Hi!
My PC has been booting and running slower and slower lately. I got suspicious when I attempted to use IE and the screen flashed as though the window were going to open but something would not allow it to. I have found that IE is not located in my Programs and Features list. However, I still have the icons in my start menu as well as on my desktop and files in the Programs files folders. I attempted to go to my bank's website and was given the warning about being on a public network, or computer. Normally it does not, instead it knows it is a private computer. I also noticed that my PC isn't sleeping anymore. I originally had it set to sleep after a specific amount of time and then request my password to regain access afterwards.
I have run AVAST and found 54 items during a boot scan which I moved to the virus chest.
I have run MBAM and found the following:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 6/13/2014
Scan Time: 2:01:48 AM
Logfile:
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.06.13.02
Rootkit Database: v2014.06.02.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Koony
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 281362
Time Elapsed: 34 min, 3 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 1
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Updater\WajamUpdaterV3.exe, 2956, Delete-on-Reboot, [0ee83542b4c79b9b23fb6f6e37cc30d0]
Modules: 0
(No malicious items detected)
Registry Keys: 161
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\APPID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}, Quarantined, [6393294e57242214969ae98c6999a060],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}, Quarantined, [6393294e57242214969ae98c6999a060],
PUP.Optional.DefaultTab.A, HKLM\SOFTWARE\CLASSES\APPID\{72D89EBF-0C5D-4190-91FD-398E45F1D007}, Quarantined, [04f21d5a304bef47622c122f22e09967],
PUP.Optional.DefaultTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{72D89EBF-0C5D-4190-91FD-398E45F1D007}, Quarantined, [04f21d5a304bef47622c122f22e09967],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\APPID\{80FABB17-63AF-4655-9F07-B6509EE37AF2}, Quarantined, [eb0b9add9be0cb6ba80ba4d0c141bc44],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassSvc, Quarantined, [eb0b9add9be0cb6ba80ba4d0c141bc44],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [eb0b9add9be0cb6ba80ba4d0c141bc44],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassSvc, Quarantined, [eb0b9add9be0cb6ba80ba4d0c141bc44],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [eb0b9add9be0cb6ba80ba4d0c141bc44],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{80FABB17-63AF-4655-9F07-B6509EE37AF2}, Quarantined, [eb0b9add9be0cb6ba80ba4d0c141bc44],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{80FABB17-63AF-4655-9F07-B6509EE37AF2}, Quarantined, [eb0b9add9be0cb6ba80ba4d0c141bc44],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\APPID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}, Quarantined, [d71f2552bac19b9b43eeff768d75936d],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}, Quarantined, [d71f2552bac19b9b43eeff768d75936d],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\APPID\{F48FC5B2-094A-44C7-B48C-289738C9582D}, Quarantined, [2bcbc5b28bf01a1c486c641042c0b44c],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.Update3COMClassService, Quarantined, [2bcbc5b28bf01a1c486c641042c0b44c],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.Update3COMClassService.1.0, Quarantined, [2bcbc5b28bf01a1c486c641042c0b44c],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.Update3COMClassService, Quarantined, [2bcbc5b28bf01a1c486c641042c0b44c],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.Update3COMClassService.1.0, Quarantined, [2bcbc5b28bf01a1c486c641042c0b44c],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{F48FC5B2-094A-44C7-B48C-289738C9582D}, Quarantined, [2bcbc5b28bf01a1c486c641042c0b44c],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F48FC5B2-094A-44C7-B48C-289738C9582D}, Quarantined, [2bcbc5b28bf01a1c486c641042c0b44c],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\CLSID\{06e3475c-5521-4de8-bb12-50720f21631c}, Quarantined, [e80e1e592c4fb77f60ae61dde22015eb],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{06E3475C-5521-4DE8-BB12-50720F21631C}, Quarantined, [e80e1e592c4fb77f60ae61dde22015eb],
PUP.Optional.MindSpark.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{06E3475C-5521-4DE8-BB12-50720F21631C}, Quarantined, [e80e1e592c4fb77f60ae61dde22015eb],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{06E3475C-5521-4DE8-BB12-50720F21631C}, Quarantined, [e80e1e592c4fb77f60ae61dde22015eb],
PUP.Optional.MindSpark.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{06E3475C-5521-4DE8-BB12-50720F21631C}, Quarantined, [e80e1e592c4fb77f60ae61dde22015eb],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{06E3475C-5521-4DE8-BB12-50720F21631C}, Quarantined, [e80e1e592c4fb77f60ae61dde22015eb],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\CLSID\{b7acdf9c-c4f9-4d5d-998e-b147866b4d4c}, Quarantined, [3abc1c5b66159e98c74840fe748e52ae],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{B7ACDF9C-C4F9-4D5D-998E-B147866B4D4C}, Quarantined, [3abc1c5b66159e98c74840fe748e52ae],
PUP.Optional.MindSpark.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{B7ACDF9C-C4F9-4D5D-998E-B147866B4D4C}, Quarantined, [3abc1c5b66159e98c74840fe748e52ae],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{B7ACDF9C-C4F9-4D5D-998E-B147866B4D4C}, Quarantined, [3abc1c5b66159e98c74840fe748e52ae],
PUP.Optional.MindSpark.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{B7ACDF9C-C4F9-4D5D-998E-B147866B4D4C}, Quarantined, [3abc1c5b66159e98c74840fe748e52ae],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{B7ACDF9C-C4F9-4D5D-998E-B147866B4D4C}, Quarantined, [3abc1c5b66159e98c74840fe748e52ae],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\CLASSES\CLSID\{cf51de5b-eb36-4114-bb69-84df63fbadb4}, Quarantined, [f501d3a46b106acc9d74291536cc01ff],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CF51DE5B-EB36-4114-BB69-84DF63FBADB4}, Quarantined, [f501d3a46b106acc9d74291536cc01ff],
PUP.Optional.MindSpark.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{CF51DE5B-EB36-4114-BB69-84DF63FBADB4}, Quarantined, [f501d3a46b106acc9d74291536cc01ff],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{CF51DE5B-EB36-4114-BB69-84DF63FBADB4}, Quarantined, [f501d3a46b106acc9d74291536cc01ff],
PUP.Optional.MindSpark.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{CF51DE5B-EB36-4114-BB69-84DF63FBADB4}, Quarantined, [f501d3a46b106acc9d74291536cc01ff],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{CF51DE5B-EB36-4114-BB69-84DF63FBADB4}, Quarantined, [f501d3a46b106acc9d74291536cc01ff],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{1E0C9B2A-6447-452C-B012-2314A0C29412}, Quarantined, [20d6e196f78438fea80d0d676e94ff01],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [20d6e196f78438fea80d0d676e94ff01],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassMachineFallback, Quarantined, [20d6e196f78438fea80d0d676e94ff01],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassMachineFallback, Quarantined, [20d6e196f78438fea80d0d676e94ff01],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [20d6e196f78438fea80d0d676e94ff01],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{34A8CEB6-89BB-49F1-B5E4-0D0D6C21F3B1}, Quarantined, [51a5c4b31b601224ad090b69dc26c937],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.CredentialDialogMachine.1.0, Quarantined, [51a5c4b31b601224ad090b69dc26c937],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.CredentialDialogMachine, Quarantined, [51a5c4b31b601224ad090b69dc26c937],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.CredentialDialogMachine, Quarantined, [51a5c4b31b601224ad090b69dc26c937],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.CredentialDialogMachine.1.0, Quarantined, [51a5c4b31b601224ad090b69dc26c937],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3A4DBD3A-98CC-41CE-AD21-352D42B6F754}, Quarantined, [a84e8bec14679e981c9b4e26c53def11],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.CoCreateAsync.1.0, Quarantined, [a84e8bec14679e981c9b4e26c53def11],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.CoCreateAsync, Quarantined, [a84e8bec14679e981c9b4e26c53def11],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.CoCreateAsync, Quarantined, [a84e8bec14679e981c9b4e26c53def11],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.CoCreateAsync.1.0, Quarantined, [a84e8bec14679e981c9b4e26c53def11],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4F8A50F6-69DE-4BE3-A33A-A1079B9AC0DB}, Quarantined, [e313beb9c9b216208830d69e748e34cc],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.Update3WebMachineFallback.1.0, Quarantined, [e313beb9c9b216208830d69e748e34cc],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.Update3WebMachineFallback, Quarantined, [e313beb9c9b216208830d69e748e34cc],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.Update3WebMachineFallback, Quarantined, [e313beb9c9b216208830d69e748e34cc],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.Update3WebMachineFallback.1.0, Quarantined, [e313beb9c9b216208830d69e748e34cc],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{501CB57A-D4E2-4855-96AD-EDB0A9083395}, Quarantined, [a353f087a9d21d190aaf3143c93920e0],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.CoreMachineClass.1, Quarantined, [a353f087a9d21d190aaf3143c93920e0],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.CoreMachineClass, Quarantined, [a353f087a9d21d190aaf3143c93920e0],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.CoreMachineClass, Quarantined, [a353f087a9d21d190aaf3143c93920e0],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.CoreMachineClass.1, Quarantined, [a353f087a9d21d190aaf3143c93920e0],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5}, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\wajam.WajamBHO.1, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\wajam.WajamBHO, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\wajam.WajamBHO, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\wajam.WajamBHO.1, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.Wajam.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.Wajam.