These are the logs I prepared before seeing your note above. I will rerun AdwCleaner and post that log.
AdwCleaner[S0].txt
# AdwCleaner v3.212 - Report created 12/06/2014 at 23:48:35
# Updated 05/06/2014 by Xplode
# Operating System : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)
# Username : Chris Janien - DELL
# Running from : C:\Users\Chris Janien\Desktop\adwcleaner_3.212.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
[!] Folder Deleted : C:\ProgramData\AVG Secure Search
[!] Folder Deleted : C:\ProgramData\Conduit
[!] Folder Deleted : C:\Program Files (x86)\AVG Secure Search
[!] Folder Deleted : C:\Program Files (x86)\Conduit
[!] Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
[!] Folder Deleted : C:\Users\admin\AppData\Local\AVG Secure Search
[!] Folder Deleted : C:\Users\admin\AppData\LocalLow\AVG Secure Search
[!] Folder Deleted : C:\Users\Chris Janien\AppData\Local\Conduit
[!] Folder Deleted : C:\Users\Chris Janien\AppData\LocalLow\Conduit
[!] Folder Deleted : C:\Users\Chris Janien\AppData\LocalLow\PriceGong
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla
Key Deleted : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKLM\Software\Conduit
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16555
-\\ Google Chrome v35.0.1916.153
[ File : C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}
Deleted [Search Provider] : hxxp://
www.ask.com/web?q={searchTerms}
Deleted [Search Provider] : hxxps://isearch.avg.com/search?cid={9A6BF338-628F-46D0-940E-AAF472398278}&mid=4fdb26f0759647d6ba39d168ddcfe634-82f80214ebcc3cdbaaafdae3e923740f0b95703c&lang=en&ds=AVG&pr=fr&d=2012-05-16 19:54:42&v=12.2.5.32&sap=dsp&q={searchTerms}
[ File : C:\Users\Chris Janien\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://isearch.avg.com/search?cid={9A6BF338-628F-46D0-940E-AAF472398278}&mid=4fdb26f0759647d6ba39d168ddcfe634-82f80214ebcc3cdbaaafdae3e923740f0b95703c&lang=en&ds=AVG&pr=fr&d=2012-05-16 19:54:42&v=14.2.0.1&pid=avg&sg=&sap=dsp&q={searchTerms}
Deleted [Search Provider] : hxxp://isearch.avg.com/search?cid={9A6BF338-628F-46D0-940E-AAF472398278}&mid=4fdb26f0759647d6ba39d168ddcfe634-82f80214ebcc3cdbaaafdae3e923740f0b95703c&lang=en&ds=AVG&pr=fr&d=2012-05-16 19:54:42&v=14.2.0.1&pid=avg&sg=&sap=dsp&q={searchTerms}
Deleted [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}
Deleted [Search Provider] : hxxp://
www.ask.com/web?q={searchTerms}
*************************
AdwCleaner[R0].txt - [4022 octets] - [12/06/2014 23:46:48]
AdwCleaner[S0].txt - [3830 octets] - [12/06/2014 23:48:35]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3890 octets] ##########
AdwCleaner[RO].txt
# AdwCleaner v3.212 - Report created 12/06/2014 at 23:46:48
# Updated 05/06/2014 by Xplode
# Operating System : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)
# Username : Chris Janien - DELL
# Running from : C:\Users\Chris Janien\Desktop\adwcleaner_3.212.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found : C:\Program Files (x86)\AVG Secure Search
Folder Found : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Found : C:\Program Files (x86)\Conduit
Folder Found : C:\ProgramData\AVG Secure Search
Folder Found : C:\ProgramData\Conduit
Folder Found : C:\Users\admin\AppData\Local\AVG Secure Search
Folder Found : C:\Users\admin\AppData\LocalLow\AVG Secure Search
Folder Found : C:\Users\Chris Janien\AppData\Local\Conduit
Folder Found : C:\Users\Chris Janien\AppData\LocalLow\Conduit
Folder Found : C:\Users\Chris Janien\AppData\LocalLow\PriceGong
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Found : [x64] HKCU\Software\Conduit
Key Found : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Key Found : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Found : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Key Found : HKLM\Software\Conduit
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16555
-\\ Google Chrome v35.0.1916.153
[ File : C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Found [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}
Found [Search Provider] : hxxp://
www.ask.com/web?q={searchTerms}
