Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

My browser keeps showing proxy server127.0.0.1-88771 nonresponding [So

broswer regisitry windows7

  • This topic is locked This topic is locked

#1
moviebuff6000

moviebuff6000

    New Member

  • Member
  • Pip
  • 6 posts

My wife works from home and as a part of the requirements Belarc had to check security settings and internet speed. In the process of getting our PC "secure". Non of our browsers would open and kept getting proxy server not responding.  I have tried the going into tools and changing the settings, only to have it change back and still no browser access. System restore is only thing that resolved the issue for a few days and then same problem. All the updates Microsoft does somehow makes the settings change to where no web browser will work. NAV nor Malwarebytes are showing anything. The last system restore allowed me to access my web browser but now the auto prtectionfor NAV won't work.Please help in resolving this issue.


Edited by moviebuff6000, 04 April 2014 - 04:58 AM.

  • 0

Advertisements


#2
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts
Hello and welcome to Geeks to Go. I am sorry that you are having troubles with your computer and will try my best to help you. I know that being infected is very frustrating, but I will be here to help you through the whole process of cleaning. Removing malware can be difficult and complicated and will most likely take many steps, so please stick with me until I have declared your computer clean. I always recommend printing my instructions before following them in case you cannot keep this webpage open. Please be sure to alway follow all steps exactly as they are written and let me know what happens each time. Stop and ask if something unexpected happens or if you are unsure of how to proceed.
 
Please respect my volunteered time and stay with me until I declare your computer clean. If you are going to be delayed for a while, please let me know.
 

Please download Farbar Recovery Scan Tool and save it to your desktop.
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
  •  


    • 0

    #3
    moviebuff6000

    moviebuff6000

      New Member

    • Topic Starter
    • Member
    • Pip
    • 6 posts
    Thank you for your help. I will make sure I check back more often to ensure a timely response. I copied and pasted the two txt files requested below.
     
    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
    Ran by Raph (administrator) on RAPH-PC on 05-04-2014 18:18:04
    Running from C:\Users\Raph\Downloads
    Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
    Internet Explorer Version 11
    Boot Mode: Normal
     
    The only official download link for FRST:
    Download link from any site other than Bleeping Computer is unpermitted or outdated.
     
    ==================== Processes (Whitelisted) =================
     
    (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
    () C:\Users\Raph\AppData\Local\GCC\Controller.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
    (MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
    () C:\Program Files (x86)\pastaleads\PastaLeadsWinApp.exe
    (MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
    (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
    (Sony Corporation) C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe
    (Power Software Ltd) C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
    (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
    (PureLeads) C:\Program Files (x86)\PureLeads\PureLeadsTray.exe
    (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe
    (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.2.0.38\N360.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    () C:\Program Files (x86)\pastaleads\PastaLeadsService.exe
    (Sendori) C:\Program Files (x86)\PureLeads\plsapp.exe
    (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.2.0.38\N360.exe
    (Protexis Inc.) c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
    () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
    (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    (Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
    (PureLeads) C:\Program Files (x86)\PureLeads\PureLeadsSvc.exe
    () C:\Users\Raph\AppData\Local\GCC\Controller.exe
    (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDExtHost.exe
    (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDAppHost.exe
    (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDRuntimeHost.exe
    (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
    (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.exe
    (Google Inc.) C:\Users\Raph\AppData\Local\GCC\Chrome-bin\chrome.exe
    (Google Inc.) C:\Users\Raph\AppData\Local\GCC\Chrome-bin\chrome.exe
    (Google Inc.) C:\Users\Raph\AppData\Local\GCC\Chrome-bin\chrome.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe
    (sendori) C:\Program Files (x86)\PureLeads\PureLeads.Service.exe
    (Google Inc.) C:\Users\Raph\AppData\Local\GCC\Chrome-bin\chrome.exe
    (Google Inc.) C:\Users\Raph\AppData\Local\GCC\Chrome-bin\chrome.exe
    (Google Inc.) C:\Users\Raph\AppData\Local\GCC\Chrome-bin\chrome.exe
    (Google Inc.) C:\Users\Raph\AppData\Local\GCC\Chrome-bin\chrome.exe
    (Google Inc.) C:\Users\Raph\AppData\Local\GCC\Chrome-bin\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
     
     
    ==================== Registry (Whitelisted) ==================
     
    HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6548112 2012-06-12] (Realtek Semiconductor)
    HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-10-17] (NVIDIA Corporation)
    HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap64.dll [1063200 2013-10-17] (NVIDIA Corporation)
    HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [630912 2012-05-04] (Advanced Micro Devices, Inc.)
    HKLM-x32\...\Run: [Super-Charger] - C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [495616 2012-07-27] (MSI)
    HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [295512 2013-10-14] (RealNetworks, Inc.)
    HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
    HKLM-x32\...\Run: [Reader Application Helper] - C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe [899400 2013-11-27] (Sony Corporation)
    HKLM-x32\...\Run: [PWRISOVM.EXE] - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [337432 2013-10-23] (Power Software Ltd)
    HKLM-x32\...\Run: [] - [X]
    HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
    HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
    HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
    HKLM-x32\...\Run: [PureLeads Tray] - C:\Program Files (x86)\PureLeads\PureLeadsTray.exe [83232 2014-01-23] (PureLeads)
    HKLM-x32\...\Run: [BingDesktop] - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2353880 2013-11-01] (Microsoft Corp.)
    HKU\S-1-5-21-4097332094-2714983402-552182644-1000\...\Run: [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
    HKU\S-1-5-21-4097332094-2714983402-552182644-1000\...\Run: [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.)
    HKU\S-1-5-21-4097332094-2714983402-552182644-1000\...\Run: [AppleIEDAV] - C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe [1326408 2013-11-15] (Apple Inc.)
    AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll File Not Found
    AppInit_DLLs-x32: c:\progra~2\searchprotect\searchprotect\bin\spvc32loader.dll => "c:\progra~2\searchprotect\searchprotect\bin\spvc32loader.dll" File Not Found
     
    ==================== Internet (Whitelisted) ====================
     
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://t.msn.com/
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x822AA7130051CF01
    BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine64\21.2.0.38\coIEPlg.dll (Symantec Corporation)
    BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
    BHO-x32: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
    BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
    BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\21.2.0.38\coIEPlg.dll (Symantec Corporation)
    BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\21.2.0.38\IPS\IPSBHO.DLL (Symantec Corporation)
    BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
    BHO-x32: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
    BHO-x32: PETN - {B8107FB2-1A17-4277-B9E0-EDC058A2D774} - C:\Users\Raph\AppData\Local\TidyNetwork\petn.dll No File
    BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
    BHO-x32: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    BHO-x32: Microsoft Web Test Recorder 10.0 Helper - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
    Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.2.0.38\coIEPlg.dll (Symantec Corporation)
    Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
    Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.2.0.38\coIEPlg.dll (Symantec Corporation)
    Toolbar: HKLM-x32 - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
    Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
    Toolbar: HKCU - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.2.0.38\coIEPlg.dll (Symantec Corporation)
    DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab
    DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab
    Winsock: Catalog9 01 C:\Windows\SysWOW64\plsapp.dll [354592] (Sendori)
    Winsock: Catalog9 02 C:\Windows\SysWOW64\plsapp.dll [354592] (Sendori)
    Winsock: Catalog9 03 C:\Windows\SysWOW64\plsapp.dll [354592] (Sendori)
    Winsock: Catalog9 04 C:\Windows\SysWOW64\plsapp.dll [354592] (Sendori)
    Winsock: Catalog9 15 C:\Windows\SysWOW64\plsapp.dll [354592] (Sendori)
    Winsock: Catalog9-x64 01 C:\Windows\system32\plsapp64.dll [439296] (Sendori)
    Winsock: Catalog9-x64 02 C:\Windows\system32\plsapp64.dll [439296] (Sendori)
    Winsock: Catalog9-x64 03 C:\Windows\system32\plsapp64.dll [439296] (Sendori)
    Winsock: Catalog9-x64 04 C:\Windows\system32\plsapp64.dll [439296] (Sendori)
    Winsock: Catalog9-x64 15 C:\Windows\system32\plsapp64.dll [439296] (Sendori)
    Tcpip\Parameters: [DhcpNameServer] 75.75.76.76 75.75.75.75
     
    Chrome: 
    =======
    CHR DefaultSearchKeyword: bing.com
    CHR DefaultSearchProvider: Bing
    CHR DefaultNewTabURL: 
    CHR Extension: (RealDownloader) - C:\Users\Raph\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-03-23]
    CHR Extension: (Norton Identity Protection) - C:\Users\Raph\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2014-03-23]
    CHR Extension: (Google Wallet) - C:\Users\Raph\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-23]
    CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
    CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\21.2.0.38\Exts\Chrome.crx [2014-03-27]
     
    ==================== Services (Whitelisted) =================
     
    R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-05-04] (Advanced Micro Devices, Inc.)
    R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173272 2013-11-01] (Microsoft Corp.)
    R2 HPSLPSVC; C:\Users\Raph\AppData\Local\Temp\7zS0906\hpslpsvc64.dll [1039360 2013-07-19] (Hewlett-Packard Co.)
    R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
    R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
    R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [136704 2012-06-29] (MSI)
    S2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [58345832 2011-09-22] (Microsoft Corporation)
    R2 N360; C:\Program Files (x86)\Norton 360\Engine\21.2.0.38\N360.exe [265040 2014-03-12] (Symantec Corporation)
    R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15122208 2013-10-17] (NVIDIA Corporation)
    R2 pastaleadsServiceCore; C:\Program Files (x86)\pastaleads\PastaLeadsService.exe [361368 2014-03-18] ()
    R2 plsapp; C:\Program Files (x86)\PureLeads\plsapp.exe [3690784 2014-01-23] (Sendori)
    R2 PlsvcV1; C:\Program Files (x86)\PureLeads\PureLeadsSvc.exe [91936 2014-01-23] (PureLeads)
    R2 PlsvcV2; C:\Program Files (x86)\PureLeads\PureLeads.Service.exe [24352 2014-01-23] (sendori)
    R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
    S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [431464 2011-09-22] (Microsoft Corporation)
     
    ==================== Drivers (Whitelisted) ====================
     
    R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [55936 2011-11-13] (Advanced Micro Devices)
    R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\21.0.2.1\Definitions\BASHDefs\20140319.001\BHDrvx64.sys [1525976 2014-03-18] (Symantec Corporation)
    R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1502000.026\ccSetx64.sys [162392 2013-09-25] (Symantec Corporation)
    R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-11-21] (Symantec Corporation)
    R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2013-11-21] (Symantec Corporation)
    R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\21.0.2.1\Definitions\IPSDefs\20140404.001\IDSvia64.sys [525016 2014-04-03] (Symantec Corporation)
    R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
    R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-05] (Malwarebytes Corporation)
    R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
    R3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\21.0.2.1\Definitions\VirusDefs\20140405.003\ENG64.SYS [126040 2014-04-04] (Symantec Corporation)
    R3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\21.0.2.1\Definitions\VirusDefs\20140405.003\EX64.SYS [2099288 2014-04-04] (Symantec Corporation)
    R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-27] (NVIDIA Corporation)
    R1 SRTSP; C:\Windows\System32\Drivers\N360x64\1502000.026\SRTSP64.SYS [875736 2014-02-12] (Symantec Corporation)
    R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1502000.026\SRTSPX64.SYS [36952 2013-07-30] (Symantec Corporation)
    R0 SymDS; C:\Windows\System32\drivers\N360x64\1502000.026\SYMDS64.SYS [493656 2013-07-31] (Symantec Corporation)
    R0 SymEFA; C:\Windows\System32\drivers\N360x64\1502000.026\SYMEFA64.SYS [1148120 2014-03-03] (Symantec Corporation)
    R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-10-14] (Symantec Corporation)
    R1 SymIRON; C:\Windows\system32\drivers\N360x64\1502000.026\Ironx64.SYS [264280 2013-07-30] (Symantec Corporation)
    R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1502000.026\SYMNETS.SYS [593112 2014-02-17] (Symantec Corporation)
    S3 MSICDSetup; \??\D:\CDriver64.sys [X]
    S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]
     
    ==================== NetSvcs (Whitelisted) ===================
     
     
    ==================== One Month Created Files and Folders ========
     
    2014-04-05 18:18 - 2014-04-05 18:18 - 00018129 _____ () C:\Users\Raph\Downloads\FRST.txt
    2014-04-05 18:17 - 2014-04-05 18:18 - 00000000 ____D () C:\FRST
    2014-04-05 18:16 - 2014-04-05 18:16 - 02157056 _____ (Farbar) C:\Users\Raph\Downloads\FRST64.exe
    2014-04-04 12:26 - 2014-04-04 19:42 - 00003358 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-4097332094-2714983402-552182644-1000
    2014-04-04 06:29 - 2014-04-04 06:29 - 00000166 _____ () C:\Users\Raph\Documents\emailpw.txt
    2014-04-02 18:21 - 2014-04-04 12:14 - 00000000 ____D () C:\ProgramData\PreEmptive Solutions
    2014-04-02 17:43 - 2011-09-22 21:07 - 00105832 _____ (Microsoft Corporation) C:\Windows\system32\SQSRVRES.DLL
    2014-04-02 17:43 - 2011-09-22 21:06 - 00109416 _____ (Microsoft Corporation) C:\Windows\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.3.5500.0.dll
    2014-04-02 17:43 - 2011-09-22 17:18 - 00073064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perf-MSSQL$SQLEXPRESS-sqlctr10.3.5500.0.dll
    2014-04-02 09:06 - 2014-04-02 09:06 - 00000000 ____D () C:\ProgramData\RSA
    2014-04-02 09:05 - 2014-04-02 09:05 - 00000000 ____D () C:\Users\Raph\AppData\Local\RSA
    2014-04-02 09:05 - 2014-04-02 09:05 - 00000000 ____D () C:\Program Files (x86)\RSA SecurID Token Common
    2014-04-02 09:05 - 2014-04-02 09:05 - 00000000 ____D () C:\Program Files (x86)\RSA SecurID Software Token
    2014-04-02 09:04 - 2014-04-02 09:04 - 12518912 _____ () C:\Users\Raph\Downloads\RSASecurIDToken410.msi
    2014-04-02 09:00 - 2014-04-02 09:00 - 01527104 _____ (LogMeIn, Inc.) C:\Users\Raph\Downloads\Support-LogMeInRescue.exe
    2014-04-01 21:38 - 2014-04-01 21:38 - 00282312 _____ () C:\Windows\Minidump\040114-57174-01.dmp
    2014-04-01 21:38 - 2014-04-01 21:38 - 00000000 ____D () C:\Windows\Minidump
    2014-04-01 21:37 - 2014-04-01 21:37 - 534141396 _____ () C:\Windows\MEMORY.DMP
    2014-03-31 13:54 - 2014-03-31 13:54 - 00000000 ____D () C:\Users\Raph\AppData\Roaming\webex
    2014-03-31 13:53 - 2014-03-31 13:54 - 00000000 ____D () C:\ProgramData\WebEx
    2014-03-31 13:53 - 2014-03-31 13:53 - 00187176 _____ (Cisco WebEx LLC) C:\Users\Raph\Downloads\,staffmanagement,1607416503,-1933870862,MC,0-0,AAAAAcW0eDY3eIJvS7Pms0ns2-PWe1Aul7zVGJ83BXH4hAr30_webex.exe
    2014-03-30 21:14 - 2014-03-30 21:14 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
    2014-03-30 21:14 - 2014-03-30 21:14 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
    2014-03-30 21:05 - 2014-03-30 21:05 - 00003336 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-4097332094-2714983402-552182644-1000
    2014-03-30 20:40 - 2014-04-05 11:50 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2014-03-30 20:39 - 2014-04-04 19:08 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2014-03-30 20:39 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
    2014-03-30 20:39 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2014-03-30 20:39 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
    2014-03-30 20:22 - 2014-03-30 20:22 - 00000000 ____D () C:\Users\Raph\AppData\Local\SearchProtect
    2014-03-30 13:43 - 2014-03-30 14:11 - 00000000 ____D () C:\AdwCleaner
    2014-03-30 13:00 - 2014-04-04 19:08 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
    2014-03-30 13:00 - 2014-03-30 13:00 - 00000000 ____D () C:\ProgramData\Malwarebytes
    2014-03-28 13:57 - 2014-03-28 13:58 - 00000000 ____D () C:\Users\Raph\AppData\Local\NPE
    2014-03-27 20:08 - 2014-03-27 20:08 - 00000000 ____D () C:\Users\Default\Documents\Visual Studio 2010
    2014-03-27 20:08 - 2014-03-27 20:08 - 00000000 ____D () C:\Users\Default User\Documents\Visual Studio 2010
    2014-03-27 19:14 - 2014-03-27 19:14 - 00000000 ____D () C:\Users\Raph\Documents\Visual Studio 2008
    2014-03-27 18:54 - 2014-03-27 18:54 - 00000000 ____D () C:\ProgramData\VS
    2014-03-27 18:16 - 2014-03-27 18:16 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8
    2014-03-27 15:40 - 2014-03-27 15:40 - 00000200 _____ () C:\Users\Raph\Documents\winkeymso2010.txt
    2014-03-27 15:35 - 2014-03-27 15:35 - 06957280 _____ (Microsoft Corporation) C:\Users\Raph\Downloads\Silverlight.exe
    2014-03-27 14:58 - 2014-03-27 14:58 - 00000000 ____D () C:\Users\Raph\AppData\Roaming\Microsoft Corporation
    2014-03-27 14:47 - 2009-07-22 03:17 - 00078872 _____ (Microsoft Corporation) C:\Windows\system32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll
    2014-03-27 14:47 - 2009-07-22 03:17 - 00050200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll
    2014-03-27 14:45 - 2014-03-27 14:45 - 00000000 ____D () C:\Windows\system32\RsFx
    2014-03-27 14:44 - 2014-03-27 14:44 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 9.0
    2014-03-27 14:37 - 2014-04-04 12:14 - 00000000 ____D () C:\Program Files\Microsoft SQL Server
    2014-03-27 14:36 - 2014-04-04 12:10 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server
    2014-03-27 14:35 - 2014-03-27 14:35 - 00000000 ____D () C:\Program Files\Microsoft Sync Framework
    2014-03-27 14:34 - 2014-03-27 14:34 - 00000000 ____D () C:\Program Files\Microsoft Synchronization Services
    2014-03-27 14:34 - 2014-03-27 14:34 - 00000000 ____D () C:\Program Files\Microsoft SQL Server Compact Edition
    2014-03-27 14:34 - 2014-03-27 14:34 - 00000000 ____D () C:\Program Files (x86)\Microsoft Synchronization Services
    2014-03-27 14:34 - 2014-03-27 14:34 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
    2014-03-27 14:25 - 2014-03-30 20:13 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
    2014-03-27 14:22 - 2014-03-27 14:22 - 00000000 ____D () C:\Program Files\IIS
    2014-03-27 14:22 - 2014-03-27 14:22 - 00000000 ____D () C:\Program Files (x86)\Microsoft ASP.NET
    2014-03-27 14:22 - 2014-03-27 14:22 - 00000000 ____D () C:\Program Files (x86)\IIS
    2014-03-27 14:18 - 2014-03-27 15:02 - 00000000 ____D () C:\Users\Raph\Documents\Visual Studio 2010
    2014-03-27 14:07 - 2014-03-27 14:43 - 00000000 ____D () C:\Windows\SysWOW64\1033
    2014-03-27 14:06 - 2014-04-04 12:12 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 10.0
    2014-03-27 14:06 - 2014-03-27 14:11 - 00000000 ____D () C:\Program Files (x86)\Microsoft F#
    2014-03-27 14:06 - 2014-03-27 14:09 - 00000000 ____D () C:\Program Files (x86)\HTML Help Workshop
    2014-03-27 14:04 - 2014-04-04 12:22 - 00000000 ____D () C:\Windows\symbols
    2014-03-27 14:04 - 2014-03-30 20:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft SDKs
    2014-03-27 14:04 - 2014-03-27 14:43 - 00000000 ____D () C:\Windows\system32\1033
    2014-03-27 14:04 - 2014-03-27 14:36 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 10.0
    2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 ____D () C:\Program Files\Microsoft Help Viewer
    2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 9.0
    2014-03-27 13:15 - 2014-03-27 13:15 - 00003136 _____ () C:\Windows\System32\Tasks\{C52BFAAC-4F6C-40F5-87D7-098D3F727788}
    2014-03-27 12:57 - 2014-03-30 21:06 - 00003200 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-4097332094-2714983402-552182644-1000
    2014-03-27 12:07 - 2014-03-27 12:07 - 00003124 _____ () C:\Windows\System32\Tasks\{81328C64-A1ED-4CEC-B107-5D7D82409D5D}
    2014-03-27 11:23 - 2014-03-27 11:23 - 00000000 ____D () C:\Windows\System32\Tasks\Norton 360
    2014-03-27 11:10 - 2014-03-04 06:32 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
    2014-03-27 11:01 - 2014-04-04 12:22 - 00000000 ____D () C:\Users\Raph\AppData\Roaming\vlc
    2014-03-27 10:58 - 2014-03-30 20:59 - 00000000 ____D () C:\Users\Raph\AppData\Local\GCC
    2014-03-27 10:58 - 2014-03-30 20:25 - 00000000 ____D () C:\ProgramData\pastaleads
    2014-03-27 10:58 - 2014-03-30 20:14 - 00000000 ____D () C:\Program Files (x86)\pastaleads
    2014-03-27 10:58 - 2014-03-27 10:58 - 00004566 _____ () C:\Windows\System32\Tasks\GC_Informer
    2014-03-27 10:58 - 2014-03-27 10:58 - 00004550 _____ () C:\Windows\System32\Tasks\GC_Scheduler
    2014-03-27 08:39 - 2014-03-27 08:39 - 00000000 ____D () C:\Users\Raph\AppData\Roaming\Oracle
    2014-03-27 08:38 - 2014-03-27 08:38 - 00000000 ____D () C:\ProgramData\Sun
    2014-03-27 08:38 - 2014-03-27 08:38 - 00000000 ____D () C:\ProgramData\Oracle
    2014-03-27 08:38 - 2014-03-27 08:37 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
    2014-03-27 08:37 - 2014-03-27 08:37 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
    2014-03-27 08:37 - 2014-03-27 08:37 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
    2014-03-27 08:37 - 2014-03-27 08:37 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
    2014-03-27 08:37 - 2014-03-27 08:37 - 00000000 ____D () C:\Program Files (x86)\Java
    2014-03-27 08:33 - 2014-03-27 10:32 - 00000000 ____D () C:\Program Files (x86)\PureLeads
    2014-03-27 08:33 - 2014-03-27 08:33 - 00000000 ____D () C:\ProgramData\PureLeads
    2014-03-27 08:33 - 2014-03-27 08:33 - 00000000 ____D () C:\Program Files (x86)\DownloadXCtrl.com
    2014-03-27 08:33 - 2014-01-23 18:12 - 00354592 _____ (Sendori) C:\Windows\SysWOW64\plsapp.dll
    2014-03-27 08:33 - 2013-11-13 22:41 - 00439296 _____ (Sendori) C:\Windows\system32\plsapp64.dll
    2014-03-27 08:09 - 2014-03-30 20:14 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
    2014-03-24 08:51 - 2014-04-01 21:48 - 00000000 ____D () C:\Program Files (x86)\Belarc
    2014-03-23 02:38 - 2014-03-23 02:38 - 00002255 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
    2014-03-23 02:37 - 2014-04-05 17:49 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2014-03-23 02:37 - 2014-04-05 07:49 - 00000890 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2014-03-23 02:37 - 2014-03-31 07:44 - 00003890 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
    2014-03-23 02:37 - 2014-03-31 07:44 - 00003638 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
    2014-03-23 02:37 - 2014-03-23 02:37 - 00000000 ____D () C:\Program Files (x86)\Google
    2014-03-23 02:36 - 2014-03-23 02:38 - 00000000 ____D () C:\Users\Raph\AppData\Local\Google
    2014-03-20 23:03 - 2014-03-20 23:03 - 15783992 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
    2014-03-20 23:03 - 2014-03-20 23:03 - 11589272 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
    2014-03-20 23:03 - 2014-03-20 23:03 - 09690424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 31474976 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 25255256 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 23716640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 17755424 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 17561544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 12708128 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
    2014-03-20 23:02 - 2014-03-20 23:02 - 11636176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 09728064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 03143456 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 02958792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 02783008 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 02411976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433523.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 01516488 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433523.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 00892704 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 00877856 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 00863064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 00846168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
    2014-03-19 00:17 - 2014-03-19 00:28 - 00105472 _____ () C:\Users\Raph\Downloads\coriejuniel_resume.pub
    2014-03-19 00:15 - 2014-03-19 00:16 - 00105472 _____ () C:\Users\Raph\Downloads\corie_resume.pub
    2014-03-18 23:58 - 2014-03-18 23:58 - 00105472 _____ () C:\Users\Raph\Documents\corie resume.pub
    2014-03-18 19:01 - 2014-03-18 19:01 - 00000000 ____D () C:\Windows\System32\Tasks\Games
    2014-03-15 17:09 - 2014-03-15 17:09 - 00000000 ____D () C:\Users\Raph\Downloads\John Legend - Love in the Future [Deluxe Version] (2013)
    2014-03-15 16:57 - 2014-03-15 16:57 - 00000000 ____D () C:\Users\Raph\Downloads\Marvin Sapp - I Win (2012)
    2014-03-12 14:28 - 2014-03-01 01:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2014-03-12 14:28 - 2014-03-01 00:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2014-03-12 14:28 - 2014-03-01 00:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2014-03-12 14:28 - 2014-02-28 23:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2014-03-12 14:28 - 2014-02-28 23:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2014-03-12 14:28 - 2014-02-28 23:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2014-03-12 14:28 - 2014-02-28 23:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2014-03-12 14:28 - 2014-02-28 23:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2014-03-12 14:28 - 2014-02-28 23:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2014-03-12 14:28 - 2014-02-28 23:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2014-03-12 14:28 - 2014-02-28 23:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2014-03-12 14:28 - 2014-02-28 23:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2014-03-12 14:28 - 2014-02-28 23:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2014-03-12 14:28 - 2014-02-28 23:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2014-03-12 14:28 - 2014-02-28 23:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2014-03-12 14:28 - 2014-02-28 23:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2014-03-12 14:28 - 2014-02-28 23:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2014-03-12 14:28 - 2014-02-28 22:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2014-03-12 14:28 - 2014-02-28 22:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2014-03-12 14:28 - 2014-02-28 22:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2014-03-12 14:28 - 2014-02-28 22:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2014-03-12 14:28 - 2014-02-28 22:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2014-03-12 14:28 - 2014-02-28 22:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2014-03-12 14:28 - 2014-02-28 22:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2014-03-12 14:28 - 2014-02-28 22:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2014-03-12 14:28 - 2014-02-28 22:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2014-03-12 14:28 - 2014-02-28 22:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2014-03-12 14:28 - 2014-02-28 22:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2014-03-12 14:28 - 2014-02-28 22:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2014-03-12 14:28 - 2014-02-28 22:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2014-03-12 14:28 - 2014-02-28 22:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2014-03-12 14:28 - 2014-02-28 22:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2014-03-12 14:28 - 2014-02-28 22:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2014-03-12 14:28 - 2014-02-28 22:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2014-03-12 14:28 - 2014-02-28 21:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2014-03-12 14:28 - 2014-02-28 21:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2014-03-12 14:28 - 2014-02-28 21:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2014-03-12 14:28 - 2014-02-28 21:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2014-03-12 14:28 - 2014-02-28 21:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2014-03-12 14:28 - 2014-02-28 21:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2014-03-12 14:28 - 2014-02-06 20:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2014-03-12 14:28 - 2014-02-03 21:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
    2014-03-12 14:28 - 2014-02-03 21:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
    2014-03-12 14:28 - 2014-01-28 21:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
    2014-03-12 14:28 - 2014-01-28 21:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
    2014-03-12 14:28 - 2014-01-27 21:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
    2014-03-12 14:27 - 2014-02-03 21:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
    2014-03-12 14:27 - 2014-02-03 21:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
    2014-03-11 17:02 - 2014-03-11 17:02 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
    2014-03-10 21:24 - 2014-03-19 09:46 - 00009529 _____ () C:\Users\Raph\Documents\bydgns.xspf
    2014-03-06 11:33 - 2014-03-30 20:14 - 00000000 ____D () C:\Users\Raph\Downloads\The Nut Job 2014 HDCAM x264 AC3 TiTAN
     
    ==================== One Month Modified Files and Folders =======
     
    2014-04-05 18:18 - 2014-04-05 18:18 - 00018129 _____ () C:\Users\Raph\Downloads\FRST.txt
    2014-04-05 18:18 - 2014-04-05 18:17 - 00000000 ____D () C:\FRST
    2014-04-05 18:16 - 2014-04-05 18:16 - 02157056 _____ (Farbar) C:\Users\Raph\Downloads\FRST64.exe
    2014-04-05 17:56 - 2013-10-14 22:40 - 00000000 ____D () C:\Users\Raph\AppData\Roaming\uTorrent
    2014-04-05 17:49 - 2014-03-23 02:37 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2014-04-05 17:34 - 2009-07-14 00:13 - 00876042 _____ () C:\Windows\system32\PerfStringBackup.INI
    2014-04-05 17:25 - 2014-01-04 12:27 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
    2014-04-05 12:31 - 2013-10-14 23:50 - 01553950 _____ () C:\Windows\WindowsUpdate.log
    2014-04-05 11:50 - 2014-03-30 20:40 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2014-04-05 07:49 - 2014-03-23 02:37 - 00000890 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2014-04-04 22:27 - 2009-07-13 23:51 - 00081439 _____ () C:\Windows\setupact.log
    2014-04-04 19:51 - 2009-07-13 23:45 - 00029616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2014-04-04 19:51 - 2009-07-13 23:45 - 00029616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2014-04-04 19:42 - 2014-04-04 12:26 - 00003358 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-4097332094-2714983402-552182644-1000
    2014-04-04 19:42 - 2013-11-20 18:39 - 00003222 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-4097332094-2714983402-552182644-1000
    2014-04-04 19:41 - 2013-10-15 00:02 - 00000000 ____D () C:\ProgramData\NVIDIA
    2014-04-04 19:41 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
    2014-04-04 19:08 - 2014-03-30 20:39 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2014-04-04 19:08 - 2014-03-30 13:00 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
    2014-04-04 12:24 - 2013-10-14 22:03 - 00000000 ____D () C:\Users\Raph
    2014-04-04 12:22 - 2014-03-27 14:04 - 00000000 ____D () C:\Windows\symbols
    2014-04-04 12:22 - 2014-03-27 11:01 - 00000000 ____D () C:\Users\Raph\AppData\Roaming\vlc
    2014-04-04 12:22 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\NDF
    2014-04-04 12:21 - 2013-10-14 22:36 - 00000000 ____D () C:\ProgramData\Norton
    2014-04-04 12:21 - 2013-10-14 22:11 - 00000000 ___HD () C:\SuperChargerProfile
    2014-04-04 12:21 - 2009-07-14 00:32 - 00000000 ____D () C:\Program Files\MSBuild
    2014-04-04 12:21 - 2009-07-13 22:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
    2014-04-04 12:20 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\registration
    2014-04-04 12:14 - 2014-04-02 18:21 - 00000000 ____D () C:\ProgramData\PreEmptive Solutions
    2014-04-04 12:14 - 2014-03-27 14:37 - 00000000 ____D () C:\Program Files\Microsoft SQL Server
    2014-04-04 12:14 - 2013-10-14 22:42 - 00000000 ____D () C:\ProgramData\Real
    2014-04-04 12:12 - 2014-03-27 14:06 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 10.0
    2014-04-04 12:10 - 2014-03-27 14:36 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server
    2014-04-04 06:29 - 2014-04-04 06:29 - 00000166 _____ () C:\Users\Raph\Documents\emailpw.txt
    2014-04-03 09:51 - 2014-03-30 20:39 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
    2014-04-03 09:51 - 2014-03-30 20:39 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2014-04-03 09:50 - 2014-03-30 20:39 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
    2014-04-02 09:06 - 2014-04-02 09:06 - 00000000 ____D () C:\ProgramData\RSA
    2014-04-02 09:05 - 2014-04-02 09:05 - 00000000 ____D () C:\Users\Raph\AppData\Local\RSA
    2014-04-02 09:05 - 2014-04-02 09:05 - 00000000 ____D () C:\Program Files (x86)\RSA SecurID Token Common
    2014-04-02 09:05 - 2014-04-02 09:05 - 00000000 ____D () C:\Program Files (x86)\RSA SecurID Software Token
    2014-04-02 09:04 - 2014-04-02 09:04 - 12518912 _____ () C:\Users\Raph\Downloads\RSASecurIDToken410.msi
    2014-04-02 09:00 - 2014-04-02 09:00 - 01527104 _____ (LogMeIn, Inc.) C:\Users\Raph\Downloads\Support-LogMeInRescue.exe
    2014-04-01 21:48 - 2014-03-24 08:51 - 00000000 ____D () C:\Program Files (x86)\Belarc
    2014-04-01 21:38 - 2014-04-01 21:38 - 00282312 _____ () C:\Windows\Minidump\040114-57174-01.dmp
    2014-04-01 21:38 - 2014-04-01 21:38 - 00000000 ____D () C:\Windows\Minidump
    2014-04-01 21:37 - 2014-04-01 21:37 - 534141396 _____ () C:\Windows\MEMORY.DMP
    2014-03-31 13:54 - 2014-03-31 13:54 - 00000000 ____D () C:\Users\Raph\AppData\Roaming\webex
    2014-03-31 13:54 - 2014-03-31 13:53 - 00000000 ____D () C:\ProgramData\WebEx
    2014-03-31 13:53 - 2014-03-31 13:53 - 00187176 _____ (Cisco WebEx LLC) C:\Users\Raph\Downloads\,staffmanagement,1607416503,-1933870862,MC,0-0,AAAAAcW0eDY3eIJvS7Pms0ns2-PWe1Aul7zVGJ83BXH4hAr30_webex.exe
    2014-03-31 07:44 - 2014-03-23 02:37 - 00003890 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
    2014-03-31 07:44 - 2014-03-23 02:37 - 00003638 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
    2014-03-31 07:03 - 2010-11-20 22:47 - 00206950 _____ () C:\Windows\PFRO.log
    2014-03-30 21:43 - 2013-12-15 20:15 - 00000000 ____D () C:\ProgramData\Microsoft Help
    2014-03-30 21:16 - 2009-07-13 21:34 - 00000478 _____ () C:\Windows\win.ini
    2014-03-30 21:14 - 2014-03-30 21:14 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
    2014-03-30 21:14 - 2014-03-30 21:14 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
    2014-03-30 21:06 - 2014-03-27 12:57 - 00003200 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-4097332094-2714983402-552182644-1000
    2014-03-30 21:05 - 2014-03-30 21:05 - 00003336 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-4097332094-2714983402-552182644-1000
    2014-03-30 20:59 - 2014-03-27 10:58 - 00000000 ____D () C:\Users\Raph\AppData\Local\GCC
    2014-03-30 20:59 - 2013-10-14 22:43 - 00000000 ____D () C:\Users\Raph\AppData\Local\TidyNetwork
    2014-03-30 20:25 - 2014-03-27 10:58 - 00000000 ____D () C:\ProgramData\pastaleads
    2014-03-30 20:22 - 2014-03-30 20:22 - 00000000 ____D () C:\Users\Raph\AppData\Local\SearchProtect
    2014-03-30 20:14 - 2014-03-27 10:58 - 00000000 ____D () C:\Program Files (x86)\pastaleads
    2014-03-30 20:14 - 2014-03-27 08:09 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
    2014-03-30 20:14 - 2014-03-06 11:33 - 00000000 ____D () C:\Users\Raph\Downloads\The Nut Job 2014 HDCAM x264 AC3 TiTAN
    2014-03-30 20:14 - 2014-02-25 19:18 - 00000000 ____D () C:\Users\Raph\Documents\PEMDAS_files
    2014-03-30 20:14 - 2014-02-21 20:47 - 00000000 ____D () C:\Users\Raph\Downloads\47.Ronin.2013.CAM.HCSUBS.MP4.AAC.X264-P2P
    2014-03-30 20:14 - 2014-02-11 12:04 - 00000000 ____D () C:\Users\Raph\Downloads\The.Hobbit-The.Desolation.of.Smaug.2013.mp4-KOB
    2014-03-30 20:14 - 2013-11-20 07:11 - 00000000 ____D () C:\Users\Raph\Downloads\Convert X to DVD v4.1.19.365 Including Keys [h33t][iahq76]
    2014-03-30 20:14 - 2013-10-15 00:02 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
    2014-03-30 20:14 - 2013-10-15 00:02 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
    2014-03-30 20:14 - 2010-11-21 02:16 - 00000000 ___RD () C:\Users\Public\Recorded TV
    2014-03-30 20:14 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\AppCompat
    2014-03-30 20:13 - 2014-03-27 14:25 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
    2014-03-30 20:07 - 2013-12-10 13:34 - 00000000 ____D () C:\Users\Raph\Documents\Fax
    2014-03-30 20:01 - 2014-03-27 14:04 - 00000000 ____D () C:\Program Files (x86)\Microsoft SDKs
    2014-03-30 20:01 - 2013-12-15 20:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
    2014-03-30 14:11 - 2014-03-30 13:43 - 00000000 ____D () C:\AdwCleaner
    2014-03-30 13:00 - 2014-03-30 13:00 - 00000000 ____D () C:\ProgramData\Malwarebytes
    2014-03-30 07:47 - 2013-11-18 08:03 - 00026112 ___SH () C:\Users\Raph\Documents\Thumbs.db
    2014-03-28 13:58 - 2014-03-28 13:57 - 00000000 ____D () C:\Users\Raph\AppData\Local\NPE
    2014-03-27 20:08 - 2014-03-27 20:08 - 00000000 ____D () C:\Users\Default\Documents\Visual Studio 2010
    2014-03-27 20:08 - 2014-03-27 20:08 - 00000000 ____D () C:\Users\Default User\Documents\Visual Studio 2010
    2014-03-27 19:14 - 2014-03-27 19:14 - 00000000 ____D () C:\Users\Raph\Documents\Visual Studio 2008
    2014-03-27 18:54 - 2014-03-27 18:54 - 00000000 ____D () C:\ProgramData\VS
    2014-03-27 18:16 - 2014-03-27 18:16 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8
    2014-03-27 15:40 - 2014-03-27 15:40 - 00000200 _____ () C:\Users\Raph\Documents\winkeymso2010.txt
    2014-03-27 15:35 - 2014-03-27 15:35 - 06957280 _____ (Microsoft Corporation) C:\Users\Raph\Downloads\Silverlight.exe
    2014-03-27 15:02 - 2014-03-27 14:18 - 00000000 ____D () C:\Users\Raph\Documents\Visual Studio 2010
    2014-03-27 14:58 - 2014-03-27 14:58 - 00000000 ____D () C:\Users\Raph\AppData\Roaming\Microsoft Corporation
    2014-03-27 14:45 - 2014-03-27 14:45 - 00000000 ____D () C:\Windows\system32\RsFx
    2014-03-27 14:44 - 2014-03-27 14:44 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 9.0
    2014-03-27 14:43 - 2014-03-27 14:07 - 00000000 ____D () C:\Windows\SysWOW64\1033
    2014-03-27 14:43 - 2014-03-27 14:04 - 00000000 ____D () C:\Windows\system32\1033
    2014-03-27 14:36 - 2014-03-27 14:04 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 10.0
    2014-03-27 14:35 - 2014-03-27 14:35 - 00000000 ____D () C:\Program Files\Microsoft Sync Framework
    2014-03-27 14:34 - 2014-03-27 14:34 - 00000000 ____D () C:\Program Files\Microsoft Synchronization Services
    2014-03-27 14:34 - 2014-03-27 14:34 - 00000000 ____D () C:\Program Files\Microsoft SQL Server Compact Edition
    2014-03-27 14:34 - 2014-03-27 14:34 - 00000000 ____D () C:\Program Files (x86)\Microsoft Synchronization Services
    2014-03-27 14:34 - 2014-03-27 14:34 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
    2014-03-27 14:22 - 2014-03-27 14:22 - 00000000 ____D () C:\Program Files\IIS
    2014-03-27 14:22 - 2014-03-27 14:22 - 00000000 ____D () C:\Program Files (x86)\Microsoft ASP.NET
    2014-03-27 14:22 - 2014-03-27 14:22 - 00000000 ____D () C:\Program Files (x86)\IIS
    2014-03-27 14:11 - 2014-03-27 14:06 - 00000000 ____D () C:\Program Files (x86)\Microsoft F#
    2014-03-27 14:09 - 2014-03-27 14:06 - 00000000 ____D () C:\Program Files (x86)\HTML Help Workshop
    2014-03-27 14:06 - 2009-07-14 00:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
    2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 ____D () C:\Program Files\Microsoft Help Viewer
    2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 9.0
    2014-03-27 13:15 - 2014-03-27 13:15 - 00003136 _____ () C:\Windows\System32\Tasks\{C52BFAAC-4F6C-40F5-87D7-098D3F727788}
    2014-03-27 12:07 - 2014-03-27 12:07 - 00003124 _____ () C:\Windows\System32\Tasks\{81328C64-A1ED-4CEC-B107-5D7D82409D5D}
    2014-03-27 11:23 - 2014-03-27 11:23 - 00000000 ____D () C:\Windows\System32\Tasks\Norton 360
    2014-03-27 11:17 - 2013-10-14 22:37 - 00000000 ____D () C:\Windows\system32\Drivers\N360x64
    2014-03-27 11:15 - 2013-10-14 22:37 - 00003206 _____ () C:\Windows\System32\Tasks\Norton WSC Integration
    2014-03-27 11:10 - 2013-10-15 00:02 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
    2014-03-27 10:58 - 2014-03-27 10:58 - 00004566 _____ () C:\Windows\System32\Tasks\GC_Informer
    2014-03-27 10:58 - 2014-03-27 10:58 - 00004550 _____ () C:\Windows\System32\Tasks\GC_Scheduler
    2014-03-27 10:58 - 2013-10-19 22:18 - 00001066 _____ () C:\Users\Public\Desktop\VLC media player.lnk
    2014-03-27 10:32 - 2014-03-27 08:33 - 00000000 ____D () C:\Program Files (x86)\PureLeads
    2014-03-27 08:39 - 2014-03-27 08:39 - 00000000 ____D () C:\Users\Raph\AppData\Roaming\Oracle
    2014-03-27 08:38 - 2014-03-27 08:38 - 00000000 ____D () C:\ProgramData\Sun
    2014-03-27 08:38 - 2014-03-27 08:38 - 00000000 ____D () C:\ProgramData\Oracle
    2014-03-27 08:37 - 2014-03-27 08:38 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
    2014-03-27 08:37 - 2014-03-27 08:37 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
    2014-03-27 08:37 - 2014-03-27 08:37 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
    2014-03-27 08:37 - 2014-03-27 08:37 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
    2014-03-27 08:37 - 2014-03-27 08:37 - 00000000 ____D () C:\Program Files (x86)\Java
    2014-03-27 08:33 - 2014-03-27 08:33 - 00000000 ____D () C:\ProgramData\PureLeads
    2014-03-27 08:33 - 2014-03-27 08:33 - 00000000 ____D () C:\Program Files (x86)\DownloadXCtrl.com
    2014-03-23 02:38 - 2014-03-23 02:38 - 00002255 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
    2014-03-23 02:38 - 2014-03-23 02:36 - 00000000 ____D () C:\Users\Raph\AppData\Local\Google
    2014-03-23 02:37 - 2014-03-23 02:37 - 00000000 ____D () C:\Program Files (x86)\Google
    2014-03-23 02:36 - 2013-11-20 10:51 - 00000000 ____D () C:\Users\Raph\AppData\Local\Deployment
    2014-03-20 23:03 - 2014-03-20 23:03 - 15783992 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
    2014-03-20 23:03 - 2014-03-20 23:03 - 11589272 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
    2014-03-20 23:03 - 2014-03-20 23:03 - 09690424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
    2014-03-20 23:03 - 2013-10-14 23:54 - 18302384 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 31474976 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 25255256 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 23716640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 17755424 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 17561544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 12708128 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
    2014-03-20 23:02 - 2014-03-20 23:02 - 11636176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 09728064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 03143456 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 02958792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 02783008 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 02411976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433523.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 01516488 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433523.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 00892704 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 00877856 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 00863064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 00846168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
    2014-03-20 23:02 - 2013-10-27 09:12 - 14709720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
    2014-03-20 23:02 - 2013-10-14 23:54 - 03093280 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
    2014-03-20 23:02 - 2013-10-14 23:54 - 02715264 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
    2014-03-20 23:02 - 2013-10-14 23:54 - 00024544 _____ () C:\Windows\system32\nvinfo.pb
    2014-03-19 09:46 - 2014-03-10 21:24 - 00009529 _____ () C:\Users\Raph\Documents\bydgns.xspf
    2014-03-19 00:28 - 2014-03-19 00:17 - 00105472 _____ () C:\Users\Raph\Downloads\coriejuniel_resume.pub
    2014-03-19 00:16 - 2014-03-19 00:15 - 00105472 _____ () C:\Users\Raph\Downloads\corie_resume.pub
    2014-03-18 23:58 - 2014-03-18 23:58 - 00105472 _____ () C:\Users\Raph\Documents\corie resume.pub
    2014-03-18 19:01 - 2014-03-18 19:01 - 00000000 ____D () C:\Windows\System32\Tasks\Games
    2014-03-18 15:18 - 2013-10-15 01:00 - 00000000 ____D () C:\Windows\system32\MRT
    2014-03-18 15:16 - 2013-10-15 01:00 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2014-03-15 17:09 - 2014-03-15 17:09 - 00000000 ____D () C:\Users\Raph\Downloads\John Legend - Love in the Future [Deluxe Version] (2013)
    2014-03-15 16:57 - 2014-03-15 16:57 - 00000000 ____D () C:\Users\Raph\Downloads\Marvin Sapp - I Win (2012)
    2014-03-12 15:35 - 2009-07-13 23:45 - 00497968 _____ () C:\Windows\system32\FNTCACHE.DAT
    2014-03-11 21:25 - 2014-01-04 12:27 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2014-03-11 21:25 - 2013-10-14 22:54 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2014-03-11 21:25 - 2013-10-14 22:54 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2014-03-11 17:03 - 2013-10-14 22:54 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
    2014-03-11 17:02 - 2014-03-11 17:02 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
    2014-03-08 21:38 - 2014-03-05 21:11 - 00011459 ____H () C:\Users\Raph\Documents\~WRL0350.tmp
    2014-03-06 11:31 - 2013-10-17 09:03 - 00000000 ____D () C:\Users\Raph\Desktop\My Shared Folder
     