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.Wajam.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.Wajam.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\wajam.WajamDownloader.1, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\wajam.WajamDownloader, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\wajam.WajamDownloader, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\wajam.WajamDownloader.1, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6FF2C4DD-77A4-4BB5-BA4C-B42DEFBF9137}, Quarantined, [fcfa89ee6e0df83e447690e415eda55b],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.ProcessLauncher.1.0, Quarantined, [fcfa89ee6e0df83e447690e415eda55b],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.ProcessLauncher, Quarantined, [fcfa89ee6e0df83e447690e415eda55b],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.ProcessLauncher, Quarantined, [fcfa89ee6e0df83e447690e415eda55b],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.ProcessLauncher.1.0, Quarantined, [fcfa89ee6e0df83e447690e415eda55b],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{83ABA270-8390-4CA6-AE48-FC089F55629E}, Quarantined, [a84ec3b47308de58bcff2153ce3425db],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [a84ec3b47308de58bcff2153ce3425db],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassMachine, Quarantined, [a84ec3b47308de58bcff2153ce3425db],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassMachine, Quarantined, [a84ec3b47308de58bcff2153ce3425db],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [a84ec3b47308de58bcff2153ce3425db],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{8B218A5F-1A3D-4347-94EF-A79575EB8094}, Quarantined, [7284d6a1007bdc5a4e6e5321d0321de3],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{0D89DE71-3D99-4288-84DC-F18F1047A7D8}, Quarantined, [7284d6a1007bdc5a4e6e5321d0321de3],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{8C338DDB-19FC-4C1F-B74D-6931EE55F7A1}, Quarantined, [fcfae790314a93a3d6e7472d9e64af51],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{7F1796B2-BEC6-427B-B734-F9C75ED94A80}, Quarantined, [fcfae790314a93a3d6e7472d9e64af51],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLive.OneClickCtrl.9, Quarantined, [fcfae790314a93a3d6e7472d9e64af51],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLive.OneClickCtrl.9, Quarantined, [fcfae790314a93a3d6e7472d9e64af51],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7F1796B2-BEC6-427B-B734-F9C75ED94A80}, Quarantined, [fcfae790314a93a3d6e7472d9e64af51],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{7F1796B2-BEC6-427B-B734-F9C75ED94A80}, Quarantined, [fcfae790314a93a3d6e7472d9e64af51],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLive.Update3WebControl.3, Quarantined, [fcfae790314a93a3d6e7472d9e64af51],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLive.Update3WebControl.3, Quarantined, [fcfae790314a93a3d6e7472d9e64af51],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8C338DDB-19FC-4C1F-B74D-6931EE55F7A1}, Quarantined, [fcfae790314a93a3d6e7472d9e64af51],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{8C338DDB-19FC-4C1F-B74D-6931EE55F7A1}, Quarantined, [fcfae790314a93a3d6e7472d9e64af51],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{9BDB5E09-4BBA-4422-8C2B-529B281C32B8}, Quarantined, [c92dda9d7dfe53e3e3dbde9608fa12ee],
PUP.Optional.WordOV, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{B78F92C8-DEB3-11E2-9A0A-FB64281D6ADE}, Quarantined, [c5311d5aea91a88e1dd73a3b1fe3bc44],
PUP.Optional.WordOV, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{B78F92C8-DEB3-11E2-9A0A-FB64281D6ADE}, Quarantined, [c5311d5aea91a88e1dd73a3b1fe3bc44],
PUP.Optional.WordOV, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{B78F92C8-DEB3-11E2-9A0A-FB64281D6ADE}, Quarantined, [c5311d5aea91a88e1dd73a3b1fe3bc44],
PUP.Optional.WordOV, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{B78F92C8-DEB3-11E2-9A0A-FB64281D6ADE}, Quarantined, [c5311d5aea91a88e1dd73a3b1fe3bc44],
PUP.Optional.WordOV, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{B78F92C8-DEB3-11E2-9A0A-FB64281D6ADE}, Quarantined, [c5311d5aea91a88e1dd73a3b1fe3bc44],
PUP.Optional.WordOV, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{B78F92C8-DEB3-11E2-9A0A-FB64281D6ADE}, Quarantined, [c5311d5aea91a88e1dd73a3b1fe3bc44],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C536F080-57B7-46D6-8894-C647553F2889}, Quarantined, [46b06b0c7dfe74c23d826b09fa088080],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLive.OneClickProcessLauncherMachine.1.0, Quarantined, [46b06b0c7dfe74c23d826b09fa088080],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLive.OneClickProcessLauncherMachine, Quarantined, [46b06b0c7dfe74c23d826b09fa088080],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLive.OneClickProcessLauncherMachine, Quarantined, [46b06b0c7dfe74c23d826b09fa088080],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLive.OneClickProcessLauncherMachine.1.0, Quarantined, [46b06b0c7dfe74c23d826b09fa088080],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C536F080-57B7-46D6-8894-C647553F2889}, Quarantined, [46b06b0c7dfe74c23d826b09fa088080],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CA5D945F-E738-4D0B-A0B5-25AC51C64659}, Quarantined, [8f67ccabf58642f4fdc378fc9270d729],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.CoreClass.1, Quarantined, [8f67ccabf58642f4fdc378fc9270d729],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.CoreClass, Quarantined, [8f67ccabf58642f4fdc378fc9270d729],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.CoreClass, Quarantined, [8f67ccabf58642f4fdc378fc9270d729],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.CoreClass.1, Quarantined, [8f67ccabf58642f4fdc378fc9270d729],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F7698761-4ABA-45C2-A5BB-D2163922C725}, Quarantined, [0aecde9982f931052899d59f0200cb35],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.Update3WebSvc.1.0, Quarantined, [0aecde9982f931052899d59f0200cb35],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.Update3WebSvc, Quarantined, [0aecde9982f931052899d59f0200cb35],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.Update3WebSvc, Quarantined, [0aecde9982f931052899d59f0200cb35],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.Update3WebSvc.1.0, Quarantined, [0aecde9982f931052899d59f0200cb35],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{FFCC53E6-2655-47FC-A89B-54E8D7F305D1}, Quarantined, [00f6b6c190eb0e28556d3f35e41e4ab6],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.Update3WebMachine.1.0, Quarantined, [00f6b6c190eb0e28556d3f35e41e4ab6],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.Update3WebMachine, Quarantined, [00f6b6c190eb0e28556d3f35e41e4ab6],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.Update3WebMachine, Quarantined, [00f6b6c190eb0e28556d3f35e41e4ab6],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.Update3WebMachine.1.0, Quarantined, [00f6b6c190eb0e28556d3f35e41e4ab6],
PUP.Optional.DealPly.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{AE48ED75-5A56-4C5F-BBCE-6F1AC3875F66}, Quarantined, [7d799bdc5e1d5cdadc5c231f7c868a76],
PUP.Optional.TopArcadeHits.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{CF190686-9E72-403C-B99D-682ABDB63C5B}, Quarantined, [07efe7903c3f270f1449d1a30ef4df21],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}, Quarantined, [fcfa522582f93006019dc7adab57a65a],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}, Quarantined, [807699de483301354a55d59f8e745fa1],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\APPID\DealPlyLive.exe, Quarantined, [b046c7b0f08bd165c5c9ede9699a9f61],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\APPID\priam_bho.DLL, Quarantined, [61959ed9e893e6503c485b7d0cf79a66],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\DealPlyLive, Quarantined, [7284fa7d7efdaa8cc6c9c214c142ab55],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\Iminent, Quarantined, [6b8b54235b2053e3a473c1ff02004bb5],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\RecipeHub_2j, Quarantined, [777fd2a5b1ca0c2a322d11dfc93a639d],
PUP.Optional.TigerSavings.A, HKLM\SOFTWARE\WOW6432NODE\Tiger Savings, Quarantined, [886e0e698af1c96d49906b3bcd3532ce],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\Wajam, Quarantined, [e511275039426bcb22c743ac946f5ba5],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\DealPlyLive.exe, Quarantined, [995d7ef9f7842016f29c7660b74ced13],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\priam_bho.DLL, Quarantined, [e1150275bac186b02d57f2e69b68b749],
PUP.Optional.MindSpark.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@RecipeHub_2j.com/Plugin, Quarantined, [7d79fa7de2991b1ba272c3e6aa5809f7],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@tools.dpliveupdate.com/DealPlyLive Update;version=3, Quarantined, [7c7ad89f2952a4924f42dbfb08fb36ca],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@tools.dpliveupdate.com/DealPlyLive Update;version=9, Quarantined, [8670cbac205b80b68110498d4bb8936d],
PUP.Optional.Wajam.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WajamUpdaterV3, Quarantined, [0ee83542b4c79b9b23fb6f6e37cc30d0],
PUP.Optional.Conduit.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\ConduitSearchScopes, Quarantined, [8d69e88f4239b97deb7a4992857e9769],
PUP.Optional.DealPly.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DealPlyLive, Quarantined, [7185383fdba05fd7eaa9bc1a3ec5f60a],
PUP.Optional.Iminent.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Iminent, Quarantined, [589e7403fd7e31058c8cdde3d23038c8],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\RecipeHub_2j, Quarantined, [25d1c6b1e398e353c29e15dbd330c739],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [e80e6f08f685ca6cabfa6584eb18f10f],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, Quarantined, [62947205de9ded492f5b4574d52d946c],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\RecipeHub_2j, Quarantined, [3eb8b5c215662e089b62574bb34fa759],
PUP.Optional.FreeCauseTB.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\FREECAUSE\Toolbars, Quarantined, [d323284fc8b3c274cdaf10a6946e5ea2],
PUP.Optional.SnapDo.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR, Quarantined, [14e2a6d1770426106c9e8a358f7314ec],
PUP.Optional.Wajam.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WAJAM, Quarantined, [6f87e0978eed251161250ecad82ba35d],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Wajam, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
Registry Values: 5
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{cc8ae5b8-005b-4b1a-a27d-307eddffe5c8}, Quarantined, [fef84e29c4b71f17b957d668a062dc24],
PUP.Optional.MindSpark.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{CC8AE5B8-005B-4B1A-A27D-307EDDFFE5C8}, Quarantined, [fef84e29c4b71f17b957d668a062dc24],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\WAJAM|red, 4, Quarantined, [24d25225a4d790a699eeeaeec53eac54]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR|publisher, SnapdoGOblidooYB, Quarantined, [14e2a6d1770426106c9e8a358f7314ec]
PUP.Optional.Wajam.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WAJAM|affiliate_id, 3008, Quarantined, [6f87e0978eed251161250ecad82ba35d]
Registry Data: 5
PUP.Optional.Snapdo, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://feed.snapdo.c...earchtype=ds&q={searchTerms}&installDate={installDate}, Good: (http://www.google.com), Bad: (http://feed.snapdo.c...e={installDate}),Replaced,[d0261d5abebde94de67badc7689c17e9]
PUP.Optional.Snapdo, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, http://feed.snapdo.c...earchtype=ds&q={searchTerms}&installDate={installDate}, Good: (http://www.google.com), Bad: (http://feed.snapdo.c...e={installDate}),Replaced,[ec0a0671a2d9cf6778e8c8ac2bd9fb05]
PUP.Optional.Snapdo, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, http://feed.snapdo.c...earchtype=ds&q={searchTerms}&installDate={installDate}, Good: (http://www.google.com), Bad: (http://feed.snapdo.c...e={installDate}),Replaced,[df1785f2473452e4d390ec889371da26]
PUP.Optional.Snapdo, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, http://feed.snapdo.c...earchtype=ds&q={searchTerms}&installDate={installDate}, Good: (http://www.google.com), Bad: (http://feed.snapdo.c...e={installDate}),Replaced,[fdf9f1863d3e62d4382cfa7abb49ac54]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-1077101162-4101747896-2045992607-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, http://feed.snapdo.c...earchtype=ds&q={searchTerms}&installDate={installDate}, Good: (www.google.com), Bad: (http://feed.snapdo.c...e={installDate}),Replaced,[a551a5d20972df5722daa5c573919b65]
Folders: 35
PUP.Optional.DealPly.A, C:\ProgramData\DealPlyLive, Quarantined, [71856d0ad2a971c549de75129f63c53b],
PUP.Optional.DealPly.A, C:\ProgramData\DealPlyLive\Update, Quarantined, [71856d0ad2a971c549de75129f63c53b],
PUP.Optional.DealPly.A, C:\ProgramData\DealPlyLive\Update\Log, Quarantined, [71856d0ad2a971c549de75129f63c53b],
PUP.Optional.DealPly.A, C:\Users\Koony\AppData\Roaming\Dealply, Quarantined, [43b3d1a66e0dec4a41e7fb8cdb27857b],
PUP.Optional.DealPly.A, C:\Users\Koony\AppData\Roaming\Dealply\UpdateProc, Quarantined, [43b3d1a66e0dec4a41e7fb8cdb27857b],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\CrashReports, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\Download, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\Install, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\Offline, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\Offline\{2A902E00-86A1-4729-A274-D00B91696F5B}, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam, Delete-on-Reboot, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\IE, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Updater, Delete-on-Reboot, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.OpenCandy, C:\Users\Koony\AppData\Roaming\OpenCandy, Quarantined, [43b38fe8adce5fd7a0bfdfa8a75b5ea2],
PUP.Optional.OpenCandy, C:\Users\Koony\AppData\Roaming\OpenCandy\4E1C475D286048398D26363119BCCF32, Quarantined, [43b38fe8adce5fd7a0bfdfa8a75b5ea2],
PUP.Optional.OpenCandy, C:\Users\Koony\AppData\Roaming\OpenCandy\631F8A1D479F40F1B8533BBD54DDA228, Quarantined, [43b38fe8adce5fd7a0bfdfa8a75b5ea2],
PUP.Optional.DealPly.A, C:\Users\Koony\AppData\Local\DealPlyLive, Quarantined, [bf37492ea7d447ef6617e3a48e74eb15],
PUP.Optional.DealPly.A, C:\Users\Koony\AppData\Local\DealPlyLive\CrashReports, Quarantined, [bf37492ea7d447ef6617e3a48e74eb15],
PUP.Optional.Conduit.A, C:\ProgramData\Conduit\IE, Quarantined, [d2243245f58655e1b3377b0c14ee7d83],
PUP.Optional.Conduit.A, C:\ProgramData\Conduit\IE\CT3315828, Quarantined, [d2243245f58655e1b3377b0c14ee7d83],
PUP.Optional.MixiDJToolbar.A, C:\Users\Koony\AppData\Local\MixiDJ_V30, Quarantined, [e2147403611a5dd9c40f097f5aa8a060],
PUP.Optional.MixiDJToolbar.A, C:\Users\Koony\AppData\Local\MixiDJ_V30\Logs, Quarantined, [e2147403611a5dd9c40f097f5aa8a060],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Uninstall Wajam, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\RecipeHub_2j, Quarantined, [35c11c5bd7a4b58116adcec0dc26669a],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\RecipeHub_2j\bar, Quarantined, [35c11c5bd7a4b58116adcec0dc26669a],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\RecipeHub_2j\bar\1.bin, Quarantined, [35c11c5bd7a4b58116adcec0dc26669a],
PUP.Optional.SearchProtect.A, C:\Users\Koony\AppData\Local\SearchProtect, Quarantined, [56a00a6d3c3f7fb71a423f5e3ac824dc],
PUP.Optional.SearchProtect.A, C:\Users\Koony\AppData\Local\SearchProtect\Logs, Quarantined, [56a00a6d3c3f7fb71a423f5e3ac824dc],
Files: 141
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\IE\priam_bho.dll, Quarantined, [a551611689f27eb858da690bbd45a060],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\psmachine.dll, Quarantined, [7284d6a1007bdc5a4e6e5321d0321de3],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll, Quarantined, [fcfae790314a93a3d6e7472d9e64af51],
PUP.Optional.DownloadAdmin, C:\Users\Koony\Downloads\playpickle-setup.exe, Quarantined, [6393dc9b364513238628191d08fca858],
PUP.Optional.Iminent.A, C:\Users\Koony\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage, Quarantined, [37bf3740235882b4be628d1b778bf20e],
PUP.Optional.Conduit, C:\Windows\System32\Tasks\BackgroundContainer Startup Task, Quarantined, [639346317b005dd9f0be924d0cf72dd3],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Updater\WajamUpdaterV3.exe, Delete-on-Reboot, [0ee83542b4c79b9b23fb6f6e37cc30d0],
PUP.Optional.DealPly.A, C:\ProgramData\DealPlyLive\Update\Log\DealPlyLive.log, Quarantined, [71856d0ad2a971c549de75129f63c53b],
PUP.Optional.DealPly.A, C:\Users\Koony\AppData\Roaming\Dealply\UpdateProc\config.dat, Quarantined, [43b3d1a66e0dec4a41e7fb8cdb27857b],
PUP.Optional.DealPly.A, C:\Users\Koony\AppData\Roaming\Dealply\UpdateProc\TTL.DAT, Quarantined, [43b3d1a66e0dec4a41e7fb8cdb27857b],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\DealPlyLiveBroker.exe, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\DealPlyLiveHelper.msi, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\DealPlyLiveOnDemand.exe, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_bn.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_ca.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_cs.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_da.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_de.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_el.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_en-GB.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_en.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_es-419.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_es.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_et.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_fa.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_fi.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_fil.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_fr.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_gu.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_hr.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_hu.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_id.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_is.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_it.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_iw.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_ja.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_kn.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_ko.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_lt.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_lv.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_ml.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_mr.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_ms.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_nl.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_no.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_am.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_ar.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_pt-BR.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_pt-PT.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_ro.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_ru.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_sk.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_sl.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_sr.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_sv.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_sw.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_ta.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_te.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_th.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_tr.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_uk.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_ur.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_vi.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_zh-CN.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_zh-TW.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\psuser.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_bg.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_hi.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_pl.dll, Quarantined, [fef88ceb4b3076c063c63b4cf012d32d],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\uninstall.exe, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\IE\favicon.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\IE\wajamLogo.bmp, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\amazon.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\argos.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\ask.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\bestbuy.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\bing.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\ebay.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\etsy.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\facebook.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\favicon.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\google.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\homedepot.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\ikea.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\imdb.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\lowes.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\mercado.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\mysearchweb.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\myshopping.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\searchresult.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\sears.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\setting.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\settings.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\shopping.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\target.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\tesco.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\tripadvisor.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\twitter.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\wajam.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\walmart.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\wiki.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\yahoo.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Logos\zalando.ico, Quarantined, [55a12c4bb0cb989e939d2c5bb25051af],
PUP.Optional.OpenCandy, C:\Users\Koony\AppData\Roaming\OpenCandy\4E1C475D286048398D26363119BCCF32\PureLeadsSetupx21701.exe, Quarantined, [43b38fe8adce5fd7a0bfdfa8a75b5ea2],
PUP.Optional.OpenCandy, C:\Users\Koony\AppData\Roaming\OpenCandy\631F8A1D479F40F1B8533BBD54DDA228\SkypeSetupFull(Trackable550)trackable-6.16.0.105 (1).exe, Quarantined, [43b38fe8adce5fd7a0bfdfa8a75b5ea2],
PUP.Optional.OpenCandy, C:\Users\Koony\AppData\Roaming\OpenCandy\631F8A1D479F40F1B8533BBD54DDA228\SkypeSetupFull-p2v0.exe, Quarantined, [43b38fe8adce5fd7a0bfdfa8a75b5ea2],
PUP.Optional.Conduit.A, C:\ProgramData\Conduit\IE\CT3315828\UninstallerUI.exe, Quarantined, [d2243245f58655e1b3377b0c14ee7d83],
PUP.Optional.MixiDJToolbar.A, C:\Users\Koony\AppData\Local\MixiDJ_V30\hk64tbMixi.dll, Quarantined, [e2147403611a5dd9c40f097f5aa8a060],
PUP.Optional.MixiDJToolbar.A, C:\Users\Koony\AppData\Local\MixiDJ_V30\hktbMixi.dll, Quarantined, [e2147403611a5dd9c40f097f5aa8a060],
PUP.Optional.MixiDJToolbar.A, C:\Users\Koony\AppData\Local\MixiDJ_V30\ldrtbMixi.dll, Quarantined, [e2147403611a5dd9c40f097f5aa8a060],
PUP.Optional.MixiDJToolbar.A, C:\Users\Koony\AppData\Local\MixiDJ_V30\tbMixi.dll, Quarantined, [e2147403611a5dd9c40f097f5aa8a060],
PUP.Optional.MixiDJToolbar.A, C:\Users\Koony\AppData\Local\MixiDJ_V30\toolbar.cfg, Quarantined, [e2147403611a5dd9c40f097f5aa8a060],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Settings.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\SignIn with Facebook.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\SignIn with Twitter.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Wajam Website.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Ask.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Bing.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Google.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\IMDb.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Shopping.com.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\TripAdvisor.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Wikipedia.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Search\Yahoo!.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Amazon.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Argos.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Ebay.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Etsy.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\HomeDepot.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Ikea.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Lowe's.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Mercadolivre.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\MyShopping.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Sears.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Target.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Tesco.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Walmart.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Explore Social Shopping\Zalando.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.Wajam.A, C:\Users\Koony\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\Uninstall Wajam\uninstall.lnk, Quarantined, [47af2c4b3b4058de716bb8d0bd45c33d],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\RecipeHub_2j\bar\1.bin\BOOTSTRAP.JS, Quarantined, [35c11c5bd7a4b58116adcec0dc26669a],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\RecipeHub_2j\bar\1.bin\installKeys.js, Quarantined, [35c11c5bd7a4b58116adcec0dc26669a],
Physical Sectors: 0
(No malicious items detected)
(end)
All of which I quarantined.
At this point, I have not run AdwCleaner although I do have it downloaded. I have noticed Mindspark in these lists yet it is still in my Programs and Features list and when I attempt to uninstall it I get the RUN DLL error box text:
There was a problem starting C:\ProgramFiles(x86)\RecipiesHub_2j\bar\1.bin\2jBar.dll
To which I click OK because there are no other options.
Thought should seek assistance from the professionals after working at it for a while. OTL LOG is inserted below.
Any help will be greatly appreciated.
Thank you in advance!
OTL logfile created on: 6/13/2014 9:33:29 AM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Koony\Downloads
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17031)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.71 Gb Total Physical Memory | 2.28 Gb Available Physical Memory | 61.43% Memory free
4.58 Gb Paging File | 2.30 Gb Available in Paging File | 50.15% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 441.61 Gb Total Space | 339.02 Gb Free Space | 76.77% Space Free | Partition Type: NTFS
Computer Name: SHARONJONESHALL | User Name: Koony | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/06/13 05:11:39 | 001,091,912 | ---- | M] (Google Inc.) -- C:\Windows\Temp\CR_786D4.tmp\setup.exe
PRC - [2014/06/13 05:11:34 | 039,078,480 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\Install\{F4A95357-C7DB-4DFE-AD54-73B8AA454EA4}\35.0.1916.153_chrome_installer.exe
PRC - [2014/06/13 01:21:17 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Koony\Downloads\OTL.exe
PRC - [2014/06/12 19:19:48 | 003,873,704 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2014/06/04 22:04:51 | 000,429,056 | ---- | M] (Microsoft) -- C:\Program Files\WindowsApps\Microsoft.Taptiles_2.1.1405.2329_x86__8wekyb3d8bbwe\Taptiles.exe
PRC - [2014/05/14 12:17:24 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014/05/06 22:26:43 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2014/05/03 18:08:13 | 000,227,904 | ---- | M] (WildTangent) -- C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
PRC - [2014/05/02 15:24:31 | 001,141,848 | ---- | M] (RealNetworks, Inc.) -- c:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe
PRC - [2014/05/02 15:24:25 | 000,296,520 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
PRC - [2014/04/07 03:06:58 | 000,023,552 | ---- | M] () -- C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
PRC - [2014/04/06 23:01:02 | 000,367,192 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe
PRC - [2014/04/06 23:00:42 | 000,039,568 | ---- | M] () -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
PRC - [2013/12/21 02:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/12/09 14:38:12 | 001,174,152 | ---- | M] (WiseCleaner.com) -- C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe
PRC - [2013/05/15 16:05:58 | 000,191,424 | ---- | M] (F-Secure Corporation) -- C:\Program Files (x86)\Charter Security Suite\fshoster32.exe
PRC - [2012/07/05 21:50:26 | 000,553,616 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe
PRC - [2012/07/04 13:57:44 | 000,990,320 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
PRC - [2011/09/05 13:04:58 | 002,904,984 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
========== Modules (No Company Name) ==========
MOD - [2014/05/28 05:11:05 | 000,041,984 | ---- | M] () -- C:\Users\Koony\AppData\Local\Packages\Microsoft.Taptiles_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0_32\NativeImages\Microsoft.G42d2c636#\c9c9d32d102cd8eb4ad7d760ede11f62\Microsoft.Games.Sentient.ni.dll
MOD - [2014/05/28 05:10:33 | 000,227,328 | ---- | M] () -- C:\Users\Koony\AppData\Local\Packages\Microsoft.Taptiles_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0_32\NativeImages\CEServices\5c7c9f4bd1fc9e9f637b2435b69ce105\CEServices.ni.dll
MOD - [2014/05/28 05:10:17 | 000,483,840 | ---- | M] () -- C:\Users\Koony\AppData\Local\Packages\Microsoft.Taptiles_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0_32\NativeImages\Microsoft.Xbox\7334cf3cd56e548536e510cce0ed4e14\Microsoft.Xbox.ni.dll
MOD - [2014/05/28 05:09:43 | 000,258,560 | ---- | M] () -- C:\Users\Koony\AppData\Local\Packages\Microsoft.Taptiles_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0_32\NativeImages\Arkadium.CdnModule\6aeb49424ffba822ec5d785ad67a7f28\Arkadium.CdnModule.ni.dll
MOD - [2014/05/28 05:09:41 | 000,122,880 | ---- | M] () -- C:\Users\Koony\AppData\Local\Packages\Microsoft.Taptiles_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0_32\NativeImages\Arkadium.Xaba8eb3bf#\fc79342af60c7741b6569a2d61d90a1a\Arkadium.Xaml.Toolkit.ni.dll
MOD - [2014/05/28 05:09:24 | 000,310,272 | ---- | M] () -- C:\Users\Koony\AppData\Local\Packages\Microsoft.Taptiles_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0_32\NativeImages\Arkadium.Le816657bc#\f7e5a15c9981431fd2f771b9481f83e0\Arkadium.LeaderboardModule.ni.dll
MOD - [2014/05/28 05:09:20 | 000,249,344 | ---- | M] () -- C:\Users\Koony\AppData\Local\Packages\Microsoft.Taptiles_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0_32\NativeImages\Arkadium.Awd4f12c8f#\e7a9e0b77f831f5a0cc42115ceabf2a2\Arkadium.AwardsModule.ni.dll
MOD - [2014/05/28 05:09:17 | 000,152,064 | ---- | M] () -- C:\Users\Koony\AppData\Local\Packages\Microsoft.Taptiles_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0_32\NativeImages\Arkadium.Acc213f109#\94119bff3cfaa9a57ec27e09b3e6ca5b\Arkadium.AchievementsModule.ni.dll
MOD - [2014/05/28 05:09:15 | 000,122,880 | ---- | M] () -- C:\Users\Koony\AppData\Local\Packages\Microsoft.Taptiles_8wekyb3d8bbwe\AC\Microsoft\CLR_v4.0_32\NativeImages\Arkadium.Ap4e5cc921#\d844f788b32033689d5afca27bb255a6\Arkadium.ApplicationFramework.ni.dll
MOD - [2014/05/16 04:42:56 | 000,146,944 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Numerics\8e945b32dd6b4b00c900f6c01c0f3c62\System.Numerics.ni.dll
MOD - [2014/05/16 04:42:52 | 000,008,192 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtcf595564#\ddd83eb843c6531b608b3303dd9f997d\System.Runtime.Numerics.ni.dll
MOD - [2014/05/16 04:42:50 | 000,010,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Linqbd02a4fb#\1e1404c2b5da3888fe1fb4a82f45c4d7\System.Linq.Expressions.ni.dll
MOD - [2014/05/16 04:42:44 | 000,168,448 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.IO.Cb3b124c8#\f7a43000e540605d6e0e171da4c2f1d4\System.IO.Compression.ni.dll
MOD - [2014/05/16 04:42:39 | 000,008,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Colldfb0b5ae#\6f8ded828a8d1b1f4a7976b73cf21573\System.Collections.Concurrent.ni.dll
MOD - [2014/05/09 21:10:19 | 000,008,192 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Text2f5a8366#\5fe841aca0e2050c16053dc1e744e43b\System.Text.RegularExpressions.ni.dll
MOD - [2014/05/09 21:10:14 | 000,008,192 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Refl9c203d4d#\b937d907fc3074ee680d24514c61e37f\System.Reflection.Extensions.ni.dll
MOD - [2014/05/06 22:27:10 | 003,839,088 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2014/05/02 21:21:24 | 000,008,192 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Text.Encoding\8b843c36b88d5c581c163a6f26432aa5\System.Text.Encoding.ni.dll
MOD - [2014/05/02 21:21:21 | 000,008,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runt6a32fdc5#\e689a3a0890ef282d7e70d3367726e7b\System.Runtime.Serialization.Xml.ni.dll
MOD - [2014/05/02 21:21:18 | 000,008,192 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Linq\5c5aaf5812afcf70f2136a13213c9d57\System.Linq.ni.dll
MOD - [2014/05/02 21:21:01 | 000,008,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Threading\88c5bb75b5fc29305a51f21d77640cba\System.Threading.ni.dll
MOD - [2014/05/02 21:20:57 | 000,008,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runt1e58aa76#\7ea522010e4f517cf62d62292d3f68b2\System.Runtime.Extensions.ni.dll
MOD - [2014/05/02 21:20:53 | 000,008,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml.dd7e8ed3#\d91914bd63231b7c293abb207861c919\System.Xml.ReaderWriter.ni.dll
MOD - [2014/05/02 21:20:50 | 000,008,192 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Globalization\ce0c7f8b567ffa67ee20fc986defe319\System.Globalization.ni.dll
MOD - [2014/05/02 21:20:47 | 000,008,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Reflection\66943ffdb6c6209cf0340c6a256bf169\System.Reflection.ni.dll
MOD - [2014/05/02 21:20:27 | 000,008,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml.XDocument\7ad708c95cf753ab197ba6e9463eab36\System.Xml.XDocument.ni.dll
MOD - [2014/05/02 15:24:32 | 000,572,504 | ---- | M] () -- c:\Program Files (x86)\Real\RealPlayer\RPDS\Lib\r1api.dll
MOD - [2014/05/02 09:48:20 | 000,337,920 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Data\95e459fe3e0f12f2dc9f48fb91886621\Windows.Data.ni.dll
MOD - [2014/05/02 09:48:16 | 000,012,800 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runt9e372c89#\b3ad6730fe2c9bc26d2656994615e29e\System.Runtime.InteropServices.ni.dll
MOD - [2014/05/02 09:48:13 | 000,008,192 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.IO\232833346ca4e705c2a15dd57af73bac\System.IO.ni.dll
MOD - [2014/05/02 09:48:10 | 000,008,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml.429e8964#\d875b108d13cb8d893ac4c27fff8f539\System.Xml.XmlSerializer.ni.dll
MOD - [2014/05/02 09:48:07 | 001,282,048 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Devices\bf5509cf3a0d2e3afbd0c33e9153ecbd\Windows.Devices.ni.dll
MOD - [2014/05/02 09:47:58 | 000,304,128 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Graphics\4e33edd5ee2ee09f751c0071ba0a26c3\Windows.Graphics.ni.dll
MOD - [2014/05/02 09:47:53 | 000,009,216 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Thre7bb2aad0#\7ab875026ab88e106bf40c8db4f640a1\System.Threading.Tasks.ni.dll
MOD - [2014/05/02 09:44:16 | 000,008,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Collections\ebeafb298ff3f25b6291e44deceb1d0c\System.Collections.ni.dll
MOD - [2014/05/02 09:43:44 | 000,008,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Net.caf7096d#\a609227cf29283a141334946144866f3\System.Net.Primitives.ni.dll
MOD - [2014/05/02 09:42:40 | 000,770,560 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Media\ae986fe3d2717c157eb1eeeb4d99aaa1\Windows.Media.ni.dll
MOD - [2014/05/02 09:42:27 | 000,960,000 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.UI\c95c4deae76420a882bef7161a449d72\Windows.UI.ni.dll
MOD - [2014/05/02 09:42:18 | 003,530,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.UI.Xaml\f2bf020fc6307e10194fd94e85d52a72\Windows.UI.Xaml.ni.dll
MOD - [2014/05/02 09:41:43 | 000,008,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ObjectModel\67dd353e70bac0caa6a7dde153081d12\System.ObjectModel.ni.dll
MOD - [2014/05/02 09:41:38 | 000,008,192 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Diagaa8d7fa5#\a374d5cee262e00ef48bb80a46ef261b\System.Diagnostics.Debug.ni.dll
MOD - [2014/05/02 09:41:34 | 000,014,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Servdea05680#\0c4ca02c69ce55cfcfefb541f195d705\System.ServiceModel.Primitives.ni.dll
MOD - [2014/05/02 09:41:29 | 000,797,696 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Networking\66db718389f1cd2503053c09b3de857f\Windows.Networking.ni.dll
MOD - [2014/05/02 09:41:21 | 000,133,120 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.System\726121cd59d8545addcd2c64688b5309\Windows.System.ni.dll
MOD - [2014/05/02 09:41:18 | 000,238,080 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Gloaae92e31#\a1306b1fdd9c22508f9e5d901fceb4cd\Windows.Globalization.ni.dll
MOD - [2014/05/02 09:41:14 | 000,402,432 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Security\27136c94fce321fc4e76bccb5fc38fe0\Windows.Security.ni.dll
MOD - [2014/05/02 09:41:08 | 000,008,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtdf6812ee#\b7c90cd61aa57b4858a896d7e33c30d9\System.Runtime.Serialization.Primitives.ni.dll
MOD - [2014/05/02 09:41:05 | 000,785,408 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\ee53227bcc4430088d0b560752c1cd02\System.ServiceModel.Internals.ni.dll
MOD - [2014/05/02 09:40:52 | 000,118,272 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\352d34797f7cd44cd0973c33539200f1\SMDiagnostics.ni.dll
MOD - [2014/05/02 09:40:45 | 000,228,864 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Foundation\cf021988965369c551bb0987fe019862\Windows.Foundation.ni.dll
MOD - [2014/05/02 09:40:35 | 000,808,448 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Storage\f3deb382d1f91df4e2bf1801afb4ea21\Windows.Storage.ni.dll
MOD - [2014/05/02 09:40:28 | 000,018,944 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime\7bf2203bf2d88857c463948cccf6156c\System.Runtime.ni.dll
MOD - [2014/05/02 09:40:25 | 000,008,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtbff93e24#\1849d6bdd0f61a224d41ac2963221204\System.Runtime.InteropServices.WindowsRuntime.ni.dll
MOD - [2014/05/02 09:40:23 | 001,130,496 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.App640a3541#\224ab0385dc2991b9139bdbf7bcf8e0e\Windows.ApplicationModel.ni.dll
MOD - [2014/05/01 12:41:08 | 000,392,704 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\6f7a4225a199ad7894379512ca6ae50c\System.Xml.Linq.ni.dll
MOD - [2014/05/01 12:41:06 | 007,802,880 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\77bc1a994f64193efc124c297b93fdb7\System.Xml.ni.dll
MOD - [2014/05/01 12:40:05 | 019,566,080 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\4c3126aec3364546e4ade89c24c4e742\System.ServiceModel.ni.dll
MOD - [2014/05/01 12:39:14 | 000,573,952 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runt0d283adf#\32aee6654d81a07e698f9ee18c886a2a\System.Runtime.WindowsRuntime.ni.dll
MOD - [2014/05/01 12:39:14 | 000,098,816 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtc259d85b#\ed68489987b413410ccb94c6e704f6b4\System.Runtime.WindowsRuntime.UI.Xaml.ni.dll
MOD - [2014/05/01 12:39:10 | 002,804,736 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\183eaaded316165bfbd32a991e4e8c8a\System.Runtime.Serialization.ni.dll
MOD - [2014/05/01 12:38:59 | 000,522,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Net.Http\5ba9e9e2d2253e30f3f28e12016e441d\System.Net.Http.ni.dll
MOD - [2014/05/01 12:38:25 | 000,968,192 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\c5bf2f5c3e13726b3984a900221e1778\System.Configuration.ni.dll
MOD - [2014/05/01 12:32:18 | 006,951,424 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\c1194e56644c7688e7eb0f68a57dcc30\System.Core.ni.dll
MOD - [2014/05/01 12:31:49 | 010,003,456 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\c24d08cc4e93fc4f6f15a637b00a2721\System.ni.dll
MOD - [2014/03/27 11:23:11 | 019,336,120 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014/01/27 07:52:41 | 017,395,376 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\c90ef9a73ea0044641d31b19023aad61\mscorlib.ni.dll
MOD - [2013/12/04 14:24:27 | 000,593,464 | ---- | M] () -- C:\Windows\WinSxS\x86_f-secure.qt_4_6_2_2e112a926211c0a3_4.6.482.65_none_b59e1e0911fd55ab\QtMultimediaKit1.dll
========== Services (SafeList) ==========
SRV:64bit: - [2014/05/16 04:40:06 | 002,266,296 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe -- (ClickToRunSvc)
SRV:64bit: - [2014/05/14 12:17:24 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2014/04/27 12:20:40 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2014/04/06 07:20:36 | 000,201,216 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:64bit: - [2014/03/23 22:31:14 | 000,347,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
SRV:64bit: - [2014/03/23 22:31:14 | 000,023,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:64bit: - [2014/03/08 01:41:25 | 001,306,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
SRV:64bit: - [2014/03/06 03:02:13 | 000,834,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:64bit: - [2014/02/22 11:53:10 | 003,394,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
SRV:64bit: - [2014/02/22 05:57:16 | 000,710,656 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:64bit: - [2014/02/22 05:26:58 | 000,366,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:64bit: - [2014/02/22 05:25:39 | 000,399,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:64bit: - [2014/02/22 05:25:14 | 000,269,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:64bit: - [2014/02/22 05:23:58 | 001,576,960 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:64bit: - [2014/01/27 11:38:59 | 001,584,128 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
SRV:64bit: - [2013/12/13 10:23:32 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2013/12/10 03:35:18 | 000,530,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
SRV:64bit: - [2013/11/23 00:50:00 | 000,282,112 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:64bit: - [2013/09/30 00:03:27 | 000,491,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GeofenceMonitorService.dll -- (lfsvc)
SRV:64bit: - [2013/08/22 08:31:56 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:64bit: - [2013/08/22 07:32:02 | 000,024,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
SRV:64bit: - [2013/08/22 07:31:43 | 000,040,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:64bit: - [2013/08/22 07:22:45 | 000,066,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:64bit: - [2013/08/22 07:21:15 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:64bit: - [2013/08/22 07:16:57 | 000,118,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:64bit: - [2013/08/22 06:25:28 | 000,164,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:64bit: - [2013/08/22 06:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:64bit: - [2013/08/22 06:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:64bit: - [2013/08/22 06:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:64bit: - [2013/08/22 06:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:64bit: - [2013/08/22 06:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:64bit: - [2013/08/22 06:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:64bit: - [2013/08/22 06:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
SRV:64bit: - [2013/08/22 06:02:47 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
SRV:64bit: - [2013/08/22 05:57:25 | 000,130,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV:64bit: - [2013/08/22 05:54:59 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:64bit: - [2013/08/22 05:50:59 | 000,245,760 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:64bit: - [2013/08/22 05:50:00 | 000,525,312 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:64bit: - [2013/08/22 05:45:59 | 000,151,040 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
SRV:64bit: - [2013/08/22 05:40:49 | 000,248,832 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:64bit: - [2013/08/22 05:31:03 | 000,201,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:64bit: - [2013/08/22 05:15:54 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:64bit: - [2012/08/23 00:02:36 | 000,658,576 | ---- | M] (Acer Incorporated) [On_Demand | Running] -- C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe -- (ePowerSvc)
SRV:64bit: - [2012/07/20 02:01:32 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV - [2014/05/13 21:27:27 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/05/06 22:27:01 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/05/03 18:08:13 | 000,227,904 | ---- | M] (WildTangent) [Auto | Running] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe -- (GamesAppIntegrationService)
SRV - [2014/05/03 18:08:13 | 000,203,344 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2014/05/02 15:24:31 | 001,141,848 | ---- | M] (RealNetworks, Inc.) [Auto | Running] -- c:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe -- (RealPlayer Cloud Service)
SRV - [2014/04/07 03:06:58 | 000,023,552 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe -- (RealPlayerUpdateSvc)
SRV - [2014/04/06 23:00:42 | 000,039,568 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
SRV - [2014/04/03 20:21:48 | 000,315,008 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2014/01/21 15:25:34 | 000,580,232 | ---- | M] (WiseCleaner.com) [Auto | Stopped] -- C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe -- (WiseBootAssistant)
SRV - [2013/12/21 02:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/09/30 00:03:26 | 000,357,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GeofenceMonitorService.dll -- (lfsvc)
SRV - [2013/08/22 08:31:56 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2013/08/21 23:55:35 | 000,018,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
SRV - [2013/08/21 22:53:34 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
SRV - [2013/05/15 16:05:58 | 000,191,424 | ---- | M] (F-Secure Corporation) [Auto | Running] -- C:\Program Files (x86)\Charter Security Suite\fshoster32.exe -- (fshoster)
SRV - [2012/07/13 05:02:16 | 002,451,456 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Running] -- C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe -- (IconMan_R)
SRV - [2011/11/25 19:32:36 | 000,687,400 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2014/05/15 12:17:40 | 001,039,096 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsnx.sys -- (aswSnx)
DRV:64bit: - [2014/05/15 12:17:40 | 000,423,240 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsp.sys -- (aswSP)
DRV:64bit: - [2014/05/15 12:17:40 | 000,085,328 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswstm.sys -- (aswStm)
DRV:64bit: - [2014/05/14 12:17:31 | 000,208,416 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2014/05/14 12:17:31 | 000,079,184 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2014/05/14 12:17:31 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2014/05/14 12:17:31 | 000,029,208 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:64bit: - [2014/05/14 12:17:30 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2014/03/23 22:30:57 | 000,257,880 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)
DRV:64bit: - [2014/03/23 22:30:57 | 000,123,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)
DRV:64bit: - [2014/03/23 22:27:03 | 000,035,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)
DRV:64bit: - [2014/03/19 23:41:20 | 000,376,152 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
DRV:64bit: - [2014/03/13 08:35:24 | 000,157,016 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\WINDOWS\SysNative\drivers\wof.sys -- (Wof)
DRV:64bit: - [2014/03/08 16:40:16 | 000,136,024 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
DRV:64bit: - [2014/03/08 16:35:45 | 000,467,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
DRV:64bit: - [2014/02/22 12:00:25 | 000,236,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2014/02/22 11:50:31 | 000,054,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr)
DRV:64bit: - [2014/02/22 11:49:51 | 000,325,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
DRV:64bit: - [2014/02/22 11:49:49 | 000,384,856 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
DRV:64bit: - [2014/02/22 11:49:49 | 000,189,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UCX01000.SYS -- (UCX01000)
DRV:64bit: - [2014/02/22 11:49:49 | 000,079,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
DRV:64bit: - [2014/02/22 11:49:47 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:64bit: - [2014/02/22 11:44:13 | 000,924,504 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\SysNative\drivers\refs.sys -- (ReFS)
DRV:64bit: - [2014/02/22 08:14:02 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
DRV:64bit: - [2014/01/22 08:52:10 | 000,206,080 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:64bit: - [2014/01/22 08:52:10 | 000,108,800 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2013/12/13 10:23:36 | 013,207,552 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2013/12/13 10:23:36 | 000,626,176 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2013/12/04 16:58:35 | 000,057,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
DRV:64bit: - [2013/11/10 22:48:41 | 000,039,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
DRV:64bit: - [2013/11/01 07:39:53 | 000,086,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
DRV:64bit: - [2013/10/25 21:54:32 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
DRV:64bit: - [2013/09/30 00:03:25 | 000,175,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
DRV:64bit: - [2013/09/29 23:51:06 | 000,027,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2013/09/29 23:51:01 | 000,037,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2013/08/22 09:25:40 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
DRV:64bit: - [2013/08/22 09:25:40 | 000,030,048 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\WINDOWS\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2013/08/22 08:50:19 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
DRV:64bit: - [2013/08/22 08:49:54 | 000,079,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
DRV:64bit: - [2013/08/22 08:49:33 | 000,159,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:64bit: - [2013/08/22 08:43:49 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
DRV:64bit: - [2013/08/22 08:43:48 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:64bit: - [2013/08/22 08:43:45 | 003,357,024 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2013/08/22 08:43:45 | 000,093,536 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2013/08/22 08:43:45 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
DRV:64bit: - [2013/08/22 08:43:45 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2013/08/22 08:43:44 | 000,081,760 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3.sys -- (LSI_SAS3)
DRV:64bit: - [2013/08/22 08:43:41 | 000,782,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
DRV:64bit: - [2013/08/22 08:43:41 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2013/08/22 08:43:41 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2013/08/22 08:43:41 | 000,108,896 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
DRV:64bit: - [2013/08/22 08:43:41 | 000,079,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2013/08/22 08:43:40 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:64bit: - [2013/08/22 08:43:40 | 000,082,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
DRV:64bit: - [2013/08/22 08:43:40 | 000,025,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2013/08/22 08:43:34 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:64bit: - [2013/08/22 08:43:33 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
DRV:64bit: - [2013/08/22 08:43:32 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2013/08/22 08:43:31 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
DRV:64bit: - [2013/08/22 08:43:31 | 000,072,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
DRV:64bit: - [2013/08/22 08:43:31 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
DRV:64bit: - [2013/08/22 08:39:15 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
DRV:64bit: - [2013/08/22 08:37:27 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
DRV:64bit: - [2013/08/22 08:36:12 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:64bit: - [2013/08/22 07:39:58 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2013/08/22 07:39:54 | 000,076,800 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
DRV:64bit: - [2013/08/22 07:39:50 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDScan.sys -- (WSDScan)
DRV:64bit: - [2013/08/22 07:39:31 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:64bit: - [2013/08/22 07:39:20 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
DRV:64bit: - [2013/08/22 07:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
DRV:64bit: - [2013/08/22 07:38:58 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
DRV:64bit: - [2013/08/22 07:38:48 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
DRV:64bit: - [2013/08/22 07:38:39 | 000,036,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:64bit: - [2013/08/22 07:38:26 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
DRV:64bit: - [2013/08/22 07:38:23 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
DRV:64bit: - [2013/08/22 07:38:22 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
DRV:64bit: - [2013/08/22 07:38:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)
DRV:64bit: - [2013/08/22 07:37:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
DRV:64bit: - [2013/08/22 07:37:46 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2013/08/22 07:37:42 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
DRV:64bit: - [2013/08/22 07:37:28 | 000,056,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2013/08/22 07:37:28 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
DRV:64bit: - [2013/08/22 07:37:14 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2013/08/22 07:36:43 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc63.sys -- (netvsc)
DRV:64bit: - [2013/08/22 07:36:25 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV:64bit: - [2013/08/22 07:36:17 | 000,124,928 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:64bit: - [2013/08/22 07:36:07 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
DRV:64bit: - [2013/08/22 07:35:42 | 000,103,424 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
DRV:64bit: - [2013/08/22 04:46:33 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fxppm.sys -- (FxPPM)
DRV:64bit: - [2013/08/12 19:25:46 | 000,017,624 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
DRV:64bit: - [2013/08/09 20:39:30 | 000,651,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)
DRV:64bit: - [2013/07/30 14:47:35 | 000,024,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
DRV:64bit: - [2013/07/25 15:05:39 | 000,099,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
DRV:64bit: - [2013/06/18 10:46:17 | 000,591,360 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt630x64.sys -- (RTL8168)
DRV:64bit: - [2012/07/16 20:59:12 | 000,098,472 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW86.sys -- (AtiHDAudioService)
DRV:64bit: - [2012/07/04 23:18:06 | 000,252,048 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2011/11/03 03:01:00 | 000,056,208 | ---- | M] (Rovi Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV - [2014/02/11 02:00:00 | 000,484,952 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)
DRV - [2014/02/11 02:00:00 | 000,137,648 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{33D0B8F7-D807-446F-B347-B2744D89F8F7}: "URL" = http://www.bing.com/...E10TR&pc=MAGWJS
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {C52F67DD-4AF4-410D-B356-C71D23DE324C}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {C52F67DD-4AF4-410D-B356-C71D23DE324C}
IE - HKCU\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://ws.infospace....w={searchTerms}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE11SR
IE - HKCU\..\SearchScopes\{3B32632F-C85A-444D-B977-DB8A927F5E5F}: "URL" = http://search.condui...q={searchTerms}
IE - HKCU\..\SearchScopes\{4C4C7AAB-5854-4241-A414-E2F1EF119C4A}: "URL" = http://www.dnsbasic....s={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKCU\..\SearchScopes\{855EB2F6-A22F-4289-82CE-3474A6F4E29D}: "URL" = http://search.condui...6316829764&UM=2
IE - HKCU\..\SearchScopes\{C52F67DD-4AF4-410D-B356-C71D23DE324C}: "URL" = http://search.condui...3132149919&UM=2
IE - HKCU\..\SearchScopes\{EE0D6F95-3CC8-47A2-B90A-876930E717B0}: "URL" = http://us.yhs4.searc...,19669,0,6,7635
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "www.msn.com"
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:9.0.2018.95
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:29.0.1
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.5.2: C:\Program Files (x86)\Java\jre8\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.5.2: C:\Program Files (x86)\Java\jre8\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=17.0.9.17: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=17.0.9: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=17.0.9: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=17.0.9: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=17.0.9.17: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer Cloud)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\10\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Koony\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014/05/02 15:26:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{53D8DD28-1C83-41F3-B171-C2ED5B3E5DE8}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2014/05/02 15:26:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014/06/12 19:19:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2014/06/12 19:13:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2013/08/01 19:30:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Koony\AppData\Roaming\mozilla\Extensions
[2014/06/07 17:19:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Koony\AppData\Roaming\mozilla\Firefox\Profiles\2fknfz9w.default-1402175433890\extensions
[2014/05/12 11:40:51 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/05/12 11:40:51 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2014/06/12 19:19:45 | 000,000,000 | ---D | M] (avast! Online Security) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: https://www.yahoo.co...t&type=avastbcl
CHR - plugin: Error reading preferences file
CHR - Extension: Google Docs = C:\Users\Koony\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.6_0\
CHR - Extension: Google Drive = C:\Users\Koony\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Google Voice Search Hotword (Beta) = C:\Users\Koony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5019_0\
CHR - Extension: YouTube = C:\Users\Koony\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: HelloFax: 50 Free Fax Pages = C:\Users\Koony\AppData\Local\Google\Chrome\User Data\Default\Extensions\bocmleclimfnadgmcdgecijlblfcmfnm\1.20_0\
CHR - Extension: Google Search = C:\Users\Koony\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: avast! Online Security = C:\Users\Koony\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2018.95_0\
CHR - Extension: RealPlayer Downloader = C:\Users\Koony\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\17.0.9_0\
CHR - Extension: Google Wallet = C:\Users\Koony\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Users\Koony\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
Hosts file not found
O2:64bit: - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll (RealDownloader)
O2:64bit: - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O2:64bit: - BHO: (no name) - {6C8DB2EC-499B-4897-A784-0E3186C97E9D} - No CLSID value found.
O2:64bit: - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (no name) - {6C8DB2EC-499B-4897-A784-0E3186C97E9D} - No CLSID value found.
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre8\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre8\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [F-Secure Hoster (42626)] C:\Program Files (x86)\Charter Security Suite\fshoster32.exe (F-Secure Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [SkyDrive] C:\Users\Koony\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O9:64bit: - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.178.162.3 66.189.0.100 24.159.64.23
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{75455516-D449-48BD-87AD-920195878516}: DhcpNameServer = 24.178.162.3 66.189.0.100 24.159.64.23
O18:64bit: - Protocol\Handler\osf - No CLSID value found
O18 - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014/06/13 01:47:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/06/09 18:44:47 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Pro
[2014/06/07 17:10:41 | 000,000,000 | ---D | C] -- C:\Users\Koony\Desktop\Old Firefox Data
[2014/06/01 09:42:44 | 000,000,000 | ---D | C] -- C:\Users\Koony\AppData\Local\Skype
[2014/06/01 09:42:34 | 000,000,000 | ---D | C] -- C:\Users\Koony\AppData\Roaming\Skype
[2014/06/01 09:42:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2014/06/01 09:42:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2014/06/01 09:42:19 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2014/06/01 09:42:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2014/06/01 09:40:39 | 000,000,000 | ---D | C] -- C:\Users\Koony\AppData\Roaming\ARecEngine
[2014/05/24 19:18:28 | 000,000,000 | ---D | C] -- C:\Users\Koony\AppData\Roaming\NCH Software
[2014/05/24 19:18:28 | 000,000,000 | ---D | C] -- C:\ProgramData\NCH Software
[2014/05/24 19:18:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NCH Software
[2014/05/24 19:09:11 | 000,000,000 | ---D | C] -- C:\Users\Koony\Documents\Adobe
[2014/05/22 22:57:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
[2014/05/22 22:57:11 | 000,000,000 | ---D | C] -- C:\Users\Koony\AppData\Roaming\Notepad++
[2014/05/22 22:57:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Notepad++
[2014/05/21 21:15:37 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Adobe
[2014/05/21 21:06:55 | 000,000,000 | ---D | C] -- C:\Users\Koony\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2014/05/21 20:56:51 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe
[2014/05/21 20:37:44 | 000,000,000 | ---D | C] -- C:\ProgramData\ALM
[2014/05/21 20:28:34 | 000,000,000 | ---D | C] -- C:\Users\Koony\Adobe Flash Builder 4.6
[2014/05/21 20:20:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle ES2
[2014/05/21 20:13:14 | 000,056,208 | ---- | C] (Rovi Corporation) -- C:\WINDOWS\SysNative\drivers\PxHlpa64.sys
[2014/05/21 20:13:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine
[2014/05/21 20:13:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Sonic Shared
[2014/05/21 20:13:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\My Company Name
[2014/05/21 20:08:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
[2014/05/21 20:01:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS6
[2014/05/21 20:01:30 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2014/05/21 19:21:41 | 000,000,000 | ---D | C] -- C:\Users\Koony\Desktop\Adobe CS6 Master Collection
[2014/05/21 11:59:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2014/05/21 11:51:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Photoshop CS6
[2014/05/19 22:21:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2014/05/19 22:19:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2014/05/19 22:19:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2014/05/14 12:17:29 | 000,043,152 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
========== Files - Modified Within 30 Days ==========
[2014/06/13 09:51:16 | 000,001,125 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/06/13 09:27:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2014/06/13 09:11:00 | 000,000,928 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014/06/13 03:59:59 | 000,002,210 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/06/13 03:59:38 | 000,000,924 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014/06/13 03:59:14 | 000,067,584 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014/06/13 03:58:09 | 000,000,454 | ---- | M] () -- C:\WINDOWS\tasks\Wise Care 365.job
[2014/06/13 03:57:08 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2014/06/13 03:57:03 | 3183,460,352 | -HS- | M] () -- C:\hiberfil.sys
[2014/06/12 19:20:39 | 000,001,989 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2014/06/11 17:00:38 | 000,149,332 | ---- | M] () -- C:\Users\Koony\Desktop\Dollar General Employee Info.png
[2014/06/08 20:18:31 | 000,000,406 | ---- | M] () -- C:\Users\Koony\Desktop\Fiverr Document.rtf
[2014/06/05 13:07:40 | 000,827,767 | ---- | M] () -- C:\Users\Koony\Desktop\Work Keys Duane 3.pdf
[2014/06/01 09:42:20 | 000,002,531 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2014/05/31 21:19:04 | 000,000,000 | ---- | M] () -- C:\end
[2014/05/29 17:00:17 | 000,000,434 | ---- | M] () -- C:\WINDOWS\tasks\Wise Turbo Checker.job
[2014/05/27 01:01:59 | 000,007,605 | ---- | M] () -- C:\Users\Koony\AppData\Local\resmon.resmoncfg
[2014/05/24 19:18:18 | 000,001,133 | ---- | M] () -- C:\Users\Public\Desktop\Prism Video File Converter.lnk
[2014/05/22 22:57:16 | 000,001,076 | ---- | M] () -- C:\Users\Koony\Desktop\Notepad++.lnk
[2014/05/21 21:39:09 | 005,098,592 | ---- | M] () -- C:\WINDOWS\SysNative\FNTCACHE.DAT
[2014/05/21 20:20:57 | 000,002,053 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
[2014/05/19 22:46:22 | 000,000,286 | ---- | M] () -- C:\Users\Koony\Desktop\index.html
[2014/05/15 12:17:40 | 001,039,096 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswsnx.sys
[2014/05/15 12:17:40 | 000,423,240 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswsp.sys
[2014/05/15 12:17:40 | 000,085,328 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswstm.sys
[2014/05/14 12:17:31 | 001,039,096 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswsnx.sys.1400170659609
[2014/05/14 12:17:31 | 000,423,240 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswsp.sys.1400170659609
[2014/05/14 12:17:31 | 000,334,648 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\aswBoot.exe
[2014/05/14 12:17:31 | 000,208,416 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\aswVmm.sys
[2014/05/14 12:17:31 | 000,079,184 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswMonFlt.sys
[2014/05/14 12:17:31 | 000,065,776 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\aswRvrt.sys
[2014/05/14 12:17:31 | 000,029,208 | ---- | M] () -- C:\WINDOWS\SysNative\drivers\aswHwid.sys
[2014/05/14 12:17:30 | 000,093,568 | ---- | M] (AVAST Software) -- C:\WINDOWS\SysNative\drivers\aswRdr2.sys
[2014/05/14 12:17:29 | 000,043,152 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
========== Files Created - No Company Name ==========
[2014/06/11 17:00:37 | 000,149,332 | ---- | C] () -- C:\Users\Koony\Desktop\Dollar General Employee Info.png
[2014/06/08 20:18:31 | 000,000,406 | ---- | C] () -- C:\Users\Koony\Desktop\Fiverr Document.rtf
[2014/06/05 13:07:40 | 000,827,767 | ---- | C] () -- C:\Users\Koony\Desktop\Work Keys Duane 3.pdf
[2014/06/01 09:42:20 | 000,002,531 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2014/05/27 00:59:28 | 000,007,605 | ---- | C] () -- C:\Users\Koony\AppData\Local\resmon.resmoncfg
[2014/05/24 19:18:18 | 000,001,145 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prism Video File Converter.lnk
[2014/05/24 19:18:18 | 000,001,133 | ---- | C] () -- C:\Users\Public\Desktop\Prism Video File Converter.lnk
[2014/05/22 22:57:16 | 000,001,076 | ---- | C] () -- C:\Users\Koony\Desktop\Notepad++.lnk
[2014/05/21 20:20:57 | 000,002,469 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat X Pro.lnk
[2014/05/21 20:20:57 | 000,002,053 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
[2014/05/21 20:20:56 | 000,002,481 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller X.lnk
[2014/05/21 20:14:04 | 000,001,120 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Widget Browser.lnk
[2014/05/21 20:08:59 | 000,001,020 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2014/05/16 12:52:12 | 000,000,286 | ---- | C] () -- C:\Users\Koony\Desktop\index.html
[2014/05/14 12:17:34 | 000,029,208 | ---- | C] () -- C:\WINDOWS\SysNative\drivers\aswHwid.sys
[2014/04/27 18:27:15 | 000,002,255 | ---- | C] () -- C:\WINDOWS\SysWow64\WimBootCompress.ini
[2014/03/18 19:15:22 | 000,103,936 | ---- | C] () -- C:\WINDOWS\SysWow64\OEMLicense.dll
[2013/12/19 19:40:01 | 000,000,108 | ---- | C] () -- C:\Users\Koony\AppData\Roaming\WB.CFG
[2013/12/13 10:23:14 | 000,123,392 | ---- | C] () -- C:\WINDOWS\SysWow64\amdhdl32.dll
[2013/12/04 15:00:46 | 000,000,258 | RHS- | C] () -- C:\Users\Koony\ntuser.pol
[2013/12/04 14:08:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2013/09/26 20:02:38 | 000,204,952 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsvl.dat
[2013/09/26 20:02:38 | 000,157,144 | ---- | C] () -- C:\WINDOWS\SysWow64\ativvsva.dat
[2013/09/26 20:02:36 | 000,003,917 | ---- | C] () -- C:\WINDOWS\SysWow64\atipblag.dat
[2013/09/26 20:02:18 | 000,995,342 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_as32.exe
[2013/09/26 20:02:18 | 000,798,734 | ---- | C] () -- C:\WINDOWS\SysWow64\amdocl_ld32.exe
[2013/08/22 11:36:43 | 000,215,943 | ---- | C] () -- C:\WINDOWS\SysWow64\dssec.dat
[2013/08/22 11:36:42 | 000,000,741 | ---- | C] () -- C:\WINDOWS\SysWow64\NOISE.DAT
[2013/08/22 10:46:23 | 000,067,584 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2013/08/22 03:01:23 | 000,043,131 | ---- | C] () -- C:\WINDOWS\mib.bin
[2013/08/21 23:32:36 | 000,046,080 | ---- | C] () -- C:\WINDOWS\SysWow64\BWContextHandler.dll
[2013/08/21 19:55:20 | 000,364,544 | ---- | C] () -- C:\WINDOWS\SysWow64\msjetoledb40.dll
[2013/08/21 19:52:39 | 000,673,088 | ---- | C] () -- C:\WINDOWS\SysWow64\mlang.dat
[2013/08/01 23:10:20 | 000,000,000 | ---- | C] () -- C:\ProgramData\3b213226203c332727362727333524_c
========== ZeroAccess Check ==========
[2013/12/04 21:42:13 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/04/06 12:31:39 | 021,268,952 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/04/06 11:22:20 | 018,755,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013/08/22 05:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2013/08/21 22:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013/08/22 05:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2014/06/12 18:46:48 | 000,000,000 | ---D | M] -- C:\Users\Koony\AppData\Roaming\ARecEngine
[2014/03/27 11:26:19 | 000,000,000 | ---D | M] -- C:\Users\Koony\AppData\Roaming\AVAST Software
[2013/05/26 20:49:03 | 000,000,000 | ---D | M] -- C:\Users\Koony\AppData\Roaming\casualArts
[2014/01/04 14:57:44 | 000,000,000 | ---D | M] -- C:\Users\Koony\AppData\Roaming\cerasus.media
[2014/03/22 23:16:01 | 000,000,000 | ---D | M] -- C:\Users\Koony\AppData\Roaming\Chinese Dragon
[2014/05/22 22:57:55 | 000,000,000 | ---D | M] -- C:\Users\Koony\AppData\Roaming\Notepad++
[2014/05/21 21:06:55 | 000,000,000 | ---D | M] -- C:\Users\Koony\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2014/06/12 19:14:27 | 000,000,000 | ---D | M] -- C:\Users\Koony\AppData\Roaming\uTorrent
[2013/03/24 17:44:49 | 000,000,000 | ---D | M] -- C:\Users\Koony\AppData\Roaming\WildTangent
[2014/06/13 03:58:36 | 000,000,000 | ---D | M] -- C:\Users\Koony\AppData\Roaming\Wise Care 365
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 237 bytes -> C:\Users\Koony\SkyDrive:ms-properties
< End of report >