I've been having issues with my computer it has been super slow for the past few days, My computer freezes while shutting down and My chrome Browser freezes as well.
My Windows Security Center Service and firewall cannot be started. I tried Running Malware bytes and Avira but no luck.
Thank you!
OTL logfile created on: 8/22/2013 1:08:35 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\UBALDO\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.50 Gb Total Physical Memory | 2.10 Gb Available Physical Memory | 60.00% Memory free
6.99 Gb Paging File | 5.00 Gb Available in Paging File | 71.47% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 911.88 Gb Total Space | 845.99 Gb Free Space | 92.77% Space Free | Partition Type: NTFS
Drive D: | 43.95 Gb Total Space | 16.62 Gb Free Space | 37.81% Space Free | Partition Type: NTFS
Drive E: | 68.36 Gb Total Space | 0.02 Gb Free Space | 0.03% Space Free | Partition Type: NTFS
Drive G: | 36.74 Gb Total Space | 23.69 Gb Free Space | 64.48% Space Free | Partition Type: NTFS
Computer Name: UBALDO-PC | User Name: UBALDO | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/08/22 13:08:26 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\UBALDO\Desktop\OTL.exe
PRC - [2012/11/01 03:31:42 | 000,369,152 | ---- | M] (Alcatel-Lucent) -- C:\Program Files (x86)\Common Files\Motive\pcCMService.exe
PRC - [2012/08/08 14:24:13 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012/06/20 13:18:08 | 001,568,976 | ---- | M] (Ask) -- C:\Program Files (x86)\Ask.com\Updater\Updater.exe
PRC - [2012/05/08 18:47:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2012/05/08 18:47:27 | 000,465,360 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
PRC - [2012/05/08 18:47:27 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/10/12 03:22:02 | 000,218,408 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
PRC - [2011/10/12 03:22:01 | 000,321,832 | ---- | M] () -- C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe
PRC - [2011/10/01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011/10/01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2011/08/31 03:35:01 | 000,185,640 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe
PRC - [2011/08/10 20:58:26 | 000,627,304 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
PRC - [2011/05/29 19:54:14 | 000,036,456 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
PRC - [2011/04/22 09:44:14 | 000,244,624 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe
PRC - [2011/04/02 14:34:42 | 000,340,848 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe
PRC - [2011/03/28 19:48:54 | 000,202,608 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
PRC - [2010/05/04 12:07:22 | 000,503,080 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2010/03/10 14:26:48 | 000,189,728 | ---- | M] (Protexis Inc.) -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2010/03/06 04:04:24 | 000,310,224 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
PRC - [2007/06/05 14:20:32 | 000,177,704 | ---- | M] () -- C:\Windows\SysWOW64\PSIService.exe
========== Modules (No Company Name) ==========
MOD - [2011/10/12 03:22:01 | 000,321,832 | ---- | M] () -- C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe
MOD - [2011/10/12 03:22:00 | 000,370,984 | ---- | M] () -- C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\CLNetMediaDMA.dll
MOD - [2011/08/10 20:58:26 | 000,627,304 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
MOD - [2011/08/10 20:57:22 | 000,151,656 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyHook.dll
========== Services (SafeList) ==========
SRV:64bit: - [2012/11/01 04:45:20 | 000,460,288 | ---- | M] (Alcatel-Lucent) [Auto | Running] -- C:\Program Files\Common Files\Motive\pcCMService.exe -- (pcCMService64)
SRV:64bit: - [2011/05/24 08:03:40 | 000,204,288 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011/04/22 09:44:14 | 000,244,624 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Live Updater Service)
SRV:64bit: - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2013/08/20 11:49:30 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/04/04 13:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013/04/04 13:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2013/03/26 10:12:56 | 000,319,488 | ---- | M] (Alcatel-Lucent) [Auto | Stopped] -- C:\Program Files (x86)\ATT\8.2.1.6\ma\bin\MAHostService.exe -- (ATT MAHostService)
SRV - [2012/11/01 03:31:42 | 000,369,152 | ---- | M] (Alcatel-Lucent) [Auto | Running] -- C:\Program Files (x86)\Common Files\Motive\pcCMService.exe -- (pcCMService)
SRV - [2012/05/13 13:30:40 | 000,018,432 | ---- | M] (Apache Software Foundation) [On_Demand | Stopped] -- c:\wamp\bin\apache\apache2.2.22\bin\httpd.exe -- (wampapache)
SRV - [2012/05/08 18:47:28 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012/05/08 18:47:27 | 000,465,360 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe -- (AntiVirWebService)
SRV - [2012/05/08 18:47:27 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2012/04/19 16:02:32 | 008,177,664 | ---- | M] () [On_Demand | Stopped] -- c:\wamp\bin\mysql\mysql5.5.24\bin\mysqld.exe -- (wampmysqld)
SRV - [2011/10/01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011/10/01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2011/05/29 19:54:14 | 000,036,456 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe -- (GREGService)
SRV - [2011/04/02 14:09:38 | 000,173,424 | ---- | M] (Egis Technology Inc. ) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe -- (EgisTec Ticket Service)
SRV - [2010/10/12 10:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010/05/04 12:07:22 | 000,503,080 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/10 14:26:48 | 000,189,728 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2009/06/10 14:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2007/06/05 14:20:32 | 000,177,704 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PSIService.exe -- (ProtexisLicensing)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2013/04/04 13:50:32 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2013/02/11 21:12:06 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2013/02/06 07:42:10 | 000,203,544 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:64bit: - [2013/02/06 07:42:08 | 000,102,936 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2012/09/28 09:32:56 | 000,053,760 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012/05/08 18:47:29 | 000,132,832 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2012/05/08 18:47:29 | 000,098,848 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2012/02/29 23:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/10/01 09:30:22 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2011/10/01 09:30:18 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2011/10/01 09:30:18 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2011/10/01 09:30:10 | 000,764,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2011/09/16 00:55:03 | 000,027,760 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avkmgr.sys -- (avkmgr)
DRV:64bit: - [2011/08/02 20:35:49 | 000,062,776 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV:64bit: - [2011/08/02 20:35:49 | 000,022,648 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV:64bit: - [2011/08/02 20:35:49 | 000,020,520 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV:64bit: - [2011/06/06 03:07:00 | 000,231,440 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2011/05/24 09:26:58 | 009,359,872 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011/05/24 07:25:44 | 000,309,760 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2011/05/16 07:55:28 | 000,533,096 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/05/13 03:21:02 | 000,157,672 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadbus.sys -- (ssadbus)
DRV:64bit: - [2011/03/10 23:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/10 23:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 20:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 20:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 20:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/11/11 02:16:00 | 000,037,504 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV:64bit: - [2010/11/11 02:15:58 | 000,077,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV:64bit: - [2010/06/16 14:15:36 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie64.sys -- (AtiPcie)
DRV:64bit: - [2010/02/03 22:17:54 | 000,122,624 | R--- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\smhwser.sys -- (smhwser)
DRV:64bit: - [2010/02/02 13:05:26 | 000,043,008 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MREMP50a64.sys -- (MREMP50a64)
DRV:64bit: - [2010/02/02 13:05:26 | 000,040,960 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MRESP50a64.sys -- (MRESP50a64)
DRV:64bit: - [2010/01/13 00:04:54 | 000,114,432 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\smhwdev.sys -- (smhwdev)
DRV:64bit: - [2009/12/23 09:00:39 | 000,031,744 | R--- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\smhwadb.sys -- (androidusb)
DRV:64bit: - [2009/07/13 18:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 18:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 18:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 17:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2009/06/10 13:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 13:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 13:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 13:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2010/02/02 13:09:42 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Motive\MREMP50.sys -- (MREMP50)
DRV - [2010/02/02 13:09:42 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Motive\MRESP50.sys -- (MRESP50)
DRV - [2009/07/13 18:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://google.com/http://etsy.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo....intl=us&.src=ym
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files (x86)\ATT\8.2.1.6\ma\bin\npMotive.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@Motive.com/npMotiveRequest,version=1.0: C:\Program Files (x86)\Common Files\Motive\npMotiveRequest.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
O1 HOSTS File: ([2009/06/10 14:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [ArcadeMovieService] C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000015 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://javadl-esd.su...indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.4.1)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0BB814A6-638F-4A36-86BC-45D0E5717B6B}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E3D65A4D-AB1B-421C-9C5F-DB0AE9741439}: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{1fb66e9a-1808-11e1-85cf-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{1fb66e9a-1808-11e1-85cf-806e6f6e6963}\Shell\AutoRun\command - "" = "D:\Windows Utilities\Installer64\Install.exe"
O33 - MountPoints2\{2a70f8b6-fd8c-11e1-a2ba-c89cdc6f8efe}\Shell - "" = AutoRun
O33 - MountPoints2\{2a70f8b6-fd8c-11e1-a2ba-c89cdc6f8efe}\Shell\AutoRun\command - "" = H:\PcOptions.exe
O33 - MountPoints2\{2a70f8c5-fd8c-11e1-a2ba-c89cdc6f8efe}\Shell - "" = AutoRun
O33 - MountPoints2\{2a70f8c5-fd8c-11e1-a2ba-c89cdc6f8efe}\Shell\AutoRun\command - "" = H:\PcOptions.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/08/22 13:08:01 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\UBALDO\Desktop\OTL.exe
[2013/08/21 09:11:14 | 000,000,000 | ---D | C] -- C:\Users\UBALDO\Desktop\PLANES NAME
[2013/08/15 03:16:27 | 000,526,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013/08/15 03:16:27 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013/08/15 03:16:25 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2013/08/15 03:16:25 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2013/08/15 03:16:25 | 000,089,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/08/15 03:16:25 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/08/15 03:16:25 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2013/08/15 03:16:25 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2013/08/15 03:16:25 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2013/08/15 03:16:25 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2013/08/15 03:16:25 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2013/08/15 03:16:22 | 000,603,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013/08/15 03:16:21 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013/08/15 03:16:21 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013/08/15 03:16:20 | 003,958,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013/08/14 05:30:35 | 001,472,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2013/08/14 05:30:34 | 000,224,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll
[2013/08/14 05:30:32 | 000,139,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
[2013/08/14 05:30:15 | 001,888,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
[2013/08/14 05:30:14 | 001,620,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL
[2013/08/14 05:30:14 | 001,217,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpcrt4.dll
[2013/08/14 05:30:13 | 003,913,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2013/08/14 05:30:12 | 003,968,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2013/08/14 05:30:11 | 005,550,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2013/08/14 05:30:11 | 001,732,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2013/08/14 05:30:11 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2013/08/14 05:30:10 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2013/08/14 05:30:10 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2013/08/14 05:30:10 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2013/08/14 05:30:10 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2013/08/14 05:30:10 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2011/02/02 14:02:22 | 052,743,152 | -HS- | C] (Alien Skin Software, LLC) -- C:\Users\UBALDO\AppData\Roaming\setup.exe
[3 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/08/22 13:08:26 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\UBALDO\Desktop\OTL.exe
[2013/08/22 12:48:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/08/22 09:18:45 | 000,869,418 | ---- | M] () -- C:\Users\UBALDO\Desktop\CHUCKECHEESETOPPERS.jpg
[2013/08/22 08:31:42 | 000,065,306 | ---- | M] () -- C:\Users\UBALDO\Desktop\chuck_e_cheese_birthday_invitations_all_colors_click_for_additional_6cfd60e8.jpg
[2013/08/22 08:29:58 | 000,203,108 | ---- | M] () -- C:\Users\UBALDO\Desktop\il_fullxfull_337483218.jpg
[2013/08/22 07:35:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/08/21 19:31:55 | 000,039,287 | ---- | M] () -- C:\Users\UBALDO\Desktop\il_570xN_489944018_4jhw.jpg
[2013/08/21 15:59:22 | 000,501,097 | ---- | M] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEWATERWRAPPERS1-3.jpg
[2013/08/21 15:46:45 | 000,184,913 | ---- | M] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEWATERWRAPPERDESIGN04.jpg
[2013/08/21 15:46:34 | 000,173,316 | ---- | M] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEWATERWRAPPERDESIGN05.jpg
[2013/08/21 15:05:04 | 000,834,661 | ---- | M] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEWATERWRAPPERDESIGN03.jpg
[2013/08/21 11:47:12 | 000,425,488 | ---- | M] () -- C:\Users\UBALDO\Desktop\tumblr_ml7virBdrD1qexvcfo5_1280.jpg
[2013/08/21 11:46:03 | 000,393,549 | ---- | M] () -- C:\Users\UBALDO\Desktop\tumblr_ml7virBdrD1qexvcfo3_1280.jpg
[2013/08/21 11:46:00 | 000,327,489 | ---- | M] () -- C:\Users\UBALDO\Desktop\tumblr_ml7virBdrD1qexvcfo4_1280.jpg
[2013/08/21 11:45:25 | 000,474,943 | ---- | M] () -- C:\Users\UBALDO\Desktop\tumblr_ml7virBdrD1qexvcfo2_1280.jpg
[2013/08/21 11:15:44 | 000,016,985 | ---- | M] () -- C:\Users\UBALDO\Desktop\il_340x270_459269489_a8gx.jpg
[2013/08/21 08:55:16 | 000,002,828 | -HS- | M] () -- C:\Windows\SysWow64\KGyGaAvL.sys
[2013/08/21 07:47:23 | 000,016,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/21 07:47:23 | 000,016,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/21 07:37:53 | 2814,849,024 | -HS- | M] () -- C:\hiberfil.sys
[2013/08/20 22:13:34 | 000,478,030 | ---- | M] () -- C:\Users\UBALDO\Desktop\DESPICABLEHERSHEYWRAPPERS04-06.jpg
[2013/08/20 22:07:42 | 000,420,151 | ---- | M] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEHERSHEYWRAPPERDESIGN03.jpg
[2013/08/20 22:07:29 | 000,412,518 | ---- | M] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEHERSHEYWRAPPERDESIGN04.jpg
[2013/08/20 15:27:32 | 000,642,733 | ---- | M] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEDESING01-02.jpg
[2013/08/20 15:25:34 | 000,285,846 | ---- | M] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEDESIGN03.jpg
[2013/08/20 15:24:08 | 006,681,315 | ---- | M] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEDESIGN03.pspimage
[2013/08/20 15:14:53 | 001,059,028 | ---- | M] () -- C:\Users\UBALDO\Desktop\DESPICABLEME2LOGO2.pspimage
[2013/08/20 15:14:11 | 001,063,691 | ---- | M] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEHERSHEYWRAPPERDESIGN05.jpg
[2013/08/20 12:11:11 | 001,282,959 | ---- | M] () -- C:\Users\UBALDO\Desktop\minions-file.jpg
[2013/08/20 12:07:19 | 001,955,905 | ---- | M] () -- C:\Users\UBALDO\Desktop\Despicable-Me-2-Movie.jpg
[2013/08/20 11:49:29 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/08/20 11:49:29 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/08/20 11:36:09 | 005,368,235 | ---- | M] () -- C:\Users\UBALDO\Desktop\Despicable Me 2 (2013).jpg
[2013/08/20 10:45:58 | 000,155,447 | ---- | M] () -- C:\Users\UBALDO\Desktop\americangirls.jpg
[2013/08/19 15:25:48 | 001,054,483 | ---- | M] () -- C:\Users\UBALDO\Desktop\Despicable-Me-2-Minions.jpg
[2013/08/19 14:16:51 | 000,411,965 | ---- | M] () -- C:\Users\UBALDO\Desktop\despicable_me_minion_goggles_wallpaper-1600x1200.jpg
[2013/08/19 14:03:21 | 000,261,557 | ---- | M] () -- C:\Users\UBALDO\Desktop\MINIONGOGGLES003.png
[2013/08/19 13:50:55 | 000,025,773 | ---- | M] () -- C:\Users\UBALDO\Desktop\MINIONGOGGLES3.png
[2013/08/19 13:46:45 | 000,027,355 | ---- | M] () -- C:\Users\UBALDO\Desktop\MINIONGOGGLES2.png
[2013/08/19 13:05:12 | 000,032,189 | ---- | M] () -- C:\Users\UBALDO\Desktop\GOGLES.png
[2013/08/19 12:52:21 | 000,221,782 | ---- | M] () -- C:\Users\UBALDO\Desktop\MINIONGOGGLES.ai
[2013/08/19 11:35:38 | 000,383,947 | ---- | M] () -- C:\Users\UBALDO\Desktop\Jean_texture_by_Babybird_Stock.jpg
[2013/08/19 11:35:10 | 000,532,954 | ---- | M] () -- C:\Users\UBALDO\Desktop\depositphotos_1602251-Texture-Jean.jpg
[2013/08/19 11:19:02 | 000,653,262 | ---- | M] () -- C:\Users\UBALDO\Desktop\il_fullxfull_479007725_623z.jpg
[2013/08/19 11:18:23 | 000,106,511 | ---- | M] () -- C:\Users\UBALDO\Desktop\il_570xN_479320819_8pfw.jpg
[2013/08/19 10:49:32 | 000,276,268 | ---- | M] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEDESIGN04.jpg
[2013/08/19 10:47:19 | 000,319,977 | ---- | M] () -- C:\Users\UBALDO\Desktop\il_fullxfull_491908957_6wdr.jpg
[2013/08/19 10:01:26 | 004,195,563 | ---- | M] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEDESIGN04.pspimage
[2013/08/19 08:59:47 | 000,389,307 | ---- | M] () -- C:\Users\UBALDO\Desktop\LEGODESIGN01.jpg
[2013/08/19 07:22:04 | 000,152,785 | ---- | M] () -- C:\Users\UBALDO\Desktop\Lego-cake-pops-Livinglocurto.jpg
[2013/08/19 07:00:09 | 000,834,593 | ---- | M] () -- C:\Users\UBALDO\Desktop\DESPICABLEME2LOGO.pspimage
[2013/08/19 06:55:52 | 000,235,511 | ---- | M] () -- C:\Users\UBALDO\Desktop\il_fullxfull_336979509.jpg
[2013/08/18 22:01:21 | 000,085,136 | ---- | M] () -- C:\Users\UBALDO\Desktop\Despicable-Me-2-Ilumination-Evil-Minion-Wallpaper.jpg
[2013/08/18 21:52:04 | 000,887,448 | ---- | M] () -- C:\Users\UBALDO\Desktop\despicable-me-2-wallpaper.jpg
[2013/08/18 21:51:01 | 001,391,813 | ---- | M] () -- C:\Users\UBALDO\Desktop\despicable_me_2_minions-wide.jpg
[2013/08/18 21:39:54 | 000,086,539 | ---- | M] () -- C:\Users\UBALDO\Desktop\il_570xN_483415756_jwqr.jpg
[2013/08/18 21:39:39 | 000,093,695 | ---- | M] () -- C:\Users\UBALDO\Desktop\il_570xN_489102084_5dda.jpg
[2013/08/18 21:38:56 | 000,097,911 | ---- | M] () -- C:\Users\UBALDO\Desktop\il_570xN_487155558_i2n1.jpg
[2013/08/15 03:11:38 | 000,741,188 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/08/15 03:11:38 | 000,624,606 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/08/15 03:11:38 | 000,106,724 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/08/12 22:13:53 | 000,403,347 | ---- | M] () -- C:\Users\UBALDO\Desktop\il_fullxfull_482474610_kl9k.jpg
[2013/08/11 09:01:46 | 000,611,256 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013/07/31 09:43:19 | 000,454,103 | ---- | M] () -- C:\Users\UBALDO\Desktop\MONSTERINC.jpg
[2013/07/31 09:42:44 | 000,890,939 | ---- | M] () -- C:\Users\UBALDO\Desktop\PHINEASANDFERB.jpg
[2013/07/31 09:42:00 | 000,499,704 | ---- | M] () -- C:\Users\UBALDO\Desktop\JAKEANDTHENEVERLAND.jpg
[2013/07/27 10:20:46 | 000,001,456 | ---- | M] () -- C:\Users\UBALDO\AppData\Local\Adobe Save for Web 12.0 Prefs
[2013/07/25 22:13:58 | 000,051,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2013/07/25 22:12:27 | 000,603,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013/07/25 22:12:08 | 003,958,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013/07/25 22:12:08 | 000,855,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013/07/25 22:12:04 | 000,526,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013/07/25 22:12:04 | 000,136,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2013/07/25 22:12:03 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2013/07/25 22:12:03 | 000,039,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2013/07/25 20:12:04 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013/07/25 20:12:00 | 000,391,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013/07/25 20:12:00 | 000,109,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2013/07/25 20:12:00 | 000,061,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2013/07/25 20:11:59 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2013/07/25 19:39:38 | 000,089,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/07/25 18:59:38 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/07/25 02:25:54 | 001,888,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
[2013/07/25 01:57:27 | 001,620,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL
[3 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/08/22 09:18:45 | 000,869,418 | ---- | C] () -- C:\Users\UBALDO\Desktop\CHUCKECHEESETOPPERS.jpg
[2013/08/22 08:31:52 | 000,065,306 | ---- | C] () -- C:\Users\UBALDO\Desktop\chuck_e_cheese_birthday_invitations_all_colors_click_for_additional_6cfd60e8.jpg
[2013/08/22 08:30:12 | 000,203,108 | ---- | C] () -- C:\Users\UBALDO\Desktop\il_fullxfull_337483218.jpg
[2013/08/21 19:32:24 | 000,039,287 | ---- | C] () -- C:\Users\UBALDO\Desktop\il_570xN_489944018_4jhw.jpg
[2013/08/21 15:54:44 | 000,501,097 | ---- | C] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEWATERWRAPPERS1-3.jpg
[2013/08/21 15:06:36 | 000,173,316 | ---- | C] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEWATERWRAPPERDESIGN05.jpg
[2013/08/21 15:05:04 | 000,834,661 | ---- | C] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEWATERWRAPPERDESIGN03.jpg
[2013/08/21 15:04:07 | 000,184,913 | ---- | C] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEWATERWRAPPERDESIGN04.jpg
[2013/08/21 11:47:34 | 000,425,488 | ---- | C] () -- C:\Users\UBALDO\Desktop\tumblr_ml7virBdrD1qexvcfo5_1280.jpg
[2013/08/21 11:46:55 | 000,393,549 | ---- | C] () -- C:\Users\UBALDO\Desktop\tumblr_ml7virBdrD1qexvcfo3_1280.jpg
[2013/08/21 11:46:08 | 000,327,489 | ---- | C] () -- C:\Users\UBALDO\Desktop\tumblr_ml7virBdrD1qexvcfo4_1280.jpg
[2013/08/21 11:45:41 | 000,474,943 | ---- | C] () -- C:\Users\UBALDO\Desktop\tumblr_ml7virBdrD1qexvcfo2_1280.jpg
[2013/08/21 11:16:02 | 000,016,985 | ---- | C] () -- C:\Users\UBALDO\Desktop\il_340x270_459269489_a8gx.jpg
[2013/08/20 22:13:34 | 000,478,030 | ---- | C] () -- C:\Users\UBALDO\Desktop\DESPICABLEHERSHEYWRAPPERS04-06.jpg
[2013/08/20 15:16:29 | 000,420,151 | ---- | C] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEHERSHEYWRAPPERDESIGN03.jpg
[2013/08/20 15:14:11 | 001,063,691 | ---- | C] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEHERSHEYWRAPPERDESIGN05.jpg
[2013/08/20 12:19:45 | 000,412,518 | ---- | C] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEHERSHEYWRAPPERDESIGN04.jpg
[2013/08/20 12:11:22 | 001,282,959 | ---- | C] () -- C:\Users\UBALDO\Desktop\minions-file.jpg
[2013/08/20 12:07:35 | 001,955,905 | ---- | C] () -- C:\Users\UBALDO\Desktop\Despicable-Me-2-Movie.jpg
[2013/08/20 11:35:43 | 005,368,235 | ---- | C] () -- C:\Users\UBALDO\Desktop\Despicable Me 2 (2013).jpg
[2013/08/20 10:45:58 | 000,155,447 | ---- | C] () -- C:\Users\UBALDO\Desktop\americangirls.jpg
[2013/08/19 15:26:43 | 001,054,483 | ---- | C] () -- C:\Users\UBALDO\Desktop\Despicable-Me-2-Minions.jpg
[2013/08/19 14:16:50 | 000,411,965 | ---- | C] () -- C:\Users\UBALDO\Desktop\despicable_me_minion_goggles_wallpaper-1600x1200.jpg
[2013/08/19 14:03:14 | 000,261,557 | ---- | C] () -- C:\Users\UBALDO\Desktop\MINIONGOGGLES003.png
[2013/08/19 13:50:53 | 000,025,773 | ---- | C] () -- C:\Users\UBALDO\Desktop\MINIONGOGGLES3.png
[2013/08/19 13:46:44 | 000,027,355 | ---- | C] () -- C:\Users\UBALDO\Desktop\MINIONGOGGLES2.png
[2013/08/19 13:05:11 | 000,032,189 | ---- | C] () -- C:\Users\UBALDO\Desktop\GOGLES.png
[2013/08/19 12:52:21 | 000,221,782 | ---- | C] () -- C:\Users\UBALDO\Desktop\MINIONGOGGLES.ai
[2013/08/19 11:35:45 | 000,383,947 | ---- | C] () -- C:\Users\UBALDO\Desktop\Jean_texture_by_Babybird_Stock.jpg
[2013/08/19 11:35:18 | 000,532,954 | ---- | C] () -- C:\Users\UBALDO\Desktop\depositphotos_1602251-Texture-Jean.jpg
[2013/08/19 11:19:20 | 000,653,262 | ---- | C] () -- C:\Users\UBALDO\Desktop\il_fullxfull_479007725_623z.jpg
[2013/08/19 11:18:39 | 000,106,511 | ---- | C] () -- C:\Users\UBALDO\Desktop\il_570xN_479320819_8pfw.jpg
[2013/08/19 10:53:21 | 000,642,733 | ---- | C] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEDESING01-02.jpg
[2013/08/19 10:47:41 | 000,319,977 | ---- | C] () -- C:\Users\UBALDO\Desktop\il_fullxfull_491908957_6wdr.jpg
[2013/08/19 10:02:30 | 000,285,846 | ---- | C] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEDESIGN03.jpg
[2013/08/19 10:00:38 | 000,276,268 | ---- | C] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEDESIGN04.jpg
[2013/08/19 09:53:48 | 001,059,028 | ---- | C] () -- C:\Users\UBALDO\Desktop\DESPICABLEME2LOGO2.pspimage
[2013/08/19 09:38:26 | 004,195,563 | ---- | C] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEDESIGN04.pspimage
[2013/08/19 08:57:56 | 000,389,307 | ---- | C] () -- C:\Users\UBALDO\Desktop\LEGODESIGN01.jpg
[2013/08/19 07:22:17 | 000,152,785 | ---- | C] () -- C:\Users\UBALDO\Desktop\Lego-cake-pops-Livinglocurto.jpg
[2013/08/19 07:00:08 | 000,834,593 | ---- | C] () -- C:\Users\UBALDO\Desktop\DESPICABLEME2LOGO.pspimage
[2013/08/19 06:57:03 | 006,681,315 | ---- | C] () -- C:\Users\UBALDO\Desktop\DESPICABLEMEDESIGN03.pspimage
[2013/08/19 06:56:00 | 000,235,511 | ---- | C] () -- C:\Users\UBALDO\Desktop\il_fullxfull_336979509.jpg
[2013/08/18 22:01:29 | 000,085,136 | ---- | C] () -- C:\Users\UBALDO\Desktop\Despicable-Me-2-Ilumination-Evil-Minion-Wallpaper.jpg
[2013/08/18 21:52:09 | 000,887,448 | ---- | C] () -- C:\Users\UBALDO\Desktop\despicable-me-2-wallpaper.jpg
[2013/08/18 21:51:09 | 001,391,813 | ---- | C] () -- C:\Users\UBALDO\Desktop\despicable_me_2_minions-wide.jpg
[2013/08/18 21:40:14 | 000,086,539 | ---- | C] () -- C:\Users\UBALDO\Desktop\il_570xN_483415756_jwqr.jpg
[2013/08/18 21:39:46 | 000,093,695 | ---- | C] () -- C:\Users\UBALDO\Desktop\il_570xN_489102084_5dda.jpg
[2013/08/18 21:39:07 | 000,097,911 | ---- | C] () -- C:\Users\UBALDO\Desktop\il_570xN_487155558_i2n1.jpg
[2013/08/12 22:14:05 | 000,403,347 | ---- | C] () -- C:\Users\UBALDO\Desktop\il_fullxfull_482474610_kl9k.jpg
[2013/07/31 09:43:19 | 000,454,103 | ---- | C] () -- C:\Users\UBALDO\Desktop\MONSTERINC.jpg
[2013/07/31 09:42:43 | 000,890,939 | ---- | C] () -- C:\Users\UBALDO\Desktop\PHINEASANDFERB.jpg
[2013/07/31 09:42:00 | 000,499,704 | ---- | C] () -- C:\Users\UBALDO\Desktop\JAKEANDTHENEVERLAND.jpg
[2013/05/22 21:30:45 | 000,000,037 | -HS- | C] () -- C:\Users\UBALDO\AppData\Local\70149b02515b3bb20dd492.47983420
[2013/01/23 16:42:38 | 000,000,004 | ---- | C] () -- C:\Users\UBALDO\AppData\Roaming\skype.ini
[2012/12/07 10:13:06 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
[2012/08/19 11:08:18 | 000,000,034 | ---- | C] () -- C:\Users\UBALDO\AppData\Roaming\mbam.context.scan
[2012/06/11 14:30:40 | 000,000,017 | ---- | C] () -- C:\Windows\SysWow64\shortcut_ex.dat
[2012/05/19 01:06:54 | 000,007,168 | ---- | C] () -- C:\Users\UBALDO\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/03/13 20:57:15 | 000,001,456 | ---- | C] () -- C:\Users\UBALDO\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012/02/22 22:15:42 | 000,730,638 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/02/21 23:18:14 | 000,007,608 | ---- | C] () -- C:\Users\UBALDO\AppData\Local\Resmon.ResmonCfg
[2012/02/20 21:12:00 | 000,000,088 | RHS- | C] () -- C:\Windows\SysWow64\25FFC419EC.sys
[2012/02/20 20:57:40 | 000,002,828 | -HS- | C] () -- C:\Windows\SysWow64\KGyGaAvL.sys
[2011/11/26 01:25:09 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
========== ZeroAccess Check ==========
[2013/01/27 23:46:25 | 000,002,048 | -HS- | M] () -- C:\$Recycle.bin\S-1-5-18\$b64e7e2ae3846a7bb6ba48b5c45758c7\@
[2013/01/27 23:46:25 | 000,000,000 | -HSD | M] -- C:\$Recycle.bin\S-1-5-18\$b64e7e2ae3846a7bb6ba48b5c45758c7\L
[2013/01/31 23:43:24 | 000,000,000 | -HSD | M] -- C:\$Recycle.bin\S-1-5-18\$b64e7e2ae3846a7bb6ba48b5c45758c7\U
[2009/07/13 21:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
"ThreadingModel" = Both
"" = C:\$Recycle.Bin\S-1-5-21-3018435195-4205911245-3665918404-1000\$b64e7e2ae3846a7bb6ba48b5c45758c7\n.
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/02/26 22:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/02/26 21:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\$Recycle.Bin\S-1-5-18\$b64e7e2ae3846a7bb6ba48b5c45758c7\n.
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 20:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 18:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
< End of report >