    Some content of TEMP:
    ====================
    C:\Users\Raph\AppData\Local\Temp\devcon64.exe
    C:\Users\Raph\AppData\Local\Temp\ose00000.exe
     
     
    ==================== Bamital & volsnap Check =================
     
    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\rpcss.dll => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
     
     
    LastRegBack: 2014-03-30 00:13
     
    ==================== End Of Log ============================
     
     
    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014
    Ran by Raph at 2014-04-05 18:18:21
    Running from C:\Users\Raph\Downloads
    Boot Mode: Normal
    ==========================================================
     
     
    ==================== Security Center ========================
     
    AV: Norton 360 (Enabled - Up to date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB}
    AS: Norton 360 (Enabled - Up to date) {631E4324-D31C-783F-EC5C-35AD42B18466}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    FW: Norton 360 (Enabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0}
     
    ==================== Installed Programs ======================
     
    µTorrent (HKCU\...\uTorrent) (Version: 3.3.2.30303 - BitTorrent Inc.)
    2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
    2007 Microsoft Office Suite Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
    3D Volcano ScreenSaver (HKLM-x32\...\{A86C7DF6-DB0F-4C78-8D15-D22DFC9D5A5F}) (Version: 1.0.2 - InstallX, LLC)
    Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated)
    Adobe Reader XI (11.0.06) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
    Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.0.150 - Adobe Systems, Inc.)
    AMD APP SDK Runtime (Version: 10.0.873.1 - Advanced Micro Devices Inc.) Hidden
    AMD Catalyst Install Manager (HKLM\...\{DD562794-C098-A1E5-66ED-10E8BD1C84C5}) (Version: 3.0.864.0 - Advanced Micro Devices, Inc.)
    AMD Fuel (Version: 2012.0504.1554.26509 - Advanced Micro Devices, Inc.) Hidden
    Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    Ares 3.1.7.3042 (HKLM-x32\...\{C9FF844C-02F5-4221-8AD4-0BD823533C6E}_is1) (Version: 3.1.7.3042 - Ares)
    Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.10.1.0 - Asmedia Technology)
    Baggin the Dragon Home Ed v2 (HKLM-x32\...\Baggin the Dragon Home Ed v2) (Version: 2.0.9 - EdAlive)
    Bing Bar (HKLM-x32\...\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)
    Bing Desktop (HKLM-x32\...\{7D095455-D971-4D4C-9EFD-9AF6A6584F3A}) (Version: 1.3.347.0 - Microsoft Corporation)
    Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
    Catalyst Control Center (x32 Version: 2012.0504.1554.26509 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center InstallProxy (x32 Version: 2012.0504.1554.26509 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Localization All (x32 Version: 2012.0504.1554.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Chinese Standard (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Chinese Traditional (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Czech (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Danish (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Dutch (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help English (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Finnish (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help French (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help German (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Greek (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Hungarian (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Italian (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Japanese (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Korean (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Norwegian (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Polish (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Portuguese (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Russian (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Spanish (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Swedish (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Thai (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Turkish (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    ccc-utility64 (Version: 2012.0504.1554.26509 - Advanced Micro Devices, Inc.) Hidden
    Contents (x32 Version: 16.0.0.106 - Corel Corporation) Hidden
    ConvertXtoDVD 4.1.19.365 (HKLM-x32\...\{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1) (Version: 4.1.19.365 - )
    Corel VideoStudio Pro X6 (HKLM-x32\...\_{6688A246-F6E8-48AD-9806-8D5832E9F15D}) (Version: 16.0.0.106 - Corel Corporation)
    Crystal Reports for Visual Studio (x32 Version: 12.51.0.240 - SAP) Hidden
    Dotfuscator Software Services - Community Edition (HKLM-x32\...\{1AA5BD63-6614-44B2-88A7-605191EDB835}) (Version: 5.0.2500.0 - PreEmptive Solutions)
    DownloadX ActiveX Download Control 1.6.7 (HKLM-x32\...\CA17A131-B7D9-41D6-868F-29A9BD9FCC8E_is1) (Version:  - DownloadXCtrl.com)
    Dropbox (HKCU\...\Dropbox) (Version: 2.4.7 - Dropbox, Inc.)
    GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden
    GigaClicks Crawler (HKLM-x32\...\GigaClicks Crawler) (Version: 19.0.0.62 - GigaClicks Inc.) <==== ATTENTION
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 33.0.1750.154 - Google Inc.)
    Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden
    ICA (x32 Version: 16.0.0.106 - Corel Corporation) Hidden
    iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.)
    ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden
    IPM_VS_Pro (x32 Version: 16.0 - Corel Corporation) Hidden
    iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
    Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle)
    Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
    Living Marine Aquarium 2 (HKLM-x32\...\{3C9D2B2E-53A2-4098-B931-2621C5D9822B}) (Version: 1.0.2 - InstallX, LLC)
    Malwarebytes Anti-Malware version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation)
    Math Detective A1 (HKLM-x32\...\Math Detective A1) (Version: 1.6.0.0 - The Critical Thinking Co.)
    Math Detective Beginning (HKLM-x32\...\Math Detective Beginning) (Version: 1.5.0.0 - The Critical Thinking Co.)
    Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation)
    Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
    Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
    Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
    Microsoft Application Error Reporting (x32 Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
    Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools (HKLM-x32\...\{40416836-56CC-4C0E-A6AF-5C34BADCE483}) (Version: 2.0.50217.0 - Microsoft Corporation)
    Microsoft ASP.NET MVC 2 (HKLM-x32\...\{1803A630-3C38-4D2B-9B9A-0CB37243539C}) (Version: 2.0.50217.0 - Microsoft Corporation)
    Microsoft Help Viewer 1.1 (HKLM\...\Microsoft Help Viewer 1.1) (Version: 1.1.40219 - Microsoft Corporation)
    Microsoft Help Viewer 1.1 (Version: 1.1.40219 - Microsoft Corporation) Hidden
    Microsoft Office Access MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Access Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
    Microsoft Office Groove MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Groove Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office InfoPath MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office OneNote MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Outlook MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
    Microsoft Office Publisher MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
    Microsoft Silverlight 3 SDK (HKLM-x32\...\{2012098D-EEE9-4769-8DD3-B038050854D4}) (Version: 3.0.40818.0 - Microsoft Corporation)
    Microsoft Silverlight 4 SDK (HKLM-x32\...\{05855322-BE43-41FE-B583-D3AE0C326D58}) (Version: 4.0.50826.0 - Microsoft Corporation)
    Microsoft SQL Server 2008 (64-bit) (HKLM\...\Microsoft SQL Server 10 Release) (Version:  - Microsoft Corporation)
    Microsoft SQL Server 2008 (64-bit) (Version:  - Microsoft Corporation) Hidden
    Microsoft SQL Server 2008 Browser (HKLM-x32\...\{C688457E-03FD-4941-923B-A27F4D42A7DD}) (Version: 10.3.5500.0 - Microsoft Corporation)
    Microsoft SQL Server 2008 Common Files (Version: 10.3.5500.0 - Microsoft Corporation) Hidden
    Microsoft SQL Server 2008 Database Engine Services (Version: 10.3.5500.0 - Microsoft Corporation) Hidden
    Microsoft SQL Server 2008 Database Engine Shared (Version: 10.3.5500.0 - Microsoft Corporation) Hidden
    Microsoft SQL Server 2008 Native Client (HKLM\...\{2738C4AA-420E-4E13-ADEF-B5AB250E3EF1}) (Version: 10.3.5500.0 - Microsoft Corporation)
    Microsoft SQL Server 2008 R2 Data-Tier Application Framework (HKLM-x32\...\{BC537AE0-88AF-47ED-B762-33B0D62B5188}) (Version: 10.50.1750.9 - Microsoft Corporation)
    Microsoft SQL Server 2008 R2 Data-Tier Application Project (HKLM-x32\...\{7A56D81D-6406-40E7-9184-8AC1769C4D69}) (Version: 10.50.1750.9 - Microsoft Corporation)
    Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\...\{77F1F8AD-51B8-4490-AEEC-BF480073E0FC}) (Version: 10.50.1750.9 - Microsoft Corporation)
    Microsoft SQL Server 2008 R2 Management Objects (x64) (HKLM\...\{EAEBF166-B06A-4D7F-BAF7-6615303D5C7C}) (Version: 10.50.1750.9 - Microsoft Corporation)
    Microsoft SQL Server 2008 R2 Transact-SQL Language Service (HKLM-x32\...\{09C52940-A4D1-4409-A7CC-1AAE630CF578}) (Version: 10.50.1750.9 - Microsoft Corporation)
    Microsoft SQL Server 2008 RsFx Driver (Version: 10.3.5500.0 - Microsoft Corporation) Hidden
    Microsoft SQL Server 2008 Setup Support Files  (HKLM\...\{6292D514-17A4-403F-98F9-E150F10C043D}) (Version: 10.3.5500.0 - Microsoft Corporation)
    Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
    Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
    Microsoft SQL Server Database Publishing Wizard 1.4 (HKLM-x32\...\{ACE28263-76A4-4BF5-B6F4-8BD719595969}) (Version: 10.1.2512.8 - Microsoft Corporation)
    Microsoft SQL Server System CLR Types (HKLM-x32\...\{877B76B2-F83F-4F5A-B28D-3F398641ADB6}) (Version: 10.50.1750.9 - Microsoft Corporation)
    Microsoft SQL Server System CLR Types (x64) (HKLM\...\{1E6ED082-E32D-4B2B-8B6A-70B094815135}) (Version: 10.50.1750.9 - Microsoft Corporation)
    Microsoft SQL Server VSS Writer (HKLM\...\{0826F9E4-787E-481D-83E0-BC6A57B056D5}) (Version: 10.3.5500.0 - Microsoft Corporation)
    Microsoft Sync Framework Runtime v1.0 SP1 (x64) (HKLM\...\{8438EC02-B8A9-462D-AC72-1B521349C001}) (Version: 1.0.3010.0 - Microsoft Corporation)
    Microsoft Sync Framework SDK v1.0 SP1 (HKLM-x32\...\{0E3DFC64-CC49-4BE2-8C9C-58EF129675DB}) (Version: 1.0.3010.0 - Microsoft Corporation)
    Microsoft Sync Framework Services v1.0 SP1 (x64) (HKLM\...\{034106B5-54B7-467F-B477-5B7DBB492624}) (Version: 1.0.3010.0 - Microsoft Corporation)
    Microsoft Sync Services for ADO.NET v2.0 SP1 (x64) (HKLM\...\{1D1CEEF8-3741-45BD-8E77-963E1DEBDDD3}) (Version: 2.0.3010.0 - Microsoft Corporation)
    Microsoft Team Foundation Server 2010 Object Model - ENU (HKLM\...\Microsoft Team Foundation Server 2010 Object Model - ENU) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Team Foundation Server 2010 Object Model - ENU (Version: 10.0.40219 - Microsoft Corporation) Hidden
    Microsoft Visual C++  Compilers 2010 Standard - enu - x64 (Version: 10.0.40219 - Microsoft Corporation) Hidden
    Microsoft Visual C++  Compilers 2010 Standard - enu - x86 (x32 Version: 10.0.40219 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 (HKLM-x32\...\{B7E38540-E355-3503-AFD7-635B2F2F76E1}) (Version: 9.0.30729.4974 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x64 Designtime - 10.0.30319 (HKLM\...\{F5079164-1DB9-3BDA-853B-F78AF67CE071}) (Version: 10.0.30319 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x64 Runtime - 10.0.40219 (HKLM\...\{1C7C8AAF-A16D-32E8-89E5-F6D165DE0BCE}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x86 Runtime - 10.0.40219 (HKLM-x32\...\{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual F# 2.0 Runtime (HKLM-x32\...\{85467CBC-7A39-33C9-8940-D72D9269B84F}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (HKLM-x32\...\{14DD7530-CCD2-3798-B37D-3839ED6A441C}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual Studio 2010 IntelliTrace Collection (x64) (HKLM\...\{88BAE373-00F4-3E33-828F-96E89E5E0CB9}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual Studio 2010 Office Developer Tools (x64) (Version: 10.0.40219 - Microsoft Corporation) Hidden
    Microsoft Visual Studio 2010 Performance Collection Tools SP1 - ENU (Version: 10.0.40219 - Microsoft Corporation) Hidden
    Microsoft Visual Studio 2010 Service Pack 1 (HKLM-x32\...\Microsoft Visual Studio 2010 Service Pack 1) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual Studio 2010 Service Pack 1 (x32 Version: 10.0.40219 - Microsoft Corporation) Hidden
    Microsoft Visual Studio 2010 SharePoint Developer Tools (x32 Version: 10.0.40219 - Microsoft Corporation) Hidden
    Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.31007 - Microsoft Corporation)
    Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.31010 - Microsoft Corporation) Hidden
    Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.40308 - Microsoft Corporation) Hidden
    Microsoft Visual Studio 2010 Ultimate - ENU (HKLM-x32\...\Microsoft Visual Studio 2010 Ultimate - ENU) (Version: 10.0.30319 - Microsoft Corporation)
    Microsoft Visual Studio 2010 Ultimate - ENU (x32 Version: 10.0.40219 - Microsoft Corporation) Hidden
    Microsoft Visual Studio Macro Tools (HKLM-x32\...\Microsoft Visual Studio Macro Tools) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual Studio Macro Tools (x32 Version: 9.0.30729 - Microsoft Corporation) Hidden
    MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
    My Amazing Human Body (HKLM-x32\...\{12CA5656-44F2-4F01-AE05-B1BF746D9373}) (Version: 1.1 - )
    neroxml (x32 Version: 1.0.0 - Nero AG) Hidden
    Norton 360 (HKLM-x32\...\N360) (Version: 21.2.0.38 - Symantec Corporation)
    NVIDIA 3D Vision Controller Driver 331.58 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 331.58 - NVIDIA Corporation)
    NVIDIA 3D Vision Driver 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 335.23 - NVIDIA Corporation)
    NVIDIA Control Panel 335.23 (Version: 335.23 - NVIDIA Corporation) Hidden
    NVIDIA GeForce Experience 1.7 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.7 - NVIDIA Corporation)
    NVIDIA Graphics Driver 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 335.23 - NVIDIA Corporation)
    NVIDIA Install Application (Version: 2.1002.145.1024 - NVIDIA Corporation) Hidden
    NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden
    NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden
    NVIDIA PhysX System Software 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation)
    NVIDIA ShadowPlay 9.3.16 (Version: 9.3.16 - NVIDIA Corporation) Hidden
    NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3523 - NVIDIA Corporation) Hidden
    NVIDIA Update 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation)
    NVIDIA Update Components (Version: 9.3.16 - NVIDIA Corporation) Hidden
    NVIDIA Virtual Audio 1.2.9 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.9 - NVIDIA Corporation)
    PastaQuotes (HKLM-x32\...\pastaleads) (Version: 1.0.0.3 - PastaLeads)
    PowerISO (HKLM-x32\...\PowerISO) (Version: 5.8 - Power Software Ltd)
    PureLeads (HKLM-x32\...\PureLeads) (Version: 2.0.17 - PureLeads)
    QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
    Reader for PC (HKLM-x32\...\{71FB3127-E6B2-4058-ACEE-99813554FAB6}) (Version: 2.2.00.11270 - Sony Corporation)
    RealDownloader (x32 Version: 1.3.3 - RealNetworks, Inc.) Hidden
    RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
    RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
    RealPlayer (HKLM-x32\...\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks)
    Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.53.216.2012 - Realtek)
    RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
    RSA SecurID Software Token (HKLM-x32\...\{1E7941DC-32F1-467D-8351-8955A038A76E}) (Version: 4.1.1 - RSA, The Security Division of EMC)
    Search Protect (HKLM-x32\...\SearchProtect) (Version: 2.12.10.97 - Conduit) <==== ATTENTION
    Service Pack 3 for SQL Server 2008 (KB2546951) (64-bit) (HKLM\...\KB2546951) (Version: 10.3.5500.0 - Microsoft Corporation)
    Setup (x32 Version: 16.0.0.106 - Corel Corporation) Hidden
    Share (x32 Version: 16.0.0.106 - Corel Corporation) Hidden
    Share64 (Version: 16.0.0.106 - Corel Corporation) Hidden
    SHIELD Streaming (Version: 1.6.34 - NVIDIA Corporation) Hidden
    SmartSound Common Data (HKLM-x32\...\InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.)
    SmartSound Common Data (x32 Version: 1.1.0 - SmartSound Software Inc.) Hidden
    SmartSound Quicktracks 5 (HKLM-x32\...\InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.6 - SmartSound Software Inc.)
    SmartSound Quicktracks 5 (x32 Version: 5.1.6 - SmartSound Software Inc.) Hidden
    Sql Server Customer Experience Improvement Program (Version: 10.3.5500.0 - Microsoft Corporation) Hidden
    Super-Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.012 - MSI)
    swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
    TidyNetwork (HKCU\...\TidyNetwork) (Version:  - TidyNetwork)
    Ultimate Math Invaders Home Ed v2 (HKLM-x32\...\Ultimate Math Invaders Home Ed v2) (Version: 2.0.9 - EdAlive)
    Unity Web Player (HKCU\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
    Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 Help for Common Features (KB963673) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{AB365889-0395-4FAD-B702-CA5985D53D42}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6FAA03BD-2B51-4029-9AD9-64A3B8E3C84C}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
    Update for Microsoft Office Access 2007 Help (KB963663) (HKLM-x32\...\{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{6B76A18A-AA1E-42AB-A7AD-6C84BBB43987}) (Version:  - Microsoft)
    Update for Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{199DF7B6-169C-448C-B511-1054101BE9C9}) (Version:  - Microsoft)
    Update for Microsoft Office Infopath 2007 Help (KB963662) (HKLM-x32\...\{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{716B81B8-B13C-41DF-8EAC-7A2F656CAB63}) (Version:  - Microsoft)
    Update for Microsoft Office OneNote 2007 Help (KB963670) (HKLM-x32\...\{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2744EF05-38E1-4D5D-B333-E021EDAEA245}) (Version:  - Microsoft)
    Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{ED38F8A3-4F61-494E-8BCA-E3AC7760C924}) (Version:  - Microsoft)
    Update for Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{0451F231-E3E3-4943-AB9F-58EB96171784}) (Version:  - Microsoft)
    Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2878234) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{EC1934B0-AE0F-4BBD-8955-54BB3247ED9E}) (Version:  - Microsoft)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{397B1D4F-ED7B-4ACA-A637-43B670843876}) (Version:  - Microsoft)
    Update for Microsoft Office Publisher 2007 Help (KB963667) (HKLM-x32\...\{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2E40DE55-B289-4C8B-8901-5D369B16814F}) (Version:  - Microsoft)
    Update for Microsoft Office Script Editor Help (KB963671) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{CD11C6A2-FFC6-4271-8EAB-79C3582F505C}) (Version:  - Microsoft)
    Update for Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{80E762AA-C921-4839-9D7D-DB62A72C0726}) (Version:  - Microsoft)
    Visual Studio 2010 Prerequisites - English (HKLM\...\{662014D2-0450-37ED-ABAE-157C88127BEB}) (Version: 10.0.40219 - Microsoft Corporation)
    Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{112C23F2-C036-4D40-BED4-0CB47BF5555C}) (Version: 4.0.8080.0 - Microsoft Corporation)
    VLC media player 2.1.2 (HKLM-x32\...\VLC media player) (Version: 2.1.2 - VideoLAN)
    VSClassic (x32 Version: 16.0.0.106 - Corel Corporation) Hidden
    VSHelp (x32 Version: 16.0.0.106 - Corel Corporation) Hidden
    VSPro (x32 Version: 16.0.0.106 - Corel Corporation) Hidden
    WCF RIA Services V1.0 SP1 (HKLM-x32\...\{D9E6001A-5DC3-4620-AF7A-80B6CD48645D}) (Version: 4.1.60114.0 - Microsoft Corporation)
    Web Deployment Tool (HKLM\...\{0F37D969-1260-419E-B308-EF7D29ABDE20}) (Version: 1.1.0618 - Microsoft Corporation)
    Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version:  - )
    Windows Media Encoder 9 Series (x32 Version: 9.00.2980 - Microsoft Corporation) Hidden
    Yahoo! Toolbar (HKLM-x32\...\Yahoo! Companion) (Version:  - Yahoo! Inc.)
    Yenka (HKLM-x32\...\Yenka) (Version: 3.4.2.0 - Crocodile Clips Ltd)
     
    ==================== Restore Points  =========================
     
    02-04-2014 14:04:58 Installed RSA SecurID Software Token.
    02-04-2014 22:32:31 Windows Update
    03-04-2014 13:41:54 Windows Update
    04-04-2014 09:57:11 Restore Operation
     
    ==================== Hosts content: ==========================
     
    2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
     
    ==================== Scheduled Tasks (whitelisted) =============
     
    Task: {0D8A44FC-FE46-4776-97E5-0836162EDE1F} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\21.2.0.38\SymErr.exe [2014-01-30] (Symantec Corporation)
    Task: {138D9425-AF13-45AC-B689-9EAA931761D2} - System32\Tasks\Games\UpdateCheck_S-1-5-21-4097332094-2714983402-552182644-1000
    Task: {3466B582-D74F-4090-B442-420E481642D1} - System32\Tasks\TidyNetwork Update => C:\Users\Raph\AppData\Local\TidyNetwork\petnupdate.exe
    Task: {42FAECE4-54EE-4D67-B359-271E55736BE2} - System32\Tasks\GC_Informer => %LOCALAPPDATA%\GCC\Controller.exe <==== ATTENTION
    Task: {520DE4E0-E4ED-426E-9A9C-8A44DC965821} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-4097332094-2714983402-552182644-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14] (RealNetworks, Inc.)
    Task: {57600876-8597-47F2-83FD-2E41333EE940} - System32\Tasks\Microsoft\Windows\Maintenance\UP_Scheduler => %LOCALAPPDATA%\GCC\Controller.exe <==== ATTENTION
    Task: {65BBFC5D-8755-4B1A-8018-441F28AF7DEC} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\21.2.0.38\SymErr.exe [2014-01-30] (Symantec Corporation)
    Task: {6CEBAF6F-ECDE-4159-948A-912723102A8E} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-4097332094-2714983402-552182644-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
    Task: {6EFF8D5B-1BE4-4DFE-AA83-12194DAFC3F7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-23] (Google Inc.)
    Task: {79F3B02B-3A5F-45B4-90E0-777C46BD48DC} - System32\Tasks\GC_Scheduler => %LOCALAPPDATA%\GCC\Controller.exe <==== ATTENTION
    Task: {7B3FE32D-03C6-4789-B50E-8241BE422041} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-4097332094-2714983402-552182644-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2013-08-14] (RealNetworks, Inc.)
    Task: {859CF20D-6E0B-414D-A803-5BAAA34EE625} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-23] (Google Inc.)
    Task: {89C0FA91-738A-45CF-8599-CD2404A2D9A6} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\21.2.0.38\WSCStub.exe [2014-03-11] (Symantec Corporation)
    Task: {A16B8228-2735-40F1-87D1-78A7175180CC} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
    Task: {C2FDA0B1-1D8C-4462-A1FA-999D9DDF647C} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-4097332094-2714983402-552182644-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14] (RealNetworks, Inc.)
    Task: {C943AA98-3D80-4602-8C65-F04DEF6DC14D} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-4097332094-2714983402-552182644-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
    Task: {E5B7A502-2AE9-4EB9-917E-9180CABE7A0B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-11] (Adobe Systems Incorporated)
    Task: {F70ACD85-F8F8-4864-A3EC-B2226F587289} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe [2013-11-20] (Apple Inc.)
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
     
    ==================== Loaded Modules (whitelisted) =============
     
    2012-05-04 15:41 - 2012-05-04 15:41 - 00211968 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll
    2011-11-13 14:30 - 2011-11-13 14:30 - 00676864 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll
    2011-11-13 14:31 - 2011-11-13 14:31 - 03643392 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll
    2013-10-15 00:02 - 2014-03-04 08:05 - 00116056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
    2014-03-14 00:55 - 2014-03-14 00:55 - 00491008 _____ () C:\Users\Raph\AppData\Local\GCC\Controller.exe
    2014-03-18 07:35 - 2014-03-18 07:35 - 00027032 _____ () C:\Program Files (x86)\pastaleads\PastaLeadsWinApp.exe
    2014-03-18 07:34 - 2014-03-18 07:34 - 00361368 _____ () C:\Program Files (x86)\pastaleads\PastaLeadsService.exe
    2013-08-14 15:19 - 2013-08-14 15:19 - 00039056 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
    2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    2013-09-14 01:51 - 2013-09-14 01:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\zlib1.dll
    2013-09-14 01:50 - 2013-09-14 01:50 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\libxml2.dll
    2013-11-27 21:48 - 2013-11-27 21:48 - 00880640 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\fsk.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00040264 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskMediaPlayers.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00239944 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\Fskin.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00026952 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskinLocalize.dll
    2013-11-26 12:34 - 2013-11-26 12:34 - 00798720 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskSecurity.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00125256 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskDocumentViewer.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00016200 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskPower.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00024904 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskNetInterface.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00017224 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskMobileMediaDevice.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00015176 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskTimeHardware.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00034632 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ticket.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00018760 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ebookDeviceNotifier.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00092488 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ebookUsb.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00149832 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\readerAppHelper.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00178504 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\USBDetector.dll
    2014-03-27 11:00 - 2013-12-03 21:48 - 04055504 _____ () C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\pdf.dll
    2014-03-27 11:00 - 2013-12-03 21:48 - 00399312 _____ () C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\ppgooglenaclpluginchrome.dll
    2014-03-27 11:00 - 2013-12-03 21:47 - 01619408 _____ () C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\ffmpegsumo.dll
    2013-08-13 07:15 - 2013-08-13 07:15 - 00206336 _____ () C:\Users\Raph\AppData\Local\Temp\{70C549E1-2F18-4BD8-820E-8DE33F90228B}\{DDC15C3C-64A9-45CC-9DCF-FBB22BE849E2}\Default\Extensions\jmiibbdogibcphdfkkmlimfffneaecbc\2.4_0\plugin\convenience.dll
    2014-03-23 02:38 - 2014-03-14 19:50 - 00051016 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\chrome_elf.dll
    2014-03-23 02:38 - 2014-03-14 19:50 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\libglesv2.dll
    2014-03-23 02:38 - 2014-03-14 19:50 - 00100168 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\libegl.dll
    2014-03-23 02:38 - 2014-03-14 19:50 - 04061000 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll
    2014-03-23 02:38 - 2014-03-14 19:50 - 00394568 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll
    2014-03-23 02:38 - 2014-03-14 19:50 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ffmpegsumo.dll
     
    ==================== Alternate Data Streams (whitelisted) =========
     
     
    ==================== Safe Mode (whitelisted) ===================
     
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\plsapp => ""="service"
     
    ==================== Disabled items from MSCONFIG ==============
     
     
    ==================== Faulty Device Manager Devices =============
     
     
    ==================== Event log errors: =========================
     
    Application errors:
    ==================
    Error: (04/05/2014 03:17:11 PM) (Source: SideBySide) (User: )
    Description: Activation context generation failed for "rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1".
    Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.
     
    Error: (04/05/2014 03:17:11 PM) (Source: SideBySide) (User: )
    Description: Activation context generation failed for "rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1".
    Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.
     
    Error: (04/05/2014 10:10:16 AM) (Source: SideBySide) (User: )
    Description: Activation context generation failed for "rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1".
    Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.
     
    Error: (04/05/2014 10:10:16 AM) (Source: SideBySide) (User: )
    Description: Activation context generation failed for "rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1".
    Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.
     
    Error: (04/05/2014 09:30:33 AM) (Source: SideBySide) (User: )
    Description: Activation context generation failed for "rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1".
    Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.
     
    Error: (04/05/2014 09:30:33 AM) (Source: SideBySide) (User: )
    Description: Activation context generation failed for "rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1".
    Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.
     
    Error: (04/05/2014 05:31:25 AM) (Source: Customer Experience Improvement Program) (User: )
    Description: 80004005
     
    Error: (04/05/2014 04:51:23 AM) (Source: SideBySide) (User: )
    Description: Activation context generation failed for "rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1".
    Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.
     
    Error: (04/05/2014 04:51:23 AM) (Source: SideBySide) (User: )
    Description: Activation context generation failed for "rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1".
    Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
    Please use sxstrace.exe for detailed diagnosis.
     
    Error: (04/05/2014 04:48:09 AM) (Source: Customer Experience Improvement Program) (User: )
    Description: 80004005
     
     
    System errors:
    =============
    Error: (04/05/2014 03:51:07 PM) (Source: Service Control Manager) (User: )
    Description: The PlsvcV2 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
     
    Error: (04/05/2014 11:49:56 AM) (Source: Service Control Manager) (User: )
    Description: The PlsvcV2 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
     
    Error: (04/05/2014 07:48:46 AM) (Source: Service Control Manager) (User: )
    Description: The PlsvcV2 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
     
    Error: (04/05/2014 03:47:37 AM) (Source: Service Control Manager) (User: )
    Description: The PlsvcV2 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
     
    Error: (04/04/2014 11:46:29 PM) (Source: Service Control Manager) (User: )
    Description: The PlsvcV2 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
     
    Error: (04/04/2014 07:48:37 PM) (Source: DCOM) (User: Raph-PC)
    Description: machine-defaultLocalActivation{3EEF301F-B596-4C0B-BD92-013BEAFCE793}{3EEF301F-B596-4C0B-BD92-013BEAFCE793}Raph-PCRaphS-1-5-21-4097332094-2714983402-552182644-1000LocalHost (Using LRPC)
     
    Error: (04/04/2014 07:42:43 PM) (Source: Service Control Manager) (User: )
    Description: The SQL Server (SQLEXPRESS) service failed to start due to the following error: 
    %%1053
     
    Error: (04/04/2014 07:42:43 PM) (Source: Service Control Manager) (User: )
    Description: A timeout was reached (30000 milliseconds) while waiting for the SQL Server (SQLEXPRESS) service to connect.
     
    Error: (04/04/2014 04:30:29 PM) (Source: Service Control Manager) (User: )
    Description: The PlsvcV2 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
     
    Error: (04/04/2014 00:32:18 PM) (Source: DCOM) (User: Raph-PC)
    Description: machine-defaultLocalActivation{3EEF301F-B596-4C0B-BD92-013BEAFCE793}{3EEF301F-B596-4C0B-BD92-013BEAFCE793}Raph-PCRaphS-1-5-21-4097332094-2714983402-552182644-1000LocalHost (Using LRPC)
     
     
    Microsoft Office Sessions:
    =========================
    Error: (02/27/2014 00:14:07 PM) (Source: Microsoft Office 12 Sessions)(User: )
    Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6612.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 2766 seconds with 960 seconds of active time.  This session ended with a crash.
     
     
    ==================== Memory info =========================== 
     
    Percentage of memory in use: 25%
    Total physical RAM: 16354.13 MB
    Available physical RAM: 12247.64 MB
    Total Pagefile: 32706.43 MB
    Available Pagefile: 28457.24 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.79 MB
     
    ==================== Drives ================================
     
    Drive c: () (Fixed) (Total:232.79 GB) (Free:118.83 GB) NTFS
    Drive e: (OneTouch4 Plus) (Fixed) (Total:698.64 GB) (Free:132.99 GB) NTFS
     
    ==================== MBR & Partition Table ==================
     
    ========================================================
    Disk: 0 (Size: 699 GB) (Disk ID: 31257BD1)
    Partition 1: (Active) - (Size=699 GB) - (Type=07 NTFS)
     
    ========================================================
    Disk: 1 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 92636A50)
    Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=233 GB) - (Type=07 NTFS)
     
    ==================== End Of Log ============================

    • 0

    #4
    Buddierdl

    Buddierdl

      Trusted Helper

    • Malware Removal
    • 2,524 posts

    Okay, let's start with this:

     

    You have the following Peer-to-Peer program(s) installed:
     
    uTorrent
     
    GeeksToGo does not recommend using such programs, but you should read the description of Peer-to-Peer programs below before deciding for yourself.
     
    Description of Peer-to-Peer (P2P) software.
    P2P(Peer-to-Peer) may be a great way to get lots of seemingly freeware, but it is a great way to get infected as well. The program(s) may be safe, but there's no way to tell if the file being shared is infected. P2P programs, more often than not, install adware and/or spyware and worse still, some worms spread via P2P networks, infecting you as well.
    Once upon a time, P2P file sharing was fairly safe. This is no longer true. P2P programs form a direct conduit inside your computer, their security measures are easily circumvented, and malware writers are increasingly exploiting them to spread their wares on to your computer. If your P2P program is not configured correctly, your computer may also be sharing more files than you realize. There have been cases where people's passwords, address books and other personal, private, and financial details have been exposed to a file sharing network by a badly configured program.
     
    If you need convincing, please read these short reports on the dangers of peer-2-peer programs and file sharing.
    We advise removing any P2P programs you have now and avoiding this type of software application. Whether you remove them or not is your decision. But if you decide to keep and use Peer-to-Peer programs I can guarantee that you will be coming back to this forum or another malware forum. If you do choose to keep the program(s), please do not use it / them until the computer is clean and I give the all clear.
     
     
    Step 1:Uninstalls.
     
    Please uninstall the following programs using the Programs and Features menu of the Control Panel, unless you use them and installed them purposefully.
    •  
    • GigaClicks Crawler
    • Pasta Quotes
    • Pure Leads
    • Tidy Network
     
     
    Step 2: Run JRT.
     
    thisisujrt.gif  Please download Junkware Removal Tool to your desktop.
    •  
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
     
     
    Step 3: Run MiniToolbox.
     
    Please download MiniToolBox, save it to your desktop and run it.
     
    Checkmark the following checkboxes:
    •  
    • Flush DNS
    • Report IE Proxy Settings
    • Reset IE Proxy Settings
    • Report FF Proxy Settings
    • Reset FF Proxy Settings
    • List content of Hosts
    • List IP configuration
    • List Winsock Entries
     
    Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.
     
    Note: When using "Reset FF Proxy Settings" option Firefox should be closed.
     
    Step 4: Get a fresh FRST scan.
     
    Please run FRST again and post a fresh scan for me. Please check the "Addition" check box, so that the addition.txt log is created again.
     
    Things I need in your next reply:
    •  
    • JRT log
    • MiniToolbox log
    • new FRST logs
    • How is your computer running now?
     

    • 0

    #5
    moviebuff6000

    moviebuff6000

      New Member

    • Topic Starter
    • Member
    • Pip
    • 6 posts

    Thank you so much. I had uninstalled these programs before. It seems the system store allows them to reinstall since it was on my PC during the last properly functioning configuration. I did everything you told me and have cut and pasted the txt files below. It seems everything is working like it should.

     

     

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Thisisu
    Version: 6.1.4 (04.06.2014:1)
    OS: Windows 7 Home Premium x64
    Ran by Raph on Tue 04/08/2014 at  7:52:10.77
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     
     
     
     
    ~~~ Services
     
     
     
    ~~~ Registry Values
     
    Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
    Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
    Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
    Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
    Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
    Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
    Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-4097332094-2714983402-552182644-1000\Software\Microsoft\Internet Explorer\Main\\Start Page
     
     
     
    ~~~ Registry Keys
     
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\yt.ytnavassistplugin
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\yt.ytnavassistplugin.1
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
    Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
    Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
    Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\searchprotect
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\searchprotect
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
     
     
     
    ~~~ Files
     
     
     
    ~~~ Folders
     
    Successfully deleted: [Folder] "C:\Program Files (x86)\searchprotect"
     
     
     
    ~~~ Event Viewer Logs were cleared
     
     
     
     
     
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on Tue 04/08/2014 at  8:04:27.82
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     
     
     

    MiniToolBox by Farbar  Version: 23-01-2014
    Ran by Raph (administrator) on 08-04-2014 at 08:29:46
    Running from "C:\Users\Raph\Downloads"
    Microsoft Windows 7 Home Premium  Service Pack 1 (X64)
    Boot Mode: Normal
    ***************************************************************************
     
    ========================= Flush DNS: ===================================
     
    Windows IP Configuration
     
    Successfully flushed the DNS Resolver Cache.
     
    ========================= IE Proxy Settings: ============================== 
     
    Proxy is not enabled.
    No Proxy Server is set.
     
    "Reset IE Proxy Settings": IE Proxy Settings were reset.
    ========================= Hosts content: =================================
     
     
     
    ========================= IP Configuration: ================================
     
    Realtek PCIe GBE Family Controller = Local Area Connection (Connected)
     
     
    # ----------------------------------
    # IPv4 Configuration
    # ----------------------------------
    pushd interface ipv4
     
    reset
    set global icmpredirects=enabled
     
     
    popd
    # End of IPv4 configuration
     
     
     
    Windows IP Configuration
     
       Host Name . . . . . . . . . . . . : Raph-PC
       Primary Dns Suffix  . . . . . . . : 
       Node Type . . . . . . . . . . . . : Hybrid
       IP Routing Enabled. . . . . . . . : No
       WINS Proxy Enabled. . . . . . . . : No
       DNS Suffix Search List. . . . . . : home.network
     
    Ethernet adapter Local Area Connection:
     
       Connection-specific DNS Suffix  . : home.network
       Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller
       Physical Address. . . . . . . . . : D4-3D-7E-33-D8-BD
       DHCP Enabled. . . . . . . . . . . : Yes
       Autoconfiguration Enabled . . . . : Yes
       Link-local IPv6 Address . . . . . : fe80::3055:667d:8138:576e%11(Preferred) 
       IPv4 Address. . . . . . . . . . . : 10.0.0.2(Preferred) 
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Lease Obtained. . . . . . . . . . : Tuesday, April 08, 2014 8:15:33 AM
       Lease Expires . . . . . . . . . . : Tuesday, April 15, 2014 8:15:33 AM
       Default Gateway . . . . . . . . . : 10.0.0.1
       DHCP Server . . . . . . . . . . . : 10.0.0.1
       DHCPv6 IAID . . . . . . . . . . . : 248790398
       DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-19-EE-6A-D5-D4-3D-7E-33-D8-BD
       DNS Servers . . . . . . . . . . . : 75.75.76.76
                                           75.75.75.75
       NetBIOS over Tcpip. . . . . . . . : Enabled
     
    Tunnel adapter isatap.home.network:
     
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . : home.network
       Description . . . . . . . . . . . : Microsoft ISATAP Adapter
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
     
    Tunnel adapter Teredo Tunneling Pseudo-Interface:
     
       Connection-specific DNS Suffix  . : 
       Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
       Link-local IPv6 Address . . . . . : fe80::4c:1eea:b3e0:e684%12(Preferred) 
       Default Gateway . . . . . . . . . : 
       DHCPv6 IAID . . . . . . . . . . . : 301989888
       DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-19-EE-6A-D5-D4-3D-7E-33-D8-BD
       NetBIOS over Tcpip. . . . . . . . : Disabled
    DNS request timed out.
        timeout was 2 seconds.
    Server:  UnKnown
    Address:  75.75.76.76
     
    Name:    google.com
    Addresses:  2607:f8b0:4000:802::1006
     173.194.115.72
     173.194.115.67
     173.194.115.69
     173.194.115.68
     173.194.115.78
     173.194.115.73
     173.194.115.64
     173.194.115.66
     173.194.115.71
     173.194.115.70
     173.194.115.65
     
     
    Pinging google.com [74.125.225.225] with 32 bytes of data:
    Reply from 74.125.225.225: bytes=32 time=12ms TTL=55
    Reply from 74.125.225.225: bytes=32 time=12ms TTL=55
     
    Ping statistics for 74.125.225.225:
        Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 12ms, Maximum = 12ms, Average = 12ms
    Server:  cdns02.comcast.net
    Address:  75.75.76.76
     
    DNS request timed out.
        timeout was 2 seconds.
    Name:    yahoo.com
    Addresses:  98.138.253.109
     98.139.183.24
     206.190.36.45
     
     
    Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
    Reply from 98.139.183.24: bytes=32 time=58ms TTL=47
    Reply from 98.139.183.24: bytes=32 time=61ms TTL=47
     
    Ping statistics for 98.139.183.24:
        Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 58ms, Maximum = 61ms, Average = 59ms
     
    Pinging 127.0.0.1 with 32 bytes of data:
    Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
    Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
     
    Ping statistics for 127.0.0.1:
        Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 0ms, Maximum = 0ms, Average = 0ms
    ===========================================================================
    Interface List
     11...d4 3d 7e 33 d8 bd ......Realtek PCIe GBE Family Controller
      1...........................Software Loopback Interface 1
     13...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
     12...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
    ===========================================================================
     
    IPv4 Route Table
    ===========================================================================
    Active Routes:
    Network Destination        Netmask          Gateway       Interface  Metric
              0.0.0.0          0.0.0.0         10.0.0.1         10.0.0.2     10
             10.0.0.0    255.255.255.0         On-link          10.0.0.2    266
             10.0.0.2  255.255.255.255         On-link          10.0.0.2    266
           10.0.0.255  255.255.255.255         On-link          10.0.0.2    266
            127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
            127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
      127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
            224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
            224.0.0.0        240.0.0.0         On-link          10.0.0.2    266
      255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      255.255.255.255  255.255.255.255         On-link          10.0.0.2    266
    ===========================================================================
    Persistent Routes:
      None
     
    IPv6 Route Table
    ===========================================================================
    Active Routes:
     If Metric Network Destination      Gateway
      1    306 ::1/128                  On-link
     11    266 fe80::/64                On-link
     12    306 fe80::/64                On-link
     12    306 fe80::4c:1eea:b3e0:e684/128
                                        On-link
     11    266 fe80::3055:667d:8138:576e/128
                                        On-link
      1    306 ff00::/8                 On-link
     12    306 ff00::/8                 On-link
     11    266 ff00::/8                 On-link
    ===========================================================================
    Persistent Routes:
      None
    ========================= Winsock entries =====================================
     
    Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
    Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
    Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
    Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
    Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
    Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
    Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
    x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
    x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
    x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
    x64-Catalog5 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
    x64-Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.)
    x64-Catalog9 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog9 02 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog9 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog9 04 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog9 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog9 06 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog9 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog9 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog9 09 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog9 10 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
     
    **** End of log ****
     
     

    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 (ATTENTION: ====> FRST version is 26 days old and could be outdated)
    Ran by Raph (administrator) on RAPH-PC on 08-04-2014 08:10:23
    Running from C:\Users\Raph\Downloads
    Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
    Internet Explorer Version 11
    Boot Mode: Normal
     
    The only official download link for FRST:
    Download link from any site other than Bleeping Computer is unpermitted or outdated.
     
    ==================== Processes (Whitelisted) =================
     
    (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
    () C:\Users\Raph\AppData\Local\GCC\Controller.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
    (MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
    (MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
    (Sony Corporation) C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe
    (Power Software Ltd) C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
    (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
    (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe
    (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.2.0.38\N360.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.2.0.38\N360.exe
    (Protexis Inc.) c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
    () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
    (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    (Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
    () C:\Users\Raph\AppData\Local\GCC\Controller.exe
    (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDExtHost.exe
    (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDAppHost.exe
    (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDRuntimeHost.exe
    (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
    (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe
    (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe
    (Google Inc.) C:\Users\Raph\AppData\Local\GCC\Chrome-bin\chrome.exe
    (Google Inc.) C:\Users\Raph\AppData\Local\GCC\Chrome-bin\chrome.exe
    (Google Inc.) C:\Users\Raph\AppData\Local\GCC\Chrome-bin\chrome.exe
    (Google Inc.) C:\Users\Raph\AppData\Local\GCC\Chrome-bin\chrome.exe
     
     
    ==================== Registry (Whitelisted) ==================
     
    HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6548112 2012-06-12] (Realtek Semiconductor)
    HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-10-17] (NVIDIA Corporation)
    HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap64.dll [1063200 2013-10-17] (NVIDIA Corporation)
    HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [630912 2012-05-04] (Advanced Micro Devices, Inc.)
    HKLM-x32\...\Run: [Super-Charger] - C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [495616 2012-07-27] (MSI)
    HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [295512 2013-10-14] (RealNetworks, Inc.)
    HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
    HKLM-x32\...\Run: [Reader Application Helper] - C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe [899400 2013-11-27] (Sony Corporation)
    HKLM-x32\...\Run: [PWRISOVM.EXE] - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [337432 2013-10-23] (Power Software Ltd)
    HKLM-x32\...\Run: [] - [X]
    HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
    HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
    HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
    HKLM-x32\...\Run: [BingDesktop] - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2353880 2013-11-01] (Microsoft Corp.)
    HKU\S-1-5-21-4097332094-2714983402-552182644-1000\...\Run: [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
    HKU\S-1-5-21-4097332094-2714983402-552182644-1000\...\Run: [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.)
    HKU\S-1-5-21-4097332094-2714983402-552182644-1000\...\Run: [AppleIEDAV] - C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleIEDAV.exe [1326408 2013-11-15] (Apple Inc.)
    AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll File Not Found
     
    ==================== Internet (Whitelisted) ====================
     
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://t.msn.com/
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x822AA7130051CF01
    BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine64\21.2.0.38\coIEPlg.dll (Symantec Corporation)
    BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
    BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
    BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\21.2.0.38\coIEPlg.dll (Symantec Corporation)
    BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\21.2.0.38\IPS\IPSBHO.DLL (Symantec Corporation)
    BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
    BHO-x32: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
    BHO-x32: PETN - {B8107FB2-1A17-4277-B9E0-EDC058A2D774} - C:\Users\Raph\AppData\Local\TidyNetwork\petn.dll No File
    BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
    BHO-x32: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    BHO-x32: Microsoft Web Test Recorder 10.0 Helper - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
    Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.2.0.38\coIEPlg.dll (Symantec Corporation)
    Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
    Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.2.0.38\coIEPlg.dll (Symantec Corporation)
    Toolbar: HKLM-x32 - No Name - {EF99BD32-C1FB-11D2-892F-0090271D4F88} -  No File
    Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
    Toolbar: HKCU - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.2.0.38\coIEPlg.dll (Symantec Corporation)
    DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab
    DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab
    Tcpip\Parameters: [DhcpNameServer] 75.75.76.76 75.75.75.75
     
    Chrome: 
    =======
    CHR DefaultSearchKeyword: bing.com
    CHR DefaultSearchProvider: Bing
    CHR DefaultNewTabURL: 
    CHR Extension: (RealDownloader) - C:\Users\Raph\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-03-23]
    CHR Extension: (Norton Identity Protection) - C:\Users\Raph\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2014-03-23]
    CHR Extension: (Google Wallet) - C:\Users\Raph\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-23]
    CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
    CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\21.2.0.38\Exts\Chrome.crx [2014-03-27]
     
    ==================== Services (Whitelisted) =================
     
    R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-05-04] (Advanced Micro Devices, Inc.)
    R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173272 2013-11-01] (Microsoft Corp.)
    R2 HPSLPSVC; C:\Users\Raph\AppData\Local\Temp\7zS0906\hpslpsvc64.dll [1039360 2013-07-19] (Hewlett-Packard Co.)
    R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
    R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
    R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [136704 2012-06-29] (MSI)
    S2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [58345832 2011-09-22] (Microsoft Corporation)
    R2 N360; C:\Program Files (x86)\Norton 360\Engine\21.2.0.38\N360.exe [265040 2014-03-12] (Symantec Corporation)
    R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15122208 2013-10-17] (NVIDIA Corporation)
    R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
    S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [431464 2011-09-22] (Microsoft Corporation)
     
    ==================== Drivers (Whitelisted) ====================
     
    R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [55936 2011-11-13] (Advanced Micro Devices)
    R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\21.0.2.1\Definitions\BASHDefs\20140319.001\BHDrvx64.sys [1525976 2014-03-18] (Symantec Corporation)
    R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1502000.026\ccSetx64.sys [162392 2013-09-25] (Symantec Corporation)
    R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-11-21] (Symantec Corporation)
    R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2013-11-21] (Symantec Corporation)
    R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\21.0.2.1\Definitions\IPSDefs\20140405.001\IDSvia64.sys [525016 2014-04-03] (Symantec Corporation)
    R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
    R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-05] (Malwarebytes Corporation)
    R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
    R3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\21.0.2.1\Definitions\VirusDefs\20140407.024\ENG64.SYS [126040 2014-04-04] (Symantec Corporation)
    R3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\21.0.2.1\Definitions\VirusDefs\20140407.024\EX64.SYS [2099288 2014-04-04] (Symantec Corporation)
    R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-27] (NVIDIA Corporation)
    R1 SRTSP; C:\Windows\System32\Drivers\N360x64\1502000.026\SRTSP64.SYS [875736 2014-02-12] (Symantec Corporation)
    R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1502000.026\SRTSPX64.SYS [36952 2013-07-30] (Symantec Corporation)
    R0 SymDS; C:\Windows\System32\drivers\N360x64\1502000.026\SYMDS64.SYS [493656 2013-07-31] (Symantec Corporation)
    R0 SymEFA; C:\Windows\System32\drivers\N360x64\1502000.026\SYMEFA64.SYS [1148120 2014-03-03] (Symantec Corporation)
    R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-10-14] (Symantec Corporation)
    R1 SymIRON; C:\Windows\system32\drivers\N360x64\1502000.026\Ironx64.SYS [264280 2013-07-30] (Symantec Corporation)
    R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1502000.026\SYMNETS.SYS [593112 2014-02-17] (Symantec Corporation)
    S3 MSICDSetup; \??\D:\CDriver64.sys [X]
    S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]
     
    ==================== NetSvcs (Whitelisted) ===================
     
     
    ==================== One Month Created Files and Folders ========
     
    2014-04-08 08:10 - 2014-04-08 08:10 - 00015710 _____ () C:\Users\Raph\Downloads\FRST.txt
    2014-04-08 08:05 - 2014-04-08 08:05 - 00982016 _____ (Farbar) C:\Users\Raph\Downloads\MiniToolBox.exe
    2014-04-08 08:04 - 2014-04-08 08:04 - 00003085 _____ () C:\Users\Raph\Desktop\JRT.txt
    2014-04-08 07:52 - 2014-04-08 07:52 - 00000000 ____D () C:\Windows\ERUNT
    2014-04-08 07:51 - 2014-04-08 07:51 - 01016261 _____ (Thisisu) C:\Users\Raph\Downloads\JRT.exe
    2014-04-05 18:18 - 2014-04-05 18:22 - 00044150 _____ () C:\Users\Raph\Downloads\Addition.txt
    2014-04-05 18:17 - 2014-04-08 08:10 - 00000000 ____D () C:\FRST
    2014-04-05 18:16 - 2014-04-05 18:16 - 02157056 _____ (Farbar) C:\Users\Raph\Downloads\FRST64.exe
    2014-04-04 12:26 - 2014-04-04 19:42 - 00003358 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-4097332094-2714983402-552182644-1000
    2014-04-04 06:29 - 2014-04-04 06:29 - 00000166 _____ () C:\Users\Raph\Documents\emailpw.txt
    2014-04-02 18:21 - 2014-04-04 12:14 - 00000000 ____D () C:\ProgramData\PreEmptive Solutions
    2014-04-02 17:43 - 2011-09-22 21:07 - 00105832 _____ (Microsoft Corporation) C:\Windows\system32\SQSRVRES.DLL
    2014-04-02 17:43 - 2011-09-22 21:06 - 00109416 _____ (Microsoft Corporation) C:\Windows\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.3.5500.0.dll
    2014-04-02 17:43 - 2011-09-22 17:18 - 00073064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perf-MSSQL$SQLEXPRESS-sqlctr10.3.5500.0.dll
    2014-04-02 09:06 - 2014-04-02 09:06 - 00000000 ____D () C:\ProgramData\RSA
    2014-04-02 09:05 - 2014-04-02 09:05 - 00000000 ____D () C:\Users\Raph\AppData\Local\RSA
    2014-04-02 09:05 - 2014-04-02 09:05 - 00000000 ____D () C:\Program Files (x86)\RSA SecurID Token Common
    2014-04-02 09:05 - 2014-04-02 09:05 - 00000000 ____D () C:\Program Files (x86)\RSA SecurID Software Token
    2014-04-02 09:04 - 2014-04-02 09:04 - 12518912 _____ () C:\Users\Raph\Downloads\RSASecurIDToken410.msi
    2014-04-02 09:00 - 2014-04-02 09:00 - 01527104 _____ (LogMeIn, Inc.) C:\Users\Raph\Downloads\Support-LogMeInRescue.exe
    2014-04-01 21:38 - 2014-04-01 21:38 - 00282312 _____ () C:\Windows\Minidump\040114-57174-01.dmp
    2014-04-01 21:38 - 2014-04-01 21:38 - 00000000 ____D () C:\Windows\Minidump
    2014-04-01 21:37 - 2014-04-01 21:37 - 534141396 _____ () C:\Windows\MEMORY.DMP
    2014-03-31 13:54 - 2014-03-31 13:54 - 00000000 ____D () C:\Users\Raph\AppData\Roaming\webex
    2014-03-31 13:53 - 2014-03-31 13:54 - 00000000 ____D () C:\ProgramData\WebEx
    2014-03-31 13:53 - 2014-03-31 13:53 - 00187176 _____ (Cisco WebEx LLC) C:\Users\Raph\Downloads\,staffmanagement,1607416503,-1933870862,MC,0-0,AAAAAcW0eDY3eIJvS7Pms0ns2-PWe1Aul7zVGJ83BXH4hAr30_webex.exe
    2014-03-30 21:14 - 2014-03-30 21:14 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
    2014-03-30 21:14 - 2014-03-30 21:14 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
    2014-03-30 21:05 - 2014-04-06 21:05 - 00003336 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-4097332094-2714983402-552182644-1000
    2014-03-30 20:40 - 2014-04-05 11:50 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2014-03-30 20:39 - 2014-04-04 19:08 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2014-03-30 20:39 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
    2014-03-30 20:39 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2014-03-30 20:39 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
    2014-03-30 20:22 - 2014-03-30 20:22 - 00000000 ____D () C:\Users\Raph\AppData\Local\SearchProtect
    2014-03-30 13:43 - 2014-03-30 14:11 - 00000000 ____D () C:\AdwCleaner
    2014-03-30 13:00 - 2014-04-04 19:08 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
    2014-03-30 13:00 - 2014-03-30 13:00 - 00000000 ____D () C:\ProgramData\Malwarebytes
    2014-03-28 13:57 - 2014-03-28 13:58 - 00000000 ____D () C:\Users\Raph\AppData\Local\NPE
    2014-03-27 20:08 - 2014-03-27 20:08 - 00000000 ____D () C:\Users\Default\Documents\Visual Studio 2010
    2014-03-27 20:08 - 2014-03-27 20:08 - 00000000 ____D () C:\Users\Default User\Documents\Visual Studio 2010
    2014-03-27 19:14 - 2014-03-27 19:14 - 00000000 ____D () C:\Users\Raph\Documents\Visual Studio 2008
    2014-03-27 18:54 - 2014-03-27 18:54 - 00000000 ____D () C:\ProgramData\VS
    2014-03-27 18:16 - 2014-03-27 18:16 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8
    2014-03-27 15:40 - 2014-03-27 15:40 - 00000200 _____ () C:\Users\Raph\Documents\winkeymso2010.txt
    2014-03-27 15:35 - 2014-03-27 15:35 - 06957280 _____ (Microsoft Corporation) C:\Users\Raph\Downloads\Silverlight.exe
    2014-03-27 14:58 - 2014-03-27 14:58 - 00000000 ____D () C:\Users\Raph\AppData\Roaming\Microsoft Corporation
    2014-03-27 14:47 - 2009-07-22 03:17 - 00078872 _____ (Microsoft Corporation) C:\Windows\system32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll
    2014-03-27 14:47 - 2009-07-22 03:17 - 00050200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.1.2531.0.dll
    2014-03-27 14:45 - 2014-03-27 14:45 - 00000000 ____D () C:\Windows\system32\RsFx
    2014-03-27 14:44 - 2014-03-27 14:44 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 9.0
    2014-03-27 14:37 - 2014-04-04 12:14 - 00000000 ____D () C:\Program Files\Microsoft SQL Server
    2014-03-27 14:36 - 2014-04-04 12:10 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server
    2014-03-27 14:35 - 2014-03-27 14:35 - 00000000 ____D () C:\Program Files\Microsoft Sync Framework
    2014-03-27 14:34 - 2014-03-27 14:34 - 00000000 ____D () C:\Program Files\Microsoft Synchronization Services
    2014-03-27 14:34 - 2014-03-27 14:34 - 00000000 ____D () C:\Program Files\Microsoft SQL Server Compact Edition
    2014-03-27 14:34 - 2014-03-27 14:34 - 00000000 ____D () C:\Program Files (x86)\Microsoft Synchronization Services
    2014-03-27 14:34 - 2014-03-27 14:34 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
    2014-03-27 14:25 - 2014-03-30 20:13 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
    2014-03-27 14:22 - 2014-03-27 14:22 - 00000000 ____D () C:\Program Files\IIS
    2014-03-27 14:22 - 2014-03-27 14:22 - 00000000 ____D () C:\Program Files (x86)\Microsoft ASP.NET
    2014-03-27 14:22 - 2014-03-27 14:22 - 00000000 ____D () C:\Program Files (x86)\IIS
    2014-03-27 14:18 - 2014-03-27 15:02 - 00000000 ____D () C:\Users\Raph\Documents\Visual Studio 2010
    2014-03-27 14:07 - 2014-03-27 14:43 - 00000000 ____D () C:\Windows\SysWOW64\1033
    2014-03-27 14:06 - 2014-04-04 12:12 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 10.0
    2014-03-27 14:06 - 2014-03-27 14:11 - 00000000 ____D () C:\Program Files (x86)\Microsoft F#
    2014-03-27 14:06 - 2014-03-27 14:09 - 00000000 ____D () C:\Program Files (x86)\HTML Help Workshop
    2014-03-27 14:04 - 2014-04-04 12:22 - 00000000 ____D () C:\Windows\symbols
    2014-03-27 14:04 - 2014-03-30 20:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft SDKs
    2014-03-27 14:04 - 2014-03-27 14:43 - 00000000 ____D () C:\Windows\system32\1033
    2014-03-27 14:04 - 2014-03-27 14:36 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 10.0
    2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 ____D () C:\Program Files\Microsoft Help Viewer
    2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 9.0
    2014-03-27 13:15 - 2014-03-27 13:15 - 00003136 _____ () C:\Windows\System32\Tasks\{C52BFAAC-4F6C-40F5-87D7-098D3F727788}
    2014-03-27 12:57 - 2014-04-06 21:06 - 00003200 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-4097332094-2714983402-552182644-1000
    2014-03-27 12:07 - 2014-03-27 12:07 - 00003124 _____ () C:\Windows\System32\Tasks\{81328C64-A1ED-4CEC-B107-5D7D82409D5D}
    2014-03-27 11:23 - 2014-03-27 11:23 - 00000000 ____D () C:\Windows\System32\Tasks\Norton 360
    2014-03-27 11:10 - 2014-03-04 06:32 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
    2014-03-27 11:01 - 2014-04-07 07:36 - 00000000 ____D () C:\Users\Raph\AppData\Roaming\vlc
    2014-03-27 10:58 - 2014-04-08 07:46 - 00000000 ____D () C:\Program Files (x86)\pastaleads
    2014-03-27 10:58 - 2014-03-30 20:59 - 00000000 ____D () C:\Users\Raph\AppData\Local\GCC
    2014-03-27 10:58 - 2014-03-30 20:25 - 00000000 ____D () C:\ProgramData\pastaleads
    2014-03-27 10:58 - 2014-03-27 10:58 - 00004566 _____ () C:\Windows\System32\Tasks\GC_Informer
    2014-03-27 10:58 - 2014-03-27 10:58 - 00004550 _____ () C:\Windows\System32\Tasks\GC_Scheduler
    2014-03-27 08:39 - 2014-03-27 08:39 - 00000000 ____D () C:\Users\Raph\AppData\Roaming\Oracle
    2014-03-27 08:38 - 2014-03-27 08:38 - 00000000 ____D () C:\ProgramData\Sun
    2014-03-27 08:38 - 2014-03-27 08:38 - 00000000 ____D () C:\ProgramData\Oracle
    2014-03-27 08:38 - 2014-03-27 08:37 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
    2014-03-27 08:37 - 2014-03-27 08:37 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
    2014-03-27 08:37 - 2014-03-27 08:37 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
    2014-03-27 08:37 - 2014-03-27 08:37 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
    2014-03-27 08:37 - 2014-03-27 08:37 - 00000000 ____D () C:\Program Files (x86)\Java
    2014-03-27 08:33 - 2014-03-27 08:33 - 00000000 ____D () C:\Program Files (x86)\DownloadXCtrl.com
    2014-03-27 08:33 - 2014-01-23 18:12 - 00354592 _____ (Sendori) C:\Windows\SysWOW64\plsapp.dll
    2014-03-27 08:33 - 2013-11-13 22:41 - 00439296 _____ (Sendori) C:\Windows\system32\plsapp64.dll
    2014-03-24 08:51 - 2014-04-01 21:48 - 00000000 ____D () C:\Program Files (x86)\Belarc
    2014-03-23 02:38 - 2014-03-23 02:38 - 00002255 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
    2014-03-23 02:37 - 2014-04-08 07:49 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2014-03-23 02:37 - 2014-04-08 07:49 - 00000890 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2014-03-23 02:37 - 2014-03-31 07:44 - 00003890 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
    2014-03-23 02:37 - 2014-03-31 07:44 - 00003638 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
    2014-03-23 02:37 - 2014-03-23 02:37 - 00000000 ____D () C:\Program Files (x86)\Google
    2014-03-23 02:36 - 2014-03-23 02:38 - 00000000 ____D () C:\Users\Raph\AppData\Local\Google
    2014-03-20 23:03 - 2014-03-20 23:03 - 15783992 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
    2014-03-20 23:03 - 2014-03-20 23:03 - 11589272 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
    2014-03-20 23:03 - 2014-03-20 23:03 - 09690424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 31474976 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 25255256 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 23716640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 17755424 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 17561544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 12708128 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
    2014-03-20 23:02 - 2014-03-20 23:02 - 11636176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 09728064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 03143456 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 02958792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 02783008 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 02411976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433523.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 01516488 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433523.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 00892704 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 00877856 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 00863064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 00846168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
    2014-03-19 00:17 - 2014-03-19 00:28 - 00105472 _____ () C:\Users\Raph\Downloads\coriejuniel_resume.pub
    2014-03-19 00:15 - 2014-03-19 00:16 - 00105472 _____ () C:\Users\Raph\Downloads\corie_resume.pub
    2014-03-18 23:58 - 2014-03-18 23:58 - 00105472 _____ () C:\Users\Raph\Documents\corie resume.pub
    2014-03-18 19:01 - 2014-03-18 19:01 - 00000000 ____D () C:\Windows\System32\Tasks\Games
    2014-03-15 17:09 - 2014-03-15 17:09 - 00000000 ____D () C:\Users\Raph\Downloads\John Legend - Love in the Future [Deluxe Version] (2013)
    2014-03-15 16:57 - 2014-03-15 16:57 - 00000000 ____D () C:\Users\Raph\Downloads\Marvin Sapp - I Win (2012)
    2014-03-12 14:28 - 2014-03-01 01:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2014-03-12 14:28 - 2014-03-01 00:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2014-03-12 14:28 - 2014-03-01 00:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2014-03-12 14:28 - 2014-02-28 23:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2014-03-12 14:28 - 2014-02-28 23:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2014-03-12 14:28 - 2014-02-28 23:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2014-03-12 14:28 - 2014-02-28 23:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2014-03-12 14:28 - 2014-02-28 23:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2014-03-12 14:28 - 2014-02-28 23:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2014-03-12 14:28 - 2014-02-28 23:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2014-03-12 14:28 - 2014-02-28 23:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2014-03-12 14:28 - 2014-02-28 23:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2014-03-12 14:28 - 2014-02-28 23:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2014-03-12 14:28 - 2014-02-28 23:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2014-03-12 14:28 - 2014-02-28 23:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2014-03-12 14:28 - 2014-02-28 23:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2014-03-12 14:28 - 2014-02-28 23:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2014-03-12 14:28 - 2014-02-28 22:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2014-03-12 14:28 - 2014-02-28 22:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2014-03-12 14:28 - 2014-02-28 22:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2014-03-12 14:28 - 2014-02-28 22:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2014-03-12 14:28 - 2014-02-28 22:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2014-03-12 14:28 - 2014-02-28 22:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2014-03-12 14:28 - 2014-02-28 22:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2014-03-12 14:28 - 2014-02-28 22:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2014-03-12 14:28 - 2014-02-28 22:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2014-03-12 14:28 - 2014-02-28 22:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2014-03-12 14:28 - 2014-02-28 22:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2014-03-12 14:28 - 2014-02-28 22:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2014-03-12 14:28 - 2014-02-28 22:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2014-03-12 14:28 - 2014-02-28 22:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2014-03-12 14:28 - 2014-02-28 22:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2014-03-12 14:28 - 2014-02-28 22:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2014-03-12 14:28 - 2014-02-28 22:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2014-03-12 14:28 - 2014-02-28 21:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2014-03-12 14:28 - 2014-02-28 21:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2014-03-12 14:28 - 2014-02-28 21:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2014-03-12 14:28 - 2014-02-28 21:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2014-03-12 14:28 - 2014-02-28 21:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2014-03-12 14:28 - 2014-02-28 21:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2014-03-12 14:28 - 2014-02-06 20:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2014-03-12 14:28 - 2014-02-03 21:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
    2014-03-12 14:28 - 2014-02-03 21:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
    2014-03-12 14:28 - 2014-01-28 21:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
    2014-03-12 14:28 - 2014-01-28 21:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
    2014-03-12 14:28 - 2014-01-27 21:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
    2014-03-12 14:27 - 2014-02-03 21:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
    2014-03-12 14:27 - 2014-02-03 21:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
    2014-03-11 17:02 - 2014-03-11 17:02 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
    2014-03-10 21:24 - 2014-03-19 09:46 - 00009529 _____ () C:\Users\Raph\Documents\bydgns.xspf
     
    ==================== One Month Modified Files and Folders =======
     
    2014-04-08 08:10 - 2014-04-08 08:10 - 00015710 _____ () C:\Users\Raph\Downloads\FRST.txt
    2014-04-08 08:10 - 2014-04-05 18:17 - 00000000 ____D () C:\FRST
    2014-04-08 08:05 - 2014-04-08 08:05 - 00982016 _____ (Farbar) C:\Users\Raph\Downloads\MiniToolBox.exe
    2014-04-08 08:04 - 2014-04-08 08:04 - 00003085 _____ () C:\Users\Raph\Desktop\JRT.txt
    2014-04-08 07:52 - 2014-04-08 07:52 - 00000000 ____D () C:\Windows\ERUNT
    2014-04-08 07:51 - 2014-04-08 07:51 - 01016261 _____ (Thisisu) C:\Users\Raph\Downloads\JRT.exe
    2014-04-08 07:49 - 2014-03-23 02:37 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2014-04-08 07:49 - 2014-03-23 02:37 - 00000890 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2014-04-08 07:46 - 2014-03-27 10:58 - 00000000 ____D () C:\Program Files (x86)\pastaleads
    2014-04-08 07:45 - 2013-10-14 22:40 - 00000000 ____D () C:\Users\Raph\AppData\Roaming\uTorrent
    2014-04-08 07:25 - 2014-01-04 12:27 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
    2014-04-08 07:24 - 2009-07-14 00:13 - 00876042 _____ () C:\Windows\system32\PerfStringBackup.INI
    2014-04-07 17:20 - 2013-10-14 23:50 - 01580384 _____ () C:\Windows\WindowsUpdate.log
    2014-04-07 07:36 - 2014-03-27 11:01 - 00000000 ____D () C:\Users\Raph\AppData\Roaming\vlc
    2014-04-06 21:06 - 2014-03-27 12:57 - 00003200 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-4097332094-2714983402-552182644-1000
    2014-04-06 21:05 - 2014-03-30 21:05 - 00003336 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-4097332094-2714983402-552182644-1000
    2014-04-05 18:22 - 2014-04-05 18:18 - 00044150 _____ () C:\Users\Raph\Downloads\Addition.txt
    2014-04-05 18:16 - 2014-04-05 18:16 - 02157056 _____ (Farbar) C:\Users\Raph\Downloads\FRST64.exe
    2014-04-05 11:50 - 2014-03-30 20:40 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2014-04-04 22:27 - 2009-07-13 23:51 - 00081439 _____ () C:\Windows\setupact.log
    2014-04-04 19:51 - 2009-07-13 23:45 - 00029616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2014-04-04 19:51 - 2009-07-13 23:45 - 00029616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2014-04-04 19:42 - 2014-04-04 12:26 - 00003358 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-4097332094-2714983402-552182644-1000
    2014-04-04 19:42 - 2013-11-20 18:39 - 00003222 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-4097332094-2714983402-552182644-1000
    2014-04-04 19:41 - 2013-10-15 00:02 - 00000000 ____D () C:\ProgramData\NVIDIA
    2014-04-04 19:41 - 2009-07-14 00:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
    2014-04-04 19:08 - 2014-03-30 20:39 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2014-04-04 19:08 - 2014-03-30 13:00 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
    2014-04-04 12:24 - 2013-10-14 22:03 - 00000000 ____D () C:\Users\Raph
    2014-04-04 12:22 - 2014-03-27 14:04 - 00000000 ____D () C:\Windows\symbols
    2014-04-04 12:22 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\system32\NDF
    2014-04-04 12:21 - 2013-10-14 22:36 - 00000000 ____D () C:\ProgramData\Norton
    2014-04-04 12:21 - 2013-10-14 22:11 - 00000000 ___HD () C:\SuperChargerProfile
    2014-04-04 12:21 - 2009-07-14 00:32 - 00000000 ____D () C:\Program Files\MSBuild
    2014-04-04 12:21 - 2009-07-13 22:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
    2014-04-04 12:20 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\registration
    2014-04-04 12:14 - 2014-04-02 18:21 - 00000000 ____D () C:\ProgramData\PreEmptive Solutions
    2014-04-04 12:14 - 2014-03-27 14:37 - 00000000 ____D () C:\Program Files\Microsoft SQL Server
    2014-04-04 12:14 - 2013-10-14 22:42 - 00000000 ____D () C:\ProgramData\Real
    2014-04-04 12:12 - 2014-03-27 14:06 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 10.0
    2014-04-04 12:10 - 2014-03-27 14:36 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server
    2014-04-04 06:29 - 2014-04-04 06:29 - 00000166 _____ () C:\Users\Raph\Documents\emailpw.txt
    2014-04-03 09:51 - 2014-03-30 20:39 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
    2014-04-03 09:51 - 2014-03-30 20:39 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2014-04-03 09:50 - 2014-03-30 20:39 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
    2014-04-02 09:06 - 2014-04-02 09:06 - 00000000 ____D () C:\ProgramData\RSA
    2014-04-02 09:05 - 2014-04-02 09:05 - 00000000 ____D () C:\Users\Raph\AppData\Local\RSA
    2014-04-02 09:05 - 2014-04-02 09:05 - 00000000 ____D () C:\Program Files (x86)\RSA SecurID Token Common
    2014-04-02 09:05 - 2014-04-02 09:05 - 00000000 ____D () C:\Program Files (x86)\RSA SecurID Software Token
    2014-04-02 09:04 - 2014-04-02 09:04 - 12518912 _____ () C:\Users\Raph\Downloads\RSASecurIDToken410.msi
    2014-04-02 09:00 - 2014-04-02 09:00 - 01527104 _____ (LogMeIn, Inc.) C:\Users\Raph\Downloads\Support-LogMeInRescue.exe
    2014-04-01 21:48 - 2014-03-24 08:51 - 00000000 ____D () C:\Program Files (x86)\Belarc
    2014-04-01 21:38 - 2014-04-01 21:38 - 00282312 _____ () C:\Windows\Minidump\040114-57174-01.dmp
    2014-04-01 21:38 - 2014-04-01 21:38 - 00000000 ____D () C:\Windows\Minidump
    2014-04-01 21:37 - 2014-04-01 21:37 - 534141396 _____ () C:\Windows\MEMORY.DMP
    2014-03-31 13:54 - 2014-03-31 13:54 - 00000000 ____D () C:\Users\Raph\AppData\Roaming\webex
    2014-03-31 13:54 - 2014-03-31 13:53 - 00000000 ____D () C:\ProgramData\WebEx
    2014-03-31 13:53 - 2014-03-31 13:53 - 00187176 _____ (Cisco WebEx LLC) C:\Users\Raph\Downloads\,staffmanagement,1607416503,-1933870862,MC,0-0,AAAAAcW0eDY3eIJvS7Pms0ns2-PWe1Aul7zVGJ83BXH4hAr30_webex.exe
    2014-03-31 07:44 - 2014-03-23 02:37 - 00003890 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
    2014-03-31 07:44 - 2014-03-23 02:37 - 00003638 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
    2014-03-31 07:03 - 2010-11-20 22:47 - 00206950 _____ () C:\Windows\PFRO.log
    2014-03-30 21:43 - 2013-12-15 20:15 - 00000000 ____D () C:\ProgramData\Microsoft Help
    2014-03-30 21:16 - 2009-07-13 21:34 - 00000478 _____ () C:\Windows\win.ini
    2014-03-30 21:14 - 2014-03-30 21:14 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
    2014-03-30 21:14 - 2014-03-30 21:14 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
    2014-03-30 20:59 - 2014-03-27 10:58 - 00000000 ____D () C:\Users\Raph\AppData\Local\GCC
    2014-03-30 20:59 - 2013-10-14 22:43 - 00000000 ____D () C:\Users\Raph\AppData\Local\TidyNetwork
    2014-03-30 20:25 - 2014-03-27 10:58 - 00000000 ____D () C:\ProgramData\pastaleads
    2014-03-30 20:22 - 2014-03-30 20:22 - 00000000 ____D () C:\Users\Raph\AppData\Local\SearchProtect
    2014-03-30 20:14 - 2014-03-06 11:33 - 00000000 ____D () C:\Users\Raph\Downloads\The Nut Job 2014 HDCAM x264 AC3 TiTAN
    2014-03-30 20:14 - 2014-02-25 19:18 - 00000000 ____D () C:\Users\Raph\Documents\PEMDAS_files
    2014-03-30 20:14 - 2014-02-21 20:47 - 00000000 ____D () C:\Users\Raph\Downloads\47.Ronin.2013.CAM.HCSUBS.MP4.AAC.X264-P2P
    2014-03-30 20:14 - 2014-02-11 12:04 - 00000000 ____D () C:\Users\Raph\Downloads\The.Hobbit-The.Desolation.of.Smaug.2013.mp4-KOB
    2014-03-30 20:14 - 2013-11-20 07:11 - 00000000 ____D () C:\Users\Raph\Downloads\Convert X to DVD v4.1.19.365 Including Keys [h33t][iahq76]
    2014-03-30 20:14 - 2013-10-15 00:02 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
    2014-03-30 20:14 - 2013-10-15 00:02 - 00000000 ___RD () C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
    2014-03-30 20:14 - 2010-11-21 02:16 - 00000000 ___RD () C:\Users\Public\Recorded TV
    2014-03-30 20:14 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\AppCompat
    2014-03-30 20:13 - 2014-03-27 14:25 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
    2014-03-30 20:07 - 2013-12-10 13:34 - 00000000 ____D () C:\Users\Raph\Documents\Fax
    2014-03-30 20:01 - 2014-03-27 14:04 - 00000000 ____D () C:\Program Files (x86)\Microsoft SDKs
    2014-03-30 20:01 - 2013-12-15 20:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
    2014-03-30 14:11 - 2014-03-30 13:43 - 00000000 ____D () C:\AdwCleaner
    2014-03-30 13:00 - 2014-03-30 13:00 - 00000000 ____D () C:\ProgramData\Malwarebytes
    2014-03-30 07:47 - 2013-11-18 08:03 - 00026112 ___SH () C:\Users\Raph\Documents\Thumbs.db
    2014-03-28 13:58 - 2014-03-28 13:57 - 00000000 ____D () C:\Users\Raph\AppData\Local\NPE
    2014-03-27 20:08 - 2014-03-27 20:08 - 00000000 ____D () C:\Users\Default\Documents\Visual Studio 2010
    2014-03-27 20:08 - 2014-03-27 20:08 - 00000000 ____D () C:\Users\Default User\Documents\Visual Studio 2010
    2014-03-27 19:14 - 2014-03-27 19:14 - 00000000 ____D () C:\Users\Raph\Documents\Visual Studio 2008
    2014-03-27 18:54 - 2014-03-27 18:54 - 00000000 ____D () C:\ProgramData\VS
    2014-03-27 18:16 - 2014-03-27 18:16 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8
    2014-03-27 15:40 - 2014-03-27 15:40 - 00000200 _____ () C:\Users\Raph\Documents\winkeymso2010.txt
    2014-03-27 15:35 - 2014-03-27 15:35 - 06957280 _____ (Microsoft Corporation) C:\Users\Raph\Downloads\Silverlight.exe
    2014-03-27 15:02 - 2014-03-27 14:18 - 00000000 ____D () C:\Users\Raph\Documents\Visual Studio 2010
    2014-03-27 14:58 - 2014-03-27 14:58 - 00000000 ____D () C:\Users\Raph\AppData\Roaming\Microsoft Corporation
    2014-03-27 14:45 - 2014-03-27 14:45 - 00000000 ____D () C:\Windows\system32\RsFx
    2014-03-27 14:44 - 2014-03-27 14:44 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 9.0
    2014-03-27 14:43 - 2014-03-27 14:07 - 00000000 ____D () C:\Windows\SysWOW64\1033
    2014-03-27 14:43 - 2014-03-27 14:04 - 00000000 ____D () C:\Windows\system32\1033
    2014-03-27 14:36 - 2014-03-27 14:04 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 10.0
    2014-03-27 14:35 - 2014-03-27 14:35 - 00000000 ____D () C:\Program Files\Microsoft Sync Framework
    2014-03-27 14:34 - 2014-03-27 14:34 - 00000000 ____D () C:\Program Files\Microsoft Synchronization Services
    2014-03-27 14:34 - 2014-03-27 14:34 - 00000000 ____D () C:\Program Files\Microsoft SQL Server Compact Edition
    2014-03-27 14:34 - 2014-03-27 14:34 - 00000000 ____D () C:\Program Files (x86)\Microsoft Synchronization Services
    2014-03-27 14:34 - 2014-03-27 14:34 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
    2014-03-27 14:22 - 2014-03-27 14:22 - 00000000 ____D () C:\Program Files\IIS
    2014-03-27 14:22 - 2014-03-27 14:22 - 00000000 ____D () C:\Program Files (x86)\Microsoft ASP.NET
    2014-03-27 14:22 - 2014-03-27 14:22 - 00000000 ____D () C:\Program Files (x86)\IIS
    2014-03-27 14:11 - 2014-03-27 14:06 - 00000000 ____D () C:\Program Files (x86)\Microsoft F#
    2014-03-27 14:09 - 2014-03-27 14:06 - 00000000 ____D () C:\Program Files (x86)\HTML Help Workshop
    2014-03-27 14:06 - 2009-07-14 00:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
    2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 ____D () C:\Program Files\Microsoft Help Viewer
    2014-03-27 14:04 - 2014-03-27 14:04 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 9.0
    2014-03-27 13:15 - 2014-03-27 13:15 - 00003136 _____ () C:\Windows\System32\Tasks\{C52BFAAC-4F6C-40F5-87D7-098D3F727788}
    2014-03-27 12:07 - 2014-03-27 12:07 - 00003124 _____ () C:\Windows\System32\Tasks\{81328C64-A1ED-4CEC-B107-5D7D82409D5D}
    2014-03-27 11:23 - 2014-03-27 11:23 - 00000000 ____D () C:\Windows\System32\Tasks\Norton 360
    2014-03-27 11:17 - 2013-10-14 22:37 - 00000000 ____D () C:\Windows\system32\Drivers\N360x64
    2014-03-27 11:15 - 2013-10-14 22:37 - 00003206 _____ () C:\Windows\System32\Tasks\Norton WSC Integration
    2014-03-27 11:10 - 2013-10-15 00:02 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
    2014-03-27 10:58 - 2014-03-27 10:58 - 00004566 _____ () C:\Windows\System32\Tasks\GC_Informer
    2014-03-27 10:58 - 2014-03-27 10:58 - 00004550 _____ () C:\Windows\System32\Tasks\GC_Scheduler
    2014-03-27 10:58 - 2013-10-19 22:18 - 00001066 _____ () C:\Users\Public\Desktop\VLC media player.lnk
    2014-03-27 08:39 - 2014-03-27 08:39 - 00000000 ____D () C:\Users\Raph\AppData\Roaming\Oracle
    2014-03-27 08:38 - 2014-03-27 08:38 - 00000000 ____D () C:\ProgramData\Sun
    2014-03-27 08:38 - 2014-03-27 08:38 - 00000000 ____D () C:\ProgramData\Oracle
    2014-03-27 08:37 - 2014-03-27 08:38 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
    2014-03-27 08:37 - 2014-03-27 08:37 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
    2014-03-27 08:37 - 2014-03-27 08:37 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
    2014-03-27 08:37 - 2014-03-27 08:37 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
    2014-03-27 08:37 - 2014-03-27 08:37 - 00000000 ____D () C:\Program Files (x86)\Java
    2014-03-27 08:33 - 2014-03-27 08:33 - 00000000 ____D () C:\Program Files (x86)\DownloadXCtrl.com
    2014-03-23 02:38 - 2014-03-23 02:38 - 00002255 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
    2014-03-23 02:38 - 2014-03-23 02:36 - 00000000 ____D () C:\Users\Raph\AppData\Local\Google
    2014-03-23 02:37 - 2014-03-23 02:37 - 00000000 ____D () C:\Program Files (x86)\Google
    2014-03-23 02:36 - 2013-11-20 10:51 - 00000000 ____D () C:\Users\Raph\AppData\Local\Deployment
    2014-03-20 23:03 - 2014-03-20 23:03 - 15783992 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
    2014-03-20 23:03 - 2014-03-20 23:03 - 11589272 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
    2014-03-20 23:03 - 2014-03-20 23:03 - 09690424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
    2014-03-20 23:03 - 2013-10-14 23:54 - 18302384 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 31474976 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 25255256 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 23716640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 17755424 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 17561544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 12708128 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
    2014-03-20 23:02 - 2014-03-20 23:02 - 11636176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 09728064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 03143456 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 02958792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 02783008 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 02411976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433523.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 01516488 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433523.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 00892704 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 00877856 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 00863064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
    2014-03-20 23:02 - 2014-03-20 23:02 - 00846168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
    2014-03-20 23:02 - 2013-10-27 09:12 - 14709720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
    2014-03-20 23:02 - 2013-10-14 23:54 - 03093280 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
    2014-03-20 23:02 - 2013-10-14 23:54 - 02715264 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
    2014-03-20 23:02 - 2013-10-14 23:54 - 00024544 _____ () C:\Windows\system32\nvinfo.pb
    2014-03-19 09:46 - 2014-03-10 21:24 - 00009529 _____ () C:\Users\Raph\Documents\bydgns.xspf
    2014-03-19 00:28 - 2014-03-19 00:17 - 00105472 _____ () C:\Users\Raph\Downloads\coriejuniel_resume.pub
    2014-03-19 00:16 - 2014-03-19 00:15 - 00105472 _____ () C:\Users\Raph\Downloads\corie_resume.pub
    2014-03-18 23:58 - 2014-03-18 23:58 - 00105472 _____ () C:\Users\Raph\Documents\corie resume.pub
    2014-03-18 19:01 - 2014-03-18 19:01 - 00000000 ____D () C:\Windows\System32\Tasks\Games
    2014-03-18 15:18 - 2013-10-15 01:00 - 00000000 ____D () C:\Windows\system32\MRT
    2014-03-18 15:16 - 2013-10-15 01:00 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2014-03-15 17:09 - 2014-03-15 17:09 - 00000000 ____D () C:\Users\Raph\Downloads\John Legend - Love in the Future [Deluxe Version] (2013)
    2014-03-15 16:57 - 2014-03-15 16:57 - 00000000 ____D () C:\Users\Raph\Downloads\Marvin Sapp - I Win (2012)
    2014-03-12 15:35 - 2009-07-13 23:45 - 00497968 _____ () C:\Windows\system32\FNTCACHE.DAT
    2014-03-11 21:25 - 2014-01-04 12:27 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2014-03-11 21:25 - 2013-10-14 22:54 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2014-03-11 21:25 - 2013-10-14 22:54 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2014-03-11 17:03 - 2013-10-14 22:54 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
    2014-03-11 17:02 - 2014-03-11 17:02 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
     
    Some content of TEMP:
    ====================
    C:\Users\Raph\AppData\Local\Temp\devcon64.exe
    C:\Users\Raph\AppData\Local\Temp\ose00000.exe
     
     
    ==================== Bamital & volsnap Check =================
     
    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\rpcss.dll => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
     
     
    LastRegBack: 2014-03-30 00:13
     
    ==================== End Of Log ============================
     
     

    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014
    Ran by Raph at 2014-04-08 08:11:03
    Running from C:\Users\Raph\Downloads
    Boot Mode: Normal
    ==========================================================
     
     
    ==================== Security Center ========================
     
    AV: Norton 360 (Enabled - Up to date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB}
    AS: Norton 360 (Enabled - Up to date) {631E4324-D31C-783F-EC5C-35AD42B18466}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    FW: Norton 360 (Enabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0}
     
    ==================== Installed Programs ======================
     
    2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
    2007 Microsoft Office Suite Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
    3D Volcano ScreenSaver (HKLM-x32\...\{A86C7DF6-DB0F-4C78-8D15-D22DFC9D5A5F}) (Version: 1.0.2 - InstallX, LLC)
    Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated)
    Adobe Reader XI (11.0.06) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
    Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.0.150 - Adobe Systems, Inc.)
    AMD APP SDK Runtime (Version: 10.0.873.1 - Advanced Micro Devices Inc.) Hidden
    AMD Catalyst Install Manager (HKLM\...\{DD562794-C098-A1E5-66ED-10E8BD1C84C5}) (Version: 3.0.864.0 - Advanced Micro Devices, Inc.)
    AMD Fuel (Version: 2012.0504.1554.26509 - Advanced Micro Devices, Inc.) Hidden
    Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    Ares 3.1.7.3042 (HKLM-x32\...\{C9FF844C-02F5-4221-8AD4-0BD823533C6E}_is1) (Version: 3.1.7.3042 - Ares)
    Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.10.1.0 - Asmedia Technology)
    Baggin the Dragon Home Ed v2 (HKLM-x32\...\Baggin the Dragon Home Ed v2) (Version: 2.0.9 - EdAlive)
    Bing Bar (HKLM-x32\...\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)
    Bing Desktop (HKLM-x32\...\{7D095455-D971-4D4C-9EFD-9AF6A6584F3A}) (Version: 1.3.347.0 - Microsoft Corporation)
    Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
    Catalyst Control Center (x32 Version: 2012.0504.1554.26509 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center InstallProxy (x32 Version: 2012.0504.1554.26509 - Advanced Micro Devices, Inc.) Hidden
    Catalyst Control Center Localization All (x32 Version: 2012.0504.1554.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Chinese Standard (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Chinese Traditional (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Czech (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Danish (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Dutch (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help English (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Finnish (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help French (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help German (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Greek (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Hungarian (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Italian (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Japanese (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Korean (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Norwegian (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Polish (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Portuguese (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Russian (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Spanish (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Swedish (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Thai (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    CCC Help Turkish (x32 Version: 2012.0504.1553.26509 - Advanced Micro Devices, Inc.) Hidden
    ccc-utility64 (Version: 2012.0504.1554.26509 - Advanced Micro Devices, Inc.) Hidden
    Contents (x32 Version: 16.0.0.106 - Corel Corporation) Hidden
    ConvertXtoDVD 4.1.19.365 (HKLM-x32\...\{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1) (Version: 4.1.19.365 - )
    Corel VideoStudio Pro X6 (HKLM-x32\...\_{6688A246-F6E8-48AD-9806-8D5832E9F15D}) (Version: 16.0.0.106 - Corel Corporation)
    Crystal Reports for Visual Studio (x32 Version: 12.51.0.240 - SAP) Hidden
    Dotfuscator Software Services - Community Edition (HKLM-x32\...\{1AA5BD63-6614-44B2-88A7-605191EDB835}) (Version: 5.0.2500.0 - PreEmptive Solutions)
    DownloadX ActiveX Download Control 1.6.7 (HKLM-x32\...\CA17A131-B7D9-41D6-868F-29A9BD9FCC8E_is1) (Version:  - DownloadXCtrl.com)
    Dropbox (HKCU\...\Dropbox) (Version: 2.4.7 - Dropbox, Inc.)
    GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 33.0.1750.154 - Google Inc.)
    Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden
    ICA (x32 Version: 16.0.0.106 - Corel Corporation) Hidden
    iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.)
    ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden
    IPM_VS_Pro (x32 Version: 16.0 - Corel Corporation) Hidden
    iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
    Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle)
    Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
    Living Marine Aquarium 2 (HKLM-x32\...\{3C9D2B2E-53A2-4098-B931-2621C5D9822B}) (Version: 1.0.2 - InstallX, LLC)
    Malwarebytes Anti-Malware version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation)
    Math Detective A1 (HKLM-x32\...\Math Detective A1) (Version: 1.6.0.0 - The Critical Thinking Co.)
    Math Detective Beginning (HKLM-x32\...\Math Detective Beginning) (Version: 1.5.0.0 - The Critical Thinking Co.)
    Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation)
    Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
    Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
    Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
    Microsoft Application Error Reporting (x32 Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
    Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools (HKLM-x32\...\{40416836-56CC-4C0E-A6AF-5C34BADCE483}) (Version: 2.0.50217.0 - Microsoft Corporation)
    Microsoft ASP.NET MVC 2 (HKLM-x32\...\{1803A630-3C38-4D2B-9B9A-0CB37243539C}) (Version: 2.0.50217.0 - Microsoft Corporation)
    Microsoft Help Viewer 1.1 (HKLM\...\Microsoft Help Viewer 1.1) (Version: 1.1.40219 - Microsoft Corporation)
    Microsoft Help Viewer 1.1 (Version: 1.1.40219 - Microsoft Corporation) Hidden
    Microsoft Office Access MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Access Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
    Microsoft Office Groove MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Groove Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office InfoPath MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office OneNote MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Outlook MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
    Microsoft Office Publisher MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
    Microsoft Silverlight 3 SDK (HKLM-x32\...\{2012098D-EEE9-4769-8DD3-B038050854D4}) (Version: 3.0.40818.0 - Microsoft Corporation)
    Microsoft Silverlight 4 SDK (HKLM-x32\...\{05855322-BE43-41FE-B583-D3AE0C326D58}) (Version: 4.0.50826.0 - Microsoft Corporation)
    Microsoft SQL Server 2008 (64-bit) (HKLM\...\Microsoft SQL Server 10 Release) (Version:  - Microsoft Corporation)
    Microsoft SQL Server 2008 (64-bit) (Version:  - Microsoft Corporation) Hidden
    Microsoft SQL Server 2008 Browser (HKLM-x32\...\{C688457E-03FD-4941-923B-A27F4D42A7DD}) (Version: 10.3.5500.0 - Microsoft Corporation)
    Microsoft SQL Server 2008 Common Files (Version: 10.3.5500.0 - Microsoft Corporation) Hidden
    Microsoft SQL Server 2008 Database Engine Services (Version: 10.3.5500.0 - Microsoft Corporation) Hidden
    Microsoft SQL Server 2008 Database Engine Shared (Version: 10.3.5500.0 - Microsoft Corporation) Hidden
    Microsoft SQL Server 2008 Native Client (HKLM\...\{2738C4AA-420E-4E13-ADEF-B5AB250E3EF1}) (Version: 10.3.5500.0 - Microsoft Corporation)
    Microsoft SQL Server 2008 R2 Data-Tier Application Framework (HKLM-x32\...\{BC537AE0-88AF-47ED-B762-33B0D62B5188}) (Version: 10.50.1750.9 - Microsoft Corporation)
    Microsoft SQL Server 2008 R2 Data-Tier Application Project (HKLM-x32\...\{7A56D81D-6406-40E7-9184-8AC1769C4D69}) (Version: 10.50.1750.9 - Microsoft Corporation)
    Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\...\{77F1F8AD-51B8-4490-AEEC-BF480073E0FC}) (Version: 10.50.1750.9 - Microsoft Corporation)
    Microsoft SQL Server 2008 R2 Management Objects (x64) (HKLM\...\{EAEBF166-B06A-4D7F-BAF7-6615303D5C7C}) (Version: 10.50.1750.9 - Microsoft Corporation)
    Microsoft SQL Server 2008 R2 Transact-SQL Language Service (HKLM-x32\...\{09C52940-A4D1-4409-A7CC-1AAE630CF578}) (Version: 10.50.1750.9 - Microsoft Corporation)
    Microsoft SQL Server 2008 RsFx Driver (Version: 10.3.5500.0 - Microsoft Corporation) Hidden
    Microsoft SQL Server 2008 Setup Support Files  (HKLM\...\{6292D514-17A4-403F-98F9-E150F10C043D}) (Version: 10.3.5500.0 - Microsoft Corporation)
    Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
    Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
    Microsoft SQL Server Database Publishing Wizard 1.4 (HKLM-x32\...\{ACE28263-76A4-4BF5-B6F4-8BD719595969}) (Version: 10.1.2512.8 - Microsoft Corporation)
    Microsoft SQL Server System CLR Types (HKLM-x32\...\{877B76B2-F83F-4F5A-B28D-3F398641ADB6}) (Version: 10.50.1750.9 - Microsoft Corporation)
    Microsoft SQL Server System CLR Types (x64) (HKLM\...\{1E6ED082-E32D-4B2B-8B6A-70B094815135}) (Version: 10.50.1750.9 - Microsoft Corporation)
    Microsoft SQL Server VSS Writer (HKLM\...\{0826F9E4-787E-481D-83E0-BC6A57B056D5}) (Version: 10.3.5500.0 - Microsoft Corporation)
    Microsoft Sync Framework Runtime v1.0 SP1 (x64) (HKLM\...\{8438EC02-B8A9-462D-AC72-1B521349C001}) (Version: 1.0.3010.0 - Microsoft Corporation)
    Microsoft Sync Framework SDK v1.0 SP1 (HKLM-x32\...\{0E3DFC64-CC49-4BE2-8C9C-58EF129675DB}) (Version: 1.0.3010.0 - Microsoft Corporation)
    Microsoft Sync Framework Services v1.0 SP1 (x64) (HKLM\...\{034106B5-54B7-467F-B477-5B7DBB492624}) (Version: 1.0.3010.0 - Microsoft Corporation)
    Microsoft Sync Services for ADO.NET v2.0 SP1 (x64) (HKLM\...\{1D1CEEF8-3741-45BD-8E77-963E1DEBDDD3}) (Version: 2.0.3010.0 - Microsoft Corporation)
    Microsoft Team Foundation Server 2010 Object Model - ENU (HKLM\...\Microsoft Team Foundation Server 2010 Object Model - ENU) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Team Foundation Server 2010 Object Model - ENU (Version: 10.0.40219 - Microsoft Corporation) Hidden
    Microsoft Visual C++  Compilers 2010 Standard - enu - x64 (Version: 10.0.40219 - Microsoft Corporation) Hidden
    Microsoft Visual C++  Compilers 2010 Standard - enu - x86 (x32 Version: 10.0.40219 - Microsoft Corporation) Hidden
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 (HKLM-x32\...\{B7E38540-E355-3503-AFD7-635B2F2F76E1}) (Version: 9.0.30729.4974 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x64 Designtime - 10.0.30319 (HKLM\...\{F5079164-1DB9-3BDA-853B-F78AF67CE071}) (Version: 10.0.30319 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x64 Runtime - 10.0.40219 (HKLM\...\{1C7C8AAF-A16D-32E8-89E5-F6D165DE0BCE}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x86 Runtime - 10.0.40219 (HKLM-x32\...\{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual F# 2.0 Runtime (HKLM-x32\...\{85467CBC-7A39-33C9-8940-D72D9269B84F}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (HKLM-x32\...\{14DD7530-CCD2-3798-B37D-3839ED6A441C}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual Studio 2010 IntelliTrace Collection (x64) (HKLM\...\{88BAE373-00F4-3E33-828F-96E89E5E0CB9}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual Studio 2010 Office Developer Tools (x64) (Version: 10.0.40219 - Microsoft Corporation) Hidden
    Microsoft Visual Studio 2010 Performance Collection Tools SP1 - ENU (Version: 10.0.40219 - Microsoft Corporation) Hidden
    Microsoft Visual Studio 2010 Service Pack 1 (HKLM-x32\...\Microsoft Visual Studio 2010 Service Pack 1) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual Studio 2010 Service Pack 1 (x32 Version: 10.0.40219 - Microsoft Corporation) Hidden
    Microsoft Visual Studio 2010 SharePoint Developer Tools (x32 Version: 10.0.40219 - Microsoft Corporation) Hidden
    Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.31007 - Microsoft Corporation)
    Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.31010 - Microsoft Corporation) Hidden
    Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.40308 - Microsoft Corporation) Hidden
    Microsoft Visual Studio 2010 Ultimate - ENU (HKLM-x32\...\Microsoft Visual Studio 2010 Ultimate - ENU) (Version: 10.0.30319 - Microsoft Corporation)
    Microsoft Visual Studio 2010 Ultimate - ENU (x32 Version: 10.0.40219 - Microsoft Corporation) Hidden
    Microsoft Visual Studio Macro Tools (HKLM-x32\...\Microsoft Visual Studio Macro Tools) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual Studio Macro Tools (x32 Version: 9.0.30729 - Microsoft Corporation) Hidden
    MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
    My Amazing Human Body (HKLM-x32\...\{12CA5656-44F2-4F01-AE05-B1BF746D9373}) (Version: 1.1 - )
    neroxml (x32 Version: 1.0.0 - Nero AG) Hidden
    Norton 360 (HKLM-x32\...\N360) (Version: 21.2.0.38 - Symantec Corporation)
    NVIDIA 3D Vision Controller Driver 331.58 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 331.58 - NVIDIA Corporation)
    NVIDIA 3D Vision Driver 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 335.23 - NVIDIA Corporation)
    NVIDIA Control Panel 335.23 (Version: 335.23 - NVIDIA Corporation) Hidden
    NVIDIA GeForce Experience 1.7 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.7 - NVIDIA Corporation)
    NVIDIA Graphics Driver 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 335.23 - NVIDIA Corporation)
    NVIDIA Install Application (Version: 2.1002.145.1024 - NVIDIA Corporation) Hidden
    NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden
    NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden
    NVIDIA PhysX System Software 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation)
    NVIDIA ShadowPlay 9.3.16 (Version: 9.3.16 - NVIDIA Corporation) Hidden
    NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3523 - NVIDIA Corporation) Hidden
    NVIDIA Update 10.4.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 10.4.0 - NVIDIA Corporation)
    NVIDIA Update Components (Version: 9.3.16 - NVIDIA Corporation) Hidden
    NVIDIA Virtual Audio 1.2.9 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.9 - NVIDIA Corporation)
    PowerISO (HKLM-x32\...\PowerISO) (Version: 5.8 - Power Software Ltd)
    QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
    Reader for PC (HKLM-x32\...\{71FB3127-E6B2-4058-ACEE-99813554FAB6}) (Version: 2.2.00.11270 - Sony Corporation)
    RealDownloader (x32 Version: 1.3.3 - RealNetworks, Inc.) Hidden
    RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
    RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
    RealPlayer (HKLM-x32\...\RealPlayer 16.0) (Version: 16.0.3 - RealNetworks)
    Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.53.216.2012 - Realtek)
    RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
    RSA SecurID Software Token (HKLM-x32\...\{1E7941DC-32F1-467D-8351-8955A038A76E}) (Version: 4.1.1 - RSA, The Security Division of EMC)
    Service Pack 3 for SQL Server 2008 (KB2546951) (64-bit) (HKLM\...\KB2546951) (Version: 10.3.5500.0 - Microsoft Corporation)
    Setup (x32 Version: 16.0.0.106 - Corel Corporation) Hidden
    Share (x32 Version: 16.0.0.106 - Corel Corporation) Hidden
    Share64 (Version: 16.0.0.106 - Corel Corporation) Hidden
    SHIELD Streaming (Version: 1.6.34 - NVIDIA Corporation) Hidden
    SmartSound Common Data (HKLM-x32\...\InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.)
    SmartSound Common Data (x32 Version: 1.1.0 - SmartSound Software Inc.) Hidden
    SmartSound Quicktracks 5 (HKLM-x32\...\InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.6 - SmartSound Software Inc.)
    SmartSound Quicktracks 5 (x32 Version: 5.1.6 - SmartSound Software Inc.) Hidden
    Sql Server Customer Experience Improvement Program (Version: 10.3.5500.0 - Microsoft Corporation) Hidden
    Super-Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.012 - MSI)
    swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
    Ultimate Math Invaders Home Ed v2 (HKLM-x32\...\Ultimate Math Invaders Home Ed v2) (Version: 2.0.9 - EdAlive)
    Unity Web Player (HKCU\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
    Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 Help for Common Features (KB963673) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{AB365889-0395-4FAD-B702-CA5985D53D42}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6FAA03BD-2B51-4029-9AD9-64A3B8E3C84C}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
    Update for Microsoft Office Access 2007 Help (KB963663) (HKLM-x32\...\{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{6B76A18A-AA1E-42AB-A7AD-6C84BBB43987}) (Version:  - Microsoft)
    Update for Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{199DF7B6-169C-448C-B511-1054101BE9C9}) (Version:  - Microsoft)
    Update for Microsoft Office Infopath 2007 Help (KB963662) (HKLM-x32\...\{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{716B81B8-B13C-41DF-8EAC-7A2F656CAB63}) (Version:  - Microsoft)
    Update for Microsoft Office OneNote 2007 Help (KB963670) (HKLM-x32\...\{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2744EF05-38E1-4D5D-B333-E021EDAEA245}) (Version:  - Microsoft)
    Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{ED38F8A3-4F61-494E-8BCA-E3AC7760C924}) (Version:  - Microsoft)
    Update for Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{0451F231-E3E3-4943-AB9F-58EB96171784}) (Version:  - Microsoft)
    Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2878234) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{EC1934B0-AE0F-4BBD-8955-54BB3247ED9E}) (Version:  - Microsoft)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{397B1D4F-ED7B-4ACA-A637-43B670843876}) (Version:  - Microsoft)
    Update for Microsoft Office Publisher 2007 Help (KB963667) (HKLM-x32\...\{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2E40DE55-B289-4C8B-8901-5D369B16814F}) (Version:  - Microsoft)
    Update for Microsoft Office Script Editor Help (KB963671) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{CD11C6A2-FFC6-4271-8EAB-79C3582F505C}) (Version:  - Microsoft)
    Update for Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{80E762AA-C921-4839-9D7D-DB62A72C0726}) (Version:  - Microsoft)
    Visual Studio 2010 Prerequisites - English (HKLM\...\{662014D2-0450-37ED-ABAE-157C88127BEB}) (Version: 10.0.40219 - Microsoft Corporation)
    Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{112C23F2-C036-4D40-BED4-0CB47BF5555C}) (Version: 4.0.8080.0 - Microsoft Corporation)
    VLC media player 2.1.2 (HKLM-x32\...\VLC media player) (Version: 2.1.2 - VideoLAN)
    VSClassic (x32 Version: 16.0.0.106 - Corel Corporation) Hidden
    VSHelp (x32 Version: 16.0.0.106 - Corel Corporation) Hidden
    VSPro (x32 Version: 16.0.0.106 - Corel Corporation) Hidden
    WCF RIA Services V1.0 SP1 (HKLM-x32\...\{D9E6001A-5DC3-4620-AF7A-80B6CD48645D}) (Version: 4.1.60114.0 - Microsoft Corporation)
    Web Deployment Tool (HKLM\...\{0F37D969-1260-419E-B308-EF7D29ABDE20}) (Version: 1.1.0618 - Microsoft Corporation)
    Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version:  - )
    Windows Media Encoder 9 Series (x32 Version: 9.00.2980 - Microsoft Corporation) Hidden
    Yahoo! Toolbar (HKLM-x32\...\Yahoo! Companion) (Version:  - Yahoo! Inc.)
    Yenka (HKLM-x32\...\Yenka) (Version: 3.4.2.0 - Crocodile Clips Ltd)
     
    ==================== Restore Points  =========================
     
    02-04-2014 14:04:58 Installed RSA SecurID Software Token.
    02-04-2014 22:32:31 Windows Update
    03-04-2014 13:41:54 Windows Update
    04-04-2014 09:57:11 Restore Operation
     
    ==================== Hosts content: ==========================
     
    2009-07-13 21:34 - 2009-06-10 16:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
     
    ==================== Scheduled Tasks (whitelisted) =============
     
    Task: {0D8A44FC-FE46-4776-97E5-0836162EDE1F} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\21.2.0.38\SymErr.exe [2014-01-30] (Symantec Corporation)
    Task: {138D9425-AF13-45AC-B689-9EAA931761D2} - System32\Tasks\Games\UpdateCheck_S-1-5-21-4097332094-2714983402-552182644-1000
    Task: {3466B582-D74F-4090-B442-420E481642D1} - System32\Tasks\TidyNetwork Update => C:\Users\Raph\AppData\Local\TidyNetwork\petnupdate.exe
    Task: {3B49E44F-1787-4DF5-B4AD-714B1EEC69F2} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-4097332094-2714983402-552182644-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
    Task: {42FAECE4-54EE-4D67-B359-271E55736BE2} - System32\Tasks\GC_Informer => %LOCALAPPDATA%\GCC\Controller.exe <==== ATTENTION
    Task: {520DE4E0-E4ED-426E-9A9C-8A44DC965821} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-4097332094-2714983402-552182644-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14] (RealNetworks, Inc.)
    Task: {57600876-8597-47F2-83FD-2E41333EE940} - System32\Tasks\Microsoft\Windows\Maintenance\UP_Scheduler => %LOCALAPPDATA%\GCC\Controller.exe <==== ATTENTION
    Task: {65BBFC5D-8755-4B1A-8018-441F28AF7DEC} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\21.2.0.38\SymErr.exe [2014-01-30] (Symantec Corporation)
    Task: {6EFF8D5B-1BE4-4DFE-AA83-12194DAFC3F7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-23] (Google Inc.)
    Task: {79F3B02B-3A5F-45B4-90E0-777C46BD48DC} - System32\Tasks\GC_Scheduler => %LOCALAPPDATA%\GCC\Controller.exe <==== ATTENTION
    Task: {7B3FE32D-03C6-4789-B50E-8241BE422041} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-4097332094-2714983402-552182644-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2013-08-14] (RealNetworks, Inc.)
    Task: {859CF20D-6E0B-414D-A803-5BAAA34EE625} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-23] (Google Inc.)
    Task: {89C0FA91-738A-45CF-8599-CD2404A2D9A6} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\21.2.0.38\WSCStub.exe [2014-03-11] (Symantec Corporation)
    Task: {A16B8228-2735-40F1-87D1-78A7175180CC} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
    Task: {C2FDA0B1-1D8C-4462-A1FA-999D9DDF647C} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-4097332094-2714983402-552182644-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14] (RealNetworks, Inc.)
    Task: {E5B7A502-2AE9-4EB9-917E-9180CABE7A0B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-11] (Adobe Systems Incorporated)
    Task: {F32E133B-33C3-4272-8B55-B28BF822EF53} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-4097332094-2714983402-552182644-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
    Task: {F70ACD85-F8F8-4864-A3EC-B2226F587289} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe [2013-11-20] (Apple Inc.)
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
     
    ==================== Loaded Modules (whitelisted) =============
     
    2012-05-04 15:41 - 2012-05-04 15:41 - 00211968 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll
    2011-11-13 14:30 - 2011-11-13 14:30 - 00676864 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll
    2011-11-13 14:31 - 2011-11-13 14:31 - 03643392 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll
    2013-10-15 00:02 - 2014-03-04 08:05 - 00116056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
    2014-03-14 00:55 - 2014-03-14 00:55 - 00491008 _____ () C:\Users\Raph\AppData\Local\GCC\Controller.exe
    2013-08-14 15:19 - 2013-08-14 15:19 - 00039056 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
    2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    2013-09-14 01:51 - 2013-09-14 01:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\zlib1.dll
    2013-09-14 01:50 - 2013-09-14 01:50 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\libxml2.dll
    2013-11-27 21:48 - 2013-11-27 21:48 - 00880640 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\fsk.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00040264 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskMediaPlayers.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00239944 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\Fskin.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00026952 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskinLocalize.dll
    2013-11-26 12:34 - 2013-11-26 12:34 - 00798720 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskSecurity.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00125256 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskDocumentViewer.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00016200 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskPower.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00024904 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskNetInterface.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00017224 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskMobileMediaDevice.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00015176 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskTimeHardware.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00034632 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ticket.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00018760 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ebookDeviceNotifier.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00092488 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ebookUsb.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00149832 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\readerAppHelper.dll
    2013-11-27 21:49 - 2013-11-27 21:49 - 00178504 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\USBDetector.dll
    2014-03-27 11:00 - 2013-12-03 21:48 - 04055504 _____ () C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\pdf.dll
    2014-03-27 11:00 - 2013-12-03 21:48 - 00399312 _____ () C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\ppgooglenaclpluginchrome.dll
    2014-03-27 11:00 - 2013-12-03 21:47 - 01619408 _____ () C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\ffmpegsumo.dll
    2013-08-13 07:15 - 2013-08-13 07:15 - 00206336 _____ () C:\Users\Raph\AppData\Local\Temp\{70C549E1-2F18-4BD8-820E-8DE33F90228B}\{D8A4593E-C9FA-4986-894F-20E0D6EE1CFA}\Default\Extensions\jmiibbdogibcphdfkkmlimfffneaecbc\2.4_0\plugin\convenience.dll
     
    ==================== Alternate Data Streams (whitelisted) =========
     
     
    ==================== Safe Mode (whitelisted) ===================
     
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\plsapp => ""="service"
     
    ==================== Disabled items from MSCONFIG ==============
     
     
    ==================== Faulty Device Manager Devices =============
     
     
    ==================== Event log errors: =========================
     
    Application errors:
    ==================
     
    System errors:
    =============
     
    Microsoft Office Sessions:
    =========================
    Error: (02/27/2014 00:14:07 PM) (Source: Microsoft Office 12 Sessions)(User: )
    Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6612.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 2766 seconds with 960 seconds of active time.  This session ended with a crash.
     
     
    ==================== Memory info =========================== 
     
    Percentage of memory in use: 33%
    Total physical RAM: 16354.13 MB
    Available physical RAM: 10907 MB
    Total Pagefile: 32706.43 MB
    Available Pagefile: 27392.68 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.85 MB
     
    ==================== Drives ================================
     
    Drive c: () (Fixed) (Total:232.79 GB) (Free:109.98 GB) NTFS
    Drive e: (OneTouch4 Plus) (Fixed) (Total:698.64 GB) (Free:132.99 GB) NTFS
     
    ==================== MBR & Partition Table ==================
     
    ========================================================
    Disk: 0 (Size: 699 GB) (Disk ID: 31257BD1)
    Partition 1: (Active) - (Size=699 GB) - (Type=07 NTFS)
     
    ========================================================
    Disk: 1 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 92636A50)
    Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=233 GB) - (Type=07 NTFS)
     
    ==================== End Of Log ============================

    • 0

    #6
    Buddierdl

    Buddierdl

      Trusted Helper

    • Malware Removal
    • 2,524 posts

    A little more to clean:

     

    First, please uninstall: DownloadX ActiveX Download Control 1.6.7

     

    Then, please download the attached fixlist.txt and save it to your desktop. Also move FRST from your downloads folder to your desktop (or you can download it again to your desktop). Run FRST again, and select "Fix." Post the resulting fixlog.txt.

     

    Finally, have your run adwCleaner? If so, could you run it once more and post the log for me?

    Attached Files


    • 0

    #7
    moviebuff6000

    moviebuff6000

      New Member

    • Topic Starter
    • Member
    • Pip
    • 6 posts

    I removed the file and ran the fix on FRST after moving it to my desktop. Here is the fixlog and the result log from adware cleaner.

     

    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014
    Ran by Raph at 2014-04-08 17:26:22 Run:1
    Running from C:\Users\Raph\Desktop
    Boot Mode: Normal
    ==============================================
     
    Content of fixlist:
    *****************
    AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll File Not Found
    BHO-x32: PETN - {B8107FB2-1A17-4277-B9E0-EDC058A2D774} - C:\Users\Raph\AppData\Local\TidyNetwork\petn.dll No File
    Toolbar: HKLM-x32 - No Name - {EF99BD32-C1FB-11D2-892F-0090271D4F88} -  No File
    C:\Users\Raph\AppData\Local\SearchProtect
    C:\Users\Raph\AppData\Local\TidyNetwork
    C:\Program Files (x86)\pastaleads
    C:\Users\Raph\AppData\Local\GCC
    C:\ProgramData\pastaleads
    C:\Windows\System32\Tasks\GC_Informer
    C:\Windows\System32\Tasks\GC_Scheduler
    C:\Program Files (x86)\DownloadXCtrl.com
    C:\Windows\SysWOW64\plsapp.dll
    C:\Windows\system32\plsapp64.dll
    folder: C:\Windows\system32\RsFx
    folder: C:\Windows\SysWOW64\1033
    folder: C:\Windows\system32\1033
    folder: C:\Windows\SysWOW64\Macromed
    Task: {3466B582-D74F-4090-B442-420E481642D1} - System32\Tasks\TidyNetwork Update => C:\Users\Raph\AppData\Local\TidyNetwork\petnupdate.exe
    Task: {42FAECE4-54EE-4D67-B359-271E55736BE2} - System32\Tasks\GC_Informer => %LOCALAPPDATA%\GCC\Controller.exe <==== ATTENTION
    Task: {57600876-8597-47F2-83FD-2E41333EE940} - System32\Tasks\Microsoft\Windows\Maintenance\UP_Scheduler => %LOCALAPPDATA%\GCC\Controller.exe <==== ATTENTION
    Task: {79F3B02B-3A5F-45B4-90E0-777C46BD48DC} - System32\Tasks\GC_Scheduler => %LOCALAPPDATA%\GCC\Controller.exe <==== ATTENTION
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\plsapp => ""="service"
    *****************
     
    "C:\\PROGRA~2\\SearchProtect\\SearchProtect\\bin\\SPVC64Loader.dll" => Value Data removed successfully.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B8107FB2-1A17-4277-B9E0-EDC058A2D774} => Key deleted successfully.
    HKCR\Wow6432Node\CLSID\{B8107FB2-1A17-4277-B9E0-EDC058A2D774} => Key deleted successfully.
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} => Value deleted successfully.
    HKCR\Wow6432Node\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88} => Key not found.
    C:\Users\Raph\AppData\Local\SearchProtect => Moved successfully.
    C:\Users\Raph\AppData\Local\TidyNetwork => Moved successfully.
     
    "C:\Program Files (x86)\pastaleads" directory move:
     
    C:\Program Files (x86)\pastaleads\HtmlAgilityPack.dll => Moved successfully.
    C:\Program Files (x86)\pastaleads\Newtonsoft.Json.dll => Moved successfully.
    C:\Program Files (x86)\pastaleads\PastaLeadsService.exe => Moved successfully.
    C:\Program Files (x86)\pastaleads\PastaLeadsWinApp.exe => Moved successfully.
    C:\Program Files (x86)\pastaleads\RestSharp.dll => Moved successfully.
    Could not move "C:\Program Files (x86)\pastaleads" directory. => Scheduled to move on reboot.
     
     
    "C:\Users\Raph\AppData\Local\GCC" directory move:
     
    C:\Users\Raph\AppData\Local\GCC\Controller.exe => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\GccProfiler.exe => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Modules\7z.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Modules\InSes.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\chrome.exe => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\debug.log => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\First Run => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\wow_helper.exe => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\chrome.dll => Moved successfully.
    Could not move "C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\chrome_100_percent.pak" => Scheduled to move on reboot.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\chrome_child.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\chrome_frame_helper.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\chrome_frame_helper.exe => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\chrome_launcher.exe => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\chrome_touch_100_percent.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\d3dcompiler_43.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\d3dcompiler_46.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\delegate_execute.exe => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\ffmpegsumo.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\icudt.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\libegl.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\libglesv2.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\libpeerconnection.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\metro_driver.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\nacl64.exe => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\nacl_irt_x86_32.nexe => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\nacl_irt_x86_64.nexe => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\npchrome_frame.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\pdf.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\ppgooglenaclpluginchrome.dll => Moved successfully.
    Could not move "C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\resources.pak" => Scheduled to move on reboot.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\secondarytile.png => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\widevinecdmadapter.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\xinput1_3.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\VisualElements\logo.png => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\VisualElements\smalllogo.png => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\VisualElements\splash-620x300.png => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\PepperFlash\manifest.json => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\PepperFlash\pepflashplayer.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\am.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\am.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\ar.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\ar.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\bg.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\bg.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\bn.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\bn.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\ca.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\ca.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\cs.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\cs.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\da.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\da.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\de.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\de.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\el.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\el.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\en-GB.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\en-GB.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\en-US.dll => Moved successfully.
    Could not move "C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\en-US.pak" => Scheduled to move on reboot.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\es-419.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\es-419.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\es.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\es.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\et.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\et.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\fa.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\fa.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\fi.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\fi.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\fil.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\fil.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\fr.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\fr.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\gu.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\gu.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\he.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\he.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\hi.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\hi.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\hr.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\hr.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\hu.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\hu.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\id.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\id.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\it.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\it.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\ja.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\ja.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\kn.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\kn.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\ko.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\ko.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\lt.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\lt.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\lv.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\lv.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\ml.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\ml.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\mr.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\mr.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\ms.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\ms.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\nb.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\nb.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\nl.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\nl.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\pl.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\pl.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\pt-BR.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\pt-BR.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\pt-PT.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\pt-PT.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\ro.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\ro.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\ru.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\ru.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\sk.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\sk.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\sl.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\sl.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\sr.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\sr.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\sv.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\sv.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\sw.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\sw.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\ta.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\ta.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\te.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\te.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\th.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\th.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\tr.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\tr.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\uk.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\uk.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\vi.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\vi.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\zh-CN.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\zh-CN.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\zh-TW.dll => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\zh-TW.pak => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Extensions\external_extensions.json => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\default_apps\docs.crx => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\default_apps\drive.crx => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\default_apps\external_extensions.json => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\default_apps\gmail.crx => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\default_apps\search.crx => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\default_apps\youtube.crx => Moved successfully.
    Could not move "C:\Users\Raph\AppData\Local\GCC" directory. => Scheduled to move on reboot.
     
    C:\ProgramData\pastaleads => Moved successfully.
    C:\Windows\System32\Tasks\GC_Informer => Moved successfully.
    C:\Windows\System32\Tasks\GC_Scheduler => Moved successfully.
    "C:\Program Files (x86)\DownloadXCtrl.com" => File/Directory not found.
    "C:\Windows\SysWOW64\plsapp.dll" => File/Directory not found.
    C:\Windows\system32\plsapp64.dll => Moved successfully.
     
    ========================= folder: C:\Windows\system32\RsFx ========================
     
     
    ====== End of Folder: ======
     
     
    ========================= folder: C:\Windows\SysWOW64\1033 ========================
     
    2008-07-03 21:32 - 2008-07-03 21:32 - 0099118 _____ () C:\Windows\SysWOW64\1033\s10ch_sqlncli.chm
    2008-07-10 02:38 - 2008-07-10 02:38 - 0229912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\1033\sqlnclir10.rll
    2010-03-18 23:21 - 2010-03-18 23:21 - 0017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\1033\vsjitdebuggerui.dll
     
    ====== End of Folder: ======
     
     
    ========================= folder: C:\Windows\system32\1033 ========================
     
    2008-07-03 21:32 - 2008-07-03 21:32 - 0099118 _____ () C:\Windows\system32\1033\s10ch_sqlncli.chm
    2008-07-10 04:58 - 2008-07-10 04:58 - 0229400 _____ (Microsoft Corporation) C:\Windows\system32\1033\sqlnclir10.rll
    2010-03-18 22:01 - 2010-03-18 22:01 - 0017760 _____ (Microsoft Corporation) C:\Windows\system32\1033\VSJitDebuggerUI.dll
     
    ====== End of Folder: ======
     
     
    ========================= folder: C:\Windows\SysWOW64\Macromed ========================
     
    2014-03-11 17:03 - 2014-03-11 17:03 - 0000000 ____D () C:\Windows\SysWOW64\Macromed\Director
    2014-01-28 23:39 - 2014-01-28 23:39 - 0000330 _____ () C:\Windows\SysWOW64\Macromed\Director\M5drvr32.exe
    2014-01-28 23:39 - 2014-01-28 23:39 - 0000330 _____ () C:\Windows\SysWOW64\Macromed\Director\M5if32.dll
    2013-10-14 22:54 - 2014-03-12 07:07 - 0000000 ____D () C:\Windows\SysWOW64\Macromed\Flash
    2013-10-14 22:54 - 2014-03-11 21:25 - 1575043 _____ () C:\Windows\SysWOW64\Macromed\Flash\activex.vch
    2014-03-11 21:25 - 2014-03-11 21:25 - 16350088 ____R (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\Flash32_12_0_0_77.ocx
    2013-10-14 22:54 - 2014-03-26 10:11 - 0015728 _____ () C:\Windows\SysWOW64\Macromed\Flash\FlashInstall.log
    2013-10-14 22:54 - 2014-03-11 21:25 - 0257928 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    2014-03-11 21:25 - 2014-03-11 21:25 - 0492936 _____ (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_12_0_0_77_ActiveX.dll
    2014-03-11 21:25 - 2014-03-11 21:25 - 0841096 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_12_0_0_77_ActiveX.exe
    2013-10-14 23:42 - 2013-10-14 23:42 - 0001595 _____ () C:\Windows\SysWOW64\Macromed\Flash\install.log
    2013-10-14 22:54 - 2014-01-04 12:28 - 0000047 _____ () C:\Windows\SysWOW64\Macromed\Flash\mms.cfg
    2014-03-11 17:03 - 2014-03-11 17:03 - 0000000 ____D () C:\Windows\SysWOW64\Macromed\Shockwave 10
    2014-01-28 23:39 - 2014-01-28 23:39 - 0475136 _____ (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Shockwave 10\Control.dll
    2014-01-28 23:39 - 2014-01-28 23:39 - 1507328 _____ (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Shockwave 10\dirapiX.dll
    2014-01-28 23:39 - 2014-01-28 23:39 - 0024576 _____ (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Shockwave 10\DynaPlayer.dll
    2014-01-28 23:39 - 2014-01-28 23:39 - 0606208 _____ (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Shockwave 10\iml32X.dll
    2014-01-28 23:39 - 2014-01-28 23:39 - 0339968 _____ (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Shockwave 10\Plugin.dll
    2014-01-28 23:39 - 2014-01-28 23:39 - 0479232 _____ (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Shockwave 10\PluginPing.dll
    2014-01-28 23:39 - 2014-01-28 23:39 - 0184320 _____ (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Shockwave 10\Proj.dll
    2014-01-28 23:39 - 2014-01-28 23:39 - 0009622 _____ () C:\Windows\SysWOW64\Macromed\Shockwave 10\shockwave_Projector_Loader.dcr
    2014-01-28 23:39 - 2014-01-28 23:39 - 0077824 _____ (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Shockwave 10\SwInit.exe
    2014-01-28 23:39 - 2014-01-28 23:39 - 0042040 _____ () C:\Windows\SysWOW64\Macromed\Shockwave 10\SwLogo.bmp
    2014-01-28 23:39 - 2014-01-28 23:39 - 0086016 _____ (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Shockwave 10\SwMenuX.dll
    2014-01-28 23:39 - 2014-01-28 23:39 - 0098304 _____ (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Shockwave 10\SwOnce.dll
    2014-03-11 17:03 - 2014-03-11 17:03 - 0000000 ____D () C:\Windows\SysWOW64\Macromed\Shockwave 10\Xtras
    2014-01-28 23:39 - 2014-01-28 23:39 - 0002379 _____ () C:\Windows\SysWOW64\Macromed\Shockwave 10\Xtras\autodownload.txt
    2014-01-28 23:39 - 2014-01-28 23:39 - 0028672 _____ (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Shockwave 10\Xtras\CBrowser.x32
    2014-01-28 23:39 - 2014-01-28 23:39 - 0040960 _____ (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Shockwave 10\Xtras\INetURL.x32
    2014-01-28 23:39 - 2014-01-28 23:39 - 0180224 _____ (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Shockwave 10\Xtras\Multiusr.x32
    2014-01-28 23:39 - 2014-01-28 23:39 - 0053248 _____ (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Shockwave 10\Xtras\Netfile.x32
    2014-01-28 23:39 - 2014-01-28 23:39 - 0049152 _____ (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Shockwave 10\Xtras\Netlingo.x32
    2014-01-28 23:39 - 2014-01-28 23:39 - 0053248 _____ (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Shockwave 10\Xtras\Speech.x32
     
    ====== End of Folder: ======
     
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3466B582-D74F-4090-B442-420E481642D1} => Key deleted successfully.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3466B582-D74F-4090-B442-420E481642D1} => Key deleted successfully.
    C:\Windows\System32\Tasks\TidyNetwork Update => Moved successfully.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\TidyNetwork Update => Key deleted successfully.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{42FAECE4-54EE-4D67-B359-271E55736BE2} => Key deleted successfully.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{42FAECE4-54EE-4D67-B359-271E55736BE2} => Key deleted successfully.
    C:\Windows\System32\Tasks\GC_Informer not found.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GC_Informer => Key deleted successfully.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{57600876-8597-47F2-83FD-2E41333EE940} => Key deleted successfully.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{57600876-8597-47F2-83FD-2E41333EE940} => Key deleted successfully.
    C:\Windows\System32\Tasks\Microsoft\Windows\Maintenance\UP_Scheduler => Moved successfully.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Maintenance\UP_Scheduler => Key deleted successfully.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{79F3B02B-3A5F-45B4-90E0-777C46BD48DC} => Key deleted successfully.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79F3B02B-3A5F-45B4-90E0-777C46BD48DC} => Key deleted successfully.
    C:\Windows\System32\Tasks\GC_Scheduler not found.
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GC_Scheduler => Key deleted successfully.
    HKLM\System\CurrentControlSet\Control\SafeBoot\Network\plsapp => Key deleted successfully.
     
    => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-04-08 17:29:49)<=
     
    C:\Program Files (x86)\pastaleads => Moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\chrome_100_percent.pak => Is moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\resources.pak => Is moved successfully.
    C:\Users\Raph\AppData\Local\GCC\Chrome-bin\31.0.1650.63\Locales\en-US.pak => Is moved successfully.
    C:\Users\Raph\AppData\Local\GCC => Moved successfully.
     
    ==== End of Fixlog ====
     
     
    # AdwCleaner v3.022 - Report created 30/03/2014 at 13:44:02
    # Updated 13/03/2014 by Xplode
    # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
    # Username : Raph - RAPH-PC
    # Running from : F:\AdwCleaner.exe
    # Option : Scan
     
    ***** [ Services ] *****
     
     
    ***** [ Files / Folders ] *****
     
    File Found : C:\END
    Folder Found C:\Windows\SysWOW64\AI_RecycleBin
     
    ***** [ Shortcuts ] *****
     
     
    ***** [ Registry ] *****
     
    Key Found : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
    Key Found : HKCU\Software\Conduit
    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Key Found : HKCU\Software\Softonic
    Key Found : [x64] HKCU\Software\Conduit
    Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
    Key Found : [x64] HKCU\Software\Softonic
    Key Found : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
    Key Found : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
    Key Found : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
    Key Found : HKLM\SOFTWARE\Classes\AppID\{9DC8FA51-B596-4F77-802C-5B295919C205}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{3E28F712-0D6C-4EE3-AC8C-8F060F5D7C33}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{6CE321DA-DC11-45C6-A0FC-4E8A7D978ABC}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{6EEBC7FF-67DA-4B90-9251-C2C5696E4B48}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{74137531-80F7-406F-9543-7D11385FA8C8}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{832599B2-55BF-4437-8F3E-030CF5AEB262}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{9B7B034B-944A-4261-B487-862F642F7615}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{B1A429DB-FB06-4645-B7C0-0CC405EAD3CD}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{DD67706E-819E-4EBD-BF8D-6D6147CC7A49}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{F62A4AF9-58B4-4FEC-89CC-D717A547D8E8}
    Key Found : HKLM\SOFTWARE\Classes\PCProxy.DataContainer
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
     
    ***** [ Browsers ] *****
     
    -\\ Internet Explorer v11.0.9600.16521
     
     
    -\\ Google Chrome v33.0.1750.154
     
    [ File : C:\Users\Raph\AppData\Local\Google\Chrome\User Data\Default\preferences ]
     
     
    *************************
     
    AdwCleaner[R0].txt - [3472 octets] - [30/03/2014 13:44:02]
     
    ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [3532 octets] ##########
    # AdwCleaner v3.023 - Report created 08/04/2014 at 17:36:38
    # Updated 01/04/2014 by Xplode
    # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
    # Username : Raph - RAPH-PC
    # Running from : C:\Users\Raph\Desktop\AdwCleaner.exe
    # Option : Scan
     
    ***** [ Services ] *****
     
     
    ***** [ Files / Folders ] *****
     
     
    ***** [ Shortcuts ] *****
     
     
    ***** [ Registry ] *****
     
    Key Found : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Key Found : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
    Key Found : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
    Key Found : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
     
    ***** [ Browsers ] *****
     
    -\\ Internet Explorer v11.0.9600.16521
     
     
    -\\ Google Chrome v33.0.1750.154
     
    [ File : C:\Users\Raph\AppData\Local\Google\Chrome\User Data\Default\preferences ]
     
     
    *************************
     
    AdwCleaner[R0].txt - [4860 octets] - [30/03/2014 13:44:02]
    AdwCleaner[S0].txt - [3557 octets] - [30/03/2014 14:11:26]
     
    ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [4980 octets] ##########
     

    • 0

    #8
    Buddierdl

    Buddierdl

      Trusted Helper

    • Malware Removal
    • 2,524 posts

    You can let adwCleaner clean the few things it found.

     
    You're logs are looking clean. Let's sweep for remnants.
     
    Step 1: Run SecurityCheck
     
    Download Security Check by screen317 from here or here.
    • Save it to your Desktop.
    • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
     
    Step 2: Run MBAM.
     
    • Open Malwarebytes and update the definitions.
    • Once the program has loaded, select "Perform Quick Scan", then click Scan.
    • The scan may take some time to finish, so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy&Paste the entire report in your next reply.
    Extra Note:
    If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
     
    Step 3: Run online scan.
     
    Run ESET Online Scanner:
     
    Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.
     
    • Please go here then click on: EOLS1.gif

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
  • Select the option YES, I accept the Terms of Use then click on: EOLS2.gif
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is Not checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: EOLS3.gif
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically. The scan may take several hours.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: EOLS4.gif
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.
  • Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
     
    Things I need in your next reply:
  • SecurityCheck log
  • MBAM log
  • ESET log
  • Any outstanding problems?

    • 0

    #9
    moviebuff6000

    moviebuff6000

      New Member

    • Topic Starter
    • Member
    • Pip
    • 6 posts

    Below are the log files you requested.  Computer is running fine! Thanks!
     
     Results of screen317's Security Check version 0.99.81  
     Windows 7 Service Pack 1 x64 (UAC is enabled)  
     Internet Explorer 11  
    ``````````````Antivirus/Firewall Check:`````````````` 
     Windows Firewall Enabled!  
    Norton 360    
     WMI entry may not exist for antivirus; attempting automatic update. 
    `````````Anti-malware/Other Utilities Check:````````` 
     Java 7 Update 51  
     Adobe Reader XI  
     Google Chrome 33.0.1750.154  
    ````````Process Check: objlist.exe by Laurent````````  
     Malwarebytes Anti-Malware mbamservice.exe  
     Malwarebytes Anti-Malware mbam.exe  
     RSA SecurID Token Common OnlineScannerApp.exe -?-   
    `````````````````System Health check````````````````` 
     Total Fragmentation on Drive C:  
    ````````````````````End of Log`````````````````````` 
     
     
    Malwarebytes Anti-Malware
    www.malwarebytes.org
     
    Scan Date: 4/9/2014
    Scan Time: 9:41:43 PM
    Logfile: mbam.txt
    Administrator: Yes
     
    Version: 2.00.1.1004
    Malware Database: v2014.04.10.01
    Rootkit Database: v2014.03.27.01
    License: Trial
    Malware Protection: Enabled
    Malicious Website Protection: Enabled
    Chameleon: Disabled
     
    OS: Windows 7 Service Pack 1
    CPU: x64
    File System: NTFS
    User: Raph
     
    Scan Type: Threat Scan
    Result: Completed
    Objects Scanned: 299257
    Time Elapsed: 14 min, 1 sec
     
    Memory: Enabled
    Startup: Enabled
    Filesystem: Enabled
    Archives: Enabled
    Rootkits: Enabled
    Shuriken: Enabled
    PUP: Enabled
    PUM: Enabled
     
    Processes: 0
    (No malicious items detected)
     
    Modules: 0
    (No malicious items detected)
     
    Registry Keys: 0
    (No malicious items detected)
     
    Registry Values: 0
    (No malicious items detected)
     
    Registry Data: 0
    (No malicious items detected)
     
    Folders: 0
     

    C:\Users\Raph\Downloads\Clue Finders Reading Adventures Mystery of the Missing Amulet.iso Win32/Adware.DSSAgent application
    E:\$RECYCLE.BIN\S-1-5-21-118334814-2377488127-2383457493-1000\$R5OT73F.exe Win32/Adware.Toolbar.Shopper application
    E:\$RECYCLE.BIN\S-1-5-21-118334814-2377488127-2383457493-1000\$RBTT047\pe keygen.exe a variant of Win32/Keygen.BR potentially unsafe application
    E:\$RECYCLE.BIN\S-1-5-21-118334814-2377488127-2383457493-1000\$RRTEZUC\pe keygen.exe a variant of Win32/Keygen.BR potentially unsafe application
     
    (No malicious items detected)
     
    Files: 0
    (No malicious items detected)
     
    Physical Sectors: 0
    (No malicious items detected)
     
     
    (end)

    • 0

    #10
    Buddierdl

    Buddierdl

      Trusted Helper

    • Malware Removal
    • 2,524 posts
    Congratulations, movie buff :). Your computer now appears to be clean. Please complete the followings steps to finalize the cleaning process.
     
    It would be a good idea also to reset your firewall in case the malware opened any ports.
     
    I would recommend securing Adobe Reader against the latest exploits as follows:
     
  • Launch Adobe Reader.
  • Click on Edit and select Preferences.
  • On the Left, click on the Javascript category and Uncheck Enable Acrobat Javascript.
  • Click on the Security (Enhanced) category and Uncheck Automatically trust sites from my Win OS security zones.
  • Click on the Trust Manager category and Uncheck Allow opening of non-PDF file attachments with external applications.
  • Click the OK button.
  •  
    Cleanup Time!: Please download and run Delfix:
     
    delfix.JPG
     
    Empty temp files. I would recommend doing this every so often to free up some space on your computer.
     
    Download TFC to your desktop
    • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean
  •  
    Ensure that Windows is always updated. Keeping Windows updated is very important to prevent security vulnerabilities. I recommend turning on automatic updates following the instructions below:
    • First, click on Start and click onAll Programs, then Windows Update.
    • Click on Change Settings in the left pane and then check the option for Automatic Updates.
     
    Always ensure that your firewall and anti-virus program are updated and running. These are your first line of defense against infection.
     
    Make sure that you keep all of your programs updated. Out-of-date programs can make your computer more vulnerable to infection. Software manufacturers release updates to fix security problems as they are discovered. Secunia Personal Software Inspector, free to download here, is a good program that will scan your computer looking for programs that need to be updated.
     
    This article has good information about how computers get infected. You can read it for good tips on staying clean and safe. 

    • 0

    #11
    moviebuff6000

    moviebuff6000

      New Member

    • Topic Starter
    • Member
    • Pip
    • 6 posts

    Thanks so much. You are awesome and thanks for the extra tips to keep everything secure.


    • 0

    #12
    Buddierdl

    Buddierdl

      Trusted Helper

    • Malware Removal
    • 2,524 posts

    You're welcome.  :)


    • 0

    #13
    Buddierdl

    Buddierdl

      Trusted Helper

    • Malware Removal
    • 2,524 posts
    Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

    If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

    Everyone else please begin a New Topic.
    • 0






    Similar Topics

    0 user(s) are reading this topic

    0 members, 0 guests, 0 anonymous users

    As Featured On:

    Microsoft Yahoo BBC MSN PC Magazine Washington Post HP