Found [Search Provider] : hxxps://isearch.avg.com/search?cid={9A6BF338-628F-46D0-940E-AAF472398278}&mid=4fdb26f0759647d6ba39d168ddcfe634-82f80214ebcc3cdbaaafdae3e923740f0b95703c&lang=en&ds=AVG&pr=fr&d=2012-05-16 19:54:42&v=12.2.5.32&sap=dsp&q={searchTerms}
[ File : C:\Users\Chris Janien\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Found [Search Provider] : hxxp://isearch.avg.com/search?cid={9A6BF338-628F-46D0-940E-AAF472398278}&mid=4fdb26f0759647d6ba39d168ddcfe634-82f80214ebcc3cdbaaafdae3e923740f0b95703c&lang=en&ds=AVG&pr=fr&d=2012-05-16 19:54:42&v=14.2.0.1&pid=avg&sg=&sap=dsp&q={searchTerms}
Found [Search Provider] : hxxp://isearch.avg.com/search?cid={9A6BF338-628F-46D0-940E-AAF472398278}&mid=4fdb26f0759647d6ba39d168ddcfe634-82f80214ebcc3cdbaaafdae3e923740f0b95703c&lang=en&ds=AVG&pr=fr&d=2012-05-16 19:54:42&v=14.2.0.1&pid=avg&sg=&sap=dsp&q={searchTerms}
Found [Search Provider] : hxxp://search.aol.com/aol/search?query={searchTerms}
Found [Search Provider] : hxxp://
www.ask.com/web?q={searchTerms}
*************************
AdwCleaner[R0].txt - [3866 octets] - [12/06/2014 23:46:48]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [3926 octets] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows (TM) Vista Home Premium x64
Ran by Chris Janien on Fri 06/13/2014 at 0:10:04.54
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{3362F302-A76A-444F-834C-C4CE37C9EFE2}
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Fri 06/13/2014 at 0:14:30.52
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
OTL logfile created on: 6/13/2014 12:16:28 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Chris Janien\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
16.00 Gb Total Physical Memory | 13.43 Gb Available Physical Memory | 83.92% Memory free
31.81 Gb Paging File | 29.36 Gb Available in Paging File | 92.32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 581.11 Gb Total Space | 155.38 Gb Free Space | 26.74% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 7.71 Gb Free Space | 51.40% Space Free | Partition Type: NTFS
Drive E: | 52.91 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive J: | 29.80 Gb Total Space | 29.68 Gb Free Space | 99.58% Space Free | Partition Type: FAT32
Computer Name: DELL | User Name: Chris Janien | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/06/12 23:41:48 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Chris Janien\Desktop\OTL.exe
PRC - [2013/10/31 14:47:38 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
PRC - [2013/10/31 14:47:28 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
PRC - [2013/10/31 14:47:20 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe
PRC - [2013/10/02 04:02:08 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
PRC - [2011/08/25 17:53:00 | 000,013,672 | ---- | M] (Intuit Inc.) -- C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
PRC - [2011/06/15 17:33:20 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
PRC - [2009/09/29 10:17:50 | 000,013,088 | ---- | M] (Intuit Inc.) -- C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe
PRC - [2009/06/06 16:47:37 | 000,068,592 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Quick Search Box\GoogleQuickSearchBox.exe
PRC - [2008/09/23 22:09:52 | 000,155,648 | ---- | M] (Stardock Corporation) -- C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2008/06/26 20:09:36 | 000,167,936 | ---- | M] () -- C:\Program Files (x86)\D-Link\DWA-131 revA\WlanWpsSvc.exe
PRC - [2008/04/23 03:08:13 | 000,483,328 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 7.0\Distillr\acrotray.exe
========== Modules (No Company Name) ==========
MOD - [2014/02/06 01:52:52 | 000,073,544 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2014/02/06 01:52:32 | 001,044,808 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2013/09/14 02:51:02 | 000,087,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Internet Services\zlib1.dll
MOD - [2013/09/14 02:50:36 | 001,242,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Internet Services\libxml2.dll
MOD - [2011/12/01 15:35:37 | 000,103,424 | ---- | M] () -- C:\Program Files (x86)\Google\Quick Search Box\bin\1.2.1151.245\rlz.dll
========== Services (SafeList) ==========
SRV:
64bit: - [2014/03/11 12:34:10 | 000,347,872 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:
64bit: - [2014/03/11 12:34:10 | 000,023,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:
64bit: - [2011/04/20 02:04:20 | 000,203,776 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:
64bit: - [2008/12/22 03:37:34 | 000,088,576 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe -- (AERTFilters)
SRV:
64bit: - [2008/09/23 22:09:52 | 000,155,648 | ---- | M] (Stardock Corporation) [Auto | Running] -- C:\Program Files\Dell\DellDock\DockLogin.exe -- (DockLoginService)
SRV:
64bit: - [2008/01/20 22:47:32 | 000,383,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2014/05/13 17:06:26 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/09/11 22:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2011/08/25 17:53:00 | 000,013,672 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe -- (IntuitUpdateServiceV4)
SRV - [2011/07/07 19:31:08 | 000,195,336 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011/06/15 17:33:20 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE -- (BBUpdate)
SRV - [2009/10/23 13:31:44 | 000,401,920 | ---- | M] (Amazon.com) [On_Demand | Stopped] -- C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe -- (Amazon Download Agent)
SRV - [2009/09/29 10:17:50 | 000,013,088 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe -- (IntuitUpdateService)
SRV - [2009/03/30 00:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/06/26 20:09:36 | 000,167,936 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\D-Link\DWA-131 revA\WlanWpsSvc.exe -- (WlanWpsSvc)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2014/03/11 09:52:30 | 000,133,928 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\NisDrvWFP.sys -- (NisDrv)
DRV:
64bit: - [2013/07/25 16:53:46 | 000,023,040 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\netaapl64.sys -- (Netaapl)
DRV:
64bit: - [2013/02/19 02:13:11 | 000,039,768 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:
64bit: - [2012/12/13 14:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\usbaapl64.sys -- (USBAAPL64)
DRV:
64bit: - [2012/08/21 14:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:
64bit: - [2012/02/29 09:52:46 | 000,016,384 | ---- | M] (Microsoft Corporation) [Recognizer | System | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:
64bit: - [2011/04/20 02:44:50 | 009,319,936 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\atikmdag.sys -- (R300)
DRV:
64bit: - [2011/04/20 02:44:50 | 009,319,936 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\atikmdag.sys -- (atikmdag)
DRV:
64bit: - [2011/04/20 02:44:50 | 009,319,936 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\atikmdag.sys -- (amdkmdag)
DRV:
64bit: - [2011/04/20 01:22:34 | 000,306,176 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\atikmpag.sys -- (amdkmdap)
DRV:
64bit: - [2009/09/30 20:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)
DRV:
64bit: - [2009/04/03 15:43:04 | 000,589,312 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\RTL8192su.sys -- (RTL8192su)
DRV:
64bit: - [2008/12/22 03:37:14 | 000,185,248 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:
64bit: - [2008/09/28 08:46:48 | 000,316,544 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\e1y60x64.sys -- (e1yexpress)
DRV:
64bit: - [2008/09/28 04:22:14 | 000,402,456 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\iastor.sys -- (iaStor)
DRV:
64bit: - [2008/04/16 14:49:34 | 000,028,416 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\RimUsb_AMD64.sys -- (RimUsb)
DRV:
64bit: - [2008/01/20 22:46:55 | 000,317,952 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\e1e6032e.sys -- (e1express)
DRV:
64bit: - [2007/11/14 03:00:00 | 000,053,488 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:
64bit: - [2007/04/23 14:15:48 | 000,031,016 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | System | Running] -- C:\Windows\SysNative\DRIVERS\rtlprot.sys -- (RtlProt)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:
64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={sea...putEncoding}&oe={outputEncoding}&sourceid=ie7
IE:
64bit: - HKLM\..\SearchScopes\{7C2D15BE-40CA-453C-85CC-18202160D843}: "URL" =
http://search.live.com/results.aspx?q={searchTerms}&Form=DLCDF7&pc=MDDC&src={referrer:source?}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={sea...putEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3892225521-3189527621-3242994168-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKU\S-1-5-21-3892225521-3189527621-3242994168-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-3892225521-3189527621-3242994168-1001\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-3892225521-3189527621-3242994168-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-3892225521-3189527621-3242994168-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
https://www.google.com/search?q={searchTerms}&rlz=1I7GZAZ_enUS330
IE - HKU\S-1-5-21-3892225521-3189527621-3242994168-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3892225521-3189527621-3242994168-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ==========
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=13: C:\Program Files (x86)\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\
========== Chrome ==========
CHR - default_search_provider: AVG Secure Search (Enabled)
CHR - default_search_provider: search_url =
http://isearch.avg.com/search?cid={...40f0b95703c&lang=en&ds=AVG&pr=fr&d=2012-05-16 19:54:42&v=14.2.0.1&pid=avg&sg=&sap=dsp&q={searchTerms}
CHR - default_search_provider: suggest_url =
http://toolbar.avg.com/acp?q={searchTerms}&o=1,
CHR - plugin: Error reading preferences file
CHR - Extension: Google Voice Search Hotword (Beta) = C:\Users\Chris Janien\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5019_0\
CHR - Extension: Google Wallet = C:\Users\Chris Janien\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\
O1 HOSTS File: ([2014/06/12 21:25:50 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:
64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg64.dll (Google Inc.)
O2:
64bit: - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll ()
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:
64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:
64bit: - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:
64bit: - HKU\S-1-5-21-3892225521-3189527621-3242994168-1001\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:
64bit: - HKU\S-1-5-21-3892225521-3189527621-3242994168-1001\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKU\S-1-5-21-3892225521-3189527621-3242994168-1001\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O4:
64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Acrobat Assistant 7.0] C:\Program Files (x86)\Adobe\Acrobat 7.0\Distillr\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [AmazonGSDownloaderTray] C:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe (Amazon.com)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files (x86)\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-3892225521-3189527621-3242994168-1001..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKU\S-1-5-21-3892225521-3189527621-3242994168-1001..\Run: [com.apple.dav.bookmarks.daemon] C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe (Apple Inc.)
O4 - HKU\S-1-5-21-3892225521-3189527621-3242994168-1001..\Run: [DellSystemDetect] C:\Users\Chris Janien\AppData\Local\Apps\2.0\83Z2JYHQ.VNZ\6Q8MOYRG.3J5\dell..tion_0f612f649c4a10af_0005.0008_a4204ff54ae5d3ac\DellSystemDetect.exe (Dell)
O4 - HKU\S-1-5-21-3892225521-3189527621-3242994168-1001..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - HKU\S-1-5-21-3892225521-3189527621-3242994168-1001..\Run: [updateMgr] C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3892225521-3189527621-3242994168-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3892225521-3189527621-3242994168-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-3892225521-3189527621-3242994168-1001\..Trusted Domains: dell.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-3892225521-3189527621-3242994168-1001\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {1C3DE665-D259-4C72-9D7D-C51FCB4CCFB9}
http://173.9.91.181:50000/SysCamInst.cab (Panasonic Network Camera)
O16 - DPF: {1D9EFA3B-4E85-41A8-9092-14012CD447C9}
http://192.168.1.110/img/NetCamPlayerWeb.ocx (NetCamPlayerWeb Control)
O16 - DPF: {5C0E257E-9DFE-4955-AA93-0A9B166BAB50}
http://demo.synology.com:5000/surveillance/object/SSObject.cab (SSObject Control)
O16 - DPF: {7340F0E4-AEDA-47C6-8971-9DB314030BD7}
http://extcam-2.se.axis.com/activex/decoder/h264_dec.cab (CAxH264Dec Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab (Java Plug-in 10.51.2)
O16 - DPF: {960DC750-7447-4CDE-BF1C-FB33F9129654}
http://demo.synology.com:5000/webman/3rdparty/SurveillanceStation/object/SSObject3.cab (SSObject3 Control)
O16 - DPF: {CAFEEFAC-0017-0000-0004-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab (Java Plug-in 1.7.0_04)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab (Java Plug-in 10.51.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DF6D8700-0DF3-46B4-A55B-8AEE2D362333}: DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F1CED16F-26B0-424F-8778-A79690352381}: DhcpNameServer = 75.75.75.75 75.75.76.76 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F1CED16F-26B0-424F-8778-A79690352381}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F8236E3A-7C0D-4BF1-90FB-89D042715F55}: DhcpNameServer = 172.20.10.1
O18:
64bit: - Protocol\Handler\belarc - No CLSID value found
O18:
64bit: - Protocol\Handler\linkscanner - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\linkscanner - No CLSID value found
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll ()
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img5.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img5.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/03/26 10:32:50 | 000,000,067 | R--- | M] () - E:\Autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2014/06/13 00:05:15 | 000,000,000 | ---D | C] -- C:\Users\Chris Janien\AppData\Local\CrashDumps
[2014/06/12 23:47:06 | 000,536,576 | ---- | C] (SQLite Development Team) -- C:\Windows\SysWow64\sqlite3.dll
[2014/06/12 23:46:31 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/06/12 23:41:48 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Chris Janien\Desktop\OTL.exe
[2014/06/12 23:41:22 | 001,016,261 | ---- | C] (Thisisu) -- C:\Users\Chris Janien\Desktop\JRT.exe
[2014/06/12 23:05:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2014/06/12 23:05:29 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2014/06/12 21:28:13 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2014/06/12 21:28:11 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2014/06/12 21:12:49 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2014/06/12 21:12:49 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2014/06/12 21:12:49 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2014/06/12 21:12:04 | 000,000,000 | ---D | C] -- C:\Qoobox
[2014/06/12 21:00:41 | 011,580,448 | ---- | C] (OPSWAT, Inc.) -- C:\Users\Chris Janien\Desktop\AppRemover.exe
[2014/06/12 20:49:43 | 005,205,897 | R--- | C] (Swearware) -- C:\Users\Chris Janien\Desktop\ComboFix.exe
[2014/06/12 19:43:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2014/06/12 19:22:07 | 000,000,000 | ---D | C] -- C:\ProgramData\RogueKiller
[2014/06/12 02:10:11 | 000,688,992 | R--- | C] (Swearware) -- C:\Users\Chris Janien\Desktop\dds.com
[2014/06/12 01:51:32 | 017,292,760 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Chris Janien\Desktop\mbam-setup-2.0.2.1012.exe
[2014/06/05 16:35:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Belarc
[2014/06/04 23:32:15 | 000,000,000 | ---D | C] -- C:\Users\Chris Janien\AppData\Local\Sound_Technologies,_Inc
[2014/06/04 23:30:39 | 000,000,000 | ---D | C] -- C:\Users\Chris Janien\AppData\Roaming\Reveal
[2014/06/04 23:30:15 | 000,000,000 | ---D | C] -- C:\logs
[2014/06/01 20:52:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2014/06/01 20:51:32 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2014/06/01 20:51:31 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2014/06/01 20:51:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2014/06/01 20:51:31 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2014/05/26 20:13:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2014/05/18 23:07:19 | 000,000,000 | ---D | C] -- C:\Users\Chris Janien\AppData\Roaming\TuneUp Software
[2014/05/18 23:00:00 | 000,000,000 | ---D | C] -- C:\Users\Chris Janien\AppData\Local\MFAData
[2014/05/15 03:05:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
========== Files - Modified Within 30 Days ==========
[2014/06/13 00:16:59 | 000,000,434 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{1D744372-14E5-44CE-ABF3-1595FCB41BA3}.job
[2014/06/13 00:16:11 | 000,000,597 | ---- | M] () -- C:\Users\Chris Janien\Desktop\Don't know if I have a virus or hardware problem - TechSpot Forums.website
[2014/06/13 00:06:15 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/06/12 23:54:18 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/06/12 23:51:12 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2014/06/12 23:51:11 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2014/06/12 23:51:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/06/12 23:49:39 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2014/06/12 23:41:48 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Chris Janien\Desktop\OTL.exe
[2014/06/12 23:41:24 | 001,016,261 | ---- | M] (Thisisu) -- C:\Users\Chris Janien\Desktop\JRT.exe
[2014/06/12 23:41:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/06/12 23:40:58 | 001,333,465 | ---- | M] () -- C:\Users\Chris Janien\Desktop\adwcleaner_3.212.exe
[2014/06/12 23:07:25 | 000,002,154 | ---- | M] () -- C:\Windows\epplauncher.mif
[2014/06/12 21:25:50 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2014/06/12 21:00:41 | 011,580,448 | ---- | M] (OPSWAT, Inc.) -- C:\Users\Chris Janien\Desktop\AppRemover.exe
[2014/06/12 20:49:43 | 005,205,897 | R--- | M] (Swearware) -- C:\Users\Chris Janien\Desktop\ComboFix.exe
[2014/06/12 03:09:20 | 000,001,129 | ---- | M] () -- C:\Users\Chris Janien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2014/06/12 03:09:09 | 000,002,593 | ---- | M] () -- C:\Users\Chris Janien\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft OneNote 2010.lnk
[2014/06/12 02:10:11 | 000,688,992 | R--- | M] (Swearware) -- C:\Users\Chris Janien\Desktop\dds.com
[2014/06/12 01:51:32 | 017,292,760 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Chris Janien\Desktop\mbam-setup-2.0.2.1012.exe
[2014/06/11 18:42:45 | 000,002,027 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/06/11 14:41:18 | 000,002,437 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
[2014/06/11 13:17:07 | 000,002,661 | ---- | M] () -- C:\Users\Chris Janien\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Word 2010.lnk
[2014/06/11 02:17:47 | 000,759,582 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/06/11 02:17:47 | 000,642,740 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/06/11 02:17:47 | 000,119,932 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/06/08 15:41:28 | 000,002,619 | ---- | M] () -- C:\Users\Chris Janien\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Excel 2010.lnk
[2014/06/05 16:35:18 | 000,001,981 | ---- | M] () -- C:\Users\Chris Janien\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2014/06/05 16:35:18 | 000,001,957 | ---- | M] () -- C:\Users\Public\Desktop\Belarc Advisor.lnk
[2014/06/02 14:41:53 | 000,000,711 | ---- | M] () -- C:\Users\Chris Janien\Documents\Thinkpad x201T - Shortcut.lnk
[2014/06/01 20:52:27 | 000,001,696 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2014/05/26 22:26:53 | 000,041,472 | ---- | M] () -- C:\Users\Chris Janien\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== Files Created - No Company Name ==========
[2014/06/12 23:40:58 | 001,333,465 | ---- | C] () -- C:\Users\Chris Janien\Desktop\adwcleaner_3.212.exe
[2014/06/12 23:07:25 | 000,002,154 | ---- | C] () -- C:\Windows\epplauncher.mif
[2014/06/12 23:06:07 | 000,001,828 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2014/06/12 21:12:49 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2014/06/12 21:12:49 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2014/06/12 21:12:49 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2014/06/12 21:12:49 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2014/06/12 21:12:49 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2014/06/12 19:19:22 | 000,000,597 | ---- | C] () -- C:\Users\Chris Janien\Desktop\Don't know if I have a virus or hardware problem - TechSpot Forums.website
[2014/06/05 16:35:18 | 000,001,981 | ---- | C] () -- C:\Users\Chris Janien\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2014/06/05 16:35:18 | 000,001,969 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk
[2014/06/05 16:35:18 | 000,001,957 | ---- | C] () -- C:\Users\Public\Desktop\Belarc Advisor.lnk
[2014/06/02 14:41:53 | 000,000,711 | ---- | C] () -- C:\Users\Chris Janien\Documents\Thinkpad x201T - Shortcut.lnk
[2014/06/01 20:52:27 | 000,001,696 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2014/05/18 23:54:37 | 000,000,426 | ---- | C] () -- C:\AVScanner.ini
[2013/09/23 13:59:54 | 000,752,894 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013/02/15 17:27:38 | 000,000,025 | ---- | C] () -- C:\Windows\D2P.INI
[2012/10/14 22:33:38 | 000,000,469 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2012/08/15 17:49:17 | 000,027,520 | ---- | C] () -- C:\Users\Chris Janien\AppData\Local\dt.dat
[2012/05/17 11:30:16 | 000,008,248 | ---- | C] () -- C:\Users\Chris Janien\AppData\Local\en.ini
[2012/04/22 23:10:27 | 000,000,732 | ---- | C] () -- C:\Users\Chris Janien\AppData\Local\d3d9caps64.dat
[2011/11/15 22:20:58 | 000,023,888 | ---- | C] () -- C:\Users\Chris Janien\AppData\Roaming\UserTile.png
[2011/07/04 14:09:55 | 000,000,680 | ---- | C] () -- C:\Users\Chris Janien\AppData\Local\d3d9caps.dat
[2011/06/09 20:48:27 | 000,000,136 | ---- | C] () -- C:\ProgramData\~45014776r
[2011/06/09 20:48:27 | 000,000,112 | ---- | C] () -- C:\ProgramData\~45014776
[2011/03/10 14:59:52 | 000,001,274 | ---- | C] () -- C:\Users\Chris Janien\AppData\Roaming\wklnhst.dat
[2010/11/15 22:10:01 | 000,041,472 | ---- | C] () -- C:\Users\Chris Janien\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2006/11/02 11:30:40 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/03/25 12:30:37 | 012,900,864 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/03/25 09:26:04 | 011,587,584 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/04/11 03:11:14 | 000,891,392 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\SysWow64\wbem\fastprox.dll -- [2009/04/11 02:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2008/01/20 22:50:58 | 000,513,024 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\SysWow64\wbem\wbemess.dll
========== LOP Check ==========
[2011/02/28 18:48:35 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\AVG10
[2010/02/04 02:38:08 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/12/04 23:55:11 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\com.Shutterfly.ExpressUploader
[2011/09/10 17:26:25 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\ICAClient
[2009/06/06 20:01:07 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Template
[2009/06/29 15:01:04 | 000,000,000 | ---D | M] -- C:\Users\admin\AppData\Roaming\Windows Live Writer
[2013/02/15 16:22:39 | 000,000,000 | ---D | M] -- C:\Users\Chris Janien\AppData\Roaming\Autodesk
[2011/07/21 03:59:58 | 000,000,000 | ---D | M] -- C:\Users\Chris Janien\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2014/05/11 20:45:41 | 000,000,000 | ---D | M] -- C:\Users\Chris Janien\AppData\Roaming\EncryptStick
[2011/09/03 00:13:09 | 000,000,000 | ---D | M] -- C:\Users\Chris Janien\AppData\Roaming\ICAClient
[2014/03/29 15:49:16 | 000,000,000 | ---D | M] -- C:\Users\Chris Janien\AppData\Roaming\Oracle
[2011/12/02 11:56:13 | 000,000,000 | ---D | M] -- C:\Users\Chris Janien\AppData\Roaming\PCDr
[2011/11/15 22:20:58 | 000,000,000 | ---D | M] -- C:\Users\Chris Janien\AppData\Roaming\PeerNetworking
[2014/06/04 23:30:39 | 000,000,000 | ---D | M] -- C:\Users\Chris Janien\AppData\Roaming\Reveal
[2011/06/10 12:40:19 | 000,000,000 | ---D | M] -- C:\Users\Chris Janien\AppData\Roaming\Sammsoft
[2013/09/23 14:18:59 | 000,000,000 | ---D | M] -- C:\Users\Chris Janien\AppData\Roaming\SketchUp
[2011/03/10 14:59:54 | 000,000,000 | ---D | M] -- C:\Users\Chris Janien\AppData\Roaming\Template
[2014/05/18 23:07:19 | 000,000,000 | ---D | M] -- C:\Users\Chris Janien\AppData\Roaming\TuneUp Software
[2013/02/12 15:31:30 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2013/02/12 15:31:30 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
========== Purity Check ==========
< End of report >