Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

ACER Laptop oh so slow! [Closed]


  • This topic is locked This topic is locked

#1
abooboo

abooboo

    Member

  • Member
  • PipPip
  • 12 posts
ACER with windows 7 64 bit,cripplingly slow. It is slow with outlook 2007(tried several fixes to speed it up), Any web browser very slow to react. Programs open very slowly. Scanned with avg, trend micro, and several other on line scanners. Any help greatly appreciated. Just found and registered on this site. It seems very helpful. Tanks in advance for any suggestions. OTL results as follows:


OTL logfile created on: 12/4/2013 11:13:52 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Alex\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16428)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.84 Gb Total Physical Memory | 1.23 Gb Available Physical Memory | 32.10% Memory free
7.68 Gb Paging File | 3.60 Gb Available in Paging File | 46.89% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 449.66 Gb Total Space | 385.66 Gb Free Space | 85.77% Space Free | Partition Type: NTFS
Drive E: | 7.16 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive F: | 931.48 Gb Total Space | 881.02 Gb Free Space | 94.58% Space Free | Partition Type: NTFS
Drive J: | 5.46 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive K: | 7.62 Gb Total Space | 7.62 Gb Free Space | 100.00% Space Free | Partition Type: FAT32

Computer Name: ALEX-PC | User Name: Alex | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/12/04 23:08:43 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Alex\Desktop\OTL.exe
PRC - [2013/11/27 00:45:54 | 001,383,232 | ---- | M] (Spigot, Inc.) -- C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe
PRC - [2013/11/27 00:41:58 | 000,807,800 | ---- | M] (Spigot, Inc.) -- C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe
PRC - [2013/11/25 03:19:24 | 004,026,656 | ---- | M] (Conduit) -- C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe
PRC - [2013/11/25 03:19:24 | 001,735,968 | ---- | M] (Conduit) -- C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe
PRC - [2013/11/21 19:30:54 | 002,334,384 | ---- | M] () -- C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
PRC - [2013/11/21 19:30:54 | 001,643,696 | ---- | M] (AVG Secure Search) -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.1.3\ToolbarUpdater.exe
PRC - [2013/11/21 19:30:53 | 000,161,968 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.1.3\loggingserver.exe
PRC - [2013/11/15 08:23:06 | 001,392,480 | ---- | M] () -- C:\Program Files (x86)\Opera\18.0.1284.49\opera_crashreporter.exe
PRC - [2013/11/15 08:23:05 | 043,702,624 | ---- | M] (Opera Software) -- C:\Program Files (x86)\Opera\18.0.1284.49\opera.exe
PRC - [2013/11/11 22:02:14 | 003,478,544 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
PRC - [2013/11/07 22:03:50 | 004,956,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgui.exe
PRC - [2013/11/01 14:11:20 | 000,067,584 | ---- | M] (PasswordBox, Inc.) -- C:\Program Files (x86)\PasswordBox\pbbtnService.exe
PRC - [2013/09/24 01:33:08 | 000,348,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
PRC - [2013/09/23 02:35:23 | 000,296,096 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
PRC - [2013/09/17 11:25:46 | 000,415,024 | ---- | M] () -- C:\Windows\SysWOW64\jmdp\stij.exe
PRC - [2013/09/08 16:55:33 | 006,827,008 | ---- | M] (Bandoo Media Inc.) -- C:\Users\Alex\AppData\Local\iLivid\iLivid.exe
PRC - [2013/09/04 04:16:46 | 000,844,656 | ---- | M] (Samsung) -- C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
PRC - [2013/09/04 04:16:42 | 000,311,152 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
PRC - [2013/09/04 04:16:40 | 001,564,528 | ---- | M] (Samsung) -- C:\Program Files (x86)\Samsung\Kies\Kies.exe
PRC - [2013/09/03 07:53:50 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/08/29 14:34:56 | 000,048,200 | ---- | M] () -- C:\Windows\SysWOW64\C2MP\UpdateChecker.exe
PRC - [2013/08/14 16:19:24 | 000,039,056 | ---- | M] () -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
PRC - [2013/04/04 13:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2013/04/04 13:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2013/04/04 13:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/19 22:10:10 | 001,177,536 | R--- | M] (Western Digital ) -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe
PRC - [2012/09/19 22:10:06 | 001,157,056 | R--- | M] (Western Digital ) -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
PRC - [2012/09/19 22:03:58 | 005,236,664 | R--- | M] (Western Digital Technologies, Inc.) -- C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
PRC - [2012/09/06 11:50:24 | 000,248,248 | R--- | M] (Western Digital) -- C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
PRC - [2012/09/06 11:48:44 | 001,688,008 | R--- | M] (Western Digital) -- C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe
PRC - [2012/08/26 21:03:50 | 001,088,280 | ---- | M] (Mischel Internet Security) -- C:\Program Files (x86)\TrojanHunter 5.5\THGuard.exe
PRC - [2012/04/06 21:29:22 | 000,022,120 | ---- | M] () -- C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
PRC - [2012/04/06 21:29:20 | 000,040,552 | ---- | M] () -- C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
PRC - [2012/03/23 03:33:44 | 000,355,920 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe
PRC - [2012/03/23 03:33:44 | 000,343,632 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LMworker.exe
PRC - [2012/03/23 03:33:42 | 001,105,488 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2012/02/29 07:49:06 | 000,028,264 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
PRC - [2012/02/26 13:01:56 | 000,291,608 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
PRC - [2012/02/19 20:41:40 | 000,072,864 | ---- | M] (Atheros) -- C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe
PRC - [2012/02/06 18:54:04 | 000,255,376 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe
PRC - [2012/01/05 15:22:10 | 000,256,536 | ---- | M] (NTI Corporation) -- C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
PRC - [2012/01/05 15:21:44 | 000,296,984 | ---- | M] (NTI Corporation) -- C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
PRC - [2011/12/15 22:38:48 | 000,363,800 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2011/12/15 22:38:46 | 000,277,784 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2011/12/15 22:38:24 | 000,161,560 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
PRC - [2011/11/29 21:04:56 | 000,013,592 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2011/05/20 10:44:32 | 000,986,208 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
PRC - [2011/04/25 03:24:16 | 000,726,976 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
PRC - [2011/04/25 03:22:40 | 000,305,088 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\Citrix\ICA Client\concentr.exe


========== Modules (No Company Name) ==========

MOD - [2013/11/26 22:09:06 | 016,237,448 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll
MOD - [2013/11/21 19:30:54 | 002,334,384 | ---- | M] () -- C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
MOD - [2013/11/21 19:30:54 | 000,521,904 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.1.3\log4cplusU.dll
MOD - [2013/11/21 19:30:54 | 000,145,072 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.1.3\SiteSafety.dll
MOD - [2013/11/15 08:23:08 | 000,886,624 | ---- | M] () -- C:\Program Files (x86)\Opera\18.0.1284.49\libGLESv2.dll
MOD - [2013/11/15 08:23:08 | 000,108,896 | ---- | M] () -- C:\Program Files (x86)\Opera\18.0.1284.49\libEGL.dll
MOD - [2013/11/15 08:23:07 | 000,879,968 | ---- | M] () -- C:\Program Files (x86)\Opera\18.0.1284.49\ffmpegsumo.dll
MOD - [2013/11/15 08:23:06 | 001,392,480 | ---- | M] () -- C:\Program Files (x86)\Opera\18.0.1284.49\opera_crashreporter.exe
MOD - [2013/10/09 05:49:22 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ef0a534be135cd8f0d99d938d8b1814a\System.Windows.Forms.ni.dll
MOD - [2013/10/09 05:23:29 | 000,786,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc9d#\5b44a8db5b70143f27fb695b5f72930d\System.Runtime.Remoting.ni.dll
MOD - [2013/10/09 05:23:25 | 003,910,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\18e76c3868d682a7c065bccd142eeec1\WindowsBase.ni.dll
MOD - [2013/10/09 05:23:13 | 006,998,016 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\d913e7d0b1d32187e0c234f8a1a581fc\System.Core.ni.dll
MOD - [2013/10/09 05:22:57 | 000,964,096 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\edb27e2c25837f79902054965d6813cd\System.Configuration.ni.dll
MOD - [2013/09/23 05:55:54 | 002,704,352 | ---- | M] () -- c:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll
MOD - [2013/09/17 11:25:46 | 000,415,024 | ---- | M] () -- C:\Windows\SysWOW64\jmdp\stij.exe
MOD - [2013/09/17 11:23:08 | 001,062,912 | ---- | M] () -- C:\Windows\SysWOW64\jmdp\lmrn.dll
MOD - [2013/09/10 13:45:00 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5aa44bce7933e4de09d935848f868a4b\System.Drawing.ni.dll
MOD - [2013/09/10 13:44:31 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5d22a30e587e2cac106b81fb351e7c08\System.ni.dll
MOD - [2013/09/10 13:44:25 | 011,499,520 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9a6c1b7af18b4d5a91dc7f8d6617522f\mscorlib.ni.dll
MOD - [2013/09/10 11:45:26 | 000,220,160 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb78#\9ebb29485ad98aa062204cf08fc89167\System.ServiceProcess.ni.dll
MOD - [2013/09/10 11:37:14 | 007,566,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\82d58d49946f82eb56bae40f3b097784\System.Xml.ni.dll
MOD - [2013/09/10 11:37:08 | 001,880,576 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\f4fff5d6e716c439b944025d3994170d\System.Xaml.ni.dll
MOD - [2013/09/10 11:37:05 | 018,545,152 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\775d60de39c6f0b49f1640c4e6c8de09\PresentationFramework.ni.dll
MOD - [2013/09/10 11:36:50 | 010,926,592 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\8e3d6080e8eaaaf28389f3742ff9acdd\PresentationCore.ni.dll
MOD - [2013/09/10 11:36:37 | 009,937,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ac79b74f022d9a096de2b884f4249543\System.ni.dll
MOD - [2013/09/10 11:21:53 | 016,547,328 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\bf2ecabcd96ec8238dc385b0a3ffa084\mscorlib.ni.dll
MOD - [2013/08/29 14:34:56 | 000,048,200 | ---- | M] () -- C:\Windows\SysWOW64\C2MP\UpdateChecker.exe
MOD - [2013/07/10 19:07:22 | 000,756,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL
MOD - [2012/04/06 21:29:22 | 000,022,120 | ---- | M] () -- C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
MOD - [2012/04/06 21:29:20 | 000,040,552 | ---- | M] () -- C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
MOD - [2012/01/05 15:22:36 | 000,465,344 | ---- | M] () -- C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll


========== Services (SafeList) ==========

SRV:64bit: - [2013/12/03 03:02:37 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013/09/17 11:25:42 | 001,761,584 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\dmwu.exe -- (IBUpdaterService)
SRV:64bit: - [2013/06/13 13:31:10 | 000,357,144 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2013/05/26 23:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2012/08/23 12:57:48 | 000,502,064 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\mcafee\virusscan\mcods.exe -- (McODS)
SRV:64bit: - [2012/02/22 14:48:32 | 000,162,192 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\SysNative\mfevtps.exe -- (mfevtp)
SRV:64bit: - [2012/02/22 14:21:42 | 000,210,584 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)
SRV:64bit: - [2012/02/22 14:21:16 | 000,199,272 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
SRV:64bit: - [2012/02/07 18:53:48 | 000,871,296 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe -- (ePowerSvc)
SRV:64bit: - [2012/02/06 18:54:04 | 000,255,376 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Live Updater Service)
SRV:64bit: - [2011/12/12 01:00:00 | 000,135,824 | ---- | M] (Seiko Epson Corporation) [Auto | Running] -- C:\Windows\SysNative\escsvc64.exe -- (EpsonScanSvc)
SRV:64bit: - [2011/12/08 17:38:24 | 000,607,456 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel®
SRV:64bit: - [2011/01/28 13:28:54 | 000,225,216 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- c:\Program Files\mcafee\msc\McAWFwk.exe -- (McAWFwk)
SRV:64bit: - [2011/01/27 19:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (MSK80Service)
SRV:64bit: - [2011/01/27 19:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McProxy)
SRV:64bit: - [2011/01/27 19:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McOobeSv)
SRV:64bit: - [2011/01/27 19:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McNASvc)
SRV:64bit: - [2011/01/27 19:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV:64bit: - [2011/01/27 19:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (mcmscsvc)
SRV:64bit: - [2011/01/27 19:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV:64bit: - [2011/01/27 19:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)
SRV:64bit: - [2010/09/22 19:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2013/12/03 11:08:34 | 000,000,000 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\escsvc64.exe -- (EpsonScanSvc)
SRV - [2013/12/03 11:08:33 | 000,000,000 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\mfevtps.exe -- (mfevtp)
SRV - [2013/12/03 11:08:32 | 000,000,000 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\dmwu.exe -- (IBUpdaterService)
SRV - [2013/12/03 11:08:31 | 000,000,000 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\spoolsv.exe -- (Spooler)
SRV - [2013/12/03 11:07:54 | 000,000,000 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\lsass.exe -- (VaultSvc)
SRV - [2013/12/03 11:07:54 | 000,000,000 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\lsass.exe -- (SamSs)
SRV - [2013/12/03 11:07:54 | 000,000,000 | ---- | M] () [On_Demand | Running] -- C:\Windows\SysWOW64\lsass.exe -- (ProtectedStorage)
SRV - [2013/12/03 11:07:54 | 000,000,000 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\lsass.exe -- (Netlogon)
SRV - [2013/12/03 11:07:54 | 000,000,000 | ---- | M] () [On_Demand | Running] -- C:\Windows\SysWOW64\lsass.exe -- (KeyIso)
SRV - [2013/12/03 11:07:54 | 000,000,000 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\lsass.exe -- (EFS)
SRV - [2013/11/27 00:41:58 | 000,807,800 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe -- (Application Updater)
SRV - [2013/11/26 22:09:07 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/11/25 03:19:24 | 001,735,968 | ---- | M] (Conduit) [Auto | Running] -- C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe -- (CltMngSvc)
SRV - [2013/11/21 19:30:54 | 001,643,696 | ---- | M] (AVG Secure Search) [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.1.3\ToolbarUpdater.exe -- (vToolbarUpdater17.1.3)
SRV - [2013/11/11 22:02:14 | 003,478,544 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2013/11/06 09:51:20 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/11/01 14:11:20 | 000,067,584 | ---- | M] (PasswordBox, Inc.) [Auto | Running] -- C:\Program Files (x86)\PasswordBox\pbbtnService.exe -- (PasswordBox)
SRV - [2013/09/24 01:33:08 | 000,348,008 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe -- (avgwd)
SRV - [2013/09/05 18:41:08 | 000,240,736 | ---- | M] (WildTangent) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe -- (GamesAppIntegrationService)
SRV - [2013/09/03 07:53:50 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/08/14 16:19:24 | 000,039,056 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
SRV - [2013/04/04 13:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013/04/04 13:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2013/04/04 07:44:48 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2012/09/19 22:10:10 | 001,177,536 | R--- | M] (Western Digital ) [Auto | Running] -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe -- (WDRulesService)
SRV - [2012/09/19 22:10:06 | 001,157,056 | R--- | M] (Western Digital ) [Auto | Running] -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe -- (WDBackup)
SRV - [2012/09/06 11:50:24 | 000,248,248 | R--- | M] (Western Digital) [Auto | Running] -- C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe -- (WDDriveService)
SRV - [2012/07/09 01:40:10 | 000,104,912 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2012/03/23 03:33:44 | 000,355,920 | ---- | M] (Dritek System Inc.) [Auto | Running] -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe -- (DsiWMIService)
SRV - [2012/03/08 18:49:30 | 000,107,648 | ---- | M] (Atheros Commnucations) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\AdminService.exe -- (AtherosSvc)
SRV - [2012/02/29 07:49:06 | 000,028,264 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe -- (GREGService)
SRV - [2012/02/19 20:41:40 | 000,072,864 | ---- | M] (Atheros) [Auto | Running] -- C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe -- (ZAtheros Wlan Agent)
SRV - [2012/02/19 06:18:18 | 000,276,248 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2012/02/10 03:41:36 | 000,111,776 | ---- | M] (Atheros Communication Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Acer\WDAgent\DCDhcpService.exe -- (DCDhcpService)
SRV - [2012/01/05 15:22:10 | 000,256,536 | ---- | M] (NTI Corporation) [Auto | Running] -- C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2011/12/15 22:38:48 | 000,363,800 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2011/12/15 22:38:46 | 000,277,784 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2011/12/15 22:38:24 | 000,161,560 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe -- (jhi_service)
SRV - [2011/11/29 21:04:56 | 000,013,592 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV - [2011/08/31 07:11:40 | 002,425,960 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Running] -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe -- (IconMan_R)
SRV - [2011/06/21 13:55:04 | 000,173,424 | ---- | M] (Egis Technology Inc. ) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe -- (EgisTec Ticket Service)
SRV - [2010/10/12 11:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010/06/01 16:31:28 | 002,804,568 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
SRV - [2009/06/10 15:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/11/21 19:30:54 | 000,046,368 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:64bit: - [2013/11/05 21:55:48 | 000,150,808 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgdiska.sys -- (Avgdiska)
DRV:64bit: - [2013/11/04 21:52:42 | 000,240,920 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
DRV:64bit: - [2013/10/31 23:00:18 | 000,212,280 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2013/10/31 22:49:46 | 000,294,712 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgloga.sys -- (Avgloga)
DRV:64bit: - [2013/10/24 22:25:58 | 000,194,872 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA)
DRV:64bit: - [2013/10/01 00:52:08 | 000,123,704 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:64bit: - [2013/09/11 10:20:00 | 000,016,152 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SWDUMon.sys -- (SWDUMon)
DRV:64bit: - [2013/09/10 00:43:02 | 000,031,544 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:64bit: - [2013/08/20 08:02:12 | 000,103,576 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2013/08/01 17:07:06 | 000,251,192 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:64bit: - [2013/07/31 05:23:57 | 000,139,352 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AnyDVD.sys -- (AnyDVD)
DRV:64bit: - [2013/05/23 00:12:52 | 000,059,160 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2013/05/23 00:12:50 | 000,076,568 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2013/05/23 00:12:48 | 000,077,592 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LEqdUsb.sys -- (LEqdUsb)
DRV:64bit: - [2013/05/23 00:12:48 | 000,013,080 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidEqd.sys -- (LHidEqd)
DRV:64bit: - [2013/04/04 13:50:32 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2013/03/04 06:24:27 | 000,040,344 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2012/08/23 08:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/23 08:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2012/08/23 08:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012/07/17 17:12:08 | 000,062,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2012/05/02 00:14:34 | 000,062,776 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV:64bit: - [2012/05/02 00:14:34 | 000,022,648 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV:64bit: - [2012/05/02 00:14:34 | 000,020,520 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV:64bit: - [2012/03/08 19:00:36 | 000,551,552 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:64bit: - [2012/03/08 18:59:42 | 000,281,472 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV:64bit: - [2012/03/08 18:59:24 | 000,068,736 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:64bit: - [2012/03/08 18:58:54 | 000,168,064 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV:64bit: - [2012/03/08 18:58:36 | 000,036,480 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_flt.sys -- (AthBTPort)
DRV:64bit: - [2012/03/08 18:58:18 | 000,030,848 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:64bit: - [2012/03/08 18:58:00 | 000,111,232 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_avdt.sys -- (btath_avdt)
DRV:64bit: - [2012/03/08 18:57:42 | 000,340,096 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV:64bit: - [2012/03/07 07:48:20 | 000,238,384 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
DRV:64bit: - [2012/03/01 00:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/02/26 13:01:00 | 000,788,760 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc)
DRV:64bit: - [2012/02/26 13:01:00 | 000,356,120 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub)
DRV:64bit: - [2012/02/26 13:01:00 | 000,016,152 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs)
DRV:64bit: - [2012/02/22 13:29:46 | 000,647,208 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
DRV:64bit: - [2012/02/22 13:29:46 | 000,487,296 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfefirek.sys -- (mfefirek)
DRV:64bit: - [2012/02/22 13:29:46 | 000,289,664 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfewfpk)
DRV:64bit: - [2012/02/22 13:29:46 | 000,229,528 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
DRV:64bit: - [2012/02/22 13:29:46 | 000,160,792 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeapfk.sys -- (mfeapfk)
DRV:64bit: - [2012/02/22 13:29:46 | 000,100,912 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdet.sys -- (mferkdet)
DRV:64bit: - [2012/02/22 13:29:46 | 000,075,936 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mfenlfk.sys -- (mfenlfk)
DRV:64bit: - [2012/02/22 13:29:46 | 000,065,264 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cfwids.sys -- (cfwids)
DRV:64bit: - [2012/02/15 02:41:34 | 003,538,432 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2012/02/13 20:47:36 | 014,692,224 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2012/02/07 00:03:06 | 000,018,432 | ---- | M] (NTI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV:64bit: - [2012/02/07 00:03:06 | 000,017,408 | ---- | M] (NTI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper)
DRV:64bit: - [2011/12/05 13:23:08 | 000,331,264 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2011/11/29 20:40:32 | 000,568,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011/10/13 23:49:22 | 000,108,656 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2011/09/01 21:46:28 | 000,339,048 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsPStor.sys -- (RSPCIESTOR)
DRV:64bit: - [2011/07/13 23:35:47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/07/13 23:35:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/04/25 02:49:16 | 000,087,600 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ctxusbm.sys -- (ctxusbm)
DRV:64bit: - [2011/02/16 15:29:46 | 000,017,008 | ---- | M] (VIA Labs, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vl810filter.sys -- (vl810filter)
DRV:64bit: - [2011/01/19 20:05:04 | 000,020,552 | ---- | M] (Devguru Co., Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dgderdrv.sys -- (dgderdrv)
DRV:64bit: - [2011/01/19 19:59:18 | 000,016,392 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TFsExDisk.sys -- (TFsExDisk)
DRV:64bit: - [2010/11/20 21:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/12/30 12:21:26 | 000,031,800 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\revoflt.sys -- (Revoflt)
DRV:64bit: - [2009/07/13 19:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 19:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 19:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 18:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2009/07/13 18:35:37 | 000,025,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WSDScan.sys -- (WSDScan)
DRV:64bit: - [2009/06/10 14:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 14:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 14:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 14:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2008/05/06 17:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
DRV - [2013/07/31 05:23:57 | 000,139,352 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2011/01/19 19:59:18 | 000,016,392 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys -- (TFsExDisk)
DRV - [2009/07/13 19:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {7e8a1050-cf67-4575-92df-dcc60e7d952d} - C:\Program Files (x86)\SweetPacks\prxtbSwee.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {679E83C6-CE15-4AA5-B8B5-1B0AED2D74A1}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.searchgol...3_sgol&tsp=5023
IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bbvacompass.com/
IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\URLSearchHook: {7e8a1050-cf67-4575-92df-dcc60e7d952d} - C:\Program Files (x86)\SweetPacks\prxtbSwee.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\URLSearchHook: {B9C767DD-F66A-40B4-8F12-4199A9A4393C} - C:\Program Files (x86)\SearchMe Toolbar\IE\8.3\searchmeToolbarIE.dll (Spigot, Inc.)
IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\SearchScopes,DefaultScope = {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}: "URL" = http://search.condui...rchTerms}&SSPV=
IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.searchgol...3_sgol&tsp=5023
IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\SearchScopes\{62F35670-FB5A-4894-BE5D-BEA473F4683A}: "URL" = http://search.condui...q={searchTerms}
IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\SearchScopes\{679E83C6-CE15-4AA5-B8B5-1B0AED2D74A1}: "URL" = http://search.condui...7651670315&UM=2
IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://mysearch.avg....sa&d=2013-09-18 01:07:47&v=17.1.2.1&pid=safeguard&sg=23&sap=dsp&q={searchTerms}
IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\SearchScopes\{B4D04864-F7F0-453F-9C0E-F8BB3BED17AC}: "URL" = http://search.yahoo....p={searchTerms}
IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..CT3291325.browser.search.defaultthis.engineName: true
FF - prefs.js..CT3310511.browser.search.defaultthis.engineName: "true"
FF - prefs.js..browser.search.defaultenginename: "SweetPacks Customized Web Search"
FF - prefs.js..browser.search.defaultthis.engineName: "SweetPacks Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.condui...={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=888596"
FF - prefs.js..browser.search.selectedEngine: "Conduit Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://search.condui...3AB61157&SSPV="
FF - prefs.js..extensions.enabledAddons: secureLogin%40blueimp.net:1.0.3
FF - prefs.js..extensions.enabledAddons: autofillForms%40blueimp.net:0.9.9.0
FF - prefs.js..extensions.enabledAddons: %7B277c4e95-2731-4488-8450-7714a3c30da1%7D:1.0
FF - prefs.js..extensions.enabledAddons: ffxtlbr%40searchgol.com:1.6.0
FF - prefs.js..extensions.enabledAddons: artur.dubovoy%40gmail.com:4.0.5
FF - prefs.js..extensions.enabledAddons: %7BA81031F3-6CEE-4A19-809F-4E26C1D9C1D1%7D:8.86.0.0
FF - prefs.js..extensions.enabledAddons: searchme%40mybrowserbar.com:8.2
FF - prefs.js..extensions.enabledAddons: %7B7e8a1050-cf67-4575-92df-dcc60e7d952d%7D:10.22.5.10
FF - prefs.js..extensions.enabledAddons: %7B4ED1F68A-5463-4931-9384-8FFF5ED91D92%7D:3.6.3
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:25.0
FF - prefs.js..keyword.URL: "http://search.condui...369158&UM=2&q="


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.1.3\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.52: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@logitech.com/HarmonyRemote,version=1.0.0: C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.5.109: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.5.109: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.5.109: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.5.109: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.5.109: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2013/10/09 05:45:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2013/09/11 09:11:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F003DA68-8256-4b37-A6C4-350FA04494DF}: C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2013/09/11 17:01:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2013/09/12 09:44:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.1.3.3 [2013/11/21 19:31:21 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/09/21 06:38:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/09/21 06:38:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\PasswordBox\Firefox [2013/11/21 19:31:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.8\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013/09/10 18:14:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins

[2013/09/10 16:26:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Extensions
[2010/10/23 07:38:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011/05/15 14:42:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Extensions\[email protected]
[2013/11/27 10:26:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions
[2013/09/10 17:39:03 | 000,000,000 | ---D | M] (XUL Cache) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{277c4e95-2731-4488-8450-7714a3c30da1}
[2013/09/10 17:39:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{635ABD67-4FE9-1B23-4F01-E679FA7484C1}-TRASH
[2013/11/21 12:08:44 | 000,000,000 | ---D | M] (SweetPacks) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}
[2013/11/01 16:20:38 | 000,000,000 | ---D | M] (iMacros for Firefox) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
[2013/09/10 17:39:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}-TRASH
[2013/10/27 13:04:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]
[2013/10/02 10:38:16 | 000,000,000 | ---D | M] (SearchGol) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]
[2013/10/27 13:03:38 | 000,000,000 | ---D | M] (Translate Genius) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]
[2013/10/23 19:49:26 | 000,040,867 | ---- | M] () (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]
[2013/11/06 09:03:46 | 000,342,563 | ---- | M] () (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]
[2012/12/14 10:22:18 | 000,149,045 | ---- | M] () (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]
[2012/12/12 16:11:20 | 000,083,379 | ---- | M] () (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]
[2013/10/23 11:24:31 | 000,331,553 | ---- | M] () (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]
[2013/11/08 05:10:47 | 000,048,768 | ---- | M] () (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{A81031F3-6CEE-4A19-809F-4E26C1D9C1D1}.xpi
[2013/12/03 03:10:31 | 000,000,880 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\conduit-search.xml
[2013/12/04 05:30:13 | 000,002,115 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\MyStart Search.xml
[2013/11/21 19:30:44 | 000,003,736 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\safeguard-secure-search.xml
[2013/09/23 15:03:00 | 000,001,988 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\search.xml
[2013/10/02 10:38:20 | 000,001,302 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\searchgol.xml
[2013/11/26 12:40:16 | 000,001,094 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\sweetpacks-customized-web-search.xml
[2013/09/14 14:44:35 | 000,000,904 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\yahoo.xml
[2012/09/13 07:48:16 | 000,004,140 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\youtube.xml
[2013/11/06 09:51:03 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\Extensions
[2013/11/06 09:51:03 | 000,000,000 | ---D | M] () -- C:\Program Files (x86)\Mozilla Firefox\Extensions\[email protected]
[2013/11/06 09:51:01 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013/11/06 09:51:23 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/10/09 05:45:09 | 000,000,000 | ---D | M] (McAfee SiteAdvisor) -- C:\PROGRAM FILES (X86)\MCAFEE\SITEADVISOR
[2013/11/27 10:26:34 | 000,000,000 | ---D | M] (SearchMe Toolbar) -- C:\PROGRAM FILES (X86)\SEARCHME TOOLBAR\FF
CHR - Extension: No name found = C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.6.3.1271_0\
CHR - Extension: No name found = C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.6.3.1271_1\
CHR - Extension: No name found = C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj\1.0_0\
CHR - Extension: No name found = C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.1_0\
CHR - Extension: No name found = C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.1_1\
CHR - Extension: No name found = C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.4_0\
CHR - Extension: No name found = C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.4_1\
CHR - Extension: No name found = C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\
CHR - Extension: No name found = C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\omaonpoimgkmbllpdihbnmgphjoipdhf\1.2.0.0_0\
CHR - Extension: No name found = C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp\1.0_0\

O1 HOSTS File: ([2013/11/21 12:08:52 | 000,001,349 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.2 pagead2.googlesyndication.com
O1 - Hosts: 127.0.0.2 googleadservices.com
O1 - Hosts: 127.0.0.2 www.googleadservices.com
O1 - Hosts: 127.0.0.2 partner.googleadservices.com
O1 - Hosts: 127.0.0.2 doubleclick.net
O1 - Hosts: 127.0.0.2 g.doubleclick.net
O1 - Hosts: 127.0.0.2 googleads.g.doubleclick.net
O1 - Hosts: 127.0.0.2 securepubads.g.doubleclick.net
O1 - Hosts: 127.0.0.2 ad.doubleclick.net
O1 - Hosts: 127.0.0.2 pubads.g.doubleclick.net
O1 - Hosts: 127.0.0.2 adclick.g.doubleclick.net
O1 - Hosts: 127.0.0.2 stats.g.doubleclick.net
O1 - Hosts: 127.0.0.2 fls.doubleclick.net
O1 - Hosts: 127.0.0.2 ad-emea.doubleclick.net
O1 - Hosts: 127.0.0.2 googletagservices.com
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\mcafee\systemcore\ScriptSn.20130911224208.dll (McAfee, Inc.)
O2:64bit: - BHO: (Logitech SetPoint) - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (E-Web Print) - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\EPSON Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (PasswordBox Helper) - {5DB69B97-934B-451D-94DB-32EF802A01CD} - C:\Program Files (x86)\PasswordBox\Application\pbbtn.dll (PasswordBox, Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptSn.20130911224208.dll (McAfee, Inc.)
O2 - BHO: (SweetPacks Toolbar) - {7e8a1050-cf67-4575-92df-dcc60e7d952d} - C:\Program Files (x86)\SweetPacks\prxtbSwee.dll (Conduit Ltd.)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (searchgol Helper Object) - {8F547BDD-FCD4-48F8-A06F-573D6F404A3C} - C:\Program Files (x86)\searchgol\searchgol\1.8.16.19\bh\searchgol.dll (Montera Technologeis LTD)
O2 - BHO: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.1.3.3\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
O2 - BHO: (Logitech SetPoint) - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (SearchMe Toolbar) - {B9C767DD-F66A-40B4-8F12-4199A9A4393C} - C:\Program Files (x86)\SearchMe Toolbar\IE\8.3\searchmeToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (SearchMe Toolbar) - {B9C767DD-F66A-40B4-8F12-4199A9A4393C} - C:\Program Files (x86)\SearchMe Toolbar\IE\8.3\searchmeToolbarIE64.dll (Spigot, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (searchgol Toolbar) - {00078E95-3A4A-4137-8DE7-2824908D1C17} - C:\Program Files (x86)\searchgol\searchgol\1.8.16.19\searchgolTlbr.dll (Montera Technologeis LTD)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (E-Web Print) - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\EPSON Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (SweetPacks Toolbar) - {7e8a1050-cf67-4575-92df-dcc60e7d952d} - C:\Program Files (x86)\SweetPacks\prxtbSwee.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.1.3.3\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
O3 - HKLM\..\Toolbar: (SearchMe Toolbar) - {B9C767DD-F66A-40B4-8F12-4199A9A4393C} - C:\Program Files (x86)\SearchMe Toolbar\IE\8.3\searchmeToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\Toolbar\WebBrowser: (SweetPacks Toolbar) - {7E8A1050-CF67-4575-92DF-DCC60E7D952D} - C:\Program Files (x86)\SweetPacks\prxtbSwee.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [AthBtTray] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations)
O4:64bit: - HKLM..\Run: [AtherosBtStack] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations)
O4:64bit: - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [InstantUpdate] C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuDaemon.exe ()
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Power Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [RtHDVBg_Dolby] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (NTI Corporation)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [Dolby Home Theater v4] C:\Dolby PCEE4\pcee4.exe (Dolby Laboratories Inc.)
O4 - HKLM..\Run: [KBD] C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.exe (Microsoft)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [THGuard] C:\Program Files (x86)\TrojanHunter 5.5\THGuard.exe (Mischel Internet Security)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe (Simply Super Software)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe ()
O4 - HKLM..\Run: [WD Drive Unlocker] C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe (Western Digital)
O4 - HKLM..\Run: [WD Quick View] C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe (Western Digital Technologies, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-128065933-3734797803-567976751-1000..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKU\S-1-5-21-128065933-3734797803-567976751-1000..\Run: [BackgroundContainer] C:\Users\Alex\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll (Conduit Ltd.)
O4 - HKU\S-1-5-21-128065933-3734797803-567976751-1000..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIJHE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-3540 Series" /EF "HKCU" File not found
O4 - HKU\S-1-5-21-128065933-3734797803-567976751-1000..\Run: [iLivid] C:\Users\Alex\AppData\Local\iLivid\iLivid.exe (Bandoo Media Inc.)
O4 - HKU\S-1-5-21-128065933-3734797803-567976751-1000..\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKU\S-1-5-21-128065933-3734797803-567976751-1000..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
O4 - HKU\S-1-5-21-128065933-3734797803-567976751-1000..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-128065933-3734797803-567976751-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} http://ax.emsisoft.com/asquared.cab (a-squared Scanner)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2E23478C-DA8C-4B98-93F2-54E112B15DFC}: DhcpNameServer = 192.168.4.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{32002B34-91D4-4CBD-90FD-676BCF1395D5}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.1.3\ViProtocol.dll (AVG Secure Search)
O18:64bit: - Protocol\Filter\application/x-ica - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=euc-jp - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=ISO-8859-1 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS936 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS949 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS950 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=UTF8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=UTF-8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=euc-jp - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=ISO-8859-1 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS936 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS949 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS950 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=UTF8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=UTF-8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
O18:64bit: - Protocol\Filter\ica - No CLSID value found
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll) - C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll (Conduit)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/04/07 23:00:28 | 004,573,206 | ---- | M] ( ) - C:\AutoUnpack444.exe -- [ NTFS ]
O32 - AutoRun File - [2011/11/01 14:39:30 | 000,000,079 | ---- | M] () - E:\autorun.inf -- [ UDF ]
O32 - AutoRun File - [2007/02/12 13:53:42 | 000,000,277 | R--- | M] () - J:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{1e640001-1b02-11e3-ba03-7c05072bbfb9}\Shell - "" = AutoRun
O33 - MountPoints2\{1e640001-1b02-11e3-ba03-7c05072bbfb9}\Shell\AutoRun\command - "" = E:\WD Drive Unlock.exe -- [2012/09/06 11:48:42 | 002,018,240 | ---- | M] (Western Digital)
O33 - MountPoints2\{3dca4bff-1b39-11e3-8ca0-7c05072bbfb9}\Shell - "" = AutoRun
O33 - MountPoints2\{3dca4bff-1b39-11e3-8ca0-7c05072bbfb9}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/12/04 23:08:36 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Alex\Desktop\OTL.exe
[2013/12/04 05:37:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2013/12/03 21:08:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Outlook Attachment Remover
[2013/12/03 03:09:56 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\SearchProtect
[2013/11/28 11:01:12 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\TrojanHunter
[2013/11/28 05:54:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrojanHunter
[2013/11/28 05:54:04 | 000,000,000 | ---D | C] -- C:\ProgramData\TrojanHunter
[2013/11/28 05:53:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TrojanHunter 5.5
[2013/11/28 05:50:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Licenses
[2013/11/28 05:49:58 | 000,000,000 | ---D | C] -- C:\Users\Alex\Documents\Simply Super Software
[2013/11/28 05:49:58 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Simply Super Software
[2013/11/28 05:49:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover
[2013/11/28 05:49:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trojan Remover
[2013/11/28 05:49:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software
[2013/11/27 10:26:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Application Updater
[2013/11/27 10:26:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SearchMe Toolbar
[2013/11/27 06:37:33 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\U3
[2013/11/27 06:03:03 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
[2013/11/27 06:03:03 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\IrfanView
[2013/11/27 06:03:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IrfanView
[2013/11/27 05:53:22 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\FastStone
[2013/11/27 05:48:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FastStone Image Viewer
[2013/11/27 05:48:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FastStone Image Viewer
[2013/11/27 05:45:35 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Zoner
[2013/11/27 05:45:34 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Local\Zoner
[2013/11/27 05:45:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Zoner
[2013/11/26 08:09:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/11/21 19:31:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PasswordBox
[2013/11/21 12:09:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit
[2013/11/21 12:09:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Conduit
[2013/11/21 12:09:13 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Local\Conduit
[2013/11/21 12:09:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SweetPacks
[2013/11/21 12:08:49 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\SearchProtect
[2013/11/21 12:07:22 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ljkb
[2013/11/21 12:07:21 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\jmdp
[2013/11/21 12:07:17 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\ARFC
[2013/11/21 12:07:14 | 000,033,792 | ---- | C] (IncrediMail, Ltd.) -- C:\Windows\SysNative\ImHttpComm.dll
[2013/11/21 12:02:09 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Local\SearchProtect
[2013/11/21 12:02:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SearchProtect
[2013/11/08 05:30:01 | 000,000,000 | R--D | C] -- C:\Users\Alex\Documents\My Bookmark Collections
[2013/11/08 05:09:16 | 000,000,000 | ---D | C] -- C:\Users\Alex\Documents\Linkman
[2013/11/08 05:09:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Linkman
[2013/11/06 09:51:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013/11/06 01:06:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2013/11/05 21:55:48 | 000,150,808 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgdiska.sys

========== Files - Modified Within 30 Days ==========

[2013/12/05 01:30:57 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/12/04 23:38:01 | 000,016,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/12/04 23:38:01 | 000,016,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/12/04 23:08:43 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Alex\Desktop\OTL.exe
[2013/12/04 22:25:12 | 000,785,302 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/12/04 22:25:12 | 000,664,798 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/12/04 22:25:12 | 000,122,574 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/12/04 22:21:16 | 000,067,584 | -H-- | M] () -- C:\Windows\bootstat.dat
[2013/12/04 05:29:59 | 3092,533,248 | -HS- | M] () -- C:\hiberfil.sys
[2013/12/03 21:43:03 | 000,038,085 | ---- | M] () -- C:\Users\Alex\Desktop\BrowserPasswordList.html
[2013/12/03 11:32:53 | 000,736,308 | ---- | M] () -- C:\Users\Alex\AppData\Local\census.cache
[2013/12/03 11:31:53 | 000,117,762 | ---- | M] () -- C:\Users\Alex\AppData\Local\ars.cache
[2013/12/03 11:08:40 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\igfxpers.exe
[2013/12/03 11:08:40 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\igfxext.exe
[2013/12/03 11:08:36 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\WUDFHost.exe
[2013/12/03 11:08:36 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\taskhost.exe
[2013/12/03 11:08:36 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\igfxtray.exe
[2013/12/03 11:08:36 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\igfxsrvc.exe
[2013/12/03 11:08:36 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\hkcmd.exe
[2013/12/03 11:08:34 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\escsvc64.exe
[2013/12/03 11:08:33 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\mfevtps.exe
[2013/12/03 11:08:32 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\dmwu.exe
[2013/12/03 11:08:31 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\spoolsv.exe
[2013/12/03 11:08:31 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\conhost.exe
[2013/12/03 11:07:54 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\winlogon.exe
[2013/12/03 11:07:54 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\smss.exe
[2013/12/03 11:07:54 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\services.exe
[2013/12/03 11:07:54 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\lsm.exe
[2013/12/03 11:07:54 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\lsass.exe
[2013/12/03 11:07:54 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\dwm.exe
[2013/12/03 11:07:54 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\csrss.exe
[2013/12/03 10:46:29 | 000,000,036 | ---- | M] () -- C:\Users\Alex\AppData\Local\housecall.guid.cache
[2013/12/03 03:02:41 | 000,016,284 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2013/12/03 03:02:38 | 000,016,284 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2013/11/28 05:54:12 | 000,059,392 | R--- | M] () -- C:\Windows\SysWow64\streamhlp.dll
[2013/11/28 05:54:11 | 000,001,113 | ---- | M] () -- C:\Users\Alex\Application Data\Microsoft\Internet Explorer\Quick Launch\TrojanHunter Scanner.lnk
[2013/11/21 19:31:23 | 000,003,726 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
[2013/11/21 19:30:54 | 000,046,368 | ---- | M] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/11/21 12:46:52 | 000,038,085 | ---- | M] () -- C:\BrowserPasswordList.html
[2013/11/21 12:09:37 | 000,000,000 | ---- | M] () -- C:\END
[2013/11/14 13:02:16 | 005,432,287 | ---- | M] () -- C:\Users\Alex\Documents\wf3540ug (1).pdf
[2013/11/14 12:56:13 | 000,059,527 | ---- | M] () -- C:\Users\Alex\Documents\Staley NFA Trust.pdf
[2013/11/14 12:55:16 | 000,058,500 | ---- | M] () -- C:\Users\Alex\Documents\Epson_11142013105121.pdf
[2013/11/14 12:40:53 | 000,000,000 | -H-- | M] () -- C:\Users\Alex\Documents\Default.rdp
[2013/11/05 21:55:48 | 000,150,808 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\SysNative\drivers\avgdiska.sys

========== Files Created - No Company Name ==========

[2013/12/03 21:43:03 | 000,038,085 | ---- | C] () -- C:\Users\Alex\Desktop\BrowserPasswordList.html
[2013/12/03 11:32:53 | 000,736,308 | ---- | C] () -- C:\Users\Alex\AppData\Local\census.cache
[2013/12/03 11:31:53 | 000,117,762 | ---- | C] () -- C:\Users\Alex\AppData\Local\ars.cache
[2013/12/03 11:08:40 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\igfxpers.exe
[2013/12/03 11:08:40 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\igfxext.exe
[2013/12/03 11:08:36 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\WUDFHost.exe
[2013/12/03 11:08:36 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\taskhost.exe
[2013/12/03 11:08:36 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\igfxtray.exe
[2013/12/03 11:08:36 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\igfxsrvc.exe
[2013/12/03 11:08:36 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\hkcmd.exe
[2013/12/03 11:08:34 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\escsvc64.exe
[2013/12/03 11:08:33 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\mfevtps.exe
[2013/12/03 11:08:32 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\dmwu.exe
[2013/12/03 11:08:31 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\spoolsv.exe
[2013/12/03 11:08:31 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\conhost.exe
[2013/12/03 11:07:54 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\winlogon.exe
[2013/12/03 11:07:54 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\smss.exe
[2013/12/03 11:07:54 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\services.exe
[2013/12/03 11:07:54 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\lsm.exe
[2013/12/03 11:07:54 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\lsass.exe
[2013/12/03 11:07:54 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\dwm.exe
[2013/12/03 11:07:54 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\csrss.exe
[2013/12/03 10:46:29 | 000,000,036 | ---- | C] () -- C:\Users\Alex\AppData\Local\housecall.guid.cache
[2013/12/03 03:02:41 | 000,016,284 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2013/12/03 03:02:38 | 000,016,284 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2013/11/28 05:54:11 | 000,001,113 | ---- | C] () -- C:\Users\Alex\Application Data\Microsoft\Internet Explorer\Quick Launch\TrojanHunter Scanner.lnk
[2013/11/28 05:53:59 | 000,059,392 | R--- | C] () -- C:\Windows\SysWow64\streamhlp.dll
[2013/11/21 12:46:52 | 000,038,085 | ---- | C] () -- C:\BrowserPasswordList.html
[2013/11/21 12:07:14 | 001,761,584 | ---- | C] () -- C:\Windows\SysNative\dmwu.exe
[2013/11/14 13:02:16 | 005,432,287 | ---- | C] () -- C:\Users\Alex\Documents\wf3540ug (1).pdf
[2013/11/14 12:56:13 | 000,059,527 | ---- | C] () -- C:\Users\Alex\Documents\Staley NFA Trust.pdf
[2013/11/14 12:55:16 | 000,058,500 | ---- | C] () -- C:\Users\Alex\Documents\Epson_11142013105121.pdf
[2013/11/14 12:40:53 | 000,000,000 | -H-- | C] () -- C:\Users\Alex\Documents\Default.rdp
[2013/09/25 12:18:53 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\dvdtest10024.dat
[2013/09/22 08:44:48 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib
[2013/09/21 16:40:59 | 000,000,335 | ---- | C] () -- C:\Users\Alex\AppData\Roaming\burnaware.ini
[2013/09/21 07:26:28 | 000,000,258 | RHS- | C] () -- C:\Users\Alex\ntuser.pol
[2013/09/19 03:47:58 | 000,003,726 | ---- | C] () -- C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
[2013/07/26 07:24:22 | 006,275,760 | ---- | C] () -- C:\Windows\SysWow64\avcodec-lav-55.dll
[2013/07/26 07:24:22 | 001,239,216 | ---- | C] () -- C:\Windows\SysWow64\avformat-lav-55.dll
[2013/07/26 07:24:22 | 000,394,416 | ---- | C] () -- C:\Windows\SysWow64\swscale-lav-2.dll
[2013/07/26 07:24:22 | 000,288,944 | ---- | C] () -- C:\Windows\SysWow64\avutil-lav-52.dll
[2013/07/26 07:24:22 | 000,235,184 | ---- | C] () -- C:\Windows\SysWow64\avfilter-lav-3.dll
[2013/07/26 07:24:22 | 000,190,640 | ---- | C] () -- C:\Windows\SysWow64\libbluray.dll
[2013/07/26 07:24:22 | 000,150,192 | ---- | C] () -- C:\Windows\SysWow64\avresample-lav-1.dll
[2013/06/08 05:54:10 | 003,915,776 | ---- | C] () -- C:\Windows\SysWow64\ffmpeg.dll
[2013/06/08 05:53:06 | 000,112,640 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2013/06/08 05:52:30 | 000,271,360 | ---- | C] () -- C:\Windows\SysWow64\TomsMoComp_ff.dll
[2013/06/08 05:52:12 | 000,157,184 | ---- | C] () -- C:\Windows\SysWow64\ff_unrar.dll
[2013/06/08 05:52:10 | 000,147,456 | ---- | C] () -- C:\Windows\SysWow64\ff_libmad.dll
[2013/06/08 05:52:10 | 000,099,840 | ---- | C] () -- C:\Windows\SysWow64\ff_wmv9.dll
[2013/06/08 05:52:08 | 001,525,760 | ---- | C] () -- C:\Windows\SysWow64\ff_samplerate.dll
[2013/06/08 05:52:08 | 000,211,968 | ---- | C] () -- C:\Windows\SysWow64\ff_libdts.dll
[2013/06/08 05:52:08 | 000,114,688 | ---- | C] () -- C:\Windows\SysWow64\ff_liba52.dll
[2013/06/08 05:52:06 | 000,136,704 | ---- | C] () -- C:\Windows\SysWow64\libmpeg2_ff.dll
[2013/04/04 07:19:29 | 000,778,008 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/10/12 10:40:52 | 001,622,706 | ---- | C] () -- C:\Users\Alex\Localizable.strings
[2012/09/29 16:47:28 | 000,000,178 | ---- | C] () -- C:\Windows\SysWow64\Formats.ini
[2012/05/02 00:06:26 | 000,963,912 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2012/05/02 00:06:24 | 000,261,208 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2012/05/02 00:06:19 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2012/05/02 00:06:19 | 000,058,880 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2012/05/02 00:06:18 | 013,209,600 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2011/12/08 17:14:58 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll
[2011/12/07 13:32:24 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\Lagarith.dll
[2011/05/13 08:27:44 | 000,001,288 | ---- | C] () -- C:\Users\Alex\reset.cmd

========== ZeroAccess Check ==========

[2009/07/13 22:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/07/25 20:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/25 19:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 19:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 21:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 19:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/09/10 16:26:28 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Amazon
[2013/10/25 01:17:01 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\AVG
[2013/09/09 16:14:29 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\AVG2014
[2013/10/27 13:04:27 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\BabSolution
[2013/09/10 10:41:36 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Barnes & Noble
[2013/09/10 12:04:13 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\clear.fiMVPSDK20
[2013/09/25 14:15:18 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\DefaultTab
[2013/09/11 17:36:00 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\DriverFinder
[2013/09/25 12:18:52 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\DVD-Cloner
[2013/09/25 13:36:15 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\FoozKids
[2013/09/20 11:29:57 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\HandBrake
[2013/09/17 01:53:03 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\ICAClient
[2013/11/27 06:03:03 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\IrfanView
[2013/09/11 17:01:54 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Leadertech
[2013/09/10 17:39:09 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Opera
[2013/09/09 16:18:33 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Opera Software
[2013/09/18 01:10:59 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Samsung
[2013/09/09 16:06:35 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Screensaver
[2013/11/21 12:08:49 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\SearchProtect
[2013/11/28 05:49:58 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Simply Super Software
[2013/10/23 11:24:16 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\TGF Interactive LLC
[2013/09/10 17:39:23 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Thunderbird
[2013/10/23 11:23:07 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Translate Genius
[2013/11/28 11:01:12 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\TrojanHunter
[2013/09/09 16:13:58 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\TuneUp Software
[2013/09/10 18:23:47 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\WildTangent
[2013/09/11 18:11:53 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\WinBatch
[2013/09/11 08:54:50 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Windows Live Writer
[2013/11/27 05:45:35 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Zoner
[2013/09/26 08:12:44 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2013/09/26 08:12:44 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 54 bytes -> C:\Users\Alex\ntuser.ini:l_encryption_d

< End of report >
  • 0

Advertisements


#2
Pyxis

Pyxis

    Trusted Helper

  • Malware Removal
  • 1,228 posts
Greetings,

Welcome to Geeks to Go--the friendliest online community dedicated to the sole goal of helping people from all around the world! :)

I am Pyxis and I will be assisting you with the problem at hand. Whilst I am taking the time to analyse your set of provided logs, I would like to stress the following reminders:

  • I am a student that is currently undergoing training. As such, my responses have to be checked by a professional before I present them to you to ensure you get the best quality help. If you deem I have overlooked your thread, which is in a matter of more than 24 hours, please send me a PM and I will get back to you shortly.
  • It is important that you do not install anything unless asked while the process is ongoing. Doing so may hinder or even complicate the cleaning of your system. You will get the chance to install things as you would like after the process has been completed.
  • Ensure you take extra caution to precisely follow my instructions. It is important that you only use the tools I have asked you to. The instructions for your computer are unique and should therefore only apply to your system.
I hope you keep in mind these reminders. I will be right back with a full response! :thumbsup:

Thank you.
  • 0

#3
Pyxis

Pyxis

    Trusted Helper

  • Malware Removal
  • 1,228 posts
Hi abooboo,

ACER with windows 7 64 bit,cripplingly slow. It is slow with outlook 2007(tried several fixes to speed it up), Any web browser very slow to react. Programs open very slowly. Scanned with avg, trend micro, and several other on line scanners. Any help greatly appreciated. Just found and registered on this site. It seems very helpful. Tanks in advance for any suggestions.

Your system seems to be infected with tons of adware and is experiencing conflicts with anti-virus programs thus the slowdown. Let's fix this computer. :thumbsup:

  • Step 1

    If you haven't already, download 'OTL by OldTimer' and save it to your desktop or move your existing copy into the said location.

  • Simply double-click the program icon to run it. It will ask for administrator privileges.

    Posted Image

  • Copy and paste the following into the Custom Scans/Fixes box:

    :OTL
    PRC - [2013/11/27 00:45:54 | 001,383,232 | ---- | M] (Spigot, Inc.) -- C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe
    PRC - [2013/11/27 00:41:58 | 000,807,800 | ---- | M] (Spigot, Inc.) -- C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe
    PRC - [2013/11/25 03:19:24 | 004,026,656 | ---- | M] (Conduit) -- C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe
    PRC - [2013/11/25 03:19:24 | 001,735,968 | ---- | M] (Conduit) -- C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe
    PRC - [2013/11/21 19:30:54 | 002,334,384 | ---- | M] () -- C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
    PRC - [2013/11/21 19:30:54 | 001,643,696 | ---- | M] (AVG Secure Search) -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.1.3\ToolbarUpdater.exe
    PRC - [2013/11/21 19:30:53 | 000,161,968 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.1.3\loggingserver.exe
    PRC - [2013/09/17 11:25:46 | 000,415,024 | ---- | M] () -- C:\Windows\SysWOW64\jmdp\stij.exe
    PRC - [2013/09/08 16:55:33 | 006,827,008 | ---- | M] (Bandoo Media Inc.) -- C:\Users\Alex\AppData\Local\iLivid\iLivid.exe
    PRC - [2013/08/29 14:34:56 | 000,048,200 | ---- | M] () -- C:\Windows\SysWOW64\C2MP\UpdateChecker.exe
    MOD - [2013/11/21 19:30:54 | 002,334,384 | ---- | M] () -- C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
    MOD - [2013/11/21 19:30:54 | 000,521,904 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.1.3\log4cplusU.dll
    MOD - [2013/11/21 19:30:54 | 000,145,072 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.1.3\SiteSafety.dll
    MOD - [2013/09/23 05:55:54 | 002,704,352 | ---- | M] () -- c:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll
    MOD - [2013/09/17 11:25:46 | 000,415,024 | ---- | M] () -- C:\Windows\SysWOW64\jmdp\stij.exe
    MOD - [2013/09/17 11:23:08 | 001,062,912 | ---- | M] () -- C:\Windows\SysWOW64\jmdp\lmrn.dll
    MOD - [2013/08/29 14:34:56 | 000,048,200 | ---- | M] () -- C:\Windows\SysWOW64\C2MP\UpdateChecker.exe
    SRV:64bit: - [2013/09/17 11:25:42 | 001,761,584 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\dmwu.exe -- (IBUpdaterService)
    SRV - [2013/12/03 11:08:32 | 000,000,000 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\dmwu.exe -- (IBUpdaterService)
    SRV - [2013/11/27 00:41:58 | 000,807,800 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe -- (Application Updater)
    SRV - [2013/11/25 03:19:24 | 001,735,968 | ---- | M] (Conduit) [Auto | Running] -- C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe -- (CltMngSvc)
    SRV - [2013/11/21 19:30:54 | 001,643,696 | ---- | M] (AVG Secure Search) [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.1.3\ToolbarUpdater.exe -- (vToolbarUpdater17.1.3)
    IE - HKLM\..\URLSearchHook: {7e8a1050-cf67-4575-92df-dcc60e7d952d} - C:\Program Files (x86)\SweetPacks\prxtbSwee.dll (Conduit Ltd.)
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
    IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\SOFTWARE\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.searchgol...3_sgol&tsp=5023
    IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\URLSearchHook: {7e8a1050-cf67-4575-92df-dcc60e7d952d} - C:\Program Files (x86)\SweetPacks\prxtbSwee.dll (Conduit Ltd.)
    IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\URLSearchHook: {B9C767DD-F66A-40B4-8F12-4199A9A4393C} - C:\Program Files (x86)\SearchMe Toolbar\IE\8.3\searchmeToolbarIE.dll (Spigot, Inc.)
    IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}: "URL" = http://search.condui...rchTerms}&SSPV=
    IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.searchgol...3_sgol&tsp=5023
    IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\SearchScopes\{62F35670-FB5A-4894-BE5D-BEA473F4683A}: "URL" = http://search.condui...q={searchTerms}
    IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\SearchScopes\{679E83C6-CE15-4AA5-B8B5-1B0AED2D74A1}: "URL" = http://search.condui...7651670315&UM=2
    IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://mysearch.avg....sa&d=2013-09-18 01:07:47&v=17.1.2.1&pid=safeguard&sg=23&sap=dsp&q={searchTerms}
    IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\SearchScopes\{B4D04864-F7F0-453F-9C0E-F8BB3BED17AC}: "URL" = http://search.yahoo....p={searchTerms}
    IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bbvacompass.com/
    FF - prefs.js..browser.search.defaultenginename: "SweetPacks Customized Web Search"
    FF - prefs.js..browser.search.defaultthis.engineName: "SweetPacks Customized Web Search"
    FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3310511&CUI=UN30238264301369158&UM=2&SearchSource=3&q={searchTerms}"
    FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=888596"
    FF - prefs.js..browser.search.selectedEngine: "Conduit Search"
    FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT3317740&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP7D026309-D893-4E45-B6AB-722D3AB61157&SSPV="
    FF - prefs.js..extensions.enabledAddons: searchme%40mybrowserbar.com:8.2
    FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3310511&SearchSource=2&CUI=UN30238264301369158&UM=2&q="
    FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.1.3\\npsitesafety.dll ()
    [2013/09/10 17:39:03 | 000,000,000 | ---D | M] (XUL Cache) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{277c4e95-2731-4488-8450-7714a3c30da1}
    [2013/09/10 17:39:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{635ABD67-4FE9-1B23-4F01-E679FA7484C1}-TRASH
    [2013/11/21 12:08:44 | 000,000,000 | ---D | M] (SweetPacks) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}
    [2013/09/10 17:39:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}-TRASH
    [2013/10/27 13:04:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]
    [2013/10/02 10:38:16 | 000,000,000 | ---D | M] (SearchGol) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]
    [2013/10/27 13:03:38 | 000,000,000 | ---D | M] (Translate Genius) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]
    [2013/10/23 19:49:26 | 000,040,867 | ---- | M] () (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]
    [2013/10/23 11:24:31 | 000,331,553 | ---- | M] () (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]
    [2013/12/03 03:10:31 | 000,000,880 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\conduit-search.xml
    [2013/12/04 05:30:13 | 000,002,115 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\MyStart Search.xml
    [2013/11/21 19:30:44 | 000,003,736 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\safeguard-secure-search.xml
    [2013/09/23 15:03:00 | 000,001,988 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\search.xml
    [2013/10/02 10:38:20 | 000,001,302 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\searchgol.xml
    [2013/11/26 12:40:16 | 000,001,094 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\sweetpacks-customized-web-search.xml
    [2013/11/06 09:51:03 | 000,000,000 | ---D | M] () -- C:\Program Files (x86)\Mozilla Firefox\Extensions\[email protected]
    [2013/11/27 10:26:34 | 000,000,000 | ---D | M] (SearchMe Toolbar) -- C:\PROGRAM FILES (X86)\SEARCHME TOOLBAR\FF
    O2 - BHO: (SweetPacks Toolbar) - {7e8a1050-cf67-4575-92df-dcc60e7d952d} - C:\Program Files (x86)\SweetPacks\prxtbSwee.dll (Conduit Ltd.)
    O2 - BHO: (searchgol Helper Object) - {8F547BDD-FCD4-48F8-A06F-573D6F404A3C} - C:\Program Files (x86)\searchgol\searchgol\1.8.16.19\bh\searchgol.dll (Montera Technologeis LTD)
    O2 - BHO: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.1.3.3\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
    O2 - BHO: (SearchMe Toolbar) - {B9C767DD-F66A-40B4-8F12-4199A9A4393C} - C:\Program Files (x86)\SearchMe Toolbar\IE\8.3\searchmeToolbarIE.dll (Spigot, Inc.)
    O3:64bit: - HKLM\..\Toolbar: (SearchMe Toolbar) - {B9C767DD-F66A-40B4-8F12-4199A9A4393C} - C:\Program Files (x86)\SearchMe Toolbar\IE\8.3\searchmeToolbarIE64.dll (Spigot, Inc.)
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (searchgol Toolbar) - {00078E95-3A4A-4137-8DE7-2824908D1C17} - C:\Program Files (x86)\searchgol\searchgol\1.8.16.19\searchgolTlbr.dll (Montera Technologeis LTD)
    O3 - HKLM\..\Toolbar: (SweetPacks Toolbar) - {7e8a1050-cf67-4575-92df-dcc60e7d952d} - C:\Program Files (x86)\SweetPacks\prxtbSwee.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.1.3.3\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
    O3 - HKLM\..\Toolbar: (SearchMe Toolbar) - {B9C767DD-F66A-40B4-8F12-4199A9A4393C} - C:\Program Files (x86)\SearchMe Toolbar\IE\8.3\searchmeToolbarIE.dll (Spigot, Inc.)
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\Toolbar\WebBrowser: (SweetPacks Toolbar) - {7E8A1050-CF67-4575-92DF-DCC60E7D952D} - C:\Program Files (x86)\SweetPacks\prxtbSwee.dll (Conduit Ltd.)
    O4 - HKLM..\Run: [SearchSettings] C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
    O4 - HKU\S-1-5-21-128065933-3734797803-567976751-1000..\Run: [BackgroundContainer] C:\Users\Alex\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll (Conduit Ltd.)
    O4 - HKU\S-1-5-21-128065933-3734797803-567976751-1000..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIJHE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-3540 Series" /EF "HKCU" File not found
    O4 - HKU\S-1-5-21-128065933-3734797803-567976751-1000..\Run: [iLivid] C:\Users\Alex\AppData\Local\iLivid\iLivid.exe (Bandoo Media Inc.)
    [2013/12/03 03:09:56 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\SearchProtect
    [2013/11/27 10:26:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Application Updater
    [2013/11/27 10:26:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SearchMe Toolbar
    [2013/11/21 12:09:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit
    [2013/11/21 12:09:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Conduit
    [2013/11/21 12:09:13 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Local\Conduit
    [2013/11/21 12:09:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SweetPacks
    [2013/11/21 12:08:49 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\SearchProtect
    [2013/11/21 12:07:22 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\ljkb
    [2013/11/21 12:07:21 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\jmdp
    [2013/11/21 12:07:17 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\ARFC
    [2013/11/21 12:02:09 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Local\SearchProtect
    [2013/11/21 12:02:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SearchProtect
    [2013/12/03 11:08:40 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\igfxpers.exe
    [2013/12/03 11:08:40 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\igfxext.exe
    [2013/12/03 11:08:36 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\WUDFHost.exe
    [2013/12/03 11:08:36 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\taskhost.exe
    [2013/12/03 11:08:36 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\igfxtray.exe
    [2013/12/03 11:08:36 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\igfxsrvc.exe
    [2013/12/03 11:08:36 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\hkcmd.exe
    [2013/12/03 11:08:34 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\escsvc64.exe
    [2013/12/03 11:08:33 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\mfevtps.exe
    [2013/12/03 11:08:32 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\dmwu.exe
    [2013/12/03 11:08:31 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\spoolsv.exe
    [2013/12/03 11:08:31 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\conhost.exe
    [2013/12/03 11:07:54 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\winlogon.exe
    [2013/12/03 11:07:54 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\smss.exe
    [2013/12/03 11:07:54 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\services.exe
    [2013/12/03 11:07:54 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\lsm.exe
    [2013/12/03 11:07:54 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\lsass.exe
    [2013/12/03 11:07:54 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\dwm.exe
    [2013/12/03 11:07:54 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\csrss.exe
    [2013/10/27 13:04:27 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\BabSolution
    [2013/09/25 14:15:18 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\DefaultTab
    [2013/09/11 17:36:00 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\DriverFinder
    [2013/09/25 13:36:15 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\FoozKids
    [2013/11/21 12:08:49 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\SearchProtect
    @Alternate Data Stream - 54 bytes -> C:\Users\Alex\ntuser.ini:l_encryption_d
    
    :Files
    C:\Program Files (x86)\Common Files\Spigot
    C:\Program Files (x86)\Application Updater
    C:\Program Files (x86)\SearchProtect
    C:\Program Files (x86)\AVG SafeGuard toolbar
    C:\Program Files (x86)\Common Files\AVG Secure Search
    C:\Users\Alex\AppData\Local\iLivid
    C:\Windows\SysWOW64\C2MP
    c:\ProgramData\BitGuard
    C:\Windows\SysWOW64\jmd
    C:\Program Files (x86)\SweetPacks
    C:\Program Files (x86)\searchgo
    C:\Program Files (x86)\SearchMe Toolbar
    C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.6.3.1271_0\
    C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.6.3.1271_1\
    C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj\1.0_0\
    C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.1_0\
    C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.1_1\
    C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.4_0\
    C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.4_1\
    C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\
    C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\omaonpoimgkmbllpdihbnmgphjoipdhf\1.2.0.0_0\
    C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp\1.0_0\
    
    :Commands
    [emptytemp]
    
  • Click Run Fix.
  • OTL will reboot your system. Allow it by clicking OK.
  • After the reboot, a Notepad window will appear, named MMDDYYYY_HHMMSS.log. Alternatively, you can find that log at C:\_OTL\MovedFiles\MMDDYYYY_HHMMSS.log.
  • Copy (CTRL + A and CTRL + C) and paste (CTRL + V) the content of the log in your next reply.

  • Step 2

    Download 'AdwCleaner by Xplode' and save it to your desktop.

  • Simply double-click the program icon to run it. It will ask for administrator privileges.
  • Click Scan and choose Clean after.
  • Wait for it to finish. It won't take long.
  • Click OK for the next prompts. Your system will automatically reboot.
  • A log will automatically pop-up after rebooting. Alternatively, you can find it at C:\AdwCleaner[S*].txt.
  • Copy (CTRL + A and CTRL + C) and paste (CTRL + V) the content of the log in your next reply.
  • Step 3

    You seem to have too many anti-virus programs running in your system. While it is normal to think that "the more the merrier" in certain occasions, it does not apply when choosing an anti-virus. Having multiple ones of the same kind installed (e.g. more than one anti-virus program) will make your system run slower, and they will go against one another thereby making them inefficient. You currently have:

    AVG AntiVirus Free 2014 (Anti-virus)
    Malwarebytes Anti-Malware (Scanner)
    McAfee (Anti-virus)
    TrojanHunter (Scanner)
Since I assume you paid for McAfee, I advise you to uninstall AVG AntiVirus Free 2014 and TrojanHunter through Control Panel > Add or Remove Programs (Windows XP) or Control Panel > Programs and Features > Uninstall a Program (Windows Vista & Windows 7).

If you are having difficulties, please tell me.
  • Step 4

    If you haven't already, download 'OTL by OldTimer' and save it to your desktop or move your existing copy into the said location.

  • Simply double-click the program icon to run it. It will ask for administrator privileges.
  • Ensure that the following settings are followed. Make sure all other windows are closed and let it run uninterrupted.

    Posted Image

  • Click Run Scan.
  • After a short while, two Notepad windows will appear, named OTL.txt and Extras.txt. Alternatively, you can also find these at your desktop.
  • Copy and paste (CTRL + A and CTRL + C) the content of these logs in your next reply.
  • Logs to Post
In summary of the above, I will need you to post the following log(s):
  • MMDDYYYY_HHMMSS.log (OTL)
  • AdwCleaner[S*].txt (AdwCleaner)
  • Extras.txt (OTL)
  • OTL.txt (OTL)

  • 0

#4
abooboo

abooboo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Here we go!:

All processes killed
========== OTL ==========
No active process named SearchSettings.exe was found!
No active process named ApplicationUpdater.exe was found!
No active process named cltmng.exe was found!
No active process named CltMngSvc.exe was found!
No active process named vprot.exe was found!
No active process named ToolbarUpdater.exe was found!
No active process named loggingserver.exe was found!
No active process named stij.exe was found!
No active process named iLivid.exe was found!
No active process named UpdateChecker.exe was found!
Releasing module C:\Windows\SysWOW64\jmdp\stij.exe
C:\Windows\SysWOW64\jmdp\stij.exe moved successfully.
Releasing module C:\Windows\SysWOW64\jmdp\lmrn.dll
C:\Windows\SysWOW64\jmdp\lmrn.dll moved successfully.
Error: Unable to stop service IBUpdaterService!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IBUpdaterService deleted successfully.
C:\Windows\SysNative\dmwu.exe moved successfully.
Error: Unable to stop service IBUpdaterService!
Service\Driver key IBUpdaterService not found.
C:\Windows\SysWOW64\dmwu.exe moved successfully.
Service Application Updater stopped successfully!
Service Application Updater deleted successfully!
C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe moved successfully.
Service CltMngSvc stopped successfully!
Service CltMngSvc deleted successfully!
C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe moved successfully.
Service vToolbarUpdater17.1.3 stopped successfully!
Service vToolbarUpdater17.1.3 deleted successfully!
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.1.3\ToolbarUpdater.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{7e8a1050-cf67-4575-92df-dcc60e7d952d} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\ deleted successfully.
C:\Program Files (x86)\SweetPacks\prxtbSwee.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKU\S-1-5-21-128065933-3734797803-567976751-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\bProtector Start Page| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-128065933-3734797803-567976751-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{7e8a1050-cf67-4575-92df-dcc60e7d952d} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\ not found.
File C:\Program Files (x86)\SweetPacks\prxtbSwee.dll not found.
Registry value HKEY_USERS\S-1-5-21-128065933-3734797803-567976751-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{B9C767DD-F66A-40B4-8F12-4199A9A4393C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B9C767DD-F66A-40B4-8F12-4199A9A4393C}\ deleted successfully.
C:\Program Files (x86)\SearchMe Toolbar\IE\8.3\searchmeToolbarIE.dll moved successfully.
Registry key HKEY_USERS\S-1-5-21-128065933-3734797803-567976751-1000\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}\ not found.
Registry key HKEY_USERS\S-1-5-21-128065933-3734797803-567976751-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found.
Registry key HKEY_USERS\S-1-5-21-128065933-3734797803-567976751-1000\Software\Microsoft\Internet Explorer\SearchScopes\{62F35670-FB5A-4894-BE5D-BEA473F4683A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{62F35670-FB5A-4894-BE5D-BEA473F4683A}\ not found.
Registry key HKEY_USERS\S-1-5-21-128065933-3734797803-567976751-1000\Software\Microsoft\Internet Explorer\SearchScopes\{679E83C6-CE15-4AA5-B8B5-1B0AED2D74A1}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{679E83C6-CE15-4AA5-B8B5-1B0AED2D74A1}\ not found.
Registry key HKEY_USERS\S-1-5-21-128065933-3734797803-567976751-1000\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-128065933-3734797803-567976751-1000\Software\Microsoft\Internet Explorer\SearchScopes\{B4D04864-F7F0-453F-9C0E-F8BB3BED17AC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4D04864-F7F0-453F-9C0E-F8BB3BED17AC}\ not found.
HKU\S-1-5-21-128065933-3734797803-567976751-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Prefs.js: "SweetPacks Customized Web Search" removed from browser.search.defaultenginename
Prefs.js: "SweetPacks Customized Web Search" removed from browser.search.defaultthis.engineName
Prefs.js: "http://search.condui...={searchTerms}" removed from browser.search.defaulturl
Prefs.js: "chr-greentree_ff&ilc=12&type=888596" removed from browser.search.param.yahoo-fr
Prefs.js: "Conduit Search" removed from browser.search.selectedEngine
Prefs.js: "http://search.condui...3AB61157&SSPV=" removed from browser.startup.homepage
Prefs.js: searchme%40mybrowserbar.com:8.2 removed from extensions.enabledAddons
Prefs.js: "http://search.condui...369158&UM=2&q=" removed from keyword.URL
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin\ deleted successfully.
File move failed. C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.1.3\\npsitesafety.dll scheduled to be moved on reboot.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{277c4e95-2731-4488-8450-7714a3c30da1}\defaults\preferences folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{277c4e95-2731-4488-8450-7714a3c30da1}\defaults folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{277c4e95-2731-4488-8450-7714a3c30da1}\chrome folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{277c4e95-2731-4488-8450-7714a3c30da1} folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{635ABD67-4FE9-1B23-4F01-E679FA7484C1}-TRASH\COMPONENTS folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{635ABD67-4FE9-1B23-4F01-E679FA7484C1}-TRASH folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Plugins folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\modules folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\META-INF folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\lib folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\defaults\preferences folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\defaults folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\components\mam folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\components folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\mam\content folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\mam folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\sl folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\lib\jquery.jscrollpane folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\lib\jquery.alerts\images folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\lib\jquery.alerts folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\lib folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\core folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\WEATHER\js folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\WEATHER\css folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\WEATHER folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\TWITTER\js folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\TWITTER\img folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\TWITTER folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\SEARCH\view\style\rsx folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\SEARCH\view\style folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\SEARCH\view\script folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\SEARCH\view folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\SEARCH\resources folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\SEARCH\js folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\SEARCH\Css folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\SEARCH\buildSettings folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\SEARCH folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\RADIO_PLAYER\js\resources folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\RADIO_PLAYER\js folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\RADIO_PLAYER\css\custom-theme folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\RADIO_PLAYER\css folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\RADIO_PLAYER folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\PRICE_GONG\images folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\PRICE_GONG\css\custom-theme folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\PRICE_GONG\css folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\PRICE_GONG\agreement folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\PRICE_GONG folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\Optimizer\js folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\Optimizer folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\NOTIFICATION\js folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\NOTIFICATION\images\light folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\NOTIFICATION\images\dark folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\NOTIFICATION\images folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\NOTIFICATION\css folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\NOTIFICATION folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\MULTI_RSS\js\resources folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\MULTI_RSS\js folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\MULTI_RSS\img folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\MULTI_RSS\css folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\MULTI_RSS folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\HIGHLIGHTER\js folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\HIGHLIGHTER\css folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\HIGHLIGHTER folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\EMAIL_NOTIFIER\js folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\EMAIL_NOTIFIER\css folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\EMAIL_NOTIFIER folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\APPLICATION_BUTTON\resources folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\APPLICATION_BUTTON\Js folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa\APPLICATION_BUTTON folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\wa folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\ui\menu\js folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\ui\menu\img folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\ui\menu\css folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\ui\menu folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\ui\gf\js folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\ui\gf\img folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\ui\gf\css folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\ui\gf folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\ui\gadgetFrame folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\ui\dlg\ftd\images folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\ui\dlg\ftd folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\ui\dlg folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\ui folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\sp\spsd\images folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\sp\spsd folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\sp\spbd\images folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\sp\spbd folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\sp\js folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\sp folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\options\js\resources folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\options\js folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\options\images folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\options\css folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\options folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\msd folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\api folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\ac\res folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\ac\img folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\ac\css folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\ac folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\aboutBox\js folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\aboutBox\images folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al\aboutBox folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb\al folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\tb folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\logic\uninstall\dialog\js folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\logic\uninstall\dialog\images folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\logic\uninstall\dialog\css folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\logic\uninstall\dialog folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\logic\uninstall folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content\logic folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511\content folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome\CT3310511 folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\Chrome folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{7e8a1050-cf67-4575-92df-dcc60e7d952d} folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}-TRASH\COMPONENTS folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}-TRASH folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\defaulttab\locale\en-US folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\defaulttab\locale folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\defaulttab\content folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\defaulttab\components folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\defaulttab folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\defaults\preferences folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\defaults folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected] folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\META-INF folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\content\imgs\flgs folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\content\imgs folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\content folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\components folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected] folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\resources\translategenius\tests folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\resources\translategenius\data\style folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\resources\translategenius\data\images folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\resources\translategenius\data folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\resources\translategenius folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\resources\addon-sdk\lib\sdk\windows folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\resources\addon-sdk\lib\sdk\util folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\resources\addon-sdk\lib\sdk\tabs folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\resources\addon-sdk\lib\sdk\private-browsing\window folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\resources\addon-sdk\lib\sdk\private-browsing folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\resources\addon-sdk\lib\sdk\preferences folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\resources\addon-sdk\lib\sdk\panel folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\resources\addon-sdk\lib\sdk folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\resources\addon-sdk\lib folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\resources\addon-sdk\data folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\resources\addon-sdk folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\resources folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\locale folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\defaults\preferences folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]\defaults folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected] folder moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected] moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected] moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\conduit-search.xml moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\MyStart Search.xml moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\safeguard-secure-search.xml moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\search.xml moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\searchgol.xml moved successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\sweetpacks-customized-web-search.xml moved successfully.
C:\Program Files (x86)\Mozilla Firefox\Extensions\[email protected] folder moved successfully.
C:\PROGRAM FILES (X86)\SEARCHME TOOLBAR\FF\components folder moved successfully.
C:\PROGRAM FILES (X86)\SEARCHME TOOLBAR\FF\chrome folder moved successfully.
C:\PROGRAM FILES (X86)\SEARCHME TOOLBAR\FF folder moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\ not found.
File C:\Program Files (x86)\SweetPacks\prxtbSwee.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8F547BDD-FCD4-48F8-A06F-573D6F404A3C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8F547BDD-FCD4-48F8-A06F-573D6F404A3C}\ deleted successfully.
C:\Program Files (x86)\searchgol\searchgol\1.8.16.19\bh\searchgol.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.
C:\Program Files (x86)\AVG SafeGuard toolbar\17.1.3.3\AVG SafeGuard toolbar_toolbar.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B9C767DD-F66A-40B4-8F12-4199A9A4393C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B9C767DD-F66A-40B4-8F12-4199A9A4393C}\ not found.
File C:\Program Files (x86)\SearchMe Toolbar\IE\8.3\searchmeToolbarIE.dll not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{B9C767DD-F66A-40B4-8F12-4199A9A4393C} deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B9C767DD-F66A-40B4-8F12-4199A9A4393C}\ deleted successfully.
C:\Program Files (x86)\SearchMe Toolbar\IE\8.3\searchmeToolbarIE64.dll moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{00078E95-3A4A-4137-8DE7-2824908D1C17} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00078E95-3A4A-4137-8DE7-2824908D1C17}\ deleted successfully.
C:\Program Files (x86)\searchgol\searchgol\1.8.16.19\searchgolTlbr.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{7e8a1050-cf67-4575-92df-dcc60e7d952d} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7e8a1050-cf67-4575-92df-dcc60e7d952d}\ not found.
File C:\Program Files (x86)\SweetPacks\prxtbSwee.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}\ not found.
File C:\Program Files (x86)\AVG SafeGuard toolbar\17.1.3.3\AVG SafeGuard toolbar_toolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{B9C767DD-F66A-40B4-8F12-4199A9A4393C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B9C767DD-F66A-40B4-8F12-4199A9A4393C}\ not found.
File C:\Program Files (x86)\SearchMe Toolbar\IE\8.3\searchmeToolbarIE.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_USERS\S-1-5-21-128065933-3734797803-567976751-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7E8A1050-CF67-4575-92DF-DCC60E7D952D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E8A1050-CF67-4575-92DF-DCC60E7D952D}\ not found.
File C:\Program Files (x86)\SweetPacks\prxtbSwee.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings deleted successfully.
C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe moved successfully.
Registry value HKEY_USERS\S-1-5-21-128065933-3734797803-567976751-1000\Software\Microsoft\Windows\CurrentVersion\Run\\BackgroundContainer deleted successfully.
C:\Users\Alex\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll moved successfully.
Registry value HKEY_USERS\S-1-5-21-128065933-3734797803-567976751-1000\Software\Microsoft\Windows\CurrentVersion\Run\\EPLTarget\P0000000000000000 deleted successfully.
Registry value HKEY_USERS\S-1-5-21-128065933-3734797803-567976751-1000\Software\Microsoft\Windows\CurrentVersion\Run\\iLivid deleted successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid.exe moved successfully.
C:\Windows\SysWow64\SearchProtect\Logs folder moved successfully.
C:\Windows\SysWow64\SearchProtect folder moved successfully.
C:\Program Files (x86)\Application Updater folder moved successfully.
C:\Program Files (x86)\SearchMe Toolbar\Res\Lang folder moved successfully.
C:\Program Files (x86)\SearchMe Toolbar\Res folder moved successfully.
C:\Program Files (x86)\SearchMe Toolbar\IE\8.3 folder moved successfully.
C:\Program Files (x86)\SearchMe Toolbar\IE folder moved successfully.
C:\Program Files (x86)\SearchMe Toolbar folder moved successfully.
C:\Program Files (x86)\Conduit\Community Alerts folder moved successfully.
C:\Program Files (x86)\Conduit folder moved successfully.
C:\ProgramData\Conduit\Multi\CT3310511 folder moved successfully.
C:\ProgramData\Conduit\Multi folder moved successfully.
C:\ProgramData\Conduit\IE\CT3310511 folder moved successfully.
C:\ProgramData\Conduit\IE folder moved successfully.
C:\ProgramData\Conduit folder moved successfully.
C:\Users\Alex\AppData\Local\Conduit\CT3310511 folder moved successfully.
C:\Users\Alex\AppData\Local\Conduit\BackgroundContainer folder moved successfully.
C:\Users\Alex\AppData\Local\Conduit folder moved successfully.
C:\Program Files (x86)\SweetPacks folder moved successfully.
C:\Users\Alex\AppData\Roaming\SearchProtect\Res folder moved successfully.
C:\Users\Alex\AppData\Roaming\SearchProtect folder moved successfully.
C:\Windows\SysNative\ljkb folder moved successfully.
C:\Windows\SysWow64\jmdp folder moved successfully.
C:\Windows\SysWow64\ARFC folder moved successfully.
C:\Users\Alex\AppData\Local\SearchProtect\SearchProtect\rep folder moved successfully.
C:\Users\Alex\AppData\Local\SearchProtect\SearchProtect\Logs folder moved successfully.
C:\Users\Alex\AppData\Local\SearchProtect\SearchProtect folder moved successfully.
C:\Program Files (x86)\SearchProtect\SearchProtect\rep folder moved successfully.
C:\Program Files (x86)\SearchProtect\SearchProtect\Logs folder moved successfully.
C:\Program Files (x86)\SearchProtect\SearchProtect\bin folder moved successfully.
C:\Program Files (x86)\SearchProtect\SearchProtect folder moved successfully.
C:\Windows\SysWOW64\igfxpers.exe moved successfully.
C:\Windows\SysWOW64\igfxext.exe moved successfully.
C:\Windows\SysWOW64\WUDFHost.exe moved successfully.
C:\Windows\SysWOW64\taskhost.exe moved successfully.
C:\Windows\SysWOW64\igfxtray.exe moved successfully.
C:\Windows\SysWOW64\igfxsrvc.exe moved successfully.
C:\Windows\SysWOW64\hkcmd.exe moved successfully.
C:\Windows\SysWOW64\escsvc64.exe moved successfully.
C:\Windows\SysWOW64\mfevtps.exe moved successfully.
File C:\Windows\SysWow64\dmwu.exe not found.
C:\Windows\SysWOW64\spoolsv.exe moved successfully.
C:\Windows\SysWOW64\conhost.exe moved successfully.
C:\Windows\SysWOW64\winlogon.exe moved successfully.
C:\Windows\SysWOW64\smss.exe moved successfully.
C:\Windows\SysWOW64\services.exe moved successfully.
C:\Windows\SysWOW64\lsm.exe moved successfully.
C:\Windows\SysWOW64\lsass.exe moved successfully.
C:\Windows\SysWOW64\dwm.exe moved successfully.
C:\Windows\SysWOW64\csrss.exe moved successfully.
C:\Users\Alex\AppData\Roaming\BabSolution\Shared folder moved successfully.
C:\Users\Alex\AppData\Roaming\BabSolution folder moved successfully.
C:\Users\Alex\AppData\Roaming\DefaultTab folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Download\287524 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Download\287186 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Download\286393 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Download\286369 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Download\285171 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Download\280672 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Download\270762 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Download\258718 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Download\123954 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Download folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\WSD Scan Device - 6.1.7600.16385 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\WD Virtual CD 07A8 USB Device - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\WD SES Device - 1.0.9.0 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\WD My Passport 07A8 USB Device - 6.1.7600.16385 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Volume Manager - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Virtual Bluetooth Support - 7.4.0.126 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\USB Root Hub - 6.1.7601.17586 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\USB Mass Storage Device - Port_#0002.Hub_#0004 - 6.1.7601.17577 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\USB Mass Storage Device - 6.1.7601.17577 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\USB Input Device - Port_#0002.Hub_#0004 - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\USB Input Device - 0000.001d.0000.001.004.000.000.000.000 - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\USB Input Device (Logitech Download Assistant) - 1.10.77.0 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\USB Flash Memory USB Device - 6.1.7600.16385 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\USB Composite Device - Port_#0004.Hub_#0002 - 6.1.7601.17586 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\USB Composite Device - Port_#0002.Hub_#0003 - 6.1.7601.17586 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\USB Composite Device - 6.1.7601.17586 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\USB 3.0 Hub - 1.0.4.220 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\USB 2.0 Hub - Port_#0001.Hub_#0002 - 1.0.4.220 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\UMBus Root Bus Enumerator - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\UMBus Enumerator - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Terminal Server Mouse Driver - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Terminal Server Keyboard Driver - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Teredo Tunneling Pseudo-Interface - 6.1.7600.16385 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\System timer - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\System CMOS_real time clock - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\System board - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Standard PS_2 Keyboard - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\ST500LT012-9WS142 - 6.1.7600.16385 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\SAMSUNG-SGH-I747 - 6.1.7600.16385 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Realtek PCIE CardReader - PCI bus 1, device 0, function 0 - 6.1.7601.85 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Realtek High Definition Audio - 6.0.1.6570 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Programmable interrupt controller - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Plug and Play Software Device Enumerator - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\PCI standard host CPU bridge - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\PCI bus - 1.0.4.220 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Numeric data processor - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Motherboard resources - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Microsoft Windows Management Interface for ACPI - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Microsoft Virtual Drive Enumerator Driver - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Microsoft System Management BIOS Driver - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Microsoft ISATAP Adapter - 6.1.7600.16385 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Microsoft Composite Battery - 6.1.7600.16385 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Microsoft Bluetooth Enumerator - 6.1.7601.17889 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Microsoft ACPI-Compliant System - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Microsoft ACPI-Compliant Embedded Controller - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Microsoft ACPI-Compliant Control Method Battery - 6.1.7600.16385 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Microsoft AC Adapter - 6.1.7600.16385 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Logitech Unifying USB receiver - 5.60.66.0 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Logitech HID-compliant Unifying Mouse - 5.60.66.0 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Logitech HID-compliant Unifying device - DJ Bus 0 - 5.60.66.0 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Logitech Driver Interface - 5.60.66.0 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Intel® USB 3.0 Root Hub - 1.0.4.220 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Intel® USB 3.0 eXtensible Host Controller - 1.0.4.220 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Intel® Pentium® CPU B960 @ 2.20GHz - 6.1.7600.16385 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Intel® Management Engine Interface - 8.0.0.1262 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Intel® HM77 Express Chipset LPC Controller - 1E57 - 9.3.0.1020 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Intel® HD Graphics - 8.15.10.2653 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Intel® Display Audio - 6.14.0.3090 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Intel® 82802 Firmware Hub Device - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Intel® 7 Series_C216 Chipset Family USB Enhanced Host Controller - 1E2D - 9.3.0.1011 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Intel® 7 Series_C216 Chipset Family USB Enhanced Host Controller - 1E26 - 9.3.0.1011 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Intel® 7 Series_C216 Chipset Family SMBus Host Controller - 1E22 - 9.3.0.1011 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Intel® 7 Series_C216 Chipset Family PCI Express Root Port 6 - 1E1A - 9.3.0.1020 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Intel® 7 Series_C216 Chipset Family PCI Express Root Port 2 - 1E12 - 9.3.0.1020 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Intel® 7 Series_C216 Chipset Family PCI Express Root Port 1 - 1E10 - 9.3.0.1020 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Intel® 7 Series Chipset Family SATA AHCI Controller - 11.0.0.1032 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\HL-DT-ST DVDRAM GT90N - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\High precision event timer - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\High Definition Audio Controller - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\HID-compliant mouse - 6.1.7600.16385 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\HID-compliant device - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\HID-compliant consumer control device - 6.1.7600.16385 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\HID Keyboard Device - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\HD WebCam - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Generic volume shadow copy - 6.1.7600.16385 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Generic volume - 6.1.7601.17567 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Generic USB Hub - 6.1.7601.17586 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Generic PnP Monitor - 6.1.7600.16385 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\File as Volume Driver - 6.1.7600.16385 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\EPSON WF-3540 Series - http___192.168.1.8_80_WSD_DEVICE - 1.52.0.0 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\ELAN PS_2 Port Smart-Pad - 10.6.9.9 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Direct memory access controller - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Composite Bus Enumerator - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Bluetooth USB Module - Port_#0006.Hub_#0004 - 7.4.0.126 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Bluetooth LWFLT Device - 7.4.0.101 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Bluetooth Hard Copy Cable Replacement Server - 7.4.0.90 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Bluetooth Device (RFCOMM Protocol TDI) - 6.1.7600.16385 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Bluetooth Device (Personal Area Network) - 6.1.7600.16385 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Bluetooth AVRCP Device - 7.4.0.95 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Bluetooth Audio Device - 7.4.0.125 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Atheros Bluetooth Bus - 7.4.0.90 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Atheros AR8151 PCI-E Gigabit Ethernet Controller (NDIS 6.20) - 2.0.8.8 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\Atheros AR5BWB222 Wireless Network Adapter - 10.0.0.38 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\ACPI x64-based PC - 6.1.7600.16385 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\ACPI Thermal Zone - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\ACPI Sleep Button - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\ACPI Power Button - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\ACPI Lid - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup\ACPI Fixed Feature Button - 6.1.7601.17514 folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder\Backup folder moved successfully.
C:\Users\Alex\AppData\Roaming\DriverFinder folder moved successfully.
C:\Users\Alex\AppData\Roaming\FoozKids\Local Store\modules folder moved successfully.
C:\Users\Alex\AppData\Roaming\FoozKids\Local Store\#SharedObjects\#FKCookies folder moved successfully.
C:\Users\Alex\AppData\Roaming\FoozKids\Local Store\#SharedObjects folder moved successfully.
C:\Users\Alex\AppData\Roaming\FoozKids\Local Store folder moved successfully.
C:\Users\Alex\AppData\Roaming\FoozKids folder moved successfully.
Folder C:\Users\Alex\AppData\Roaming\SearchProtect\ not found.
ADS C:\Users\Alex\ntuser.ini:l_encryption_d deleted successfully.
========== FILES ==========
C:\Program Files (x86)\Common Files\Spigot\Search Settings\Res folder moved successfully.
C:\Program Files (x86)\Common Files\Spigot\Search Settings\Lang folder moved successfully.
C:\Program Files (x86)\Common Files\Spigot\Search Settings folder moved successfully.
C:\Program Files (x86)\Common Files\Spigot\GC folder moved successfully.
C:\Program Files (x86)\Common Files\Spigot folder moved successfully.
File\Folder C:\Program Files (x86)\Application Updater not found.
C:\Program Files (x86)\SearchProtect\UI\rep folder moved successfully.
C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall folder moved successfully.
C:\Program Files (x86)\SearchProtect\UI\dialogs\settings folder moved successfully.
C:\Program Files (x86)\SearchProtect\UI\dialogs\protection folder moved successfully.
C:\Program Files (x86)\SearchProtect\UI\dialogs\libs folder moved successfully.
C:\Program Files (x86)\SearchProtect\UI\dialogs\Images folder moved successfully.
C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble folder moved successfully.
C:\Program Files (x86)\SearchProtect\UI\dialogs folder moved successfully.
C:\Program Files (x86)\SearchProtect\UI\bin folder moved successfully.
C:\Program Files (x86)\SearchProtect\UI folder moved successfully.
C:\Program Files (x86)\SearchProtect\Main\rep folder moved successfully.
C:\Program Files (x86)\SearchProtect\Main\Logs folder moved successfully.
C:\Program Files (x86)\SearchProtect\Main\bin folder moved successfully.
C:\Program Files (x86)\SearchProtect\Main folder moved successfully.
C:\Program Files (x86)\SearchProtect folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\UninstallRes\ClientPackage\Images\uninstall folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\UninstallRes\ClientPackage\Images folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\UninstallRes\ClientPackage folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\UninstallRes folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\Licenses folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\EnableHelperRes\Images folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\EnableHelperRes folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\DSPDlg_IE folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\ChromeRes\AVG Secure Search folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\ChromeRes\AVG SafeGuard toolbar folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\ChromeRes\AVG Nation toolbar folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\ChromeRes folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\ChromeGuardRes folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\Chrome\content\icons folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\Chrome\content folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\Chrome folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\BundleInstall folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\17.1.3.3 folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\17.1.2.1 folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\17.0.1.12 folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\17.0.0.9 folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\17.0.0.7 folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\15.5.0.2 folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar\15.4.0.5 folder moved successfully.
C:\Program Files (x86)\AVG SafeGuard toolbar folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.1.3 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.1.2 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.1 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.1.3 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.1.2 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.12 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.1 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.5.0 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.4.0 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\ToolBandTlb\17.1.3 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\ToolBandTlb\17.1.2 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\ToolBandTlb\17.0.12 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\ToolBandTlb\17.0.1 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\ToolBandTlb\15.5.0 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\ToolBandTlb\15.4.0 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\ToolBandTlb folder moved successfully.
Folder move failed. C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.1.3 scheduled to be moved on reboot.
C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.1.2 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.0.12 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.0.1 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.5.0 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.4.0 folder moved successfully.
Folder move failed. C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller scheduled to be moved on reboot.
C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\17.1.3 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\17.1.2 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\17.0.12 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\17.0.1 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\15.5.0 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\15.4.0 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\RewardsInstaller\17.1.3 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\RewardsInstaller\17.1.2 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\RewardsInstaller\17.0.12 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\RewardsInstaller\17.0.1 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\RewardsInstaller\15.5.0 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\RewardsInstaller\15.4.0 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\RewardsInstaller folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\DriverInstaller\17.1.3 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\DriverInstaller\17.1.2 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\DriverInstaller\17.0.12 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\DriverInstaller\17.0.1 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\DriverInstaller\15.5.0 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\DriverInstaller\15.4.0 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\DriverInstaller folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\DNTInstaller\17.1.3 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\DNTInstaller\17.1.2 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\DNTInstaller\17.0.12 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\DNTInstaller\17.0.1 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\DNTInstaller\15.5.0 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\DNTInstaller\15.4.0 folder moved successfully.
C:\Program Files (x86)\Common Files\AVG Secure Search\DNTInstaller folder moved successfully.
Folder move failed. C:\Program Files (x86)\Common Files\AVG Secure Search scheduled to be moved on reboot.
C:\Users\Alex\AppData\Local\iLivid\Windows\SysWOW64 folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Windows folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\skins\fonts folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\skins folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\sdk\lib\pkgconfig folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\sdk\lib folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\sdk\include\vlc\plugins folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\sdk\include\vlc folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\sdk\include folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\sdk\activex folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\sdk folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\visualization folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\video_output folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\video_filter folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\video_chroma folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\text_renderer folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\stream_out folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\stream_filter folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\sse2 folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\services_discovery folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\packetizer folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\notify folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\mux folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\mmxext folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\mmx folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\misc folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\meta_engine folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\media_library folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\lua folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\gui folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\demux folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\control folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\codec folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\audio_output folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\audio_mixer folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\audio_filter folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\access_output folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\access folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins\3dnow folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\plugins folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\osdmenu\default\volume folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\osdmenu\default\selection folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\osdmenu\default\selected folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\osdmenu\default folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\osdmenu folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\NSIS folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\mozilla folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\sd folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\playlist folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\modules folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\meta\reader folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\meta\fetcher folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\meta\art folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\meta folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\intf\modules folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\intf folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\http\requests folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\http\old\js folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\http\old\images folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\http\old folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\http\js folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\http\images folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\http\dialogs\old folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\http\dialogs folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\http\css\ui-lightness\images folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\http\css\ui-lightness folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\http\css folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\http folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua\extensions folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\lua folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\zu\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\zu folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\zh_TW\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\zh_TW folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\zh_CN\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\zh_CN folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\wa\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\wa folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\vi\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\vi folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\uk\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\uk folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\tr\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\tr folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\tl\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\tl folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\th\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\th folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\tet\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\tet folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\te\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\te folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ta\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ta folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\sv\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\sv folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\sr\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\sr folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\sq\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\sq folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\sl\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\sl folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\sk\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\sk folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\si\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\si folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ru\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ru folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ro\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ro folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\pt_PT\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\pt_PT folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\pt_BR\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\pt_BR folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ps\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ps folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\pl\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\pl folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\pa\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\pa folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\oc\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\oc folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\nn\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\nn folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\nl\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\nl folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ne\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ne folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\nb\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\nb folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\my\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\my folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ms\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ms folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\mn\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\mn folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ml\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ml folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\mk\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\mk folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\lv\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\lv folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\lt\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\lt folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\lg\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\lg folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ku\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ku folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ko\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ko folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\kmr\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\kmr folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\km\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\km folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\kk\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\kk folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ka\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ka folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ja\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ja folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\it\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\it folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\is\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\is folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\id\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\id folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\hy\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\hy folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\hu\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\hu folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\hr\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\hr folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\hi\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\hi folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\he\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\he folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\gl\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\gl folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ga\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ga folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\fur\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\fur folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\fr\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\fr folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\fi\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\fi folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ff\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ff folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\fa\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\fa folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\eu\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\eu folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\et\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\et folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\es\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\es folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\en_GB\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\en_GB folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\el\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\el folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\de\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\de folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\da\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\da folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\cs\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\cs folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\co\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\co folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ckb\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ckb folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\cgg\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\cgg folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ca\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ca folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\br\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\br folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\bn\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\bn folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\bg\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\bg folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\be\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\be folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ast\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ast folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ar\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ar folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\am\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\am folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\af\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\af folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ach\LC_MESSAGES folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale\ach folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\locale folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\languages folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\http\requests folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\http\old\js folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\http\old\images folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\http\old folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\http\js folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\http\images folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\http\dialogs\old folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\http\dialogs folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\http\css\ui-lightness\images folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\http\css\ui-lightness folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\http\css folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\http folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC\activex folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\VLC folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\translations folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\xml\sax folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\xml\parsers folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\xml\etree folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\xml\dom folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\xml folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\wsgiref folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\unittest\test folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\unittest folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\test\xmltestdata folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\test\leakers folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\test\decimaltestdata folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\test\crashers folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\test folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\sqlite3\test folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\sqlite3 folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\site-packages\xbmcswift\tests folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\site-packages\xbmcswift\skel\resources\lib folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\site-packages\xbmcswift\skel\resources\language\English folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\site-packages\xbmcswift\skel\resources\language folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\site-packages\xbmcswift\skel\resources folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\site-packages\xbmcswift\skel folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\site-packages\xbmcswift\mockxbmc folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\site-packages\xbmcswift\ext folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\site-packages\xbmcswift folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\site-packages\simplejson\tests folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\site-packages\simplejson folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\site-packages\elementtree folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\site-packages\danishaddons folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\site-packages folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\pydoc_data folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\multiprocessing\dummy folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\multiprocessing folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\msilib folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\mechanize folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\logging folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\lib2to3\tests\data\fixers\myfixes folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\lib2to3\tests\data\fixers folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\lib2to3\tests\data folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\lib2to3\tests folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\lib2to3\pgen2 folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\lib2to3\fixes folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\lib2to3 folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\lib-tk\test\test_ttk folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\lib-tk\test\test_tkinter folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\lib-tk\test folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\lib-tk folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\json\tests folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\json folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\importlib folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\idlelib\Icons folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\idlelib folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\hotshot folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\encodings folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\email\test\data folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\email\test folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\email\mime folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\email folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\distutils\tests folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\distutils\command folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\distutils folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\curses folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\ctypes\test folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\ctypes\macholib folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\ctypes folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\compiler folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\bsddb\test folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib\bsddb folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\Lib folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\imageformats folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid\webcache4\prepared folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid\webcache4\data7\f folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid\webcache4\data7\e folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid\webcache4\data7\d folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid\webcache4\data7\c folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid\webcache4\data7\b folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid\webcache4\data7\a folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid\webcache4\data7\9 folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid\webcache4\data7\8 folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid\webcache4\data7\7 folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid\webcache4\data7\6 folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid\webcache4\data7\5 folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid\webcache4\data7\4 folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid\webcache4\data7\3 folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid\webcache4\data7\2 folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid\webcache4\data7\1 folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid\webcache4\data7\0 folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid\webcache4\data7 folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid\webcache4 folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\iLivid folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid\DLLs folder moved successfully.
C:\Users\Alex\AppData\Local\iLivid folder moved successfully.
C:\Windows\SysWOW64\C2MP folder moved successfully.
c:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8} folder moved successfully.
c:\ProgramData\BitGuard\2.6.1694.246 folder moved successfully.
c:\ProgramData\BitGuard folder moved successfully.
File\Folder C:\Windows\SysWOW64\jmd not found.
File\Folder C:\Program Files (x86)\SweetPacks not found.
File\Folder C:\Program Files (x86)\searchgo not found.
File\Folder C:\Program Files (x86)\SearchMe Toolbar not found.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.6.3.1271_0\Resources folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.6.3.1271_0 folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.6.3.1271_1\Resources folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.6.3.1271_1 folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj\1.0_0 folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.1_0 folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj\1.1_1 folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.4_0\icons folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.4_0 folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.4_1\scripts folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.4_1\icons folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk\2.4_1 folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\zh_TW folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\zh_CN folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\tr folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\sr folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\sk folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\ru folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\pt_PT folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\pt_BR folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\pl folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\nl folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\ko folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\ja folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\it folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\id folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\hu folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\fr folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\es_419 folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\es folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\en folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\de folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\da folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales\cs folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\_locales folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\content\tabs folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\content\icons\search_box folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\content\icons\dnt_disabled folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\content\icons folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\content\css folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\content\bho folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0\content folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.0.1.12_0 folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\omaonpoimgkmbllpdihbnmgphjoipdhf\1.2.0.0_0\LogitechHarmony.plugin\Contents\Resources\English.lproj folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\omaonpoimgkmbllpdihbnmgphjoipdhf\1.2.0.0_0\LogitechHarmony.plugin\Contents\Resources folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\omaonpoimgkmbllpdihbnmgphjoipdhf\1.2.0.0_0\LogitechHarmony.plugin\Contents\MacOS folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\omaonpoimgkmbllpdihbnmgphjoipdhf\1.2.0.0_0\LogitechHarmony.plugin\Contents folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\omaonpoimgkmbllpdihbnmgphjoipdhf\1.2.0.0_0\LogitechHarmony.plugin folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\omaonpoimgkmbllpdihbnmgphjoipdhf\1.2.0.0_0 folder moved successfully.
C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp\1.0_0 folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Flash cache emptied: 0 bytes

User: Alex
->Temp folder emptied: 416055575 bytes
->Temporary Internet Files folder emptied: 264100132 bytes
->Java cache emptied: 984198 bytes
->FireFox cache emptied: 59757882 bytes
->Google Chrome cache emptied: 6469280 bytes
->Flash cache emptied: 59653 bytes

User: All Users

User: david

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 57472 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 226840166 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 81246 bytes
RecycleBin emptied: 19488030 bytes

Total Files Cleaned = 948.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 12072013_083324

Files\Folders moved on Reboot...
File\Folder C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.1.3\\npsitesafety.dll not found!
Folder move failed. C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.1.3 scheduled to be moved on reboot.
Folder move failed. C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.1.3 scheduled to be moved on reboot.
Folder move failed. C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller scheduled to be moved on reboot.
Folder move failed. C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.1.3 scheduled to be moved on reboot.
Folder move failed. C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller scheduled to be moved on reboot.
Folder move failed. C:\Program Files (x86)\Common Files\AVG Secure Search scheduled to be moved on reboot.
C:\Users\Alex\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Alex\AppData\Local\Temp\MMDUtl.log moved successfully.
C:\Users\Alex\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
File move failed. C:\Windows\temp\dsiwmis.log scheduled to be moved on reboot.
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
------------------------------------------

# AdwCleaner v3.014 - Report created 07/12/2013 at 09:05:55
# Updated 01/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Alex - ALEX-PC
# Running from : C:\Users\Alex\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\AVG SafeGuard toolbar
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec
Folder Deleted : C:\Program Files (x86)\Linksicle
Folder Deleted : C:\Program Files (x86)\myfree codec
Folder Deleted : C:\Program Files (x86)\searchgol
Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Deleted : C:\Windows\SysWOW64\WNLT
[!] Folder Deleted : C:\Users\Alex\AppData\Local\AVG SafeGuard toolbar
Folder Deleted : C:\Users\Alex\AppData\Local\Searchprotect
Folder Deleted : C:\Users\Alex\AppData\LocalLow\AVG SafeGuard toolbar
Folder Deleted : C:\Users\Alex\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Alex\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Alex\AppData\LocalLow\Search Settings
Folder Deleted : C:\Users\Alex\AppData\LocalLow\SweetPacks
Folder Deleted : C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
Folder Deleted : C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\Smartbar
Folder Deleted : C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\ValueApps
Folder Deleted : C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj
Folder Deleted : C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
Folder Deleted : C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
Folder Deleted : C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Folder Deleted : C:\Users\Alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp
File Deleted : C:\END
File Deleted : C:\Windows\System32\ImhxxpComm.dll
File Deleted : C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iLivid.lnk
File Deleted : C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\bProtector_extensions.rdf
File Deleted : C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\bprotector_prefs.js
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml
File Deleted : C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\user.js
File Deleted : C:\Windows\System32\Tasks\BackgroundContainer Startup Task
File Deleted : C:\Windows\System32\Tasks\EPUpdater

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\aipfmkinhleccnodemkoofnnofpbbpac
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\hbcennhacfaagdopikcegfcobcadeocj
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp
Key Deleted : HKCU\Software\Classes\iLivid.torrent
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\PriceGongIE.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI
Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.BrowserWndAPI.1
Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj
Key Deleted : HKLM\SOFTWARE\Classes\AVG SafeGuard toolbar.PugiObj.1
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Key Deleted : HKLM\SOFTWARE\Classes\esrv.searchgolESrvc
Key Deleted : HKLM\SOFTWARE\Classes\esrv.searchgolESrvc.1
Key Deleted : HKLM\SOFTWARE\Classes\PriceGongIE.PriceGongCtrl
Key Deleted : HKLM\SOFTWARE\Classes\PriceGongIE.PriceGongCtrl.1
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\searchgol.searchgolappCore
Key Deleted : HKLM\SOFTWARE\Classes\searchgol.searchgolappCore.1
Key Deleted : HKLM\SOFTWARE\Classes\searchgol.searchgoldskBnd
Key Deleted : HKLM\SOFTWARE\Classes\searchgol.searchgoldskBnd.1
Key Deleted : HKLM\SOFTWARE\Classes\searchgol.searchgolHlpr
Key Deleted : HKLM\SOFTWARE\Classes\searchgol.searchgolHlpr.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKCU\Software\5a53dad1e03abe14
Key Deleted : HKLM\SOFTWARE\5a53dad1e03abe14
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3310511
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4277F7CF-0000-46CF-BA49-D624465C4BAB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{835315FC-1BF6-4CA9-80CD-F6C158D40692}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{88AF4F6A-C6B7-4229-9275-824E98BF97F9}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{539F74BF-7E5C-46BD-9D45-35B1A91C9CBD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{840A13FF-B464-4782-9C96-AAF3092E55DD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9448AC19-EB62-46D5-B7DA-B059A7DB466A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D2A2595C-4FE4-4315-AA9B-19DBD6271B71}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D8E43B96-EB46-4820-92B7-232AEB735685}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E6C03E0-D368-4690-8168-9848D4C0F587}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3860D897-7DCD-473C-9744-B21DB133AB20}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{105F25A9-C42F-48A6-998D-0494E8AE336A}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{88AF4F6A-C6B7-4229-9275-824E98BF97F9}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00078E95-3A4A-4137-8DE7-2824908D1C17}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8F547BDD-FCD4-48F8-A06F-573D6F404A3C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B9C767DD-F66A-40B4-8F12-4199A9A4393C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7E8A1050-CF67-4575-92DF-DCC60E7D952D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5E6C03E0-D368-4690-8168-9848D4C0F587}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00078E95-3A4A-4137-8DE7-2824908D1C17}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8F547BDD-FCD4-48F8-A06F-573D6F404A3C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B9C767DD-F66A-40B4-8F12-4199A9A4393C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7E8A1050-CF67-4575-92DF-DCC60E7D952D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5E6C03E0-D368-4690-8168-9848D4C0F587}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8C5CBB76-7379-4490-AA5B-B037C0A36381}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4FA8093B-2C81-4B9B-B763-5B5253B41043}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{465CD051-76EB-424E-A831-29B22E61DB39}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1F8EDE97-36D5-422A-B8F0-9406E2D87C60}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3860D897-7DCD-473C-9744-B21DB133AB20}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\AVG SafeGuard toolbar
Key Deleted : HKCU\Software\BabSolution
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\DataMngr
[#] Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\DefaultTab
Key Deleted : HKCU\Software\ilivid
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\Myfree Codec
Key Deleted : HKCU\Software\Search Settings
Key Deleted : HKCU\Software\searchgol LTD
Key Deleted : HKCU\Software\Searchgol
Key Deleted : HKCU\Software\wnlt
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\BackgroundContainer
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\Search Settings
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\SweetPacks
Key Deleted : HKLM\Software\Application Updater
Key Deleted : HKLM\Software\AVG SafeGuard toolbar
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\Software\BabylonToolbar
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\Myfree Codec
Key Deleted : HKLM\Software\Search Settings
Key Deleted : HKLM\Software\Searchgol
Key Deleted : HKLM\Software\SearchProtect
Key Deleted : HKLM\Software\SweetPacks
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG SafeGuard toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ilivid
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search-Gol Chrome Toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Searchgol
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wnlt
Key Deleted : [x64] HKLM\SOFTWARE\wnlt
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\lucky leap

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16428


-\\ Mozilla Firefox v25.0 (en-US)

[ File : C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\prefs.js ]

Line Deleted : user_pref("CT3291325.1000082.isPlayDisplay", "true");
Line Deleted : user_pref("CT3291325.1000082.state", "{\"state\":\"stopped\",\"text\":\"Californi...\",\"description\":\"California Rock - Rock\",\"url\":\"hxxp://www.feedlive.net/california.asx\"}");
Line Deleted : user_pref("CT3291325.1000234.TWC_TMP_city", "LONGVIEW");
Line Deleted : user_pref("CT3291325.1000234.TWC_TMP_country", "US");
Line Deleted : user_pref("CT3291325.1000234.TWC_country", "UNITED STATES");
Line Deleted : user_pref("CT3291325.1000234.TWC_locId", "USTX0793");
Line Deleted : user_pref("CT3291325.1000234.TWC_location", "Longview, TX");
Line Deleted : user_pref("CT3291325.1000234.TWC_region", "US");
Line Deleted : user_pref("CT3291325.1000234.TWC_temp_dis", "f");
Line Deleted : user_pref("CT3291325.1000234.TWC_wind_dis", "mph");
Line Deleted : user_pref("CT3291325.129823441080029011.isToggled_item0_12", "true");
Line Deleted : user_pref("CT3291325.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3291325.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3291325.Facebook_Mode.enc", "Mg==");
Line Deleted : user_pref("CT3291325.Facebook_User_Locale.enc", "ZW4=");
Line Deleted : user_pref("CT3291325.FirstTime", "true");
Line Deleted : user_pref("CT3291325.FirstTimeFF3", "true");
Line Deleted : user_pref("CT3291325.LAST_CLIENT_STATS_SUBMIT_2.enc", "MTM3ODgyNzYxMw==");
Line Deleted : user_pref("CT3291325.LOCAL_COOKIE_STATS_LAST_SUBMIT_6.enc", "MTM3ODgyNzYyOQ==");
Line Deleted : user_pref("CT3291325.LOCAL_COOKIE_STATS_STATS_SITE_IRRELEVANT.enc", "Nw==");
Line Deleted : user_pref("CT3291325.LOCAL_COOKIE_STATS_STATS_SITE_SUPPORTED.enc", "NA==");
Line Deleted : user_pref("CT3291325.LOCAL_COOKIE_STATS_STATS_USE_RELATED.enc", "MQ==");
Line Deleted : user_pref("CT3291325.LOCAL_COOKIE_THROTTLE_BASEadd_stats|0|LOCAL_COOKIE_STATS_STATS_SITE_IRRELEVANT.enc", "MTM3ODgyODA4OQ==");
Line Deleted : user_pref("CT3291325.LOCAL_COOKIE_THROTTLE_BASEadd_stats|0|LOCAL_COOKIE_STATS_STATS_SITE_SUPPORTED.enc", "MTM3ODgyODE2OA==");
Line Deleted : user_pref("CT3291325.LOCAL_COOKIE_THROTTLE_BASEadd_stats|LOCAL_COOKIE_STATS_STATS_USE_RELATED.enc", "MTM3ODgyNzY5NA==");
Line Deleted : user_pref("CT3291325.LOCAL_COOKIE_THROTTLE_BASEloopback|hxxp://up.autocompleteplus.com/up?q=office%202013&l=yourbittorrent.com&t=1&o=office%20&v=0.5&d=conduit2.enc", "MTM3ODgyNzY5Nw==");
Line Deleted : user_pref("CT3291325.PG_ENABLE", "dHJ1ZQ==");
Line Deleted : user_pref("CT3291325.SF_JUST_INSTALLED.enc", "RkFMU0U=");
Line Deleted : user_pref("CT3291325.SF_STATUS.enc", "RU5BQkxFRA==");
Line Deleted : user_pref("CT3291325.SF_USER_ID.enc", "Y2lkXzEwOTIwMTMxMDQwOTEwNjA0MQ==");
Line Deleted : user_pref("CT3291325.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3291325&SearchSource=2&CUI=UN14929519622089165&UM=2&q=");
Line Deleted : user_pref("CT3291325.UserID", "UN14929519622089165");
Line Deleted : user_pref("CT3291325.acp_personal.appstate.enc", "ZW5hYmxl");
Line Deleted : user_pref("CT3291325.addressBarTakeOverEnabledInHidden", "true");
Line Deleted : user_pref("CT3291325.browser.search.defaultthis.engineName", true);
Line Deleted : user_pref("CT3291325.cbfirsttime.enc", "VHVlIFNlcCAxMCAyMDEzIDEwOjQwOjEzIEdNVC0wNTAwIChDZW50cmFsIFN0YW5kYXJkIFRpbWUp");
Line Deleted : user_pref("CT3291325.countryCode", "US");
Line Deleted : user_pref("CT3291325.defaultSearch", "true");
Line Deleted : user_pref("CT3291325.embeddedsData", "[{\"appId\":\"130075605210846225\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"insta[...]
Line Deleted : user_pref("CT3291325.enableAlerts", "true");
Line Deleted : user_pref("CT3291325.enableSearchFromAddressBar", "true");
Line Deleted : user_pref("CT3291325.firstTimeDialogOpened", "true");
Line Deleted : user_pref("CT3291325.fixPageNotFoundError", "true");
Line Deleted : user_pref("CT3291325.fixPageNotFoundErrorByUser", "false");
Line Deleted : user_pref("CT3291325.fixPageNotFoundErrorInHidden", "true");
Line Deleted : user_pref("CT3291325.fullUserID", "UN14929519622089165.IN.20130910100453");
Line Deleted : user_pref("CT3291325.hxxp___facebook_conduitapps_com.APP_WIN_FEATURES.enc", "cmVzaXphYmxlPTAsaHNjcm9sbD0wLHZzY3JvbGw9MCx0aXRsZWJhcj0xLGNsb3NlYnV0dG9uPTEsc2F2ZXJlc2l6ZWRzaXplPTAsb3BlbnBvc2l0aW9uPWFsaWd[...]
Line Deleted : user_pref("CT3291325.installId", "stub.exe");
Line Deleted : user_pref("CT3291325.installType", "conduitnsisintegration");
Line Deleted : user_pref("CT3291325.isCheckedStartAsHidden", true);
Line Deleted : user_pref("CT3291325.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3291325.isFirstTimeToolbarLoading", "false");
Line Deleted : user_pref("CT3291325.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3291325.keyword", true);
Line Deleted : user_pref("CT3291325.lastNewTabSettings", "{\"isEnabled\":false,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT3291325&octid=CT3291325&SearchSource=15&CUI=UN14929519622089165&SSPV=&Lay=1&UM=2\"}");
Line Deleted : user_pref("CT3291325.lastVersion", "10.20.0.513");
Line Deleted : user_pref("CT3291325.mam_gk_appStateReportTime.enc", "MTM3OTQ5MTc5MTAyMw==");
Line Deleted : user_pref("CT3291325.mam_gk_appState_ACplus.enc", "b24=");
Line Deleted : user_pref("CT3291325.mam_gk_appState_CouponBuddy.enc", "b24=");
Line Deleted : user_pref("CT3291325.mam_gk_appState_Discover.enc", "b24=");
Line Deleted : user_pref("CT3291325.mam_gk_appState_Easytobook.enc", "b24=");
Line Deleted : user_pref("CT3291325.mam_gk_appState_Easytobook_targeted.enc", "b24=");
Line Deleted : user_pref("CT3291325.mam_gk_appState_Find-a-Pro.enc", "b24=");
Line Deleted : user_pref("CT3291325.mam_gk_appState_PiclickV2-WebSearch.enc", "b24=");
Line Deleted : user_pref("CT3291325.mam_gk_appState_PriceGong.enc", "b24=");
Line Deleted : user_pref("CT3291325.mam_gk_appState_WindowShopper.enc", "b24=");
Line Deleted : user_pref("CT3291325.mam_gk_appsData.enc", "eyJhcHBzIjpbeyJpZCI6IlByaWNlR29uZyIsInVybCI6Imh0dHA6Ly9wcmljZWdvbmcuY29uZHVpdGFwcHMuY29tL01BTS92MS9odG1sX2NvbXAuaHRtbCIsInNjcmlwdFVybCI6bnVsbCwib3B0aW9uc0Rp[...]
Line Deleted : user_pref("CT3291325.mam_gk_appsDefaultEnabled.enc", "bnVsbA==");
Line Deleted : user_pref("CT3291325.mam_gk_calledSetupService.enc", "MQ==");
Line Deleted : user_pref("CT3291325.mam_gk_configuration.enc", "eyJjb25maWd1cmF0aW9uIjpbeyJpZCI6IlBpY2xpY2tWMi1XZWJTZWFyY2giLCJjcml0ZXJpYXMiOlt7ImNyaXRlcmlhSWQiOiI0YWVmZWVlYS1hY2MxLTRlMDUtYjdhMi05MzU1MmQwMDk1MmMiLCJ[...]
Line Deleted : user_pref("CT3291325.mam_gk_currentVersion.enc", "MS4xMC40LjA=");
Line Deleted : user_pref("CT3291325.mam_gk_existingUsersRecoveryDone.enc", "MQ==");
Line Deleted : user_pref("CT3291325.mam_gk_first_time.enc", "MQ==");
Line Deleted : user_pref("CT3291325.mam_gk_lastLoginTime.enc", "MTM3OTQ5MTc4Mzk0NQ==");
Line Deleted : user_pref("CT3291325.mam_gk_localization.enc", "eyJnYWRnZXRDb250ZW50UG9saWN5Ijp7IlRleHQiOiJDb250ZW50IFBvbGljeSJ9LCJnYWRnZXREZXNjcmlwdGlvblByaW1hcnkiOnsiVGV4dCI6IlZhbHVlIEFwcHMgZW5yaWNoZXMgeW91ciB3ZWIg[...]
Line Deleted : user_pref("CT3291325.mam_gk_mamEnabled.enc", "dHJ1ZQ==");
Line Deleted : user_pref("CT3291325.mam_gk_new_welcome_experience.enc", "MQ==");
Line Deleted : user_pref("CT3291325.mam_gk_pgUnloadedOnce.enc", "dHJ1ZQ==");
Line Deleted : user_pref("CT3291325.mam_gk_settings1.10.4.0.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiMzVfMCIsImlzVGVzdCI6dHJ1ZSwiVXNlckNvdW50cnlDb2RlIjoiVVMiLCJpc1dlbGNvbWVFeHBl[...]
Line Deleted : user_pref("CT3291325.mam_gk_showWelcomeGadget.enc", "ZmFsc2U=");
Line Deleted : user_pref("CT3291325.mam_gk_userId.enc", "ZmM1Y2Y1N2MtMmJmYS00MjBhLWI5MDctOWE0NzFmMDcyMTNl");
Line Deleted : user_pref("CT3291325.mam_gk_user_approval_interacted.enc", "MQ==");
Line Deleted : user_pref("CT3291325.mam_gk_welcomeDialogMode.enc", "MQ==");
Line Deleted : user_pref("CT3291325.missingMachineIdSent", "true");
Line Deleted : user_pref("CT3291325.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"about%3Ablank\",\"EB_MAIN_FRAME_TITLE\":\"\",\"EB_SEARCH_TERM\":\"\",\"EB_TOOLBAR_SUB_DOMAIN\":\"hxxp://KeyBar112.OurToolbar.com/[...]
Line Deleted : user_pref("CT3291325.openThankYouPage", "false");
Line Deleted : user_pref("CT3291325.openUninstallPage", "true");
Line Deleted : user_pref("CT3291325.originalHomepage", "chrome://branding/locale/browserconfig.properties");
Line Deleted : user_pref("CT3291325.originalSearchAddressUrl", "");
Line Deleted : user_pref("CT3291325.originalSearchEngine", "Google");
Line Deleted : user_pref("CT3291325.originalSearchEngineName", "Google");
Line Deleted : user_pref("CT3291325.revertSettingsEnabled", "false");
Line Deleted : user_pref("CT3291325.search.searchAppId", "130075605210846225");
Line Deleted : user_pref("CT3291325.search.searchCount", "0");
Line Deleted : user_pref("CT3291325.searchFromAddressBarEnabledByUser", "true");
Line Deleted : user_pref("CT3291325.searchInNewTabEnabledByUser", "false");
Line Deleted : user_pref("CT3291325.searchInNewTabEnabledInHidden", "true");
Line Deleted : user_pref("CT3291325.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"false\"}");
Line Deleted : user_pref("CT3291325.searchSuggestEnabledByUser", "false");
Line Deleted : user_pref("CT3291325.searchUserMode", "2");
Line Deleted : user_pref("CT3291325.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3291325.sendUsageEnabled", "false");
Line Deleted : user_pref("CT3291325.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3291325.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
Line Deleted : user_pref("CT3291325.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3291325\"}");
Line Deleted : user_pref("CT3291325.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://KeyBar112.OurToolbar.com//xpi\"}");
Line Deleted : user_pref("CT3291325.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"KeyBar 1.12 \"}");
Line Deleted : user_pref("CT3291325.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3291325.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
Line Deleted : user_pref("CT3291325.serviceLayer_services_Configuration_lastUpdate", "1379491784221");
Line Deleted : user_pref("CT3291325.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1378827590265");
Line Deleted : user_pref("CT3291325.serviceLayer_services_appsMetadata_lastUpdate", "1379492094103");
Line Deleted : user_pref("CT3291325.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1378827590393");
Line Deleted : user_pref("CT3291325.serviceLayer_services_login_10.20.0.513_lastUpdate", "1379491783768");
Line Deleted : user_pref("CT3291325.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1378827590314");
Line Deleted : user_pref("CT3291325.serviceLayer_services_searchAPI_lastUpdate", "1379491784086");
Line Deleted : user_pref("CT3291325.serviceLayer_services_serviceMap_lastUpdate", "1379491783691");
Line Deleted : user_pref("CT3291325.serviceLayer_services_setupAPI_lastUpdate", "1378827587520");
Line Deleted : user_pref("CT3291325.serviceLayer_services_toolbarContextMenu_lastUpdate", "1378827590082");
Line Deleted : user_pref("CT3291325.serviceLayer_services_toolbarSettings_lastUpdate", "1379492094162");
Line Deleted : user_pref("CT3291325.serviceLayer_services_translation_lastUpdate", "1379491783644");
Line Deleted : user_pref("CT3291325.settingsINI", true);
Line Deleted : user_pref("CT3291325.shouldFirstTimeDialog", "false");
Line Deleted : user_pref("CT3291325.showToolbarPermission", "false");
Line Deleted : user_pref("CT3291325.smartbar.CTID", "CT3291325");
Line Deleted : user_pref("CT3291325.smartbar.Uninstall", "0");
Line Deleted : user_pref("CT3291325.smartbar.homepage", true);
Line Deleted : user_pref("CT3291325.smartbar.toolbarName", "KeyBar 1.12 ");
Line Deleted : user_pref("CT3291325.startPage", "true");
Line Deleted : user_pref("CT3291325.toolbarBornServerTime", "10-9-2013");
Line Deleted : user_pref("CT3291325.toolbarCurrentServerTime", "18-9-2013");
Line Deleted : user_pref("CT3291325.toolbarDisabled", "true");
Line Deleted : user_pref("CT3291325.toolbarLoginClientTime", "Tue Sep 10 2013 10:39:46 GMT-0500 (Central Standard Time)");
Line Deleted : user_pref("CT3291325.url_history0001.enc", "aHR0cDovL3d3dy52ZXJ0b3IuY29tL2luZGV4LnBocD9tb2Q9ZG93bmxvYWQmaWQ9MzA1MDExOTo6OmNsaWNraGFuZGxlcjo6OjEzNzg4MjgxNzQyMzcsLCxodHRwOi8vd3d3LnZlcnRvci5jb20vaW5kZXgu[...]
Line Deleted : user_pref("CT3291325_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1379491773182,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Line Deleted : user_pref("CT3310511.ConnectTB_activeApp.enc", "aW5zdGFncmFt");
Line Deleted : user_pref("CT3310511.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3310511.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3310511.FF19Solved", "true");
Line Deleted : user_pref("CT3310511.FirstTime", "true");
Line Deleted : user_pref("CT3310511.FirstTimeFF3", "true");
Line Deleted : user_pref("CT3310511.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3310511&SearchSource=2&CUI=UN30238264301369158&UM=2&q=");
Line Deleted : user_pref("CT3310511.UserID", "UN30238264301369158");
Line Deleted : user_pref("CT3310511.addressBarTakeOverEnabledInHidden", "true");
Line Deleted : user_pref("CT3310511.browser.search.defaultthis.engineName", "true");
Line Deleted : user_pref("CT3310511.countryCode", "US");
Line Deleted : user_pref("CT3310511.defaultSearch", "true");
Line Deleted : user_pref("CT3310511.embeddedsData", "[{\"appId\":\"10000002\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"instantAlert\":[...]
Line Deleted : user_pref("CT3310511.enableAlerts", "true");
Line Deleted : user_pref("CT3310511.enableSearchFromAddressBar", "true");
Line Deleted : user_pref("CT3310511.firstTimeDialogOpened", "true");
Line Deleted : user_pref("CT3310511.fixPageNotFoundError", "true");
Line Deleted : user_pref("CT3310511.fixPageNotFoundErrorByUser", "true");
Line Deleted : user_pref("CT3310511.fixPageNotFoundErrorInHidden", "true");
Line Deleted : user_pref("CT3310511.fullUserID", "UN30238264301369158.IN.20131121120833");
Line Deleted : user_pref("CT3310511.installDate", "21/11/2013 12:08:42");
Line Deleted : user_pref("CT3310511.installId", "cid116");
Line Deleted : user_pref("CT3310511.installSessionId", "{0FE2866D-86E8-4BAA-8081-46DDD7968341}");
Line Deleted : user_pref("CT3310511.installSp", "TRUE");
Line Deleted : user_pref("CT3310511.installType", "conduitnsisintegration");
Line Deleted : user_pref("CT3310511.installUsage", "2013-11-26T21:38:49.7910164+03:00");
Line Deleted : user_pref("CT3310511.installUsageEarly", "2013-11-26T21:38:47.9502282+03:00");
Line Deleted : user_pref("CT3310511.installerVersion", "1.8.1.4");
Line Deleted : user_pref("CT3310511.isCheckedStartAsHidden", true);
Line Deleted : user_pref("CT3310511.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3310511.isFirstTimeToolbarLoading", "false");
Line Deleted : user_pref("CT3310511.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Line Deleted : user_pref("CT3310511.keyword", "true");
Line Deleted : user_pref("CT3310511.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT3310511&octid=CT3310511&SearchSource=15&CUI=UN30238264301369158&SSPV=&Lay=1&UM=2\"}");
Line Deleted : user_pref("CT3310511.lastVersion", "10.22.5.10");
Line Deleted : user_pref("CT3310511.mam_gk_installer_preapproved.enc", "ZmFsc2U=");
Line Deleted : user_pref("CT3310511.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fus.yhs4.search.yahoo.com%2Fyhs%2Ferrorhandler%3Fhsimp%3Dyhse-001%26hspart%3DCND%26type%3DA65[...]
Line Deleted : user_pref("CT3310511.openThankYouPage", "false");
Line Deleted : user_pref("CT3310511.openUninstallPage", "true");
Line Deleted : user_pref("CT3310511.originalHomepage", "hxxp://search.conduit.com/?ctid=CT3317740&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP7D026309-D893-4E45-B6AB-722D3AB61157&SSPV=");
Line Deleted : user_pref("CT3310511.originalSearchAddressUrl", "");
Line Deleted : user_pref("CT3310511.originalSearchEngine", "Conduit Search");
Line Deleted : user_pref("CT3310511.originalSearchEngineName", "DuckDuckGo");
Line Deleted : user_pref("CT3310511.revertSettingsEnabled", "false");
Line Deleted : user_pref("CT3310511.search.searchAppId", "10000002");
Line Deleted : user_pref("CT3310511.search.searchCount", "0");
Line Deleted : user_pref("CT3310511.searchFromAddressBarEnabledByUser", "true");
Line Deleted : user_pref("CT3310511.searchInNewTabEnabledByUser", "true");
Line Deleted : user_pref("CT3310511.searchInNewTabEnabledInHidden", "true");
Line Deleted : user_pref("CT3310511.searchRevert", "false");
Line Deleted : user_pref("CT3310511.searchSuggestEnabledByUser", "true");
Line Deleted : user_pref("CT3310511.searchUninstallUserMode", "2");
Line Deleted : user_pref("CT3310511.searchUserMode", "2");
Line Deleted : user_pref("CT3310511.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3310511.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3310511.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
Line Deleted : user_pref("CT3310511.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3310511\"}");
Line Deleted : user_pref("CT3310511.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://SweetPacks.OurToolbar.com//xpi\"}");
Line Deleted : user_pref("CT3310511.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"SweetPacks \"}");
Line Deleted : user_pref("CT3310511.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
Line Deleted : user_pref("CT3310511.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
Line Deleted : user_pref("CT3310511.serviceLayer_services_Configuration_lastUpdate", "1385491163279");
Line Deleted : user_pref("CT3310511.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1385491164356");
Line Deleted : user_pref("CT3310511.serviceLayer_services_appsMetadata_lastUpdate", "1385491164737");
Line Deleted : user_pref("CT3310511.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1385491164671");
Line Deleted : user_pref("CT3310511.serviceLayer_services_installUsage_ToolbarInstallEarly_lastUpdate", "1385491163305");
Line Deleted : user_pref("CT3310511.serviceLayer_services_installUsage_ToolbarInstall_lastUpdate", "1385491165473");
Line Deleted : user_pref("CT3310511.serviceLayer_services_login_10.22.5.10_lastUpdate", "1385491164954");
Line Deleted : user_pref("CT3310511.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1385491164624");
Line Deleted : user_pref("CT3310511.serviceLayer_services_searchAPI_lastUpdate", "1385491163313");
Line Deleted : user_pref("CT3310511.serviceLayer_services_serviceMap_lastUpdate", "1385491162798");
Line Deleted : user_pref("CT3310511.serviceLayer_services_toolbarContextMenu_lastUpdate", "1385491164571");
Line Deleted : user_pref("CT3310511.serviceLayer_services_toolbarSettings_lastUpdate", "1385491163078");
Line Deleted : user_pref("CT3310511.serviceLayer_services_translation_lastUpdate", "1385491164518");
Line Deleted : user_pref("CT3310511.settingsINI", true);
Line Deleted : user_pref("CT3310511.shouldFirstTimeDialog", "false");
Line Deleted : user_pref("CT3310511.showToolbarPermission", "false");
Line Deleted : user_pref("CT3310511.smartbar.CTID", "CT3310511");
Line Deleted : user_pref("CT3310511.smartbar.Uninstall", "0");
Line Deleted : user_pref("CT3310511.smartbar.homepage", "true");
Line Deleted : user_pref("CT3310511.smartbar.toolbarName", "SweetPacks ");
Line Deleted : user_pref("CT3310511.startPage", "true");
Line Deleted : user_pref("CT3310511.toolbarBornServerTime", "26-11-2013");
Line Deleted : user_pref("CT3310511.toolbarCurrentServerTime", "26-11-2013");
Line Deleted : user_pref("CT3310511.toolbarInstallDate", "21-11-2013 12:08:34");
Line Deleted : user_pref("CT3310511.toolbarLoginClientTime", "Tue Nov 26 2013 12:39:24 GMT-0600 (Central Standard Time)");
Line Deleted : user_pref("CT3310511.versionFromInstaller", "10.22.5.10");
Line Deleted : user_pref("CT3310511.xpeMode", "0");
Line Deleted : user_pref("CT3310511_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1385491158297,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Line Deleted : user_pref("Smartbar.ConduitHomepagesList", "");
Line Deleted : user_pref("Smartbar.ConduitSearchEngineList", "SweetPacks Customized Web Search");
Line Deleted : user_pref("Smartbar.ConduitSearchUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3310511&SearchSource=2&CUI=UN30238264301369158&UM=2&q=");
Line Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
Line Deleted : user_pref("Smartbar.keywordURLSelectedCTID", "CT3310511");
Line Deleted : user_pref("browser.newtab.url", "hxxp://search.conduit.com/?ctid=CT3317740&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=2&UP=SP7D026309-D893-4E45-B6AB-722D3AB61157");
Line Deleted : user_pref("extensions.enabledAddons", "secureLogin%40blueimp.net:1.0.3,autofillForms%40blueimp.net:0.9.9.0,%7B277c4e95-2731-4488-8450-7714a3c30da1%7D:1.0,ffxtlbr%40searchgol.com:1.6.0,artur.dubovoy%40[...]
Line Deleted : user_pref("extensions.searchgol.admin", false);
Line Deleted : user_pref("extensions.searchgol.aflt", "babsst");
Line Deleted : user_pref("extensions.searchgol.appId", "{4277F7CF-0000-46CF-BA49-D624465C4BAB}");
Line Deleted : user_pref("extensions.searchgol.autoRvrt", "false");
Line Deleted : user_pref("extensions.searchgol.bbDpng", "26");
Line Deleted : user_pref("extensions.searchgol.cntry", "US");
Line Deleted : user_pref("extensions.searchgol.dfltLng", "en");
Line Deleted : user_pref("extensions.searchgol.excTlbr", false);
Line Deleted : user_pref("extensions.searchgol.ffxUnstlRst", false);
Line Deleted : user_pref("extensions.searchgol.hdrMd5", "67683D2B4C80C2510CEE3075E034B76A");
Line Deleted : user_pref("extensions.searchgol.id", "1e48d6be0000000000002cd05ab0b027");
Line Deleted : user_pref("extensions.searchgol.instlDay", "15980");
Line Deleted : user_pref("extensions.searchgol.instlRef", "sst");
Line Deleted : user_pref("extensions.searchgol.lastVrsnTs", "1.8.16.1911:38:18");
Line Deleted : user_pref("extensions.searchgol.newTab", false);
Line Deleted : user_pref("extensions.searchgol.prdct", "searchgol");
Line Deleted : user_pref("extensions.searchgol.prtnrId", "searchgol");
Line Deleted : user_pref("extensions.searchgol.rvrt", "false");
Line Deleted : user_pref("extensions.searchgol.sg", "azb");
Line Deleted : user_pref("extensions.searchgol.smplGrp", "azb");
Line Deleted : user_pref("extensions.searchgol.tlbrId", "base");
Line Deleted : user_pref("extensions.searchgol.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.searchgol.vrsn", "1.8.16.19");
Line Deleted : user_pref("extensions.searchgol.vrsnTs", "1.8.16.1911:38:18");
Line Deleted : user_pref("extensions.searchgol.vrsni", "1.8.16.19");
Line Deleted : user_pref("plugin.state.npconduitfirefoxplugin", 2);
Line Deleted : user_pref("smartbar.addressBarOwnerCTID", "CT3310511");
Line Deleted : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3291325&CUI=UN14929519622089165&UM=2&SearchSource=13,hxxp://search.conduit.com/?ctid=CT3310511&CUI=UN30238264301369158&UM=2[...]
Line Deleted : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3291325&SearchSource=2&CUI=UN14929519622089165&UM=2&q=,hxxp://search.conduit.com/ResultsExt.aspx?cti[...]
Line Deleted : user_pref("smartbar.defaultSearchOwnerCTID", "CT3310511");
Line Deleted : user_pref("smartbar.homePageOwnerCTID", "CT3310511");
Line Deleted : user_pref("smartbar.machineId", "LSJARLEKXDYOO81LFR3OFZZ8DT1DMYTJ73CPA3ER8BG/QXSPKQBQW5YDXWZ6OYVCCE8BWYEUABYL1HGPQ4QNMA");
Line Deleted : user_pref("valueApps.CT3310511./9B+7E+x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E,x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E-x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E.:2z527", "247E4035422A363879453A7C36412C742E20213128335449563E4A4C2E58583D263F2E324247");
Line Deleted : user_pref("valueApps.CT3310511./9B+7E.:2z527.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E.x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E/x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E06CG5EL8:", "6E6D696D6F6B74756E77");
Line Deleted : user_pref("valueApps.CT3310511./9B+7E06CG5EL8:.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E06CG5EL;8I:K", "247E2D2F226A74736F7375717A7B747D242F4B49474F42357D5D5C3D");
Line Deleted : user_pref("valueApps.CT3310511./9B+7E06CG5EL;8I:K.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E0x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E1x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E2x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E31;CJ7C==B@MPF&QFI", "247E61393F236B25766F7874732B222D6F4250454E337B3544504A4A4F4D5A5D53335E5356433A452854555E4A334C3D3C4F46515E6269553E5D586876755C455E656E7D23722[...]
Line Deleted : user_pref("valueApps.CT3310511./9B+7E31;CJ7C==B@MPF&QFI.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E31;CJ7FK;KG#NCEP@MC+VKN.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E31;CJFB@AM=L>%PEH.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E31;CJHB>F!LAD.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E3x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E4x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E5x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E6x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E7x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E8x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E9x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E:x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E;x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E<x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E=x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E>x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7E?x305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./[email protected]", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7EAx305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7EBE3G=;D9N9=D", "372C2D326975762E3A3C7B3A39434A494841434B265146492965504656496571734D334B57");
Line Deleted : user_pref("valueApps.CT3310511./9B+7EBE3G=;D9N9=D.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511./9B+7EBx305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7ECx305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7EDx305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B+7Etx305.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511./9B-0?3G>D", "683D686A6D3F40437A737374472078784E4F257E7C7D7E2A275254255528262B2F2A3031");
Line Deleted : user_pref("valueApps.CT3310511./9B-0?3G>D.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511./9B-0?3G@6:5;", "");
Line Deleted : user_pref("valueApps.CT3310511./9B-0?3G@6:5;.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511./9B-0?3GFA7EF", "2B2E2C3D");
Line Deleted : user_pref("valueApps.CT3310511./9B-0?3GFA7EF.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511./9B-3=3ECCJA=F>", "247E333D2C452F4135276F297B7E7D21202F26313E4249357D37382F3A494D5D513F283338435D6554695B65546D57695D5D686365533C70766C66755E");
Line Deleted : user_pref("valueApps.CT3310511./9B-3=3ECCJA=F>.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511./9B/>01=9A6K6<IM;KRIE@PDAWM", "6A696B7273747576");
Line Deleted : user_pref("valueApps.CT3310511./9B/>01=9A6K6<IM;[email protected]", false);
Line Deleted : user_pref("valueApps.CT3310511./9B3=>@44I48?", "372C2D3269757633423633414847203E3D474E4D4C45474F2A554A4D2D5858585E4B554E366352564F");
Line Deleted : user_pref("valueApps.CT3310511./9B3=>@44I48?.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511./9B5BA==9CJAG", "683E3E3F70706C767A47734645794748777A7E504F");
Line Deleted : user_pref("valueApps.CT3310511./9B5BA==9CJAG.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511./9B6B11G4C56B>F;P;ANR@P", "6E6D696D6F6B74756E77797878");
Line Deleted : user_pref("valueApps.CT3310511./9B6B11G4C56B>F;P;[email protected]", false);
Line Deleted : user_pref("valueApps.CT3310511./[email protected];7B=?OFB>>RHIQS", "393F352F3E");
Line Deleted : user_pref("valueApps.CT3310511./[email protected];7B=?OFB>>RHIQS.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511./9B9643G3/9E", "6A");
Line Deleted : user_pref("valueApps.CT3310511./9B9643G3/9E.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511./9B;45>:BI9I7IE", "2B2E2C3D");
Line Deleted : user_pref("valueApps.CT3310511./9B;45>:BI9I7IE.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511./9B<:222H64<", "393F352F3E");
Line Deleted : user_pref("valueApps.CT3310511./9B<:222H64<.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511./9B<:222H64<L8DAJ", "6D70706F7673747975722A7973727A75757B21");
Line Deleted : user_pref("valueApps.CT3310511./9B<:222H64<L8DAJ.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511./9B=+03EH8H8J?:", "4443");
Line Deleted : user_pref("valueApps.CT3310511./9B=+03EH8H8J?:.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511./9B?+E2A52D8", "372C2D326975762E3A3C7B3A39434A494841434B2651464929655046566470727951555E5E52");
Line Deleted : user_pref("valueApps.CT3310511./9B?+E2A52D8.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511./9B?B0D:8AJ62<H", "6D");
Line Deleted : user_pref("valueApps.CT3310511./9B?B0D:8AJ62<H.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511./9BA@0<0BI6A7GN:6@L?", "6C");
Line Deleted : user_pref("valueApps.CT3310511./9BA@0<0BI6A7GN:6@L?.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.PG_ENABLE", "74727565");
Line Deleted : user_pref("valueApps.CT3310511.PG_ENABLE.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.SF_JUST_INSTALLED", "46414C5345");
Line Deleted : user_pref("valueApps.CT3310511.SF_JUST_INSTALLED.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.SF_STATUS", "454E41424C4544");
Line Deleted : user_pref("valueApps.CT3310511.SF_STATUS.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.SF_USER_ID", "6369645F323631313230313331323430343138313534373233");
Line Deleted : user_pref("valueApps.CT3310511.SF_USER_ID.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511._key_edilia__uID", "34636636383366362D333266322D343561662D386535372D333734393830376365656631");
Line Deleted : user_pref("valueApps.CT3310511._key_edilia__uID.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.cb_experience_000", "34");
Line Deleted : user_pref("valueApps.CT3310511.cb_experience_000.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.cb_firstuse0100", "31");
Line Deleted : user_pref("valueApps.CT3310511.cb_firstuse0100.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.cb_user_id_000", "43423739393935323234393735345F313338353439313238383331305F46697265666F78");
Line Deleted : user_pref("valueApps.CT3310511.cb_user_id_000.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.cbfirsttime", "547565204E6F7620323620323031332031323A33393A343920474D542D30363030202843656E7472616C205374616E646172642054696D6529");
Line Deleted : user_pref("valueApps.CT3310511.cbfirsttime.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.discover-experiments-photopop", "7B226E616D65223A2270686F746F706F7030222C2276657273696F6E223A31307D");
Line Deleted : user_pref("valueApps.CT3310511.discover-experiments-photopop.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.discover-periodic-reports", "7B2270696E675F30223A5B313338353439313234343830312C31343430303030305D7D");
Line Deleted : user_pref("valueApps.CT3310511.discover-periodic-reports.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.discover-user-id", "2263353934646337352D633535622D346131342D623631662D36666538613866353533373422");
Line Deleted : user_pref("valueApps.CT3310511.discover-user-id.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.ground-country-code", "22555322");
Line Deleted : user_pref("valueApps.CT3310511.ground-country-code.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.impression_session_counter", "30");
Line Deleted : user_pref("valueApps.CT3310511.impression_session_counter.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.impression_session_id", "2231353330353161392D323131302D343935392D383663302D37616233613965353531613022");
Line Deleted : user_pref("valueApps.CT3310511.impression_session_id.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.impression_session_last_active", "31333835343931333637303831");
Line Deleted : user_pref("valueApps.CT3310511.impression_session_last_active.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appStateReportTime", "31333835343931313639363536");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appStateReportTime.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appState_CouponBuddy", "6F6E");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appState_CouponBuddy.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appState_Discover", "6F6E");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appState_Discover.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appState_Discover_Apps", "6F6E");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appState_Discover_Apps.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appState_Easytobook", "6F6E");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appState_Easytobook.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appState_Easytobook_targeted", "6F6E");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appState_Easytobook_targeted.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appState_Find-a-Pro", "6F6E");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appState_Find-a-Pro.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appState_PriceGong", "6F6E");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appState_PriceGong.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appState_WindowShopper", "6F6E");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appState_WindowShopper.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appState_YieldKit", "6F6E");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appState_YieldKit.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appState_app13", "6F6E");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appState_app13.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appsConfig.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appsDefaultEnabled", "74727565");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_appsDefaultEnabled.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_calledSetupService", "31");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_calledSetupService.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_currentVersion", "312E31312E342E32");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_currentVersion.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_existingUsersRecoveryDone", "31");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_existingUsersRecoveryDone.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_first_time", "31");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_first_time.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_globalKeysMigratedToLocalStorage", "31");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_globalKeysMigratedToLocalStorage.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_lastLoginTime", "31333835343931313639383830");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_lastLoginTime.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_localization.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_mamEnabled", "74727565");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_mamEnabled.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_migrated_from_ls", "31");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_migrated_from_ls.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_new_welcome_experience", "31");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_new_welcome_experience.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_settings1.11.4.2.storedInFile", true);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_showWelcomeGadget", "66616C7365");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_showWelcomeGadget.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_stamp", "38365F30");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_stamp.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_userId", "6E756C6C");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_userId.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_user_approval_interacted", "31");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_user_approval_interacted.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_welcomeDialogMode", "31");
Line Deleted : user_pref("valueApps.CT3310511.mam_gk_welcomeDialogMode.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.rematchagent-periodic-reports", "7B2270696E675F30223A5B313338353439313138393532352C31343430303030305D7D");
Line Deleted : user_pref("valueApps.CT3310511.rematchagent-periodic-reports.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.rematchagent-user-id", "2234356237623361612D396333392D346337382D383662352D66313638326237363135646222");
Line Deleted : user_pref("valueApps.CT3310511.rematchagent-user-id.storedInFile", false);
Line Deleted : user_pref("valueApps.CT3310511.url_history0001", "73746172743A3A3A636C69636B68616E646C65723A3A3A313338353439313238383533362C2C2C73746172743A3A3A636C69636B68616E646C65723A3A3A31333835343931323935343434[...]
Line Deleted : user_pref("valueApps.CT3310511.url_history0001.storedInFile", true);

*************************

AdwCleaner[R0].txt - [56635 octets] - [07/12/2013 09:05:12]
AdwCleaner[S0].txt - [57090 octets] - [07/12/2013 09:05:55]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [57151 octets] ##########
----------------------
OTL Extras logfile created on: 12/7/2013 9:15:40 AM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Alex\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16428)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.84 Gb Total Physical Memory | 1.98 Gb Available Physical Memory | 51.57% Memory free
7.68 Gb Paging File | 5.63 Gb Available in Paging File | 73.29% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 449.66 Gb Total Space | 386.85 Gb Free Space | 86.03% Space Free | Partition Type: NTFS
Drive E: | 7.16 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive F: | 931.48 Gb Total Space | 881.02 Gb Free Space | 94.58% Space Free | Partition Type: NTFS
Drive J: | 5.46 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive K: | 7.62 Gb Total Space | 7.62 Gb Free Space | 100.00% Space Free | Partition Type: FAT32

Computer Name: ALEX-PC | User Name: Alex | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = OperaStable] -- C:\Program Files (x86)\Opera\Launcher.exe (Opera Software)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = OperaStable] -- C:\Program Files (x86)\Opera\Launcher.exe (Opera Software)

[HKEY_USERS\S-1-5-21-128065933-3734797803-567976751-1000\SOFTWARE\Classes\<extension>]
.html [@ = OperaStable] -- C:\Program Files (x86)\Opera\Launcher.exe (Opera Software)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Opera\launcher.exe" -noautoupdate "%1" (Opera Software)
https [open] -- "C:\Program Files (x86)\Opera\launcher.exe" -noautoupdate "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [Browse with FastStone] -- "C:\Program Files (x86)\FastStone Image Viewer\FSViewer.exe" "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Scan with Trojan Remover] -- C:\Program Files (x86)\Trojan Remover\rmvtrjan.exe /d "%1" (Simply Super Software)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Opera\launcher.exe" -noautoupdate "%1" (Opera Software)
https [open] -- "C:\Program Files (x86)\Opera\launcher.exe" -noautoupdate "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [Browse with FastStone] -- "C:\Program Files (x86)\FastStone Image Viewer\FSViewer.exe" "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Scan with Trojan Remover] -- C:\Program Files (x86)\Trojan Remover\rmvtrjan.exe /d "%1" (Simply Super Software)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{027BFC2E-3C34-4488-89DE-6983DDA934DC}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{0435E474-4E62-41A1-AB6F-4EC5E875472E}" = rport=139 | protocol=6 | dir=out | app=system |
"{1CE1B2C2-918B-42EC-876E-9AE6C14D4BC9}" = lport=445 | protocol=6 | dir=in | app=system |
"{27E41ECB-53BA-44E1-B226-2551249C198C}" = rport=445 | protocol=6 | dir=out | app=system |
"{4528DCF8-CBF4-4539-983A-DB78BA0F9586}" = lport=2869 | protocol=6 | dir=in | app=system |
"{4FD9A018-A3CB-49A3-8E83-7382D7CFD169}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{5DDE82A5-CDBA-4337-BD2F-3BCF7625578A}" = lport=10243 | protocol=6 | dir=in | app=system |
"{6036BC0E-0E28-4132-9052-D192F37040E1}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |
"{60DFFA64-2920-455B-8ED5-B1AE655F010C}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{68A4A9DA-3915-4B17-9DDA-ED0DD2EAE44F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6A6DA2B3-E402-4F2A-B148-8D6F4C9548DA}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{6DDA714E-7123-4825-8B2E-A8C316637B10}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{79EF668B-8C64-4A1C-AB3F-A910E689184C}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{85FB6EE6-F8BE-4F01-BC99-713F02559565}" = lport=53 | protocol=17 | dir=in | app=c:\program files (x86)\acer\wdagent\dcdhcpservice.exe |
"{A10B1C4C-EF9C-4FF8-B8AE-57A113BA02CC}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{A2268BD4-4C3B-4C37-AF13-1A3946DD4599}" = lport=139 | protocol=6 | dir=in | app=system |
"{A7F8335D-3514-4BC8-954B-08C460B54C85}" = rport=137 | protocol=17 | dir=out | app=system |
"{ABF818B4-442C-4558-8221-C306B0529B0C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BBDB379E-F0EF-458B-90EE-5BB33A43A39E}" = rport=10243 | protocol=6 | dir=out | app=system |
"{C106A733-2B2A-4B39-971A-45171473A68A}" = lport=138 | protocol=17 | dir=in | app=system |
"{C58C46B5-771B-44E2-86A6-86E763990D0A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D5FDDE21-AEF0-4520-A5B3-9C1235E55325}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D6069AC7-7E28-43D7-A148-EC177968791D}" = lport=137 | protocol=17 | dir=in | app=system |
"{D823902D-27DC-40EE-B246-4D06F57797C3}" = rport=138 | protocol=17 | dir=out | app=system |
"{EBB52A14-CC6D-473C-A53A-68BB567305AA}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F7D900BF-96C6-4E65-9EE6-260BA45528B3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FA295828-42C8-4294-9A20-7204FD2A87E9}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01B9079A-40DE-4CA4-9FB9-8F544A3356DC}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgmfapx.exe |
"{08B79AE8-CA25-46EC-81B3-7F89E20AA3CF}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi media\dmcdaemon.exe |
"{0B1C3A32-5CCD-4735-BE2A-CA04D3F84E7B}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |
"{0C03741C-87AD-4B30-8257-6B7D949FA4EF}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{0E6A23AB-811D-440C-91F5-94BDBBE718E0}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{125C1E00-A678-432E-8C21-10AAF885A673}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgnsa.exe |
"{15551CF7-9331-42C5-98E5-A49D3426FF15}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk20\mvp\videoplayer.exe |
"{1AAF3D15-877A-49E1-9420-8C18FEF5D62D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1CE4C4BB-4E91-4C07-9672-007DA791C5D2}" = protocol=6 | dir=in | app=c:\windows\syswow64\arfc\wrtc.exe |
"{1ED8A11B-FF00-4831-AD7E-BC28BD0EAB1E}" = protocol=6 | dir=in | app=c:\windows\syswow64\muzapp.exe |
"{213E6462-3C4B-4972-A476-72618B8B75D8}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{24E7E957-EDEB-438B-968F-EB0729341D31}" = protocol=17 | dir=in | app=c:\users\alex\appdata\local\ilivid\ilivid.exe |
"{265DAA28-8CEA-4F39-B006-3EB32B998F50}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgemca.exe |
"{3FB81B1B-FED7-43C3-A659-DD0588455492}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk20\movie\playmovie.exe |
"{41805074-4301-4F46-B4B9-195E92E6FF8E}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi media\dmcdaemon.exe |
"{4547D957-70F3-49A6-9F6F-AED9AE1E0353}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgemca.exe |
"{499A3E61-91A6-48FD-8B89-D6E810B2F53B}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\dmcdaemon.exe |
"{4BF32EB6-E010-4313-B385-B3411E9B1EAE}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgdiagex.exe |
"{4CE1D7DF-E5E6-4108-A2AE-386974655A5B}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\windowsupnp.exe |
"{4EF39314-2A33-49AC-971D-41E02E9E8517}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{4FA29017-CEA5-426E-99D4-46CEC35F2CF8}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk20\mvp\musicplayer.exe |
"{5272221E-6B88-48E8-A170-0F1D72D56428}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgdiagex.exe |
"{5295D936-940C-47E7-9680-3920BF598BC8}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{545BBEA3-5020-43C6-BCF8-7976DF48D452}" = protocol=58 | dir=out | [email protected],-28546 |
"{594B39F2-F88D-4322-A0BD-44089ED144FA}" = protocol=6 | dir=in | app=c:\program files (x86)\epson software\ecprintersetup\enpapp.exe |
"{5A239645-1F2B-4735-B68F-FDE0B29EA597}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\windowsupnp.exe |
"{5BC671A0-34C4-4A6D-86CD-7289D39883E8}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{68DBB63A-2270-4195-9FCE-E8A750E6FD54}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{6CCF14B1-C3BE-44BA-94B1-F6632569D4FC}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgmfapx.exe |
"{76B9BCD6-F71D-492F-A430-80E9C5CD279C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7AB4BE4B-52CB-41B2-941F-12552D3A69C8}" = protocol=17 | dir=in | app=c:\windows\syswow64\muzapp.exe |
"{7D4FA5A3-8332-4BE3-B9DD-73B564CF903B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7E9E67E0-D867-47D9-929C-E0A4F2A41536}" = protocol=58 | dir=in | [email protected],-28545 |
"{84FA9734-993B-4896-A8D1-851AC33AEFB7}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgnsa.exe |
"{885455AC-FA16-48BF-B518-D89B302E3366}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{8F4F6EC6-4436-4FD8-9A54-98A0AD34551A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{97FEF8CE-338B-48ED-A3E7-438D11F7DF1D}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |
"{994D45C5-B03C-4FFE-B315-197F79F8829B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{9E42E32A-44B1-48B0-945A-1BDB35F42B75}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{A164AACD-A3DE-4044-8125-4FA4C6D8F94B}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi media\windowsupnpmv.exe |
"{A1C570B2-5D06-48CE-BF46-6FD2E9BF3E3B}" = protocol=1 | dir=out | [email protected],-28544 |
"{A2352F64-F28F-4692-99F2-E35881E80F39}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\dmcdaemon.exe |
"{AED8B4E0-DBE7-414E-8D9C-FEBE8E0E2F52}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B0E5AC75-443D-4443-A126-FA9E609B167B}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B14E0DCD-4308-4887-BA48-2C8C26A1D309}" = protocol=6 | dir=in | app=c:\windows\system32\dmwu.exe |
"{B316B088-0F3A-4C9C-BF36-79F536BE621F}" = protocol=6 | dir=in | app=c:\users\alex\appdata\local\ilivid\ilivid.exe |
"{BB5554BC-B784-4373-AD01-F73DF56B7B90}" = protocol=17 | dir=in | app=c:\windows\syswow64\arfc\wrtc.exe |
"{BC02288B-4FAD-4BE9-B518-75B862193BE3}" = protocol=17 | dir=in | app=c:\windows\system32\dmwu.exe |
"{C2E14F2E-8AFF-446D-B942-E95FE9BFFDE0}" = protocol=1 | dir=in | [email protected],-28543 |
"{CD276ACD-C81F-44A9-A047-C06256C20373}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CDA0455B-06E4-4F25-957C-8749EB36044E}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{D1DFEEA4-9D74-4DCF-94FC-C5709BF96D09}" = protocol=6 | dir=out | app=system |
"{D6B92D54-A105-4ECC-897A-C32632C41063}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E14EF0DD-48E5-4B39-930A-F0E91E9A1721}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi media\windowsupnpmv.exe |
"{E52C0812-B3FA-452B-8C39-29BC9088C63F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E64C0412-B3F2-4181-9E19-961D10384F63}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{E84AB423-5085-4805-BB33-5AF38AE71C2E}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{ED84D0F5-A880-4830-B14F-0C3DAC147BE5}" = protocol=17 | dir=in | app=c:\windows\syswow64\arfc\wrtc.exe |
"{F535404B-04F3-4D00-A94A-AC773C783C75}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{F6F4F3BB-8EE7-4881-BDEE-D417750EE603}" = protocol=17 | dir=in | app=c:\program files (x86)\epson software\ecprintersetup\enpapp.exe |
"{FD23E6E0-59C8-4A88-8769-1D9A66E3EA55}" = protocol=6 | dir=in | app=c:\windows\syswow64\arfc\wrtc.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B78ECB0-1A6B-4E6D-89D7-0E7CE77F0427}" = MyWinLocker
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1AD147D0-BE0E-3D6C-AC11-64F6DC4163F1}" = Microsoft .NET Framework 4.5
"{1F557316-CFC0-41BD-AFF7-8BC49CE444D7}" = Shredder
"{230D1595-57DA-4933-8C4E-375797EBB7E1}" = Atheros Bluetooth Suite (64)
"{34883B9C-CDFE-46F0-9C5B-935484C218C3}" = AVG 2014
"{5E2CD4FB-4538-4831-8176-05D653C3E6D4}" = Windows Live Remote Service Resources
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6199B534-A1B6-46ED-873B-97B0ECF8F81E}" = Intel® Trusted Connect Service Client
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 3.0.7
"{682EC6E8-A300-45FD-8F09-0F3A6EA334D6}" = Acer Instant Update Service
"{6FE8A1DA-8CA6-4801-BF0F-0F2FED143FF4}" = WD SmartWare
"{7F624BD1-4FE0-432F-B928-68302E156D04}" = AVG 2014
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C775E70-A791-4DA8-BCC3-6AB7136F4484}" = Visual Studio 2012 x64 Redistributables
"{8EB588BD-D398-40D0-ADF7-BE1CEEF7C116}" = Windows Live Remote Client Resources
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A508D5A2-3AC1-4594-A718-A663D6D3CF11}" = Windows Live Remote Service Resources
"{A679FBE4-BA2D-4514-8834-030982C8B31A}" = Windows Live Remote Service Resources
"{B750FA38-7AB0-42CB-ACBB-E7DBE9FF603F}" = Windows Live Remote Client Resources
"{CFF3C688-2198-4BC3-A399-598226949C39}" = Windows Live Remote Client Resources
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"AVG" = AVG 2014
"Elantech" = ETDWare PS/2-X64 10.6.9.9_WHQL
"EPSON WF-3540 Series" = EPSON WF-3540 Series Printer Uninstall
"sp6" = Logitech SetPoint 6.61

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03BF5CB1-B72E-4CA6-A278-F65680F05420}" = HP Picasso Media Center Add-In
"{05E379CC-F626-4E7D-8354-463865B303BF}" = Windows Live UX Platform Language Pack
"{0A5B39D2-7ED6-4779-BCC9-37F381139DB3}" = Adobe AIR
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}" = Backup Manager V3
"{0D261C88-454B-46FE-B43B-640E621BDA11}" = Windows Live Mail
"{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{21DD6041-7251-40FA-9D06-C5EB30268E0F}" = Qualcomm Atheros Direct Connect
"{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel® USB 3.0 eXtensible Host Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F83217040FF}" = Java 7 Update 45
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Qualcomm Atheros WiFi Driver Installation
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}" = Windows Live
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{39F15B50-A977-4CA6-B1C3-6A8724CDA025}" = MyWinLocker 4
"{3B9A92DA-6374-4872-B646-253F18624D5F}" = Windows Live Writer
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{402ED4A1-8F5B-387A-8688-997ABF58B8F2}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup
"{43B43577-2514-4CE0-B14A-7E85C17C0453}" = Windows Live Essentials
"{4664ED39-C80A-48F7-93CD-EBDCAFAB6CC5}" = Windows Live Writer Resources
"{488F0347-C4A7-4374-91A7-30818BEDA710}" = Galerie de photos Windows Live
"{48C0DC5E-820A-44F2-890E-29B68EDD3C78}" = Windows Live Writer
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5C6F884D-680C-448B-B4C9-22296EE1B206}" = Logitech Harmony Remote Software 7
"{5D273F60-0525-48BA-A5FB-D0CAA4A952AE}" = Windows Live Movie Maker
"{613C0AC5-3A67-4B94-8B13-9176AD83F5BF}" = newsXpresso
"{62687B11-58B5-4A18-9BC3-9DF4CE03F194}" = Windows Live Writer Resources
"{634F79E1-2A41-4C40-9E8D-89EC740AC9D6}" = Harmony Browser Plug-in
"{644063FA-ABA3-42AC-A8AC-3EDC0706018B}" = Windows Live Mesh
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{695C8469-7822-4B31-A673-5ED84815B649}" = Epson E-Web Print
"{698BBAD8-B116-495D-B879-0F07A533E57F}" = Samsung Story Album Viewer
"{6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}" = Windows Live Movie Maker
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-acer" = WildTangent Games App (Acer Games)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7170F93F-6B61-4DC1-A664-0E222744CEC7}" = Citrix online plug-in (DV)
"{72E40002-8CEC-47C1-A099-83AC8E173BF0}" = WD Drive Utilities
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{75FEF7D1-4C05-4659-BDAC-BC56284DB377}" = SearchMe Toolbar v8.3
"{77477AEA-5757-47D8-8B33-939F43D82218}" = Windows Live UX Platform Language Pack
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{78DAE910-CA72-450E-AD22-772CB1A00678}" = Windows Live Mesh
"{7D1C7B9F-2744-4388-B128-5C75B8BCCC84}" = Windows Live Essentials
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{80F19EAA-44C4-47C2-AE87-1C7628E858D6}" = Logitech Harmony Remote Software 7
"{83270912-15C7-4336-822E-E8F1B1BBCA60}" = WD Security
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{841F1FB4-FDF8-461C-A496-3E1CFD84C0B5}" = Windows Live Mesh
"{8471021C-F529-43DE-84DF-3612E10F58C4}" = Remote Control USB Driver
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8D68CE08-9A14-4B7B-9857-3C646A2F34C7}" = Fooz Kids Platform
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8FF3891F-01B5-4A71-BFCD-20761890471C}" = Windows Live Messenger
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}" = Visual Studio 2012 x86 Redistributables
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9DA3F03B-2CEE-4344-838E-117861E61FAF}" = Windows Live Mail
"{9FAE6E8D-E686-49F5-A574-0A58DFD9580C}" = Windows Live Mail
"{A0382E3C-7384-429A-9BFA-AF5888E5A193}" = Acer Crystal Eye Webcam
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A199DB88-E22D-4CE7-90AC-B8BE396D7BF4}" = Windows Live Movie Maker
"{A3AD65CC-B2CE-49da-AE4E-CC2ECF4EC0F8}" = clear.fi SDK - MVP 2
"{A41A708E-3BE6-4561-855D-44027C1CF0F8}" = Windows Live Photo Common
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A737E18A-5171-40D0-8034-7DD243420081}" = Software Updater
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB61A2E9-37D3-485D-9085-19FBDF8CEF4A}" = Windows Live Messenger
"{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.8) MUI
"{AE66F944-596A-4D09-9A1C-DAF3DE836991}" = Citrix online plug-in (HDX)
"{B26438B4-BF51-49C3-9567-7F14A5E40CB9}" = Dolby Home Theater v4
"{B33B61FE-701F-425F-98AB-2B85725CBF68}" = Windows Live Photo Common
"{B3BE54A4-8DFE-4593-8E66-56AB7133B812}" = Windows Live Writer
"{B5AD89F2-03D3-4206-8487-018298007DD0}" = clear.fi Photo
"{B8ECD0D3-AE08-4891-B6C7-32F96B75EB6C}" = EPSON Printer Finder
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C893D8C0-1BA0-4517-B11C-E89B65E72F70}" = Windows Live Photo Common
"{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}" = RealDownloader
"{C9E1343D-E21E-4508-A1BE-04A089EC137D}" = Windows Live Messenger
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}" = NTI Media Maker 9
"{D3E5A972-9A15-427D-AE78-8181A5FD943C}" = eBay Worldwide
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D641760F-FE66-4655-99B9-59A451F2FFAB}" = Citrix online plug-in (USB)
"{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}" = Epson Connect Printer Setup
"{DAF7BB88-6392-40aa-A714-8392C4BDBD2C}" = clear.fi SDK- Movie 2
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DF71ABBB-B834-41C0-BB58-80B0545D754C}" = Windows Live UX Platform Language Pack
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E727A662-AF9F-4DEE-81C5-F4A1686F3DFC}" = Windows Live Writer Resources
"{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}" = Galería fotográfica de Windows Live
"{E9AF1707-3F3A-49E2-8345-4F2D629D0876}" = clear.fi Media
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F77EF646-19EB-11E1-9A9E-984BE15F174E}" = Evernote v. 4.5.2
"{F7A46527-DF1F-4B0F-9637-98547E189442}" = Windows Live Galeria de Fotos
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{F9F0C5D5-AAE5-45FA-95C2-CA1EE0FA067A}" = Citrix online plug-in (Web)
"{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel® OpenCL CPU Runtime
"{FCDB0EF3-673C-FDCE-6498-750F51391660}" = Fooz Kids
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AnyDVD" = AnyDVD
"BN_DesktopReader" = NOOK for PC
"BurnAware Professional_is1" = BurnAware Professional 6.5
"CitrixOnlinePluginPackWeb" = Citrix online plug-in - web
"DriverFinder" = DriverFinder
"DVD-Cloner 2013_is1" = DVD-Cloner V10.60 Build 1210
"DVDFab 8 Qt_is1" = DVDFab 8.1.0.2 (30/06/2011) Qt Beta
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPSON Scanner" = EPSON Scan
"FastStone Image Viewer" = FastStone Image Viewer 4.9
"FoozKids" = Fooz Kids
"HandBrake" = HandBrake 0.9.9.1
"Identity Card" = Identity Card
"IECT3310511" = SweetPacks Toolbar for IE
"InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}" = Acer Backup Manager
"InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite
"InstallShield_{613C0AC5-3A67-4B94-8B13-9176AD83F5BF}" = newsXpresso
"InstallShield_{698BBAD8-B116-495D-B879-0F07A533E57F}" = Samsung Story Album Viewer
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"InstallShield_{A0382E3C-7384-429A-9BFA-AF5888E5A193}" = Acer Crystal Eye Webcam
"InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}" = NTI Media Maker 9
"InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso
"IrfanView" = IrfanView (remove only)
"LManager" = Launch Manager
"Mozilla Firefox 25.0 (x86 en-US)" = Mozilla Firefox 25.0 (x86 en-US)
"Mozilla Thunderbird 17.0.8 (x86 en-US)" = Mozilla Thunderbird 17.0.8 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Opera 17.0.1241.45" = Opera Stable 17.0.1241.45
"Opera 18.0.1284.63" = Opera Stable 18.0.1284.63
"Primg_is1" = Primg version 1.2.1.1
"RealPlayer 15.0" = RealPlayer
"Trojan Remover_is1" = Trojan Remover 6.8.8
"TrojanHunter_is1" = TrojanHunter 5.5
"USB3 Hub FW Upgrade Tool_is1" = USB3 Hub FW Upgrade Tool version 0.41
"WildTangent acer Master Uninstall" = Acer Games
"Windows 7 - Codec Pack" = Windows 7 Codec Pack 4.0.8
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WTA-18783bba-3ba4-4441-958a-1863903a9359" = Chronicles of Albian
"WTA-55aa58bb-563b-4d6e-8e43-f9dbf53d4f7d" = Bejeweled 3
"WTA-aee01df8-fb8d-4ff0-888f-8a0b73e0125a" = Agatha Christie - Death on the Nile
"WTA-c1724715-6873-43fe-be1f-56e51e86c48b" = Chuzzle Deluxe
"WTA-c223e470-f16a-4f32-87cd-5bc1c6fb4161" = Zuma's Revenge

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-128065933-3734797803-567976751-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 9/24/2013 11:04:54 AM | Computer Name = Alex-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\Alex\Downloads\SoftonicDownloader_for_dvd-decrypter.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 9/25/2013 4:11:28 AM | Computer Name = Alex-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\EPSON
Software\Download Navigator\EPSDNAVI.EXE".Error in manifest or policy file "" on
line . A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Error - 9/25/2013 7:34:47 AM | Computer Name = Alex-PC | Source = WinMgmt | ID = 10
Description =

Error - 9/25/2013 7:46:59 AM | Computer Name = Alex-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 10.0.9200.16686 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 1c4 Start
Time: 01ceb9e4cd5367b9 Termination Time: 22 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id: 2adce892-25d8-11e3-a745-7c05072bbfb9

Error - 9/25/2013 10:42:59 AM | Computer Name = Alex-PC | Source = Application Error | ID = 1000
Description = Faulting application name: IEXPLORE.EXE, version: 10.0.9200.16686,
time stamp: 0x52058cf0 Faulting module name: luckyleapbho.dll, version: 1.0.0.1,
time stamp: 0x522012b2 Exception code: 0xc0000005 Fault offset: 0x00004811 Faulting
process id: 0x21dc Faulting application start time: 0x01ceb9f394498481 Faulting application
path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path:
C:\Program Files (x86)\lucky leap\luckyleapbho.dll Report Id: c5144225-25f0-11e3-a745-7c05072bbfb9

Error - 9/25/2013 4:16:18 PM | Computer Name = Alex-PC | Source = WinMgmt | ID = 10
Description =

Error - 9/25/2013 5:18:29 PM | Computer Name = Alex-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe".
Dependent
Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 9/25/2013 5:18:29 PM | Computer Name = Alex-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe".
Dependent
Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 9/26/2013 1:33:01 AM | Computer Name = Alex-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\EPSON
Software\Download Navigator\EPSDNAVI.EXE".Error in manifest or policy file "" on
line . A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Error - 9/26/2013 6:47:34 AM | Computer Name = Alex-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Epson
Software\Download Navigator\EPSDNAVI.EXE".Error in manifest or policy file "" on
line . A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

[ System Events ]
Error - 11/26/2013 1:30:06 PM | Computer Name = Alex-PC | Source = DCOM | ID = 10010
Description =

Error - 11/26/2013 1:30:33 PM | Computer Name = Alex-PC | Source = DCOM | ID = 10010
Description =

Error - 11/26/2013 1:30:36 PM | Computer Name = Alex-PC | Source = DCOM | ID = 10010
Description =

Error - 11/26/2013 1:30:45 PM | Computer Name = Alex-PC | Source = Service Control Manager | ID = 7031
Description = The McAfee McShield service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 5000 milliseconds:
Restart the service.

Error - 11/26/2013 1:32:50 PM | Computer Name = Alex-PC | Source = DCOM | ID = 10010
Description =

Error - 11/27/2013 8:30:30 AM | Computer Name = Alex-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk2\DR6.

Error - 11/27/2013 8:30:30 AM | Computer Name = Alex-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk2\DR6.

Error - 11/27/2013 8:30:31 AM | Computer Name = Alex-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk2\DR6.

Error - 11/27/2013 8:30:31 AM | Computer Name = Alex-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk2\DR6.

Error - 11/28/2013 1:06:01 PM | Computer Name = Alex-PC | Source = DCOM | ID = 10016
Description =


< End of report >
--------------------------------------------
OTL logfile created on: 12/7/2013 9:36:07 AM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Alex\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16428)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.84 Gb Total Physical Memory | 1.69 Gb Available Physical Memory | 43.92% Memory free
7.68 Gb Paging File | 5.19 Gb Available in Paging File | 67.55% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 449.66 Gb Total Space | 386.85 Gb Free Space | 86.03% Space Free | Partition Type: NTFS
Drive E: | 7.16 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive F: | 931.48 Gb Total Space | 881.02 Gb Free Space | 94.58% Space Free | Partition Type: NTFS
Drive J: | 5.46 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive K: | 7.62 Gb Total Space | 7.62 Gb Free Space | 100.00% Space Free | Partition Type: FAT32

Computer Name: ALEX-PC | User Name: Alex | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/12/06 06:40:13 | 001,392,480 | ---- | M] () -- C:\Program Files (x86)\Opera\18.0.1284.63\opera_crashreporter.exe
PRC - [2013/12/06 06:40:12 | 043,704,160 | ---- | M] (Opera Software) -- C:\Program Files (x86)\Opera\18.0.1284.63\opera.exe
PRC - [2013/12/04 23:08:43 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Alex\Desktop\OTL.exe
PRC - [2013/11/11 22:02:14 | 003,478,544 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
PRC - [2013/11/07 22:03:50 | 004,956,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgui.exe
PRC - [2013/11/01 14:11:20 | 000,067,584 | ---- | M] (PasswordBox, Inc.) -- C:\Program Files (x86)\PasswordBox\pbbtnService.exe
PRC - [2013/09/24 01:33:08 | 000,348,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
PRC - [2013/09/23 02:35:23 | 000,296,096 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
PRC - [2013/09/04 04:16:46 | 000,844,656 | ---- | M] (Samsung) -- C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
PRC - [2013/09/04 04:16:42 | 000,311,152 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
PRC - [2013/09/04 04:16:40 | 001,564,528 | ---- | M] (Samsung) -- C:\Program Files (x86)\Samsung\Kies\Kies.exe
PRC - [2013/09/03 07:53:50 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/08/29 14:34:56 | 000,048,200 | ---- | M] () -- C:\_OTL\MovedFiles\12072013_083324\C_Windows\SysWOW64\C2MP\UpdateChecker.exe
PRC - [2013/08/14 16:19:24 | 000,039,056 | ---- | M] () -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
PRC - [2012/09/19 22:10:10 | 001,177,536 | R--- | M] (Western Digital ) -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe
PRC - [2012/09/19 22:10:06 | 001,157,056 | R--- | M] (Western Digital ) -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
PRC - [2012/09/19 22:03:58 | 005,236,664 | R--- | M] (Western Digital Technologies, Inc.) -- C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
PRC - [2012/09/06 11:50:24 | 000,248,248 | R--- | M] (Western Digital) -- C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
PRC - [2012/09/06 11:48:44 | 001,688,008 | R--- | M] (Western Digital) -- C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe
PRC - [2012/08/26 21:03:50 | 001,088,280 | ---- | M] (Mischel Internet Security) -- C:\Program Files (x86)\TrojanHunter 5.5\THGuard.exe
PRC - [2012/04/06 21:29:22 | 000,022,120 | ---- | M] () -- C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
PRC - [2012/04/06 21:29:20 | 000,040,552 | ---- | M] () -- C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
PRC - [2012/03/23 03:33:44 | 000,355,920 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe
PRC - [2012/03/23 03:33:44 | 000,343,632 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LMworker.exe
PRC - [2012/03/23 03:33:42 | 001,105,488 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2012/02/29 07:49:06 | 000,028,264 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
PRC - [2012/02/26 13:01:56 | 000,291,608 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
PRC - [2012/02/19 20:41:40 | 000,072,864 | ---- | M] (Atheros) -- C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe
PRC - [2012/02/06 18:54:04 | 000,255,376 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe
PRC - [2012/01/05 15:22:10 | 000,256,536 | ---- | M] (NTI Corporation) -- C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
PRC - [2012/01/05 15:21:44 | 000,296,984 | ---- | M] (NTI Corporation) -- C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
PRC - [2011/12/15 22:38:48 | 000,363,800 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2011/12/15 22:38:46 | 000,277,784 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2011/12/15 22:38:24 | 000,161,560 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
PRC - [2011/11/29 21:04:56 | 000,013,592 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2011/05/20 10:44:32 | 000,986,208 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
PRC - [2011/04/25 03:24:16 | 000,726,976 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
PRC - [2011/04/25 03:22:40 | 000,305,088 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\Citrix\ICA Client\concentr.exe


========== Modules (No Company Name) ==========

MOD - [2013/12/06 06:40:15 | 000,886,112 | ---- | M] () -- C:\Program Files (x86)\Opera\18.0.1284.63\libGLESv2.dll
MOD - [2013/12/06 06:40:15 | 000,108,896 | ---- | M] () -- C:\Program Files (x86)\Opera\18.0.1284.63\libEGL.dll
MOD - [2013/12/06 06:40:14 | 000,879,968 | ---- | M] () -- C:\Program Files (x86)\Opera\18.0.1284.63\ffmpegsumo.dll
MOD - [2013/12/06 06:40:13 | 001,392,480 | ---- | M] () -- C:\Program Files (x86)\Opera\18.0.1284.63\opera_crashreporter.exe
MOD - [2013/10/09 05:49:22 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ef0a534be135cd8f0d99d938d8b1814a\System.Windows.Forms.ni.dll
MOD - [2013/10/09 05:23:29 | 000,786,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc9d#\5b44a8db5b70143f27fb695b5f72930d\System.Runtime.Remoting.ni.dll
MOD - [2013/10/09 05:23:25 | 003,910,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\18e76c3868d682a7c065bccd142eeec1\WindowsBase.ni.dll
MOD - [2013/10/09 05:23:13 | 006,998,016 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\d913e7d0b1d32187e0c234f8a1a581fc\System.Core.ni.dll
MOD - [2013/10/09 05:22:57 | 000,964,096 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\edb27e2c25837f79902054965d6813cd\System.Configuration.ni.dll
MOD - [2013/09/10 13:45:00 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5aa44bce7933e4de09d935848f868a4b\System.Drawing.ni.dll
MOD - [2013/09/10 13:44:31 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5d22a30e587e2cac106b81fb351e7c08\System.ni.dll
MOD - [2013/09/10 13:44:25 | 011,499,520 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9a6c1b7af18b4d5a91dc7f8d6617522f\mscorlib.ni.dll
MOD - [2013/09/10 11:45:26 | 000,220,160 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb78#\9ebb29485ad98aa062204cf08fc89167\System.ServiceProcess.ni.dll
MOD - [2013/09/10 11:37:14 | 007,566,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\82d58d49946f82eb56bae40f3b097784\System.Xml.ni.dll
MOD - [2013/09/10 11:37:08 | 001,880,576 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\f4fff5d6e716c439b944025d3994170d\System.Xaml.ni.dll
MOD - [2013/09/10 11:37:05 | 018,545,152 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\775d60de39c6f0b49f1640c4e6c8de09\PresentationFramework.ni.dll
MOD - [2013/09/10 11:36:50 | 010,926,592 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\8e3d6080e8eaaaf28389f3742ff9acdd\PresentationCore.ni.dll
MOD - [2013/09/10 11:36:37 | 009,937,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ac79b74f022d9a096de2b884f4249543\System.ni.dll
MOD - [2013/09/10 11:21:53 | 016,547,328 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\bf2ecabcd96ec8238dc385b0a3ffa084\mscorlib.ni.dll
MOD - [2013/08/29 14:34:56 | 000,048,200 | ---- | M] () -- C:\_OTL\MovedFiles\12072013_083324\C_Windows\SysWOW64\C2MP\UpdateChecker.exe
MOD - [2013/07/10 19:07:22 | 000,756,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL
MOD - [2012/04/06 21:29:22 | 000,022,120 | ---- | M] () -- C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
MOD - [2012/04/06 21:29:20 | 000,040,552 | ---- | M] () -- C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
MOD - [2012/01/05 15:22:36 | 000,465,344 | ---- | M] () -- C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll


========== Services (SafeList) ==========

SRV:64bit: - [2013/12/03 03:02:37 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013/06/13 13:31:10 | 000,357,144 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2013/05/26 23:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2012/02/07 18:53:48 | 000,871,296 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe -- (ePowerSvc)
SRV:64bit: - [2012/02/06 18:54:04 | 000,255,376 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Live Updater Service)
SRV:64bit: - [2011/12/12 01:00:00 | 000,135,824 | ---- | M] (Seiko Epson Corporation) [Auto | Running] -- C:\Windows\SysNative\escsvc64.exe -- (EpsonScanSvc)
SRV:64bit: - [2011/12/08 17:38:24 | 000,607,456 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel®
SRV:64bit: - [2010/09/22 19:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2013/11/26 22:09:07 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/11/11 22:02:14 | 003,478,544 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2013/11/06 09:51:20 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/11/01 14:11:20 | 000,067,584 | ---- | M] (PasswordBox, Inc.) [Auto | Running] -- C:\Program Files (x86)\PasswordBox\pbbtnService.exe -- (PasswordBox)
SRV - [2013/09/24 01:33:08 | 000,348,008 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe -- (avgwd)
SRV - [2013/09/05 18:41:08 | 000,240,736 | ---- | M] (WildTangent) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe -- (GamesAppIntegrationService)
SRV - [2013/09/03 07:53:50 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/08/14 16:19:24 | 000,039,056 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
SRV - [2013/04/04 07:44:48 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2012/09/19 22:10:10 | 001,177,536 | R--- | M] (Western Digital ) [Auto | Running] -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe -- (WDRulesService)
SRV - [2012/09/19 22:10:06 | 001,157,056 | R--- | M] (Western Digital ) [Auto | Running] -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe -- (WDBackup)
SRV - [2012/09/06 11:50:24 | 000,248,248 | R--- | M] (Western Digital) [Auto | Running] -- C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe -- (WDDriveService)
SRV - [2012/07/09 01:40:10 | 000,104,912 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2012/03/23 03:33:44 | 000,355,920 | ---- | M] (Dritek System Inc.) [Auto | Running] -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe -- (DsiWMIService)
SRV - [2012/03/08 18:49:30 | 000,107,648 | ---- | M] (Atheros Commnucations) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\AdminService.exe -- (AtherosSvc)
SRV - [2012/02/29 07:49:06 | 000,028,264 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe -- (GREGService)
SRV - [2012/02/19 20:41:40 | 000,072,864 | ---- | M] (Atheros) [Auto | Running] -- C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe -- (ZAtheros Wlan Agent)
SRV - [2012/02/19 06:18:18 | 000,276,248 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2012/02/10 03:41:36 | 000,111,776 | ---- | M] (Atheros Communication Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Acer\WDAgent\DCDhcpService.exe -- (DCDhcpService)
SRV - [2012/01/05 15:22:10 | 000,256,536 | ---- | M] (NTI Corporation) [Auto | Running] -- C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2011/12/15 22:38:48 | 000,363,800 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2011/12/15 22:38:46 | 000,277,784 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2011/12/15 22:38:24 | 000,161,560 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe -- (jhi_service)
SRV - [2011/11/29 21:04:56 | 000,013,592 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV - [2011/08/31 07:11:40 | 002,425,960 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe -- (IconMan_R)
SRV - [2011/06/21 13:55:04 | 000,173,424 | ---- | M] (Egis Technology Inc. ) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe -- (EgisTec Ticket Service)
SRV - [2010/10/12 11:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010/06/01 16:31:28 | 002,804,568 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
SRV - [2009/06/10 15:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/11/21 19:30:54 | 000,046,368 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:64bit: - [2013/11/05 21:55:48 | 000,150,808 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgdiska.sys -- (Avgdiska)
DRV:64bit: - [2013/11/04 21:52:42 | 000,240,920 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
DRV:64bit: - [2013/10/31 23:00:18 | 000,212,280 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2013/10/31 22:49:46 | 000,294,712 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgloga.sys -- (Avgloga)
DRV:64bit: - [2013/10/24 22:25:58 | 000,194,872 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA)
DRV:64bit: - [2013/10/01 00:52:08 | 000,123,704 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:64bit: - [2013/09/11 10:20:00 | 000,016,152 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SWDUMon.sys -- (SWDUMon)
DRV:64bit: - [2013/09/10 00:43:02 | 000,031,544 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:64bit: - [2013/08/20 08:02:12 | 000,103,576 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2013/08/01 17:07:06 | 000,251,192 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:64bit: - [2013/07/31 05:23:57 | 000,139,352 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AnyDVD.sys -- (AnyDVD)
DRV:64bit: - [2013/05/23 00:12:52 | 000,059,160 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2013/05/23 00:12:50 | 000,076,568 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2013/05/23 00:12:48 | 000,077,592 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LEqdUsb.sys -- (LEqdUsb)
DRV:64bit: - [2013/05/23 00:12:48 | 000,013,080 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidEqd.sys -- (LHidEqd)
DRV:64bit: - [2013/03/04 06:24:27 | 000,040,344 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2012/08/23 08:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/23 08:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2012/08/23 08:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012/07/17 17:12:08 | 000,062,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2012/05/02 00:14:34 | 000,062,776 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV:64bit: - [2012/05/02 00:14:34 | 000,022,648 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV:64bit: - [2012/05/02 00:14:34 | 000,020,520 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV:64bit: - [2012/03/08 19:00:36 | 000,551,552 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:64bit: - [2012/03/08 18:59:42 | 000,281,472 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV:64bit: - [2012/03/08 18:59:24 | 000,068,736 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:64bit: - [2012/03/08 18:58:54 | 000,168,064 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV:64bit: - [2012/03/08 18:58:36 | 000,036,480 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_flt.sys -- (AthBTPort)
DRV:64bit: - [2012/03/08 18:58:18 | 000,030,848 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:64bit: - [2012/03/08 18:58:00 | 000,111,232 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_avdt.sys -- (btath_avdt)
DRV:64bit: - [2012/03/08 18:57:42 | 000,340,096 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV:64bit: - [2012/03/07 07:48:20 | 000,238,384 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
DRV:64bit: - [2012/03/01 00:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/02/26 13:01:00 | 000,788,760 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc)
DRV:64bit: - [2012/02/26 13:01:00 | 000,356,120 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub)
DRV:64bit: - [2012/02/26 13:01:00 | 000,016,152 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs)
DRV:64bit: - [2012/02/15 02:41:34 | 003,538,432 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2012/02/13 20:47:36 | 014,692,224 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2012/02/07 00:03:06 | 000,018,432 | ---- | M] (NTI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV:64bit: - [2012/02/07 00:03:06 | 000,017,408 | ---- | M] (NTI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper)
DRV:64bit: - [2011/12/05 13:23:08 | 000,331,264 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2011/11/29 20:40:32 | 000,568,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011/10/13 23:49:22 | 000,108,656 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2011/09/01 21:46:28 | 000,339,048 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsPStor.sys -- (RSPCIESTOR)
DRV:64bit: - [2011/07/13 23:35:47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/07/13 23:35:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/04/25 02:49:16 | 000,087,600 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ctxusbm.sys -- (ctxusbm)
DRV:64bit: - [2011/02/16 15:29:46 | 000,017,008 | ---- | M] (VIA Labs, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vl810filter.sys -- (vl810filter)
DRV:64bit: - [2011/01/19 20:05:04 | 000,020,552 | ---- | M] (Devguru Co., Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dgderdrv.sys -- (dgderdrv)
DRV:64bit: - [2011/01/19 19:59:18 | 000,016,392 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TFsExDisk.sys -- (TFsExDisk)
DRV:64bit: - [2010/11/20 21:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/12/30 12:21:26 | 000,031,800 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\revoflt.sys -- (Revoflt)
DRV:64bit: - [2009/07/13 19:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 19:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 19:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 18:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2009/07/13 18:35:37 | 000,025,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WSDScan.sys -- (WSDScan)
DRV:64bit: - [2009/06/10 14:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 14:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 14:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 14:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2008/05/06 17:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
DRV - [2013/07/31 05:23:57 | 000,139,352 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2011/01/19 19:59:18 | 000,016,392 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys -- (TFsExDisk)
DRV - [2009/07/13 19:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.defaultthis.engineName: ""
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.param.yahoo-fr: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: ""
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.52: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@logitech.com/HarmonyRemote,version=1.0.0: C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.5.109: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.5.109: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.5.109: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.5.109: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.5.109: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2013/09/11 09:11:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F003DA68-8256-4b37-A6C4-350FA04494DF}: C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2013/09/11 17:01:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/09/21 06:38:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/09/21 06:38:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\PasswordBox\Firefox [2013/11/21 19:31:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.8\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013/09/10 18:14:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins

[2013/09/10 16:26:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Extensions
[2010/10/23 07:38:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011/05/15 14:42:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Extensions\[email protected]
[2013/12/07 08:36:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions
[2013/11/01 16:20:38 | 000,000,000 | ---D | M] (iMacros for Firefox) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
[2013/11/06 09:03:46 | 000,342,563 | ---- | M] () (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]
[2012/12/14 10:22:18 | 000,149,045 | ---- | M] () (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]
[2012/12/12 16:11:20 | 000,083,379 | ---- | M] () (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]
[2013/11/08 05:10:47 | 000,048,768 | ---- | M] () (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{A81031F3-6CEE-4A19-809F-4E26C1D9C1D1}.xpi
[2013/09/14 14:44:35 | 000,000,904 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\yahoo.xml
[2012/09/13 07:48:16 | 000,004,140 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\youtube.xml
[2013/12/07 08:36:10 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\Extensions
[2013/11/06 09:51:01 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013/11/06 09:51:23 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
File not found (No name found) -- C:\PROGRAM FILES (X86)\MCAFEE\SITEADVISOR
File not found (No name found) -- C:\PROGRAM FILES (X86)\SEARCHME TOOLBAR\FF
File not found (No name found) -- C:\USERS\ALEX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\069K9X0A.DEFAULT\EXTENSIONS\{277C4E95-2731-4488-8450-7714A3C30DA1}
File not found (No name found) -- C:\USERS\ALEX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\069K9X0A.DEFAULT\EXTENSIONS\{7E8A1050-CF67-4575-92DF-DCC60E7D952D}
File not found (No name found) -- C:\USERS\ALEX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\069K9X0A.DEFAULT\EXTENSIONS\[email protected]

O1 HOSTS File: ([2013/11/21 12:08:52 | 000,001,349 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.2 pagead2.googlesyndication.com
O1 - Hosts: 127.0.0.2 googleadservices.com
O1 - Hosts: 127.0.0.2 www.googleadservices.com
O1 - Hosts: 127.0.0.2 partner.googleadservices.com
O1 - Hosts: 127.0.0.2 doubleclick.net
O1 - Hosts: 127.0.0.2 g.doubleclick.net
O1 - Hosts: 127.0.0.2 googleads.g.doubleclick.net
O1 - Hosts: 127.0.0.2 securepubads.g.doubleclick.net
O1 - Hosts: 127.0.0.2 ad.doubleclick.net
O1 - Hosts: 127.0.0.2 pubads.g.doubleclick.net
O1 - Hosts: 127.0.0.2 adclick.g.doubleclick.net
O1 - Hosts: 127.0.0.2 stats.g.doubleclick.net
O1 - Hosts: 127.0.0.2 fls.doubleclick.net
O1 - Hosts: 127.0.0.2 ad-emea.doubleclick.net
O1 - Hosts: 127.0.0.2 googletagservices.com
O2:64bit: - BHO: (Logitech SetPoint) - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
O2 - BHO: (E-Web Print) - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\EPSON Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (PasswordBox Helper) - {5DB69B97-934B-451D-94DB-32EF802A01CD} - C:\Program Files (x86)\PasswordBox\Application\pbbtn.dll (PasswordBox, Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (Logitech SetPoint) - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (E-Web Print) - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\EPSON Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION)
O4:64bit: - HKLM..\Run: [AthBtTray] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations)
O4:64bit: - HKLM..\Run: [AtherosBtStack] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations)
O4:64bit: - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [InstantUpdate] C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuDaemon.exe ()
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Power Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [RtHDVBg_Dolby] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (NTI Corporation)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [Dolby Home Theater v4] C:\Dolby PCEE4\pcee4.exe (Dolby Laboratories Inc.)
O4 - HKLM..\Run: [KBD] C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.exe (Microsoft)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [THGuard] C:\Program Files (x86)\TrojanHunter 5.5\THGuard.exe (Mischel Internet Security)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TrojanScanner] C:\Program Files (x86)\Trojan Remover\Trjscan.exe (Simply Super Software)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKLM..\Run: [WD Drive Unlocker] C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe (Western Digital)
O4 - HKLM..\Run: [WD Quick View] C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe (Western Digital Technologies, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-128065933-3734797803-567976751-1000..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKU\S-1-5-21-128065933-3734797803-567976751-1000..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIJHE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-3540 Series" /EF "HKCU" File not found
O4 - HKU\S-1-5-21-128065933-3734797803-567976751-1000..\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKU\S-1-5-21-128065933-3734797803-567976751-1000..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
O4 - HKU\S-1-5-21-128065933-3734797803-567976751-1000..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-128065933-3734797803-567976751-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} http://ax.emsisoft.com/asquared.cab (a-squared Scanner)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2E23478C-DA8C-4B98-93F2-54E112B15DFC}: DhcpNameServer = 192.168.4.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{32002B34-91D4-4CBD-90FD-676BCF1395D5}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=euc-jp - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=ISO-8859-1 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS936 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS949 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS950 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=UTF8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=UTF-8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=euc-jp - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=ISO-8859-1 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS936 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS949 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS950 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=UTF8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=UTF-8 - No CLSID value found
O18:64bit: - Protocol\Filter\ica - No CLSID value found
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll) - File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/04/07 23:00:28 | 004,573,206 | ---- | M] ( ) - C:\AutoUnpack444.exe -- [ NTFS ]
O32 - AutoRun File - [2011/11/01 14:39:30 | 000,000,079 | ---- | M] () - E:\autorun.inf -- [ UDF ]
O32 - AutoRun File - [2007/02/12 13:53:42 | 000,000,277 | R--- | M] () - J:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{1e640001-1b02-11e3-ba03-7c05072bbfb9}\Shell - "" = AutoRun
O33 - MountPoints2\{1e640001-1b02-11e3-ba03-7c05072bbfb9}\Shell\AutoRun\command - "" = E:\WD Drive Unlock.exe -- [2012/09/06 11:48:42 | 002,018,240 | ---- | M] (Western Digital)
O33 - MountPoints2\{3dca4bff-1b39-11e3-8ca0-7c05072bbfb9}\Shell - "" = AutoRun
O33 - MountPoints2\{3dca4bff-1b39-11e3-8ca0-7c05072bbfb9}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/12/07 09:10:17 | 000,000,000 | ---D | C] -- C:\Users\Alex\Desktop\New folder (2)
[2013/12/07 09:04:43 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013/12/07 08:32:08 | 000,000,000 | ---D | C] -- C:\_OTL
[2013/12/04 23:08:36 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Alex\Desktop\OTL.exe
[2013/12/03 21:08:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Outlook Attachment Remover
[2013/12/03 03:06:11 | 000,028,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEUDINIT.EXE
[2013/12/03 03:02:46 | 000,940,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/12/03 03:02:46 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
[2013/12/03 03:02:42 | 000,645,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll
[2013/12/03 03:02:42 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
[2013/12/03 03:02:42 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/12/03 03:02:41 | 001,926,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013/12/03 03:02:41 | 001,051,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2013/12/03 03:02:41 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2013/12/03 03:02:41 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2013/12/03 03:02:41 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013/12/03 03:02:41 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2013/12/03 03:02:41 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013/12/03 03:02:41 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2013/12/03 03:02:41 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2013/12/03 03:02:41 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2013/12/03 03:02:41 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2013/12/03 03:02:41 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013/12/03 03:02:41 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2013/12/03 03:02:41 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2013/12/03 03:02:41 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2013/12/03 03:02:41 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2013/12/03 03:02:41 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2013/12/03 03:02:41 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2013/12/03 03:02:40 | 000,942,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll
[2013/12/03 03:02:40 | 000,610,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013/12/03 03:02:40 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2013/12/03 03:02:40 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2013/12/03 03:02:40 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2013/12/03 03:02:40 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013/12/03 03:02:40 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2013/12/03 03:02:40 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/12/03 03:02:40 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2013/12/03 03:02:40 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/12/03 03:02:40 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2013/12/03 03:02:40 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2013/12/03 03:02:40 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2013/12/03 03:02:40 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2013/12/03 03:02:40 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2013/12/03 03:02:39 | 005,765,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013/12/03 03:02:39 | 000,708,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2013/12/03 03:02:39 | 000,574,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013/12/03 03:02:39 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2013/12/03 03:02:39 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2013/12/03 03:02:39 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2013/12/03 03:02:39 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2013/12/03 03:02:39 | 000,090,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/12/03 03:02:39 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2013/12/03 03:02:39 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2013/12/03 03:02:39 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2013/12/03 03:02:39 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2013/12/03 03:02:38 | 001,993,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2013/12/03 03:02:38 | 001,228,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2013/12/03 03:02:38 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2013/12/03 03:02:38 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2013/12/03 03:02:38 | 000,453,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2013/12/03 03:02:38 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2013/12/03 03:02:38 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2013/12/03 03:02:38 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013/12/03 03:02:38 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2013/12/03 03:02:38 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2013/12/03 03:02:38 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2013/12/03 03:02:38 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2013/12/03 03:02:38 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2013/12/03 03:02:37 | 000,774,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013/12/03 03:02:37 | 000,626,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013/12/03 03:02:37 | 000,548,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2013/12/03 03:02:37 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2013/12/03 03:02:37 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2013/12/03 03:02:37 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2013/12/03 03:02:37 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2013/12/03 03:02:37 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2013/12/03 03:02:37 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2013/12/03 03:02:37 | 000,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2013/12/03 03:02:37 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013/12/03 03:02:37 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2013/12/03 03:02:37 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2013/12/03 03:02:37 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2013/12/03 03:02:37 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2013/12/03 03:02:37 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2013/12/03 03:02:37 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2013/11/28 11:01:12 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\TrojanHunter
[2013/11/28 05:54:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrojanHunter
[2013/11/28 05:54:04 | 000,000,000 | ---D | C] -- C:\ProgramData\TrojanHunter
[2013/11/28 05:53:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TrojanHunter 5.5
[2013/11/28 05:50:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Licenses
[2013/11/28 05:49:58 | 000,000,000 | ---D | C] -- C:\Users\Alex\Documents\Simply Super Software
[2013/11/28 05:49:58 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Simply Super Software
[2013/11/28 05:49:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover
[2013/11/28 05:49:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trojan Remover
[2013/11/28 05:49:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software
[2013/11/27 06:37:33 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\U3
[2013/11/27 06:03:03 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
[2013/11/27 06:03:03 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\IrfanView
[2013/11/27 06:03:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IrfanView
[2013/11/27 05:53:22 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\FastStone
[2013/11/27 05:48:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FastStone Image Viewer
[2013/11/27 05:48:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FastStone Image Viewer
[2013/11/27 05:45:35 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Zoner
[2013/11/27 05:45:34 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Local\Zoner
[2013/11/27 05:45:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Zoner
[2013/11/26 08:09:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/11/21 19:31:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PasswordBox
[2013/11/12 15:43:28 | 001,474,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2013/11/12 15:42:58 | 001,930,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll
[2013/11/12 15:42:58 | 001,796,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll
[2013/11/12 15:42:57 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\credui.dll
[2013/11/12 15:42:57 | 000,190,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SmartcardCredentialProvider.dll
[2013/11/12 15:42:57 | 000,152,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SmartcardCredentialProvider.dll
[2013/11/12 15:42:22 | 001,447,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2013/11/12 15:42:22 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2013/11/12 15:42:21 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2013/11/12 15:42:20 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2013/11/12 15:42:20 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2013/11/12 15:42:04 | 000,404,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32.dll
[2013/11/12 15:42:01 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FWPUCLNT.DLL
[2013/11/12 15:42:00 | 000,830,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nshwfp.dll
[2013/11/12 15:42:00 | 000,656,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nshwfp.dll
[2013/11/12 15:42:00 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\FWPUCLNT.DLL
[2013/11/08 05:30:01 | 000,000,000 | R--D | C] -- C:\Users\Alex\Documents\My Bookmark Collections
[2013/11/08 05:09:16 | 000,000,000 | ---D | C] -- C:\Users\Alex\Documents\Linkman
[2013/11/08 05:09:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Linkman
[2013/11/08 05:00:01 | 001,233,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml4.dll
[2013/11/08 05:00:01 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdocurs.dll
[2013/11/08 05:00:01 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VB6STKIT.dll
[2013/11/08 05:00:01 | 000,089,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\vb5db.dll
[2013/11/08 05:00:00 | 000,415,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrepl35.dll
[2013/11/08 05:00:00 | 000,397,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrdo20.dll
[2013/11/08 05:00:00 | 000,287,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxbse35.dll
[2013/11/08 05:00:00 | 000,252,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrd2x35.dll
[2013/11/08 05:00:00 | 000,250,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSPDOX35.dll
[2013/11/08 05:00:00 | 000,165,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstext35.dll
[2013/11/08 04:59:59 | 001,046,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msjet35.dll
[2013/11/08 04:59:59 | 000,570,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dao350.dll
[2013/11/08 04:59:59 | 000,330,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msexch35.dll
[2013/11/08 04:59:59 | 000,250,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msexcl35.dll
[2013/11/08 04:59:59 | 000,166,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msltus35.dll
[2013/11/08 04:59:59 | 000,123,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msjint35.dll
[2013/11/08 04:59:59 | 000,024,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msjter35.dll
[2013/11/08 04:59:58 | 000,152,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\comdlg32.ocx

========== Files - Modified Within 30 Days ==========

[2013/12/07 09:33:32 | 000,000,193 | ---- | M] () -- C:\Windows\WORDPAD.INI
[2013/12/07 09:30:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/12/07 09:14:45 | 000,016,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/12/07 09:14:45 | 000,016,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/12/07 09:12:02 | 000,785,302 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/12/07 09:12:02 | 000,664,798 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/12/07 09:12:02 | 000,122,574 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/12/07 09:07:16 | 000,067,584 | -H-- | M] () -- C:\Windows\bootstat.dat
[2013/12/07 09:07:13 | 3092,533,248 | -HS- | M] () -- C:\hiberfil.sys
[2013/12/07 09:02:51 | 000,002,273 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk
[2013/12/04 23:08:43 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Alex\Desktop\OTL.exe
[2013/12/03 21:43:03 | 000,038,085 | ---- | M] () -- C:\Users\Alex\Desktop\BrowserPasswordList.html
[2013/12/03 11:32:53 | 000,736,308 | ---- | M] () -- C:\Users\Alex\AppData\Local\census.cache
[2013/12/03 11:31:53 | 000,117,762 | ---- | M] () -- C:\Users\Alex\AppData\Local\ars.cache
[2013/12/03 10:46:29 | 000,000,036 | ---- | M] () -- C:\Users\Alex\AppData\Local\housecall.guid.cache
[2013/12/03 03:02:46 | 000,940,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/12/03 03:02:46 | 000,194,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
[2013/12/03 03:02:42 | 000,645,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll
[2013/12/03 03:02:42 | 000,235,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
[2013/12/03 03:02:42 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/12/03 03:02:41 | 001,926,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013/12/03 03:02:41 | 001,051,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2013/12/03 03:02:41 | 000,703,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2013/12/03 03:02:41 | 000,616,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2013/12/03 03:02:41 | 000,440,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013/12/03 03:02:41 | 000,337,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2013/12/03 03:02:41 | 000,233,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013/12/03 03:02:41 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2013/12/03 03:02:41 | 000,151,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2013/12/03 03:02:41 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2013/12/03 03:02:41 | 000,083,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2013/12/03 03:02:41 | 000,069,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013/12/03 03:02:41 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2013/12/03 03:02:41 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2013/12/03 03:02:41 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2013/12/03 03:02:41 | 000,034,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2013/12/03 03:02:41 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2013/12/03 03:02:41 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2013/12/03 03:02:41 | 000,016,284 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2013/12/03 03:02:40 | 000,942,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll
[2013/12/03 03:02:40 | 000,610,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013/12/03 03:02:40 | 000,553,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2013/12/03 03:02:40 | 000,127,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2013/12/03 03:02:40 | 000,116,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2013/12/03 03:02:40 | 000,112,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013/12/03 03:02:40 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2013/12/03 03:02:40 | 000,086,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/12/03 03:02:40 | 000,086,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2013/12/03 03:02:40 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/12/03 03:02:40 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2013/12/03 03:02:40 | 000,056,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2013/12/03 03:02:40 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2013/12/03 03:02:40 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2013/12/03 03:02:40 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2013/12/03 03:02:39 | 005,765,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013/12/03 03:02:39 | 000,708,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2013/12/03 03:02:39 | 000,574,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013/12/03 03:02:39 | 000,247,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2013/12/03 03:02:39 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2013/12/03 03:02:39 | 000,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2013/12/03 03:02:39 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2013/12/03 03:02:39 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/12/03 03:02:39 | 000,077,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2013/12/03 03:02:39 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2013/12/03 03:02:39 | 000,040,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2013/12/03 03:02:39 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2013/12/03 03:02:38 | 001,993,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2013/12/03 03:02:38 | 001,228,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2013/12/03 03:02:38 | 000,817,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2013/12/03 03:02:38 | 000,616,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2013/12/03 03:02:38 | 000,453,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2013/12/03 03:02:38 | 000,413,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2013/12/03 03:02:38 | 000,296,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2013/12/03 03:02:38 | 000,235,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013/12/03 03:02:38 | 000,218,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2013/12/03 03:02:38 | 000,081,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2013/12/03 03:02:38 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2013/12/03 03:02:38 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2013/12/03 03:02:38 | 000,030,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2013/12/03 03:02:38 | 000,016,284 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2013/12/03 03:02:37 | 000,774,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013/12/03 03:02:37 | 000,626,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013/12/03 03:02:37 | 000,548,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2013/12/03 03:02:37 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2013/12/03 03:02:37 | 000,147,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2013/12/03 03:02:37 | 000,143,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2013/12/03 03:02:37 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2013/12/03 03:02:37 | 000,135,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2013/12/03 03:02:37 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2013/12/03 03:02:37 | 000,101,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2013/12/03 03:02:37 | 000,084,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013/12/03 03:02:37 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2013/12/03 03:02:37 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2013/12/03 03:02:37 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2013/12/03 03:02:37 | 000,048,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2013/12/03 03:02:37 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2013/12/03 03:02:37 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2013/11/28 05:54:12 | 000,059,392 | R--- | M] () -- C:\Windows\SysWow64\streamhlp.dll
[2013/11/28 05:54:11 | 000,001,113 | ---- | M] () -- C:\Users\Alex\Application Data\Microsoft\Internet Explorer\Quick Launch\TrojanHunter Scanner.lnk
[2013/11/26 22:09:06 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/11/26 22:09:06 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/11/21 19:31:23 | 000,003,726 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
[2013/11/21 19:30:54 | 000,046,368 | ---- | M] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/11/21 12:46:52 | 000,038,085 | ---- | M] () -- C:\BrowserPasswordList.html
[2013/11/14 13:02:16 | 005,432,287 | ---- | M] () -- C:\Users\Alex\Documents\wf3540ug (1).pdf
[2013/11/14 12:56:13 | 000,059,527 | ---- | M] () -- C:\Users\Alex\Documents\Staley NFA Trust.pdf
[2013/11/14 12:55:16 | 000,058,500 | ---- | M] () -- C:\Users\Alex\Documents\Epson_11142013105121.pdf
[2013/11/14 12:40:53 | 000,000,000 | -H-- | M] () -- C:\Users\Alex\Documents\Default.rdp

========== Files Created - No Company Name ==========

[2013/12/07 09:33:32 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2013/12/03 21:43:03 | 000,038,085 | ---- | C] () -- C:\Users\Alex\Desktop\BrowserPasswordList.html
[2013/12/03 11:32:53 | 000,736,308 | ---- | C] () -- C:\Users\Alex\AppData\Local\census.cache
[2013/12/03 11:31:53 | 000,117,762 | ---- | C] () -- C:\Users\Alex\AppData\Local\ars.cache
[2013/12/03 10:46:29 | 000,000,036 | ---- | C] () -- C:\Users\Alex\AppData\Local\housecall.guid.cache
[2013/12/03 03:02:41 | 000,016,284 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2013/12/03 03:02:38 | 000,016,284 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2013/11/28 05:54:11 | 000,001,113 | ---- | C] () -- C:\Users\Alex\Application Data\Microsoft\Internet Explorer\Quick Launch\TrojanHunter Scanner.lnk
[2013/11/28 05:53:59 | 000,059,392 | R--- | C] () -- C:\Windows\SysWow64\streamhlp.dll
[2013/11/21 12:46:52 | 000,038,085 | ---- | C] () -- C:\BrowserPasswordList.html
[2013/11/14 13:02:16 | 005,432,287 | ---- | C] () -- C:\Users\Alex\Documents\wf3540ug (1).pdf
[2013/11/14 12:56:13 | 000,059,527 | ---- | C] () -- C:\Users\Alex\Documents\Staley NFA Trust.pdf
[2013/11/14 12:55:16 | 000,058,500 | ---- | C] () -- C:\Users\Alex\Documents\Epson_11142013105121.pdf
[2013/11/14 12:40:53 | 000,000,000 | -H-- | C] () -- C:\Users\Alex\Documents\Default.rdp
[2013/09/25 12:18:53 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\dvdtest10024.dat
[2013/09/22 08:44:48 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib
[2013/09/21 16:40:59 | 000,000,335 | ---- | C] () -- C:\Users\Alex\AppData\Roaming\burnaware.ini
[2013/09/21 07:26:28 | 000,000,258 | RHS- | C] () -- C:\Users\Alex\ntuser.pol
[2013/09/19 03:47:58 | 000,003,726 | ---- | C] () -- C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
[2013/07/26 07:24:22 | 006,275,760 | ---- | C] () -- C:\Windows\SysWow64\avcodec-lav-55.dll
[2013/07/26 07:24:22 | 001,239,216 | ---- | C] () -- C:\Windows\SysWow64\avformat-lav-55.dll
[2013/07/26 07:24:22 | 000,394,416 | ---- | C] () -- C:\Windows\SysWow64\swscale-lav-2.dll
[2013/07/26 07:24:22 | 000,288,944 | ---- | C] () -- C:\Windows\SysWow64\avutil-lav-52.dll
[2013/07/26 07:24:22 | 000,235,184 | ---- | C] () -- C:\Windows\SysWow64\avfilter-lav-3.dll
[2013/07/26 07:24:22 | 000,190,640 | ---- | C] () -- C:\Windows\SysWow64\libbluray.dll
[2013/07/26 07:24:22 | 000,150,192 | ---- | C] () -- C:\Windows\SysWow64\avresample-lav-1.dll
[2013/06/08 05:54:10 | 003,915,776 | ---- | C] () -- C:\Windows\SysWow64\ffmpeg.dll
[2013/06/08 05:53:06 | 000,112,640 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2013/06/08 05:52:30 | 000,271,360 | ---- | C] () -- C:\Windows\SysWow64\TomsMoComp_ff.dll
[2013/06/08 05:52:12 | 000,157,184 | ---- | C] () -- C:\Windows\SysWow64\ff_unrar.dll
[2013/06/08 05:52:10 | 000,147,456 | ---- | C] () -- C:\Windows\SysWow64\ff_libmad.dll
[2013/06/08 05:52:10 | 000,099,840 | ---- | C] () -- C:\Windows\SysWow64\ff_wmv9.dll
[2013/06/08 05:52:08 | 001,525,760 | ---- | C] () -- C:\Windows\SysWow64\ff_samplerate.dll
[2013/06/08 05:52:08 | 000,211,968 | ---- | C] () -- C:\Windows\SysWow64\ff_libdts.dll
[2013/06/08 05:52:08 | 000,114,688 | ---- | C] () -- C:\Windows\SysWow64\ff_liba52.dll
[2013/06/08 05:52:06 | 000,136,704 | ---- | C] () -- C:\Windows\SysWow64\libmpeg2_ff.dll
[2013/04/04 07:19:29 | 000,778,008 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/10/12 10:40:52 | 001,622,706 | ---- | C] () -- C:\Users\Alex\Localizable.strings
[2012/09/29 16:47:28 | 000,000,178 | ---- | C] () -- C:\Windows\SysWow64\Formats.ini
[2012/05/02 00:06:26 | 000,963,912 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2012/05/02 00:06:24 | 000,261,208 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2012/05/02 00:06:19 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2012/05/02 00:06:19 | 000,058,880 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2012/05/02 00:06:18 | 013,209,600 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2011/12/08 17:14:58 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll
[2011/05/13 08:27:44 | 000,001,288 | ---- | C] () -- C:\Users\Alex\reset.cmd

========== ZeroAccess Check ==========

[2009/07/13 22:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/07/25 20:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/25 19:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 19:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 21:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 19:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/09/10 16:26:28 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Amazon
[2013/10/25 01:17:01 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\AVG
[2013/09/09 16:14:29 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\AVG2014
[2013/09/10 10:41:36 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Barnes & Noble
[2013/09/10 12:04:13 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\clear.fiMVPSDK20
[2013/09/25 12:18:52 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\DVD-Cloner
[2013/09/20 11:29:57 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\HandBrake
[2013/09/17 01:53:03 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\ICAClient
[2013/11/27 06:03:03 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\IrfanView
[2013/09/11 17:01:54 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Leadertech
[2013/09/10 17:39:09 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Opera
[2013/09/09 16:18:33 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Opera Software
[2013/09/18 01:10:59 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Samsung
[2013/09/09 16:06:35 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Screensaver
[2013/11/28 05:49:58 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Simply Super Software
[2013/10/23 11:24:16 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\TGF Interactive LLC
[2013/09/10 17:39:23 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Thunderbird
[2013/10/23 11:23:07 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Translate Genius
[2013/11/28 11:01:12 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\TrojanHunter
[2013/09/09 16:13:58 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\TuneUp Software
[2013/09/10 18:23:47 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\WildTangent
[2013/09/11 18:11:53 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\WinBatch
[2013/09/11 08:54:50 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Windows Live Writer
[2013/11/27 05:45:35 | 000,000,000 | ---D | M] -- C:\Users\Alex\AppData\Roaming\Zoner
[2013/09/26 08:12:44 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2013/09/26 08:12:44 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software

========== Purity Check ==========



< End of report >
--------------------------------------
You guys ROCK!!
  • 0

#5
Pyxis

Pyxis

    Trusted Helper

  • Malware Removal
  • 1,228 posts
Thanks for the logs! :) While I am preparing my next fix, could you let me know if I got this right? You uninstalled McAfee and Malwarebytes Anti-Malware, and chose to keep AVG AntiVirus Free 2014 and TrojanHunter. May I also ask whether you pay for TrojanHunter? Note that it is a trial program.
  • 0

#6
abooboo

abooboo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Forgot to unistall trojan hunter. Will do so now.
  • 0

#7
Pyxis

Pyxis

    Trusted Helper

  • Malware Removal
  • 1,228 posts

Forgot to unistall trojan hunter. Will do so now.

Note that you have Trojan Remover and TrojanHunter 5.5. Both are trial programs. If you did not purchase either, you might as well remove them unless you wish to end the trial for some reason. :) Anyway, how is your system running?

  • Step 1

    Upon careful inspection, your log indicates that the program(s) listed below is installed on your computer. I would like to request for the removal of the program(s) as it is associated with malware, adware or spyware. Please proceed to uninstalling by going to Control Panel (Windows XP) or Programs and Features (Windows Vista or Windows 7). If Windows says it cannot locate the program(s) and that it prompts for it to be removed from the list instead, do so by allowing it.

    DriverFinder
    SweetPacks Toolbar for IE
Inform me if you encounter problems in the removal process.
  • Step 2

    Copy and paste the content of the code box below into an empty Notepad window.

    Windows Registry Editor Version 5.00
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{0B1C3A32-5CCD-4735-BE2A-CA04D3F84E7B}"=-
    "{1CE4C4BB-4E91-4C07-9672-007DA791C5D2}"=-
    "{1ED8A11B-FF00-4831-AD7E-BC28BD0EAB1E}"=-
    "{24E7E957-EDEB-438B-968F-EB0729341D31}"=- 
    "{7AB4BE4B-52CB-41B2-941F-12552D3A69C8}"=-
    "{97FEF8CE-338B-48ED-A3E7-438D11F7DF1D}"=-
    "{B14E0DCD-4308-4887-BA48-2C8C26A1D309}"=-
    "{B316B088-0F3A-4C9C-BF36-79F536BE621F}"=-
    "{BB5554BC-B784-4373-AD01-F73DF56B7B90}"=-
    "{BC02288B-4FAD-4BE9-B518-75B862193BE3}"=-
    "{ED84D0F5-A880-4830-B14F-0C3DAC147BE5}"=- 
    "{FD23E6E0-59C8-4A88-8769-1D9A66E3EA55}"=-
  • Save it on your desktop as Fix.reg.
  • Open the file by double-clicking it and allow it to run. You will be prompted for an action.

    Posted Image

  • Don't be afraid as it is safe. Click Yes to proceed.
  • Step 3

    If you haven't already, download 'OTL by OldTimer' and save it to your desktop or move your existing copy into the said location.

  • Simply double-click the program icon to run it. It will ask for administrator privileges.

    Posted Image

  • Copy and paste the following into the Custom Scans/Fixes box:

    :OTL
    PRC - [2013/08/29 14:34:56 | 000,048,200 | ---- | M] () -- C:\_OTL\MovedFiles\12072013_083324\C_Windows\SysWOW64\C2MP\UpdateChecker.exe
    MOD - [2013/08/29 14:34:56 | 000,048,200 | ---- | M] () -- C:\_OTL\MovedFiles\12072013_083324\C_Windows\SysWOW64\C2MP\UpdateChecker.exe
    [2013/09/19 03:47:58 | 000,003,726 | ---- | C] () -- C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
    [2013/09/25 12:18:53 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\dvdtest10024.dat
    [2013/12/07 09:02:51 | 000,002,273 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk
    O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll) - File not found
    File not found (No name found) -- C:\USERS\ALEX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\069K9X0A.DEFAULT\EXTENSIONS\{7E8A1050-CF67-4575-92DF-DCC60E7D952D}
    File not found (No name found) -- C:\USERS\ALEX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\069K9X0A.DEFAULT\EXTENSIONS\[email protected]
    File not found (No name found) -- C:\PROGRAM FILES (X86)\MCAFEE\SITEADVISOR
    File not found (No name found) -- C:\PROGRAM FILES (X86)\SEARCHME TOOLBAR\FF
    File not found (No name found) -- C:\USERS\ALEX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\069K9X0A.DEFAULT\EXTENSIONS\{277C4E95-2731-4488-8450-7714A3C30DA1}
    [2013/11/08 05:10:47 | 000,048,768 | ---- | M] () (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{A81031F3-6CEE-4A19-809F-4E26C1D9C1D1}.xpi
    
    :Files
    C:\USERS\ALEX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\069K9X0A.DEFAULT\EXTENSIONS\[email protected]
    C:\USERS\ALEX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\069K9X0A.DEFAULT\EXTENSIONS\{7E8A1050-CF67-4575-92DF-DCC60E7D952D}
    C:\USERS\ALEX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\069K9X0A.DEFAULT\EXTENSIONS\{277C4E95-2731-4488-8450-7714A3C30DA1}
    C:\PROGRAM FILES (X86)\SEARCHME TOOLBAR
    C:\PROGRAM FILES (X86)\MCAFEE\
    
    
  • Click Run Fix.
  • After, a Notepad window will appear, named MMDDYYYY_HHMMSS.log. Alternatively, you can find that log at C:\_OTL\MovedFiles\MMDDYYYY_HHMMSS.log.
  • Copy (CTRL + A and CTRL + C) and paste (CTRL + V) the content of the log in your next reply.
  • Step 4

    Download 'Junkware Removal Tool by thisisu' and save it to your desktop.

  • Ensure all programs and windows are closed before proceeding.
  • Simply double-click the program icon to run it. It will ask for administrator privileges.
  • A black window will appear. Press any key to continue.
  • Wait for it to finish. It won't take long.
  • A log will automatically pop-up once done. Alternatively, you can find JRT.txt at your desktop.
  • Copy (CTRL + A and CTRL + C) and paste (CTRL + V) the content of the log in your next reply.
  • Step 5

    Download 'SecurityCheck by screen317' and save it to your desktop.

  • Simply double-click the program icon to run it. It will ask for administrator privileges.
  • A black window will appear. Press any key to continue.
  • Wait for it to finish. It won't take long.
  • A log will automatically pop-up after once done.
  • Copy (CTRL + A and CTRL + C) and paste (CTRL + V) the content of the log in your next reply.
  • Logs to Post
In summary of the above, I will need you to post the following log(s):
  • MMDDYYYY_HHMMSS.log (OTL)
  • checkup.txt (SecurityCheck)
  • JRT.txt (Junkware Removal Tool)

  • 0

#8
abooboo

abooboo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
okay:

========== OTL ==========
Process UpdateChecker.exe killed successfully!
C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml moved successfully.
C:\Windows\SysWOW64\dvdtest10024.dat moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll deleted successfully.
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{A81031F3-6CEE-4A19-809F-4E26C1D9C1D1}.xpi moved successfully.
========== FILES ==========
File\Folder C:\USERS\ALEX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\069K9X0A.DEFAULT\EXTENSIONS\[email protected] not found.
File\Folder C:\USERS\ALEX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\069K9X0A.DEFAULT\EXTENSIONS\{7E8A1050-CF67-4575-92DF-DCC60E7D952D} not found.
File\Folder C:\USERS\ALEX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\069K9X0A.DEFAULT\EXTENSIONS\{277C4E95-2731-4488-8450-7714A3C30DA1} not found.
File\Folder C:\PROGRAM FILES (X86)\SEARCHME TOOLBAR not found.
C:\PROGRAM FILES (X86)\McAfee\Temp\qxzAB52\x64 folder moved successfully.
C:\PROGRAM FILES (X86)\McAfee\Temp\qxzAB52 folder moved successfully.
C:\PROGRAM FILES (X86)\McAfee\Temp\qxz6FC3 folder moved successfully.
C:\PROGRAM FILES (X86)\McAfee\Temp folder moved successfully.
C:\PROGRAM FILES (X86)\McAfee folder moved successfully.

OTL by OldTimer - Version 3.2.69.0 log created on 12082013_165812
-------------------------------
Results of screen317's Security Check version 0.99.77
Windows 7 Service Pack 1 x64 (UAC is disabled!)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
AVG AntiVirus Free Edition 2014
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Java 7 Update 45
Adobe Flash Player 11.9.900.152
Adobe Reader 10.1.8 Adobe Reader out of Date!
Mozilla Firefox (25.0)
Mozilla Thunderbird (17.0.8)
Google Chrome 30.0.1599.101
````````Process Check: objlist.exe by Laurent````````
AVG avgwdsvc.exe
windows defender MpCmdRun.exe
Symantec Norton Online Backup NOBuAgent.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 1%
````````````````````End of Log``````````````````````
-------------------------------
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x64
Ran by Alex on Sun 12/08/2013 at 16:59:31.92
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-128065933-3734797803-567976751-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim



~~~ Files

Successfully deleted: [File] "C:\Users\Alex\appdata\locallow\SkwConfig.bin"



~~~ Folders

Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"



~~~ FireFox

Successfully deleted the following from C:\Users\Alex\AppData\Roaming\mozilla\firefox\profiles\069k9x0a.default\prefs.js

user_pref("extensions.defaulttab.installdate", 1379970178);
Emptied folder: C:\Users\Alex\AppData\Roaming\mozilla\firefox\profiles\069k9x0a.default\minidumps [3 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sun 12/08/2013 at 17:09:54.52
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Thanks again-running tons better already.
  • 0

#9
Pyxis

Pyxis

    Trusted Helper

  • Malware Removal
  • 1,228 posts
I'll need one final check before I let you go in peace. :lol:

  • Step 1

    You currently have the following outdated program(s) installed. I highly recommend that you perform an update. You will find the download link(s) for the new version(s) below.

    Adobe Reader -- Update

    Note: Please untick any optional offers Adobe products might come with.
Uninstall the previous version(s) before installing the updated one(s). If you run into any errors, let me know.
  • Step 2

    If you haven't already, download 'OTL by OldTimer' and save it to your desktop or move your existing copy into the said location.

  • Simply double-click the program icon to run it. It will ask for administrator privileges.

    Posted Image

  • Copy and paste the following into the Custom Scans/Fixes box:

    netsvcs
    BASESERVICES
    %SYSTEMDRIVE%\*.exe
    dir "%systemdrive%\*" /S /A:L /C
    /md5start
    services.*
    explorer.exe
    Userinit.exe
    svchost.exe
    /md5stop
    CREATERESTOREPOINT
  • Click Run Scan.
  • Files are being searched and it may take some time. Once done, two Notepad windows will appear, named OTL.txt and Extras.txt. Alternatively, you can also find these at your desktop.
  • Copy and paste (CTRL + A and CTRL + C) the content of these logs in your next reply.
  • Logs to Post
In summary of the above, I will need you to post the following log(s):
  • Extras.txt (OTL)
  • OTL.txt (OTL)

  • 0

#10
abooboo

abooboo

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Thank you so much for the help.

OTL Extras logfile created on: 12/9/2013 6:13:01 PM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Alex\Desktop\programs
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16428)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.84 Gb Total Physical Memory | 1.67 Gb Available Physical Memory | 43.39% Memory free
7.68 Gb Paging File | 5.05 Gb Available in Paging File | 65.76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 449.66 Gb Total Space | 389.92 Gb Free Space | 86.72% Space Free | Partition Type: NTFS
Drive E: | 7.16 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive F: | 931.48 Gb Total Space | 881.02 Gb Free Space | 94.58% Space Free | Partition Type: NTFS
Drive J: | 5.46 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive K: | 7.62 Gb Total Space | 7.62 Gb Free Space | 100.00% Space Free | Partition Type: FAT32

Computer Name: ALEX-PC | User Name: Alex | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = OperaStable] -- C:\Program Files (x86)\Opera\Launcher.exe (Opera Software)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = OperaStable] -- C:\Program Files (x86)\Opera\Launcher.exe (Opera Software)

[HKEY_USERS\S-1-5-21-128065933-3734797803-567976751-1000\SOFTWARE\Classes\<extension>]
.html [@ = OperaStable] -- C:\Program Files (x86)\Opera\Launcher.exe (Opera Software)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Opera\launcher.exe" -noautoupdate "%1" (Opera Software)
https [open] -- "C:\Program Files (x86)\Opera\launcher.exe" -noautoupdate "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [Browse with FastStone] -- "C:\Program Files (x86)\FastStone Image Viewer\FSViewer.exe" "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Opera\launcher.exe" -noautoupdate "%1" (Opera Software)
https [open] -- "C:\Program Files (x86)\Opera\launcher.exe" -noautoupdate "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView] -- "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [Browse with FastStone] -- "C:\Program Files (x86)\FastStone Image Viewer\FSViewer.exe" "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{027BFC2E-3C34-4488-89DE-6983DDA934DC}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{0435E474-4E62-41A1-AB6F-4EC5E875472E}" = rport=139 | protocol=6 | dir=out | app=system |
"{1CE1B2C2-918B-42EC-876E-9AE6C14D4BC9}" = lport=445 | protocol=6 | dir=in | app=system |
"{27E41ECB-53BA-44E1-B226-2551249C198C}" = rport=445 | protocol=6 | dir=out | app=system |
"{4528DCF8-CBF4-4539-983A-DB78BA0F9586}" = lport=2869 | protocol=6 | dir=in | app=system |
"{4FD9A018-A3CB-49A3-8E83-7382D7CFD169}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{5DDE82A5-CDBA-4337-BD2F-3BCF7625578A}" = lport=10243 | protocol=6 | dir=in | app=system |
"{6036BC0E-0E28-4132-9052-D192F37040E1}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |
"{60DFFA64-2920-455B-8ED5-B1AE655F010C}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{68A4A9DA-3915-4B17-9DDA-ED0DD2EAE44F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6A6DA2B3-E402-4F2A-B148-8D6F4C9548DA}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{6DDA714E-7123-4825-8B2E-A8C316637B10}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{79EF668B-8C64-4A1C-AB3F-A910E689184C}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{85FB6EE6-F8BE-4F01-BC99-713F02559565}" = lport=53 | protocol=17 | dir=in | app=c:\program files (x86)\acer\wdagent\dcdhcpservice.exe |
"{A10B1C4C-EF9C-4FF8-B8AE-57A113BA02CC}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{A2268BD4-4C3B-4C37-AF13-1A3946DD4599}" = lport=139 | protocol=6 | dir=in | app=system |
"{A7F8335D-3514-4BC8-954B-08C460B54C85}" = rport=137 | protocol=17 | dir=out | app=system |
"{ABF818B4-442C-4558-8221-C306B0529B0C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BBDB379E-F0EF-458B-90EE-5BB33A43A39E}" = rport=10243 | protocol=6 | dir=out | app=system |
"{C106A733-2B2A-4B39-971A-45171473A68A}" = lport=138 | protocol=17 | dir=in | app=system |
"{C58C46B5-771B-44E2-86A6-86E763990D0A}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D5FDDE21-AEF0-4520-A5B3-9C1235E55325}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D6069AC7-7E28-43D7-A148-EC177968791D}" = lport=137 | protocol=17 | dir=in | app=system |
"{D823902D-27DC-40EE-B246-4D06F57797C3}" = rport=138 | protocol=17 | dir=out | app=system |
"{EBB52A14-CC6D-473C-A53A-68BB567305AA}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F7D900BF-96C6-4E65-9EE6-260BA45528B3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FA295828-42C8-4294-9A20-7204FD2A87E9}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01B9079A-40DE-4CA4-9FB9-8F544A3356DC}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgmfapx.exe |
"{08B79AE8-CA25-46EC-81B3-7F89E20AA3CF}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi media\dmcdaemon.exe |
"{0C03741C-87AD-4B30-8257-6B7D949FA4EF}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{0E6A23AB-811D-440C-91F5-94BDBBE718E0}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{125C1E00-A678-432E-8C21-10AAF885A673}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgnsa.exe |
"{15551CF7-9331-42C5-98E5-A49D3426FF15}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk20\mvp\videoplayer.exe |
"{1AAF3D15-877A-49E1-9420-8C18FEF5D62D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{213E6462-3C4B-4972-A476-72618B8B75D8}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{265DAA28-8CEA-4F39-B006-3EB32B998F50}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgemca.exe |
"{3FB81B1B-FED7-43C3-A659-DD0588455492}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk20\movie\playmovie.exe |
"{41805074-4301-4F46-B4B9-195E92E6FF8E}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi media\dmcdaemon.exe |
"{4547D957-70F3-49A6-9F6F-AED9AE1E0353}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgemca.exe |
"{499A3E61-91A6-48FD-8B89-D6E810B2F53B}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\dmcdaemon.exe |
"{4BF32EB6-E010-4313-B385-B3411E9B1EAE}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgdiagex.exe |
"{4CE1D7DF-E5E6-4108-A2AE-386974655A5B}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\windowsupnp.exe |
"{4EF39314-2A33-49AC-971D-41E02E9E8517}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{4FA29017-CEA5-426E-99D4-46CEC35F2CF8}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk20\mvp\musicplayer.exe |
"{5272221E-6B88-48E8-A170-0F1D72D56428}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2014\avgdiagex.exe |
"{5295D936-940C-47E7-9680-3920BF598BC8}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{545BBEA3-5020-43C6-BCF8-7976DF48D452}" = protocol=58 | dir=out | [email protected],-28546 |
"{594B39F2-F88D-4322-A0BD-44089ED144FA}" = protocol=6 | dir=in | app=c:\program files (x86)\epson software\ecprintersetup\enpapp.exe |
"{5A239645-1F2B-4735-B68F-FDE0B29EA597}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\windowsupnp.exe |
"{5BC671A0-34C4-4A6D-86CD-7289D39883E8}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{68DBB63A-2270-4195-9FCE-E8A750E6FD54}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{6CCF14B1-C3BE-44BA-94B1-F6632569D4FC}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgmfapx.exe |
"{76B9BCD6-F71D-492F-A430-80E9C5CD279C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7D4FA5A3-8332-4BE3-B9DD-73B564CF903B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7E9E67E0-D867-47D9-929C-E0A4F2A41536}" = protocol=58 | dir=in | [email protected],-28545 |
"{84FA9734-993B-4896-A8D1-851AC33AEFB7}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2014\avgnsa.exe |
"{885455AC-FA16-48BF-B518-D89B302E3366}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{8F4F6EC6-4436-4FD8-9A54-98A0AD34551A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{994D45C5-B03C-4FFE-B315-197F79F8829B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{9E42E32A-44B1-48B0-945A-1BDB35F42B75}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{A164AACD-A3DE-4044-8125-4FA4C6D8F94B}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi media\windowsupnpmv.exe |
"{A1C570B2-5D06-48CE-BF46-6FD2E9BF3E3B}" = protocol=1 | dir=out | [email protected],-28544 |
"{A2352F64-F28F-4692-99F2-E35881E80F39}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\dmcdaemon.exe |
"{AED8B4E0-DBE7-414E-8D9C-FEBE8E0E2F52}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B0E5AC75-443D-4443-A126-FA9E609B167B}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C2E14F2E-8AFF-446D-B942-E95FE9BFFDE0}" = protocol=1 | dir=in | [email protected],-28543 |
"{CD276ACD-C81F-44A9-A047-C06256C20373}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CDA0455B-06E4-4F25-957C-8749EB36044E}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{D1DFEEA4-9D74-4DCF-94FC-C5709BF96D09}" = protocol=6 | dir=out | app=system |
"{D6B92D54-A105-4ECC-897A-C32632C41063}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E14EF0DD-48E5-4B39-930A-F0E91E9A1721}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi media\windowsupnpmv.exe |
"{E52C0812-B3FA-452B-8C39-29BC9088C63F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E64C0412-B3F2-4181-9E19-961D10384F63}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{E84AB423-5085-4805-BB33-5AF38AE71C2E}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{F535404B-04F3-4D00-A94A-AC773C783C75}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{F6F4F3BB-8EE7-4881-BDEE-D417750EE603}" = protocol=17 | dir=in | app=c:\program files (x86)\epson software\ecprintersetup\enpapp.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B78ECB0-1A6B-4E6D-89D7-0E7CE77F0427}" = MyWinLocker
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1AD147D0-BE0E-3D6C-AC11-64F6DC4163F1}" = Microsoft .NET Framework 4.5
"{1F557316-CFC0-41BD-AFF7-8BC49CE444D7}" = Shredder
"{230D1595-57DA-4933-8C4E-375797EBB7E1}" = Atheros Bluetooth Suite (64)
"{34883B9C-CDFE-46F0-9C5B-935484C218C3}" = AVG 2014
"{5E2CD4FB-4538-4831-8176-05D653C3E6D4}" = Windows Live Remote Service Resources
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6199B534-A1B6-46ED-873B-97B0ECF8F81E}" = Intel® Trusted Connect Service Client
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 3.0.7
"{682EC6E8-A300-45FD-8F09-0F3A6EA334D6}" = Acer Instant Update Service
"{6FE8A1DA-8CA6-4801-BF0F-0F2FED143FF4}" = WD SmartWare
"{7F624BD1-4FE0-432F-B928-68302E156D04}" = AVG 2014
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C775E70-A791-4DA8-BCC3-6AB7136F4484}" = Visual Studio 2012 x64 Redistributables
"{8EB588BD-D398-40D0-ADF7-BE1CEEF7C116}" = Windows Live Remote Client Resources
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A508D5A2-3AC1-4594-A718-A663D6D3CF11}" = Windows Live Remote Service Resources
"{A679FBE4-BA2D-4514-8834-030982C8B31A}" = Windows Live Remote Service Resources
"{B750FA38-7AB0-42CB-ACBB-E7DBE9FF603F}" = Windows Live Remote Client Resources
"{CFF3C688-2198-4BC3-A399-598226949C39}" = Windows Live Remote Client Resources
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"AVG" = AVG 2014
"Elantech" = ETDWare PS/2-X64 10.6.9.9_WHQL
"EPSON WF-3540 Series" = EPSON WF-3540 Series Printer Uninstall
"sp6" = Logitech SetPoint 6.61

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03BF5CB1-B72E-4CA6-A278-F65680F05420}" = HP Picasso Media Center Add-In
"{05E379CC-F626-4E7D-8354-463865B303BF}" = Windows Live UX Platform Language Pack
"{0A5B39D2-7ED6-4779-BCC9-37F381139DB3}" = Adobe AIR
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}" = Backup Manager V3
"{0D261C88-454B-46FE-B43B-640E621BDA11}" = Windows Live Mail
"{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{21DD6041-7251-40FA-9D06-C5EB30268E0F}" = Qualcomm Atheros Direct Connect
"{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel® USB 3.0 eXtensible Host Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F83217040FF}" = Java 7 Update 45
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Qualcomm Atheros WiFi Driver Installation
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}" = Windows Live
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{39F15B50-A977-4CA6-B1C3-6A8724CDA025}" = MyWinLocker 4
"{3B9A92DA-6374-4872-B646-253F18624D5F}" = Windows Live Writer
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{402ED4A1-8F5B-387A-8688-997ABF58B8F2}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup
"{43B43577-2514-4CE0-B14A-7E85C17C0453}" = Windows Live Essentials
"{4664ED39-C80A-48F7-93CD-EBDCAFAB6CC5}" = Windows Live Writer Resources
"{488F0347-C4A7-4374-91A7-30818BEDA710}" = Galerie de photos Windows Live
"{48C0DC5E-820A-44F2-890E-29B68EDD3C78}" = Windows Live Writer
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5C6F884D-680C-448B-B4C9-22296EE1B206}" = Logitech Harmony Remote Software 7
"{5D273F60-0525-48BA-A5FB-D0CAA4A952AE}" = Windows Live Movie Maker
"{613C0AC5-3A67-4B94-8B13-9176AD83F5BF}" = newsXpresso
"{62687B11-58B5-4A18-9BC3-9DF4CE03F194}" = Windows Live Writer Resources
"{634F79E1-2A41-4C40-9E8D-89EC740AC9D6}" = Harmony Browser Plug-in
"{644063FA-ABA3-42AC-A8AC-3EDC0706018B}" = Windows Live Mesh
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{695C8469-7822-4B31-A673-5ED84815B649}" = Epson E-Web Print
"{698BBAD8-B116-495D-B879-0F07A533E57F}" = Samsung Story Album Viewer
"{6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}" = Windows Live Movie Maker
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-acer" = WildTangent Games App (Acer Games)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7170F93F-6B61-4DC1-A664-0E222744CEC7}" = Citrix online plug-in (DV)
"{72E40002-8CEC-47C1-A099-83AC8E173BF0}" = WD Drive Utilities
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{75FEF7D1-4C05-4659-BDAC-BC56284DB377}" = SearchMe Toolbar v8.3
"{77477AEA-5757-47D8-8B33-939F43D82218}" = Windows Live UX Platform Language Pack
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{78DAE910-CA72-450E-AD22-772CB1A00678}" = Windows Live Mesh
"{7D1C7B9F-2744-4388-B128-5C75B8BCCC84}" = Windows Live Essentials
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{80F19EAA-44C4-47C2-AE87-1C7628E858D6}" = Logitech Harmony Remote Software 7
"{83270912-15C7-4336-822E-E8F1B1BBCA60}" = WD Security
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{841F1FB4-FDF8-461C-A496-3E1CFD84C0B5}" = Windows Live Mesh
"{8471021C-F529-43DE-84DF-3612E10F58C4}" = Remote Control USB Driver
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8D68CE08-9A14-4B7B-9857-3C646A2F34C7}" = Fooz Kids Platform
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8FF3891F-01B5-4A71-BFCD-20761890471C}" = Windows Live Messenger
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}" = Visual Studio 2012 x86 Redistributables
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9DA3F03B-2CEE-4344-838E-117861E61FAF}" = Windows Live Mail
"{9FAE6E8D-E686-49F5-A574-0A58DFD9580C}" = Windows Live Mail
"{A0382E3C-7384-429A-9BFA-AF5888E5A193}" = Acer Crystal Eye Webcam
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A199DB88-E22D-4CE7-90AC-B8BE396D7BF4}" = Windows Live Movie Maker
"{A3AD65CC-B2CE-49da-AE4E-CC2ECF4EC0F8}" = clear.fi SDK - MVP 2
"{A3B308B9-BE96-4334-816F-3D82B19A7DE2}" = Software Updater
"{A41A708E-3BE6-4561-855D-44027C1CF0F8}" = Windows Live Photo Common
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB61A2E9-37D3-485D-9085-19FBDF8CEF4A}" = Windows Live Messenger
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.04)
"{AE66F944-596A-4D09-9A1C-DAF3DE836991}" = Citrix online plug-in (HDX)
"{B26438B4-BF51-49C3-9567-7F14A5E40CB9}" = Dolby Home Theater v4
"{B33B61FE-701F-425F-98AB-2B85725CBF68}" = Windows Live Photo Common
"{B3BE54A4-8DFE-4593-8E66-56AB7133B812}" = Windows Live Writer
"{B5AD89F2-03D3-4206-8487-018298007DD0}" = clear.fi Photo
"{B8ECD0D3-AE08-4891-B6C7-32F96B75EB6C}" = EPSON Printer Finder
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C893D8C0-1BA0-4517-B11C-E89B65E72F70}" = Windows Live Photo Common
"{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}" = RealDownloader
"{C9E1343D-E21E-4508-A1BE-04A089EC137D}" = Windows Live Messenger
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}" = NTI Media Maker 9
"{D3E5A972-9A15-427D-AE78-8181A5FD943C}" = eBay Worldwide
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D641760F-FE66-4655-99B9-59A451F2FFAB}" = Citrix online plug-in (USB)
"{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}" = Epson Connect Printer Setup
"{DAF7BB88-6392-40aa-A714-8392C4BDBD2C}" = clear.fi SDK- Movie 2
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DF71ABBB-B834-41C0-BB58-80B0545D754C}" = Windows Live UX Platform Language Pack
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E727A662-AF9F-4DEE-81C5-F4A1686F3DFC}" = Windows Live Writer Resources
"{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}" = Galería fotográfica de Windows Live
"{E9AF1707-3F3A-49E2-8345-4F2D629D0876}" = clear.fi Media
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F77EF646-19EB-11E1-9A9E-984BE15F174E}" = Evernote v. 4.5.2
"{F7A46527-DF1F-4B0F-9637-98547E189442}" = Windows Live Galeria de Fotos
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{F9F0C5D5-AAE5-45FA-95C2-CA1EE0FA067A}" = Citrix online plug-in (Web)
"{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel® OpenCL CPU Runtime
"{FCDB0EF3-673C-FDCE-6498-750F51391660}" = Fooz Kids
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AnyDVD" = AnyDVD
"BN_DesktopReader" = NOOK for PC
"BurnAware Professional_is1" = BurnAware Professional 6.5
"CitrixOnlinePluginPackWeb" = Citrix online plug-in - web
"DVD-Cloner 2013_is1" = DVD-Cloner V10.60 Build 1210
"DVDFab 8 Qt_is1" = DVDFab 8.1.0.2 (30/06/2011) Qt Beta
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPSON Scanner" = EPSON Scan
"FastStone Image Viewer" = FastStone Image Viewer 4.9
"FoozKids" = Fooz Kids
"HandBrake" = HandBrake 0.9.9.1
"Identity Card" = Identity Card
"InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}" = Acer Backup Manager
"InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite
"InstallShield_{613C0AC5-3A67-4B94-8B13-9176AD83F5BF}" = newsXpresso
"InstallShield_{698BBAD8-B116-495D-B879-0F07A533E57F}" = Samsung Story Album Viewer
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"InstallShield_{A0382E3C-7384-429A-9BFA-AF5888E5A193}" = Acer Crystal Eye Webcam
"InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}" = NTI Media Maker 9
"InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso
"IrfanView" = IrfanView (remove only)
"LManager" = Launch Manager
"Mozilla Firefox 25.0 (x86 en-US)" = Mozilla Firefox 25.0 (x86 en-US)
"Mozilla Thunderbird 17.0.8 (x86 en-US)" = Mozilla Thunderbird 17.0.8 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Opera 17.0.1241.45" = Opera Stable 17.0.1241.45
"Opera 18.0.1284.63" = Opera Stable 18.0.1284.63
"Primg_is1" = Primg version 1.2.1.1
"RealPlayer 15.0" = RealPlayer
"USB3 Hub FW Upgrade Tool_is1" = USB3 Hub FW Upgrade Tool version 0.41
"WildTangent acer Master Uninstall" = Acer Games
"Windows 7 - Codec Pack" = Windows 7 Codec Pack 4.0.8
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WTA-18783bba-3ba4-4441-958a-1863903a9359" = Chronicles of Albian
"WTA-55aa58bb-563b-4d6e-8e43-f9dbf53d4f7d" = Bejeweled 3
"WTA-aee01df8-fb8d-4ff0-888f-8a0b73e0125a" = Agatha Christie - Death on the Nile
"WTA-c1724715-6873-43fe-be1f-56e51e86c48b" = Chuzzle Deluxe
"WTA-c223e470-f16a-4f32-87cd-5bc1c6fb4161" = Zuma's Revenge

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-128065933-3734797803-567976751-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 12/8/2013 9:00:01 PM | Computer Name = Alex-PC | Source = Windows Backup | ID = 4103
Description =

Error - 12/9/2013 10:12:39 AM | Computer Name = Alex-PC | Source = Application Hang | ID = 1002
Description = The program opera.exe version 18.0.1284.63 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 17c4 Start
Time: 01cef41a8c0d5a26 Termination Time: 62 Application Path: C:\Program Files (x86)\Opera\18.0.1284.63\opera.exe

Report
Id: ef3a5379-60db-11e3-959b-7c05072bbfb9

[ OSession Events ]
Error - 12/3/2013 5:09:25 PM | Computer Name = Alex-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6680.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1336
seconds with 720 seconds of active time. This session ended with a crash.


< End of report >
OTL logfile created on: 12/9/2013 6:13:01 PM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Alex\Desktop\programs
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16428)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.84 Gb Total Physical Memory | 1.67 Gb Available Physical Memory | 43.39% Memory free
7.68 Gb Paging File | 5.05 Gb Available in Paging File | 65.76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 449.66 Gb Total Space | 389.92 Gb Free Space | 86.72% Space Free | Partition Type: NTFS
Drive E: | 7.16 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive F: | 931.48 Gb Total Space | 881.02 Gb Free Space | 94.58% Space Free | Partition Type: NTFS
Drive J: | 5.46 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive K: | 7.62 Gb Total Space | 7.62 Gb Free Space | 100.00% Space Free | Partition Type: FAT32

Computer Name: ALEX-PC | User Name: Alex | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/12/06 06:40:13 | 001,392,480 | ---- | M] () -- C:\Program Files (x86)\Opera\18.0.1284.63\opera_crashreporter.exe
PRC - [2013/12/06 06:40:12 | 043,704,160 | ---- | M] (Opera Software) -- C:\Program Files (x86)\Opera\18.0.1284.63\opera.exe
PRC - [2013/12/04 23:08:43 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Alex\Desktop\programs\OTL.exe
PRC - [2013/11/11 22:02:14 | 003,478,544 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
PRC - [2013/11/07 22:03:50 | 004,956,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgui.exe
PRC - [2013/11/01 14:11:20 | 000,067,584 | ---- | M] (PasswordBox, Inc.) -- C:\Program Files (x86)\PasswordBox\pbbtnService.exe
PRC - [2013/09/24 01:33:08 | 000,348,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
PRC - [2013/09/23 02:35:23 | 000,296,096 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
PRC - [2013/09/05 08:04:00 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/09/04 04:16:46 | 000,844,656 | ---- | M] (Samsung) -- C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
PRC - [2013/09/04 04:16:42 | 000,311,152 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
PRC - [2013/09/04 04:16:40 | 001,564,528 | ---- | M] (Samsung) -- C:\Program Files (x86)\Samsung\Kies\Kies.exe
PRC - [2013/08/14 16:19:24 | 000,039,056 | ---- | M] () -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
PRC - [2012/09/19 22:10:10 | 001,177,536 | R--- | M] (Western Digital ) -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe
PRC - [2012/09/19 22:10:06 | 001,157,056 | R--- | M] (Western Digital ) -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
PRC - [2012/09/19 22:03:58 | 005,236,664 | R--- | M] (Western Digital Technologies, Inc.) -- C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
PRC - [2012/09/06 11:50:24 | 000,248,248 | R--- | M] (Western Digital) -- C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
PRC - [2012/09/06 11:48:44 | 001,688,008 | R--- | M] (Western Digital) -- C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe
PRC - [2012/08/26 21:03:50 | 001,088,280 | ---- | M] (Mischel Internet Security) -- C:\Program Files (x86)\TrojanHunter 5.5\THGuard.exe
PRC - [2012/04/06 21:29:22 | 000,022,120 | ---- | M] () -- C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
PRC - [2012/04/06 21:29:20 | 000,040,552 | ---- | M] () -- C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
PRC - [2012/03/23 03:33:44 | 000,355,920 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe
PRC - [2012/03/23 03:33:44 | 000,343,632 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LMworker.exe
PRC - [2012/03/23 03:33:42 | 001,105,488 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2012/02/29 07:49:06 | 000,028,264 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
PRC - [2012/02/26 13:01:56 | 000,291,608 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
PRC - [2012/02/19 20:41:40 | 000,072,864 | ---- | M] (Atheros) -- C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe
PRC - [2012/01/05 15:22:10 | 000,256,536 | ---- | M] (NTI Corporation) -- C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
PRC - [2012/01/05 15:21:44 | 000,296,984 | ---- | M] (NTI Corporation) -- C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
PRC - [2011/12/15 22:38:48 | 000,363,800 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2011/12/15 22:38:46 | 000,277,784 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2011/12/15 22:38:24 | 000,161,560 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
PRC - [2011/11/29 21:04:56 | 000,013,592 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2011/05/20 10:44:32 | 000,986,208 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
PRC - [2011/04/25 03:24:16 | 000,726,976 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
PRC - [2011/04/25 03:22:40 | 000,305,088 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\Citrix\ICA Client\concentr.exe


========== Modules (No Company Name) ==========

MOD - [2013/12/06 06:40:15 | 000,886,112 | ---- | M] () -- C:\Program Files (x86)\Opera\18.0.1284.63\libGLESv2.dll
MOD - [2013/12/06 06:40:15 | 000,108,896 | ---- | M] () -- C:\Program Files (x86)\Opera\18.0.1284.63\libEGL.dll
MOD - [2013/12/06 06:40:14 | 000,879,968 | ---- | M] () -- C:\Program Files (x86)\Opera\18.0.1284.63\ffmpegsumo.dll
MOD - [2013/12/06 06:40:13 | 001,392,480 | ---- | M] () -- C:\Program Files (x86)\Opera\18.0.1284.63\opera_crashreporter.exe
MOD - [2013/11/26 22:09:06 | 016,237,448 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll
MOD - [2013/10/09 05:49:22 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ef0a534be135cd8f0d99d938d8b1814a\System.Windows.Forms.ni.dll
MOD - [2013/10/09 05:23:29 | 000,786,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc9d#\5b44a8db5b70143f27fb695b5f72930d\System.Runtime.Remoting.ni.dll
MOD - [2013/10/09 05:23:25 | 003,910,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\18e76c3868d682a7c065bccd142eeec1\WindowsBase.ni.dll
MOD - [2013/10/09 05:23:13 | 006,998,016 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\d913e7d0b1d32187e0c234f8a1a581fc\System.Core.ni.dll
MOD - [2013/10/09 05:22:57 | 000,964,096 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\edb27e2c25837f79902054965d6813cd\System.Configuration.ni.dll
MOD - [2013/09/10 13:45:00 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5aa44bce7933e4de09d935848f868a4b\System.Drawing.ni.dll
MOD - [2013/09/10 13:44:31 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5d22a30e587e2cac106b81fb351e7c08\System.ni.dll
MOD - [2013/09/10 13:44:25 | 011,499,520 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9a6c1b7af18b4d5a91dc7f8d6617522f\mscorlib.ni.dll
MOD - [2013/09/10 11:45:26 | 000,220,160 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb78#\9ebb29485ad98aa062204cf08fc89167\System.ServiceProcess.ni.dll
MOD - [2013/09/10 11:37:14 | 007,566,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\82d58d49946f82eb56bae40f3b097784\System.Xml.ni.dll
MOD - [2013/09/10 11:37:08 | 001,880,576 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\f4fff5d6e716c439b944025d3994170d\System.Xaml.ni.dll
MOD - [2013/09/10 11:37:05 | 018,545,152 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\775d60de39c6f0b49f1640c4e6c8de09\PresentationFramework.ni.dll
MOD - [2013/09/10 11:36:50 | 010,926,592 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\8e3d6080e8eaaaf28389f3742ff9acdd\PresentationCore.ni.dll
MOD - [2013/09/10 11:36:37 | 009,937,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ac79b74f022d9a096de2b884f4249543\System.ni.dll
MOD - [2013/09/10 11:21:53 | 016,547,328 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\bf2ecabcd96ec8238dc385b0a3ffa084\mscorlib.ni.dll
MOD - [2012/04/06 21:29:22 | 000,022,120 | ---- | M] () -- C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
MOD - [2012/04/06 21:29:20 | 000,040,552 | ---- | M] () -- C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
MOD - [2012/01/05 15:22:36 | 000,465,344 | ---- | M] () -- C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll


========== Services (SafeList) ==========

SRV:64bit: - [2013/12/03 03:02:37 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013/06/13 13:31:10 | 000,357,144 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2013/05/26 23:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2012/02/07 18:53:48 | 000,871,296 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe -- (ePowerSvc)
SRV:64bit: - [2012/02/06 18:54:04 | 000,255,376 | ---- | M] (Acer Incorporated) [Auto | Stopped] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Live Updater Service)
SRV:64bit: - [2011/12/12 01:00:00 | 000,135,824 | ---- | M] (Seiko Epson Corporation) [Auto | Running] -- C:\Windows\SysNative\escsvc64.exe -- (EpsonScanSvc)
SRV:64bit: - [2011/12/08 17:38:24 | 000,607,456 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel®
SRV:64bit: - [2010/09/22 19:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2013/11/26 22:09:07 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/11/11 22:02:14 | 003,478,544 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2013/11/06 09:51:20 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/11/01 14:11:20 | 000,067,584 | ---- | M] (PasswordBox, Inc.) [Auto | Running] -- C:\Program Files (x86)\PasswordBox\pbbtnService.exe -- (PasswordBox)
SRV - [2013/09/24 01:33:08 | 000,348,008 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe -- (avgwd)
SRV - [2013/09/05 18:41:08 | 000,240,736 | ---- | M] (WildTangent) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe -- (GamesAppIntegrationService)
SRV - [2013/09/05 08:04:00 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/08/14 16:19:24 | 000,039,056 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
SRV - [2013/04/04 07:44:48 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2012/09/19 22:10:10 | 001,177,536 | R--- | M] (Western Digital ) [Auto | Running] -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe -- (WDRulesService)
SRV - [2012/09/19 22:10:06 | 001,157,056 | R--- | M] (Western Digital ) [Auto | Running] -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe -- (WDBackup)
SRV - [2012/09/06 11:50:24 | 000,248,248 | R--- | M] (Western Digital) [Auto | Running] -- C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe -- (WDDriveService)
SRV - [2012/07/09 01:40:10 | 000,104,912 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2012/03/23 03:33:44 | 000,355,920 | ---- | M] (Dritek System Inc.) [Auto | Running] -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe -- (DsiWMIService)
SRV - [2012/03/08 18:49:30 | 000,107,648 | ---- | M] (Atheros Commnucations) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\AdminService.exe -- (AtherosSvc)
SRV - [2012/02/29 07:49:06 | 000,028,264 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe -- (GREGService)
SRV - [2012/02/19 20:41:40 | 000,072,864 | ---- | M] (Atheros) [Auto | Running] -- C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe -- (ZAtheros Wlan Agent)
SRV - [2012/02/19 06:18:18 | 000,276,248 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2012/02/10 03:41:36 | 000,111,776 | ---- | M] (Atheros Communication Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Acer\WDAgent\DCDhcpService.exe -- (DCDhcpService)
SRV - [2012/01/05 15:22:10 | 000,256,536 | ---- | M] (NTI Corporation) [Auto | Running] -- C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2011/12/15 22:38:48 | 000,363,800 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2011/12/15 22:38:46 | 000,277,784 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2011/12/15 22:38:24 | 000,161,560 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe -- (jhi_service)
SRV - [2011/11/29 21:04:56 | 000,013,592 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV - [2011/08/31 07:11:40 | 002,425,960 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe -- (IconMan_R)
SRV - [2011/06/21 13:55:04 | 000,173,424 | ---- | M] (Egis Technology Inc. ) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe -- (EgisTec Ticket Service)
SRV - [2010/10/12 11:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010/06/01 16:31:28 | 002,804,568 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
SRV - [2009/06/10 15:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/11/21 19:30:54 | 000,046,368 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:64bit: - [2013/11/05 21:55:48 | 000,150,808 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgdiska.sys -- (Avgdiska)
DRV:64bit: - [2013/11/04 21:52:42 | 000,240,920 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
DRV:64bit: - [2013/10/31 23:00:18 | 000,212,280 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2013/10/31 22:49:46 | 000,294,712 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgloga.sys -- (Avgloga)
DRV:64bit: - [2013/10/24 22:25:58 | 000,194,872 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA)
DRV:64bit: - [2013/10/01 00:52:08 | 000,123,704 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:64bit: - [2013/09/11 10:20:00 | 000,016,152 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SWDUMon.sys -- (SWDUMon)
DRV:64bit: - [2013/09/10 00:43:02 | 000,031,544 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:64bit: - [2013/08/20 08:02:12 | 000,103,576 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2013/08/01 17:07:06 | 000,251,192 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:64bit: - [2013/07/31 05:23:57 | 000,139,352 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AnyDVD.sys -- (AnyDVD)
DRV:64bit: - [2013/05/23 00:12:52 | 000,059,160 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2013/05/23 00:12:50 | 000,076,568 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2013/05/23 00:12:48 | 000,077,592 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LEqdUsb.sys -- (LEqdUsb)
DRV:64bit: - [2013/05/23 00:12:48 | 000,013,080 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidEqd.sys -- (LHidEqd)
DRV:64bit: - [2013/03/04 06:24:27 | 000,040,344 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2012/08/23 08:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/23 08:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2012/08/23 08:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012/07/17 17:12:08 | 000,062,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2012/05/02 00:14:34 | 000,062,776 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV:64bit: - [2012/05/02 00:14:34 | 000,022,648 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV:64bit: - [2012/05/02 00:14:34 | 000,020,520 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV:64bit: - [2012/03/08 19:00:36 | 000,551,552 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:64bit: - [2012/03/08 18:59:42 | 000,281,472 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV:64bit: - [2012/03/08 18:59:24 | 000,068,736 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:64bit: - [2012/03/08 18:58:54 | 000,168,064 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV:64bit: - [2012/03/08 18:58:36 | 000,036,480 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_flt.sys -- (AthBTPort)
DRV:64bit: - [2012/03/08 18:58:18 | 000,030,848 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:64bit: - [2012/03/08 18:58:00 | 000,111,232 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_avdt.sys -- (btath_avdt)
DRV:64bit: - [2012/03/08 18:57:42 | 000,340,096 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV:64bit: - [2012/03/07 07:48:20 | 000,238,384 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
DRV:64bit: - [2012/03/01 00:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/02/26 13:01:00 | 000,788,760 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc)
DRV:64bit: - [2012/02/26 13:01:00 | 000,356,120 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub)
DRV:64bit: - [2012/02/26 13:01:00 | 000,016,152 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs)
DRV:64bit: - [2012/02/15 02:41:34 | 003,538,432 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2012/02/13 20:47:36 | 014,692,224 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2012/02/07 00:03:06 | 000,018,432 | ---- | M] (NTI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV:64bit: - [2012/02/07 00:03:06 | 000,017,408 | ---- | M] (NTI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper)
DRV:64bit: - [2011/12/05 13:23:08 | 000,331,264 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2011/11/29 20:40:32 | 000,568,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011/10/13 23:49:22 | 000,108,656 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2011/09/01 21:46:28 | 000,339,048 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsPStor.sys -- (RSPCIESTOR)
DRV:64bit: - [2011/07/13 23:35:47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/07/13 23:35:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/04/25 02:49:16 | 000,087,600 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ctxusbm.sys -- (ctxusbm)
DRV:64bit: - [2011/02/16 15:29:46 | 000,017,008 | ---- | M] (VIA Labs, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vl810filter.sys -- (vl810filter)
DRV:64bit: - [2011/01/19 20:05:04 | 000,020,552 | ---- | M] (Devguru Co., Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dgderdrv.sys -- (dgderdrv)
DRV:64bit: - [2011/01/19 19:59:18 | 000,016,392 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TFsExDisk.sys -- (TFsExDisk)
DRV:64bit: - [2010/11/20 21:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/12/30 12:21:26 | 000,031,800 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\revoflt.sys -- (Revoflt)
DRV:64bit: - [2009/07/13 19:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 19:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 19:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 18:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2009/07/13 18:35:37 | 000,025,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WSDScan.sys -- (WSDScan)
DRV:64bit: - [2009/06/10 14:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 14:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 14:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 14:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2008/05/06 17:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
DRV - [2013/07/31 05:23:57 | 000,139,352 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2011/01/19 19:59:18 | 000,016,392 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys -- (TFsExDisk)
DRV - [2009/07/13 19:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-128065933-3734797803-567976751-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.defaultthis.engineName: ""
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.param.yahoo-fr: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: ""
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.52: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@logitech.com/HarmonyRemote,version=1.0.0: C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.5.109: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.5.109: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.5.109: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.5.109: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.5.109: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2013/09/11 09:11:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F003DA68-8256-4b37-A6C4-350FA04494DF}: C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2013/09/11 17:01:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/09/21 06:38:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/09/21 06:38:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\PasswordBox\Firefox [2013/11/21 19:31:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.8\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013/09/10 18:14:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0.8\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins

[2013/09/10 16:26:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Extensions
[2010/10/23 07:38:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011/05/15 14:42:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Extensions\[email protected]
[2013/12/08 16:58:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions
[2013/11/01 16:20:38 | 000,000,000 | ---D | M] (iMacros for Firefox) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
[2013/11/06 09:03:46 | 000,342,563 | ---- | M] () (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]
[2012/12/14 10:22:18 | 000,149,045 | ---- | M] () (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]
[2012/12/12 16:11:20 | 000,083,379 | ---- | M] () (No name found) -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\extensions\[email protected]
[2013/09/14 14:44:35 | 000,000,904 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\yahoo.xml
[2012/09/13 07:48:16 | 000,004,140 | ---- | M] () -- C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\069k9x0a.default\searchplugins\youtube.xml
[2013/12/07 08:36:10 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\Extensions
[2013/11/06 09:51:01 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013/11/06 09:51:23 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
File not found (No name found) -- C:\PROGRAM FILES (X86)\MCAFEE\SITEADVISOR
File not found (No name found) -- C:\PROGRAM FILES (X86)\SEARCHME TOOLBAR\FF
File not found (No name found) -- C:\USERS\ALEX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\069K9X0A.DEFAULT\EXTENSIONS\{277C4E95-2731-4488-8450-7714A3C30DA1}
File not found (No name found) -- C:\USERS\ALEX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\069K9X0A.DEFAULT\EXTENSIONS\{7E8A1050-CF67-4575-92DF-DCC60E7D952D}
File not found (No name found) -- C:\USERS\ALEX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\069K9X0A.DEFAULT\EXTENSIONS\{A81031F3-6CEE-4A19-809F-4E26C1D9C1D1}.XPI
File not found (No name found) -- C:\USERS\ALEX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\069K9X0A.DEFAULT\EXTENSIONS\[email protected]

O1 HOSTS File: ([2013/12/08 07:36:41 | 000,000,822 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Logitech SetPoint) - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
O2 - BHO: (E-Web Print) - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\EPSON Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (PasswordBox Helper) - {5DB69B97-934B-451D-94DB-32EF802A01CD} - C:\Program Files (x86)\PasswordBox\Application\pbbtn.dll (PasswordBox, Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (Logitech SetPoint) - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (E-Web Print) - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\EPSON Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION)
O4:64bit: - HKLM..\Run: [AthBtTray] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations)
O4:64bit: - HKLM..\Run: [AtherosBtStack] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations)
O4:64bit: - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [InstantUpdate] C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuDaemon.exe ()
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Power Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [RtHDVBg_Dolby] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (NTI Corporation)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [Dolby Home Theater v4] C:\Dolby PCEE4\pcee4.exe (Dolby Laboratories Inc.)
O4 - HKLM..\Run: [KBD] C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.exe (Microsoft)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKLM..\Run: [WD Drive Unlocker] C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe (Western Digital)
O4 - HKLM..\Run: [WD Quick View] C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe (Western Digital Technologies, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-128065933-3734797803-567976751-1000..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKU\S-1-5-21-128065933-3734797803-567976751-1000..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIJHE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-3540 Series" /EF "HKCU" File not found
O4 - HKU\S-1-5-21-128065933-3734797803-567976751-1000..\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKU\S-1-5-21-128065933-3734797803-567976751-1000..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
O4 - HKU\S-1-5-21-128065933-3734797803-567976751-1000..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-128065933-3734797803-567976751-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} http://ax.emsisoft.com/asquared.cab (a-squared Scanner)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2E23478C-DA8C-4B98-93F2-54E112B15DFC}: DhcpNameServer = 192.168.4.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{32002B34-91D4-4CBD-90FD-676BCF1395D5}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=euc-jp - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=ISO-8859-1 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS936 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS949 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS950 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=UTF8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=UTF-8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=euc-jp - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=ISO-8859-1 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS936 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS949 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS950 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=UTF8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=UTF-8 - No CLSID value found
O18:64bit: - Protocol\Filter\ica - No CLSID value found
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/04/07 23:00:28 | 004,573,206 | ---- | M] ( ) - C:\AutoUnpack444.exe -- [ NTFS ]
O32 - AutoRun File - [2011/11/01 14:39:30 | 000,000,079 | ---- | M] () - E:\autorun.inf -- [ UDF ]
O32 - AutoRun File - [2007/02/12 13:53:42 | 000,000,277 | R--- | M] () - J:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{1e640001-1b02-11e3-ba03-7c05072bbfb9}\Shell - "" = AutoRun
O33 - MountPoints2\{1e640001-1b02-11e3-ba03-7c05072bbfb9}\Shell\AutoRun\command - "" = E:\WD Drive Unlock.exe -- [2012/09/06 11:48:42 | 002,018,240 | ---- | M] (Western Digital)
O33 - MountPoints2\{3dca4bff-1b39-11e3-8ca0-7c05072bbfb9}\Shell - "" = AutoRun
O33 - MountPoints2\{3dca4bff-1b39-11e3-8ca0-7c05072bbfb9}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/12/09 18:10:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2013/12/09 18:06:44 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013/12/09 08:21:35 | 000,000,000 | ---D | C] -- C:\Users\Alex\Desktop\Cellphone data spying It's not just the NSA_files
[2013/12/08 16:59:30 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013/12/08 16:30:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Software
[2013/12/07 09:10:17 | 000,000,000 | ---D | C] -- C:\Users\Alex\Desktop\New folder (2)
[2013/12/07 09:04:43 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013/12/07 08:32:08 | 000,000,000 | ---D | C] -- C:\_OTL
[2013/12/03 21:08:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Outlook Attachment Remover
[2013/12/03 03:06:11 | 000,028,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEUDINIT.EXE
[2013/12/03 03:02:46 | 000,940,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/12/03 03:02:46 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
[2013/12/03 03:02:42 | 000,645,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll
[2013/12/03 03:02:42 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
[2013/12/03 03:02:42 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/12/03 03:02:41 | 001,926,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013/12/03 03:02:41 | 001,051,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2013/12/03 03:02:41 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2013/12/03 03:02:41 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2013/12/03 03:02:41 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013/12/03 03:02:41 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2013/12/03 03:02:41 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013/12/03 03:02:41 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2013/12/03 03:02:41 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2013/12/03 03:02:41 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2013/12/03 03:02:41 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2013/12/03 03:02:41 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013/12/03 03:02:41 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2013/12/03 03:02:41 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2013/12/03 03:02:41 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2013/12/03 03:02:41 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2013/12/03 03:02:41 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2013/12/03 03:02:41 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2013/12/03 03:02:40 | 000,942,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll
[2013/12/03 03:02:40 | 000,610,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013/12/03 03:02:40 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2013/12/03 03:02:40 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2013/12/03 03:02:40 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2013/12/03 03:02:40 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013/12/03 03:02:40 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2013/12/03 03:02:40 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/12/03 03:02:40 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2013/12/03 03:02:40 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/12/03 03:02:40 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2013/12/03 03:02:40 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2013/12/03 03:02:40 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2013/12/03 03:02:40 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2013/12/03 03:02:40 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2013/12/03 03:02:39 | 005,765,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013/12/03 03:02:39 | 000,708,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2013/12/03 03:02:39 | 000,574,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013/12/03 03:02:39 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2013/12/03 03:02:39 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2013/12/03 03:02:39 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2013/12/03 03:02:39 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2013/12/03 03:02:39 | 000,090,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/12/03 03:02:39 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2013/12/03 03:02:39 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2013/12/03 03:02:39 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2013/12/03 03:02:39 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2013/12/03 03:02:38 | 001,993,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2013/12/03 03:02:38 | 001,228,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2013/12/03 03:02:38 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2013/12/03 03:02:38 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2013/12/03 03:02:38 | 000,453,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2013/12/03 03:02:38 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2013/12/03 03:02:38 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2013/12/03 03:02:38 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013/12/03 03:02:38 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2013/12/03 03:02:38 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2013/12/03 03:02:38 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2013/12/03 03:02:38 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2013/12/03 03:02:38 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2013/12/03 03:02:37 | 000,774,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013/12/03 03:02:37 | 000,626,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013/12/03 03:02:37 | 000,548,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2013/12/03 03:02:37 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2013/12/03 03:02:37 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2013/12/03 03:02:37 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2013/12/03 03:02:37 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2013/12/03 03:02:37 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2013/12/03 03:02:37 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2013/12/03 03:02:37 | 000,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2013/12/03 03:02:37 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013/12/03 03:02:37 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2013/12/03 03:02:37 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2013/12/03 03:02:37 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2013/12/03 03:02:37 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2013/12/03 03:02:37 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2013/12/03 03:02:37 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2013/11/28 11:01:12 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\TrojanHunter
[2013/11/28 05:53:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TrojanHunter 5.5
[2013/11/28 05:50:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Licenses
[2013/11/27 06:37:33 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\U3
[2013/11/27 06:03:03 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
[2013/11/27 06:03:03 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\IrfanView
[2013/11/27 06:03:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IrfanView
[2013/11/27 05:53:22 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\FastStone
[2013/11/27 05:48:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FastStone Image Viewer
[2013/11/27 05:48:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FastStone Image Viewer
[2013/11/27 05:45:35 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Roaming\Zoner
[2013/11/27 05:45:34 | 000,000,000 | ---D | C] -- C:\Users\Alex\AppData\Local\Zoner
[2013/11/27 05:45:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Zoner
[2013/11/26 08:09:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/11/21 19:31:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PasswordBox
[2013/11/12 15:43:28 | 001,474,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2013/11/12 15:42:58 | 001,930,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll
[2013/11/12 15:42:58 | 001,796,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll
[2013/11/12 15:42:57 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\credui.dll
[2013/11/12 15:42:57 | 000,190,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SmartcardCredentialProvider.dll
[2013/11/12 15:42:57 | 000,152,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SmartcardCredentialProvider.dll
[2013/11/12 15:42:22 | 001,447,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2013/11/12 15:42:22 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2013/11/12 15:42:21 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2013/11/12 15:42:20 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2013/11/12 15:42:20 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2013/11/12 15:42:04 | 000,404,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32.dll
[2013/11/12 15:42:01 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FWPUCLNT.DLL
[2013/11/12 15:42:00 | 000,830,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nshwfp.dll
[2013/11/12 15:42:00 | 000,656,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nshwfp.dll
[2013/11/12 15:42:00 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\FWPUCLNT.DLL

========== Files - Modified Within 30 Days ==========

[2013/12/09 18:10:20 | 000,002,023 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2013/12/09 17:30:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/12/09 08:21:35 | 000,397,087 | ---- | M] () -- C:\Users\Alex\Desktop\Cellphone data spying It's not just the NSA.htm
[2013/12/08 17:19:58 | 000,000,193 | ---- | M] () -- C:\Windows\WORDPAD.INI
[2013/12/07 09:14:45 | 000,016,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/12/07 09:14:45 | 000,016,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/12/07 09:12:02 | 000,785,302 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/12/07 09:12:02 | 000,664,798 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/12/07 09:12:02 | 000,122,574 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/12/07 09:07:16 | 000,067,584 | -H-- | M] () -- C:\Windows\bootstat.dat
[2013/12/07 09:07:13 | 3092,533,248 | -HS- | M] () -- C:\hiberfil.sys
[2013/12/03 21:43:03 | 000,038,085 | ---- | M] () -- C:\Users\Alex\Desktop\BrowserPasswordList.html
[2013/12/03 11:32:53 | 000,736,308 | ---- | M] () -- C:\Users\Alex\AppData\Local\census.cache
[2013/12/03 11:31:53 | 000,117,762 | ---- | M] () -- C:\Users\Alex\AppData\Local\ars.cache
[2013/12/03 10:46:29 | 000,000,036 | ---- | M] () -- C:\Users\Alex\AppData\Local\housecall.guid.cache
[2013/12/03 03:02:46 | 000,940,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/12/03 03:02:46 | 000,194,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
[2013/12/03 03:02:42 | 000,645,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll
[2013/12/03 03:02:42 | 000,235,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
[2013/12/03 03:02:42 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/12/03 03:02:41 | 001,926,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013/12/03 03:02:41 | 001,051,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2013/12/03 03:02:41 | 000,703,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2013/12/03 03:02:41 | 000,616,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2013/12/03 03:02:41 | 000,440,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013/12/03 03:02:41 | 000,337,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2013/12/03 03:02:41 | 000,233,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013/12/03 03:02:41 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2013/12/03 03:02:41 | 000,151,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2013/12/03 03:02:41 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2013/12/03 03:02:41 | 000,083,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2013/12/03 03:02:41 | 000,069,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013/12/03 03:02:41 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2013/12/03 03:02:41 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2013/12/03 03:02:41 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2013/12/03 03:02:41 | 000,034,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2013/12/03 03:02:41 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2013/12/03 03:02:41 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2013/12/03 03:02:41 | 000,016,284 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2013/12/03 03:02:40 | 000,942,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll
[2013/12/03 03:02:40 | 000,610,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013/12/03 03:02:40 | 000,553,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2013/12/03 03:02:40 | 000,127,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2013/12/03 03:02:40 | 000,116,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2013/12/03 03:02:40 | 000,112,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013/12/03 03:02:40 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2013/12/03 03:02:40 | 000,086,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/12/03 03:02:40 | 000,086,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2013/12/03 03:02:40 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/12/03 03:02:40 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2013/12/03 03:02:40 | 000,056,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2013/12/03 03:02:40 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2013/12/03 03:02:40 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2013/12/03 03:02:40 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2013/12/03 03:02:39 | 005,765,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013/12/03 03:02:39 | 000,708,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2013/12/03 03:02:39 | 000,574,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013/12/03 03:02:39 | 000,247,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2013/12/03 03:02:39 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2013/12/03 03:02:39 | 000,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2013/12/03 03:02:39 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2013/12/03 03:02:39 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/12/03 03:02:39 | 000,077,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2013/12/03 03:02:39 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2013/12/03 03:02:39 | 000,040,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2013/12/03 03:02:39 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2013/12/03 03:02:38 | 001,993,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2013/12/03 03:02:38 | 001,228,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2013/12/03 03:02:38 | 000,817,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2013/12/03 03:02:38 | 000,616,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2013/12/03 03:02:38 | 000,453,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2013/12/03 03:02:38 | 000,413,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2013/12/03 03:02:38 | 000,296,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2013/12/03 03:02:38 | 000,235,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013/12/03 03:02:38 | 000,218,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2013/12/03 03:02:38 | 000,081,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2013/12/03 03:02:38 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2013/12/03 03:02:38 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2013/12/03 03:02:38 | 000,030,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2013/12/03 03:02:38 | 000,016,284 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2013/12/03 03:02:37 | 000,774,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013/12/03 03:02:37 | 000,626,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013/12/03 03:02:37 | 000,548,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2013/12/03 03:02:37 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2013/12/03 03:02:37 | 000,147,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2013/12/03 03:02:37 | 000,143,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2013/12/03 03:02:37 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2013/12/03 03:02:37 | 000,135,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2013/12/03 03:02:37 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2013/12/03 03:02:37 | 000,101,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2013/12/03 03:02:37 | 000,084,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013/12/03 03:02:37 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2013/12/03 03:02:37 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2013/12/03 03:02:37 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2013/12/03 03:02:37 | 000,048,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2013/12/03 03:02:37 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2013/12/03 03:02:37 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2013/11/28 05:54:12 | 000,059,392 | R--- | M] () -- C:\Windows\SysWow64\streamhlp.dll
[2013/11/26 22:09:06 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/11/26 22:09:06 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/11/21 19:30:54 | 000,046,368 | ---- | M] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/11/21 12:46:52 | 000,038,085 | ---- | M] () -- C:\BrowserPasswordList.html
[2013/11/14 13:02:16 | 005,432,287 | ---- | M] () -- C:\Users\Alex\Documents\wf3540ug (1).pdf
[2013/11/14 12:56:13 | 000,059,527 | ---- | M] () -- C:\Users\Alex\Documents\Staley NFA Trust.pdf
[2013/11/14 12:55:16 | 000,058,500 | ---- | M] () -- C:\Users\Alex\Documents\Epson_11142013105121.pdf
[2013/11/14 12:40:53 | 000,000,000 | -H-- | M] () -- C:\Users\Alex\Documents\Default.rdp

========== Files Created - No Company Name ==========

[2013/12/09 18:10:20 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2013/12/09 18:10:20 | 000,002,023 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2013/12/09 08:21:34 | 000,397,087 | ---- | C] () -- C:\Users\Alex\Desktop\Cellphone data spying It's not just the NSA.htm
[2013/12/07 09:33:32 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2013/12/03 21:43:03 | 000,038,085 | ---- | C] () -- C:\Users\Alex\Desktop\BrowserPasswordList.html
[2013/12/03 11:32:53 | 000,736,308 | ---- | C] () -- C:\Users\Alex\AppData\Local\census.cache
[2013/12/03 11:31:53 | 000,117,762 | ---- | C] () -- C:\Users\Alex\AppData\Local\ars.cache
[2013/12/03 10:46:29 | 000,000,036 | ---- | C] () -- C:\Users\Alex\AppData\Local\housecall.guid.cache
[2013/12/03 03:02:41 | 000,016,284 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2013/12/03 03:02:38 | 000,016,284 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2013/11/28 05:53:59 | 000,059,392 | R--- | C] () -- C:\Windows\SysWow64\streamhlp.dll
[2013/11/21 12:46:52 | 000,038,085 | ---- | C] () -- C:\BrowserPasswordList.html
[2013/11/14 13:02:16 | 005,432,287 | ---- | C] () -- C:\Users\Alex\Documents\wf3540ug (1).pdf
[2013/11/14 12:56:13 | 000,059,527 | ---- | C] () -- C:\Users\Alex\Documents\Staley NFA Trust.pdf
[2013/11/14 12:55:16 | 000,058,500 | ---- | C] () -- C:\Users\Alex\Documents\Epson_11142013105121.pdf
[2013/11/14 12:40:53 | 000,000,000 | -H-- | C] () -- C:\Users\Alex\Documents\Default.rdp
[2013/09/22 08:44:48 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib
[2013/09/21 16:40:59 | 000,000,335 | ---- | C] () -- C:\Users\Alex\AppData\Roaming\burnaware.ini
[2013/09/21 07:26:28 | 000,000,258 | RHS- | C] () -- C:\Users\Alex\ntuser.pol
[2013/07/26 07:24:22 | 006,275,760 | ---- | C] () -- C:\Windows\SysWow64\avcodec-lav-55.dll
[2013/07/26 07:24:22 | 001,239,216 | ---- | C] () -- C:\Windows\SysWow64\avformat-lav-55.dll
[2013/07/26 07:24:22 | 000,394,416 | ---- | C] () -- C:\Windows\SysWow64\swscale-lav-2.dll
[2013/07/26 07:24:22 | 000,288,944 | ---- | C] () -- C:\Windows\SysWow64\avutil-lav-52.dll
[2013/07/26 07:24:22 | 000,235,184 | ---- | C] () -- C:\Windows\SysWow64\avfilter-lav-3.dll
[2013/07/26 07:24:22 | 000,190,640 | ---- | C] () -- C:\Windows\SysWow64\libbluray.dll
[2013/07/26 07:24:22 | 000,150,192 | ---- | C] () -- C:\Windows\SysWow64\avresample-lav-1.dll
[2013/06/08 05:54:10 | 003,915,776 | ---- | C] () -- C:\Windows\SysWow64\ffmpeg.dll
[2013/06/08 05:53:06 | 000,112,640 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2013/06/08 05:52:30 | 000,271,360 | ---- | C] () -- C:\Windows\SysWow64\TomsMoComp_ff.dll
[2013/06/08 05:52:12 | 000,157,184 | ---- | C] () -- C:\Windows\SysWow64\ff_unrar.dll
[2013/06/08 05:52:10 | 000,147,456 | ---- | C] () -- C:\Windows\SysWow64\ff_libmad.dll
[2013/06/08 05:52:10 | 000,099,840 | ---- | C] () -- C:\Windows\SysWow64\ff_wmv9.dll
[2013/06/08 05:52:08 | 001,525,760 | ---- | C] () -- C:\Windows\SysWow64\ff_samplerate.dll
[2013/06/08 05:52:08 | 000,211,968 | ---- | C] () -- C:\Windows\SysWow64\ff_libdts.dll
[2013/06/08 05:52:08 | 000,114,688 | ---- | C] () -- C:\Windows\SysWow64\ff_liba52.dll
[2013/06/08 05:52:06 | 000,136,704 | ---- | C] () -- C:\Windows\SysWow64\libmpeg2_ff.dll
[2013/04/04 07:19:29 | 000,778,008 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/10/12 10:40:52 | 001,622,706 | ---- | C] () -- C:\Users\Alex\Localizable.strings
[2012/09/29 16:47:28 | 000,000,178 | ---- | C] () -- C:\Windows\SysWow64\Formats.ini
[2012/05/02 00:06:26 | 000,963,912 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2012/05/02 00:06:24 | 000,261,208 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2012/05/02 00:06:19 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2012/05/02 00:06:19 | 000,058,880 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2012/05/02 00:06:18 | 013,209,600 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll
[2011/05/13 08:27:44 | 000,001,288 | ---- | C] () -- C:\Users\Alex\reset.cmd

========== ZeroAccess Check ==========

[2009/07/13 22:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/07/25 20:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/25 19:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 19:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 21:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 19:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Custom Scans ==========

========== Base Services ==========
SRV:64bit: - [2009/07/13 19:40:01 | 000,072,192 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\aelupsvc.dll -- (AeLookupSvc)
SRV:64bit: - [2013/02/26 23:47:10 | 000,070,144 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appinfo.dll -- (Appinfo)
SRV:64bit: - [2009/07/13 19:38:55 | 000,079,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\alg.exe -- (ALG)
SRV:64bit: - [2010/11/20 21:23:51 | 000,849,920 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\qmgr.dll -- (BITS)
SRV:64bit: - [2010/11/20 21:24:00 | 000,705,024 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\BFE.DLL -- (BFE)
SRV:64bit: - [2013/09/24 19:03:24 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\lsass.exe -- (KeyIso)
SRV:64bit: - [2009/07/13 19:40:50 | 000,402,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\es.dll -- (EventSystem)
SRV - [2009/07/13 19:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\es.dll -- (EventSystem)
SRV:64bit: - [2012/07/04 16:13:27 | 000,136,704 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\browser.dll -- (Browser)
SRV:64bit: - [2013/07/08 23:46:20 | 000,184,320 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cryptsvc.dll -- (CryptSvc)
SRV - [2013/07/08 22:46:31 | 000,140,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\cryptsvc.dll -- (CryptSvc)
SRV:64bit: - [2010/11/20 21:24:01 | 000,512,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (DcomLaunch)
SRV:64bit: - [2010/11/20 21:24:00 | 000,317,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp)
SRV - [2010/11/20 21:24:09 | 000,254,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp)
SRV:64bit: - [2011/07/13 23:28:35 | 000,183,296 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dnsrslvr.dll -- (Dnscache)
SRV:64bit: - [2009/07/13 19:40:35 | 000,111,104 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\eapsvc.dll -- (EapHost)
SRV:64bit: - [2009/07/13 19:41:00 | 000,038,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\hidserv.dll -- (hidserv)
SRV - [2009/07/13 19:15:24 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\hidserv.dll -- (hidserv)
SRV:64bit: - [2009/07/13 19:41:10 | 000,359,424 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\ipnathlp.dll -- (SharedAccess)
SRV:64bit: - [2010/11/20 21:23:48 | 000,501,248 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\IPSECSVC.DLL -- (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV:64bit: - [2009/07/13 19:41:54 | 000,524,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\swprv.dll -- (swprv)
SRV:64bit: - [2009/07/13 19:41:26 | 000,067,584 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\mmcss.dll -- (MMCSS)
SRV:64bit: - [2009/07/13 19:41:52 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netman.dll -- (Netman)
SRV:64bit: - [2009/07/13 19:41:52 | 000,459,776 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofm.dll -- (netprofm)
SRV - [2009/07/13 19:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\netprofm.dll -- (netprofm)
SRV:64bit: - [2012/10/03 11:44:21 | 000,303,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nlasvc.dll -- (NlaSvc)
SRV:64bit: - [2009/07/13 19:41:53 | 000,025,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nsisvc.dll -- (nsi)
SRV:64bit: - [2011/09/21 03:37:16 | 000,404,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\umpnpmgr.dll -- (PlugPlay)
SRV:64bit: - [2012/02/11 00:36:02 | 000,559,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\spoolsv.exe -- (Spooler)
SRV:64bit: - [2013/09/24 19:03:24 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\lsass.exe -- (ProtectedStorage)
No service found with a name of EMDMgmt
SRV:64bit: - [2009/07/13 19:41:53 | 000,099,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasauto.dll -- (RasAuto)
SRV:64bit: - [2010/11/20 21:24:17 | 000,344,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasmans.dll -- (RasMan)
SRV:64bit: - [2010/11/20 21:24:01 | 000,512,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (RpcSs)
SRV:64bit: - [2010/11/20 21:24:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\seclogon.dll -- (seclogon)
SRV:64bit: - [2013/09/24 19:03:24 | 000,030,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsass.exe -- (SamSs)
SRV:64bit: - [2009/07/13 19:41:58 | 000,097,280 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wscsvc.dll -- (wscsvc)
SRV:64bit: - [2010/11/20 21:23:48 | 000,236,032 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\srvsvc.dll -- (LanmanServer)
SRV:64bit: - [2010/11/20 21:23:55 | 000,370,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\shsvcs.dll -- (ShellHWDetection)
SRV - [2010/11/20 21:24:03 | 000,328,192 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\shsvcs.dll -- (ShellHWDetection)
No service found with a name of slsvc
SRV:64bit: - [2010/11/20 21:24:16 | 001,110,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\schedsvc.dll -- (Schedule)
SRV:64bit: - [2010/11/20 21:24:32 | 000,316,928 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tapisrv.dll -- (TapiSrv)
SRV - [2010/11/20 21:24:00 | 000,242,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\tapisrv.dll -- (TapiSrv)
SRV:64bit: - [2009/07/13 19:41:55 | 000,044,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\themeservice.dll -- (Themes)
SRV:64bit: - [2012/04/30 23:40:20 | 000,209,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\profsvc.dll -- (ProfSvc)
SRV:64bit: - [2010/11/20 21:23:55 | 001,600,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\VSSVC.exe -- (VSS)
SRV:64bit: - [2010/11/20 21:24:32 | 000,679,424 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioSrv)
SRV:64bit: - [2010/11/20 21:24:32 | 000,679,424 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioEndpointBuilder)
SRV:64bit: - [2010/11/20 21:25:06 | 000,170,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\sdrsvc.dll -- (SDRSVC)
SRV:64bit: - [2013/05/26 23:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2010/11/20 21:23:55 | 001,646,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wevtsvc.dll -- (eventlog)
SRV:64bit: - [2010/11/20 21:24:28 | 000,828,416 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\MPSSVC.dll -- (MpsSvc)
SRV:64bit: - [2010/11/20 21:24:48 | 000,580,096 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wiaservc.dll -- (stisvc)
SRV:64bit: - [2010/11/20 21:24:15 | 000,128,000 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\msiexec.exe -- (msiserver)
SRV - [2010/11/20 21:24:28 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWow64\msiexec.exe -- (msiserver)
SRV:64bit: - [2009/07/13 19:41:56 | 000,242,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wbem\WMIsvc.dll -- (Winmgmt)
SRV:64bit: - [2012/06/02 16:19:43 | 002,428,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wuaueng.dll -- (wuauserv)
SRV:64bit: - [2010/11/20 21:24:09 | 000,252,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dot3svc.dll -- (dot3svc)
SRV:64bit: - [2009/07/13 19:41:56 | 000,886,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wlansvc.dll -- (Wlansvc)
SRV:64bit: - [2010/11/20 21:24:32 | 000,118,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wkssvc.dll -- (LanmanWorkstation)

< %SYSTEMDRIVE%\*.exe >
[2007/04/07 23:00:28 | 004,573,206 | ---- | M] ( ) -- C:\AutoUnpack444.exe
[2007/04/07 22:47:32 | 009,757,184 | ---- | M] () -- C:\StepMania-3.9.exe

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is Acer
Volume Serial Number is 1E48-D6BE
Directory of C:\
07/13/2009 11:08 PM <JUNCTION> Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/13/2009 11:08 PM <JUNCTION> Application Data [C:\ProgramData]
07/13/2009 11:08 PM <JUNCTION> Desktop [C:\Users\Public\Desktop]
07/13/2009 11:08 PM <JUNCTION> Documents [C:\Users\Public\Documents]
07/13/2009 11:08 PM <JUNCTION> Favorites [C:\Users\Public\Favorites]
07/13/2009 11:08 PM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009 11:08 PM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/13/2009 11:08 PM <SYMLINKD> All Users [C:\ProgramData]
07/13/2009 11:08 PM <JUNCTION> Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\Alex
09/10/2013 07:02 AM <JUNCTION> Application Data [C:\Users\Alex\AppData\Roaming]
09/10/2013 07:02 AM <JUNCTION> Cookies [C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Cookies]
09/10/2013 07:02 AM <JUNCTION> Local Settings [C:\Users\Alex\AppData\Local]
09/10/2013 07:02 AM <JUNCTION> My Documents [C:\Users\Alex\Documents]
09/10/2013 07:02 AM <JUNCTION> NetHood [C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
09/10/2013 07:02 AM <JUNCTION> PrintHood [C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
09/10/2013 07:02 AM <JUNCTION> Recent [C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Recent]
09/10/2013 07:02 AM <JUNCTION> SendTo [C:\Users\Alex\AppData\Roaming\Microsoft\Windows\SendTo]
09/10/2013 07:02 AM <JUNCTION> Start Menu [C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu]
09/10/2013 07:02 AM <JUNCTION> Templates [C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Alex\AppData\Local
09/10/2013 07:02 AM <JUNCTION> Application Data [C:\Users\Alex\AppData\Local]
09/10/2013 07:02 AM <JUNCTION> History [C:\Users\Alex\AppData\Local\Microsoft\Windows\History]
09/10/2013 07:02 AM <JUNCTION> Temporary Internet Files [C:\Users\Alex\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Alex\Documents
09/10/2013 07:02 AM <JUNCTION> My Music [C:\Users\Alex\Music]
09/10/2013 07:02 AM <JUNCTION> My Pictures [C:\Users\Alex\Pictures]
09/10/2013 07:02 AM <JUNCTION> My Videos [C:\Users\Alex\Videos]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/13/2009 11:08 PM <JUNCTION> Application Data [C:\ProgramData]
07/13/2009 11:08 PM <JUNCTION> Desktop [C:\Users\Public\Desktop]
07/13/2009 11:08 PM <JUNCTION> Documents [C:\Users\Public\Documents]
07/13/2009 11:08 PM <JUNCTION> Favorites [C:\Users\Public\Favorites]
07/13/2009 11:08 PM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009 11:08 PM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/13/2009 11:08 PM <JUNCTION> Application Data [C:\Users\Default\AppData\Roaming]
07/13/2009 11:08 PM <JUNCTION> Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/13/2009 11:08 PM <JUNCTION> Local Settings [C:\Users\Default\AppData\Local]
07/13/2009 11:08 PM <JUNCTION> My Documents [C:\Users\Default\Documents]
07/13/2009 11:08 PM <JUNCTION> NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/13/2009 11:08 PM <JUNCTION> PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/13/2009 11:08 PM <JUNCTION> Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/13/2009 11:08 PM <JUNCTION> SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/13/2009 11:08 PM <JUNCTION> Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/13/2009 11:08 PM <JUNCTION> Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/13/2009 11:08 PM <JUNCTION> Application Data [C:\Users\Default\AppData\Local]
07/13/2009 11:08 PM <JUNCTION> History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009 11:08 PM <JUNCTION> Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/13/2009 11:08 PM <JUNCTION> My Music [C:\Users\Default\Music]
07/13/2009 11:08 PM <JUNCTION> My Pictures [C:\Users\Default\Pictures]
07/13/2009 11:08 PM <JUNCTION> My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/13/2009 11:08 PM <JUNCTION> My Music [C:\Users\Public\Music]
07/13/2009 11:08 PM <JUNCTION> My Pictures [C:\Users\Public\Pictures]
07/13/2009 11:08 PM <JUNCTION> My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
50 Dir(s) 418,639,245,312 bytes free

< MD5 for: EXPLORER.EXE >
[2011/07/13 23:30:29 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/07/13 23:30:29 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011/07/13 23:30:29 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/07/13 23:30:29 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 21:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/07/13 23:30:29 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011/07/13 23:30:29 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 21:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: SERVICES >
[2009/06/10 15:00:26 | 000,017,463 | ---- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES._ >
[2004/08/04 04:00:00 | 000,001,989 | ---- | M] () MD5=29BB3BBBE3D49156A42BFB3DD000F554 -- C:\I386\SERVICES._

< MD5 for: SERVICES.CFG >
[2012/09/23 20:43:36 | 000,603,848 | R--- | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2013/09/05 08:04:00 | 000,559,090 | ---- | M] () MD5=8ADD48E413D05BF2E7AEC00173DDFABC -- C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Services\Services.cfg

< MD5 for: SERVICES.DAT >
[2013/11/05 16:18:20 | 000,003,117 | ---- | M] () MD5=5F3B95A58780ADA3F223F004CDEE9967 -- C:\Users\Alex\AppData\Local\Temp\jrt\services.dat

< MD5 for: SERVICES.EX_ >
[2004/08/04 04:00:00 | 000,049,955 | ---- | M] () MD5=85A738BA493104ED103B26CADEB8B543 -- C:\I386\SERVICES.EX_

< MD5 for: SERVICES.EXE >
[2009/07/13 19:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
[2009/07/13 19:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2013/12/03 11:07:54 | 000,000,000 | ---- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E -- C:\_OTL\MovedFiles\12072013_083324\C_Windows\SysWOW64\services.exe
[2001/08/17 13:00:00 | 000,101,376 | ---- | M] (Microsoft Corporation) MD5=E3DF4A0252D287C44606EE55355E1623 -- C:\I386\SYSTEM32\services.exe
[2001/08/17 20:00:00 | 000,101,376 | ---- | M] (Microsoft Corporation) MD5=E3DF4A0252D287C44606EE55355E1623 -- C:\MiniNT\system32\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2010/11/21 01:06:16 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 -- C:\Windows\SysNative\en-US\services.exe.mui
[2010/11/21 01:06:16 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 -- C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.JS >
[2013/12/03 15:19:44 | 000,003,147 | ---- | M] () MD5=2FD91762B4C2F6ED25428D709A8B3A84 -- C:\Program Files (x86)\PasswordBox\Firefox\resources\passwordbox\lib\services.js
[2012/01/26 12:14:48 | 000,018,691 | ---- | M] () MD5=9358495E94D1710E6BC4EC57E602F2EE -- C:\Program Files (x86)\Barnes & Noble\BNDesktopReader\HTML\js\services.js

< MD5 for: SERVICES.LNK >
[2009/07/13 22:54:05 | 000,001,288 | ---- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 22:54:05 | 000,001,288 | ---- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 -- C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 14:44:06 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\SysNative\wbem\services.mof
[2009/06/10 14:44:06 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MS_ >
[2004/08/04 04:00:00 | 000,003,649 | ---- | M] () MD5=64E9F61D2ED093C361862DE36433B5E1 -- C:\I386\SERVICES.MS_

< MD5 for: SERVICES.MSC >
[2010/11/21 01:06:14 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysNative\en-US\services.msc
[2009/06/10 14:38:36 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysNative\services.msc
[2010/11/21 01:06:17 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 15:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysWOW64\services.msc
[2010/11/21 01:06:14 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 14:38:36 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2010/11/21 01:06:17 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 15:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 14:16:17 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 14:16:17 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: SERVICES.TICO >
[2009/09/25 13:00:00 | 000,002,038 | ---- | M] () MD5=D669B1B2EBE288A61680C3C863828D28 -- C:\Program Files (x86)\AVG\AVG PC TuneUp\data\services.tico

< MD5 for: SVCHOST.EXE >
[2001/08/17 13:00:00 | 000,012,800 | ---- | M] (Microsoft Corporation) MD5=0F7D9C87B0CE1FA520473119752C6F79 -- C:\I386\SYSTEM32\svchost.exe
[2001/08/17 20:00:00 | 000,012,800 | ---- | M] (Microsoft Corporation) MD5=0F7D9C87B0CE1FA520473119752C6F79 -- C:\MiniNT\system32\svchost.exe
[2009/07/13 19:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2011/03/01 02:10:51 | 000,027,648 | ---- | M] (Microsoft Corporation) MD5=635455A95EB8EC47AC72142E501465ED -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7601.21671_none_14271b75353e4391\svchost.exe
[2011/03/01 02:07:49 | 000,027,648 | ---- | M] (Microsoft Corporation) MD5=6F68F63794097E54F36474ED4384B759 -- C:\Windows\SysNative\svchost.exe
[2011/03/01 02:07:49 | 000,027,648 | ---- | M] (Microsoft Corporation) MD5=6F68F63794097E54F36474ED4384B759 -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7601.17568_none_13af509c1c123937\svchost.exe
[2011/03/01 02:07:49 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=A91A288C91F9D9F1CFA4FAA9893C4D55 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7601.21671_none_b8087ff17ce0d25b\svchost.exe
[2009/07/13 19:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
[2011/03/01 02:05:31 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=ECDB182F885292145826C58252B53000 -- C:\Windows\SysWOW64\svchost.exe
[2011/03/01 02:05:31 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=ECDB182F885292145826C58252B53000 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7601.17568_none_b790b51863b4c801\svchost.exe

< MD5 for: USERINIT.EXE >
[2001/08/17 13:00:00 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=585398603F570F9705774D65D292E5D1 -- C:\I386\SYSTEM32\userinit.exe
[2001/08/17 20:00:00 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=585398603F570F9705774D65D292E5D1 -- C:\MiniNT\system32\userinit.exe
[2010/11/20 21:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010/11/20 21:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010/11/20 21:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010/11/20 21:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< End of report >
  • 0

#11
Pyxis

Pyxis

    Trusted Helper

  • Malware Removal
  • 1,228 posts
Looks like we are almost done here. :) How is your computer running?

  • Step 1

    Upon careful inspection, your log indicates that the program(s) listed below is installed on your computer. I would like to request for the removal of the program(s) as it is associated with malware, adware or spyware. Please proceed to uninstalling by going to Control Panel (Windows XP) or Programs and Features (Windows Vista or Windows 7). If Windows says it cannot locate the program(s) and that it prompts for it to be removed from the list instead, do so by allowing it.

    SearchMe Toolbar v8.3
    Software Updater
Inform me if you encounter problems in the removal process.
  • 0

#12
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP