company Name ==========
 
[2014/06/24 13:10:37 | 384,224,754 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2014/06/09 07:21:02 | 000,000,969 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2014.lnk
[2014/06/07 09:43:27 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2014/06/07 09:43:27 | 000,184,320 | R--- | C] () -- C:\Windows\MBR.exe
[2014/06/07 09:43:27 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2014/06/07 09:43:27 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2014/06/07 09:43:27 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2014/06/02 13:22:44 | 000,349,912 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/06/02 07:04:47 | 000,457,116 | ---- | C] () -- C:\Users\The Myers\Documents\img006.jpg
[2014/06/02 07:02:19 | 000,455,758 | ---- | C] () -- C:\Users\The Myers\Documents\img005.jpg
[2014/05/30 08:18:55 | 000,068,782 | ---- | C] () -- C:\Users\The Myers\AppData\Local\erwbobfb
[2014/05/30 08:14:52 | 000,000,000 | ---- | C] () -- C:\Users\The Myers\AppData\Roaming\SharedSettings.ccs
[2014/02/25 04:02:42 | 000,774,632 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013/12/30 21:40:01 | 000,000,030 | ---- | C] () -- C:\Users\The Myers\AppData\Roaming\WB.CFG
[2013/08/09 08:10:36 | 000,000,000 | ---- | C] () -- C:\Users\The Myers\acrobat.exe
[2013/06/25 18:37:34 | 000,000,258 | RHS- | C] () -- C:\Users\The Myers\ntuser.pol
[2013/05/27 09:26:48 | 000,003,737 | ---- | C] () -- C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
[2013/04/07 17:43:28 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat
[2012/11/19 03:33:32 | 000,065,656 | ---- | C] () -- C:\Windows\SysWow64\bdmpegv.dll
[2012/11/19 03:33:30 | 000,022,640 | ---- | C] () -- C:\Windows\SysWow64\bdmjpeg.dll
[2012/02/05 16:50:26 | 000,000,779 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
 
========== ZeroAccess Check ==========
 
[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/03/24 22:43:12 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/03/24 22:09:54 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 21:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 08:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 21:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2013/04/07 17:43:18 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\0F0C1V0V1L1C2Z2Y1T1I0F1T1H1L1I1L1P1B
[2013/09/20 09:09:54 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\AVG2014
[2013/03/16 15:59:55 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\BANDISOFT
[2011/08/14 13:04:36 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1
[2011/08/18 09:05:19 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\EPSON
[2013/10/07 21:06:25 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\IrfanView
[2011/08/13 17:22:48 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\OEM
[2011/08/14 12:00:20 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\Opera
[2012/10/14 08:19:02 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\TuneUp Software
[2012/10/28 14:45:15 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\Unity
[2011/08/14 13:30:14 | 000,000,000 | ---D | M] -- C:\Users\The Myers\AppData\Roaming\WildTangent
 
========== Purity Check ==========
 
 
 
< End of report >
 

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP