Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Choppy, Delayed Responses, Please Help Or My Nerdy laptop Will Surely

Malware Spyware virus choppy delayed overheat sick

  • This topic is locked This topic is locked

#1
CaramelBliss*

CaramelBliss*

    Member

  • Member
  • PipPip
  • 63 posts

  Hello, Fellow Geeks

 

 

   I own a 2007 Toshiba laptop and every time I have issues, I run straight to you guys. Okay, I believe it is a virus, but I am never too sure anymore with all the hacking and things out there ...

  

  whenever I use internet Explorer or even chrome, my typing is delayed, the responses to websites are delayed. And sometimes unresponsive all together. It its not just on the web. Now I'm seeing the same thing when I open files I have saved on my computer. I am a fast typist and sometimes, though I KNOW I'm typing to right thing, I still have to proof read and notice letters missing from words or even different words typed in all together. I have scanned my laptop many times with Microsoft Security Essentials and this and all I get every time :

         PC STATUS: PROTECTED

        YOUR PC IS BEING PROTECTED AND MONITORED

         And Green checks all over the place.

 

But no warning about sickness like it usually would. So, I ran the OLT scan and here are the results:

 

     OTL logfile created on: 3/25/2014 1:43:07 PM - Run 1

OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Stephie\Downloads
 Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16521)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
2.87 Gb Total Physical Memory | 1.54 Gb Available Physical Memory | 53.53% Memory free
5.74 Gb Paging File | 4.20 Gb Available in Paging File | 73.23% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 224.17 Gb Total Space | 74.91 Gb Free Space | 33.42% Space Free | Partition Type: NTFS
 
Computer Name: STEPHIESLIFE | User Name: Stephie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/03/25 13:41:58 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Stephie\Downloads\OTL (1).exe
PRC - [2014/03/14 20:50:42 | 000,859,976 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2014/01/24 16:45:21 | 001,025,312 | ---- | M] (Conduit Ltd.) -- C:\Users\Stephie\AppData\Local\NativeMessaging\CT3220468\1_0_0_10\TBMessagingHost.exe
PRC - [2013/10/23 16:01:10 | 000,300,552 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MpCmdRun.exe
PRC - [2013/10/23 16:01:10 | 000,280,288 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\NisSrv.exe
PRC - [2013/10/23 16:01:10 | 000,022,208 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2013/10/23 15:55:28 | 000,948,440 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2013/08/01 20:52:57 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2013/06/25 21:48:08 | 000,228,552 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
PRC - [2013/05/14 14:26:12 | 003,289,208 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012/11/22 22:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2012/10/18 12:10:42 | 000,103,864 | ---- | M] () -- C:\Users\Stephie\AppData\Roaming\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe
PRC - [2011/11/30 05:26:26 | 000,393,640 | ---- | M] () -- C:\VTech\DownloadManager\System\AgentMonitor.exe
PRC - [2011/11/12 13:04:12 | 000,268,640 | ---- | M] (LeapFrog Enterprises, Inc.) -- C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
PRC - [2011/11/12 12:21:58 | 006,141,792 | ---- | M] (LeapFrog Enterprises, Inc.) -- C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
PRC - [2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010/11/20 08:17:00 | 000,302,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cmd.exe
PRC - [2009/08/14 20:19:44 | 000,326,192 | ---- | M] (VMware, Inc.) -- C:\Windows\System32\vmnetdhcp.exe
PRC - [2009/08/14 20:19:30 | 000,399,920 | ---- | M] (VMware, Inc.) -- C:\Windows\System32\vmnat.exe
PRC - [2009/08/14 20:19:24 | 000,113,200 | ---- | M] (VMware, Inc.) -- C:\Program Files\VMware\VMware Player\vmware-authd.exe
PRC - [2009/08/14 20:19:10 | 000,064,048 | ---- | M] (VMware, Inc.) -- C:\Program Files\VMware\VMware Player\hqtray.exe
PRC - [2009/04/01 18:11:06 | 001,283,384 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe
PRC - [2009/04/01 18:10:58 | 000,062,776 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe
PRC - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/07/19 00:39:30 | 000,083,312 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
PRC - [2008/06/02 17:26:48 | 000,505,720 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\SmoothView\SmoothView.exe
PRC - [2008/05/09 15:49:30 | 000,716,800 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
PRC - [2008/05/08 14:11:58 | 004,787,712 | ---- | M] () -- C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
PRC - [2008/04/29 14:33:28 | 000,417,792 | ---- | M] (Chicony) -- C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
PRC - [2008/04/24 22:35:46 | 000,073,728 | ---- | M] (Toshiba) -- C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe
PRC - [2008/04/24 13:26:18 | 000,202,560 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
PRC - [2008/04/24 13:25:22 | 000,202,560 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
PRC - [2008/04/17 03:19:48 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
PRC - [2008/04/15 21:54:42 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/04/15 21:54:40 | 000,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/04/08 19:14:50 | 006,037,504 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2008/02/06 17:52:52 | 000,431,456 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
PRC - [2008/02/06 17:52:40 | 000,431,456 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
PRC - [2007/12/03 21:03:52 | 000,126,976 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\SMARTLogService\TosIPCSrv.exe
PRC - [2007/11/21 21:23:32 | 000,129,632 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\TODDSrv.exe
PRC - [2006/08/23 19:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/03/14 20:50:40 | 000,394,568 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\33.0.1750.154\ppgooglenaclpluginchrome.dll
MOD - [2014/03/14 20:50:38 | 004,061,000 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\33.0.1750.154\pdf.dll
MOD - [2014/03/14 20:50:35 | 000,716,616 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\33.0.1750.154\libglesv2.dll
MOD - [2014/03/14 20:50:34 | 000,100,168 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\33.0.1750.154\libegl.dll
MOD - [2014/03/14 20:50:32 | 001,647,432 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\33.0.1750.154\ffmpegsumo.dll
MOD - [2014/03/14 20:50:30 | 000,051,016 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\33.0.1750.154\chrome_elf.dll
MOD - [2014/02/14 19:56:29 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\8bc548587e91ecf0552a40e47bbf99cc\System.Windows.Forms.ni.dll
MOD - [2014/02/14 19:56:20 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5c24d3b0041ebf4f48a93615b9fa3de9\System.Drawing.ni.dll
MOD - [2014/02/14 19:55:50 | 005,464,064 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\2c9156c92877b8f46960da931124f422\System.Xml.ni.dll
MOD - [2014/02/14 19:55:43 | 000,978,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\5b6ddf934128d538cd5cd77bf4209b93\System.Configuration.ni.dll
MOD - [2014/02/14 19:55:41 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\b3a78269847005365001c33870cd121f\System.ni.dll
MOD - [2014/02/14 19:55:29 | 011,499,520 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ede2c6c842840e009f01bcc74fa4c457\mscorlib.ni.dll
MOD - [2012/10/18 12:10:42 | 000,103,864 | ---- | M] () -- C:\Users\Stephie\AppData\Roaming\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe
MOD - [2012/10/18 12:10:18 | 000,049,080 | ---- | M] () -- C:\Users\Stephie\AppData\Roaming\ShopAtHome\ShopAtHomeHelper\ShopAtHomeHelperPS.dll
MOD - [2011/11/30 05:26:26 | 000,393,640 | ---- | M] () -- C:\VTech\DownloadManager\System\AgentMonitor.exe
MOD - [2011/10/26 18:57:39 | 008,007,680 | ---- | M] () -- C:\Windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll
MOD - [2011/09/14 10:19:06 | 008,500,224 | ---- | M] () -- C:\Program Files\LeapFrog\LeapFrog Connect\QtGui4.dll
MOD - [2011/09/14 10:19:06 | 002,348,544 | ---- | M] () -- C:\Program Files\LeapFrog\LeapFrog Connect\QtCore4.dll
MOD - [2010/11/11 05:24:31 | 000,028,160 | ---- | M] () -- C:\VTech\DownloadManager\System\DACommCenter.dll
MOD - [2010/07/13 09:07:23 | 007,826,432 | ---- | M] () -- C:\VTech\DownloadManager\System\QtGui4.dll
MOD - [2010/07/05 05:19:39 | 000,116,736 | ---- | M] () -- C:\VTech\DownloadManager\System\QtSolutions_SOAP-2.7.dll
MOD - [2010/06/23 21:16:19 | 002,150,400 | ---- | M] () -- C:\VTech\DownloadManager\System\QtCore4.dll
MOD - [2010/06/02 01:05:40 | 000,119,808 | ---- | M] () -- C:\VTech\DownloadManager\System\imageformats\qjpeg4.dll
MOD - [2010/06/02 00:38:06 | 009,837,568 | ---- | M] () -- C:\VTech\DownloadManager\System\QtWebKit4.dll
MOD - [2010/06/01 22:56:04 | 000,232,960 | ---- | M] () -- C:\VTech\DownloadManager\System\phonon4.dll
MOD - [2010/06/01 22:54:24 | 002,530,816 | ---- | M] () -- C:\VTech\DownloadManager\System\QtXmlPatterns4.dll
MOD - [2010/06/01 22:29:22 | 000,934,912 | ---- | M] () -- C:\VTech\DownloadManager\System\QtNetwork4.dll
MOD - [2010/06/01 22:28:00 | 000,335,360 | ---- | M] () -- C:\VTech\DownloadManager\System\QtXml4.dll
MOD - [2010/06/01 10:17:46 | 000,929,792 | ---- | M] () -- C:\Program Files\Yahoo!\Messenger\yui.dll
MOD - [2009/08/30 22:14:16 | 003,571,200 | ---- | M] () -- C:\Program Files\Combined Community Codec Pack\Filters\FFDShow\ffdshow.ax
MOD - [2009/08/14 20:20:28 | 000,068,656 | ---- | M] () -- C:\Program Files\VMware\VMware Player\zlib1.dll
MOD - [2009/08/14 20:19:38 | 000,970,288 | ---- | M] () -- C:\Program Files\VMware\VMware Player\libxml2.dll
MOD - [2008/05/08 14:11:58 | 004,787,712 | ---- | M] () -- C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
MOD - [2008/03/06 14:14:54 | 005,121,912 | ---- | M] () -- C:\Program Files\Toshiba\FlashCards\BlackPng.dll
MOD - [2007/12/25 16:03:40 | 000,015,184 | ---- | M] () -- C:\Program Files\Toshiba\PCDiag\NotifyPCD.dll
MOD - [2006/12/01 21:55:42 | 000,009,216 | ---- | M] () -- C:\Program Files\Toshiba\TBS\NotifyTBS.dll
MOD - [2006/10/10 14:44:16 | 000,009,728 | ---- | M] () -- C:\Program Files\Toshiba\TOSHIBA Assist\NotifyX.dll
MOD - [2006/10/07 14:57:04 | 000,053,248 | ---- | M] () -- C:\Program Files\Toshiba\TOSHIBA Disc Creator\NotifyTDC.dll
 
 
========== Services (SafeList) ==========
 
SRV - File not found [Auto | Stopped] -- C:\Combo\PEV.cfxxe EXEC /i C:\Combo\HIDEC.exe C:\Combo\SWREG.EXE ACL HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep /RESET /Q -- (PEVSystemStart)
SRV - File not found [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_HelperSvc.exe -- (getPlus®
SRV - [2014/03/14 14:29:13 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/02/28 23:38:23 | 000,108,032 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV - [2014/01/29 22:05:28 | 000,227,904 | ---- | M] (WildTangent) [On_Demand | Stopped] -- C:\Program Files\WildTangent Games\App\GamesAppIntegrationService.exe -- (GamesAppIntegrationService)
SRV - [2013/10/23 16:01:10 | 000,280,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2013/10/23 16:01:10 | 000,022,208 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2013/10/23 09:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/05/27 00:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2013/05/14 14:26:12 | 003,289,208 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2011/11/12 12:21:58 | 006,141,792 | ---- | M] (LeapFrog Enterprises, Inc.) [Auto | Running] -- C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe -- (LeapFrog Connect Device Service)
SRV - [2010/10/12 13:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010/06/02 14:34:58 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2009/08/14 20:19:44 | 000,326,192 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\System32\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2009/08/14 20:19:30 | 000,399,920 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\System32\vmnat.exe -- (VMware NAT Service)
SRV - [2009/08/14 20:19:24 | 000,113,200 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files\VMware\VMware Player\vmware-authd.exe -- (VMAuthdService)
SRV - [2009/07/13 21:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/06/05 20:07:28 | 000,250,616 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2009/04/01 18:10:58 | 000,062,776 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV - [2008/12/01 11:49:02 | 000,191,024 | ---- | M] (VMware, Inc.) [On_Demand | Stopped] -- C:\Program Files\VMware\VMware Player\vmware-ufad.exe -- (ufad-ws60)
SRV - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/07/19 00:39:30 | 000,083,312 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe -- (TNaviSrv)
SRV - [2008/04/24 22:35:46 | 000,073,728 | ---- | M] (Toshiba) [On_Demand | Running] -- C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe -- (SmartFaceVWatchSrv)
SRV - [2008/04/24 13:26:18 | 000,202,560 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe -- (sprtsvc_ddoctorv2)
SRV - [2008/04/17 03:19:48 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
SRV - [2008/04/16 19:53:00 | 000,954,368 | ---- | M] (Atheros Communications, Inc.) [On_Demand | Stopped] -- C:\Program Files\Jumpstart\jswpsapi.exe -- (jswpsapi)
SRV - [2008/04/15 21:54:42 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
SRV - [2008/02/06 17:52:40 | 000,431,456 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2007/12/03 21:03:52 | 000,126,976 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\Toshiba\SMARTLogService\TosIPCSrv.exe -- (TOSHIBA SMART Log Service)
SRV - [2007/11/21 21:23:32 | 000,129,632 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv)
SRV - [2006/08/23 19:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\PCTINDIS5.SYS -- (PCTINDIS5)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\PCASp50.sys -- (PCASp50)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\pctnullport.sys -- (Nmea)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\easytthr.sys -- (easytether)
DRV - [2013/09/27 10:53:06 | 000,104,768 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2011/11/12 12:18:20 | 000,019,456 | ---- | M] (LeapFrog) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\FlyUsb.sys -- (FlyUsb)
DRV - [2011/05/13 03:21:06 | 000,136,808 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadmdm.sys -- (ssadmdm)
DRV - [2011/05/13 03:21:06 | 000,121,064 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadbus.sys -- (ssadbus)
DRV - [2011/05/13 03:21:06 | 000,114,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadserd.sys -- (ssadserd)
DRV - [2011/05/13 03:21:06 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadmdfl.sys -- (ssadmdfl)
DRV - [2010/12/15 07:02:12 | 000,034,936 | ---- | M] (F5 Networks, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\covpnwlh.sys -- (urvpndrv)
DRV - [2010/12/15 07:02:05 | 000,013,944 | ---- | M] (F5 Networks) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\urfltwlh.sys -- (f5ipfw)
DRV - [2010/11/20 06:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 05:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/05/16 21:09:42 | 000,226,816 | ---- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SWNC5E00.sys -- (SWNC5E00)
DRV - [2010/05/16 21:09:42 | 000,157,440 | ---- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\swmx00.sys -- (swmx00)
DRV - [2010/05/16 21:09:26 | 000,229,376 | ---- | M] (Novatel Wireless Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NWADIenum.sys -- (NWADI)
DRV - [2010/03/26 21:07:28 | 000,319,488 | ---- | M] (Beceem communications pvt ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\drxvi314.sys -- (bcm)
DRV - [2010/03/26 21:04:24 | 000,051,456 | ---- | M] (Beceem communications pvt ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BcmBusCtr.sys -- (bcmbusctr)
DRV - [2009/12/20 11:53:32 | 000,234,016 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2009/09/21 18:58:28 | 001,218,048 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009/09/11 15:48:04 | 000,066,056 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WmXlCore.sys -- (WmXlCore)
DRV - [2009/09/11 15:47:54 | 000,014,984 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WmVirHid.sys -- (WmVirHid)
DRV - [2009/09/11 15:47:32 | 000,035,592 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WmFilter.sys -- (WmFilter)
DRV - [2009/09/11 15:47:22 | 000,022,792 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WmBEnum.sys -- (WmBEnum)
DRV - [2009/08/14 20:20:36 | 000,032,304 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\hcmon.sys -- (hcmon)
DRV - [2009/08/14 20:20:34 | 000,054,960 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmci.sys -- (vmci)
DRV - [2009/08/14 20:20:34 | 000,026,288 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmnetuserif.sys -- (VMnetuserif)
DRV - [2009/08/14 20:20:32 | 000,023,216 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMkbd.sys -- (vmkbd)
DRV - [2009/08/14 20:13:56 | 000,857,520 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmx86.sys -- (vmx86)
DRV - [2009/08/14 13:40:04 | 000,031,280 | R--- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmnetbridge.sys -- (VMnetBridge)
DRV - [2009/08/14 13:40:04 | 000,031,280 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmusb.sys -- (vmusb)
DRV - [2009/08/14 13:40:04 | 000,016,560 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmnetadapter.sys -- (VMnetAdapter)
DRV - [2009/07/13 19:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/13 18:13:48 | 001,035,776 | ---- | M] (LSI Corp) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2008/12/01 11:47:08 | 000,022,448 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Program Files\VMware\VMware Player\vstor2-ws60.sys -- (vstor2-ws60)
DRV - [2008/10/15 11:58:34 | 000,024,840 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\swmsflt.sys -- (swmsflt)
DRV - [2008/05/29 15:53:26 | 000,112,640 | ---- | M] (C-motech Co.,Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\cm_net.sys -- (cm_net)
DRV - [2008/05/29 15:53:26 | 000,103,680 | ---- | M] (C-motech Co.,Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\cm_ser.sys -- (cm_ser)
DRV - [2008/04/28 20:59:18 | 000,020,384 | ---- | M] (Atheros Communications, Inc.) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\jswpslwf.sys -- (jswpslwf)
DRV - [2008/01/18 12:22:00 | 000,009,216 | ---- | M] (Inventec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\sysprep\PEDRV.SYS -- (SVRPEDRV)
DRV - [2007/12/17 15:45:20 | 000,018,432 | ---- | M] (Chicony Electronics Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\UVCFTR_S.SYS -- (UVCFTR)
DRV - [2007/12/14 15:53:24 | 000,024,200 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV - [2007/11/09 18:00:52 | 000,023,640 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\TVALZ_O.SYS -- (TVALZ)
DRV - [2007/06/28 07:18:10 | 001,310,720 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CM108.sys -- (USBPNPA)
DRV - [2006/11/20 17:11:14 | 000,007,168 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\FwLnk.sys -- (FwLnk)
DRV - [2006/11/09 02:32:00 | 000,219,264 | ---- | M] (TOSHIBA CORPORATION) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\KR10I.sys -- (KR10I)
DRV - [2006/11/09 02:31:00 | 000,211,072 | ---- | M] (TOSHIBA CORPORATION) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\KR10N.sys -- (KR10N)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylo....10&affID=19591
IE - HKLM\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {837EC233-EE7F-4796-BBFE-ED94397C77F6}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{837EC233-EE7F-4796-BBFE-ED94397C77F6}: "URL" = http://www.google.co...ng}&rlz=1I7TSHB
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT3220468
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co...=TSHB&bmod=TSHB
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 3A CA DF 1A D8 E4 CB 01  [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE11SR
IE - HKCU\..\SearchScopes\{11C12D3A-00D2-41F8-B205-9565DA0F1F55}: "URL" = http://websearch.sho...q={searchTerms}
IE - HKCU\..\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}: "URL" = http://www.crawler.c...rms}&tbid=60116
IE - HKCU\..\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}: "URL" = http://search.babylo....10&affID=19591
IE - HKCU\..\SearchScopes\{3A80A42E-1331-4A90-8AAE-3CF866EA37D1}: "URL" = http://www.bing.com/...ge}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{837EC233-EE7F-4796-BBFE-ED94397C77F6}: "URL" = http://www.google.co...TSHB_en___US330
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT3220468
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incre...&loc=search_box
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo....s}&fr=chr-iobit
IE - HKCU\..\SearchScopes\Comcast: "URL" = http://search.xfinit...art_tech_search
IE - HKCU\..\SearchScopes\Yahoo!: "URL" = http://us.search.yah...&fr=iobit-trans
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/npracplug;version=1.0.0.0: C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll (RealNetworks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\[email protected]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Stephie\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\SiteRanker\firefox\
 
[2011/05/30 09:28:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stephie\AppData\Roaming\Mozilla\Extensions
[2009/06/03 09:50:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stephie\AppData\Roaming\Mozilla\Extensions\[email protected]
[2013/01/23 13:30:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stephie\AppData\Roaming\Mozilla\Firefox\extensions
[2013/01/23 13:30:57 | 000,000,000 | ---D | M] (uTorrentControl_v2) -- C:\Users\Stephie\AppData\Roaming\Mozilla\Firefox\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
[2011/05/30 09:28:22 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/07/09 14:38:37 | 000,002,423 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
 
========== Chrome  ==========
 
CHR - default_search_provider: Privitize VPN (Enabled)
CHR - default_search_provider: search_url = http://searchab.com/...q={searchTerms}
CHR - default_search_provider: suggest_url = ,
CHR - homepage: http://google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\33.0.1750.154\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U32 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: RealArcade Mozilla Plugin (Enabled) = C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live™ Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Yahoo! activeX Plug-in Bridge (Enabled) = C:\Program Files\Yahoo!\Common\npyaxmpb.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Stephie\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.320.5 (Enabled) = C:\Windows\system32\npdeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Google Drive = C:\Users\Stephie\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Stephie\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: MagniPic = C:\Users\Stephie\AppData\Local\Google\Chrome\User Data\Default\Extensions\caokccjjnkaaallapcogpiicmlokebik\1\
CHR - Extension: Google Search = C:\Users\Stephie\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: uTorrentControl_v2 = C:\Users\Stephie\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.26.9.505_0\
CHR - Extension: uTorrentControl_v2 = C:\Users\Stephie\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.26.9.505_0\nativeMessaging\nmHost
CHR - Extension: Skype Click to Call = C:\Users\Stephie\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\7.1.15383.6004_0\
CHR - Extension: Zoomex = C:\Users\Stephie\AppData\Local\Google\Chrome\User Data\Default\Extensions\maidkcbceeikkbcjnpmdlfcadfchcama\1\
CHR - Extension: Google Wallet = C:\Users\Stephie\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Users\Stephie\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2011/06/14 18:59:49 | 000,000,003 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5} - C:\PROGRA~1\SITERA~1\SiteRank.dll File not found
O2 - BHO: (ShopAtHome.com Cash Back Helper) - {66516A07-F617-488A-90CF-4E690CFB3C5F} - C:\Users\Stephie\AppData\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll (ShopAtHome.com)
O2 - BHO: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (ShopAtHome.com Toolbar) - {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - C:\Users\Stephie\AppData\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll (ShopAtHome.com)
O3 - HKLM\..\Toolbar: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (ShopAtHome.com Toolbar) - {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - C:\Users\Stephie\AppData\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll (ShopAtHome.com)
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentControl_v2 Toolbar) - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [AgentMonitor] C:\VTech\DownloadManager\System\AgentMonitor.exe ()
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [ddoctorv2] C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [HSON] C:\Program Files\Toshiba\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Monitor] C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PrivitizeVPN] C:\Program Files\PrivitizeVPN\PrivitizeVPN.exe (OOO Industry)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [ShopAtHomeWatcher] C:\Users\Stephie\AppData\Roaming\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe ()
O4 - HKLM..\Run: [SiteRanker] "C:\Program Files\SiteRanker\SiteRankTray.exe" File not found
O4 - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [UVS12 Preload] C:\Program Files\Corel\Corel VideoStudio 12\uvPL.exe (Ulead Systems, Inc.)
O4 - HKLM..\Run: [VMware hqtray] C:\Program Files\VMware\VMware Player\hqtray.exe (VMware, Inc.)
O4 - HKCU..\Run: [APISupport] C:\Users\Stephie\AppData\Local\Conduit\APISupport\APISupport.dll (Conduit Ltd.)
O4 - HKCU..\Run: [BackgroundContainer] C:\Users\Stephie\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll (Conduit Ltd.)
O4 - HKCU..\Run: [Desktop Software] "C:\Program Files\Common Files\SupportSoft\bin\bcont.exe"  /ini "C:\Program Files\ComcastUI\Desktop Software\uinstaller.ini" /fromrun /starthidden File not found
O4 - HKCU..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" File not found
O4 - HKCU..\Run: [Facebook Update] C:\Users\Stephie\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [TBHostSupport] C:\Users\Stephie\AppData\Local\TBHostSupport\TBHostSupport_0.dll (Conduit Ltd.)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; GTB6.3; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; Media Center PC 5.0; SLCC1)" -"http://www.freeonlin...sagi-bokan.html" File not found
O4 - Startup: C:\Users\Stephie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: alpineaccess.net ([mail] http in Trusted sites)
O15 - HKCU\..Trusted Domains: evolvondemand.net ([sitel] https in Trusted sites)
O16 - DPF: {2BCDB465-81F9-41CB-832C-8037A4064446} C:\Users\Stephie\AppData\Local\Temp\f5tmp\urxvpn.cab (F5 Networks VPN Manager)
O16 - DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} C:\Users\Stephie\AppData\Local\Temp\f5tmp\f5tunsrv.cab (F5 Networks Dynamic Application Tunnel Control)
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} https://a2fp3.alpine...llerControl.cab (F5 Networks Auto Update)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {C3D96A02-EEA7-4264-98D7-D882A7338DE5} http://imgfarm.com/i...tup1.0.0.12.cab (Reg Error: Key error.)
O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} C:\Users\Stephie\AppData\Local\Temp\f5tmp\urxshost.cab (F5 Networks SuperHost Class)
O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} C:\Users\Stephie\AppData\Local\Temp\f5tmp\urxhost.cab (F5 Networks Host Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0A2E6BA9-3B42-4B4C-BBFB-E7D86FD7E9DB}: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3275D0AC-DBE6-4B7F-BFCE-D4697877AC7A}: NameServer = 10.124.6.3
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5BE236FD-3749-4E42-988B-53DC570CF5F6}: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F2AAEF74-6A77-42E9-B4E2-38D70F68F0DF}: NameServer = 10.124.6.3
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O24 - Desktop WallPaper: 
O24 - Desktop BackupWallPaper: 
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{0b90b343-6737-11e1-8df2-001e339f5028}\Shell - "" = AutoRun
O33 - MountPoints2\{0b90b343-6737-11e1-8df2-001e339f5028}\Shell\AutoRun\command - "" = E:\Autorun.exe
O33 - MountPoints2\{a3e34131-0721-11e1-ba75-001e339f5028}\Shell - "" = AutoRun
O33 - MountPoints2\{a3e34131-0721-11e1-ba75-001e339f5028}\Shell\AutoRun\command - "" = E:\iStudio.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\iStudio.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/03/24 20:10:01 | 000,000,000 | ---D | C] -- C:\Users\Stephie\AppData\Local\{5885F4F9-2DE1-4B25-994B-F50E1E6D15F1}
[2014/03/15 14:33:58 | 000,000,000 | ---D | C] -- C:\Users\Stephie\AppData\Local\{D95E10E4-83E9-4EF3-9B13-F0D339E785B1}
[2014/03/14 13:46:31 | 000,000,000 | ---D | C] -- C:\Users\Stephie\AppData\Local\{DCE22005-D0CB-45CD-8E1A-21662ACB02B4}
[2014/03/04 10:55:32 | 000,000,000 | ---D | C] -- C:\Users\Stephie\AppData\Local\{D51DDC73-32E2-4131-9680-E6799678FA37}
[2014/03/03 12:34:54 | 000,000,000 | ---D | C] -- C:\Users\Stephie\AppData\Local\{79153C15-E596-4743-A064-3AF35468E511}
[2014/03/01 07:37:32 | 000,000,000 | ---D | C] -- C:\Users\Stephie\AppData\Local\{B76A591E-5929-409E-ADF7-56C4F28A7D61}
[2014/02/27 22:06:54 | 000,000,000 | ---D | C] -- C:\Users\Stephie\AppData\Local\{23B42590-D80A-442B-ADA5-E5E84D07C60F}
[2014/02/27 18:48:01 | 000,000,000 | ---D | C] -- C:\Users\Stephie\AppData\Local\{EE94E912-5C3C-4988-B285-D348E1AE4155}
[2014/02/27 15:05:21 | 000,000,000 | ---D | C] -- C:\Users\Stephie\AppData\Local\{CD87E642-C2FE-4DEF-90C5-C88C1C6CCDCD}
[2009/08/22 17:39:38 | 000,774,144 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2014/03/25 13:44:37 | 000,009,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/03/25 13:44:37 | 000,009,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/03/25 13:41:50 | 000,627,096 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014/03/25 13:41:50 | 000,107,966 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014/03/25 13:36:13 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/03/25 13:35:09 | 000,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl
[2014/03/25 13:34:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/03/25 13:34:45 | 2312,105,984 | -HS- | M] () -- C:\hiberfil.sys
[2014/03/25 13:29:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/03/25 12:55:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/03/25 12:36:00 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2844338048-2687002610-4010198750-1000UA.job
[2014/03/25 12:36:00 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2844338048-2687002610-4010198750-1000Core.job
[2014/03/24 20:07:32 | 000,466,080 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2014/03/22 18:48:41 | 000,004,862 | ---- | M] () -- C:\Users\Stephie\Desktop\work from home ideas.rtf
[2014/03/14 18:16:18 | 000,001,904 | ---- | M] () -- C:\WildTangent Games App - wildgames.lnk
[2014/03/14 18:16:17 | 000,002,266 | ---- | M] () -- C:\Users\Public\Desktop\WildTangent Games App - wildgames.lnk
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2014/03/02 09:10:17 | 000,004,862 | ---- | C] () -- C:\Users\Stephie\Desktop\work from home ideas.rtf
[2011/11/20 12:41:36 | 000,000,581 | ---- | C] () -- C:\Users\Stephie\AppData\Local\cookies.ini
[2011/05/22 21:08:28 | 000,072,080 | ---- | C] () -- C:\Users\Stephie\g2mdlhlpx.exe
[2011/04/28 09:08:40 | 000,009,728 | ---- | C] () -- C:\Users\Stephie\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/22 13:46:23 | 000,000,081 | ---- | C] () -- C:\Users\Stephie\CTX.DAT
[2010/02/16 00:22:04 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/07/01 14:08:47 | 000,000,000 | ---- | C] () -- C:\Users\Stephie\AppData\Roaming\wklnhst.dat
 
========== ZeroAccess Check ==========
 
[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/25 21:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 08:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/13 21:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
========== LOP Check ==========
 
[2010/02/15 23:55:08 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\Alchemy Mindworks
[2010/06/22 14:09:39 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\Auslogics
[2012/05/05 20:21:04 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\Azureus
[2010/07/30 08:59:27 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\Bytemobile
[2010/02/15 23:55:10 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\CasualForge
[2011/03/02 00:13:52 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\enchant
[2010/02/15 23:55:10 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\GOL_byHasbro
[2010/02/15 23:55:11 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\IObit
[2010/02/15 23:55:15 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\LimeWire
[2010/02/15 23:55:23 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\LimeWireTurbo
[2010/02/15 23:55:58 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\Mysteryville2
[2010/05/20 12:12:44 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\OpenOffice.org
[2010/02/15 23:56:01 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\Reg Tool
[2011/05/30 09:32:38 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\Sammsoft
[2013/01/23 13:13:17 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\ShopAtHome
[2010/02/15 23:56:01 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\Sierra Wireless
[2010/02/15 23:56:01 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\SiteRanker
[2011/10/26 18:39:00 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\SoftGrid Client
[2010/07/30 09:10:21 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\Sprint
[2010/02/16 19:16:50 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\SupportSoft
[2010/02/15 23:56:02 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\Template
[2014/01/30 18:32:51 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\Three Rings Design
[2010/05/13 01:15:33 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\TOSHIBA
[2010/10/03 23:33:44 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\TP
[2010/02/15 23:56:05 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\Ulead Systems
[2010/02/15 23:56:06 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\Uniblue
[2010/02/15 23:56:06 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\W Photo Studio Viewer
[2010/11/10 21:01:08 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\webex
[2013/06/03 14:56:36 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\WildTangent
[2010/02/15 23:56:06 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\WinBatch
[2011/12/16 00:09:23 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\Windows Live Writer
 
========== Purity Check ==========
 
 
 
< End of report >
 
 I can say, when I am on Internet Explorer, it is the worse. I have deleted and re-downloaded it a thousand times. Could my access to that be causing my hardware issues offline??
I could really use the help. Thanks so much for reading.

 

 

       


  • 0

Advertisements


#2
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,886 posts

Hello and welcome to Geeks to Go! My nickname is Pystryker :) , and I will be helping you with your issue today.


Before we get started, I have a few things I need to go over with you
 

  • Please do not install any new software during the cleaning process other than the tools I provide for you.  This can hinder the cleaning process.
  • Please subscribe to this topic.  By subscribing, the board will notify you when a new reply is added to your topic.  Look at the top right side of your topic title and click the Follow this Topic button.
    • If any of your security programs give you a warning about any tool I ask you to use, please do not worry.  All the links and tools I provide to you will be safe.

     
  • Please read through my instructions carefully and completely before executing them.
     
  • Please make sure that all the programs I ask you to download are downloaded to and run from your Desktop.
     
  • Please make sure you print out these instructions so that you will be able to refer to them while working on your machine.  Part of the solution(s) to your problem may involve us working in Safe Mode and you will need them to go by.  
     
  • Please do not run any tools other than the ones I ask you to, when I ask you to.  Some of these tools can be very dangerous if used improperly.  Also, if you use a tool that I have not requested you use, it can cause false positives, thereby delaying the complete cleaning of your machine.
     
  • Please read through my instructions carefully and make sure you complete them from start to finish. I will make sure that I lay the instructions out in a step by step order to make them easy to follow
     
  • This is a complicated process.  It requires several steps, patience, and careful following of my instructions in the order they are given to diagnose your problems to get your machine back in working order.
     
  • Please stay with me until the end of all steps and procedures and I declare your system clean.  Just because there is a lack of symptoms does not indicate a clean machine. I promise to do the same for you.
     
  • Please make sure you reply within 3 days to my responses, if there is no reply within 3 days, the topic will be closed and you will need to request the topic be reopened.
     
  • Before we get started, please remember we will do our best to get your machine repaired.  However, there are some cases where the only solution is a reformat and reinstall of the operating system.  This is a worst case scenario though.
     
  • It is impossible for me to know what interactions may happen between your computer's software and the tools we will use to clean your machine.  Therefore, I highly recommend you backup any critical personal files on your machine before we start.
     
  • If possible, please have your original Windows installation disks handy, just in case.
     
  • If you have any questions at all, please don't hesitate to ask.  There's no such thing as a stupid question when dealing with malware.
     
  • If you are unsure of an instruction I give you, or if something unexepected occurs, Do NOT proceed!  Stop and ask for clarification of the instruction or tell me what occurred.
     
  • Please copy and paste the contents of any requested logs in your replies.  Do not attach the log files in your replies unless requested to do so.
     
  • Please remember, the fixes are for your machine and your machine ONLY!


Once we have cleaned your machine, we'll have some cleanup and prevention steps to go through. We will also provide you with some information about how to reduce your chances of infection and get some protections in place to help defend you against this in the future


Please be patient while I am analyzing your logs.  I know you are probably scared and very frustrated with this problem, but I am a volunteer and sometimes life does get in the way. :)

Now, let's get started, shall we? :thumbsup:


Hello :)  

There should be another log that was created during the initial OTL run called Extras.txt  It will be in the same location as where you ran OTL from.  In this case, here:  C:\Users\Stephie\Downloads.  Please post that log in your next reply.

I'd like you to run a scan for me and post the log along with the Extras log.  I'm currently working on a fix for your machine and will post when I see the 2 requested logs. :)

One other thing:  Don't worry, we'll do our best to get your machine working properly again. :thumbsup:


Please disable your antivirus for the duration of my instructions.  Don't forget to re-enable them after you have completed the steps.


Scan with aswMBR

 

  • Please download aswMBR.exe to your desktop.
  • Double click the file to run it.
  • It will ask if you want to download the latest Avast! virus definitions, please answer yes.

aswmbrscan_zpsdc05b0f9.jpg



  • Click the Scan button to begin the scan.

aswmbrsavelog_zps1aeef48e.jpg



  • Once the scan has finished, click on Save Log, save it to your desktop as asw.txt, and please post it in your next reply.
  • Click Exit

Things I need to see in your next post:

Extras.txt Log

aswMBR Log

 

Please ignore the duplicate post below this.  Our board software is new and I'm still learning all of the ins and outs of it. :)


 


  • 0

#3
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,886 posts

Hello and welcome to Geeks to Go! My nickname is Pystryker :) , and I will be helping you with your issue today.


Before we get started, I have a few things I need to go over with you
 

  • Please do not install any new software during the cleaning process other than the tools I provide for you.  This can hinder the cleaning process.
  • Please subscribe to this topic.  By subscribing, the board will notify you when a new reply is added to your topic.  Look at the top right side of your topic title and click the Follow this Topic button.
    • If any of your security programs give you a warning about any tool I ask you to use, please do not worry.  All the links and tools I provide to you will be safe.

     
  • Please read through my instructions carefully and completely before executing them.
     
  • Please make sure that all the programs I ask you to download are downloaded to and run from your Desktop.
     
  • Please make sure you print out these instructions so that you will be able to refer to them while working on your machine.  Part of the solution(s) to your problem may involve us working in Safe Mode and you will need them to go by.  
     
  • Please do not run any tools other than the ones I ask you to, when I ask you to.  Some of these tools can be very dangerous if used improperly.  Also, if you use a tool that I have not requested you use, it can cause false positives, thereby delaying the complete cleaning of your machine.
     
  • Please read through my instructions carefully and make sure you complete them from start to finish. I will make sure that I lay the instructions out in a step by step order to make them easy to follow
     
  • This is a complicated process.  It requires several steps, patience, and careful following of my instructions in the order they are given to diagnose your problems to get your machine back in working order.
     
  • Please stay with me until the end of all steps and procedures and I declare your system clean.  Just because there is a lack of symptoms does not indicate a clean machine. I promise to do the same for you.
     
  • Please make sure you reply within 3 days to my responses, if there is no reply within 3 days, the topic will be closed and you will need to request the topic be reopened.
     
  • Before we get started, please remember we will do our best to get your machine repaired.  However, there are some cases where the only solution is a reformat and reinstall of the operating system.  This is a worst case scenario though.
     
  • It is impossible for me to know what interactions may happen between your computer's software and the tools we will use to clean your machine.  Therefore, I highly recommend you backup any critical personal files on your machine before we start.
     
  • If possible, please have your original Windows installation disks handy, just in case.
     
  • If you have any questions at all, please don't hesitate to ask.  There's no such thing as a stupid question when dealing with malware.
     
  • If you are unsure of an instruction I give you, or if something unexepected occurs, Do NOT proceed!  Stop and ask for clarification of the instruction or tell me what occurred.
     
  • Please copy and paste the contents of any requested logs in your replies.  Do not attach the log files in your replies unless requested to do so.
     
  • Please remember, the fixes are for your machine and your machine ONLY!


Once we have cleaned your machine, we'll have some cleanup and prevention steps to go through. We will also provide you with some information about how to reduce your chances of infection and get some protections in place to help defend you against this in the future


Please be patient while I am analyzing your logs.  I know you are probably scared and very frustrated with this problem, but I am a volunteer and sometimes life does get in the way. :)

Now, let's get started, shall we? :thumbsup:


Hello :)  

There should be another log that was created during the initial OTL run called Extras.txt  It will be in the same location as where you ran OTL from.  In this case, here:  C:\Users\Stephie\Downloads.  Please post that log in your next reply.

I'd like you to run a scan for me and post the log along with the Extras log.  I'm currently working on a fix for your machine and will post when I see the 2 requested logs. :)

One other thing:  Don't worry, we'll do our best to get your machine working properly again. :thumbsup:


Please disable your antivirus for the duration of my instructions.  Don't forget to re-enable them after you have completed the steps.
 

 

Scan with aswMBR

 

Please download aswMBR.exe to your desktop.

  • Double click the file to run it.
  • It will ask if you want to download the latest Avast! virus definitions, please answer yes.

aswmbrscan_zpsdc05b0f9.jpg



  • Click the Scan button to begin the scan.

aswmbrsavelog_zps1aeef48e.jpg



  • Once the scan has finished, click on Save Log, save it to your desktop as asw.txt, and please post it in your next reply.
  • Click Exit

Things I need to see in your next post:

Extras.txt Log

aswMBR Log



 

 


  • 0

#4
CaramelBliss*

CaramelBliss*

    Member

  • Topic Starter
  • Member
  • PipPip
  • 63 posts

Hi! Thanks so much for taking up my case. Here are the requested scan results.:

 

 extras.txt

 

  OTL Extras logfile created on: 3/25/2014 1:43:07 PM - Run 1

OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Stephie\Downloads
 Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16521)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
2.87 Gb Total Physical Memory | 1.54 Gb Available Physical Memory | 53.53% Memory free
5.74 Gb Paging File | 4.20 Gb Available in Paging File | 73.23% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 224.17 Gb Total Space | 74.91 Gb Free Space | 33.42% Space Free | Partition Type: NTFS
 
Computer Name: STEPHIESLIFE | User Name: Stephie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Sprint\Sprint SmartView\SwiApiMux.exe" = C:\Program Files\Sprint\Sprint SmartView\SwiApiMux.exe:*:Enabled:SwiApiMux
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01CDE2C9-4787-486A-AA2D-207457A15855}" = rport=445 | protocol=6 | dir=out | app=system | 
"{0CF2CB41-0E24-44AF-A450-9D3EED8C5368}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe | 
"{11997D90-B2DF-4D9E-9E6F-B061DD6DF64F}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | 
"{13CF8D48-DFFA-49A2-9630-CCC6A09E043C}" = lport=138 | protocol=17 | dir=in | app=system | 
"{2703147C-C3A7-41A7-B9D6-A4B015388996}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{2C9FF878-DA00-4640-AB9D-2EFD4BF6F2F9}" = rport=138 | protocol=17 | dir=out | app=system | 
"{306371A9-9E6D-4DA6-A9B5-697836CD4952}" = lport=4482 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer | 
"{37A6E41F-544C-4C9F-9EEA-6F4A702F0212}" = lport=137 | protocol=17 | dir=in | app=system | 
"{3C379C46-0601-4914-B092-39FDCC159C03}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{4786964C-0660-4235-8761-12AE91DF2923}" = rport=137 | protocol=17 | dir=out | app=system | 
"{4CA9A2F6-D154-4EC4-9F90-333CF0074B7D}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | 
"{4EE615E1-106E-4377-872C-A1BC4DC592D2}" = lport=139 | protocol=6 | dir=in | app=system | 
"{59AE82DC-8089-48DF-89C5-413079DB8710}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{5B88AFDC-D3E5-42C3-9E33-50BBB75F7FF5}" = rport=139 | protocol=6 | dir=out | app=system | 
"{70BD0354-09C5-4641-BA2F-2CBEC085D825}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | 
"{85926437-5E9B-490F-88E6-F4EA6D9FFED8}" = lport=4482 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery | 
"{8FEB9EC1-4697-4665-B9BF-D03B7B10786E}" = lport=4481 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery | 
"{93D53FFA-C886-426C-AF3D-22FC58AFDC86}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | 
"{A4FE161D-9731-4A37-B193-C88A865606DC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{AE267549-EBEB-4933-BDD7-2A4FD8E59680}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{B05CD2CD-D7A5-4E3C-881A-84706F48EC63}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{B4BEB738-767D-48C8-A2FE-5134AD58B23C}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | 
"{B5B30DD4-6D9D-4BE3-9DF9-711CC67D9F89}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | 
"{C10DF9B6-191A-4E40-96C9-DEFE7A0689AB}" = lport=4481 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer | 
"{D5F59D8C-A9DE-41C0-B51E-3D1675105B9C}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | 
"{E46BC3B3-854D-47CC-B799-55B6D9565A89}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{F04B1FE3-31EB-4AD8-91E0-1162BFAA9F18}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{F47227EB-AF99-4804-B3EA-A0327D7CB855}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 | 
"{FA3CFC66-8F21-4191-BE06-040F79EE5353}" = lport=445 | protocol=6 | dir=in | app=system | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1B911778-D935-4DFC-B5BC-663D56E113D2}" = protocol=6 | dir=in | app=c:\program files\hp\hp deskjet 1000 j110 series\bin\usbsetup.exe | 
"{2116AFAB-9B94-46EF-93B7-E5EA51A86C17}" = protocol=1 | dir=out | [email protected],-28544 | 
"{2A855C87-5A63-4095-B55E-D426F9969FC8}" = protocol=17 | dir=in | app=c:\users\stephie\appdata\local\mediaget2\mediaget.exe | 
"{34A9F86C-7F8E-4CA6-B917-7761C31ECDA3}" = protocol=1 | dir=in | [email protected],-28543 | 
"{35D69891-F6EA-48F0-BEF6-4800261AE9E1}" = protocol=17 | dir=in | app=c:\users\stephie\desktop\limewire\limewire.exe | 
"{3CBC34A7-CD11-4908-9E4A-6F17269D2747}" = protocol=17 | dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\devicesetup.exe | 
"{44A87628-C3B7-4364-A57F-F7318B681738}" = protocol=17 | dir=in | app=c:\program files\hp\hp deskjet 1000 j110 series\bin\usbsetup.exe | 
"{44F88954-D915-435E-9192-2F9E6E458402}" = protocol=6 | dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\devicesetup.exe | 
"{4DF0D843-D634-4352-BD29-9340F035790D}" = protocol=17 | dir=in | app=c:\program files\vmware\vmware player\vmware-authd.exe | 
"{51AFABC2-8A3A-4B3C-99EC-4AA2197C6550}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe | 
"{5905FB84-2EB6-445A-A41B-59C4A9FB65E9}" = protocol=6 | dir=in | app=c:\program files\cdv software entertainment usa\sacred 2 - fallen angel\system\sacred2.exe | 
"{59A517F1-D66A-4C94-984B-3818E2B02585}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | 
"{5B442058-9F50-4C86-96F5-9B02B34799FF}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{5F740ACF-73A5-406B-956B-F52EDB5F8B62}" = protocol=6 | dir=in | app=c:\program files\world of warcraft\launcher.exe | 
"{5F7F2B79-51C4-4024-9224-1137EAA07DB8}" = protocol=6 | dir=in | app=c:\program files\vmware\vmware player\vmware-authd.exe | 
"{69D49667-1C9A-49A2-871D-76EA14ED882C}" = dir=in | app=c:\users\stephie\appdata\local\facebook\video\skype\facebookvideocalling.exe | 
"{6B2A5DAF-76B8-4BBE-BA33-7DB14126E761}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe | 
"{6D6B0E37-608C-42DF-A27E-F3F93C108834}" = protocol=6 | dir=in | app=c:\program files\research in motion\blackberry desktop\rim.desktop.exe | 
"{714116CA-6178-43CF-B47F-7F75881F7130}" = protocol=17 | dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\hpnetworkcommunicator.exe | 
"{7BEEBDD8-1E3F-4761-893B-DB17E5159F21}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe | 
"{83A9FE6E-B978-4373-87A5-025FBFE5944D}" = dir=in | app=c:\program files\skype\phone\skype.exe | 
"{8B56F850-0981-4190-A7D6-F0E86A12A1A1}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | 
"{8D778DB9-31DC-46AB-90E7-D72AFBBFA1AD}" = protocol=17 | dir=in | app=c:\program files\world of warcraft\launcher.patch.exe | 
"{8E0BB376-CC2B-4F0D-B2C2-D8153A59A3C1}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe | 
"{8F6CD9E6-F344-49BE-A993-EFB2B0783BFD}" = protocol=6 | dir=in | app=c:\users\stephie\desktop\limewire\limewire.exe | 
"{92DA8D19-ACC4-4A65-AA4D-D45560EAE49D}" = protocol=58 | dir=in | [email protected],-28545 | 
"{9B4BD31E-74C5-4BFD-B395-42A5A4FE9598}" = protocol=58 | dir=out | [email protected],-28546 | 
"{A449B291-3E1A-46D8-A68E-B0B40A1A1213}" = protocol=6 | dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\hpnetworkcommunicator.exe | 
"{B2E9966E-7080-41B0-A347-1B207B99018A}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe | 
"{BFD468AB-F8D6-40E4-AE08-688C74BFAE09}" = protocol=6 | dir=in | app=c:\program files\world of warcraft\launcher.patch.exe | 
"{C2B79199-E4B3-4005-8314-F97CA770A421}" = protocol=17 | dir=in | app=c:\program files\research in motion\blackberry desktop\rim.desktop.exe | 
"{D0EACF06-A75B-433E-87C4-BBFBEC8A75B7}" = protocol=17 | dir=in | app=c:\program files\world of warcraft\launcher.exe | 
"{D5564147-C668-4536-B83C-110DB791BF31}" = protocol=6 | dir=in | app=c:\program files\cdv software entertainment usa\sacred 2 - fallen angel\system\s2gs.exe | 
"{D5C671E4-BA07-46AE-9070-94894A694DF0}" = protocol=6 | dir=in | app=c:\users\stephie\appdata\local\mediaget2\mediaget.exe | 
"{D8687631-20BE-4B1C-A632-CBD325CE68A7}" = protocol=17 | dir=in | app=c:\program files\cdv software entertainment usa\sacred 2 - fallen angel\system\s2gs.exe | 
"{DF67DA80-C05C-4649-9860-D319450261AC}" = dir=in | app=c:\program files\leapfrog\leapfrog connect\leapfrogconnect.exe | 
"{E21622EF-3FF7-444D-953F-996E8B553B37}" = protocol=6 | dir=in | app=c:\program files\vmware\vmware player\vmware-authd.exe | 
"{E2DC0194-5B38-4843-9816-7CA4D1DECD4E}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe | 
"{E2E5305D-BD8F-48B4-A13F-600E50E45F33}" = protocol=17 | dir=in | app=c:\program files\cdv software entertainment usa\sacred 2 - fallen angel\system\sacred2.exe | 
"{E5CD0C25-532E-448E-AB18-72AC8B422ED9}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe | 
"{E8C08C7A-122A-4C8A-9CF4-8277F29BAF90}" = protocol=17 | dir=in | app=c:\program files\vmware\vmware player\vmware-authd.exe | 
"TCP Query User{08DF1094-277A-478D-93BF-B6FA206DAE81}C:\program files\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe | 
"TCP Query User{3C363475-CDAD-4419-8BF0-0A1F3EFBABE6}C:\users\stephie\appdata\local\mediaget2\mediaget.exe" = protocol=6 | dir=in | app=c:\users\stephie\appdata\local\mediaget2\mediaget.exe | 
"TCP Query User{7126DA6E-0605-4AC3-BEBA-572D4A6F298D}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | 
"TCP Query User{9864A093-A00F-44A5-B5B8-B4704CF891A4}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe | 
"TCP Query User{C591609F-ACA1-4188-8564-CBDE4459DD3A}C:\program files\cdv software entertainment usa\sacred 2 - fallen angel\system\s2gs.exe" = protocol=6 | dir=in | app=c:\program files\cdv software entertainment usa\sacred 2 - fallen angel\system\s2gs.exe | 
"UDP Query User{7A137380-5317-4347-BA31-420E664A8E4D}C:\program files\cdv software entertainment usa\sacred 2 - fallen angel\system\s2gs.exe" = protocol=17 | dir=in | app=c:\program files\cdv software entertainment usa\sacred 2 - fallen angel\system\s2gs.exe | 
"UDP Query User{8066E30B-5E82-4F15-8B43-C195053A779C}C:\program files\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe | 
"UDP Query User{A300E377-4842-4EBF-9E03-A455C37B5B56}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe | 
"UDP Query User{F0666AF8-2969-4D4D-9CB2-A6200BB9A186}C:\users\stephie\appdata\local\mediaget2\mediaget.exe" = protocol=17 | dir=in | app=c:\users\stephie\appdata\local\mediaget2\mediaget.exe | 
"UDP Query User{F6069B5E-A266-415E-98F3-135051ACF924}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{00C1B233-D218-484B-8078-9375482C5608}" = LeapFrog Tag Plugin
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0CD47142-BA4F-46B0-AA92-2675864928B8}" = Microsoft Security Client
"{0D5D0BEE-FBA9-4928-A50D-6CDFAB827755}" = TOSHIBA ConfigFree
"{1023383E-D9F6-478C-A965-23A4657B3C9A}" = Sacred 2
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{247C5DDA-FFD7-44E0-8BF7-79BC80A0BF87}" = Windows Live Family Safety
"{26A24AE4-039D-4CA4-87B4-2F83217051FF}" = Java 7 Update 51
"{2883F6F5-0509-43F3-868C-D50330DD9DD3}" = TOSHIBA Hardware Setup
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2D6E3D97-1FDF-4993-AC75-72F59EC445C5}" = Windows Live Family Safety
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{40C4903E-EDFB-4CAE-A611-41FEBA585921}" = VTech Download Agent Library
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B1E87C3-00DE-4898-8E39-E390AAEF2391}" = TOSHIBA Supervisor Password
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.11
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{6DA93E66-5FA8-44ED-9CCA-40773444C10D}" = HP Deskjet 3050 J610 series Basic Device Software
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-wildgames" = WildTangent Games App
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{895722FE-25FE-4854-95AC-B0C42F9DBEDA}" = REALTEK RTL8187B Wireless LAN Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}" = Facebook Video Calling 2.0.0.447
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-003F-0409-0000-0000000FF1CE}" = Microsoft Office Excel Viewer
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{992C016C-CA8F-4D13-ABAB-D24A481C102B}" = LeapFrog Leapster2 Plugin
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9E384B32-59C8-46EF-BEA6-4DC8F27CDB8E}" = InstallVC90Support
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A50DE037-B5C0-4C8A-8049-B0C576B313D1}" = Google+ Auto Backup
"{A53A11EA-0095-493F-86FA-A15E8A86A405}" = VMware Player
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.1
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B0BCDCBD-863D-4CAB-BF68-8D1F6B1BDC13}" = Atheros Wi-Fi Protected Setup Library
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Disc Creator
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B95B1BA9-F887-4B3C-8D3A-CCD4C4675120}" = Microsoft Default Manager
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C53D16CC-E56F-47B8-906E-70AAF8EABB4F}" = Toshiba Registration
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D87149B3-7A1D-4548-9CBF-032B791E5908}" = Desktop Doctor
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1497C00-2605-433E-822E-3E82649CE056}" = HP Deskjet 3050 J610 series Product Improvement Study
"{E1E56B8A-1AAF-422A-91DB-625059FB9863}" = TOSHIBA Desktop Links
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0FDF9C9-1DDC-401F-B638-36F1CAE8A875}" = VideoStudio
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}" = HP Deskjet 3050 J610 series Help
"{F9D59E62-845F-49A2-8B75-DDB00661673C}" = LeapFrog Connect
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"781745E87AFF80C0C1388CFF79D19ECAB2E9BB47" = Windows Driver Package - LeapFrog (FlyUsb) USB  (11/05/2008 1.1.1.0)
"8F14F2ECEDE68D26EA515B48DC25B39103C4FE8D" = Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net  (09/10/2009 02.03.05.012)
"ActiveTouchMeetingClient" = WebEx
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 12 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"CCleaner" = CCleaner
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2009-09-09
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Google Chrome" = Google Chrome
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Photo Creations" = HP Photo Creations
"iLivid" = iLivid
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"InstallShield_{F0FDF9C9-1DDC-401F-B638-36F1CAE8A875}" = Corel VideoStudio 12
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Leapster2Plugin" = Use the entry named LeapFrog Connect to uninstall (LeapFrog Leapster2 Plugin)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"Picasa 3" = Picasa 3
"PrivitizeVPN" = PrivitizeVPN
"ShopAtHome.com Helper" = ShopAtHome.com Helper
"ShopAtHome.com Toolbar" = ShopAtHome.com Toolbar
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"SystemRequirementsLab" = System Requirements Lab
"TagPlugin" = Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Plugin)
"TVWiz" = Intel® TV Wizard
"UPCShell" = LeapFrog Connect
"uTorrentControl_v2 Toolbar" = uTorrentControl_v2 Toolbar
"VLC media player" = VLC media player 2.0.1
"VTechDownloadManager" = Learning Lodge Navigator
"WildTangent toshiba Master Uninstall" = WildTangent Games
"WildTangent wildgames Master Uninstall" = WildTangent Games
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite" = Windows Live Essentials
"WT050971" = FATE
"WT050972" = FATE Undiscovered Realms
"WTA-d3d31004-e99e-4092-b8f5-ab3a9a385960" = Nancy Drew: Secrets Can Kill Remastered
"WTA-d3d5e9ea-60cd-4a4d-8e17-bc096f55d780" = Cake Mania Main Street
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Adobe Connect Add-in" = Adobe Connect Add-in
"GoToMeeting" = GoToMeeting 4.5.0.457
"Puzzle Pirates" = Puzzle Pirates
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 3/22/2014 6:45:23 PM | Computer Name = StephiesLife | Source = Windows Backup | ID = 4103
Description = 
 
Error - 3/22/2014 7:03:05 PM | Computer Name = StephiesLife | Source = MsiInstaller | ID = 11720
Description = 
 
Error - 3/22/2014 7:03:07 PM | Computer Name = StephiesLife | Source = WinMgmt | ID = 10
Description = 
 
Error - 3/24/2014 8:07:56 PM | Computer Name = StephiesLife | Source = WinMgmt | ID = 10
Description = 
 
Error - 3/24/2014 8:10:40 PM | Computer Name = StephiesLife | Source = Application Error | ID = 1000
Description = Faulting application name: uvPL.exe, version: 9.0.0.0, time stamp:
 0x4849008a  Faulting module name: HttpHandle302.dll, version: 1.0.0.1, time stamp:
 0x507f1288  Exception code: 0xc0000005  Fault offset: 0x00005015  Faulting process id:
 0xfbc  Faulting application start time: 0x01cf47be79e39104  Faulting application path:
 C:\Program Files\Corel\Corel VideoStudio 12\uvPL.exe  Faulting module path: C:\Users\Stephie\AppData\Roaming\ShopAtHome\ShopAtHomeHelper\HttpHandle302.dll
Report
 Id: e58e4fb3-b3b1-11e3-9e5d-001e339f5028
 
Error - 3/24/2014 8:10:58 PM | Computer Name = StephiesLife | Source = Application Error | ID = 1000
Description = Faulting application name: uvPL.exe, version: 9.0.0.0, time stamp:
 0x4849008a  Faulting module name: HttpHandle302.dll, version: 1.0.0.1, time stamp:
 0x507f1288  Exception code: 0xc0000005  Fault offset: 0x00005015  Faulting process id:
 0xfbc  Faulting application start time: 0x01cf47be79e39104  Faulting application path:
 C:\Program Files\Corel\Corel VideoStudio 12\uvPL.exe  Faulting module path: C:\Users\Stephie\AppData\Roaming\ShopAtHome\ShopAtHomeHelper\HttpHandle302.dll
Report
 Id: f0258f0b-b3b1-11e3-9e5d-001e339f5028
 
Error - 3/24/2014 8:17:57 PM | Computer Name = StephiesLife | Source = Windows Backup | ID = 4103
Description = 
 
Error - 3/24/2014 8:26:13 PM | Computer Name = StephiesLife | Source = Customer Experience Improvement Program | ID = 1008
Description = 
 
Error - 3/25/2014 12:27:47 PM | Computer Name = StephiesLife | Source = Customer Experience Improvement Program | ID = 1008
Description = 
 
Error - 3/25/2014 1:09:36 PM | Computer Name = StephiesLife | Source = WinMgmt | ID = 10
Description = 
 
Error - 3/25/2014 1:36:33 PM | Computer Name = StephiesLife | Source = WinMgmt | ID = 10
Description = 
 
[ System Events ]
Error - 3/25/2014 1:08:40 PM | Computer Name = StephiesLife | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!
 
Error - 3/25/2014 1:08:40 PM | Computer Name = StephiesLife | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!
 
Error - 3/25/2014 1:08:51 PM | Computer Name = StephiesLife | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!
 
Error - 3/25/2014 1:09:13 PM | Computer Name = StephiesLife | Source = Service Control Manager | ID = 7034
Description = The SQL Server VSS Writer service terminated unexpectedly.  It has
 done this 1 time(s).
 
Error - 3/25/2014 1:09:13 PM | Computer Name = StephiesLife | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
   jswpslwf
 
Error - 3/25/2014 1:34:41 PM | Computer Name = StephiesLife | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!
 
Error - 3/25/2014 1:34:41 PM | Computer Name = StephiesLife | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!
 
Error - 3/25/2014 1:34:52 PM | Computer Name = StephiesLife | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!
 
Error - 3/25/2014 1:35:17 PM | Computer Name = StephiesLife | Source = Service Control Manager | ID = 7034
Description = The SQL Server VSS Writer service terminated unexpectedly.  It has
 done this 1 time(s).
 
Error - 3/25/2014 1:35:17 PM | Computer Name = StephiesLife | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
   jswpslwf
 
 
< End of report >
 
 
 
 
 
and asw.txt:
   aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2014-03-26 15:45:51
-----------------------------
15:45:51.043    OS Version: Windows 6.1.7601 Service Pack 1
15:45:51.044    Number of processors: 2 586 0xF0D
15:45:51.045    ComputerName: STEPHIESLIFE  UserName: Stephie
15:45:52.314    Initialize success
15:46:18.264    AVAST engine defs: 14032602
15:46:53.865    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
15:46:53.869    Disk 0 Vendor: WDC_WD25 11.0 Size: 238475MB BusType: 3
15:46:54.206    Disk 0 MBR read successfully
15:46:54.211    Disk 0 MBR scan
15:46:54.276    Disk 0 Windows 7 default MBR code
15:46:54.287    Disk 0 Partition 1 00     27 Hidden NTFS WinRE NTFS         1500 MB offset 2048
15:46:54.309    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS       229555 MB offset 3074048
15:46:54.345    Disk 0 Partition 3 00     17 Hidd HPFS/NTFS NTFS         7419 MB offset 473202688
15:46:54.399    Disk 0 scanning sectors +488396800
15:46:54.612    Disk 0 scanning C:\Windows\system32\drivers
15:47:31.413    Service scanning
15:47:51.092    Service MpKslb80963eb c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{52228CBD-9110-4BA6-AB86-59B5EC4CF9AF}\MpKslb80963eb.sys **LOCKED** 32
15:48:21.850    Modules scanning
15:48:50.890    Disk 0 trace - called modules:
15:48:50.918    ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys halmacpi.dll 
15:48:50.924    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x87021030]
15:48:50.931    3 CLASSPNP.SYS[8b7a959e] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x865e1028]
15:48:52.380    AVAST engine scan C:\Windows
15:49:06.453    AVAST engine scan C:\Windows\system32
15:55:05.072    AVAST engine scan C:\Windows\system32\drivers
15:55:36.070    AVAST engine scan C:\Users\Stephie
16:45:37.986    AVAST engine scan C:\ProgramData
16:58:16.136    Scan finished successfully
17:05:34.676    Disk 0 MBR has been saved successfully to "C:\Users\Stephie\Desktop\MBR.dat"
17:05:34.758    The log file has been saved successfully to "C:\Users\Stephie\Desktop\asw.txt"
 
 
 
 Sorry took so long to scan. And thanks again for taking my case. I feel extra reassured.  :wave:
 

  • 0

#5
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,886 posts

Sorry took so long to scan. And thanks again for taking my case. I feel extra reassured.  :wave:

 

 

No worries on the scan, we'll do this on the schedule that works the best for you. :)  And you're quite welcome. :thumbsup:

 

 

 

We have some work to do, so let's get started. :)


The Dangers of P2P Programs

I noticed that you have a P2P file sharing  program on your computer . I cannot stress highly enough the danger in using these types of programs. P2P programs are one of the major avenues of infection these days. The files downloaded with these programs are more likely than not infected with trojans, malware, rootkits, etc.

 You run the risk of getting an infection that can compromise your sensitive data, such as financial records, personal information, etc. That is just the infection aspect of using P2P programs. You also run the risk of possible arrest, fines, or in severe cases, jail time for illegal downloading of copyrighted material.

Here are some information sources about the dangers of P2P programs:

FBI - Peer to Peer Scams

USA Today Artticle on P2P Programs

File Sharing Infects 500,000 Computers

I very much recommend you uninstall this program from your machine. If not, I can guarantee you will be back needing help with your machine again. The risks of infections from content downloaded with P2P programs far outweigh any benefit of using them.

It is, of course, your choice as to whether or not you remove the program from your machine. It is my duty though, to point out how dangerous it is to use these programs. However, I must request that you do not use it while we are cleaning your machine.




Step 1:  Chrome Changes and Program Uninstalls


Changing Chrome's Homepage

We need to change your homepage in Chrome.  Please follow the instructions below.
 

  • Open Chrome and type this in the address bar:  chrome:settings
  • When the Settings page opens, look under On Startup and then click Open a specific set of pages and click Set Pages
  • When the window opens, type in any page you wish as your new start page.
  • Once you have typed in your new home page, close the window.


Remove Chrome Extensions

There is an extension in Chrome that needs to be removed, please follow the instructions below to remove it.

Start Chrome and type this into the address bar:  chrome:extensions

This will display a page of all the installed extensions.  Please remove the extension below by clicking the trash can icon beside it

Zoomex


Program Uninstalls

Please uinstall the following programs as they are known adware/malware related programs.

iLivid

ShopAtHome.com Helper

ShopAtHome.com Toolbar





Step 2:  OTL Fix


Let's run an OTL fix:

Warning:  This fix is to be used on this system and this system ONLY.  Using this fix on any other machine other than yours can seriously damage it.

Be advised that when the fix commences, it will shut down all running processes and you may lose the desktop and icons, they will return on reboot.

Run OTL by double clicking it (Windows Vista, Windows 7, and 8, right click and select "Run as Administrator)



  • Copy the text in the quote box below (do not copy the word "quote") and paste in the in the box marked Custom Scans/Fixes as shown in the graphic below.

otlrunfix.jpg



:Commands
[createrestorepoint]

:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylo....10&affID=19591
IE - HKLM\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT3220468
IE - HKCU\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes\{11C12D3A-00D2-41F8-B205-9565DA0F1F55}: "URL" = http://websearch.sho...q={searchTerms}
IE - HKCU\..\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}: "URL" = http://www.crawler.c...rms}&tbid=60116
IE - HKCU\..\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}: "URL" = http://search.babylo....10&affID=19591
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT3220468
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incre...&loc=search_box
[2011/07/09 14:38:37 | 000,002,423 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
O2 - BHO: (no name) - {11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5} - C:\PROGRA~1\SITERA~1\SiteRank.dll File not found
O2 - BHO: (ShopAtHome.com Cash Back Helper) - {66516A07-F617-488A-90CF-4E690CFB3C5F} - C:\Users\Stephie\AppData\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll (ShopAtHome.com)
O2 - BHO: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (ShopAtHome.com Toolbar) - {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - C:\Users\Stephie\AppData\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll (ShopAtHome.com)
O3 - HKLM\..\Toolbar: (uTorrentControl_v2 Toolbar) - {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (ShopAtHome.com Toolbar) - {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - C:\Users\Stephie\AppData\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll (ShopAtHome.com)
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentControl_v2 Toolbar) - {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:\Program Files\uTorrentControl_v2\prxtbuTor.dll (Conduit Ltd.)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [PrivitizeVPN] C:\Program Files\PrivitizeVPN\PrivitizeVPN.exe (OOO Industry)
O4 - HKLM..\Run: [ShopAtHomeWatcher] C:\Users\Stephie\AppData\Roaming\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe ()
O4 - HKLM..\Run: [SiteRanker] "C:\Program Files\SiteRanker\SiteRankTray.exe" File not found
O4 - HKCU..\Run: [APISupport] C:\Users\Stephie\AppData\Local\Conduit\APISupport\APISupport.dll (Conduit Ltd.)
O4 - HKCU..\Run: [BackgroundContainer] C:\Users\Stephie\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll (Conduit Ltd.)
O4 - HKCU..\Run: [Desktop Software] "C:\Program Files\Common Files\SupportSoft\bin\bcont.exe"  /ini "C:\Program Files\ComcastUI\Desktop Software\uinstaller.ini" /fromrun /starthidden File not found
O4 - HKCU..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" File not found
O4 - HKCU..\Run: [TBHostSupport] C:\Users\Stephie\AppData\Local\TBHostSupport\TBHostSupport_0.dll (Conduit Ltd.)
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html File not found
O15 - HKCU\..Trusted Domains: alpineaccess.net ([mail] http in Trusted sites)
O15 - HKCU\..Trusted Domains: evolvondemand.net ([sitel] https in Trusted sites)
O33 - MountPoints2\{0b90b343-6737-11e1-8df2-001e339f5028}\Shell - "" = AutoRun
O33 - MountPoints2\{0b90b343-6737-11e1-8df2-001e339f5028}\Shell\AutoRun\command - "" = E:\Autorun.exe
O33 - MountPoints2\{a3e34131-0721-11e1-ba75-001e339f5028}\Shell - "" = AutoRun
O33 - MountPoints2\{a3e34131-0721-11e1-ba75-001e339f5028}\Shell\AutoRun\command - "" = E:\iStudio.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\iStudio.exe
[2013/01/23 13:13:17 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\ShopAtHome
[2010/02/15 23:56:01 | 000,000,000 | ---D | M] -- C:\Users\Stephie\AppData\Roaming\SiteRanker


:Files
netsh advfirewall reset /c
netsh advfirewall set allprofiles state on /c
C:\Users\Stephie\AppData\Local\NativeMessaging
C:\Users\Stephie\AppData\Roaming\ShopAtHome

:Commands
[emptytemp]
[resethosts]

                                            
 

  • Click the Run Fix button at the top of the OTL control panel.
  • Let the program run until it's finished and then reboot the computer.
  • Once your machine has rebooted, a log will open.   Please post that log in your next reply.

If you have any problems, questions, or need further explanation, please post a message in this thread and I will get back to you asap.



Step 3:  AdwCleaner


Download ADWcleaner by clicking herePlease save it to your Desktop


adwcleaner2_zps680e0e15.jpg
 

  • Double click (Vista and 7 Users)right click the adwcleaner.exe file and click Run as Adminstrator and accept the UAC prompt to run AdwCleaner
  • Close any open windows or browsers.
  • Pause your Anti-Virus program if it is running.
  • Once it starts, click on the Scan button.  
  • Let the scan complete itself.  This may take a few minutes.
  • Once the scan has finished,  it will say  "Pending, uncheck elements you don't want to remove.", don't worry about unchecking anything and then click the Clean button.  When finished, it will ask to reboot.  Please reboot.
  • When the machine has rebooted, a log will be produced.  Please copy/paste that in your next reply.  Here's how:
  • Click the Report button and the log will open.  Copy and Paste the contents of the log file into your next reply.

    This report is also saved at C:\AdwCleaner[R0].txt


Step 4:  Junkware Removal Tool


thisisujrt.gif  Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.


Step 5:  OTL Quick Scan




  • Start OTL and this time click the Quick Scan button
  • OTL will scan your system and produce one log when finished.
  • Please post that log in your next reply.


Things I need to see in your next post:

OTL Fix Log

AdwCleaner Log

Junkware Removal Tool

OTL Quick Scan Log

Question:  How is the computer running now?




 


  • 0

#6
CaramelBliss*

CaramelBliss*

    Member

  • Topic Starter
  • Member
  • PipPip
  • 63 posts

Man.... Yoshi's (my laptop) is in bad shape, huh.  :no:  I'm doing the next steps right now and thanks for the useful information on the P2Ps too. I had no idea... I've back up my files already as well. I'll have my results in the next post.


  • 0

#7
CaramelBliss*

CaramelBliss*

    Member

  • Topic Starter
  • Member
  • PipPip
  • 63 posts

Okay,

 So, here's the skinny, I uninstalled all that you suggested, but couldn't find the iLivid though I remember the icon and the day I downloaded it. I also remember deleting it right after I downloaded it. Just bad Juju. But, the JRT scan results showed that it was found and deleted. Tricky tricky. Okay, here are the results...

 

 OTL Fix Log:

 

All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6}\ deleted successfully.
C:\Program Files\uTorrentControl_v2\prxtbuTor.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6}\ not found.
File C:\Program Files\uTorrentControl_v2\prxtbuTor.dll not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{11C12D3A-00D2-41F8-B205-9565DA0F1F55}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11C12D3A-00D2-41F8-B205-9565DA0F1F55}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}\ not found.
C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{66516A07-F617-488A-90CF-4E690CFB3C5F}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{66516A07-F617-488A-90CF-4E690CFB3C5F}\ not found.
File C:\Users\Stephie\AppData\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473b6bd-4691-4744-a82b-7854eb3d70b6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6}\ not found.
File C:\Program Files\uTorrentControl_v2\prxtbuTor.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{311B58DC-A4DC-4B04-B1B5-60299AD3D803} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{311B58DC-A4DC-4B04-B1B5-60299AD3D803}\ not found.
File C:\Users\Stephie\AppData\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{7473b6bd-4691-4744-a82b-7854eb3d70b6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7473b6bd-4691-4744-a82b-7854eb3d70b6}\ not found.
File C:\Program Files\uTorrentControl_v2\prxtbuTor.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{311B58DC-A4DC-4B04-B1B5-60299AD3D803} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{311B58DC-A4DC-4B04-B1B5-60299AD3D803}\ not found.
File C:\Users\Stephie\AppData\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7473B6BD-4691-4744-A82B-7854EB3D70B6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7473B6BD-4691-4744-A82B-7854EB3D70B6}\ not found.
File C:\Program Files\uTorrentControl_v2\prxtbuTor.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\PrivitizeVPN deleted successfully.
C:\Program Files\PrivitizeVPN\PrivitizeVPN.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ShopAtHomeWatcher deleted successfully.
File C:\Users\Stephie\AppData\Roaming\ShopAtHome\ShopAtHomeHelper\ShopAtHomeWatcher.exe not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SiteRanker deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\APISupport not found.
C:\Users\Stephie\AppData\Local\Conduit\APISupport\APISupport.dll moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\BackgroundContainer deleted successfully.
C:\Users\Stephie\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Desktop Software deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\DW6 deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\TBHostSupport deleted successfully.
C:\Users\Stephie\AppData\Local\TBHostSupport\TBHostSupport_0.dll moved successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Google Sidewiki...\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\alpineaccess.net\mail\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\evolvondemand.net\sitel\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b90b343-6737-11e1-8df2-001e339f5028}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0b90b343-6737-11e1-8df2-001e339f5028}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0b90b343-6737-11e1-8df2-001e339f5028}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0b90b343-6737-11e1-8df2-001e339f5028}\ not found.
File E:\Autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a3e34131-0721-11e1-ba75-001e339f5028}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a3e34131-0721-11e1-ba75-001e339f5028}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a3e34131-0721-11e1-ba75-001e339f5028}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a3e34131-0721-11e1-ba75-001e339f5028}\ not found.
File E:\iStudio.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ not found.
File E:\iStudio.exe not found.
C:\Users\Stephie\AppData\Roaming\ShopAtHome\ShopAtHomeHelper folder moved successfully.
C:\Users\Stephie\AppData\Roaming\ShopAtHome folder moved successfully.
C:\Users\Stephie\AppData\Roaming\SiteRanker folder moved successfully.
========== FILES ==========
< netsh advfirewall reset /c >
Ok.
C:\Users\Stephie\Downloads\cmd.bat deleted successfully.
C:\Users\Stephie\Downloads\cmd.txt deleted successfully.
< netsh advfirewall set allprofiles state on /c >
Ok.
C:\Users\Stephie\Downloads\cmd.bat deleted successfully.
C:\Users\Stephie\Downloads\cmd.txt deleted successfully.
C:\Users\Stephie\AppData\Local\NativeMessaging\CT3220468\1_0_0_9 folder moved successfully.
C:\Users\Stephie\AppData\Local\NativeMessaging\CT3220468\1_0_0_7 folder moved successfully.
C:\Users\Stephie\AppData\Local\NativeMessaging\CT3220468\1_0_0_6 folder moved successfully.
C:\Users\Stephie\AppData\Local\NativeMessaging\CT3220468\1_0_0_4 folder moved successfully.
C:\Users\Stephie\AppData\Local\NativeMessaging\CT3220468\1_0_0_10 folder moved successfully.
C:\Users\Stephie\AppData\Local\NativeMessaging\CT3220468 folder moved successfully.
C:\Users\Stephie\AppData\Local\NativeMessaging folder moved successfully.
File\Folder C:\Users\Stephie\AppData\Roaming\ShopAtHome not found.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: HighSprited1
->Temp folder emptied: 39932 bytes
->Temporary Internet Files folder emptied: 12216238 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 456 bytes
 
User: Public
 
User: Stephie
->Temp folder emptied: 308894904 bytes
->Temporary Internet Files folder emptied: 633773375 bytes
->Java cache emptied: 16203662 bytes
->Google Chrome cache emptied: 388536902 bytes
->Flash cache emptied: 5342563 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1057472 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 487743464 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 1,768.00 mb
 
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.69.0 log created on 03282014_124603

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


AdwCleaner Log:

 

# AdwCleaner v3.022 - Report created 28/03/2014 at 13:07:37
# Updated 13/03/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
# Username : Stephie - STEPHIESLIFE
# Running from : C:\Users\Stephie\Desktop\adwcleaner.exe
# Option : Clean

***** [ Services ] *****

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\clsoft ltd
Folder Deleted : C:\ProgramData\MagniPic
Folder Deleted : C:\ProgramData\Premium
Folder Deleted : C:\ProgramData\Trymedia
Folder Deleted : C:\ProgramData\Zoomex
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SiteRanker
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\Crawler
Folder Deleted : C:\Program Files\iLivid
Folder Deleted : C:\Program Files\uniblue
Folder Deleted : C:\Program Files\uTorrentControl_v2
Folder Deleted : C:\Users\Stephie\AppData\Local\Conduit
Folder Deleted : C:\Users\Stephie\AppData\Local\Ilivid Player
Folder Deleted : C:\Users\Stephie\AppData\Local\TBHostSupport
Folder Deleted : C:\Users\Stephie\AppData\Local\WhiteListing
Folder Deleted : C:\Users\Stephie\AppData\LocalLow\BabylonToolbar
Folder Deleted : C:\Users\Stephie\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Stephie\AppData\LocalLow\FunWebProducts
Folder Deleted : C:\Users\Stephie\AppData\LocalLow\MagniPic
Folder Deleted : C:\Users\Stephie\AppData\LocalLow\MyWebSearch
Folder Deleted : C:\Users\Stephie\AppData\LocalLow\SiteRanker
Folder Deleted : C:\Users\Stephie\AppData\LocalLow\Zoomex
Folder Deleted : C:\Users\Stephie\AppData\LocalLow\uTorrentControl_v2
Folder Deleted : C:\Users\Stephie\AppData\Roaming\uniblue
Folder Deleted : C:\Users\HighSprited1\AppData\LocalLow\SiteRanker
File Deleted : C:\Windows\Downloaded Program Files\popcaploader.inf
File Deleted : C:\Users\Stephie\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_app.mam.conduit.com_0.localstorage
File Deleted : C:\Users\Stephie\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_app.mam.conduit.com_0.localstorage-journal
File Deleted : C:\Windows\System32\Tasks\BackgroundContainer Startup Task

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb
Key Deleted : HKCU\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{21AE875B-7B7E-47D3-8BD5-8BA78E0E16DF}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{21AE875B-7B7E-47D3-8BD5-8BA78E0E16DF}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\conduit.com
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Key Deleted : HKLM\SOFTWARE\Classes\ilivid
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askchecker_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askchecker_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BabylonToolbarsrv_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BabylonToolbarsrv_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_1_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_1_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_rasmancs
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3220468
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5D0F555B-4A30-4436-9447-77A3964513DD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EC8666C4-665B-4EA5-9C5F-C8859070B352}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\FunWebProducts
Key Deleted : HKCU\Software\ilivid
Key Deleted : HKCU\Software\PrivitizeVPNInstallDates
Key Deleted : HKCU\Software\StartSearch
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\Zugo
Key Deleted : HKCU\Software\uTorrentControl_v2
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\BackgroundContainer
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\Fun Web Products
Key Deleted : HKCU\Software\AppDataLow\Software\FunWebProducts
Key Deleted : HKCU\Software\AppDataLow\Software\MyWebSearch
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\uTorrentControl_v2
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\ilivid
Key Deleted : HKLM\Software\systweak
Key Deleted : HKLM\Software\Trymedia Systems
Key Deleted : HKLM\Software\uTorrentControl_v2
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ilivid
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentControl_v2 Toolbar
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16521

-\\ Google Chrome v33.0.1750.154

[ File : C:\Users\Stephie\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted : search_url
Deleted : keyword

*************************

AdwCleaner[R0].txt - [8791 octets] - [28/03/2014 13:05:54]
AdwCleaner[S0].txt - [8772 octets] - [28/03/2014 13:07:37]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8832 octets] ##########

 

   
Junkware Removal Tool:

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Home Premium x86
Ran by Stephie on Fri 03/28/2014 at 13:42:45.68
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

~~~ Services

 

~~~ Registry Values

 

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iLividSetupV1[1]_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iLividSetupV1[1]_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iLividSetupV1[2]_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iLividSetupV1[2]_RASMANCS

 

~~~ Files

 

~~~ Folders

Successfully deleted: [Folder] "C:\Users\Stephie\appdata\local\cre"
Successfully deleted: [Folder] "C:\Program Files\coupons"
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{00E14B7B-6FA7-434D-BFFC-3E4F6EA77A06}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{01B1105C-C31F-46D9-8508-C33463C6FECB}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{020754FA-D735-4514-A9B5-68B77B29F36E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{023D03D8-DF47-4BAA-9DCA-0104934BB652}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{02D75F6F-3B0B-4206-8632-E726D6A7F6C4}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{02E20812-5583-4AD3-88E8-6C536AA15843}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{02ED5845-4D09-49FD-8734-7A5380575C01}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{032C9F75-966F-4BB3-82F6-0A8EC47634D3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{033F35AC-85F3-4ACF-AF89-134F6FF9B261}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{03E42139-6EF6-4259-A8E6-40F1F04AAD89}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{041CE119-6F49-4C2D-8F4F-8834013D6C24}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{046769E5-3C91-4849-BE36-4B71E2C16688}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{04C90D48-277C-43D1-BCC2-C5AA55722A49}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{04D168E5-6F0C-4BE5-B7D8-BCDB80E48514}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{050EDDCD-C430-4E04-87A4-9E8A18B31DDC}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0557B7FB-A313-49AA-9F70-405E6F1644C5}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{055A0927-4FCD-48A6-9313-2AA1B6188D85}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{05C2DC65-B20A-457F-9766-235AD94FBBC5}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0618CDF3-AA44-47DA-9274-A8AD02A2D024}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{062A6E1E-A598-4A17-BF0A-9D1A4349CA67}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{062EA701-65CC-4082-A51E-13496BFCA5A9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0634E627-9546-48A8-A6C8-6F1FB3B1EB27}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0647DFC7-3B6A-40F0-ABAA-D460B2047F18}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{07452642-360F-4D68-AE28-F0F8E8002B6E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0816FCF5-E1CB-4A07-80C6-DA06BD2F9617}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{084D7775-E29A-4BAB-90A2-9749DD2A4DEE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{087A4117-2EB9-4478-8A50-9A20730C1E40}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{08A43CDE-B290-40D4-8B7C-7F9E0C041E6B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{091AEA76-E657-471F-8467-9B7E4425CD55}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{092D0B83-F8DE-4F96-9B03-A7E7F08E9B07}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{09423A40-4BF2-47EE-B0B2-26B79298171E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{09D99C50-59E6-47AD-A474-F701F87CA5D1}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0A4B5604-3624-4A42-B08C-A37CA90F6245}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0B794A16-8964-49AE-9D3E-5701CEFA821B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0BC2B699-7385-4E78-A9B0-AB9F4EE3ABE8}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0BEBEBCC-7926-4CE3-B504-B3A4A93BB427}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0C14D97C-75FE-4798-A395-F4B265D62B95}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0C25EA60-39F3-4971-8B74-4909FF1E4637}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0C5B9B5F-A202-4B4A-B89F-FEE6A2E729DD}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0CD0BCAA-5DAD-4A8A-B5BF-32187AF17845}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0CDF38B6-8DAB-42D4-A577-5D81B69D3FE7}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0D056CF3-967E-4013-9697-46F5162C45E2}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0D3BE75A-A68A-41DF-9A3A-E86D97C2BB0D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0D5E7F63-94FD-4A2F-AD15-39EE8B058285}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0E145453-1BC9-4A79-939D-DC1FC0BD5D58}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0E22F875-B0A7-4CFD-AFA6-BF7CFD55C6DD}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0ECE551D-59C1-4969-BF73-3050E8CD7D72}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0ED7302F-FA69-4645-90BF-A0D018BA0FB7}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{0F7A85E3-BDA5-486C-925B-ED3FE076931F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{10899877-DA20-4AA0-8586-023FFA3A7AA9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{10CD5C05-12E7-40DC-9C23-5CB8BBB5E9EF}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{1182E2F6-1E38-47A4-B5FA-15666913604B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{11A5F0A2-E031-41B2-9CB1-546F8E6F4ECE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{11B8A9AB-9DFE-456A-8856-1E2C59C49199}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{1205A492-ACA3-4005-94D9-E33998140E30}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{12C89545-250F-4885-AFC9-971AA1936ACB}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{1339091F-0724-4D38-B69E-CE1ED57B1F45}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{13E4F200-226B-4FFC-8FF7-AE204C9F9403}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{14171494-BCAE-4EB5-A3F5-04DBAAD7DD8B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{145139A3-C489-4EDA-B5F4-DDBB7DBBEBFE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{14E5632E-E097-4C5C-AA7E-DF50B0EA5B50}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{15372DDC-D75B-4705-A6D5-6F52F39FD438}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{16145EEC-AF11-4711-967C-8F75F2C742EE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{164C679B-916B-4A44-8DB4-3E680A650ADC}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{16A895A9-C5A1-4FCF-906E-BB82C58939B1}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{17856C42-0912-40C8-89A2-B1DDC39DF33F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{183BAA7B-1F23-420F-AB4D-13BFAB196F80}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{1844B4AF-2B4B-408E-92F1-D69DD25848B2}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{18BF40CC-939D-4405-8506-8DE2AF1EC0F7}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{18DACD6F-260F-4A5C-8951-4C5915BEBFEC}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{18E94A62-9C51-4155-9C57-358F2B2CF003}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{19122681-6B13-42C9-8990-23EAFD1894DC}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{1913B9F1-E17F-493B-AE97-DAB5E682C2DE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{192ACFF1-9EE3-4C2F-8278-1A663225D27A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{1977DB84-B4EE-4792-8178-F2B3223A263D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{1A03275B-5ACB-466E-94A2-37E365AD3B0D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{1A564D98-693E-491C-B570-94768A3972B7}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{1A5D81F1-2B8E-4326-ACCD-518A9662FECE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{1AA57DF5-B08F-4536-BA20-21DDFEE40C6C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{1AFF8A84-360D-477F-BFE9-FC794B56D315}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{1B3C12DE-D777-4E84-8768-267583C69207}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{1B860CD8-C4EA-41E2-ADE0-89F631ED0BA8}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{1B88893F-4856-4E43-A3D8-82351A1C9F7A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{1B93D4E4-7383-4A24-B56E-E4DEFE757DB4}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{1D2F43BF-AB76-4B12-BF8E-9BE816B5EA25}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{1D874819-A33C-411B-9F9D-85F5ECD81205}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{1DA42469-3F42-4BDD-9AC8-639B90A73224}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{1E7CE6E1-3E03-41E4-9636-EE1F04B1D772}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{1F13592D-CDF7-4833-AF78-6D76C75162EE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2010FF24-C5C0-4113-A796-E730F2A9269A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2164D9AD-97C4-4230-9774-E4A18F40B89E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{216B9F17-D92D-4AC7-B30C-52ACBB8037E9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2245645D-6768-475F-A713-9813D6FFA535}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{228D3B15-32B3-461E-AE1A-2433B44F705D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{22BC9EE9-0FDE-4BE8-8A83-A285BF537516}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{22E3093D-148D-433F-B41F-F09A4641925B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{234CC460-1AE1-43E5-B9D4-E7A0CB840F69}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{23A81A95-6638-45A0-BA68-A3566ACC0C5B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{23B42590-D80A-442B-ADA5-E5E84D07C60F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{23B90E71-98BE-4251-BDF5-550771B8D23B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{24D010C1-AE62-44BF-8B38-4AB01F5B2A28}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{255684CE-DF82-4389-9600-950E914ADCCB}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2584C9E7-932B-41B9-84DC-B62BF1CB6BF3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{25A14091-A9BA-4F20-8B61-F4A243399255}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{25AF871D-B1BC-41E6-8D90-4E870EC15137}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{261D1E6E-7B63-4985-9C45-C0D4EB05628E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{266ECA0B-AA5A-4A90-8502-ABD110B0E369}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2689D1F9-738A-4C4A-BDA3-50CFF6AF0535}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{26A0F23B-D1C3-45AB-9F54-998004D77347}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{26AF4DDE-CD51-4FFB-9995-9312F9B8ADCA}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{26EAB3D8-368E-40AC-930E-2F34E1FE5B6C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{27679480-3B75-40A9-8BFA-234E9FC850DE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{28183D30-B781-4068-A4C4-6FC56B5B091F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2835E898-F735-4793-B0B5-186AD14B8D51}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{28FA8ABA-3573-4279-B20A-708A559D76D9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{29A15489-4C89-4FF9-91E7-0E394B230F88}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{29E10D38-9922-4771-B8A6-765E6746F5FB}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2A28F38A-0EA6-4EFE-95BF-6BA92E1EE44D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2A51E94C-C33C-4E59-B224-5C2E1C3ADA7E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2A6B0C09-1DF0-47BA-842C-812523FEB6BE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2A924FB3-921D-46D6-962A-CFAA713C9AB6}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2BDFF391-AC43-49ED-B272-37951C1AE321}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2C1B662B-EEBE-40DF-B235-9A9702593F67}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2C5C12A3-4920-4409-957B-D93F61244F31}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2CC9CE2F-2A75-4EB8-B5E1-1CB66ECDA11B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2D002F76-F167-4B76-A69D-69565006CA45}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2DD6737F-3797-466B-9635-8BE0860C60C8}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2E004CC2-C5F3-4848-ABDD-0DEA2C163BF5}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2E6257A3-E01A-465F-8511-E132359D5AF8}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2EDE22F0-C408-4DEA-A042-8C16FBBCF376}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2F611EB5-3C74-4CE3-A119-515A48760838}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{2F99142D-496A-41B9-A1A4-78B36629FF96}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{303C787D-891F-485E-B6EF-5F700887AFD1}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{307ABB03-3F93-4C9F-9058-EEB6AA9A9E53}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{30AFE971-47A0-495C-B0A1-F80CA7CC0885}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{31BB3E91-1500-4D9C-8F2F-257B427E7F5A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{31C10A1F-CE2C-45EE-9D33-D2247C7643B8}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{31C9FB28-D4DF-449B-9CF5-D565E47213E5}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{323CB396-82ED-4A7A-8A2B-0C9C465E8A50}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3284654F-366F-4C80-9C20-D8F1D4DEADAE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{329459FD-D14C-4816-B670-4F72F7F859C4}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{32A8C97E-B6F8-4784-A7DC-770442A901A3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{32E01863-CC19-4F6A-8D5F-3794E853666A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{32E9F985-FAA6-4F92-BCBA-8030D773AB2A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{33F86275-5FA3-457A-AA93-449F0BCE86B9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3587D52A-140D-4BB7-8E08-1FDB696D0B08}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{35B89EE1-9B6E-4D69-AA9F-BB75016BC480}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3603233D-4C92-4E2A-8C10-3F715F1EC044}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{36C65A0F-6D0F-481B-85AC-A2C60F9BE723}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{36D9A4A3-A55A-4C1A-882D-0F45E15F9B19}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{36EBD766-12D5-4E0D-8BAA-F99B896AEC4A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{36ED615C-07D2-4BB7-9AF5-6FE864460094}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{37E934C3-6FB7-499A-B4F1-9A7BCD5EDDAD}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{38473289-ED98-4611-AA89-12EFEFF53E7C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{38E8A594-5B45-4269-B54E-6033B475676A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{39687D04-8633-48CC-8D96-1061C0EBAA78}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3A394675-ABB2-4237-B619-CDBC70B7E54F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3A5EB7DC-25FC-4FD2-8EBE-CAF7A1C2C581}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3C182BC7-2754-4D47-B77D-9F621C694E18}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3C239D24-00A5-42AB-AEB4-F16722C1757B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3C48C9D5-74B5-4709-A371-CD02B896D717}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3C9E5B18-EC16-461C-B600-F24F2399743D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3CE152DD-0A9C-4D12-88F9-F8CA095E115B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3D2ECABC-884E-4274-885F-BDAC24DBC765}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3D499F22-E840-4AE4-9520-75E31E4E4771}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3D7D9508-3FDD-45D8-9744-D92CC199F6F8}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3D81F920-B043-4D4B-A32D-1B5D8C2A8ED3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3DE41675-29E0-49F8-9941-125783ED6640}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3E1009BF-1B35-478E-867A-A6DD7810E44E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3E409452-2904-4B4D-AD72-30394998661E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3EA428B8-BF1F-4353-916A-3AF6BD61EB58}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3ECDB59A-08B7-4250-A795-E3D9FFFB4366}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3F0878B3-A3CB-4220-9564-08E48432EBF1}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3FC2E01D-5E41-468B-AAC2-F8AFEA7F51A5}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{3FE03AE2-A6BF-4AA9-8CB1-19BE8213CAED}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4028BC63-7FB4-48B4-9217-9E08DE28841A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4033CC89-A7AF-48C1-ABAF-2DD6962C57F6}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4078D152-2303-4C94-8E2B-6B08F9F9011D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{40893B48-9E73-4987-B71A-620C1E35EF57}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{40BCD396-6507-4AFE-AB7C-C5CE8A46702D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4195BC54-A9E5-49A5-B58C-A0582143EB52}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{41A964CD-9B81-4443-B6BA-40C6D258D6AD}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{41FDE362-7F58-4D1E-AE9F-59D3302D5BB0}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{42A88AD5-2EB1-4D82-B46E-17DAB746E688}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{42EAD016-2D4C-48C9-BD33-FD2743A6DE56}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{43272D90-C01E-49EF-943D-8A2F8464C4FF}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{43D6DA7C-79F3-47BA-AE0D-AA3F71473216}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{440BE7C8-88A1-417F-B319-E4ADA2CCB197}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{448ECF8B-0085-4879-BF5C-F044B47858F0}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{457E99B9-1617-4D27-88EC-CC32929DF92C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{459B3285-7D4D-458D-8677-0E8AA73CC23B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{45E50802-2C29-4202-8514-628A1D5F4122}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{463AC23D-F9D9-4648-A5A9-B0564868ADF7}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{46DD2884-61C7-42FB-A0BD-123A035D60C3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{472B7F21-89D4-4501-BC28-E60FD32CEFD1}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{487E1A35-9988-4C32-8E63-6FE81E0CB1C1}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4987FFF5-3EA7-43FA-BA49-F1B53E82824B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{498E7A1D-D90D-4AD7-AFA4-85098BB5C164}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{49D080C0-9541-4A7F-B005-0AE13D9F3538}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{49F7C6DF-11FE-4E8C-B435-0D912101247D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4A469A30-700D-4E4E-BA03-DC8C13E47377}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4A4BC279-AB31-4A3F-80D3-0B1B0C4BDBD3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4AAB1224-E5B6-4879-AEB2-49672F2BBEC2}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4AE562B6-50F3-4D55-A273-C775976D2250}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4B6CCFB2-D8F3-426D-A5FD-F78B5F48F5B3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4B6EE9BA-9894-46B1-8883-4D5F16DD7E55}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4B7486F0-CD60-4F6C-8FF8-7950BB24AF5E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4BD4C900-F501-4500-B193-A1CED8F543BB}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4C30FC7C-9E01-4C74-B41B-8A7150742549}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4C3867EE-21A1-4D0B-9A3F-AA4034C59E5C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4D1F4F63-E3CB-453B-B7FC-22E2C2E7F012}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4D7B49EC-EE80-49EA-91AD-52F14785C813}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4D7CCA60-1A5A-466B-BB4F-BBD35F6887FE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4DD52B2D-4B0E-4FDD-84B3-62E3E5A79DB3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4DF2C3CB-A582-4785-BC79-1390112FF305}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4F0989BF-1C2C-4B4C-B7A3-A79E4E0BDA1E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{4F1400FC-414A-4DAC-88C3-D1C4C232D6B1}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{500A0153-8C74-444D-8587-9C02FBA32D81}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{50126734-6F93-42D2-BF58-FCB98CA686CE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5035B1FF-B4EA-4B9D-A474-14ADBED8BFC3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{503E78DB-86A1-4472-8B9F-DA474BF2E823}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5042455A-B379-4897-8262-28C4BBD2A573}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{50660187-AEB1-4B64-9A7C-55942B2BE251}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{50D30BDD-F683-4E2D-9339-C6E063B7CFC0}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{510CEC8D-762E-4484-A2FD-C3D3A6BB0CB4}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{51FF332F-7F18-4EBA-B671-3677A5A4FC8B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{52191A5C-43C1-4CA1-A3B0-7B3850039D7E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{52352A49-9517-4FD4-B3F1-26E487FA6054}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5246E670-A9CF-4653-8DCA-8699C38057C9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{52FAF976-966A-4488-9449-E3027B0A57D7}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{532364F9-F79C-4A49-B69A-32D5BBD0E4E7}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{53621C9C-388E-4EAE-B3DA-8E96C61C59A1}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{537C9DAA-B5A8-46BC-B0CC-502E583D64C5}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{53A70946-05BE-4257-8940-9445E4D48447}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{53AFB460-3A7E-4378-8F84-B3B69EDB569E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5499D57A-F811-482F-B4EE-68716ABFA527}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{54B73A9E-FD85-428F-92FA-385722A088E2}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{552417AE-E42A-4B1D-B16A-D473C9E5331B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{552EDDEE-32F5-4D73-BCBE-D02ABB580C2F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{56409856-BE3C-4EFF-B9A2-B3EF49BC723A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5669B4CF-E0CA-45DA-8363-9B4BF59D48D3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{568ABF1D-88B0-4038-9EE6-7CFA796490EC}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{56D74776-3397-438C-8284-318C44C34325}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{56EBE48E-8F70-41BF-8C6C-EC90D19AA199}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{571ADC09-F77F-4B29-9ECF-943B63C8AC36}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{573B0C40-4810-463B-865C-9E5E3533A614}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{573C492F-4CB5-40EC-8C9C-69250701DA55}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5786F0FE-9385-423D-8A00-FE0B634C732E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{578C9D52-3866-4A27-A76A-8669C7F043E9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{57ABAEFF-048B-40FD-BEC2-7A8C56C2983E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5885F4F9-2DE1-4B25-994B-F50E1E6D15F1}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5923885C-A682-4A0C-905C-F49B2F981253}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{598E3553-CABE-4189-B7F2-C496482552F3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{59B761F6-DF57-4C1A-9CD4-1CA7BD814757}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5A01DFB7-982B-4854-B338-51FC422B306C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5AC5740E-DB50-470D-9EF7-968C774EFEC5}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5AD338E4-CEDE-44CD-8728-71D749E9DD0C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5B09FF0D-D2B8-4F1A-B7BB-F12EF4D1D27A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5C08D9A7-A4F5-4FFB-A780-B67AAD2EE534}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5C190CA9-A878-4776-B600-3EFFC000EF22}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5C21EA15-E58E-42A5-BAA5-09157567EF7D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5C853869-C3FA-45BC-8F15-439922BC434F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5D23D5E7-8085-456C-BD38-70E177CBAB17}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5DE03860-9DDF-4DDF-8A03-C0A691CF3347}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5FB368DF-2017-488B-919A-9CC171B1577A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5FCF84C4-1330-4B35-A5A6-E7BDBFC71D76}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5FE92D6F-D332-4F1D-9941-0C5A92E00CEE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{5FEF0BB6-5AB0-4B36-8FB5-ED119D756ACE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{60206AF2-5022-4A6E-97BC-8BBD229A35F9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{604C8F65-99E5-4C4E-9771-3A65C19A7D38}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{606F1D3C-01BC-430C-B726-D92A5D533985}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{60B341C9-5ADF-4D0A-AF0B-C6B9AE37C2D9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6130F2B0-DF1C-4917-AD95-8B8F7C4E710C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{617D3352-C73B-4538-B407-8665EEC6E4FD}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6182DFCA-AD0F-416F-85C7-CAB22664ED65}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{61DC02BF-F1D2-4264-ABBE-8CF91FD5AFA7}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{61E526A3-C0CA-4CAC-A8DB-44E0974FCDB1}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{62654396-3E31-476E-911D-66AA29820368}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6368B692-57FE-4C6D-8FFC-AFE1CCC2774B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{640BD4BF-9A17-4C25-A7EE-F3CB78D90F74}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{64AC367C-9F89-40C7-B80E-38A59EAB61B0}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{66318DE0-75F6-44F5-8643-607CDB5F9DA8}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{664ACD4A-BA89-49D0-BB4D-670682B48963}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{665D9A47-17B5-4D1D-9520-2D73AF5889A1}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6666FD5B-2651-4754-816B-E505BDA33EFD}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{666E65FD-B8BC-40F3-AA54-F0504874E7AE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{679CAC0B-1AF3-435A-B3E2-457A92D32F5A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{67CA250D-5EE8-4591-AD90-C479D0F45857}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{687F7F75-8E73-4878-8B0B-859CE02024B1}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{68805497-B1ED-4363-AA57-17B1BE2B9329}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{68CA2AEF-C07F-405D-A04B-9A85CE90EF46}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{69618206-7FF9-4C3D-A19E-9E5DC1BC8EC9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6971D9C7-3BAA-4368-AC1F-9A2F43CADF92}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{69B5C63F-1838-45DB-B6FE-0A9B3983FB21}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6A1C1C42-6552-4A09-B776-518D83E92ED8}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6A4070F2-6475-4B03-A535-0EF7EAD02FE5}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6A7C06D6-6554-46E8-A013-8189CC11FD45}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6AAAB23A-B4C9-4985-95C6-C64C4364F248}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6ABD7084-E9BF-4177-9F7A-3771533C3A4E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6B0C440A-841B-4886-A04A-1842A15616D4}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6B143916-D167-4236-8848-3F1477ED560D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6B6B76BA-82A6-4C14-A712-82EAF16467DB}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6C2842C8-CE5D-4C37-A2E4-3C632DFAFC90}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6C41DC09-1344-40C4-8D3D-B1B7A6F5B41C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6C7EC896-0D7B-416F-A0BC-FD7CB3F62D85}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6C8DFE79-B17B-4EB3-B83C-0A1B0CB1B191}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6C9525E6-9E17-4443-A766-A30B568909E5}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6CFB1011-66B8-445A-BCCE-DE1EC96EF827}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6D24E958-2718-4679-99CF-9732B05E9267}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6E55C111-628C-422D-A932-BAD6115222F2}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6E9C89D3-77B8-4F6B-93D3-E75E8A32C359}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{6F6056A7-83FA-4E40-B8E1-30AF47F05302}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{709E2687-0ADC-4DC2-B91C-6F3D33C6E78E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{711A0F4C-5D45-4A77-BC22-123431ACAE7D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7194F96E-258B-40D1-8625-F74E87B1CCE3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{71A52E27-D79C-46B3-8BCA-ABF0BF696CCD}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{720787BE-C2E3-4580-8BED-A2016167D487}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{728B5511-9AE7-4C96-A215-C0213A080BFD}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{72969CA1-D281-4EFE-AC5B-89C45969B3C9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{72B62197-A2E1-4C48-A53B-EA30687E8632}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{72D2EDBF-209D-4B50-B551-DD6B8AB9A332}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{738296A0-B91C-47E5-B5F7-D6DF83E8DFD0}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{73C93834-57CB-43CA-9497-77635F63D47E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{74299FFD-4E08-46E6-8BE6-A8250626A5E7}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{74BB5A77-04E1-4E9D-936B-BD6F53FDAC4C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{74E29BDA-20BC-438B-B8D6-166A6647622A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{74ECF315-D2C1-4F30-8D08-877F9F6C1C84}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{758EEC5B-B8E5-4BA4-A21A-19FD8C653446}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7595AF09-FC2F-451D-84B2-9E1B79A59EC5}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{75FEB223-C552-430E-973F-5C0AC2A665F0}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7604002A-B744-451B-A1A5-9CEE78C86EBA}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{76AAD8DB-64C3-492A-84F2-164F6429A282}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{76AE4F6B-9F55-47E7-B73E-FCE6A1B1C06E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{76E85FD2-06F8-462A-B1F6-56BC2CE95342}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7721B4A1-F136-46C6-B68E-0BEC492E9A39}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7727256E-A973-4205-B774-599DEA808473}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{775646EB-C150-4756-9B36-C64B398C2968}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7761CD74-097F-4D1B-A830-BA97EEAF9CA4}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{77F944C1-7089-490C-9FCF-D20743B52042}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{77FC055D-CFC1-4053-979D-48C3E8248769}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7806A319-E892-4C07-B499-6559A6697F75}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{785B8954-4FB9-40A3-B5C2-2E13E6F8D765}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{787971E9-66AC-465F-B38E-513ACB10F485}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7890A4BA-85DD-477E-B51A-F4A02F6030C5}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{79153C15-E596-4743-A064-3AF35468E511}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7946493A-224E-47E9-82AD-925F34590BFD}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{79BB5346-F781-4547-A768-15B3D6620F04}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{79C6442C-4EA1-45FD-98A2-C1905460A5E9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7A055B61-E426-4C2F-BFAC-14432F9C7AB0}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7A0A34F8-C7AE-4ABD-AC18-77FFAD9F21DF}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7AB086B6-B292-4C63-8BA9-760CB42E61BE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7AB1B271-4B8B-454F-A309-4E4287648B1E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7B32A26C-F5C0-4DEC-9D32-55CD99CDF456}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7B9CC68C-BEE3-4DDF-96F7-C1EA76C1E481}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7BC5EE54-F55C-4EAC-8813-EBF78F88A459}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7BD40378-09B0-4301-AEA2-83AF065E1A42}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7BF3B3A3-4479-412C-8582-B68BB24C4A98}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7C64E063-1897-496C-87E6-1121F07C1285}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7C9D9C81-963A-46FA-84B7-5C04FE5D69C9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7D4D8889-AE25-4F51-B9EF-302A0AB24389}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7E3E008F-BE5D-48A3-A0D5-48ED07C7D1F6}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7E47E1D3-4E90-4D1E-B096-34B6CDD5C42B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7E99F9BC-1E65-405F-9C17-EBDC647AA5F4}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7F184817-0C4A-4556-8068-71B2FB98663F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{7FB606F3-C9BA-4354-BD3F-979B671BD3A4}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{81E4183A-EA37-4F02-9081-AAFC6D0A7E57}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{81FEDCFA-65CB-4451-A09B-DEDB3BB8C39D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8259BA09-26D4-41EE-BAAE-67545DF5042C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{82A522CD-D421-4C4E-BC96-E2A22DBA7232}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{82AB7D21-D9ED-4E07-8E7E-199396807406}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{82B484EA-E995-4093-BA2D-C25F9C522FD1}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8311474C-2089-48F4-ADFB-3B7EE2A35C96}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8335C6CF-3484-4771-8CE6-AA7C2D1573BF}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{837D7429-1540-478E-962E-641C003FD101}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{83FA90B1-70FE-4638-9CE5-99379C904815}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{84268D3D-F9B0-4294-8DE8-2FE3971C38F3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8490A336-8380-4D24-91EE-FEB5476A669C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{859B5220-7F69-4A22-BF53-C0A2FCF41583}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8623F9CA-0302-4B43-9FA4-72B2843748B9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8663B517-6B08-4913-9349-99D3C89DA97C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{86E89C21-5DA7-4521-885F-94B3C29827B3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{870DC8A7-A7EA-4B4B-8732-04F672567631}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{877BE6A0-D035-4DE9-8DAD-D893C311277F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8786541F-2987-4EDD-9977-3A79A5F859A7}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8838CC7C-ED36-46D3-9E59-3846A9B6C6C6}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8843553D-18B2-49C0-96B5-E3F2EB6D34A1}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8872DD51-AAB0-4F45-A5C5-0AC7DE6D007E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{888E546A-F8B3-4AC9-B1A7-67FCA84B92BF}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{88D0A737-D4D4-4131-AAFA-5A7060D76C2F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{88D68F4D-43C0-4819-AF6F-14F53FC4E4D6}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{896917A4-12B6-43EB-A5FD-68188FE51322}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8989C736-B6B1-4390-80C7-6D92C2357937}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{89C29D76-9E10-4A15-B891-FE495DD1AC02}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{89F5F69A-1043-469D-B00E-58BF034293F9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8A79BAC2-8BBC-4792-8DBE-DED91434263D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8A9AC9EE-4F74-4697-83B1-E2509E27D317}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8B68E84C-19C8-417F-9020-275ED247DDB2}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8B75DF43-A660-4427-A0CE-A49FD52EADDE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8B8AEEDC-30ED-4297-8A55-D315E14F2C7F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8BF950D4-B74F-4CA3-AB83-22B7F7818A81}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8C855077-3CA3-44CC-B252-B602CA911C8F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8CF15CA8-DE6A-4E65-B8B9-A59B283765D4}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8D3B7BF4-5B43-4B7A-A297-3FDB1FC05E49}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8D6A7C23-E31D-4E28-B1BB-EBC2213C7EB0}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8D722D46-179D-40AA-BA7A-8C648B71D97A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8DD1F089-81EF-4BEE-8756-254BC7A88BEE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8DE69AF0-4136-486A-ADD0-3B90139F0592}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8E075697-AACA-4981-AED4-DE06C301707F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8E6FA459-3871-4522-B3BB-78F1A569C060}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8E903627-D182-4D0F-8F23-BF6B28C3628D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{8F2C4C18-6226-4775-AEB3-A2AE285B02A2}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{903D2694-4F83-429F-8F8E-98E56E920E32}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{909726E4-AE6D-4E47-B9E5-62CEA7837762}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{90F8ECBA-08D4-4E92-ACCA-CBC9923A3A3A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{912A6F02-AD08-4B27-8BAD-4F128E3D3141}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9157145B-6DA5-4784-9C8E-27964C71DE73}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{927DEDCC-A48D-45BC-8694-2F424A026875}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{929C7710-F2AB-4C38-9EEA-B01F1F1E294C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{92BFDA34-AF3F-4BFB-93D6-A536CDFA4558}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{93183FEB-B491-47DB-BD2B-65FC2F6663C6}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{93324FF4-DDA2-4F41-AA21-0DAC7D6FFF55}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9363B7EF-0DB0-4E0A-898E-2E411073665F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{939EBC51-1C79-43FD-A39E-C1BF1ED80B3A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{93A23C79-E615-4A88-88DB-7AF3F0BF6853}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{93B02FD5-A895-44DC-8E81-03B7C68C12BD}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{93C6555A-5614-4412-AC5A-941F57F7E75E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{940DA111-54CE-4438-8006-7D3439543E45}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{944CDF44-637F-4707-A640-793B22DF3963}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{945876C8-E088-4265-9E3E-52FCBB8B2F39}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{94932A80-F5D1-49F9-95B8-712B817152B1}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{94A20654-1AF2-477C-9B26-EB5093AB62FB}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{95344E8D-7CBD-4EF3-8936-E20604DF5259}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9538DDE1-B110-4F03-881D-22EC0E7926FB}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{954FA0A4-5CBA-438F-B8CC-90A8B6BCE198}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{95663FE1-84FB-44EA-9FD9-529985E1D43E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9573D676-3F83-49ED-8956-1E6778220553}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9647F912-3390-44B1-B74F-87437EB6F6D5}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{965B3DB9-3869-4C04-AE65-4F5181AC2B45}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{967A7EE4-38CD-45D2-A23E-060E76DEFAEB}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{974EAED6-A83E-4941-80FD-579C9C8D1BDC}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{97B10704-129D-483B-90AD-6A3E8918D057}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{97C5939C-FFCA-4B00-8627-1562389E6235}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{97F9BB1F-E0FC-4FD6-A8AC-CD20579464EB}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{981F35F5-F31B-4623-BEC4-3518BCF9C703}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{99A0E64E-E774-4F58-B29F-22865A67E6A6}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9A0911FB-65F8-47A2-A143-066004E21B0C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9A41CBC9-BEBF-41C8-A89E-7C507E9F11E3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9A825BFA-CFCD-4993-BE8F-FB4171BB17AA}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9AD12E70-085A-4D9C-AC1A-42285A61C87D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9B0245DD-BFBD-4A26-ADB0-F9E29E8F1DAB}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9B405639-854C-4FB0-A5F9-FC50301CEE24}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9BF218E3-A163-46DE-9B25-B91D7A1D5CBC}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9C3C09A2-28DD-43A5-8B66-FA0F6DE5ECE9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9C63137A-7B26-4A11-8140-CBC5757097CB}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9C7C06D4-46FC-42DE-9B6F-5420D1951D1B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9D134383-EEBF-4F43-A4C9-A46F4AF65B3F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9D1BC91A-805D-4901-969B-E6A63C6703CF}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9E03B08F-597E-43C6-B0DB-074AE4371CE3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9E3C2667-8FAB-4BA3-84E9-1D748D91B109}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9E6F9398-ABBC-43F9-86F3-5F06F01494E6}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9F3A03ED-9688-42CE-A8B2-913159E1E647}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9F74AE01-18C0-41F6-BBA2-4FEF4D57BEBB}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{9F98F7D4-503D-4546-B3A7-9803F3B3F12B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{A0CEC9CE-E48B-452A-81D2-33FADEE3B139}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{A194B512-9D53-4B90-A6BC-191586B06858}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{A2F1AE61-5968-4F2B-8B0A-2A9D82709E6C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{A3337ECC-5340-4256-A4C1-4D0D099B0BEC}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{A3515806-4337-4BB3-B943-0B7CDE907BD0}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{A3A2E6B8-972D-4062-A748-4EE1916DB5ED}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{A5075D7A-CDA8-4AB2-907A-8FA5E6D726C0}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{A6623738-8610-46F3-9AC3-1F8B8EEFDED6}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{A71B44D5-548D-4CAA-AFA0-FD26F4D7DC89}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{A7BD0A31-6B8C-4A8B-A1F2-EA1651C97F9C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{A7DF06AA-4A93-4B60-AC7B-149112DA1E42}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{A80DF813-B154-41AD-ABCB-1B4EF5B4D0B8}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{A8345DDA-F882-4DDC-8110-DA2F69D180C9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{A83A204F-ED66-4463-92C4-44E76462B27A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{A8504866-19AE-4D09-AEE2-16491FE4AB66}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{A9B452C0-0032-4BDF-9802-832047DF2737}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{A9F02462-976F-452E-9F9A-FADB0EACCCAF}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{AA8960C1-3DF5-4DFB-893F-3F1A72275EC1}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{AAC3050B-E27C-48FE-A6FE-2CC23E39348E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{AB1136F7-25FE-44D8-B726-D07CDB5E6C14}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{ABAF724E-F279-4AE8-8C51-3D0A534DABA9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{AC426586-7A19-4A2C-AA5D-54BF651392EE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{AD08C779-858D-46C2-858F-12746887A815}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{AD648F41-AEAD-46D4-A761-548AC88D7DB7}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{AD7842CD-A799-4396-8C8F-36D45C7AA38D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{ADE1AF25-AA56-442D-914D-443BFA002258}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{AE14546A-55BE-494E-991D-BA281B0D253F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{AF293028-4E1D-4C9E-8639-AC8F280882DD}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{AFA1945B-5026-4E4A-91B3-6D06147DC770}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{AFFC2314-061A-489B-B0FB-90998FAFFB4C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{B0127B51-7611-4FBD-A194-CB929B293C96}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{B0EC3C55-3FD8-4193-828A-C54926AC19A2}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{B0FE51A8-94C9-4F4C-8A59-45D8F064A52A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{B13FB6C1-E01D-4739-845F-8BAC738BC1E5}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{B18C96B3-0444-4416-A984-3585871C4922}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{B1A1C4D9-E910-446F-9B8B-51A8656DDC25}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{B1E64F3C-34EC-4ABB-B11B-33E0B838D990}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{B3DDE927-1A30-4BE6-9C30-0A118D3019C2}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{B47F484C-3933-4EA2-B7D0-A24C19765A92}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{B4DA1CCE-EC87-4D0C-A6DB-D3E96B866878}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{B4EB09F3-8F4E-4224-85FE-981DAC24DF5F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{B54AE42E-03BC-45C3-942E-CAE525D85CBE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{B5517E8A-1EB8-4A24-A3D0-C6685968D2ED}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{B670282B-B609-49B1-B315-70A1596483CE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{B76A591E-5929-409E-ADF7-56C4F28A7D61}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{B7C31C6A-6353-43A9-B5E4-C6C8AEA05024}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{B86249E2-E100-493C-9358-0A49AF0439C1}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{B879971E-B62E-409A-BDD9-4FCEB42ABFCA}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{B8948FE9-4CAF-4E61-A771-C129840B3A17}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{B997F9A1-095E-4AB7-86ED-EF7398BEA499}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{BA9BD3E9-0A3C-48E4-A7B5-721028D1F1E8}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{BACCB244-A83C-4816-8152-EB8C933C6212}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{BAE0DB73-3088-4F4C-85B8-FBF86269CA08}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{BBAAC744-525E-4B45-A516-09A29D6E70FB}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{BBB3ED1B-05A6-4B5F-92C0-A5288562FD4C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{BC3B0A2A-DD4D-45D0-A1D6-65C464333255}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{BD270D55-16E0-41BD-A0F0-17161C094BC1}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{BD4D9C23-1DBD-4A44-A44C-62B00BD352B8}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{BD6FB093-6882-4AA5-B480-E591CE41F06C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{BDD0524C-63DF-4840-B9AF-112463778EAD}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{BDF2F760-4219-45A9-A6D8-091EA2B910A0}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{BE744B23-1FE9-4000-A152-AB1589915A1E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{BF0718B1-D81F-45E8-889B-ACF5F597CE5C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{BF5DFF08-DB7A-45FF-B421-D197B04B95EA}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{BFBA975F-2680-44A9-93C6-E526EB311584}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{BFBE4C12-E082-4965-A241-211840B253E6}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C002649D-00B5-4EE0-B200-C7610F3C0390}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C03CEE76-82AE-4B87-B3F0-002EF7AEEE0C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C0631861-0888-4C0C-AC2B-3631CD998124}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C080C991-392F-460A-BF73-D6F050149EE6}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C0C35B61-884B-4477-9FB6-F4DE3F98D704}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C0F427FA-AED9-43E6-80B6-8358FDDF231A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C1B7E295-D697-42B1-92D3-CCB157D47731}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C1E2E03C-37C0-4EE1-9407-F8967732CD16}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C25E7079-C6BC-4555-8F63-6B7A09E87BC3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C276B3C1-10AF-4815-8867-10806F3316DA}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C2C991BC-C0F0-4208-9095-D98E5953229A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C2E7366B-8A3C-4436-A9A2-48CED70A2BA0}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C360D99C-D16F-43DE-996B-98C1BF472B8A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C3A2070B-318C-4429-983E-0999B4084092}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C40CFD45-218A-4894-8EE8-FCF797B9D60B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C4AF6F6E-2760-4D2D-8482-FC7391699242}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C5409F37-B365-4104-BC44-2534F97064FF}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C584DC9D-54A9-4659-A102-7E26966A0ED3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C5D07734-F4DF-42B4-8052-D47DEE158EBE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C667BD54-F6D8-4DEE-B7E5-DE10A2C1DF67}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C690C87B-F3E5-4CEF-8C59-6BD38B02D158}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C6E90200-1B10-4678-91AB-AA72E9859FD2}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C7163EF3-E614-4CD3-B9B1-67D682F2C90A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C734CABA-D2A2-420E-B62B-1550BEB23D00}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C7ED5B5E-F0C7-4880-ABDF-4BE85FD6DABE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C81A53A2-41F4-482A-9C16-B443F671841E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C84EDC6E-94EC-47B2-88BA-691ED7C8782E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C87D16FE-D26E-463B-A24F-33B2C0964A71}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C8B32ABA-F033-4A6D-B2D8-F36A941813A3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C8B622E9-57A5-4235-A124-F623CD6D5CB7}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C8C1CBFB-6E73-4857-8FD5-3B4DA5AECAE0}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C8FF161D-996B-4224-A001-DD1B7CDD4DC3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C985E50B-AD1B-4558-9EDC-E074BE926A8B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C988460E-F05A-4BB2-97AD-265A8927E26C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{C9B1754D-D2A7-4F44-95D2-33E0CBB7FB56}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{CA0BCB3F-3309-4231-90EC-07592EA44291}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{CA50094F-3D58-40A2-BF44-32B1C12477CE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{CB3B4C09-84BC-4A5A-87B4-E9653C33E578}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{CBD69C9C-30E5-4BD9-872E-88223F3194CF}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{CC10E60F-41CE-4381-AC56-7CDFC7016517}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{CCE1DB42-DDE8-4260-8466-B3941E5F514A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{CD87E642-C2FE-4DEF-90C5-C88C1C6CCDCD}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{CD8E7B8E-6602-4265-AD5B-C3758F402683}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{CDFE9A29-4B70-4326-8779-BD74CDA5C837}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{CE65975B-1DE3-49DE-B5AC-E17957427105}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{CE86C32B-7EE6-4DC8-8DC0-7882C54B7143}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{CED8D2BF-AC1A-42EE-8ABA-FF6FA02E1820}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{CF0391B1-35C1-45B5-883D-927FBD3C81DC}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{CF1190C8-71D4-412E-B31B-F75987588A23}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{CF9549C1-CED7-4143-810C-C6B78799752F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D0879ED8-AFC2-4320-B23A-1288C7D7BE4B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D0C38CCA-F5A6-432B-9F6C-96EDD819E989}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D0E26141-9F1C-4D8F-BE59-2C913D2B4F5D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D176B6E0-9756-4725-92E7-650A8FAC0B9D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D1C56194-FCE9-4E9F-A13E-D592E22AC576}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D2F85B47-D569-4B51-9D8F-98D4DCBA7C46}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D359192B-1F10-4B65-9D59-E4EE2442B07E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D38E0843-7922-4C7E-9603-8E2FB165830F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D4065049-0703-4C67-B666-BB3648221066}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D42D1F6F-3A35-434A-A519-5209C6ACAD8F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D47508C1-5993-4C10-A8E2-AA0A3E624A5C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D4C666DF-51EF-4B3A-AACA-5A510417EA0A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D4DF17FF-647E-4A5F-BDBC-CC47ACBA0D9A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D4FB7EBF-CACF-459C-A5D5-1ADEEA642E89}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D51DDC73-32E2-4131-9680-E6799678FA37}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D5315E8A-2274-42D3-8FB2-43C06F3851FE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D536AB41-BDE5-4223-96A9-2EF8B6A3CFE4}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D55465C9-D38D-4EB6-834F-FA05EB6FEC81}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D5676955-113D-4302-A3AB-F104C1E7301B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D59993A6-79B9-4FE5-A702-E2F680CA7C9E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D59CE564-950B-47DB-B635-33E47499CA98}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D61E91E8-6FC3-44A2-B861-23322644E5E2}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D65D4B49-6765-478D-8CB2-D9E042D9050E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D70041C0-C701-4A1F-A2E2-55A21046D723}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D7639CB0-EBA7-47C6-AFE2-3793DA7C6622}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D7EFAA24-9946-4777-8B14-8049A2803F14}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D8F31A30-7D7F-4CB9-8009-DB4A80F56732}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D95E10E4-83E9-4EF3-9B13-F0D339E785B1}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D979E238-7CA1-49F7-BB70-BFE5234D3310}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D9812C99-D551-4424-BCA2-2EE539E71246}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{D98EA97D-E024-4489-84A9-7D09255A58BB}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{DA0934A6-ED8C-4C89-B4BA-7B2B40937E88}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{DA51FE40-33D1-49B3-957C-D440928535F0}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{DB46DDF9-34F6-455E-9DF2-34398D9FDCD8}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{DBE36EB3-5854-4505-9C94-9359C51E3EC2}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{DC2F7F26-CC8D-4A0F-916C-49760123C599}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{DC33E714-2596-4249-9DB8-00507F8E19FC}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{DC3B1B7A-3EE2-4E87-B398-A042513FA775}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{DCCB255A-9369-4B98-89AD-DEBCC8B70BD3}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{DCDB3AFC-E2B3-49E2-850C-F204A3C01846}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{DCE22005-D0CB-45CD-8E1A-21662ACB02B4}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{DE125209-F1B9-420A-BD72-490902398B52}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{DF0A7525-6366-4A6B-B628-C801F2D367FF}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{DF6201FD-4DE2-47E6-BE69-C962AF8ED9F9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{DF7D9AC9-06A7-4762-9B23-7B9D1A5E776D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E0174521-A7F9-4880-A00C-BAD9E57BF346}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E0308459-24AA-493E-A5CF-F5FBE2E7921B}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E050DD6F-DA12-49DF-8439-8E5EA922075D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E0BCBD38-BA79-402B-930B-D998CE6A1365}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E10206CF-CF56-4007-8A49-B0E80D3421DF}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E13E9037-7CCF-43AA-8FC0-DA2B9E675975}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E1F49315-B4D6-41E5-A37B-F1BF0D0D0A54}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E244CFCB-AEB6-4CAA-A4C4-13992DCF712F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E28BEF06-B6A4-4CB6-A562-BAE20DEA2881}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E30D2E98-CC14-40EF-892C-7348672F4B92}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E3452937-734A-4B23-80BF-B54C047A567D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E362C665-8BB4-47EB-8120-3AEF5EC562E4}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E37440CD-92B0-4C7A-983D-34DACE648DB8}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E3C5EE43-E792-4E95-ABF5-03AABD3D9F9A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E3E7A1F3-FD4A-46E4-B2C4-527820A745DB}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E42C710E-D829-4126-923A-2859FC3C1F4C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E439D966-284B-4E3A-B5B3-4533DCEAD373}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E53ADA7F-3266-458F-9FB0-148FA7D30531}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E540DE32-731F-4EFC-8023-6728488636B6}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E62C19A6-1708-44E3-A30C-F06DA226B267}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E65F776F-F37D-40CE-9DEE-0150BAC08DBA}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E6841D80-11B9-42CE-B9D2-50E574598887}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E6B9C89C-D730-4337-AFEC-E90329CB17B2}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E6DFFB8F-AB2D-4011-941D-7166FB5BC97E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E72F513A-99CF-4F38-864A-C54F1527E81A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E837A8A8-448F-4560-BD8C-8BA2A6ABBF05}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E8482C5D-83A0-4F03-97D0-3FF577BA701E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E94E7555-32C2-4A2F-B661-15C3479E0557}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E98E7E5A-D26F-46D6-9357-8F09F9C090ED}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E99CB7C2-84A2-48EE-8D50-EA32E1E9368F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{E9C5A868-E7F5-4059-BA8C-77FC820949B8}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{EA04E706-F73C-41B6-AE5E-794B4D3EDA1A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{EA08F7EA-1EC8-438A-AF1E-472C0E104EFF}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{EAA5F687-3C96-4E7A-9533-F1A249530B05}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{EBB9B8ED-3B1B-4420-9694-93E86C1B4B55}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{EC84B015-FAE3-458C-8315-1830023ACBA1}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{ECB6F7E0-91AD-43F9-9385-46B89DA0B7E9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{EDA0A7F4-1A06-49EC-8FF1-E964E36191C5}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{EDCD0AB4-FC4B-4284-B299-0A94BA73A8AC}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{EE721E58-5996-4E40-9E21-2930DA1E004A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{EE94E912-5C3C-4988-B285-D348E1AE4155}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{EE97EBF2-62E7-471F-8538-3F8274A4BCC8}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{EF6E958D-52D1-4E79-925C-3D5FB65B07E9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F05248B7-0ED7-481A-A850-F699246FE674}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F1877C67-698E-4CB7-B79E-B584E9324CAA}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F1DA0C52-392A-40AC-B060-AE2B524748DA}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F2895B99-E020-4117-BB7B-DF0EDC1C2079}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F2FB6AB7-223D-4F90-A930-B9D225D43438}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F399C25C-29C8-4249-AA49-45F135D62F65}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F4F4B6E4-1F30-4CAA-B199-16C3888C1F25}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F51AACD1-5474-427E-9B0A-62D7BEA3C898}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F520CBA2-D295-44EC-97FF-1E9C95B201E9}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F544C5FC-79BF-4584-A102-8457154626D6}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F5A0B2CC-D314-4E76-AA0E-BEAADBB60EA2}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F61F0E06-B64F-470A-95BA-0D388DF5DED5}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F6287078-634C-4886-ADC3-A8A48674C03F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F63F4A9E-E5BB-47DA-8A77-175022D4A52C}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F64A84F4-EE08-40F4-909A-6821DEE8496F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F672014C-E869-4A89-81F6-72311B5EAA4E}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F6B8D9DE-E752-44F3-9B9E-A6C93CC4A022}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F6B97592-DC3C-4983-932A-288DB82CB3A6}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F6BAE26A-E49B-4F57-B867-2E53A8227D78}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F6F84CE5-102E-477D-B09B-94940FEE43FC}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F73732C6-6E2A-438E-A1D0-78B94292902A}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F8815457-81D9-4493-A807-8321EDC745AB}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F8B390D4-B714-45DA-A7FB-129C17779218}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F90E5BAA-9924-43EE-B4AB-547F466B55FB}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F94554FD-9922-40C6-B6A2-26773978BCFE}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{F95FD47E-93F9-4E16-8ECB-A6FE06EB766F}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{FA66E5CD-0B8E-4A8B-8B0E-7FD801449416}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{FA86A3A8-FA98-415A-AA6D-A0722DBEEDF6}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{FB8A36B0-CB46-45A8-A8E6-864F34FAC462}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{FCB10002-0D3B-4B5E-B6C6-7081BC88CAE5}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{FCB5FE46-510E-4C1E-9240-47E6D6455965}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{FCF04FAA-DE01-4AE2-A6C6-5CBB369CE7AD}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{FDCAF74C-0E68-45F9-AFE2-92F9993A84C7}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{FE1EDF0F-C9A0-410A-863D-629896E04A1D}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{FE3F46EB-C592-4B18-83E9-4B248B4C7056}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{FE4D9007-E435-4DED-84A8-61CE82CA9593}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{FEC03578-1454-46C9-A2E7-D1788923DF70}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{FF51BC40-A61D-4E54-91F9-BD320BBC0D27}
Successfully deleted: [Empty Folder] C:\Users\Stephie\appdata\local\{FFA67046-2085-43A8-8A40-83B0087D4499}

 

~~~ Event Viewer Logs were cleared

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Fri 03/28/2014 at 13:45:47.36
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

OTL Quick Scan Log :

OTL logfile created on: 3/28/2014 1:46:39 PM - Run 2
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Stephie\Desktop
 Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16521)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
2.87 Gb Total Physical Memory | 1.86 Gb Available Physical Memory | 64.87% Memory free
5.74 Gb Paging File | 4.59 Gb Available in Paging File | 79.92% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 224.17 Gb Total Space | 78.05 Gb Free Space | 34.82% Space Free | Partition Type: NTFS
 
Computer Name: STEPHIESLIFE | User Name: Stephie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/03/28 13:37:43 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Stephie\Desktop\OTL.exe
PRC - [2013/10/23 16:01:10 | 000,022,208 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2013/10/23 15:55:28 | 000,948,440 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2013/06/25 21:48:08 | 000,228,552 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
PRC - [2013/05/14 14:26:12 | 003,289,208 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012/11/22 22:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2011/11/30 05:26:26 | 000,393,640 | ---- | M] () -- C:\VTech\DownloadManager\System\AgentMonitor.exe
PRC - [2011/11/12 13:04:12 | 000,268,640 | ---- | M] (LeapFrog Enterprises, Inc.) -- C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
PRC - [2011/11/12 12:21:58 | 006,141,792 | ---- | M] (LeapFrog Enterprises, Inc.) -- C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
PRC - [2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/08/14 20:19:44 | 000,326,192 | ---- | M] (VMware, Inc.) -- C:\Windows\System32\vmnetdhcp.exe
PRC - [2009/08/14 20:19:30 | 000,399,920 | ---- | M] (VMware, Inc.) -- C:\Windows\System32\vmnat.exe
PRC - [2009/08/14 20:19:24 | 000,113,200 | ---- | M] (VMware, Inc.) -- C:\Program Files\VMware\VMware Player\vmware-authd.exe
PRC - [2009/08/14 20:19:10 | 000,064,048 | ---- | M] (VMware, Inc.) -- C:\Program Files\VMware\VMware Player\hqtray.exe
PRC - [2009/07/13 21:14:46 | 000,115,200 | ---- | M] () -- \\?\C:\Windows\System32\wbem\WMIADAP.EXE
PRC - [2009/04/01 18:11:06 | 001,283,384 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe
PRC - [2009/04/01 18:10:58 | 000,062,776 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe
PRC - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/07/19 00:39:30 | 000,083,312 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
PRC - [2008/06/02 17:26:48 | 000,505,720 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\SmoothView\SmoothView.exe
PRC - [2008/05/09 15:49:30 | 000,716,800 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
PRC - [2008/05/08 14:11:58 | 004,787,712 | ---- | M] () -- C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
PRC - [2008/04/29 14:33:28 | 000,417,792 | ---- | M] (Chicony) -- C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
PRC - [2008/04/24 22:35:46 | 000,073,728 | ---- | M] (Toshiba) -- C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe
PRC - [2008/04/24 13:26:18 | 000,202,560 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
PRC - [2008/04/24 13:25:22 | 000,202,560 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
PRC - [2008/04/17 03:19:48 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
PRC - [2008/04/15 21:54:42 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/04/15 21:54:40 | 000,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/04/08 19:14:50 | 006,037,504 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2008/02/06 17:52:52 | 000,431,456 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
PRC - [2008/02/06 17:52:40 | 000,431,456 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
PRC - [2007/12/03 21:03:52 | 000,126,976 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\Toshiba\SMARTLogService\TosIPCSrv.exe
PRC - [2007/11/21 21:23:32 | 000,129,632 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\TODDSrv.exe
PRC - [2006/08/23 19:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/02/14 19:56:29 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\8bc548587e91ecf0552a40e47bbf99cc\System.Windows.Forms.ni.dll
MOD - [2014/02/14 19:56:20 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5c24d3b0041ebf4f48a93615b9fa3de9\System.Drawing.ni.dll
MOD - [2014/02/14 19:55:50 | 005,464,064 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\2c9156c92877b8f46960da931124f422\System.Xml.ni.dll
MOD - [2014/02/14 19:55:43 | 000,978,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\5b6ddf934128d538cd5cd77bf4209b93\System.Configuration.ni.dll
MOD - [2014/02/14 19:55:41 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\b3a78269847005365001c33870cd121f\System.ni.dll
MOD - [2014/02/14 19:55:29 | 011,499,520 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ede2c6c842840e009f01bcc74fa4c457\mscorlib.ni.dll
MOD - [2011/11/30 05:26:26 | 000,393,640 | ---- | M] () -- C:\VTech\DownloadManager\System\AgentMonitor.exe
MOD - [2011/10/26 18:57:39 | 008,007,680 | ---- | M] () -- C:\Windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll
MOD - [2011/09/14 10:19:06 | 008,500,224 | ---- | M] () -- C:\Program Files\LeapFrog\LeapFrog Connect\QtGui4.dll
MOD - [2011/09/14 10:19:06 | 002,348,544 | ---- | M] () -- C:\Program Files\LeapFrog\LeapFrog Connect\QtCore4.dll
MOD - [2010/11/11 05:24:31 | 000,028,160 | ---- | M] () -- C:\VTech\DownloadManager\System\DACommCenter.dll
MOD - [2010/07/13 09:07:23 | 007,826,432 | ---- | M] () -- C:\VTech\DownloadManager\System\QtGui4.dll
MOD - [2010/07/05 05:19:39 | 000,116,736 | ---- | M] () -- C:\VTech\DownloadManager\System\QtSolutions_SOAP-2.7.dll
MOD - [2010/06/23 21:16:19 | 002,150,400 | ---- | M] () -- C:\VTech\DownloadManager\System\QtCore4.dll
MOD - [2010/06/02 01:05:40 | 000,119,808 | ---- | M] () -- C:\VTech\DownloadManager\System\imageformats\qjpeg4.dll
MOD - [2010/06/02 00:38:06 | 009,837,568 | ---- | M] () -- C:\VTech\DownloadManager\System\QtWebKit4.dll
MOD - [2010/06/01 22:56:04 | 000,232,960 | ---- | M] () -- C:\VTech\DownloadManager\System\phonon4.dll
MOD - [2010/06/01 22:54:24 | 002,530,816 | ---- | M] () -- C:\VTech\DownloadManager\System\QtXmlPatterns4.dll
MOD - [2010/06/01 22:29:22 | 000,934,912 | ---- | M] () -- C:\VTech\DownloadManager\System\QtNetwork4.dll
MOD - [2010/06/01 22:28:00 | 000,335,360 | ---- | M] () -- C:\VTech\DownloadManager\System\QtXml4.dll
MOD - [2010/06/01 10:17:46 | 000,929,792 | ---- | M] () -- C:\Program Files\Yahoo!\Messenger\yui.dll
MOD - [2009/08/30 22:14:16 | 003,571,200 | ---- | M] () -- C:\Program Files\Combined Community Codec Pack\Filters\FFDShow\ffdshow.ax
MOD - [2009/08/14 20:20:28 | 000,068,656 | ---- | M] () -- C:\Program Files\VMware\VMware Player\zlib1.dll
MOD - [2009/08/14 20:19:38 | 000,970,288 | ---- | M] () -- C:\Program Files\VMware\VMware Player\libxml2.dll
MOD - [2008/05/08 14:11:58 | 004,787,712 | ---- | M] () -- C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
MOD - [2008/03/06 14:14:54 | 005,121,912 | ---- | M] () -- C:\Program Files\Toshiba\FlashCards\BlackPng.dll
MOD - [2007/12/25 16:03:40 | 000,015,184 | ---- | M] () -- C:\Program Files\Toshiba\PCDiag\NotifyPCD.dll
MOD - [2006/12/01 21:55:42 | 000,009,216 | ---- | M] () -- C:\Program Files\Toshiba\TBS\NotifyTBS.dll
MOD - [2006/10/10 14:44:16 | 000,009,728 | ---- | M] () -- C:\Program Files\Toshiba\TOSHIBA Assist\NotifyX.dll
MOD - [2006/10/07 14:57:04 | 000,053,248 | ---- | M] () -- C:\Program Files\Toshiba\TOSHIBA Disc Creator\NotifyTDC.dll
 
 
========== Services (SafeList) ==========
 
SRV - File not found [Auto | Stopped] -- C:\Combo\PEV.cfxxe EXEC /i C:\Combo\HIDEC.exe C:\Combo\SWREG.EXE ACL HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep /RESET /Q -- (PEVSystemStart)
SRV - File not found [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_HelperSvc.exe -- (getPlus®
SRV - [2014/03/14 14:29:13 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/02/28 23:38:23 | 000,108,032 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV - [2014/01/29 22:05:28 | 000,227,904 | ---- | M] (WildTangent) [On_Demand | Stopped] -- C:\Program Files\WildTangent Games\App\GamesAppIntegrationService.exe -- (GamesAppIntegrationService)
SRV - [2013/10/23 16:01:10 | 000,280,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2013/10/23 16:01:10 | 000,022,208 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2013/10/23 09:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/05/27 00:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2013/05/14 14:26:12 | 003,289,208 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2011/11/12 12:21:58 | 006,141,792 | ---- | M] (LeapFrog Enterprises, Inc.) [Auto | Running] -- C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe -- (LeapFrog Connect Device Service)
SRV - [2010/10/12 13:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010/06/02 14:34:58 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2009/08/14 20:19:44 | 000,326,192 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\System32\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2009/08/14 20:19:30 | 000,399,920 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\System32\vmnat.exe -- (VMware NAT Service)
SRV - [2009/08/14 20:19:24 | 000,113,200 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files\VMware\VMware Player\vmware-authd.exe -- (VMAuthdService)
SRV - [2009/07/13 21:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/06/05 20:07:28 | 000,250,616 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2009/04/01 18:10:58 | 000,062,776 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV - [2008/12/01 11:49:02 | 000,191,024 | ---- | M] (VMware, Inc.) [On_Demand | Stopped] -- C:\Program Files\VMware\VMware Player\vmware-ufad.exe -- (ufad-ws60)
SRV - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/07/19 00:39:30 | 000,083,312 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe -- (TNaviSrv)
SRV - [2008/04/24 22:35:46 | 000,073,728 | ---- | M] (Toshiba) [On_Demand | Running] -- C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe -- (SmartFaceVWatchSrv)
SRV - [2008/04/24 13:26:18 | 000,202,560 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe -- (sprtsvc_ddoctorv2)
SRV - [2008/04/17 03:19:48 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
SRV - [2008/04/16 19:53:00 | 000,954,368 | ---- | M] (Atheros Communications, Inc.) [On_Demand | Stopped] -- C:\Program Files\Jumpstart\jswpsapi.exe -- (jswpsapi)
SRV - [2008/04/15 21:54:42 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
SRV - [2008/02/06 17:52:40 | 000,431,456 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2007/12/03 21:03:52 | 000,126,976 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\Toshiba\SMARTLogService\TosIPCSrv.exe -- (TOSHIBA SMART Log Service)
SRV - [2007/11/21 21:23:32 | 000,129,632 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv)
SRV - [2006/08/23 19:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\PCTINDIS5.SYS -- (PCTINDIS5)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\PCASp50.sys -- (PCASp50)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\pctnullport.sys -- (Nmea)
DRV - File not found [Kernel | System | Stopped] -- c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{52228CBD-9110-4BA6-AB86-59B5EC4CF9AF}\MpKslb80963eb.sys -- (MpKslb80963eb)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\easytthr.sys -- (easytether)
DRV - [2013/09/27 10:53:06 | 000,104,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2011/11/12 12:18:20 | 000,019,456 | ---- | M] (LeapFrog) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\FlyUsb.sys -- (FlyUsb)
DRV - [2011/05/13 03:21:06 | 000,136,808 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadmdm.sys -- (ssadmdm)
DRV - [2011/05/13 03:21:06 | 000,121,064 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadbus.sys -- (ssadbus)
DRV - [2011/05/13 03:21:06 | 000,114,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadserd.sys -- (ssadserd)
DRV - [2011/05/13 03:21:06 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadmdfl.sys -- (ssadmdfl)
DRV - [2010/12/15 07:02:12 | 000,034,936 | ---- | M] (F5 Networks, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\covpnwlh.sys -- (urvpndrv)
DRV - [2010/12/15 07:02:05 | 000,013,944 | ---- | M] (F5 Networks) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\urfltwlh.sys -- (f5ipfw)
DRV - [2010/11/20 06:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 05:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/05/16 21:09:42 | 000,226,816 | ---- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SWNC5E00.sys -- (SWNC5E00)
DRV - [2010/05/16 21:09:42 | 000,157,440 | ---- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\swmx00.sys -- (swmx00)
DRV - [2010/05/16 21:09:26 | 000,229,376 | ---- | M] (Novatel Wireless Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NWADIenum.sys -- (NWADI)
DRV - [2010/03/26 21:07:28 | 000,319,488 | ---- | M] (Beceem communications pvt ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\drxvi314.sys -- (bcm)
DRV - [2010/03/26 21:04:24 | 000,051,456 | ---- | M] (Beceem communications pvt ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BcmBusCtr.sys -- (bcmbusctr)
DRV - [2009/12/20 11:53:32 | 000,234,016 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2009/09/21 18:58:28 | 001,218,048 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009/09/11 15:48:04 | 000,066,056 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WmXlCore.sys -- (WmXlCore)
DRV - [2009/09/11 15:47:54 | 000,014,984 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WmVirHid.sys -- (WmVirHid)
DRV - [2009/09/11 15:47:32 | 000,035,592 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WmFilter.sys -- (WmFilter)
DRV - [2009/09/11 15:47:22 | 000,022,792 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WmBEnum.sys -- (WmBEnum)
DRV - [2009/08/14 20:20:36 | 000,032,304 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\hcmon.sys -- (hcmon)
DRV - [2009/08/14 20:20:34 | 000,054,960 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmci.sys -- (vmci)
DRV - [2009/08/14 20:20:34 | 000,026,288 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmnetuserif.sys -- (VMnetuserif)
DRV - [2009/08/14 20:20:32 | 000,023,216 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMkbd.sys -- (vmkbd)
DRV - [2009/08/14 20:13:56 | 000,857,520 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmx86.sys -- (vmx86)
DRV - [2009/08/14 13:40:04 | 000,031,280 | R--- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmnetbridge.sys -- (VMnetBridge)
DRV - [2009/08/14 13:40:04 | 000,031,280 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmusb.sys -- (vmusb)
DRV - [2009/08/14 13:40:04 | 000,016,560 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmnetadapter.sys -- (VMnetAdapter)
DRV - [2009/07/13 19:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/13 18:13:48 | 001,035,776 | ---- | M] (LSI Corp) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2008/12/01 11:47:08 | 000,022,448 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Program Files\VMware\VMware Player\vstor2-ws60.sys -- (vstor2-ws60)
DRV - [2008/10/15 11:58:34 | 000,024,840 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\swmsflt.sys -- (swmsflt)
DRV - [2008/05/29 15:53:26 | 000,112,640 | ---- | M] (C-motech Co.,Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\cm_net.sys -- (cm_net)
DRV - [2008/05/29 15:53:26 | 000,103,680 | ---- | M] (C-motech Co.,Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\cm_ser.sys -- (cm_ser)
DRV - [2008/04/28 20:59:18 | 000,020,384 | ---- | M] (Atheros Communications, Inc.) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\jswpslwf.sys -- (jswpslwf)
DRV - [2008/01/18 12:22:00 | 000,009,216 | ---- | M] (Inventec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\sysprep\PEDRV.SYS -- (SVRPEDRV)
DRV - [2007/12/17 15:45:20 | 000,018,432 | ---- | M] (Chicony Electronics Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\UVCFTR_S.SYS -- (UVCFTR)
DRV - [2007/12/14 15:53:24 | 000,024,200 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV - [2007/11/09 18:00:52 | 000,023,640 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\TVALZ_O.SYS -- (TVALZ)
DRV - [2007/06/28 07:18:10 | 001,310,720 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CM108.sys -- (USBPNPA)
DRV - [2006/11/20 17:11:14 | 000,007,168 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\FwLnk.sys -- (FwLnk)
DRV - [2006/11/09 02:32:00 | 000,219,264 | ---- | M] (TOSHIBA CORPORATION) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\KR10I.sys -- (KR10I)
DRV - [2006/11/09 02:31:00 | 000,211,072 | ---- | M] (TOSHIBA CORPORATION) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\KR10N.sys -- (KR10N)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{837EC233-EE7F-4796-BBFE-ED94397C77F6}: "URL" = http://www.google.co...ng}&rlz=1I7TSHB
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co...=TSHB&bmod=TSHB
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 3A CA DF 1A D8 E4 CB 01  [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE11SR
IE - HKCU\..\SearchScopes\{3A80A42E-1331-4A90-8AAE-3CF866EA37D1}: "URL" = http://www.bing.com/...ge}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{837EC233-EE7F-4796-BBFE-ED94397C77F6}: "URL" = http://www.google.co...TSHB_en___US330
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo....s}&fr=chr-iobit
IE - HKCU\..\SearchScopes\Comcast: "URL" = http://search.xfinit...art_tech_search
IE - HKCU\..\SearchScopes\Yahoo!: "URL" = http://us.search.yah...&fr=iobit-trans
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/npracplug;version=1.0.0.0: C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll (RealNetworks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\[email protected]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Stephie\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\SiteRanker\firefox\
 
[2011/05/30 09:28:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stephie\AppData\Roaming\Mozilla\Extensions
[2009/06/03 09:50:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stephie\AppData\Roaming\Mozilla\Extensions\[email protected]
[2013/01/23 13:30:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stephie\AppData\Roaming\Mozilla\Firefox\extensions
[2013/01/23 13:30:57 | 000,000,000 | ---D | M] (uTorrentControl_v2) -- C:\Users\Stephie\AppData\Roaming\Mozilla\Firefox\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
[2011/05/30 09:28:22 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
 
========== Chrome  ==========
 
CHR - default_search_provider: Privitize VPN (Enabled)
CHR - default_search_provider: search_url = http://www.google.com
CHR - default_search_provider: suggest_url = ,
CHR - homepage: http://google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\33.0.1750.154\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U32 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: RealArcade Mozilla Plugin (Enabled) = C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live™ Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Yahoo! activeX Plug-in Bridge (Enabled) = C:\Program Files\Yahoo!\Common\npyaxmpb.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Stephie\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.320.5 (Enabled) = C:\Windows\system32\npdeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Google Drive = C:\Users\Stephie\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Stephie\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\Stephie\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Skype Click to Call = C:\Users\Stephie\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\7.1.15383.6004_0\
CHR - Extension: Google Wallet = C:\Users\Stephie\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Users\Stephie\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2014/03/28 12:52:58 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: ::1       localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [AgentMonitor] C:\VTech\DownloadManager\System\AgentMonitor.exe ()
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [ddoctorv2] C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [HSON] C:\Program Files\Toshiba\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Monitor] C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [UVS12 Preload] C:\Program Files\Corel\Corel VideoStudio 12\uvPL.exe (Ulead Systems, Inc.)
O4 - HKLM..\Run: [VMware hqtray] C:\Program Files\VMware\VMware Player\hqtray.exe (VMware, Inc.)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Stephie\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; GTB6.3; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; Media Center PC 5.0; SLCC1)" -"http://www.freeonlin...sagi-bokan.html" File not found
O4 - Startup: C:\Users\Stephie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O16 - DPF: {2BCDB465-81F9-41CB-832C-8037A4064446} C:\Users\Stephie\AppData\Local\Temp\f5tmp\urxvpn.cab (F5 Networks VPN Manager)
O16 - DPF: {41EF3CD2-D8CC-4438-84B1-280BB4E77C8E} C:\Users\Stephie\AppData\Local\Temp\f5tmp\f5tunsrv.cab (F5 Networks Dynamic Application Tunnel Control)
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} https://a2fp3.alpine...llerControl.cab (F5 Networks Auto Update)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {C3D96A02-EEA7-4264-98D7-D882A7338DE5} http://imgfarm.com/i...tup1.0.0.12.cab (Reg Error: Key error.)
O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} C:\Users\Stephie\AppData\Local\Temp\f5tmp\urxshost.cab (F5 Networks SuperHost Class)
O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} C:\Users\Stephie\AppData\Local\Temp\f5tmp\urxhost.cab (F5 Networks Host Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0A2E6BA9-3B42-4B4C-BBFB-E7D86FD7E9DB}: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3275D0AC-DBE6-4B7F-BFCE-D4697877AC7A}: NameServer = 10.124.6.3
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5BE236FD-3749-4E42-988B-53DC570CF5F6}: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F2AAEF74-6A77-42E9-B4E2-38D70F68F0DF}: NameServer = 10.124.6.3
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/03/28 13:39:09 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2014/03/28 13:37:43 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Stephie\Desktop\OTL.exe
[2014/03/28 13:16:44 | 001,038,974 | ---- | C] (Thisisu) -- C:\Users\Stephie\Desktop\JRT.exe
[2014/03/28 13:11:59 | 000,000,000 | ---D | C] -- C:\Users\Stephie\Desktop\The Cleanup
[2014/03/28 13:04:49 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/03/28 12:46:03 | 000,000,000 | ---D | C] -- C:\_OTL
[2014/03/14 13:55:19 | 000,509,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qedit.dll
[2014/03/14 13:55:15 | 000,108,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwcollector.exe
[2014/03/14 13:55:15 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwproxystub.dll
[2014/03/14 13:55:15 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2014/03/14 13:55:15 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2014/03/14 13:55:14 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2014/03/14 13:55:14 | 000,646,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsSpellCheckingFacility.exe
[2014/03/14 13:55:14 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9diag.dll
[2014/03/14 13:55:14 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwcollectorres.dll
[2014/03/14 13:55:12 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2014/03/14 13:55:12 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2014/03/14 13:55:11 | 004,244,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2014/03/14 13:55:08 | 002,724,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2014/03/14 13:55:08 | 000,524,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2014/03/14 13:55:07 | 001,964,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2014/03/14 13:55:07 | 000,208,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2014/03/14 13:55:07 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2014/03/14 13:55:06 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2014/03/14 13:54:40 | 002,349,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2014/03/14 13:54:39 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wer.dll
[2009/08/22 17:39:38 | 000,774,144 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2014/03/28 13:48:37 | 000,627,096 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014/03/28 13:48:37 | 000,107,966 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014/03/28 13:48:32 | 000,009,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/03/28 13:48:32 | 000,009,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/03/28 13:41:32 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/03/28 13:41:18 | 000,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl
[2014/03/28 13:41:06 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/03/28 13:41:01 | 2312,105,984 | -HS- | M] () -- C:\hiberfil.sys
[2014/03/28 13:37:43 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Stephie\Desktop\OTL.exe
[2014/03/28 13:29:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/03/28 13:16:44 | 001,038,974 | ---- | M] (Thisisu) -- C:\Users\Stephie\Desktop\JRT.exe
[2014/03/28 13:02:46 | 001,950,720 | ---- | M] () -- C:\Users\Stephie\Desktop\adwcleaner.exe
[2014/03/28 12:55:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/03/28 12:52:58 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts
[2014/03/28 12:36:01 | 000,000,936 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2844338048-2687002610-4010198750-1000UA.job
[2014/03/28 12:36:00 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2844338048-2687002610-4010198750-1000Core.job
[2014/03/28 12:11:17 | 000,004,783 | ---- | M] () -- C:\Users\Stephie\Desktop\work from home ideas.rtf
[2014/03/26 17:05:34 | 000,000,512 | ---- | M] () -- C:\Users\Stephie\Desktop\MBR.dat
[2014/03/26 15:16:50 | 000,004,952 | ---- | M] () -- C:\Users\Stephie\Desktop\clean system.rtf
[2014/03/24 20:07:32 | 000,466,080 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2014/03/14 18:16:18 | 000,001,904 | ---- | M] () -- C:\WildTangent Games App - wildgames.lnk
[2014/03/14 18:16:17 | 000,002,266 | ---- | M] () -- C:\Users\Public\Desktop\WildTangent Games App - wildgames.lnk
[2014/03/14 14:29:12 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2014/03/14 14:29:12 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2014/03/01 00:11:20 | 002,724,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2014/03/01 00:10:48 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieetwcollectorres.dll
[2014/02/28 23:52:43 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2014/02/28 23:51:53 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieetwproxystub.dll
[2014/02/28 23:43:55 | 000,043,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2014/02/28 23:43:28 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2014/02/28 23:40:17 | 000,440,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2014/02/28 23:38:26 | 000,112,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2014/02/28 23:38:23 | 000,108,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieetwcollector.exe
[2014/02/28 23:37:35 | 000,553,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9diag.dll
[2014/02/28 23:31:30 | 000,646,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MsSpellCheckingFacility.exe
[2014/02/28 23:25:29 | 000,208,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2014/02/28 23:16:09 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2014/02/28 23:14:15 | 004,244,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2014/02/28 23:03:49 | 000,524,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2014/02/28 23:00:08 | 001,964,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2014/02/28 22:25:42 | 000,703,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2014/03/28 13:02:46 | 001,950,720 | ---- | C] () -- C:\Users\Stephie\Desktop\adwcleaner.exe
[2014/03/26 17:05:34 | 000,000,512 | ---- | C] () -- C:\Users\Stephie\Desktop\MBR.dat
[2014/03/26 14:54:14 | 000,004,952 | ---- | C] () -- C:\Users\Stephie\Desktop\clean system.rtf
[2014/03/02 09:10:17 | 000,004,783 | ---- | C] () -- C:\Users\Stephie\Desktop\work from home ideas.rtf
[2011/11/20 12:41:36 | 000,000,581 | ---- | C] () -- C:\Users\Stephie\AppData\Local\cookies.ini
[2011/05/22 21:08:28 | 000,072,080 | ---- | C] () -- C:\Users\Stephie\g2mdlhlpx.exe
[2011/04/28 09:08:40 | 000,009,728 | ---- | C] () -- C:\Users\Stephie\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/22 13:46:23 | 000,000,081 | ---- | C] () -- C:\Users\Stephie\CTX.DAT
[2010/02/16 00:22:04 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/07/01 14:08:47 | 000,000,000 | ---- | C] () -- C:\Users\Stephie\AppData\Roaming\wklnhst.dat
 
========== ZeroAccess Check ==========
 
[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/25 21:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 08:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/13 21:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >

 

 

How's It Running Now, You Ask?! :geek: 

  Well, I pulled the ultimate test, a speed typing test. That's when I noticed the issues the first time when the computer couldn't keep up with my typing.... It went beautifully! :yeah:  I'm cruising through sites and files like it's new again. I hope the OLT scan shows good things this time. I'll keep an eye out for your reply. You rock!!!! :D 

 

 


  • 0

#8
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,886 posts

So, here's the skinny, I uninstalled all that you suggested, but couldn't find the iLivid though I remember the icon and the day I downloaded it. I also remember deleting it right after I downloaded it. Just bad Juju. But, the JRT scan results showed that it was found and deleted. Tricky tricky. Okay, here are the results...


Hello :)

I didn't see too much evidence in there, but what was there, the fixes took care of. :thumbsup:

 

How's It Running Now, You Ask?! :geek:

Well, I pulled the ultimate test, a speed typing test. That's when I noticed the issues the first time when the computer couldn't keep up with my typing.... It went beautifully! :yeah: I'm cruising through sites and files like it's new again. I hope the OLT scan shows good things this time. I'll keep an eye out for your reply. You rock!!!! :D


:D That's what I love to hear.   :) I don't see any active malware in the OTL log so, let's run a sweep for any remnants and check for out of date programs on your machine.


Please disable your antivirus for the duration of my instructions. Don't forget to re-enable them after you have completed the steps.


Step 1: Scan with Malwarebytes


Please download Malwarebytes Anti-Malware to your desktop
Install the progamme and select update
Once it has updated select Settings > Detection and Protection
Tick Scan for rootkits

MBAMsettings_zpsb6b9ada0.jpg

Go back to the Dashboard and select Scan Now

MBAMScan_zps8ba7d192.jpg

If threats are detected, click the Apply Actions button, MBAM will ask for a reboot.

MBAMReboot_zps9089ab30.jpg

MBAMLog_zpsade07f42.jpg

On completion of the scan (or after the reboot) select View Detailed Log
Select Export > Select text file and save to the desktop



Step 2: Scan with ESET Online Scanner


Please note: You can use Internet Explorer or Firefox for this step. Either browser used will have to be ran in admin mode.

Right click on either the Internet Explorer icon or the Firefox icon in the Start Menu or Quick Launch Bar on the Task bar and select Run as Administrator from the menu.

If you use Firefox, you will be prompted to download esetsmartinstaller_enu.exe. Please do so, then double click it to install it.

Please click on this link and then click the ESET Online Scanner bar ---->esetbar_zps93905f48.jpg

  • Select the option YES, I accept the Terms of Use then click on Start
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked.
  • Make sure that the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
  • Scan for potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth Technology
  • Now click on Start
  • The virus signature database will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically. The scan may take several hours.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • Now click on Finish
  • Use notepad to open the logfile located at C:\Program Files(x86)\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

 

 

Step 3: SecurityCheck Scan


Download Security Checksecuritycheck_zpsb7736812.jpg by screen317 from here or here.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • NOTE: If SecurityCheck aborts and you get the following message: UNSUPPORTED OPERATING SYSTEM! ABORTED! try rebooting the system and then run SecurityCheck again.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

 

Things I need to see in your next post:

  • ESET Scan Log
  • MBAM Log
  • SecurityCheck Log

  • 0

#9
CaramelBliss*

CaramelBliss*

    Member

  • Topic Starter
  • Member
  • PipPip
  • 63 posts

Man, you were NOT kidding about the online scan taking hours. Finally done with it all, but not sure the online scan "logged correctly. It said it found 39 potential threats, but the log does not say any of that. Here's what I mean...

 

 

           ESET Scan Log:

ESETSm[email protected] as CAB hook log:
OnlineScanner.ocx - registred OK  

           

  (SOOOO not kidding, This is it...)

              

  • MBAM Log:

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 3/29/2014
Scan Time: 9:20:32 PM
Logfile: mbam log.txt
Administrator: Yes

Version: 2.00.0.1000
Malware Database: v2014.03.29.08
Rootkit Database: v2014.03.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Chameleon: Disabled

OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Stephie

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 259667
Time Elapsed: 18 min, 49 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)

(end)

 

 

  • SecurityCheck Log ;

 

 

  

 Results of screen317's Security Check version 0.99.4 
 Windows 7 Service Pack 1 (UAC is enabled)
 Internet Explorer 8 
``````````````````````````````
Antivirus/Firewall Check:

 Windows Firewall Enabled! 
 ESET Online Scanner v3  
 Microsoft Security Essentials   
 WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:

 CCleaner    
 Java 7 Update 51 
 Adobe Flash Player 10.0.32.18 
Adobe Reader 9.5.1
````````````````````````````````
Process Check: 
objlist.exe by Laurent

 Windows Defender MSMpEng.exe
 Microsoft Security Essentials msseces.exe
````````````````````````````````
DNS Vulnerability Check:

 GREAT! (Not vulnerable to DNS cache poisoning)

``````````End of Log````````````

 

 

 

 

   Okay, So what's next? Thanks for your patience. It's been a long day. :bashhead: 

 

 

  


  • 0

#10
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,886 posts

Man, you were NOT kidding about the online scan taking hours. Finally done with it all, but not sure the online scan "logged correctly. It said it found 39 potential threats, but the log does not say any of that. Here's what I mean...


ESET Scan Log:

[email protected] as CAB hook log:
OnlineScanner.ocx - registred OK



(SOOOO not kidding, This is it...)

 
That happens from time to time for some reason, and the threats it found are usually either already quarantined or files that have malware bundled with them. But, let's take a look with a different scanner. I'd like to get rid of the potential threats to your machine. :thumbsup:
 
 

   Okay, So what's next? Thanks for your patience. It's been a long day. :bashhead:

 
 
You're quite welcome, it's our pleasure. :)
 



Scan with NMC:

Please download Norman Malware Cleaner and save it to your Desktop.

Alternate download location here.

  • Double-click on Norman_Malware_Cleaner.exe >> Accept.
  • Click on the Options tab >> General Options and deselect the following:

Enable Norman Protection Community

  • Now click on Cleaning Options and deselect the following:

Enable Cleaning
Quarantine objects before cleaning

  • Click on Apply >> then the Scan tab >> ensure the Quick scan is selected only.
  • Then click on Start
  • Once the scan has completed a log will be created on your desktop named: Nmc_Year-Month-Day-Time.Log
  • Click on the Quit tab.
  • Post the aforementioned log in your next reply

Things I need to see in your next post:

NMC Log


  • 0

#11
CaramelBliss*

CaramelBliss*

    Member

  • Topic Starter
  • Member
  • PipPip
  • 63 posts

Welp, Good to know that happens. ^_^

 

 NMC Log:

 

Norman Malware Cleaner v2.08.08
Copyright © 1990 - 2013, Norman Shark AS.

Norman Scanner Engine Version: 7.02.06
nvcbin.def: Version: 7.02.7573, Date: 2014/03/31 08:37:28, Variants: 27301814

Operating System: Windows 7 Service Pack 1

Switches: /iagree /noclean /noquarantine
Running without NSAK

Scan started: 2014/03/31 13:12:54

Running pre-scan cleanup routine...

Number of malicious objects found: 0
Number of malicious objects cleaned: 0
Scanning time: 0s

Scanning system for active rootkit activity...

Number of malicious objects found: 0
Number of malicious objects cleaned: 0
Number of malicious files found: 0
Number of malicious files cleaned: 0
Scanning time: 0s

Scanning running processes and process memory...

Number of files found: 798
Number of objects found: 9407
Number of objects scanned: 9407
Number of objects not scanned: 0
Number of malicious memory objects found: 0
Number of malicious objects cleaned: 0
Number of malicious files found: 0
Number of malicious files cleaned: 0
Scanning time: 1m 57s

Scanning system for FakeAV...

Number of malicious objects found: 0
Number of malicious objects cleaned: 0
Number of malicious files found: 0
Number of malicious files cleaned: 0
Scanning time: 0s

Running quick scan...

Number of files found: 4625
Number of archives unpacked: 3
Number of objects found: 4719
Number of objects scanned: 4719
Number of objects not scanned: 0
Number of malicious objects found: 0
Number of malicious objects cleaned: 0
Number of malicious files found: 0
Number of malicious files cleaned: 0
Scanning time: 3m 20s

Running post-scan cleanup routine...

Number of malicious objects found: 0
Number of malicious objects cleaned: 0
Scanning time: 0s

Results:
Total number of files found: 5423
Total number of archives unpacked: 3
Total number of objects found: 14126
Total number of objects scanned: 14126
Total number of objects not scanned: 0
Total number of malicious objects found: 0
Total scanning time: 5m 17s

 

I don't know much about Scan results, but this one looks good... I think :spoton:


  • 0

#12
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,886 posts

I don't know much about Scan results, but this one looks good... I think :spoton:


It looks good, no active malware detected. :) The ESET scan most likely picked up the infected files we've already killed, so I'm going take a moment and say...


Great news, your logs are CLEAN! :thumbsup: :) But we still have a few things we need to address namely:
  • I need to remove the tools we installed on your machine.
  • We also have some information to help protect you in the future and a program to protect your machine against a truly insidious ransomware program called CryptoLocker.
Step 1: Tool Removal, and Creation of a Clean Restore Point
  • Download Delfix from here
  • Ensure Remove disinfection tools is ticked
    Also tick:
    • Create registry backup
    • Purge system restore
    delfix.jpg
  • Click Run
The program will run for a few moments and then notepad will open with a log. Please paste the log in your next reply

You can remove ESET Online Scanner and Norman Malware Cleaner at this time.

I'd recommend keeping Malwarebytes Anti-Malware installed. Make sure to update it and run it at least once a week. If it detects items like PUP's (potentially unwanted programs) and such, go ahead and delete those. If it detects something like a trojan, come see us. :)


Step 2: Tips, Information, and Protection against CryptoLocker


Watch what you open in your emails. If you get an email from an unknown source with any attached files, do not open it.

Be careful of the websites you visit.

When installing new programs, don't be "click happy" and click through the screens. Many programs come with adware in them and are set to install them by default. Several programs require that you uncheck or select no to prevent the installation. Take you time and read each screen as you go. :)

To help protect yourself while on the web, I recommend you read How did I get infected in the first place?

A warning about CryptoLocker

CryptoLocker is a ransomware program that was released around the beginning of September 2013 that targets all versions of Windows including Windows XP, Windows Vista, Windows 7, and Windows 8. This ransomware will encrypt certain files using a mixture of RSA & AES encryption. When it has finished encrypting your files, it will display a CryptoLocker payment program that prompts you to send a ransom of either $100 or $300 in order to decrypt the files. This screen will also display a timer stating that you have 72 hours, or 4 days, to pay the ransom or it will delete your encryption key and you will not have any way to decrypt your files. This ransom must be paid using MoneyPak vouchers or Bitcoins. Once you send the payment and it is verified, the program will decrypt the files that it encrypted.

Please download and install CryptoPrevent to lock your machine down from this infection.

CryptoPrevent_zps1835f65d.jpg

Are there any further issues I can assist you with?
  • 0

#13
pystryker

pystryker

    Trusted Helper

  • Malware Removal
  • 3,886 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics


Also tagged with one or more of these keywords: Malware, Spyware, virus, choppy, delayed, overheat, sick

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP