Second part of OTL log:
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@rim.com/npappworld: C:\Program Files\Research In Motion Limited\BlackBerry App World Browser Plugin\npappworld.dll ()
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Mark\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Mark\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/06/12 23:50:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2011/02/28 14:54:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/09/08 21:57:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F04D2D30-776C-4d02-8627-8E4385ECA58D}: C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2012.6.3.2\coFFPlgn\ [2012/09/16 21:47:29 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\
smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/06/12 23:50:47 | 000,000,000 | ---D | M]
[2010/07/11 16:47:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mark\AppData\Roaming\Mozilla\Extensions
[2010/07/11 16:47:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mark\AppData\Roaming\Mozilla\Extensions\
home2@tomtom.com
[2012/09/08 15:06:30 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/10/17 19:14:28 | 000,002,149 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\adawaretb.xml
========== Chrome ==========
CHR - homepage:
CHR - homepage:
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Mark\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Mark\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Mark\AppData\Local\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Motive Plugin (Enabled) = C:\Program Files\Common Files\Motive\npMotive.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Musicnotes (Enabled) = C:\Program Files\Musicnotes\npmusicn.dll
CHR - plugin: ScorchPlugin (Enabled) = C:\Program Files\Musicnotes\npsibelius.dll
CHR - plugin: BlackBerry AppWorld (Enabled) = C:\Program Files\Research In Motion Limited\BlackBerry App World Browser Plugin\npappworld.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = c:\program files\real\realplayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Download Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprpplugin.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprjplug.dll
CHR - Extension: YouTube = C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Motive Extension = C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\edmgmpmklgfbohogafcfobonnkogchec\1.0_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Norton Identity Protection = C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.1.1.4_0\
CHR - Extension: Gmail = C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/09/15 21:40:33 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AOL Toolbar Launcher) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Broadband Toolbar 5.0\aoltb.dll (AOL LLC)
O2 - BHO: (Norton Identity Protection) - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} - C:\Program Files\Norton Identity Safe\Engine\2012.6.3.2\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Identity Safe Toolbar) - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files\Norton Identity Safe\Engine\2012.6.3.2\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (AOL Broadband Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Broadband Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-802167735-3406490535-3852651081-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-802167735-3406490535-3852651081-1000\..\Toolbar\WebBrowser: (AOL Broadband Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Broadband Toolbar 5.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] "C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe" File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [btbb_McciTrayApp] C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe (Alcatel-Lucent)
O4 - HKLM..\Run: [Google Updater] C:\Program Files\Google\Google Updater\GoogleUpdater.exe (Google)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\aol\1219316984\ee\aolsoftware.exe (AOL LLC)
O4 - HKLM..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe File not found
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [OsdMaestro] C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro)
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateReg] C:\Windows\System32\jureg.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-802167735-3406490535-3852651081-1000..\Run: [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - HKU\S-1-5-21-802167735-3406490535-3852651081-1000..\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKU\S-1-5-21-802167735-3406490535-3852651081-1000..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-802167735-3406490535-3852651081-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-802167735-3406490535-3852651081-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKU\S-1-5-21-802167735-3406490535-3852651081-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-802167735-3406490535-3852651081-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKU\S-1-5-21-802167735-3406490535-3852651081-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
O8 - Extra context menu item: &AOL Toolbar Search - c:\Program Files\AOL\AOL Broadband Toolbar 5.0\resources\en-GB\local\search.html ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-802167735-3406490535-3852651081-1000\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {44990B00-3C9D-426D-81DF-AAB636FA4345}
https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlcm.cab (Reg Error: Value error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DF935B54-EE05-4BDB-BF19-E742BFB044C4}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\570\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Users\Mark\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Mark\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\System32\ezUPBHook.dll (EasyBits Software Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/04 23:47:14 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/09/15 22:22:44 | 000,000,000 | ---D | C] -- C:\Users\Mark\Documents\log
[2012/09/15 21:54:11 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/09/15 21:40:43 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/09/15 21:19:41 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/09/15 21:19:41 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/09/15 21:19:41 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/09/15 21:19:33 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/09/15 21:18:54 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/09/15 09:51:56 | 000,000,000 | ---D | C] -- C:\FRST
[2012/09/13 20:51:00 | 000,132,744 | R--- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\NST\7DC06030.002\ccSetx86.sys
[2012/09/13 20:50:57 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Identity Safe
[2012/09/13 20:50:57 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NST
[2012/09/13 20:50:57 | 000,000,000 | ---D | C] -- C:\Program Files\Norton Identity Safe
[2012/09/13 20:50:57 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NST\7DC06030.002
[2012/09/13 19:51:06 | 000,000,000 | ---D | C] -- C:\NBRT
[2012/09/09 19:44:17 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Local\CrashDumps
[2012/09/09 17:11:18 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Roaming\Malwarebytes
[2012/09/09 17:11:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/09/09 09:11:27 | 000,000,000 | ---D | C] -- C:\ProgramData\SMR310
[2012/09/09 09:11:09 | 000,097,440 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\SMR310.SYS
[2012/09/08 17:16:38 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/09/08 15:29:12 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NBRTWizard
[2012/09/08 15:29:12 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\NBRTWizard\0501000.01A
[2012/09/08 15:29:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Bootable Recovery Tool Wizard
[2012/09/08 15:29:10 | 000,000,000 | ---D | C] -- C:\Program Files\Norton Bootable Recovery Tool Wizard
[2012/09/08 14:52:28 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton
[2012/09/07 22:04:20 | 000,000,000 | ---D | C] -- C:\Windows\System32\N360_BACKUP
[2012/09/07 20:02:06 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Local\NPE
[2012/09/07 19:33:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012/09/07 19:30:24 | 000,000,000 | ---D | C] -- C:\Users\Mark\Documents\Symantec
[2012/09/07 19:26:16 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
[2012/09/07 19:26:16 | 000,000,000 | ---D | C] -- C:\Program Files\NortonInstaller
[2012/09/07 18:31:23 | 000,000,000 | ---D | C] -- C:\Users\Mark\Sources
[2012/09/07 18:09:30 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Local\NokiaAccount
[2012/09/07 17:43:02 | 000,000,000 | ---D | C] -- C:\Users\Mark\Documents\NPS
[2012/08/23 10:29:59 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Local\MediaShow
[2012/08/23 10:26:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BT Desktop Help
[2012/08/23 09:03:17 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Local\Power2Go8
[2012/08/22 17:04:14 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Local\MediaServer
[2012/08/22 17:04:14 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\CyberLink
[2012/08/22 17:04:11 | 000,000,000 | ---D | C] -- C:\ProgramData\PDVD
[2012/08/22 17:02:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewBlue
[2012/08/22 16:58:54 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\CyberLink
[2012/08/22 16:54:16 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Local\Cyberlink
[2012/08/22 16:51:42 | 000,000,000 | ---D | C] -- C:\ProgramData\install_clap
[2012/08/22 16:47:38 | 000,000,000 | ---D | C] -- C:\ProgramData\CLSK
[2009/04/10 16:47:51 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Mark\AppData\Roaming\pcouffin.sys
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/09/16 22:25:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/16 22:22:55 | 000,000,508 | ---- | M] () -- C:\Users\Mark\Desktop\OTL.exe - Shortcut.lnk
[2012/09/16 21:56:15 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/16 21:45:23 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/16 21:45:22 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/16 21:45:22 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/16 21:45:19 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/09/16 21:45:15 | 3488,915,456 | -HS- | M] () -- C:\hiberfil.sys
[2012/09/16 19:36:13 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-802167735-3406490535-3852651081-1000UA.job
[2012/09/16 10:14:00 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2012/09/15 21:40:33 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/09/15 20:35:00 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-802167735-3406490535-3852651081-1000Core.job
[2012/09/15 19:28:17 | 000,000,064 | ---- | M] () -- C:\Windows\System32\rp_stats.dat
[2012/09/15 19:28:17 | 000,000,044 | ---- | M] () -- C:\Windows\System32\rp_rules.dat
[2012/09/13 19:54:27 | 271,553,641 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/09/13 19:36:20 | 000,000,873 | ---- | M] () -- C:\Users\Mark\Desktop\Norton Installation Files.lnk
[2012/09/13 18:50:01 | 000,070,656 | ---- | M] () -- C:\Windows\System32\umstartup.etl
[2012/09/12 10:22:20 | 000,033,046 | ---- | M] () -- C:\Users\Mark\AppData\Roaming\wklnhst.dat
[2012/09/11 16:29:30 | 012,888,064 | ---- | M] () -- C:\Users\Mark\Documents\dan passport photo.wps
[2012/09/09 18:51:46 | 000,064,000 | ---- | M] () -- C:\Users\Mark\Documents\DDS log 1 and 2.wps
[2012/09/09 09:11:09 | 000,097,440 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\SMR310.SYS
[2012/09/09 08:28:18 | 000,285,328 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/09/08 18:55:25 | 002,416,348 | ---- | M] () -- C:\Windows\System32\drivers\Cat.DB
[2012/09/08 14:41:32 | 000,000,040 | ---- | M] () -- C:\Users\Public\Documents\_rgpl
[2012/09/07 18:29:50 | 000,001,537 | ---- | M] () -- C:\Users\Mark\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Explorer.lnk
[2012/09/07 18:29:44 | 000,001,537 | ---- | M] () -- C:\Users\Mark\Desktop\Windows Explorer.lnk
[2012/09/07 18:14:29 | 000,604,124 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/09/07 18:14:29 | 000,107,264 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/09/07 17:47:10 | 000,000,134 | ---- | M] () -- C:\Users\Mark\Desktop\Programs.lnk
[2012/09/01 21:39:28 | 000,038,400 | ---- | M] () -- C:\Users\Mark\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/08/27 12:39:38 | 001,483,597 | ---- | M] () -- C:\Users\Mark\Documents\scan0012.jpg
[2012/08/25 11:46:19 | 001,122,273 | ---- | M] () -- C:\Users\Mark\Documents\Centauro.jpg
[2012/08/23 10:26:46 | 000,001,095 | ---- | M] () -- C:\Users\Public\Desktop\BT Desktop Help.lnk
[2012/08/22 17:38:01 | 000,001,046 | ---- | M] () -- C:\Users\Mark\Application Data\Microsoft\Internet Explorer\Quick Launch\CyberLink DVD Suite Deluxe.lnk
[2012/08/22 15:37:57 | 1238,864,448 | ---- | M] () -- C:\Users\Mark\Documents\CyberLink_MES120105-04.exe
[2012/08/22 04:14:29 | 000,000,172 | ---- | M] () -- C:\Windows\System32\drivers\NBRTWizard\0501000.01A\isolate.ini
[2012/08/21 11:51:55 | 011,912,192 | ---- | M] () -- C:\Users\Mark\Documents\New @ Condado.wps
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/09/16 22:22:55 | 000,000,508 | ---- | C] () -- C:\Users\Mark\Desktop\OTL.exe - Shortcut.lnk
[2012/09/15 21:19:41 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/09/15 21:19:41 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/09/15 21:19:41 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/09/15 21:19:41 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/09/15 21:19:41 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/09/15 20:42:41 | 3488,915,456 | -HS- | C] () -- C:\hiberfil.sys
[2012/09/13 20:50:58 | 000,000,827 | R--- | C] () -- C:\Windows\System32\drivers\NST\7DC06030.002\ccSetx86.inf
[2012/09/13 20:50:57 | 000,007,468 | R--- | C] () -- C:\Windows\System32\drivers\NST\7DC06030.002\ccsetx86.cat
[2012/09/13 20:50:57 | 000,000,172 | ---- | C] () -- C:\Windows\System32\drivers\NST\7DC06030.002\isolate.ini
[2012/09/11 16:29:27 | 012,888,064 | ---- | C] () -- C:\Users\Mark\Documents\dan passport photo.wps
[2012/09/09 18:51:45 | 000,064,000 | ---- | C] () -- C:\Users\Mark\Documents\DDS log 1 and 2.wps
[2012/09/08 18:52:20 | 002,416,348 | ---- | C] () -- C:\Windows\System32\drivers\Cat.DB
[2012/09/08 15:29:12 | 000,000,172 | ---- | C] () -- C:\Windows\System32\drivers\NBRTWizard\0501000.01A\isolate.ini
[2012/09/08 14:52:28 | 000,000,873 | ---- | C] () -- C:\Users\Mark\Desktop\Norton Installation Files.lnk
[2012/09/08 14:41:32 | 000,000,040 | ---- | C] () -- C:\Users\Public\Documents\_rgpl
[2012/09/07 18:29:50 | 000,001,537 | ---- | C] () -- C:\Users\Mark\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Explorer.lnk
[2012/09/07 18:29:44 | 000,001,537 | ---- | C] () -- C:\Users\Mark\Desktop\Windows Explorer.lnk
[2012/09/07 17:47:10 | 000,000,134 | ---- | C] () -- C:\Users\Mark\Desktop\Programs.lnk
[2012/08/25 11:47:12 | 001,122,273 | ---- | C] () -- C:\Users\Mark\Documents\Centauro.jpg
[2012/08/23 10:26:46 | 000,001,095 | ---- | C] () -- C:\Users\Public\Desktop\BT Desktop Help.lnk
[2012/08/22 17:38:01 | 000,001,046 | ---- | C] () -- C:\Users\Mark\Application Data\Microsoft\Internet Explorer\Quick Launch\CyberLink DVD Suite Deluxe.lnk
[2012/08/22 15:23:29 | 1238,864,448 | ---- | C] () -- C:\Users\Mark\Documents\CyberLink_MES120105-04.exe
[2012/08/21 11:51:55 | 011,912,192 | ---- | C] () -- C:\Users\Mark\Documents\New @ Condado.wps
[2012/02/06 15:36:11 | 000,000,037 | ---- | C] () -- C:\Windows\Qtw.ini
[2012/01/16 13:01:48 | 003,304,960 | ---- | C] () -- C:\Users\Mark\Dancard6.wps
[2011/11/26 13:25:20 | 000,000,064 | ---- | C] () -- C:\Windows\System32\rp_stats.dat
[2011/11/26 13:25:20 | 000,000,044 | ---- | C] () -- C:\Windows\System32\rp_rules.dat
[2011/06/16 23:42:54 | 000,000,000 | ---- | C] () -- C:\Users\Mark\AppData\Local\{0F4A96EB-8BAE-4078-A0D4-DEF926CD6265}
[2011/06/15 23:52:23 | 000,000,000 | ---- | C] () -- C:\Users\Mark\AppData\Local\{3B110506-E16A-4CEB-9457-D618758456B5}
[2011/05/31 17:41:20 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2011/05/31 17:41:20 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2011/04/09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2010/06/03 10:13:04 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/10/20 07:28:56 | 000,000,680 | ---- | C] () -- C:\Users\Mark\AppData\Local\d3d9caps.dat
[2009/04/10 16:47:51 | 000,007,887 | ---- | C] () -- C:\Users\Mark\AppData\Roaming\pcouffin.cat
[2009/04/10 16:47:51 | 000,001,144 | ---- | C] () -- C:\Users\Mark\AppData\Roaming\pcouffin.inf
[2009/02/17 11:09:36 | 000,000,000 | ---- | C] () -- C:\ProgramData\LauncherAccess.dt
[2008/10/06 16:38:15 | 000,038,400 | ---- | C] () -- C:\Users\Mark\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/08/20 12:38:24 | 000,033,046 | ---- | C] () -- C:\Users\Mark\AppData\Roaming\wklnhst.dat
========== LOP Check ==========
[2011/05/07 11:16:55 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\acccore
[2009/09/06 20:34:15 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Alawar
[2009/02/17 10:40:27 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Amazon
[2009/06/30 21:38:18 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2010/04/25 19:27:58 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\eGames
[2010/04/09 10:13:04 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Farm Mania
[2010/09/17 21:23:27 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Friday's games
[2009/05/06 19:49:47 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Gamelab
[2012/09/08 18:51:33 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\GetRightToGo
[2010/03/21 13:47:36 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Home Sweet Home Christmas
[2012/05/03 20:15:14 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\LEGO Company
[2009/10/27 18:20:58 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Nokia
[2009/09/09 18:44:51 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\PC Suite
[2010/03/18 19:45:29 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\PlayFirst
[2011/04/11 19:10:56 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Registry Mechanic
[2011/11/01 21:45:06 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Research In Motion
[2012/09/07 18:52:56 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Samsung
[2009/03/26 08:21:14 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\SaveThePuppy
[2010/02/21 10:53:27 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\SBTT
[2010/10/19 17:13:52 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Template
[2009/09/06 20:31:44 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\TikGames
[2010/07/11 16:47:57 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\TomTom
[2012/09/08 21:58:21 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\uTorrent
[2012/09/01 22:35:53 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Vso
[2009/12/28 13:58:24 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Wild Tangent
[2011/03/29 18:29:31 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\WildTangent
[2008/11/19 22:03:40 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\WinBatch
[2012/09/16 20:18:41 | 000,032,600 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 64 bytes -> C:\Users\Mark\Documents\snow angel.MOV:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Mark\Documents\sliding on snow.MOV:TOC.WMV
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP

FC5A2B2
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP

1B5B4F1
< End of report >