Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Safe Finder Yahoo [Solved]


  • This topic is locked This topic is locked

#1
LANCE1313

LANCE1313

    Member

  • Member
  • PipPip
  • 42 posts

I was updating my programs using File Hippo as per usual and I am now unable to use Chrome.  I'm now using firefox which functions but I keep getting redirected to "Safe Finder" provided by yahoo search.  I don't think I've been downloading anything suspicisous recently.  I hoped someone could direct me to remove it.  Thanks.

 

 

 

OTL logfile created on: 8/30/2014 10:15:02 AM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\LANCE\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17239)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
 
5.93 Gb Total Physical Memory | 3.19 Gb Available Physical Memory | 53.75% Memory free
11.87 Gb Paging File | 8.70 Gb Available in Paging File | 73.27% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 116.44 Gb Total Space | 28.90 Gb Free Space | 24.82% Space Free | Partition Type: NTFS
Drive D: | 329.79 Gb Total Space | 201.03 Gb Free Space | 60.96% Space Free | Partition Type: NTFS
Drive F: | 2.98 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
 
Computer Name: LANCE-PC | User Name: LANCE | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/08/30 10:14:17 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\LANCE\Downloads\OTL.exe
PRC - [2014/08/27 19:18:39 | 001,868,976 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_179.exe
PRC - [2014/08/27 18:52:10 | 000,034,816 | ---- | M] () -- C:\Program Files (x86)\LPT\srptsl.exe
PRC - [2014/08/27 18:52:08 | 000,023,040 | ---- | M] () -- C:\Users\LANCE\AppData\Local\LPT\srptm.exe
PRC - [2014/08/27 18:51:38 | 000,028,160 | ---- | M] (Smartbar) -- C:\Users\LANCE\AppData\Local\Smartbar\Application\SafeFinder.exe
PRC - [2014/08/27 18:50:32 | 000,023,552 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\Lrcnta.exe
PRC - [2014/08/27 18:43:28 | 000,032,768 | ---- | M] () -- C:\Program Files (x86)\LPT\srpts.exe
PRC - [2014/07/30 20:04:40 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2014/07/29 20:22:10 | 036,414,496 | ---- | M] (Dropbox, Inc.) -- C:\Users\LANCE\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2014/07/17 21:39:41 | 000,389,744 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
PRC - [2013/12/21 02:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/11/20 16:43:26 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
PRC - [2013/10/01 20:09:06 | 000,928,136 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
PRC - [2013/10/01 20:08:24 | 000,153,992 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\Citrix\ICA Client\redirector.exe
PRC - [2013/10/01 20:08:04 | 000,395,656 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
PRC - [2013/10/01 16:29:04 | 001,505,608 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\Citrix\Receiver\Receiver.exe
PRC - [2013/09/05 03:35:24 | 001,364,256 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2013/08/29 19:27:28 | 000,414,496 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2013/08/09 14:53:42 | 000,054,152 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe
PRC - [2009/11/12 14:10:06 | 001,597,440 | ---- | M] () -- C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
PRC - [2009/11/02 18:21:26 | 000,103,720 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
PRC - [2009/10/26 14:10:42 | 000,174,720 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe
PRC - [2009/10/09 14:27:44 | 006,937,216 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
PRC - [2009/09/30 23:34:22 | 002,314,240 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2009/09/30 23:33:08 | 000,262,144 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/09/24 17:50:02 | 000,053,888 | ---- | M] () -- C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
PRC - [2009/08/20 00:31:48 | 000,170,624 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
PRC - [2009/06/19 14:29:42 | 000,105,016 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
PRC - [2009/06/19 14:29:26 | 002,488,888 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Hotkey\ATKOSD.exe
PRC - [2009/06/15 21:30:42 | 000,084,536 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe
PRC - [2009/05/18 19:58:38 | 000,305,720 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
PRC - [2008/12/29 20:32:54 | 000,237,693 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\SB Audigy\Volume Panel\VolPanlu.exe
PRC - [2008/12/22 21:15:34 | 000,174,648 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Hotkey\WDC.exe
PRC - [2008/08/14 01:00:08 | 000,113,208 | ---- | M] (ASUS) -- C:\Program Files (x86)\ASUS\ATK Hotkey\KBFiltr.exe
PRC - [2007/11/30 15:20:44 | 000,051,768 | ---- | M] () -- C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
PRC - [2007/08/08 04:08:40 | 000,094,208 | ---- | M] () -- C:\Program Files\ATKGFNEX\GFNEXSrv.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/08/30 09:23:32 | 000,146,432 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__84542ff99aed6a4d\Interop.SHDocVw.dll
MOD - [2014/08/30 08:08:57 | 000,043,008 | ---- | M] () -- c:\Users\LANCE\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpk6tqvy.dll
MOD - [2014/08/27 19:18:37 | 017,048,240 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll
MOD - [2014/08/27 18:52:14 | 000,070,144 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\srut.dll
MOD - [2014/08/27 18:52:14 | 000,070,144 | ---- | M] () -- C:\Users\LANCE\AppData\Local\LPT\srut.dll
MOD - [2014/08/27 18:52:10 | 000,029,184 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\srsbs.dll
MOD - [2014/08/27 18:52:08 | 000,081,920 | ---- | M] () -- C:\Users\LANCE\AppData\Local\LPT\srpt.dll
MOD - [2014/08/27 18:52:08 | 000,042,496 | ---- | M] () -- C:\Users\LANCE\AppData\Local\LPT\srptc.dll
MOD - [2014/08/27 18:52:08 | 000,023,040 | ---- | M] () -- C:\Users\LANCE\AppData\Local\LPT\srptm.exe
MOD - [2014/08/27 18:52:06 | 000,030,720 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\srom.dll
MOD - [2014/08/27 18:52:06 | 000,025,088 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\srpdm.dll
MOD - [2014/08/27 18:52:06 | 000,025,088 | ---- | M] () -- C:\Users\LANCE\AppData\Local\LPT\srpdm.dll
MOD - [2014/08/27 18:52:04 | 000,254,976 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\srns.dll
MOD - [2014/08/27 18:52:04 | 000,047,104 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\srbu.dll
MOD - [2014/08/27 18:52:04 | 000,047,104 | ---- | M] () -- C:\Users\LANCE\AppData\Local\LPT\srbu.dll
MOD - [2014/08/27 18:52:04 | 000,027,648 | ---- | M] () -- C:\Users\LANCE\AppData\Local\LPT\sreu.dll
MOD - [2014/08/27 18:52:00 | 000,086,016 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\srau.dll
MOD - [2014/08/27 18:52:00 | 000,067,584 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\sppsm.dll
MOD - [2014/08/27 18:52:00 | 000,067,584 | ---- | M] () -- C:\Users\LANCE\AppData\Local\LPT\sppsm.dll
MOD - [2014/08/27 18:51:58 | 000,150,016 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\smti.dll
MOD - [2014/08/27 18:51:58 | 000,066,560 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\spbl.dll
MOD - [2014/08/27 18:51:58 | 000,030,720 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\smtu.dll
MOD - [2014/08/27 18:51:56 | 000,073,728 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\smsp.dll
MOD - [2014/08/27 18:51:56 | 000,038,912 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\smta.dll
MOD - [2014/08/27 18:51:50 | 000,158,208 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll
MOD - [2014/08/27 18:51:50 | 000,158,208 | ---- | M] () -- C:\Users\LANCE\AppData\Local\LPT\Smartbar.Resources.HistoryAndStatsWrapper.dll
MOD - [2014/08/27 18:51:50 | 000,061,952 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll
MOD - [2014/08/27 18:51:50 | 000,035,328 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll
MOD - [2014/08/27 18:51:46 | 000,044,032 | ---- | M] () -- C:\Users\LANCE\AppData\Local\LPT\Smartbar.Monetization.Proxy.ProxyService.dll
MOD - [2014/08/27 18:51:46 | 000,027,136 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll
MOD - [2014/08/27 18:51:46 | 000,027,136 | ---- | M] () -- C:\Users\LANCE\AppData\Local\LPT\Smartbar.Personalization.Common.dll
MOD - [2014/08/27 18:51:42 | 000,165,888 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll
MOD - [2014/08/27 18:51:42 | 000,165,888 | ---- | M] () -- C:\Users\LANCE\AppData\Local\LPT\Smartbar.Infrastructure.Utilities.dll
MOD - [2014/08/27 18:51:42 | 000,065,536 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll
MOD - [2014/08/27 18:51:40 | 000,050,176 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll
MOD - [2014/08/27 18:51:40 | 000,014,848 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll
MOD - [2014/08/27 18:51:38 | 002,425,344 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll
MOD - [2014/08/27 18:51:38 | 000,696,832 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll
MOD - [2014/08/27 18:51:38 | 000,078,848 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll
MOD - [2014/08/27 18:51:34 | 000,014,336 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\siem.dll
MOD - [2014/08/27 18:51:32 | 000,193,024 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\sgmu.dll
MOD - [2014/08/27 18:51:32 | 000,024,064 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\sgml.dll
MOD - [2014/08/27 18:51:32 | 000,011,776 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\sidc.dll
MOD - [2014/08/27 18:50:46 | 000,018,944 | ---- | M] () -- C:\Users\LANCE\AppData\Local\LPT\Smartbar.Common.dll
MOD - [2014/08/27 18:50:40 | 000,026,112 | ---- | M] () -- C:\Users\LANCE\AppData\Local\LPT\ProxySettings.dll
MOD - [2014/08/27 18:50:34 | 000,043,520 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\MACTrackBarLib.dll
MOD - [2014/08/27 18:50:32 | 000,032,768 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\lrcnt.dll
MOD - [2014/08/27 18:50:32 | 000,023,552 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\Lrcnta.exe
MOD - [2014/08/27 18:47:36 | 000,099,840 | ---- | M] () -- C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\extensions\{f33c613b-851e-a627-440b-ac974e123ffc}\components\SmartbarFireFoxRemotePlugin_31.dll
MOD - [2014/08/26 14:13:42 | 000,059,392 | ---- | M] () -- C:\Users\LANCE\AppData\Local\LPT\Community.CsharpSqlite.SQLiteClient.dll
MOD - [2014/08/15 12:42:52 | 000,452,096 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\e8541169aa6f8bddf0d31d1ea53cf353\UIAutomationClient.ni.dll
MOD - [2014/08/15 12:42:43 | 001,051,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\39d333d05320d912a94364f525776dd5\System.Management.ni.dll
MOD - [2014/08/15 12:42:15 | 000,220,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\c8addf267ca00688b8b651e5de4bd025\CustomMarshalers.ni.dll
MOD - [2014/08/15 12:38:07 | 000,141,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\1a66585927678d21c32532bd507521f1\System.Configuration.Install.ni.dll
MOD - [2014/08/15 12:37:59 | 001,840,640 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\f11fcbd60483807eefa81820c92b37db\System.Web.Services.ni.dll
MOD - [2014/08/15 12:37:58 | 011,922,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\40d52224797a152552eee1f8433403e4\System.Web.ni.dll
MOD - [2014/08/15 12:37:46 | 000,627,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\fc907d9e7f46293a41081f98502eb7d2\System.Transactions.ni.dll
MOD - [2014/08/15 12:37:45 | 006,638,592 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8cf8109a63bd7d75874bba9b108f2aef\System.Data.ni.dll
MOD - [2014/08/15 12:37:14 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\434e3a5de2f98ed740aac2b24c6d0890\System.Windows.Forms.ni.dll
MOD - [2014/08/15 12:37:06 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\bce52f0521c930a2e305badb3ea07128\System.Drawing.ni.dll
MOD - [2014/08/15 12:37:04 | 000,185,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\30041b0a68a897437dd9091ba8f89223\UIAutomationTypes.ni.dll
MOD - [2014/08/15 12:37:03 | 002,515,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\876cf10ce95a4a6c3639f576af502e2e\System.Data.SqlXml.ni.dll
MOD - [2014/08/15 12:37:03 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\ec7140de731a291e741f3569063e3438\Accessibility.ni.dll
MOD - [2014/08/15 12:37:01 | 005,464,064 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\abca6deea510151b5d8e51bdabd17bea\System.Xml.ni.dll
MOD - [2014/08/15 12:36:57 | 000,978,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce5e2af0775efc3c91ba62d5d26fb39\System.Configuration.ni.dll
MOD - [2014/08/15 12:36:42 | 003,348,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\4aa535ef604745958a236cfbbbbf6297\WindowsBase.ni.dll
MOD - [2014/08/15 12:36:33 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\2ee90c95adb50b0e75b814fcb9d87f8e\System.ni.dll
MOD - [2014/08/15 12:36:23 | 011,499,520 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\f8be9e33457f57805b4068f90099e428\mscorlib.ni.dll
MOD - [2014/07/30 20:04:25 | 003,800,688 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2014/07/29 20:20:20 | 003,610,624 | ---- | M] () -- C:\Users\LANCE\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
MOD - [2014/07/17 21:39:32 | 000,023,152 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\nsldappr32v60.dll
MOD - [2014/07/17 21:39:31 | 000,158,832 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\nsldap32v60.dll
MOD - [2014/07/17 21:39:29 | 003,338,352 | ---- | M] () -- C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
MOD - [2014/05/12 11:21:54 | 000,061,440 | ---- | M] () -- C:\Users\LANCE\AppData\Local\Smartbar\Application\AxInterop.WMPLib.dll
MOD - [2014/03/20 18:49:19 | 002,952,704 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2014/03/20 18:49:17 | 000,069,120 | ---- | M] () -- C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
MOD - [2014/03/04 01:57:21 | 000,261,632 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
MOD - [2014/02/13 09:49:35 | 012,894,208 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\f4f6ee0df2aa4189bf36e6335cb92761\System.Windows.Forms.ni.dll
MOD - [2014/02/13 09:49:22 | 001,644,544 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\5cd2aee5e7c07227c694d89219688ab3\System.Drawing.ni.dll
MOD - [2014/02/13 09:49:18 | 010,060,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ff26cc03e6d57d8abd13b990332e67c6\System.ni.dll
MOD - [2014/02/13 09:49:12 | 000,045,056 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Accessibility\e7e7e3b82e91028e6ed05189f837ea13\Accessibility.ni.dll
MOD - [2014/02/13 09:49:08 | 016,953,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\ce5f61c5754789df97be8dc991c47d07\mscorlib.ni.dll
MOD - [2014/02/06 01:52:52 | 000,073,544 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2014/02/06 01:52:32 | 001,044,808 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2013/09/14 02:51:02 | 000,087,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Internet Services\zlib1.dll
MOD - [2013/09/14 02:50:36 | 001,242,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Internet Services\libxml2.dll
MOD - [2013/09/06 18:33:00 | 008,007,680 | ---- | M] () -- C:\Windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll
MOD - [2013/08/23 15:01:44 | 025,100,288 | ---- | M] () -- C:\Users\LANCE\AppData\Roaming\Dropbox\bin\libcef.dll
MOD - [2013/07/10 18:07:22 | 000,756,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL
MOD - [2012/08/07 09:01:52 | 000,536,576 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Document Creator\EDCAddin.dll
MOD - [2012/08/07 09:01:28 | 000,614,912 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Document Creator\EDCOffice.dll
MOD - [2009/11/12 14:10:06 | 001,597,440 | ---- | M] () -- C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
MOD - [2009/11/02 18:23:36 | 000,013,096 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
MOD - [2009/11/02 18:20:10 | 000,619,816 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
MOD - [2009/09/24 17:50:02 | 000,053,888 | ---- | M] () -- C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
MOD - [2009/06/02 22:09:06 | 000,225,280 | ---- | M] () -- C:\Program Files (x86)\ASUS\VirtualCamera\virtualCamera.ax
MOD - [2009/03/26 18:46:42 | 000,148,480 | ---- | M] () -- C:\Windows\SysWOW64\APOMngr.DLL
MOD - [2009/02/06 22:52:24 | 000,073,728 | ---- | M] () -- C:\Windows\SysWOW64\CmdRtr.DLL
MOD - [2007/11/30 15:20:44 | 000,051,768 | ---- | M] () -- C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2014/07/25 09:00:25 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2014/04/09 09:13:48 | 000,289,256 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe -- (McComponentHostService)
SRV:64bit: - [2014/03/11 12:34:10 | 000,347,872 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2014/03/11 12:34:10 | 000,023,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2013/08/09 20:02:12 | 002,252,504 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Windows\SysNative\BtwRSupportService.exe -- (BcmBtRSupport)
SRV:64bit: - [2013/05/27 01:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/09/17 15:36:34 | 000,359,552 | ---- | M] (ASUSTeK Computer Inc.) [Auto | Running] -- C:\Windows\SysNative\FBAgent.exe -- (AFBAgent)
SRV:64bit: - [2009/07/01 22:54:02 | 000,864,032 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2007/08/08 04:08:40 | 000,094,208 | ---- | M] () [Auto | Running] -- C:\Program Files\ATKGFNEX\GFNEXSrv.exe -- (ATKGFNEXSrv)
SRV - [2014/08/27 19:18:40 | 000,262,320 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/08/27 18:43:28 | 000,032,768 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\LPT\srpts.exe -- (LPTSystemUpdater)
SRV - [2014/07/17 21:39:21 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/03/20 18:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2013/12/21 02:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/10/23 08:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/09/11 22:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/09/05 03:35:24 | 001,364,256 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2013/08/29 19:27:28 | 000,414,496 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2010/01/23 14:43:55 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service)
SRV - [2010/01/23 14:43:51 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2009/09/30 23:34:22 | 002,314,240 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2009/09/30 23:33:08 | 000,262,144 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2009/06/15 21:30:42 | 000,084,536 | ---- | M] (ASUS) [Auto | Running] -- C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe -- (ASLDRService)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014/03/20 20:24:50 | 000,283,064 | ---- | M] (Disc Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2014/03/11 09:52:30 | 000,133,928 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2013/12/04 03:22:50 | 000,196,384 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2013/10/01 22:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2013/09/24 08:10:34 | 000,097,768 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ctxusbm.sys -- (ctxusbm)
DRV:64bit: - [2013/08/09 20:02:14 | 000,170,712 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcbtums.sys -- (bcbtums)
DRV:64bit: - [2013/08/09 20:02:14 | 000,166,104 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (btwampfl)
DRV:64bit: - [2012/12/13 13:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012/08/23 10:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/02/15 09:16:48 | 000,011,576 | ---- | M] (Samsung Electronics) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\SSPORT.sys -- (SSPORT)
DRV:64bit: - [2011/06/27 01:37:00 | 002,753,536 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 05:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2009/10/02 00:58:57 | 000,537,112 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009/09/17 16:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV:64bit: - [2009/08/17 00:15:43 | 000,286,768 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2009/07/20 05:29:39 | 000,015,416 | ---- | M] ( ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kbfiltr.sys -- (kbfiltr)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 20:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2009/07/13 20:35:37 | 000,025,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDScan.sys -- (WSDScan)
DRV:64bit: - [2009/07/13 20:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009/07/04 23:27:02 | 000,055,808 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rixdpe64.sys -- (rixdpcie)
DRV:64bit: - [2009/07/02 12:54:52 | 000,060,416 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rimspe64.sys -- (rimspci)
DRV:64bit: - [2009/07/01 00:46:51 | 000,098,344 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2009/07/01 00:46:47 | 000,132,648 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2009/07/01 00:46:39 | 000,021,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2009/06/28 23:53:45 | 000,058,368 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2009/06/10 16:35:57 | 000,056,832 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SiSG664.sys -- (SiSGbeLH)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/20 04:11:05 | 001,799,680 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\snp2uvc.sys -- (SNP2UVC)
DRV:64bit: - [2009/05/12 21:07:19 | 000,015,928 | ---- | M] (ASUS) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ATK64AMD.sys -- (MTsensor)
DRV:64bit: - [2009/04/07 03:33:07 | 000,035,104 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2008/05/23 21:27:28 | 000,154,168 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV:64bit: - [2008/05/06 17:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
DRV:64bit: - [2007/07/24 15:11:32 | 000,014,904 | ---- | M] () [Kernel | Auto | Running] -- C:\Program Files\ATKGFNEX\ASMMAP64.sys -- (ASMMAP64)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.safefind...q={searchTerms}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.safefind...q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.safefind...q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://feed.safefind...Qp4CtkJPsHJj1Eg,
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.safefind...q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.safefind...q={searchTerms}
IE - HKCU\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKCU\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.safefind...q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename: "SafeFinder Search"
FF - prefs.js..browser.search.selectedEngine: "SafeFinder Search"
FF - prefs.js..browser.startup.homepage: "http://feed.safefind...4CtkJPsHJj1Eg,"
FF - prefs.js..extensions.enabledAddons: SkipScreen%40SkipScreen:0.7.2
FF - prefs.js..extensions.enabledAddons: %7B66E978CD-981F-47DF-AC42-E3CF417C1467%7D:0.4.3
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20131118
FF - prefs.js..extensions.enabledAddons: %7Bc36177c0-224a-11da-8cd6-0800200c9a91%7D:3.9.811
FF - prefs.js..extensions.enabledAddons: isreaditlater%40ideashower.com:3.0.5
FF - prefs.js..extensions.enabledAddons: %7B73a6fe31-595d-460b-a920-fcc0f8843232%7D:2.6.8.36
FF - prefs.js..extensions.enabledAddons: %7Bf33c613b-851e-a627-440b-ac974e123ffc%7D:1.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:31.0
FF - prefs.js..keyword.URL: "http://feed.safefind...6721ChbSA,,&q="
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.20.2: C:\Program Files\Java\jre1.8.0_20\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.20.2: C:\Program Files\Java\jre1.8.0_20\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.0: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Citrix.com/npican: C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll (Citrix Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 31.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 31.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 31.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2014/06/11 17:25:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 31.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{e4f94d1e-2f53-401e-8885-681602c0ddd8}: C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014/04/04 06:36:14 | 000,010,691 | ---- | M] ()
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 31.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 31.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2013/09/05 20:17:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\LANCE\AppData\Roaming\Mozilla\Extensions
[2014/08/30 10:11:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\extensions
[2013/12/08 21:33:13 | 000,000,000 | ---D | M] (WOT) -- C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2014/08/30 10:01:36 | 000,000,000 | ---D | M] ("SafeFinder Smartbar") -- C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\extensions\{f33c613b-851e-a627-440b-ac974e123ffc}
[2014/07/22 12:29:21 | 000,000,000 | ---D | M] (Pocket) -- C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\extensions\[email protected]
[2014/08/30 10:11:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\extensions\staged
[2013/01/23 09:54:18 | 000,012,140 | ---- | M] () (No name found) -- C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\extensions\[email protected]
[2013/07/21 21:40:58 | 000,071,038 | ---- | M] () (No name found) -- C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\extensions\[email protected]
[2014/08/23 16:10:32 | 000,708,114 | ---- | M] () (No name found) -- C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi
[2012/07/13 06:39:22 | 000,003,793 | ---- | M] () (No name found) -- C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\extensions\{66E978CD-981F-47DF-AC42-E3CF417C1467}.xpi
[2014/08/07 11:44:56 | 000,538,675 | ---- | M] () (No name found) -- C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2013/09/07 10:32:18 | 000,166,436 | ---- | M] () (No name found) -- C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\extensions\{c36177c0-224a-11da-8cd6-0800200c9a91}.xpi
[2014/07/24 21:38:54 | 000,967,685 | ---- | M] () (No name found) -- C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/07/13 05:27:52 | 000,434,392 | ---- | M] () (No name found) -- C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
[2014/08/30 10:11:39 | 000,539,819 | ---- | M] () (No name found) -- C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\extensions\staged\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2014/08/30 09:23:55 | 000,022,883 | ---- | M] () -- C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\searchplugins\SafeFinder Search.xml
[2014/07/30 20:04:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/07/30 20:04:40 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
 
========== Chrome  ==========
 
CHR - default_search_provider:  (Enabled)
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - plugin: Error reading preferences file
CHR - Extension: Google Docs = C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: Google Drive = C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Google Voice Search Hotword (Beta) = C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\
CHR - Extension: WOT = C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\2.5.16_0\
CHR - Extension: YouTube = C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: SuperSaiyanTheme = C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplciigccgelconelnbdhnhpgibcbjfe\1_0\
CHR - Extension: Netrunner Lookup = C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\falbpbbdomlkdjlfippfjopgihdekanf\1.3.6_0\
CHR - Extension: AdBlock = C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.7.13_0\
CHR - Extension: Hola Better Internet = C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio\1.4.431_0\
CHR - Extension: No name found = C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14345.1002_0\
CHR - Extension: Social Fixer for Facebook = C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifmhoabcaeehkljcfclfiieohkohdgbb\10.6_0\
CHR - Extension: Disconnect = C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeoacafpbcihiomhlakheieifhpjdfeo\5.18.14_0\
CHR - Extension: The Great Suspender = C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\klbibkeccnjlkjkiokjodocebajanakg\4.74_0\
CHR - Extension: Google Wallet = C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
 
O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_20\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_20\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4:64bit: - HKLM..\Run: [CDAServer] C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe ()
O4:64bit: - HKLM..\Run: [EeeStorageBackup] C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe ()
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RunDLLEntry] C:\Windows\SysNative\AmbRunE.DLL (Creative Technology Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe (ASUS)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe (ASUS)
O4 - HKLM..\Run: [CitrixReceiver] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk" File not found
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKLM..\Run: [Redirector] C:\Program Files (x86)\Citrix\ICA Client\redirector.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files (x86)\Creative\SB Audigy\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [Browser Infrastructure Helper] C:\Users\LANCE\AppData\Local\Smartbar\Application\SafeFinder.exe (Smartbar)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (Disc Soft Ltd)
O4 - HKCU..\Run: [FileHippo.com] C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe (FileHippo.com)
O4 - HKCU..\Run: [GoogleChromeAutoLaunch_06652FE761E59AF1CD30EA9A61DFF3A9] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKCU..\Run: [HP Officejet Pro 8600 (NET)] C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - HKCU..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found
O4 - Startup: C:\Users\LANCE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\LANCE\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O8:64bit: - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{193F5FC8-40DA-47C3-9992-D94342833366}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:64bit: - Protocol\Filter\application/x-ica - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=euc-jp - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=ISO-8859-1 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS936 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS949 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS950 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=UTF8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=UTF-8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=euc-jp - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=ISO-8859-1 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS936 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS949 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS950 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=UTF8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=UTF-8 - No CLSID value found
O18:64bit: - Protocol\Filter\ica - No CLSID value found
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20:64bit: - AppInit_DLLs: (C:\Users\LANCE\AppData\Local\Smartbar\Application\Resources\crdlil64.dll) - C:\Users\LANCE\AppData\Local\Smartbar\Application\Resources\crdlil64.dll ()
O20 - AppInit_DLLs: (C:\Users\LANCE\AppData\Local\Smartbar\Application\Resources\crdlil.dll) - C:\Users\LANCE\AppData\Local\Smartbar\Application\Resources\crdlil.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013/06/08 02:27:12 | 000,000,071 | R--- | M] () - F:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{8b8dda66-64f1-11e3-857a-e0cb4e302f58}\Shell - "" = AutoRun
O33 - MountPoints2\{8b8dda66-64f1-11e3-857a-e0cb4e302f58}\Shell\AutoRun\command - "" = F:\Setup.exe -- [2013/06/08 02:27:12 | 001,233,279 | R--- | M] (Frozenbyte                                                  )
O33 - MountPoints2\{9fc835fc-6ca6-11e3-8716-e0cb4e302f58}\Shell - "" = AutoRun
O33 - MountPoints2\{9fc835fc-6ca6-11e3-8716-e0cb4e302f58}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\start.exe
O33 - MountPoints2\{b12ff93c-ab0e-11e3-abef-e0cb4e302f58}\Shell - "" = AutoRun
O33 - MountPoints2\{b12ff93c-ab0e-11e3-abef-e0cb4e302f58}\Shell\AutoRun\command - "" = F:\Setup.exe -- [2013/06/08 02:27:12 | 001,233,279 | R--- | M] (Frozenbyte                                                  )
O33 - MountPoints2\{e9162f72-44b1-11e3-a90a-e0cb4e302f58}\Shell - "" = AutoRun
O33 - MountPoints2\{e9162f72-44b1-11e3-a90a-e0cb4e302f58}\Shell\AutoRun\command - "" = "G:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/08/30 09:31:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2014/08/30 09:30:23 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2014/08/30 09:30:22 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2014/08/30 09:30:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2014/08/30 09:30:22 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2014/08/30 09:24:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LPT
[2014/08/30 09:23:28 | 000,000,000 | ---D | C] -- C:\Users\LANCE\AppData\Local\Smartbar
[2014/08/30 09:23:28 | 000,000,000 | ---D | C] -- C:\Users\LANCE\AppData\Local\LPT
[2014/08/30 09:23:10 | 000,000,000 | ---D | C] -- C:\Users\LANCE\AppData\Roaming\0F1L1I1P0H1L1E1E1F
[2014/08/30 09:21:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2014/08/17 11:48:39 | 000,000,000 | ---D | C] -- C:\Users\LANCE\Desktop\Grand Rounds
 
========== Files - Modified Within 30 Days ==========
 
[2014/08/30 10:10:56 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/08/30 10:10:56 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/08/30 09:48:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/08/30 09:37:01 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/08/30 09:24:27 | 000,002,607 | ---- | M] () -- C:\Users\LANCE\Desktop\Search.lnk
[2014/08/30 09:23:44 | 000,000,873 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2014/08/30 09:20:19 | 000,002,112 | ---- | M] () -- C:\Users\LANCE\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2014/08/30 09:20:18 | 000,002,088 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
[2014/08/30 09:15:06 | 000,001,726 | ---- | M] () -- C:\Users\Public\Desktop\Defraggler.lnk
[2014/08/30 09:13:49 | 000,000,824 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014/08/30 08:07:51 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/08/30 08:07:31 | 000,479,072 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/08/30 08:07:18 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/08/30 08:06:21 | 484,315,135 | -HS- | M] () -- C:\hiberfil.sys
[2014/08/26 20:10:25 | 000,088,503 | ---- | M] () -- C:\Users\LANCE\Desktop\Resume Jennifer Salmikivi 2014.pdf
[2014/08/26 11:09:06 | 000,002,281 | ---- | M] () -- C:\Users\LANCE\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2014/08/19 21:34:09 | 000,000,962 | ---- | M] () -- C:\Users\Public\Desktop\calibre - E-book management.lnk
[2014/08/19 21:24:19 | 000,781,298 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/08/19 21:24:19 | 000,666,392 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/08/19 21:24:19 | 000,126,036 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/08/16 09:32:01 | 000,632,940 | ---- | M] () -- C:\Users\LANCE\Desktop\Awareness Article.pdf
[2014/08/16 09:31:37 | 000,522,737 | ---- | M] () -- C:\Users\LANCE\Desktop\Awareness Editorial.pdf
[2014/08/15 12:37:52 | 000,001,053 | ---- | M] () -- C:\Users\LANCE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2014/08/14 13:09:12 | 000,173,922 | ---- | M] () -- C:\Users\LANCE\Desktop\Untitled.png
[2014/08/14 13:06:48 | 000,053,912 | ---- | M] () -- C:\Users\LANCE\Desktop\1931178_33613854123_9766_n.jpg
 
========== Files Created - No Company Name ==========
 
[2014/08/30 09:24:10 | 000,002,654 | ---- | C] () -- C:\Users\LANCE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
[2014/08/30 09:24:10 | 000,002,607 | ---- | C] () -- C:\Users\LANCE\Desktop\Search.lnk
[2014/08/30 09:23:44 | 000,000,873 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2014/08/30 09:20:18 | 000,002,088 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
[2014/08/30 09:15:06 | 000,001,726 | ---- | C] () -- C:\Users\Public\Desktop\Defraggler.lnk
[2014/08/30 09:13:49 | 000,000,824 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014/08/26 20:10:25 | 000,088,503 | ---- | C] () -- C:\Users\LANCE\Desktop\Resume Jennifer Salmikivi 2014.pdf
[2014/08/19 21:34:09 | 000,000,962 | ---- | C] () -- C:\Users\Public\Desktop\calibre - E-book management.lnk
[2014/08/16 09:32:01 | 000,632,940 | ---- | C] () -- C:\Users\LANCE\Desktop\Awareness Article.pdf
[2014/08/16 09:31:37 | 000,522,737 | ---- | C] () -- C:\Users\LANCE\Desktop\Awareness Editorial.pdf
[2014/08/14 13:09:12 | 000,173,922 | ---- | C] () -- C:\Users\LANCE\Desktop\Untitled.png
[2014/08/14 13:06:47 | 000,053,912 | ---- | C] () -- C:\Users\LANCE\Desktop\1931178_33613854123_9766_n.jpg
[2014/07/06 15:14:43 | 000,016,384 | ---- | C] () -- C:\Users\LANCE\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014/03/10 20:49:12 | 001,571,136 | ---- | C] () -- C:\Windows\TotalUninstaller.exe
[2014/01/04 17:55:40 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
[2013/12/15 11:18:54 | 000,765,700 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013/09/16 22:30:03 | 000,152,896 | ---- | C] () -- C:\Windows\wiainst64.exe
[2010/01/23 14:27:16 | 000,131,368 | ---- | C] () -- C:\ProgramData\FullRemove.exe
 
========== ZeroAccess Check ==========
 
[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/06/24 22:05:42 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/06/24 21:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 21:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 08:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 21:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2014/08/30 09:23:10 | 000,000,000 | ---D | M] -- C:\Users\LANCE\AppData\Roaming\0F1L1I1P0H1L1E1E1F
[2013/09/05 21:14:52 | 000,000,000 | ---D | M] -- C:\Users\LANCE\AppData\Roaming\Asus WebStorage
[2013/10/19 10:05:26 | 000,000,000 | ---D | M] -- C:\Users\LANCE\AppData\Roaming\Audacity
[2014/08/19 21:15:30 | 000,000,000 | ---D | M] -- C:\Users\LANCE\AppData\Roaming\calibre
[2013/12/15 10:25:54 | 000,000,000 | ---D | M] -- C:\Users\LANCE\AppData\Roaming\DAEMON Tools Lite
[2014/08/30 08:09:08 | 000,000,000 | ---D | M] -- C:\Users\LANCE\AppData\Roaming\Dropbox
[2014/02/04 19:00:31 | 000,000,000 | ---D | M] -- C:\Users\LANCE\AppData\Roaming\ICAClient
[2013/09/06 21:01:27 | 000,000,000 | ---D | M] -- C:\Users\LANCE\AppData\Roaming\LolClient
[2014/03/10 20:51:25 | 000,000,000 | ---D | M] -- C:\Users\LANCE\AppData\Roaming\Samsung
[2013/09/05 22:14:59 | 000,000,000 | ---D | M] -- C:\Users\LANCE\AppData\Roaming\Stardock
[2013/09/05 20:55:26 | 000,000,000 | ---D | M] -- C:\Users\LANCE\AppData\Roaming\Thunderbird
[2014/08/30 08:05:20 | 000,000,000 | ---D | M] -- C:\Users\LANCE\AppData\Roaming\tixati
[2013/12/15 16:04:46 | 000,000,000 | ---D | M] -- C:\Users\LANCE\AppData\Roaming\Trine2
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:5C321E34

< End of report >

 

 

OTL Extras logfile created on: 8/30/2014 10:15:02 AM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\LANCE\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17239)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
 
5.93 Gb Total Physical Memory | 3.19 Gb Available Physical Memory | 53.75% Memory free
11.87 Gb Paging File | 8.70 Gb Available in Paging File | 73.27% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 116.44 Gb Total Space | 28.90 Gb Free Space | 24.82% Space Free | Partition Type: NTFS
Drive D: | 329.79 Gb Total Space | 201.03 Gb Free Space | 60.96% Space Free | Partition Type: NTFS
Drive F: | 2.98 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
 
Computer Name: LANCE-PC | User Name: LANCE | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AutoUpdateDisableNotify" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1A460EC4-5DF9-41DA-967A-5F7A3C00D9A6}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{1B7D2485-7748-479A-B9A3-A57A0A2236EE}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |
"{21CDD142-D7AD-4571-A88D-7514B3A54C91}" = rport=445 | protocol=6 | dir=out | app=system |
"{2DF96445-FA36-42B9-8DCA-71B0B90D0DDC}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2E383178-59E1-4DF0-B6A8-E0A1EAE33237}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{390E2D11-B9E1-45CC-AA65-DF7B14792F81}" = lport=2869 | protocol=6 | dir=in | app=system |
"{3958D136-D8A6-491D-B595-0EE9A28CB891}" = rport=137 | protocol=17 | dir=out | app=system |
"{4B3C40F4-9BB9-4A95-B3CE-EF7F74DA8143}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4C31D8E7-900B-49A1-A685-0CEB855A9F29}" = rport=139 | protocol=6 | dir=out | app=system |
"{4FF00754-CA37-4BFE-9F6F-C9CE42EE56A9}" = lport=137 | protocol=17 | dir=in | app=system |
"{52BAA22A-6E5F-47CD-915E-236EDCF9142F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7656DEA3-0002-4088-BC46-B3C823111CC5}" = rport=10243 | protocol=6 | dir=out | app=system |
"{8B581033-441E-4AA7-B6A2-AEB80B02DC2F}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{90C1EF5A-D2E1-4AC6-92E9-BD14BDB87808}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{945BC9C5-2681-43C7-8B6A-805AA0B25FF4}" = lport=445 | protocol=6 | dir=in | app=system |
"{9A091423-5243-4E65-8CB1-C7DE648129C5}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |
"{9F643BD7-D14D-482E-ACE8-14BCCDED974C}" = lport=10243 | protocol=6 | dir=in | app=system |
"{A07B4763-FB32-45C9-90C7-084AB4201831}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C19331C6-D38D-4DC7-99AB-B5CE5C1AAC9D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{CAA22946-8CC3-461A-B3EF-FE49BAC2FA93}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{CED49042-C277-4558-8821-A35B44941BEA}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{CF9E4B2C-3C78-4FED-A6D1-F98E6D14F0B9}" = lport=138 | protocol=17 | dir=in | app=system |
"{DCEE8CA5-6AB0-4CB3-8B35-3F421D1C62EE}" = rport=138 | protocol=17 | dir=out | app=system |
"{E4DA7BD9-92C4-4772-88C1-6B9601F8EB09}" = lport=139 | protocol=6 | dir=in | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03DFEB97-2D54-41F7-AC15-50C9671F20DB}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |
"{09677D1E-08D2-4F28-8175-62973EFBA2B8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0B0A4710-9074-4B6D-809D-701080CA4BB8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{0BF23462-356C-42CD-9D64-55A82A3EA5EB}" = protocol=6 | dir=in | app=c:\program files\common files\common desktop agent\cdasrv.exe |
"{0E6712C4-127F-46DC-84E0-29DA27FF7830}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{0FA3C9F4-5F05-45FE-8B05-BF0DB6F5A4AE}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\easy document creator\usdagent.exe |
"{1127AF90-828A-4739-B4AC-F1107EB0BD02}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{12F362D7-D74C-4877-98FB-A86E8FB70C0C}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{175514D6-A008-4391-9D40-3C4EC6C75026}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\easy printer manager\cdas2pc\cdas2pc.exe |
"{1E53D135-2464-4912-9FD3-1FACE5C9B2D4}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\easy printer manager\ids.application.exe |
"{22DC4D20-F3AA-4374-9FD9-FE28C8CC395A}" = dir=in | app=c:\program files\hp\hp officejet pro 8600\bin\faxapplications.exe |
"{2431A3A1-C918-4331-B462-C77000563E56}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2380\agent.exe |
"{26206BE4-E528-4040-907F-295175072FC1}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\samsung universal scan driver\usdagent.exe |
"{2631553C-739D-4932-9E04-567038E8CE75}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\easy printer manager\ids.application.exe |
"{2A8E9947-DE8A-4C41-ADEB-172BA0A83DFC}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2380\agent.exe |
"{32601CD2-D6F0-431D-953C-2A5D833EE888}" = dir=in | app=c:\program files\hp\hp officejet pro 8600\bin\sendafax.exe |
"{32A7EB24-A4C5-4676-9998-9F0B925A40E1}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\samsung universal scan driver\usdagent.exe |
"{36CD0B79-263A-44CF-B32C-C9B8488348D6}" = protocol=17 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe |
"{3CC2FCEC-EF44-4F86-8267-995420AF811B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{41209E88-4B20-48A4-8855-98A581284343}" = protocol=58 | dir=out | [email protected],-28546 |
"{4383404B-EAE8-4867-B64A-DBB55F4993A3}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{44943C4A-5EDB-4E0D-85FB-CCB00FC0F491}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\easy document creator\usdagent.exe |
"{46388D43-54C5-49AA-8F3F-C9836B972865}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4714E8F8-88A2-48F9-B514-408131B4D10B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4BD17FDB-ACF5-4130-BBC5-BB4C63DD18F5}" = protocol=17 | dir=in | app=c:\windows\twain_32\samsung\scx3400\scnsearch\usdagent.exe |
"{4C04C6C2-0024-4950-9B7F-005ACF73BEDA}" = dir=in | app=c:\program files\hp\hp officejet pro 8600\bin\devicesetup.exe |
"{4EBAE931-0CDF-47B1-A331-ECCEDFAE99A8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{59568671-8506-4D98-B73F-E719FED783C8}" = dir=in | app=c:\program files\hp\hp officejet pro 8600\bin\hpnetworkcommunicator.exe |
"{5CF0A983-4454-4B39-BD09-C0ACEDC122B1}" = protocol=1 | dir=in | [email protected],-28543 |
"{6007AB26-B05C-43D0-8EF5-9EEB39E04FE9}" = protocol=1 | dir=out | [email protected],-28544 |
"{6B8A1F98-6562-45DF-B463-93BC0EE80EB8}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{6C968F22-04FF-46A8-B023-23AE04DB52BA}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{71476FFB-D1C3-4784-99C9-F140F559C74A}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\samsung universal scan driver\iccupdater.exe |
"{7339E1FA-594D-4C64-8A98-35A0E622BC67}" = protocol=17 | dir=in | app=c:\program files\common files\common desktop agent\cdasrv.exe |
"{78423C39-5477-4875-9EFF-4FCF6EFCE51E}" = protocol=6 | dir=out | app=system |
"{80CD1473-8FFD-4CBD-8D71-9373F7E6CE63}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{89C39D6F-0061-4B82-B51D-0B0455DAE0C1}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\easy printer manager\cdas2pc\cdas2pc.exe |
"{89DDEA00-98F8-4A72-9D4E-6E64EE754606}" = protocol=6 | dir=in | app=c:\users\lance\appdata\roaming\dropbox\bin\dropbox.exe |
"{914DF3FE-7582-44A7-A889-ADA33CAEFD16}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{A16DEFF2-1C21-4E41-89A7-32A0F50C691E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A16E1272-5D62-450F-BE9C-ADC51138F82E}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A36198DF-45B3-418A-B2EA-41E99CDE9003}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |
"{A48F5B30-68CE-4AF5-8942-A62DDCEAF0C1}" = dir=in | app=c:\program files\hp\hp officejet pro 8600\bin\hpnetworkcommunicatorcom.exe |
"{A8C46F22-E7AE-46AF-8A4E-1A61AA33C99F}" = dir=in | app=c:\program files\hp\hp officejet pro 8600\bin\digitalwizards.exe |
"{B1477266-5749-4579-A375-E27DE1921874}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\easy printer manager\ordersupplies.exe |
"{BFA81932-CC3C-47D9-9C6C-F55FF33B1314}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{C131A833-581B-4884-A326-920334CA6BD4}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\easy printer manager\idsalert.exe |
"{CAF2E9DA-33D9-4D4D-84BE-87A3987C9CCC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CC1A5B61-134D-4EE7-9BCF-8E029CA647A2}" = protocol=6 | dir=in | app=c:\windows\twain_32\samsung\scx3400\scnsearch\usdagent.exe |
"{CEB544C8-0A09-4FFE-BBF9-4E063630C599}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D787458E-34D2-4258-95C4-8CE01652429E}" = protocol=17 | dir=in | app=c:\users\lance\appdata\roaming\dropbox\bin\dropbox.exe |
"{D9696F79-5F9B-4699-9086-FBEBCFA4B40E}" = protocol=6 | dir=in | app=c:\program files (x86)\samsung\easy printer manager\idsalert.exe |
"{DB13AA20-BB37-43DC-9A3B-A6D8046F6547}" = protocol=6 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe |
"{DBFD7E84-B0B9-485E-93EA-36A4D36AB8B2}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E56797E5-8E61-4021-9891-E102D0AAE1E4}" = protocol=58 | dir=in | [email protected],-28545 |
"{EAC42D58-7E37-49BC-9C34-D08A4B7C0329}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\easy printer manager\ordersupplies.exe |
"{F337EA70-E571-4F3E-8481-4655EAE6E626}" = protocol=17 | dir=in | app=c:\program files (x86)\samsung\samsung universal scan driver\iccupdater.exe |
"TCP Query User{5DDA53EE-CBB5-4D5D-B0E3-80FFB13D039B}C:\program files\tixati\tixati.exe" = protocol=6 | dir=in | app=c:\program files\tixati\tixati.exe |
"TCP Query User{A01E93F2-E817-4676-9BE3-E888B5BD19DA}C:\program files (x86)\frozenbyte\trine 2 - complete story\trine2_32bit.exe" = protocol=6 | dir=in | app=c:\program files (x86)\frozenbyte\trine 2 - complete story\trine2_32bit.exe |
"TCP Query User{B7C55AC1-89CC-478D-821E-A22D246FF8F4}C:\program files\tixati\tixati.exe" = protocol=6 | dir=in | app=c:\program files\tixati\tixati.exe |
"TCP Query User{FE9D9127-A908-456F-AC4A-C55BA5306222}C:\users\lance\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\lance\appdata\roaming\dropbox\bin\dropbox.exe |
"UDP Query User{282CBD27-B8B1-4F07-ADD5-DE5B9CDCEADD}C:\program files\tixati\tixati.exe" = protocol=17 | dir=in | app=c:\program files\tixati\tixati.exe |
"UDP Query User{698166AA-A4D7-40B1-8D0A-667929C0C841}C:\program files\tixati\tixati.exe" = protocol=17 | dir=in | app=c:\program files\tixati\tixati.exe |
"UDP Query User{8B661810-1B9A-4ED6-AF94-61E7102F36AA}C:\program files (x86)\frozenbyte\trine 2 - complete story\trine2_32bit.exe" = protocol=17 | dir=in | app=c:\program files (x86)\frozenbyte\trine 2 - complete story\trine2_32bit.exe |
"UDP Query User{CD0E0AC1-D63F-4520-B302-3707FC5CBEC9}C:\users\lance\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\lance\appdata\roaming\dropbox\bin\dropbox.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{031A0E14-0413-4C97-9772-2639B782F46F}" = Common Desktop Agent
"{10CD364B-FFCC-48BE-B469-B9622A033075}" = Fences
"{13F4A7F3-EABC-4261-AF6B-1317777F0755}" = Fast Boot
"{26A24AE4-039D-4CA4-87B4-2F86418020F0}" = Java 8 Update 20 (64-bit)
"{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}" = Apple Mobile Device Support
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{77DE5105-D05E-448C-96CB-7FA381903753}" = iTunes
"{791A06E2-340F-43B0-8FAB-62D151339362}" = HP Officejet Pro 8600 Basic Device Software
"{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1
"{81E20D41-C277-4526-934D-F2380AF91B78}" = iCloud
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{91EFE3A1-585E-4F66-B5F6-F118F56C4C47}" = ASUS Power4Gear Hybrid
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = WIDCOMM Bluetooth Software
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 327.02
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 327.02
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 327.02
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.14.17
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.3.26.4
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{BFAE8D5B-F918-486F-B74E-90762DF11C5C}" = Microsoft Security Client
"ASUS WebStorage" = ASUS WebStorage
"CCleaner" = CCleaner
"Defraggler" = Defraggler
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft Security Client" = Microsoft Security Essentials
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VLC media player" = VLC media player
"WinRAR archiver" = WinRAR 5.01 (64-bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{012C59CF-074A-43DA-8085-B6E636733B59}" = Citrix Receiver(Aero)
"{022CBB38-CEF0-42BA-906A-A49BEFAE0BEE}" = RICOH R5U230 Media Driver ver.2.05.02.02
"{06585B02-F20D-4AB2-9A64-86EF2AE0F8F0}" = ASUS AI Recovery
"{0969AF05-4FF6-4C00-9406-43599238DE0D}" = ASUS Splendid Video Enhancement Technology
"{0A3925EA-5B0E-401B-A189-7419149747B2}" = Adobe AIR
"{0E1C5B43-1837-4F98-A96B-79A8A0A5955F}" = Citrix Receiver(USB)
"{111EE7DF-FC45-40C7-98A7-753AC46B12FB}" = QuickTime 7
"{1898B668-CCF5-429F-A86F-9837E5439D77}" = SafeFinder Smartbar
"{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3
"{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}" = Wireless Console 3
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{38F8D823-008D-4E5A-BBCE-867A86C2BF2B}" = Sound Blaster Audigy HD
"{3B05F2FB-745B-4012-ADF2-439F36B2E70B}" = ATKOSD2
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{47117FCA-0D00-4B6D-9D68-00B763629463}" = Self-service Plug-in
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5B65EF64-1DFA-414A-8C94-7BB726158E21}" = ControlDeck
"{5E8AC853-65BB-4C99-A09E-19B81851E14C}" = Citrix Receiver Updater
"{60D6618B-153F-4353-8185-908E676E5888}" = ASUS FancyStart
"{64452561-169F-4A36-A2FF-B5E118EC65F5}" = ASUS SmartLogon
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{78002155-F025-4070-85B3-7C0453561701}" = Apple Application Support
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.18
"{7C05592D-424B-46CB-B505-E0013E8E75C9}" = ATK Hotkey
"{8F21291E-0444-4B1D-B9F9-4370A73E346D}" = WinFlash
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.08)
"{ADE8A83D-BB70-4FB5-BA19-26C47EA31894}" = Citrix Receiver(DV)
"{B5A5627C-0173-4DB2-ADA8-740479370F67}" = Express Gate
"{B6B5F07C-88D5-49D3-A1A7-A6D4BC37DCCC}" = SNS Upload for Easy Document Creator
"{B83FC356-B7C0-441F-8A4D-D71E088E7974}" = NVIDIA PhysX
"{BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24}" = LPT System Updater Service
"{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
"{C4E28723-0663-4012-9BDC-E21A14C1316C}" = Citrix Receiver (HDX Flash Redirection)
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{CA55005D-94AC-4596-9646-679D6CC0D620}" = Citrix Authentication Manager
"{D1E5870E-E3E5-4475-98A6-ADD614524ADF}" = ATK Media
"{D3D54F3E-C5C3-443D-978F-87A72E5616E8}" = ATK Generic Function Service
"{D9EE360A-7C19-47EC-93C7-97DEFF64804B}" = Citrix Receiver Inside
"{DD649DA2-BBD9-4247-85DD-E04F7C1E8552}" = calibre
"{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}" = ASUS Live Update
"{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F390D923-76F1-458E-8218-8C0C156CDCFD}" = Online Plug-in
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 14 Plugin
"ASUS AP Bank_is1" = ASUS AP Bank
"ASUS_ScreenSaver_GSeries" = ASUS_ScreenSaver_GSeries
"Audacity_is1" = Audacity 2.0.4
"CitrixOnlinePluginPackWeb" = Citrix Receiver
"DAEMON Tools Lite" = DAEMON Tools Lite
"Diablo III" = Diablo III
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FileHippo.com" = FileHippo.com Update Checker
"Google Chrome" = Google Chrome
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"LAME_is1" = LAME v3.99.3 (for Windows)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"MozBackup" = MozBackup 1.5.1
"Mozilla Firefox 31.0 (x86 en-US)" = Mozilla Firefox 31.0 (x86 en-US)
"Mozilla Thunderbird 31.0 (x86 en-US)" = Mozilla Thunderbird 31.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Samsung Easy Document Creator" = Samsung Easy Document Creator
"Samsung Easy Printer Manager" = Samsung Easy Printer Manager
"Samsung OCR Software" = Samsung OCR Software
"Samsung Printer Live Update" = Samsung Printer Live Update
"Samsung Scan Process Machine" = Samsung Scan Process Machine
"Samsung SCX-3400 Series" = Samsung SCX-3400 Series
"Samsung Universal Scan Driver" = Samsung Universal Scan Driver
"SpywareBlaster_is1" = SpywareBlaster 5.0
"tixati" = Tixati
"Trine 2 - Complete Story_is1" = Trine 2 - Complete Story
"View User Guide" = View User's Guide
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"VLC Media Player 64-bit Packages" = VLC Media Player 64-bit Packages
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 7/30/2014 9:20:47 PM | Computer Name = LANCE-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4134
 
Error - 8/1/2014 4:30:20 PM | Computer Name = LANCE-PC | Source = System Restore | ID = 8193
Description =
 
Error - 8/1/2014 4:37:39 PM | Computer Name = LANCE-PC | Source = System Restore | ID = 8193
Description =
 
Error - 8/1/2014 4:37:39 PM | Computer Name = LANCE-PC | Source = System Restore | ID = 8193
Description =
 
Error - 8/1/2014 4:37:45 PM | Computer Name = LANCE-PC | Source = System Restore | ID = 8193
Description =
 
Error - 8/1/2014 4:37:52 PM | Computer Name = LANCE-PC | Source = System Restore | ID = 8193
Description =
 
Error - 8/1/2014 4:38:12 PM | Computer Name = LANCE-PC | Source = ESENT | ID = 623
Description = wuaueng.dll (1060) SUS20ClientDataStore: The version store for this
 instance (0) has reached its maximum size of 32Mb. It is likely that a long-running
 transaction is preventing cleanup of the version store and causing it to build
up in size. Updates will be rejected until the long-running transaction has been
 completely committed or rolled back.    Possible long-running transaction:     SessionId:
 0x00000000015F04A0     Session-context: 0x00000000     Session-context ThreadId: 0x00000000000044F8

    Cleanup:
 1
 
Error - 8/1/2014 4:40:53 PM | Computer Name = LANCE-PC | Source = System Restore | ID = 8193
Description =
 
Error - 8/2/2014 6:40:09 PM | Computer Name = LANCE-PC | Source = System Restore | ID = 8193
Description =
 
Error - 8/2/2014 7:20:59 PM | Computer Name = LANCE-PC | Source = System Restore | ID = 8193
Description =
 
[ System Events ]
Error - 7/24/2014 9:29:31 PM | Computer Name = LANCE-PC | Source = BTHUSB | ID = 327697
Description = The local Bluetooth adapter has failed in an undetermined manner and
 will not be used. The driver has been unloaded.
 
Error - 7/24/2014 9:29:44 PM | Computer Name = LANCE-PC | Source = BTHUSB | ID = 327697
Description = The local Bluetooth adapter has failed in an undetermined manner and
 will not be used. The driver has been unloaded.
 
Error - 8/2/2014 12:02:47 AM | Computer Name = LANCE-PC | Source = DCOM | ID = 10010
Description =
 
Error - 8/2/2014 6:29:04 PM | Computer Name = LANCE-PC | Source = BTHUSB | ID = 327697
Description = The local Bluetooth adapter has failed in an undetermined manner and
 will not be used. The driver has been unloaded.
 
Error - 8/2/2014 6:29:46 PM | Computer Name = LANCE-PC | Source = BTHUSB | ID = 327697
Description = The local Bluetooth adapter has failed in an undetermined manner and
 will not be used. The driver has been unloaded.
 
Error - 8/4/2014 8:24:53 AM | Computer Name = LANCE-PC | Source = BTHUSB | ID = 327697
Description = The local Bluetooth adapter has failed in an undetermined manner and
 will not be used. The driver has been unloaded.
 
Error - 8/4/2014 8:25:22 AM | Computer Name = LANCE-PC | Source = BTHUSB | ID = 327697
Description = The local Bluetooth adapter has failed in an undetermined manner and
 will not be used. The driver has been unloaded.
 
Error - 8/6/2014 4:30:04 PM | Computer Name = LANCE-PC | Source = BTHUSB | ID = 327697
Description = The local Bluetooth adapter has failed in an undetermined manner and
 will not be used. The driver has been unloaded.
 
Error - 8/6/2014 4:30:19 PM | Computer Name = LANCE-PC | Source = BTHUSB | ID = 327697
Description = The local Bluetooth adapter has failed in an undetermined manner and
 will not be used. The driver has been unloaded.
 
Error - 8/15/2014 12:32:21 PM | Computer Name = LANCE-PC | Source = BTHUSB | ID = 327697
Description = The local Bluetooth adapter has failed in an undetermined manner and
 will not be used. The driver has been unloaded.
 
 
< End of report >


  • 0

Advertisements


#2
dbreeze

dbreeze

    Trusted Helper

  • Malware Removal
  • 2,216 posts
Hi LANCE1313,

Welcome to Geeks to Go. My name is dbreeze and I'll be helping you with this problem. Before I get into the removal of malware / correction of your problem, I need you to be aware of the following:
  • As I am in the final phase of training right now, my responses to you may be delayed slightly as they have to be checked by my adviser (good news for you, as there will be two sets of eyes fixing your problem). I promise to be as prompt as possible in helping you, so please bear with me and we will get through this.
  • Please read all of my response through at least once before attempting to follow the procedures described.I would recommend printing them out, if you can, as you can check off each step as you complete it. Also, as some of the cleaning may be done in Safe Mode and there will be no internet connection then, you will find that having the steps printed for reference speeds the cleaning process along. If there's anything you don't understand or isn't totally clear to you, please come back to me for clarification before you start those steps.
  • All of the assistants and staff at Geeks to Go are here on a volunteer basis; please respect our time given to the cause of helping others.If you are going to be away for more than 4 days, please let me know here. (I will do the same for you.) We do realize that 'life happens' and situations arise unexpectedly; we just ask that you keep us up to date. That being said, please notice the following Geeks to Go rule:
  • Posts that are not replied to in four (4) days will result in the topic being closed. We have not forgotten you; this is just an effort to keep the boards organized and flowing. To continue on your closed topic, please PM me or any Moderator to have the topic reactivated. If, at any time during our working together, I have not responded to you in 2 days (48 hours), then please PM me.
  • Malware removal is a complex, multiple step process; please stay with me on this thread (don't start another thread) until I declare that your logs are clean and you are good to go. The absence of apparent issues does not mean your system is clean; I will tell you when everything looks good for you to go and help you remove the tools we have used.
  • If any of the security programs on your system should give any warnings about the software tools I ask you to download and use, please do not be alarmed.All of the tools I will have you use are safe to use (as instructed) and malware free.
  • While we strive to disrupt your system as little as possible, things happen.If you can, it would be best to back up your personal files now (if you do not already have a backup). You can store these on a CD/DVD, USB drive or stick, anywhere but on your same system. This will save you from possible anguish later if something unforeseen happens.
  • Please do not run any other tools or scanners than what I ask you to.Some of the openly available software made for malware removal can make changes to your system that interfere with the cleaning of the malware, or even destroy your system. I will use only what the situation calls for and direct you in the proper use of that software.
  • Please do not attach any log files to your replies unless I specifically ask you.Instead please copy and paste so as to include the log in your reply. You can do this in separate posts if it's easier for you.
Let's get started....


While OTL is fine, we have a different scanner that will help with Chrome a little better.


Please download Farbar Recovery Scan Tool 64bit and save it to your Desktop.
  • Right click on the FRST64.exe file on your desktop and select "Run as Administrator..." When the tool opens click Yes to disclaimer.
  • Press the Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
Thank you.
  • 0

#3
LANCE1313

LANCE1313

    Member

  • Topic Starter
  • Member
  • PipPip
  • 42 posts

Thanks.  Here we go

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-08-2014
Ran by LANCE (administrator) on LANCE-PC on 30-08-2014 17:09:40
Running from C:\Users\LANCE\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingc...can-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingc...can-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe
() C:\Program Files\ATKGFNEX\GFNEXSrv.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\WDC.exe
(ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
() C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
() C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
() C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(FileHippo.com) C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
(ASUS) C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\SB Audigy\Volume Panel\VolPanlu.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\redirector.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\Receiver\Receiver.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Dropbox, Inc.) C:\Users\LANCE\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\POWERPNT.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Smartbar) C:\Users\LANCE\AppData\Local\Smartbar\Application\SafeFinder.exe
() C:\Program Files (x86)\LPT\srpts.exe
() C:\Program Files (x86)\LPT\srptsl.exe
() C:\Users\LANCE\AppData\Local\LPT\srptm.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_179.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_179.exe
() C:\Users\LANCE\AppData\Local\Smartbar\Application\Lrcnta.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [EeeStorageBackup] => C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [1732608 2009-11-26] ()
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1813288 2009-08-17] (Synaptics Incorporated)
HKLM\...\Run: [RunDLLEntry] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\AmbRunE.dll,RunDLLEntry
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [456704 2012-02-20] ()
HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe [6937216 2009-10-09] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe [170624 2009-08-20] (ASUS)
HKLM-x32\...\Run: [VolPanel] => C:\Program Files (x86)\Creative\SB Audigy\Volume Panel\VolPanlu.exe [237693 2008-12-29] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [CitrixReceiver] => "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk"
HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [395656 2013-10-01] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [153992 2013-10-01] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-07-30] (Oracle Corporation)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.)
HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-09-06] (Microsoft Corporation)
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\Run: [FileHippo.com] => C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe [307712 2012-11-23] (FileHippo.com)
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\Run: [HP Officejet Pro 8600 (NET)] => C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21653096 2014-07-24] (Skype Technologies S.A.)
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\Run: [GoogleChromeAutoLaunch_06652FE761E59AF1CD30EA9A61DFF3A9] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [852808 2014-08-28] (Google Inc.)
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-13] (Microsoft Corporation)
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\Run: [Browser Infrastructure Helper] => C:\Users\LANCE\AppData\Local\Smartbar\Application\SafeFinder.exe [28160 2014-08-27] (Smartbar)
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\MountPoints2: {8b8dda66-64f1-11e3-857a-e0cb4e302f58} - F:\setup.exe
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\MountPoints2: {9fc835fc-6ca6-11e3-8716-e0cb4e302f58} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\start.exe
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\MountPoints2: {b12ff93c-ab0e-11e3-abef-e0cb4e302f58} - F:\setup.exe
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\MountPoints2: {e9162f72-44b1-11e3-a90a-e0cb4e302f58} - "G:\WD SmartWare.exe" autoplay=true
AppInit_DLLs: C:\Users\LANCE\AppData\Local\Smartbar\Application\Resources\crdlil64.dll => C:\Users\LANCE\AppData\Local\Smartbar\Application\Resources\crdlil64.dll [77856 2014-08-30] ()
AppInit_DLLs-x32: C:\Users\LANCE\AppData\Local\Smartbar\Application\Resources\crdlil.dll => C:\Users\LANCE\AppData\Local\Smartbar\Application\Resources\crdlil.dll [67104 2014-08-30] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk
ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{60D6618B-153F-4353-8185-908E676E5888}\_DCE9A4DB2A5F2786140FA3.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\LANCE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\LANCE\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: AsusWSShellExt_B -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\service\AsusWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: AsusWSShellExt_O -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\service\AsusWSShellExt64.dll (eCareme Technologies, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://feed.safefind...Qp4CtkJPsHJj1Eg,
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.safefind...q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.safefind...q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.safefind...q={searchTerms}
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.safefind...q={searchTerms}
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.safefind...q={searchTerms}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.safefind...q={searchTerms}
BHO: SafeFinder SmartbarEngine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_20\bin\ssv.dll (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_20\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: SafeFinder SmartbarEngine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM - SafeFinder Smartbar - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\system32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - SafeFinder Smartbar - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} -  No File
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default
FF NewTab: hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9howjcx7fZ0FW0FE0MeOOoZRxBPJEUsk-wpxHmB3CTiJ1nKG5c7zeDTgKQ7Ogd3N9Y1Lg9drO5_rPZZzRHyehMi2esTX98_V4FYrTTlyzdeESSPJspg03Idt4-aiFO9fl7k75P43uOGoP6UPgpq1OXTAP48DQmpp4Sb_w,,
FF DefaultSearchEngine: SafeFinder Search
FF SelectedSearchEngine: SafeFinder Search
FF Homepage: hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9howjcx7fZ0FW0FE0MeOOoZRxBPJEUsk-wpxHmB3CTiJ1nKG5c7zeDTgKQ7Ogd3N9Y1Lg9drO5_rPZZzRd0qYXWCc8vv0EK9znlBTsQV6jMzVXBkR2sd1TQ0vYUQjmFgWWtTQ_1sr9GauGrGFoMjjvQp4CtkJPsHJj1Eg,,
FF Keyword.URL: hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9howjcx7fZ0FW0FE0MeOOoZRxBPJEUsk-wpxHmB3CTiJ1nKG5c7zeDTgKQ7Ogd3N9Y1Lg9drO5_rPZZzRuT8eTPEaYy76HQTcnLyJ-HJP1OsSFx-MZoUgdqpvfLxocVtlrsBioiJTzm2v3ukSFscWH28gaHu6721ChbSA,,&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll ()
FF Plugin: @java.com/DTPlugin,version=11.20.2 -> C:\Program Files\Java\jre1.8.0_20\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.20.2 -> C:\Program Files\Java\jre1.8.0_20\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll (Citrix Systems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\searchplugins\SafeFinder Search.xml
FF Extension: Pocket - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\[email protected] [2014-07-22]
FF Extension: No Name - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\staged [2014-08-30]
FF Extension: WOT - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-12-08]
FF Extension: SafeFinder Smartbar - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\{f33c613b-851e-a627-440b-ac974e123ffc} [2014-08-30]
FF Extension: Cleanest Addon Manager - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\[email protected] [2013-09-05]
FF Extension: SkipScreen - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\[email protected] [2013-09-05]
FF Extension: Flagfox - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2014-03-10]
FF Extension: New Tab Homepage - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\{66E978CD-981F-47DF-AC42-E3CF417C1467}.xpi [2013-09-05]
FF Extension: NoScript - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-12-12]
FF Extension: Fasterfox - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\{c36177c0-224a-11da-8cd6-0800200c9a91}.xpi [2013-09-05]
FF Extension: Adblock Plus - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-09-05]
FF Extension: Download Statusbar - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi [2013-09-05]
FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]

Chrome:
=======
CHR HomePage: Default -> C636E567E0B7E5ED7CAA98DA48BAA6857D980A1F637CEC013514ECA70F1CA894
CHR DefaultSearchKeyword: Default -> 67F30E9B43E283EA7629FE09DED50A37EBB364E74050FDE018B2EC9664C40054
CHR DefaultSearchURL: Default -> 7B2991C89EB8228127EF9FEFBB687A003982395DC7AAA96084310E15C63755F3
CHR Profile: C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-22]
CHR Extension: (Google Drive) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-22]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-24]
CHR Extension: (WOT) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2014-05-22]
CHR Extension: (YouTube) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-22]
CHR Extension: (Google Search) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-22]
CHR Extension: (SuperSaiyanTheme) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplciigccgelconelnbdhnhpgibcbjfe [2014-05-22]
CHR Extension: (Netrunner Lookup) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\falbpbbdomlkdjlfippfjopgihdekanf [2014-05-22]
CHR Extension: (AdBlock) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-05-22]
CHR Extension: (Hola Better Internet) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2014-05-22]
CHR Extension: (Google Keep - notes and lists) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2014-05-22]
CHR Extension: (Social Fixer for Facebook) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifmhoabcaeehkljcfclfiieohkohdgbb [2014-05-22]
CHR Extension: (Disconnect) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeoacafpbcihiomhlakheieifhpjdfeo [2014-05-22]
CHR Extension: (The Great Suspender) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\klbibkeccnjlkjkiokjodocebajanakg [2014-05-22]
CHR Extension: (Google Wallet) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-22]
CHR Extension: (Gmail) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-22]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () [File not signed]
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2013-08-09] (Broadcom Corporation.)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2010-01-23] (Creative Labs) [File not signed]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2010-01-23] (Creative Labs) [File not signed]
R2 LMS; C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe [262144 2009-09-30] (Intel Corporation) [File not signed]
R2 LPTSystemUpdater; C:\Program Files (x86)\LPT\srpts.exe [32768 2014-08-27] ()
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 UNS; C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2314240 2009-09-30] (Intel Corporation) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASMMAP64; C:\Program Files\ATKGFNEX\ASMMAP64.sys [14904 2007-07-24] ()
S3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [170712 2013-08-09] (Broadcom Corporation.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-03-20] (Disc Soft Ltd)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1799680 2009-05-20] ()
U3 tmlwf; No ImagePath
U3 tmwfp; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-30 17:09 - 2014-08-30 17:10 - 00031277 _____ () C:\Users\LANCE\Downloads\FRST.txt
2014-08-30 17:09 - 2014-08-30 17:09 - 02103808 _____ (Farbar) C:\Users\LANCE\Downloads\FRST64.exe
2014-08-30 17:09 - 2014-08-30 17:09 - 00000000 ____D () C:\FRST
2014-08-30 10:25 - 2014-08-30 10:25 - 00071084 _____ () C:\Users\LANCE\Downloads\Extras.Txt
2014-08-30 10:23 - 2014-08-30 10:23 - 00137872 _____ () C:\Users\LANCE\Downloads\OTL.Txt
2014-08-30 10:14 - 2014-08-30 10:14 - 00602112 _____ (OldTimer Tools) C:\Users\LANCE\Downloads\OTL.exe
2014-08-30 09:31 - 2014-08-30 09:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-08-30 09:30 - 2014-08-30 09:31 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-08-30 09:30 - 2014-08-30 09:31 - 00000000 ____D () C:\Program Files\iTunes
2014-08-30 09:30 - 2014-08-30 09:31 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-08-30 09:30 - 2014-08-30 09:30 - 00000000 ____D () C:\Program Files\iPod
2014-08-30 09:24 - 2014-08-30 09:25 - 00000000 ____D () C:\Program Files (x86)\LPT
2014-08-30 09:24 - 2014-08-30 09:24 - 00002654 _____ () C:\Users\LANCE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-08-30 09:24 - 2014-08-30 09:24 - 00002607 _____ () C:\Users\LANCE\Desktop\Search.lnk
2014-08-30 09:23 - 2014-08-30 09:23 - 00000873 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-08-30 09:23 - 2014-08-30 09:23 - 00000000 ____D () C:\Users\LANCE\AppData\Roaming\0F1L1I1P0H1L1E1E1F
2014-08-30 09:23 - 2014-08-30 09:23 - 00000000 ____D () C:\Users\LANCE\AppData\Local\Smartbar
2014-08-30 09:23 - 2014-08-30 09:23 - 00000000 ____D () C:\Users\LANCE\AppData\Local\LPT
2014-08-30 09:22 - 2014-08-30 09:22 - 25611537 _____ () C:\Users\LANCE\Downloads\vlc-2.1.5-win64.exe
2014-08-30 09:20 - 2014-08-30 09:20 - 00002088 _____ () C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2014-08-30 09:15 - 2014-08-30 09:15 - 00001726 _____ () C:\Users\Public\Desktop\Defraggler.lnk
2014-08-30 09:13 - 2014-08-30 09:13 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-08-30 09:10 - 2014-08-30 09:17 - 113492816 _____ (Apple Inc.) C:\Users\LANCE\Downloads\iTunes64Setup.exe
2014-08-30 09:10 - 2014-08-30 09:16 - 96138664 _____ (Oracle Corporation) C:\Users\LANCE\Downloads\jre-8u20-windows-x64.exe
2014-08-30 09:10 - 2014-08-30 09:12 - 26472832 _____ (Mozilla) C:\Users\LANCE\Downloads\Thunderbird Setup 31.0.exe
2014-08-30 09:10 - 2014-08-30 09:11 - 04901352 _____ (Piriform Ltd) C:\Users\LANCE\Downloads\ccsetup417.exe
2014-08-30 09:10 - 2014-08-30 09:11 - 04362512 _____ (Piriform Ltd) C:\Users\LANCE\Downloads\dfsetup218.exe
2014-08-30 09:10 - 2014-08-30 09:10 - 00768024 _____ ( ) C:\Users\LANCE\Downloads\vlc-2.1.5-win64_inst.exe
2014-08-30 09:09 - 2014-08-30 09:10 - 18743160 _____ (Adobe Systems Inc.) C:\Users\LANCE\Downloads\AdobeAIRInstaller.exe
2014-08-29 17:01 - 2014-08-22 22:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-29 17:01 - 2014-08-22 21:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-29 17:01 - 2014-08-22 20:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 10:20 - 2014-08-22 11:46 - 00107567 _____ () C:\Users\LANCE\Desktop\Sinai Grand Rounds.pptx
2014-08-19 21:34 - 2014-08-19 21:34 - 00000962 _____ () C:\Users\Public\Desktop\calibre - E-book management.lnk
2014-08-19 21:15 - 2014-08-19 21:16 - 56419840 _____ () C:\Users\LANCE\Downloads\calibre-1.48.0.msi
2014-08-19 21:11 - 2014-08-19 21:16 - 00000000 ____D () C:\Users\LANCE\Downloads\Book Requests
2014-08-17 11:48 - 2014-08-17 13:05 - 00000000 ____D () C:\Users\LANCE\Desktop\Grand Rounds
2014-08-15 12:36 - 2014-08-30 08:07 - 00003170 _____ () C:\Windows\System32\Tasks\P4GIntlCtrl
2014-08-15 10:45 - 2013-10-01 22:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-08-15 10:45 - 2013-10-01 22:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-08-15 10:45 - 2013-10-01 22:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-08-15 10:45 - 2013-10-01 21:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-08-15 10:45 - 2013-10-01 21:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-08-15 10:45 - 2013-10-01 21:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-08-15 10:45 - 2013-10-01 21:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-08-15 10:45 - 2013-10-01 20:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2014-08-15 10:45 - 2013-10-01 20:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2014-08-15 10:45 - 2013-10-01 20:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-08-15 10:45 - 2013-10-01 20:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-08-15 10:45 - 2013-10-01 19:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-08-15 10:45 - 2013-10-01 19:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-08-15 10:45 - 2013-10-01 18:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-08-15 10:45 - 2013-10-01 16:57 - 06578176 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-08-15 10:45 - 2013-10-01 16:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-08-15 10:44 - 2013-10-01 20:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-08-15 10:44 - 2013-10-01 19:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-08-15 10:27 - 2014-06-30 18:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-15 10:27 - 2014-06-30 18:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-15 10:27 - 2014-03-09 17:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-15 10:27 - 2014-03-09 17:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-15 10:27 - 2014-03-09 17:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-15 10:27 - 2014-03-09 17:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-15 10:26 - 2014-06-06 02:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-15 10:26 - 2014-06-06 02:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-15 10:26 - 2013-12-03 22:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-08-15 10:26 - 2013-12-03 22:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-08-15 10:26 - 2013-12-03 22:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-08-15 10:26 - 2013-12-03 22:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-08-15 10:26 - 2013-12-03 22:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-08-15 10:26 - 2013-12-03 21:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-08-15 10:26 - 2013-12-03 21:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-08-15 10:26 - 2013-12-03 21:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-08-15 10:26 - 2013-12-03 21:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-08-15 10:25 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-08-15 10:25 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-08-15 10:25 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-08-15 10:25 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-08-15 10:25 - 2014-07-08 22:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-08-15 10:25 - 2014-07-08 21:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-08-15 10:25 - 2014-07-08 21:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-08-15 10:25 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-08-15 10:25 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-08-15 10:25 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-08-15 10:25 - 2014-07-08 18:38 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-08-15 10:25 - 2014-07-08 18:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
2014-08-15 10:25 - 2014-06-24 22:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-15 10:25 - 2014-06-24 21:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-15 10:25 - 2014-05-30 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-08-15 10:25 - 2014-05-30 04:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-08-15 10:25 - 2014-05-30 04:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-08-15 10:25 - 2014-05-30 04:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-08-15 10:25 - 2014-05-30 04:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-08-15 10:25 - 2014-05-30 04:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-08-15 10:25 - 2014-05-30 04:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-08-15 10:25 - 2014-05-30 03:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-08-15 10:25 - 2014-05-30 03:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-08-15 10:25 - 2014-05-30 03:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-08-15 10:25 - 2014-05-30 03:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-08-15 10:25 - 2014-05-30 03:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-08-15 10:25 - 2014-05-30 03:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-08-15 10:25 - 2014-05-30 03:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-08-15 10:25 - 2014-02-03 22:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-08-15 10:25 - 2014-02-03 22:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-08-15 10:25 - 2014-02-03 22:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-08-15 10:25 - 2014-02-03 22:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-08-15 10:25 - 2014-02-03 22:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-08-15 10:25 - 2014-01-27 22:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-08-15 10:25 - 2014-01-23 22:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-08-15 10:25 - 2013-12-03 22:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-08-15 10:25 - 2013-12-03 22:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-08-15 10:25 - 2013-12-03 22:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-08-15 10:25 - 2013-12-03 22:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-08-15 10:25 - 2013-12-03 22:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-08-15 10:25 - 2013-12-03 22:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-08-15 10:25 - 2013-12-03 22:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-08-15 10:25 - 2013-12-03 22:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-08-15 10:25 - 2013-12-03 22:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-08-15 10:25 - 2013-09-24 22:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-08-15 10:25 - 2013-09-24 21:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-08-15 10:23 - 2014-02-03 22:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-08-15 10:23 - 2014-02-03 22:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-08-15 10:19 - 2014-07-15 23:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-15 10:19 - 2014-07-15 22:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-15 10:18 - 2014-07-31 19:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-15 10:18 - 2014-07-31 19:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-15 10:18 - 2014-07-25 10:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-15 10:18 - 2014-07-25 10:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-15 10:18 - 2014-07-25 10:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-15 10:18 - 2014-07-25 09:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-15 10:18 - 2014-07-25 09:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-15 10:18 - 2014-07-25 09:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-15 10:18 - 2014-07-25 09:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-15 10:18 - 2014-07-25 09:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-15 10:18 - 2014-07-25 09:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-15 10:18 - 2014-07-25 09:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-15 10:18 - 2014-07-25 09:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-15 10:18 - 2014-07-25 09:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-15 10:18 - 2014-07-25 09:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-15 10:18 - 2014-07-25 09:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-15 10:18 - 2014-07-25 09:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-15 10:18 - 2014-07-25 08:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-15 10:18 - 2014-07-25 08:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-15 10:18 - 2014-07-25 08:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-15 10:18 - 2014-07-25 08:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-15 10:18 - 2014-07-25 08:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-15 10:18 - 2014-07-25 08:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-15 10:18 - 2014-07-25 08:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-15 10:18 - 2014-07-25 08:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-15 10:18 - 2014-07-25 08:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-15 10:18 - 2014-07-25 08:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-15 10:18 - 2014-07-25 08:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-15 10:18 - 2014-07-25 08:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-15 10:18 - 2014-07-25 08:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-15 10:18 - 2014-07-25 08:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-15 10:18 - 2014-07-25 08:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-15 10:18 - 2014-07-25 08:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-15 10:18 - 2014-07-25 08:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-15 10:18 - 2014-07-25 08:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-15 10:18 - 2014-07-25 08:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-15 10:18 - 2014-07-25 07:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-15 10:18 - 2014-07-25 07:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-15 10:18 - 2014-07-25 07:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-15 10:18 - 2014-07-25 07:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-15 10:18 - 2014-07-25 07:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-15 10:18 - 2014-07-25 07:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-15 10:18 - 2014-07-25 07:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-15 10:18 - 2014-07-25 07:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-15 10:18 - 2014-07-25 07:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-15 10:18 - 2014-07-25 07:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-15 10:18 - 2014-07-25 07:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-15 10:18 - 2014-07-25 07:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-15 10:18 - 2014-07-25 07:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-08-15 10:18 - 2014-07-25 07:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-15 10:18 - 2014-07-25 06:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-15 10:18 - 2014-07-25 06:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-15 10:18 - 2014-07-25 06:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-15 10:18 - 2014-07-25 06:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-15 10:18 - 2014-07-25 06:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-15 10:18 - 2014-07-25 06:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-15 10:18 - 2014-06-15 22:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-15 10:18 - 2014-06-03 06:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-15 10:18 - 2014-06-03 06:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-15 10:18 - 2014-06-03 06:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-15 10:18 - 2014-06-03 06:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-15 10:18 - 2014-06-03 05:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-15 10:18 - 2014-06-03 05:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-15 10:18 - 2014-06-03 05:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-15 10:16 - 2014-07-13 22:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-15 10:16 - 2014-07-13 21:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-01 16:37 - 2014-05-14 12:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-01 16:37 - 2014-05-14 12:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-01 16:37 - 2014-05-14 12:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-01 16:37 - 2014-05-14 12:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-01 16:37 - 2014-05-14 12:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-08-01 16:37 - 2014-05-14 12:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-01 16:37 - 2014-05-14 12:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-08-01 16:37 - 2014-05-14 12:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-01 16:37 - 2014-05-14 12:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-01 16:37 - 2014-05-14 12:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-01 16:37 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-01 16:37 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-01 16:37 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-01 16:37 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-30 17:10 - 2014-08-30 17:09 - 00031277 _____ () C:\Users\LANCE\Downloads\FRST.txt
2014-08-30 17:09 - 2014-08-30 17:09 - 02103808 _____ (Farbar) C:\Users\LANCE\Downloads\FRST64.exe
2014-08-30 17:09 - 2014-08-30 17:09 - 00000000 ____D () C:\FRST
2014-08-30 17:09 - 2013-09-05 21:41 - 00000000 ____D () C:\Users\LANCE\AppData\Roaming\Skype
2014-08-30 17:05 - 2010-01-23 13:44 - 01410716 _____ () C:\Windows\WindowsUpdate.log
2014-08-30 17:05 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-08-30 17:04 - 2014-05-22 21:27 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-30 17:04 - 2013-09-05 21:58 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-30 10:25 - 2014-08-30 10:25 - 00071084 _____ () C:\Users\LANCE\Downloads\Extras.Txt
2014-08-30 10:23 - 2014-08-30 10:23 - 00137872 _____ () C:\Users\LANCE\Downloads\OTL.Txt
2014-08-30 10:14 - 2014-08-30 10:14 - 00602112 _____ (OldTimer Tools) C:\Users\LANCE\Downloads\OTL.exe
2014-08-30 10:10 - 2009-07-14 00:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-30 10:10 - 2009-07-14 00:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-30 09:31 - 2014-08-30 09:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-08-30 09:31 - 2014-08-30 09:30 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-08-30 09:31 - 2014-08-30 09:30 - 00000000 ____D () C:\Program Files\iTunes
2014-08-30 09:31 - 2014-08-30 09:30 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-08-30 09:30 - 2014-08-30 09:30 - 00000000 ____D () C:\Program Files\iPod
2014-08-30 09:28 - 2013-09-05 20:55 - 00000000 ____D () C:\Users\LANCE\AppData\Local\Thunderbird
2014-08-30 09:25 - 2014-08-30 09:24 - 00000000 ____D () C:\Program Files (x86)\LPT
2014-08-30 09:24 - 2014-08-30 09:24 - 00002654 _____ () C:\Users\LANCE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-08-30 09:24 - 2014-08-30 09:24 - 00002607 _____ () C:\Users\LANCE\Desktop\Search.lnk
2014-08-30 09:23 - 2014-08-30 09:23 - 00000873 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-08-30 09:23 - 2014-08-30 09:23 - 00000000 ____D () C:\Users\LANCE\AppData\Roaming\0F1L1I1P0H1L1E1E1F
2014-08-30 09:23 - 2014-08-30 09:23 - 00000000 ____D () C:\Users\LANCE\AppData\Local\Smartbar
2014-08-30 09:23 - 2014-08-30 09:23 - 00000000 ____D () C:\Users\LANCE\AppData\Local\LPT
2014-08-30 09:22 - 2014-08-30 09:22 - 25611537 _____ () C:\Users\LANCE\Downloads\vlc-2.1.5-win64.exe
2014-08-30 09:21 - 2014-01-16 21:00 - 00000000 ____D () C:\Program Files\Java
2014-08-30 09:20 - 2014-08-30 09:20 - 00002088 _____ () C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2014-08-30 09:20 - 2014-06-11 17:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-08-30 09:20 - 2013-09-05 20:54 - 00002100 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
2014-08-30 09:20 - 2013-09-05 20:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-08-30 09:19 - 2014-01-16 21:00 - 00319912 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-08-30 09:19 - 2014-01-16 21:00 - 00191400 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-08-30 09:19 - 2014-01-16 21:00 - 00190888 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-08-30 09:19 - 2014-01-16 21:00 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-08-30 09:19 - 2013-11-03 14:41 - 00000000 ____D () C:\ProgramData\Oracle
2014-08-30 09:17 - 2014-08-30 09:10 - 113492816 _____ (Apple Inc.) C:\Users\LANCE\Downloads\iTunes64Setup.exe
2014-08-30 09:16 - 2014-08-30 09:10 - 96138664 _____ (Oracle Corporation) C:\Users\LANCE\Downloads\jre-8u20-windows-x64.exe
2014-08-30 09:15 - 2014-08-30 09:15 - 00001726 _____ () C:\Users\Public\Desktop\Defraggler.lnk
2014-08-30 09:15 - 2013-09-05 21:30 - 00000000 ____D () C:\Program Files\Defraggler
2014-08-30 09:13 - 2014-08-30 09:13 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-08-30 09:13 - 2013-09-05 21:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-08-30 09:13 - 2013-09-05 21:31 - 00000000 ____D () C:\Program Files\CCleaner
2014-08-30 09:12 - 2014-08-30 09:10 - 26472832 _____ (Mozilla) C:\Users\LANCE\Downloads\Thunderbird Setup 31.0.exe
2014-08-30 09:11 - 2014-08-30 09:10 - 04901352 _____ (Piriform Ltd) C:\Users\LANCE\Downloads\ccsetup417.exe
2014-08-30 09:11 - 2014-08-30 09:10 - 04362512 _____ (Piriform Ltd) C:\Users\LANCE\Downloads\dfsetup218.exe
2014-08-30 09:10 - 2014-08-30 09:10 - 00768024 _____ ( ) C:\Users\LANCE\Downloads\vlc-2.1.5-win64_inst.exe
2014-08-30 09:10 - 2014-08-30 09:09 - 18743160 _____ (Adobe Systems Inc.) C:\Users\LANCE\Downloads\AdobeAIRInstaller.exe
2014-08-30 08:09 - 2014-01-19 14:09 - 00000000 ___RD () C:\Users\LANCE\Dropbox
2014-08-30 08:09 - 2014-01-19 14:08 - 00000000 ____D () C:\Users\LANCE\AppData\Roaming\Dropbox
2014-08-30 08:07 - 2014-08-15 12:36 - 00003170 _____ () C:\Windows\System32\Tasks\P4GIntlCtrl
2014-08-30 08:07 - 2014-05-22 21:27 - 00000892 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-30 08:07 - 2013-11-10 02:00 - 00014726 _____ () C:\Windows\setupact.log
2014-08-30 08:07 - 2010-01-23 14:50 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-08-30 08:07 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-30 08:07 - 2009-07-14 00:45 - 00479072 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-30 08:05 - 2013-09-14 21:15 - 00000000 ____D () C:\Users\LANCE\AppData\Roaming\tixati
2014-08-27 19:45 - 2013-09-05 21:57 - 00000000 ____D () C:\Users\LANCE\AppData\Local\Adobe
2014-08-27 19:18 - 2013-09-05 21:58 - 00699568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-27 19:18 - 2013-09-05 21:58 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-27 19:18 - 2013-09-05 21:58 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-08-26 11:42 - 2013-09-11 18:14 - 00000099 _____ () C:\Users\Public\LMDebug.log
2014-08-22 22:07 - 2014-08-29 17:01 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-22 21:45 - 2014-08-29 17:01 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-22 20:59 - 2014-08-29 17:01 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 11:46 - 2014-08-22 10:20 - 00107567 _____ () C:\Users\LANCE\Desktop\Sinai Grand Rounds.pptx
2014-08-19 21:34 - 2014-08-19 21:34 - 00000962 _____ () C:\Users\Public\Desktop\calibre - E-book management.lnk
2014-08-19 21:34 - 2013-09-05 21:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre - E-book Management
2014-08-19 21:34 - 2013-09-05 21:53 - 00000000 ____D () C:\Program Files (x86)\Calibre2
2014-08-19 21:24 - 2009-07-14 01:13 - 00781298 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-19 21:16 - 2014-08-19 21:15 - 56419840 _____ () C:\Users\LANCE\Downloads\calibre-1.48.0.msi
2014-08-19 21:16 - 2014-08-19 21:11 - 00000000 ____D () C:\Users\LANCE\Downloads\Book Requests
2014-08-19 21:15 - 2013-09-05 21:53 - 00000000 ____D () C:\Users\LANCE\AppData\Roaming\calibre
2014-08-17 13:29 - 2013-09-16 07:33 - 00000000 ____D () C:\Users\LANCE\AppData\Roaming\vlc
2014-08-17 13:05 - 2014-08-17 11:48 - 00000000 ____D () C:\Users\LANCE\Desktop\Grand Rounds
2014-08-15 21:43 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\rescache
2014-08-15 12:37 - 2014-01-19 14:09 - 00000000 ____D () C:\Users\LANCE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-08-15 12:36 - 2013-09-05 21:36 - 00000000 ____D () C:\ProgramData\Skype
2014-08-15 12:32 - 2013-11-12 07:53 - 00140598 _____ () C:\Windows\PFRO.log
2014-08-15 12:30 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-08-15 12:30 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-08-15 12:30 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-15 10:48 - 2010-01-23 13:55 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-15 10:38 - 2013-09-05 21:54 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-15 10:35 - 2013-09-05 21:54 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-31 19:41 - 2014-08-15 10:18 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-31 19:16 - 2014-08-15 10:18 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll

Some content of TEMP:
====================
C:\Users\LANCE\AppData\Local\Temp\bitool.dll
C:\Users\LANCE\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpk6tqvy.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-08-27 18:58

==================== End Of Log ============================

 

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-08-2014
Ran by LANCE at 2014-08-30 17:10:35
Running from C:\Users\LANCE\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 13.0.0.111 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 13.0.0.111 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.0.32.18 - Adobe Systems Incorporated)
Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.179 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}) (Version: 7.1.2.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ASUS AI Recovery (HKLM-x32\...\{06585B02-F20D-4AB2-9A64-86EF2AE0F8F0}) (Version: 1.0.7 - ASUS)
ASUS AP Bank (HKLM-x32\...\ASUS AP Bank_is1) (Version: 1.0.0.0 - ASUSTEK)
ASUS FancyStart (HKLM-x32\...\{60D6618B-153F-4353-8185-908E676E5888}) (Version: 1.0.5 - ASUSTeK Computer Inc.)
ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.20 - ASUS)
ASUS Live Update (HKLM-x32\...\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}) (Version: 2.5.9 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{91EFE3A1-585E-4F66-B5F6-F118F56C4C47}) (Version: 1.1.22 - ASUS)
ASUS SmartLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0007 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0028 - ASUS)
ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.17 - asus)
ASUS WebStorage (HKLM\...\ASUS WebStorage) (Version: 2.0.36.1260 - eCareme Technologies, Inc.)
ASUS_ScreenSaver_GSeries (HKLM-x32\...\ASUS_ScreenSaver_GSeries) (Version:  - )
Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 7.0 - Atheros)
Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.7 - Atheros Communications Inc.)
ATK Generic Function Service (HKLM-x32\...\{D3D54F3E-C5C3-443D-978F-87A72E5616E8}) (Version: 1.00.0008 - ATK)
ATK Hotkey (HKLM-x32\...\{7C05592D-424B-46CB-B505-E0013E8E75C9}) (Version: 1.0.0054 - ASUS)
ATK Media (HKLM-x32\...\{D1E5870E-E3E5-4475-98A6-ADD614524ADF}) (Version: 2.0.0006 - ASUS)
ATKOSD2 (HKLM-x32\...\{3B05F2FB-745B-4012-ADF2-439F36B2E70B}) (Version: 7.0.0007 - ASUS)
Audacity 2.0.4 (HKLM-x32\...\Audacity_is1) (Version: 2.0.4 - Audacity Team)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
calibre (HKLM-x32\...\{DD649DA2-BBD9-4247-85DD-E04F7C1E8552}) (Version: 1.48.0 - Kovid Goyal)
CCleaner (HKLM\...\CCleaner) (Version: 4.17 - Piriform)
Choice Guard (x32 Version: 1.2.87.0 - Microsoft Corporation) Hidden
Citrix Authentication Manager (x32 Version: 5.1.0.62606 - Citrix Systems, Inc.) Hidden
Citrix Receiver (HDX Flash Redirection) (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
Citrix Receiver (HKLM-x32\...\CitrixOnlinePluginPackWeb) (Version: 14.1.0.0 - Citrix Systems, Inc.)
Citrix Receiver Inside (x32 Version: 4.1.0.56471 - Citrix Systems, Inc.) Hidden
Citrix Receiver Updater (x32 Version: 4.1.0.56461 - Citrix Systems, Inc.) Hidden
Citrix Receiver(Aero) (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
Citrix Receiver(DV) (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
Citrix Receiver(USB) (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
Common Desktop Agent (Version: 1.62.0 - OEM) Hidden
ControlDeck (HKLM-x32\...\{5B65EF64-1DFA-414A-8C94-7BB726158E21}) (Version: 1.0.4 - ASUS)
Creative MediaSource 5 (HKLM-x32\...\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}) (Version: 5.00 - Creative Technology Limited)
CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1908 - CyberLink Corp.)
CyberLink LabelPrint (x32 Version: 2.5.1908 - CyberLink Corp.) Hidden
CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3509a - CyberLink Corp.)
CyberLink Power2Go (x32 Version: 6.1.3509a - CyberLink Corp.) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Defraggler (HKLM\...\Defraggler) (Version: 2.18 - Piriform)
Diablo III (HKLM-x32\...\Diablo III) (Version:  - Blizzard Entertainment)
Dropbox (HKCU\...\Dropbox) (Version: 2.10.27 - Dropbox, Inc.)
Express Gate (HKLM-x32\...\{B5A5627C-0173-4DB2-ADA8-740479370F67}) (Version: 1.2.13.34 - DeviceVM, Inc.)
Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.4 - ASUS)
Fences (Version: 1.0 - Stardock Corporation) Hidden
FileHippo.com Update Checker (HKLM-x32\...\FileHippo.com) (Version:  - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.102 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
HP Officejet Pro 8600 Basic Device Software (HKLM\...\{791A06E2-340F-43B0-8FAB-62D151339362}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation)
iTunes (HKLM\...\{77DE5105-D05E-448C-96CB-7FA381903753}) (Version: 11.3.1.2 - Apple Inc.)
Java 8 Update 20 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418020F0}) (Version: 8.0.200 - Oracle Corporation)
Java Auto Updater (x32 Version: 2.8.20.26 - Oracle Corporation) Hidden
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
League of Legends (HKLM-x32\...\{92606477-9366-4D3B-8AE3-6BE4B29727AB}) (Version: 1.3 - Riot Games)
LPT System Updater Service (HKLM-x32\...\{BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24}) (Version: 1.0.0.0 - LPT) <==== ATTENTION
Malwarebytes Anti-Malware version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Access MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Groove MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Publisher MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
MozBackup 1.5.1 (HKLM-x32\...\MozBackup) (Version:  - Pavel Cvrcek)
Mozilla Firefox 31.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 en-US)) (Version: 31.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla)
Mozilla Thunderbird 31.0 (x86 en-US) (HKLM-x32\...\Mozilla Thunderbird 31.0 (x86 en-US)) (Version: 31.0 - Mozilla)
NVIDIA 3D Vision Driver 327.02 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 327.02 - NVIDIA Corporation)
NVIDIA Control Panel 327.02 (Version: 327.02 - NVIDIA Corporation) Hidden
NVIDIA Graphics Driver 327.02 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 327.02 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.26.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.26.4 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.141.953 - NVIDIA Corporation) Hidden
NVIDIA PhysX (HKLM-x32\...\{B83FC356-B7C0-441F-8A4D-D71E088E7974}) (Version: 9.09.0428 - NVIDIA Corporation)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.2702 - NVIDIA Corporation) Hidden
NVIDIA Update 1.14.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.14.17 - NVIDIA Corporation)
NVIDIA Update Components (Version: 1.14.17 - NVIDIA Corporation) Hidden
Online Plug-in (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5983 - Realtek Semiconductor Corp.)
RICOH R5U230 Media Driver ver.2.05.02.02 (HKLM-x32\...\{022CBB38-CEF0-42BA-906A-A49BEFAE0BEE}) (Version: 2.05.02.02 - RICOH)
SafeFinder Smartbar (HKLM-x32\...\{1898B668-CCF5-429F-A86F-9837E5439D77}) (Version: 11.114.72.19232 - Linkury Ltd.) <==== ATTENTION
Samsung Easy Document Creator (HKLM-x32\...\Samsung Easy Document Creator) (Version: 1.04.06 (07/08/2012) - Samsung Electronics Co., Ltd.)
Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 1.02.63.01(09/08/2012) - Samsung Electronics Co., Ltd.)
Samsung OCR Software (HKLM-x32\...\Samsung OCR Software) (Version: 1.01.05 (29/11/2013) - Samsung Electronics Co., Ltd.)
Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.)
Samsung Scan Process Machine (x32 Version: 1.00.20.02 - Samsung Electronics Co., Ltd.) Hidden
Samsung SCX-3400 Series (HKLM-x32\...\Samsung SCX-3400 Series) (Version: 1.20 (04/12/2013) - Samsung Electronics Co., Ltd.)
Samsung Universal Scan Driver (HKLM-x32\...\Samsung Universal Scan Driver) (Version: 1.2.6.0 - Samsung Electronics Co., Ltd.)
Self-service Plug-in (x32 Version: 4.1.0.41738 - Citrix Systems, Inc.) Hidden
Skype™ 6.18 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.18.106 - Skype Technologies S.A.)
SNS Upload for Easy Document Creator (HKLM-x32\...\{B6B5F07C-88D5-49D3-A1A7-A6D4BC37DCCC}) (Version: 1.0.0 - Samsung Electronics Co.,Ltd)
Sound Blaster Audigy HD (HKLM-x32\...\{38F8D823-008D-4E5A-BBCE-867A86C2BF2B}) (Version: 1.0 - Creative Technology Limited)
SpywareBlaster 5.0 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.1.1 - Synaptics Incorporated)
Tixati (HKLM-x32\...\tixati) (Version:  - )
Trine 2 - Complete Story (HKLM-x32\...\Trine 2 - Complete Story_is1) (Version:  - )
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for Microsoft Office 2007 Help for Common Features (KB963673) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{AB365889-0395-4FAD-B702-CA5985D53D42}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office Access 2007 Help (KB963663) (HKLM-x32\...\{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{6B76A18A-AA1E-42AB-A7AD-6C84BBB43987}) (Version:  - Microsoft)
Update for Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{199DF7B6-169C-448C-B511-1054101BE9C9}) (Version:  - Microsoft)
Update for Microsoft Office Infopath 2007 Help (KB963662) (HKLM-x32\...\{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{716B81B8-B13C-41DF-8EAC-7A2F656CAB63}) (Version:  - Microsoft)
Update for Microsoft Office OneNote 2007 Help (KB963670) (HKLM-x32\...\{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2744EF05-38E1-4D5D-B333-E021EDAEA245}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{ED38F8A3-4F61-494E-8BCA-E3AC7760C924}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{0451F231-E3E3-4943-AB9F-58EB96171784}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2883097) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{B2260BC9-D561-46EE-B33D-739CF760A2A9}) (Version:  - Microsoft)
Update for Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{397B1D4F-ED7B-4ACA-A637-43B670843876}) (Version:  - Microsoft)
Update for Microsoft Office Publisher 2007 Help (KB963667) (HKLM-x32\...\{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2E40DE55-B289-4C8B-8901-5D369B16814F}) (Version:  - Microsoft)
Update for Microsoft Office Script Editor Help (KB963671) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{CD11C6A2-FFC6-4271-8EAB-79C3582F505C}) (Version:  - Microsoft)
Update for Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{80E762AA-C921-4839-9D7D-DB62A72C0726}) (Version:  - Microsoft)
View User's Guide (HKLM-x32\...\View User Guide) (Version: 3.60.02.0 - )
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
VLC Media Player 64-bit Packages (HKCU\...\VLC Media Player 64-bit Packages) (Version:  - ) <==== ATTENTION
WIDCOMM Bluetooth Software (HKLM\...\{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}) (Version: 6.2.0.9600 - Broadcom Corporation)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.29.0 - ASUS)
WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
Wireless Console 3 (HKLM-x32\...\{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}) (Version: 3.0.14 - ASUS)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-2552895503-36244919-2108235947-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\LANCE\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2552895503-36244919-2108235947-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\LANCE\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2552895503-36244919-2108235947-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\LANCE\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2552895503-36244919-2108235947-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\LANCE\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2552895503-36244919-2108235947-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\LANCE\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2552895503-36244919-2108235947-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\LANCE\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2552895503-36244919-2108235947-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\LANCE\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2552895503-36244919-2108235947-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\LANCE\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2552895503-36244919-2108235947-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\LANCE\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

==================== Restore Points  =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 22:34 - 2009-06-10 17:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {06CAE7A2-D8F3-4C12-BFC7-82C671D8F0B3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-08-27] (Adobe Systems Incorporated)
Task: {1B8AD5B6-A2C4-4DE7-9BC8-E7C5637D75DA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-22] (Google Inc.)
Task: {391898B6-D8B2-44B9-8605-9C363E1867C7} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2009-07-23] (ATK)
Task: {3B4E56B3-2C2B-41B3-B2BF-03B39D46F967} - System32\Tasks\WC3 => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2009-11-12] ()
Task: {4813C419-40A2-4428-AE86-CDAE408C79B6} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe [2007-11-30] ()
Task: {50D96765-A0B2-41AC-80A8-734FFC1A11A2} - System32\Tasks\P4GIntlCtrl => C:\Program Files\P4G\IntlCtrl.exe [2009-08-11] (TODO: <Company name>)
Task: {54E450ED-B9DE-4F44-9DC3-3B4BFB350060} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-08-21] (Piriform Ltd)
Task: {6DDAE9D3-EC60-4422-9E2B-03C88114029D} - System32\Tasks\ASUSControlDeck => C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe [2009-09-24] ()
Task: {9B4A864F-9400-4D5F-9A02-DACC5C5D49B4} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2009-08-29] (ATK)
Task: {C07C4CF0-71B1-41C1-81D9-BBA64BD61F32} - System32\Tasks\{01895298-B62E-4A13-AD02-AAA838791B4F} => Firefox.exe http://ui.skype.com/...;LastError=1618
Task: {E54F1FD4-5EF4-4725-99F9-8FAA3E729870} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-22] (Google Inc.)
Task: {EDE6AD79-0CF1-4CBD-B61D-BBEC2FD4B574} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2009-05-18] (ASUS)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2010-01-23 14:40 - 2007-08-08 04:08 - 00094208 _____ () C:\Program Files\ATKGFNEX\GFNEXSrv.exe
2013-06-28 10:12 - 2013-06-28 10:12 - 00034304 _____ () C:\Windows\System32\ssm1mlm.dll
2009-11-27 01:29 - 2009-11-27 01:29 - 00148752 _____ () C:\Program Files (x86)\ASUS\ASUS WebStorage\EcaremeDLL.dll
2010-01-23 14:20 - 2010-01-23 14:20 - 00029968 _____ () C:\Windows\assembly\GAC_MSIL\SqliteShared\1.0.3617.20553__0d0f4b69e50e559b\SqliteShared.dll
2010-01-23 14:20 - 2010-01-23 14:20 - 00931840 _____ () C:\Windows\assembly\GAC_64\System.Data.SQLite\1.0.60.0__db937bc2d44ff139\System.Data.SQLite.dll
2009-07-01 22:54 - 2009-07-01 22:54 - 00173344 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll
2013-12-15 11:12 - 2013-08-29 18:43 - 00097568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2008-10-01 03:02 - 2008-10-01 03:08 - 00011264 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2010-01-23 14:41 - 2007-11-30 15:20 - 00051768 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
2009-09-24 17:50 - 2009-09-24 17:50 - 00053888 _____ () C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
2009-08-28 19:00 - 2009-08-28 19:00 - 00041984 _____ () C:\Program Files\P4G\DevMng.dll
2009-08-19 15:57 - 2009-08-19 15:57 - 00029184 _____ () C:\Program Files\P4G\OvrClk.dll
2010-01-23 14:40 - 2007-03-09 22:58 - 00124416 _____ () C:\Program Files\ATKGFNEX\AGFNEX64.dll
2009-11-12 14:10 - 2009-11-12 14:10 - 01597440 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
2009-11-26 09:52 - 2009-11-26 09:52 - 01732608 _____ () C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe
2012-02-20 22:23 - 2012-02-20 22:23 - 00456704 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
2012-02-20 22:23 - 2012-02-20 22:23 - 00051200 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrvPS.dll
2013-06-28 10:12 - 2014-05-14 11:02 - 01252864 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\ssm1mdu.dll
2011-01-27 15:28 - 2011-01-27 15:28 - 00706048 _____ () C:\Windows\system32\SnMinDrv.dll
2014-08-27 18:43 - 2014-08-27 18:43 - 00032768 _____ () C:\Program Files (x86)\LPT\srpts.exe
2014-08-27 18:43 - 2014-08-27 18:52 - 00034816 _____ () C:\Program Files (x86)\LPT\srptsl.exe
2014-08-27 18:52 - 2014-08-27 18:52 - 00023040 _____ () C:\Users\LANCE\AppData\Local\LPT\srptm.exe
2014-08-27 18:50 - 2014-08-27 18:50 - 00023552 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\Lrcnta.exe
2013-09-14 02:51 - 2013-09-14 02:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\zlib1.dll
2013-09-14 02:50 - 2013-09-14 02:50 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\libxml2.dll
2009-06-02 22:09 - 2009-06-02 22:09 - 00225280 _____ () C:\Program Files (x86)\asus\VirtualCamera\virtualCamera.ax
2010-01-23 14:38 - 2009-02-06 22:52 - 00073728 _____ () C:\Windows\SysWOW64\CmdRtr.DLL
2010-01-23 14:38 - 2009-03-26 18:46 - 00148480 _____ () C:\Windows\SysWOW64\APOMngr.DLL
2014-08-30 08:08 - 2014-08-30 08:08 - 00043008 _____ () c:\users\lance\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpk6tqvy.dll
2013-08-23 15:01 - 2013-08-23 15:01 - 25100288 _____ () C:\Users\LANCE\AppData\Roaming\Dropbox\bin\libcef.dll
2012-08-07 09:01 - 2012-08-07 09:01 - 00536576 _____ () C:\Program Files (x86)\Samsung\Easy Document Creator\EDCAddin.dll
2012-08-07 09:01 - 2012-08-07 09:01 - 00614912 _____ () C:\Program Files (x86)\Samsung\Easy Document Creator\EDCOffice.dll
2013-07-10 18:07 - 2013-07-10 18:07 - 00756888 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL
2009-11-02 18:20 - 2009-11-02 18:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2009-11-02 18:23 - 2009-11-02 18:23 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2014-06-11 17:25 - 2014-07-17 21:39 - 03338352 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
2014-06-11 17:25 - 2014-07-17 21:39 - 00158832 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2014-06-11 17:25 - 2014-07-17 21:39 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00050176 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll
2014-08-27 18:52 - 2014-08-27 18:52 - 00086016 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\srau.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00165888 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 02425344 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00066560 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\spbl.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00158208 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00014336 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\siem.dll
2014-08-27 18:52 - 2014-08-27 18:52 - 00067584 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\sppsm.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00696832 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00014848 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00078848 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00027136 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll
2014-08-27 18:52 - 2014-08-27 18:52 - 00070144 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\srut.dll
2014-08-27 18:52 - 2014-08-27 18:52 - 00029184 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\srsbs.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00065536 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00150016 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\smti.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00073728 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\smsp.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00011776 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\sidc.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00030720 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\smtu.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00038912 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\smta.dll
2014-08-27 18:52 - 2014-08-27 18:52 - 00030720 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\srom.dll
2014-08-27 18:52 - 2014-08-27 18:52 - 00047104 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\srbu.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00024064 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\sgml.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00061952 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll
2014-08-27 18:52 - 2014-08-27 18:52 - 00025088 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\srpdm.dll
2014-08-27 18:50 - 2014-08-27 18:50 - 00043520 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\MACTrackBarLib.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00035328 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00193024 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\sgmu.dll
2014-05-12 11:21 - 2014-05-12 11:21 - 00061440 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\AxInterop.WMPLib.dll
2014-08-27 18:52 - 2014-08-27 18:52 - 00254976 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\srns.dll
2014-08-27 18:43 - 2014-08-27 18:52 - 00042496 _____ () C:\Program Files (x86)\LPT\srptc.dll
2014-08-27 18:42 - 2014-08-27 18:50 - 00018944 _____ () C:\Program Files (x86)\LPT\Smartbar.Common.dll
2014-08-27 18:43 - 2014-08-27 18:52 - 00070144 _____ () C:\Program Files (x86)\LPT\srut.dll
2014-08-27 18:52 - 2014-08-27 18:52 - 00081920 _____ () C:\Users\LANCE\AppData\Local\LPT\srpt.dll
2014-08-27 18:52 - 2014-08-27 18:52 - 00042496 _____ () C:\Users\LANCE\AppData\Local\LPT\srptc.dll
2014-08-27 18:50 - 2014-08-27 18:50 - 00018944 _____ () C:\Users\LANCE\AppData\Local\LPT\Smartbar.Common.dll
2014-08-27 18:52 - 2014-08-27 18:52 - 00070144 _____ () C:\Users\LANCE\AppData\Local\LPT\srut.dll
2014-08-27 18:52 - 2014-08-27 18:52 - 00067584 _____ () C:\Users\LANCE\AppData\Local\LPT\sppsm.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00158208 _____ () C:\Users\LANCE\AppData\Local\LPT\Smartbar.Resources.HistoryAndStatsWrapper.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00027136 _____ () C:\Users\LANCE\AppData\Local\LPT\Smartbar.Personalization.Common.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00165888 _____ () C:\Users\LANCE\AppData\Local\LPT\Smartbar.Infrastructure.Utilities.dll
2014-08-27 18:52 - 2014-08-27 18:52 - 00047104 _____ () C:\Users\LANCE\AppData\Local\LPT\srbu.dll
2014-08-27 18:52 - 2014-08-27 18:52 - 00025088 _____ () C:\Users\LANCE\AppData\Local\LPT\srpdm.dll
2014-08-27 18:50 - 2014-08-27 18:50 - 00026112 _____ () C:\Users\LANCE\AppData\Local\LPT\ProxySettings.dll
2014-08-27 18:51 - 2014-08-27 18:51 - 00044032 _____ () C:\Users\LANCE\AppData\Local\LPT\Smartbar.Monetization.Proxy.ProxyService.dll
2014-08-27 18:52 - 2014-08-27 18:52 - 00027648 _____ () C:\Users\LANCE\AppData\Local\LPT\sreu.dll
2014-08-26 14:13 - 2014-08-26 14:13 - 00059392 _____ () C:\Users\LANCE\AppData\Local\LPT\Community.CsharpSqlite.SQLiteClient.dll
2014-02-06 01:52 - 2014-02-06 01:52 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-06 01:52 - 2014-02-06 01:52 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-07-30 20:04 - 2014-07-30 20:04 - 03800688 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-08-30 09:24 - 2014-08-27 18:47 - 00099840 _____ () C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\extensions\{f33c613b-851e-a627-440b-ac974e123ffc}\components\SmartbarFireFoxRemotePlugin_31.dll
2014-08-27 19:18 - 2014-08-27 19:18 - 17048240 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll
2014-08-27 18:50 - 2014-08-27 18:50 - 00032768 _____ () C:\Users\LANCE\AppData\Local\Smartbar\Application\lrcnt.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:5C321E34

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: ADSMTray => C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s

==================== Faulty Device Manager Devices =============

Name: BT-253 module
Description: BT-253 module
Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Manufacturer: Broadcom
Service: BTHUSB
Problem: : Windows has stopped this device because it has reported problems. (Code 43)
Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation.


==================== Event log errors: =========================

Application errors:
==================
Error: (08/30/2014 05:04:02 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 16748376

Error: (08/30/2014 05:04:02 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 16748376

Error: (08/30/2014 05:04:02 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (08/30/2014 05:04:01 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 16747331

Error: (08/30/2014 05:04:01 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 16747331

Error: (08/30/2014 05:04:01 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (08/30/2014 05:04:00 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 16746317

Error: (08/30/2014 05:04:00 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 16746317

Error: (08/30/2014 05:04:00 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (08/30/2014 05:03:59 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 16745319


System errors:
=============
Error: (08/30/2014 08:07:46 AM) (Source: BTHUSB) (EventID: 17) (User: )
Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.

Error: (08/30/2014 08:06:36 AM) (Source: BTHUSB) (EventID: 17) (User: )
Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.

Error: (08/17/2014 09:58:30 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 1.179.3103.0

    Update Source: %NT AUTHORITY59

    Update Stage: 4.5.0216.00

    Source Path: 4.5.0216.01

    Signature Type: %NT AUTHORITY602

    Update Type: %NT AUTHORITY604

    User: NT AUTHORITY\SYSTEM

    Current Engine Version: %NT AUTHORITY605

    Previous Engine Version: %NT AUTHORITY606

    Error code: %NT AUTHORITY607

    Error description: %NT AUTHORITY608

Error: (08/17/2014 09:58:30 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 1.179.3103.0

    Update Source: %NT AUTHORITY59

    Update Stage: 4.5.0216.00

    Source Path: 4.5.0216.01

    Signature Type: %NT AUTHORITY602

    Update Type: %NT AUTHORITY604

    User: NT AUTHORITY\SYSTEM

    Current Engine Version: %NT AUTHORITY605

    Previous Engine Version: %NT AUTHORITY606

    Error code: %NT AUTHORITY607

    Error description: %NT AUTHORITY608

Error: (08/15/2014 00:33:35 PM) (Source: BTHUSB) (EventID: 17) (User: )
Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.

Error: (08/15/2014 00:32:21 PM) (Source: BTHUSB) (EventID: 17) (User: )
Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.

Error: (08/06/2014 04:30:19 PM) (Source: BTHUSB) (EventID: 17) (User: )
Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.

Error: (08/06/2014 04:30:04 PM) (Source: BTHUSB) (EventID: 17) (User: )
Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.

Error: (08/04/2014 08:25:22 AM) (Source: BTHUSB) (EventID: 17) (User: )
Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.

Error: (08/04/2014 08:24:53 AM) (Source: BTHUSB) (EventID: 17) (User: )
Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.


Microsoft Office Sessions:
=========================

==================== Memory info ===========================

Processor: Intel® Core™ i7 CPU Q 720 @ 1.60GHz
Percentage of memory in use: 46%
Total physical RAM: 6077.17 MB
Available physical RAM: 3223.96 MB
Total Pagefile: 12152.52 MB
Available Pagefile: 8923.51 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:116.44 GB) (Free:28.8 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:329.79 GB) (Free:201.03 GB) NTFS
Drive f: (TRINE 2 COMPLETE) (CDROM) (Total:2.98 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 76692CA8)
Partition 1: (Not Active) - (Size=19.5 GB) - (Type=1C)
Partition 2: (Active) - (Size=116.4 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=329.8 GB) - (Type=OF Extended)

==================== End Of Log ============================


  • 0

#4
dbreeze

dbreeze

    Trusted Helper

  • Malware Removal
  • 2,216 posts
Hi LANCE1313,

I've gone over the logs you posted and we have a lot of work to do. Let's get to it, shall we?

First >>>>

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.


Second>>>>


:upset: :upset: :upset: ALERT!!! P2P WARNING ALERT!!! :upset: :upset: :upset:



You have a P2P / file sharing application on your system!! While this may not be a surprize to you (most likely installed by you or another user on the system) and the file sharing application itself may be safe, the files shared could be a little more than you hoped for. File sharing has been shown to be a major source for trojans, virii, worms and webbot attacks to spread on the internet. There are exploits in file sharing software that can be used to compromise your system and personal information. You may be sharing a lot more than just a little bandwidth to 'help the community share' information.

Geeks to Go recommends that you uninstall your P2P software; you have to have open pathways (network ports) in and out of your system and you could be helping to move illegal files (copyrighted material (software, movies, video, etc.) even if you don't 'download' them yourself.

If you choose to keep your P2P program installed, I must ask that you de-activate / shutdown the software and not use it until the cleaning of your system is done.

Application to uninstall: Tixati

Need more info? Read these:Third>>>>


Please go to START (Windows Orb) >> Control Panel >> Uninstall a Program or Programs and Features and remove the following (if listed):

LPT System Updater Service
SafeFinder Smartbar
VLC Media Player 64-bit Packages
Tixati (Optional P2P)


To do so, left clicking on the name once and then click Uninstall/Change at the bar above the list window.

Follow the prompts of the uninstaller BUT please read carefully any questions it asks before answering; some uninstallers will try and deceive you into keeping the software.


Fourth>>>>


If FRST64 is still open from the last step, you can leave it open to run the Fixlist below.

Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy. Paste this into the open notepad. Save it to your desktop as fixlist.txt


start
(Smartbar) C:\Users\LANCE\AppData\Local\Smartbar\Application\SafeFinder.exe
() C:\Program Files (x86)\LPT\srpts.exe
() C:\Program Files (x86)\LPT\srptsl.exe
() C:\Users\LANCE\AppData\Local\LPT\srptm.exe
() C:\Users\LANCE\AppData\Local\Smartbar\Application\Lrcnta.exe
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\Run: [Browser Infrastructure Helper] => C:\Users\LANCE\AppData\Local\Smartbar\Application\SafeFinder.exe [28160 2014-08-27] (Smartbar)
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\MountPoints2: {8b8dda66-64f1-11e3-857a-e0cb4e302f58} - F:\setup.exe
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\MountPoints2: {9fc835fc-6ca6-11e3-8716-e0cb4e302f58} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\start.exe
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\MountPoints2: {b12ff93c-ab0e-11e3-abef-e0cb4e302f58} - F:\setup.exe
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\MountPoints2: {e9162f72-44b1-11e3-a90a-e0cb4e302f58} - "G:\WD SmartWare.exe" autoplay=true
AppInit_DLLs: C:\Users\LANCE\AppData\Local\Smartbar\Application\Resources\crdlil64.dll => C:\Users\LANCE\AppData\Local\Smartbar\Application\Resources\crdlil64.dll [77856 2014-08-30] ()
AppInit_DLLs-x32: C:\Users\LANCE\AppData\Local\Smartbar\Application\Resources\crdlil.dll => C:\Users\LANCE\AppData\Local\Smartbar\Application\Resources\crdlil.dll [67104 2014-08-30] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk
ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{60D6618B-153F-4353-8185-908E676E5888}\_DCE9A4DB2A5F2786140FA3.exe ()
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://feed.safefind...Qp4CtkJPsHJj1Eg,
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.safefind...q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.safefind...q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.safefind...q={searchTerms}
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.safefind...q={searchTerms}
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.safefind...q={searchTerms}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.safefind...q={searchTerms}
BHO: SafeFinder SmartbarEngine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO-x32: SafeFinder SmartbarEngine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM - SafeFinder Smartbar - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\system32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - SafeFinder Smartbar - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
2014-08-30 09:23 - 2014-08-30 09:23 - 00000873 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-08-30 09:23 - 2014-08-30 09:23 - 00000000 ____D () C:\Users\LANCE\AppData\Roaming\0F1L1I1P0H1L1E1E1F
2014-08-30 09:22 - 2014-08-30 09:22 - 25611537 _____ () C:\Users\LANCE\Downloads\vlc-2.1.5-win64.exe
2014-08-30 09:10 - 2014-08-30 09:10 - 00768024 _____ ( ) C:\Users\LANCE\Downloads\vlc-2.1.5-win64_inst.exe
AlternateDataStreams: C:\ProgramData\Temp:5C321E34
C:\Users\LANCE\AppData\Local\Smartbar
C:\Program Files (x86)\LPT
C:\Users\LANCE\AppData\Local\LPT
C:\Windows\Installer\{60D6618B-153F-4353-8185-908E676E5888}
EmptyTemp:
end


NOTE. It's important that both files, FRST64 and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


Fifth>>>>


We need a follow up scan with FRST to check the status of the fix and see if we need some file replacements or proceed with cleaning.
  • Right click on the FRST64.exe file on your desktop and select "Run as Administrator..." When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
Things for your next reply(s):
  • Did Defogger run OK?
  • Did the Uninstalls proceed alright and what programs did you uninstall?
  • The Fixlog.txt log text.
  • The new FRST.txt log text.
  • Any questions or comments you may have.
You can provide the log files in separate posts here if that is easier for you; I don't mind that.
  • 0

#5
LANCE1313

LANCE1313

    Member

  • Topic Starter
  • Member
  • PipPip
  • 42 posts

I had some issues with the first step.  After the "Finished" message it didn't prompt me to restart. It gave me the option of reenabling the drivers and only if I selected that did it prompt to restart. Please let me know what you want me to do.

 

Thanks

 

First >>>>

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.

  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK

IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.


  • 0

#6
dbreeze

dbreeze

    Trusted Helper

  • Malware Removal
  • 2,216 posts

Thanks for coming and asking directions.  I have now updated these directions as it should have said that if DeFogger does not ask to reboot your system, to continue on and post the file defogger_disable.log in your reply here.  Can you do that now please?


  • 0

#7
LANCE1313

LANCE1313

    Member

  • Topic Starter
  • Member
  • PipPip
  • 42 posts

I attempted to uninstall all 4 programs.  3 were successful but VLC media package suggested it had already been uninstalled when I attempted.  It prompted me to take it off the programs list which I declined to do.

 

Logs are posted below. Defogger seemed to run fine but there doesn't seem to be much in the log. Maybe you'll tell me that's a good thing.  Let me know if i've missed something.

 

 

defogger_disable by jpshortstuff (23.02.10.1)
Log created at 20:18 on 02/09/2014 (LANCE)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-

 

 

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 03-09-2014
Ran by LANCE at 2014-09-02 20:35:39 Run:1
Running from C:\Users\LANCE\Downloads
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
(Smartbar) C:\Users\LANCE\AppData\Local\Smartbar\Application\SafeFinder.exe
() C:\Program Files (x86)\LPT\srpts.exe
() C:\Program Files (x86)\LPT\srptsl.exe
() C:\Users\LANCE\AppData\Local\LPT\srptm.exe
() C:\Users\LANCE\AppData\Local\Smartbar\Application\Lrcnta.exe
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\Run: [Browser Infrastructure Helper] => C:\Users\LANCE\AppData\Local\Smartbar\Application\SafeFinder.exe [28160 2014-08-27] (Smartbar)
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\MountPoints2: {8b8dda66-64f1-11e3-857a-e0cb4e302f58} - F:\setup.exe
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\MountPoints2: {9fc835fc-6ca6-11e3-8716-e0cb4e302f58} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\start.exe
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\MountPoints2: {b12ff93c-ab0e-11e3-abef-e0cb4e302f58} - F:\setup.exe
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\MountPoints2: {e9162f72-44b1-11e3-a90a-e0cb4e302f58} - "G:\WD SmartWare.exe" autoplay=true
AppInit_DLLs: C:\Users\LANCE\AppData\Local\Smartbar\Application\Resources\crdlil64.dll => C:\Users\LANCE\AppData\Local\Smartbar\Application\Resources\crdlil64.dll [77856 2014-08-30] ()
AppInit_DLLs-x32: C:\Users\LANCE\AppData\Local\Smartbar\Application\Resources\crdlil.dll => C:\Users\LANCE\AppData\Local\Smartbar\Application\Resources\crdlil.dll [67104 2014-08-30] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk
ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{60D6618B-153F-4353-8185-908E676E5888}\_DCE9A4DB2A5F2786140FA3.exe ()
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://feed.safefind...Qp4CtkJPsHJj1Eg,
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.safefind...q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.safefind...q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.safefind...q={searchTerms}
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.safefind...q={searchTerms}
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.safefind...q={searchTerms}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.safefind...q={searchTerms}
BHO: SafeFinder SmartbarEngine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO-x32: SafeFinder SmartbarEngine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM - SafeFinder Smartbar - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\system32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - SafeFinder Smartbar - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - No File
2014-08-30 09:23 - 2014-08-30 09:23 - 00000873 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-08-30 09:23 - 2014-08-30 09:23 - 00000000 ____D () C:\Users\LANCE\AppData\Roaming\0F1L1I1P0H1L1E1E1F
2014-08-30 09:22 - 2014-08-30 09:22 - 25611537 _____ () C:\Users\LANCE\Downloads\vlc-2.1.5-win64.exe
2014-08-30 09:10 - 2014-08-30 09:10 - 00768024 _____ ( ) C:\Users\LANCE\Downloads\vlc-2.1.5-win64_inst.exe
AlternateDataStreams: C:\ProgramData\Temp:5C321E34
C:\Users\LANCE\AppData\Local\Smartbar
C:\Program Files (x86)\LPT
C:\Users\LANCE\AppData\Local\LPT
C:\Windows\Installer\{60D6618B-153F-4353-8185-908E676E5888}
EmptyTemp:
end
*****************

C:\Users\LANCE\AppData\Local\Smartbar\Application\SafeFinder.exe => No running process found
C:\Program Files (x86)\LPT\srpts.exe => No running process found
C:\Program Files (x86)\LPT\srptsl.exe => No running process found
C:\Users\LANCE\AppData\Local\LPT\srptm.exe => No running process found
C:\Users\LANCE\AppData\Local\Smartbar\Application\Lrcnta.exe => No running process found
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Browser Infrastructure Helper => Value not found.
"HKU\S-1-5-21-2552895503-36244919-2108235947-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8b8dda66-64f1-11e3-857a-e0cb4e302f58}" => Key deleted successfully.
"HKCR\CLSID\{8b8dda66-64f1-11e3-857a-e0cb4e302f58}" => Key not found.
"HKU\S-1-5-21-2552895503-36244919-2108235947-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9fc835fc-6ca6-11e3-8716-e0cb4e302f58}" => Key deleted successfully.
"HKCR\CLSID\{9fc835fc-6ca6-11e3-8716-e0cb4e302f58}" => Key not found.
"HKU\S-1-5-21-2552895503-36244919-2108235947-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b12ff93c-ab0e-11e3-abef-e0cb4e302f58}" => Key deleted successfully.
"HKCR\CLSID\{b12ff93c-ab0e-11e3-abef-e0cb4e302f58}" => Key not found.
"HKU\S-1-5-21-2552895503-36244919-2108235947-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e9162f72-44b1-11e3-a90a-e0cb4e302f58}" => Key deleted successfully.
"HKCR\CLSID\{e9162f72-44b1-11e3-a90a-e0cb4e302f58}" => Key not found.
"C:\Users\LANCE\AppData\Local\Smartbar\Application\Resources\crdlil64.dll" => Value Data not found.
"C:\Users\LANCE\AppData\Local\Smartbar\Application\Resources\crdlil.dll" => Value Data not found.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk => Moved successfully.
C:\Windows\Installer\{60D6618B-153F-4353-8185-908E676E5888}\_DCE9A4DB2A5F2786140FA3.exe => Moved successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => value deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => Key deleted successfully.
"HKCR\CLSID\{006ee092-9658-4fd6-bd8e-a21a348e59f5}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0}" => Key not found.
"HKCR\CLSID\{31ad400d-1b06-4e33-a59a-90c2c140cba0}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0}" => Key not found.
"HKCR\Wow6432Node\CLSID\{31ad400d-1b06-4e33-a59a-90c2c140cba0}" => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} => value deleted successfully.
"HKCR\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}" => Key deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113} => value deleted successfully.
"HKCR\Wow6432Node\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}" => Key deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => value deleted successfully.
"HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}" => Key not found.
"HKCR\PROTOCOLS\Filter\application/x-ica" => Key deleted successfully.
"HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC}" => Key not found.
"HKCR\PROTOCOLS\Filter\application/x-ica; charset=euc-jp" => Key deleted successfully.
"HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC}" => Key not found.
"HKCR\PROTOCOLS\Filter\application/x-ica; charset=ISO-8859-1" => Key deleted successfully.
"HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC}" => Key not found.
"HKCR\PROTOCOLS\Filter\application/x-ica; charset=MS936" => Key deleted successfully.
"HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC}" => Key not found.
"HKCR\PROTOCOLS\Filter\application/x-ica; charset=MS949" => Key deleted successfully.
"HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC}" => Key not found.
"HKCR\PROTOCOLS\Filter\application/x-ica; charset=MS950" => Key deleted successfully.
"HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC}" => Key not found.
"HKCR\PROTOCOLS\Filter\application/x-ica; charset=UTF-8" => Key deleted successfully.
"HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC}" => Key not found.
"HKCR\PROTOCOLS\Filter\application/x-ica; charset=UTF8" => Key deleted successfully.
"HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC}" => Key not found.
"HKCR\PROTOCOLS\Filter\application/x-ica;charset=euc-jp" => Key deleted successfully.
"HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC}" => Key not found.
"HKCR\PROTOCOLS\Filter\application/x-ica;charset=ISO-8859-1" => Key deleted successfully.
"HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC}" => Key not found.
"HKCR\PROTOCOLS\Filter\application/x-ica;charset=MS936" => Key deleted successfully.
"HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC}" => Key not found.
"HKCR\PROTOCOLS\Filter\application/x-ica;charset=MS949" => Key deleted successfully.
"HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC}" => Key not found.
"HKCR\PROTOCOLS\Filter\application/x-ica;charset=MS950" => Key deleted successfully.
"HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC}" => Key not found.
"HKCR\PROTOCOLS\Filter\application/x-ica;charset=UTF-8" => Key deleted successfully.
"HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC}" => Key not found.
"HKCR\PROTOCOLS\Filter\application/x-ica;charset=UTF8" => Key deleted successfully.
"HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC}" => Key not found.
"HKCR\PROTOCOLS\Filter\ica" => Key deleted successfully.
"HKCR\CLSID\{CFB6322E-CC85-4d1b-82C7-893888A236BC}" => Key not found.
C:\Users\Public\Desktop\VLC media player.lnk => Moved successfully.
C:\Users\LANCE\AppData\Roaming\0F1L1I1P0H1L1E1E1F => Moved successfully.
C:\Users\LANCE\Downloads\vlc-2.1.5-win64.exe => Moved successfully.
C:\Users\LANCE\Downloads\vlc-2.1.5-win64_inst.exe => Moved successfully.
C:\ProgramData\Temp => ":5C321E34" ADS removed successfully.
"C:\Users\LANCE\AppData\Local\Smartbar" => File/Directory not found.
"C:\Program Files (x86)\LPT" => File/Directory not found.
"C:\Users\LANCE\AppData\Local\LPT" => File/Directory not found.
C:\Windows\Installer\{60D6618B-153F-4353-8185-908E676E5888} => Moved successfully.
EmptyTemp: => Removed 8.9 GB temporary data.


The system needed a reboot.

==== End of Fixlog ====

 

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-09-2014
Ran by LANCE (administrator) on LANCE-PC on 02-09-2014 21:50:52
Running from C:\Users\LANCE\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingc...can-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingc...can-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe
() C:\Program Files\ATKGFNEX\GFNEXSrv.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
() C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
() C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
(ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\WDC.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(FileHippo.com) C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
(ASUS) C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\SB Audigy\Volume Panel\VolPanlu.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\redirector.exe
(Dropbox, Inc.) C:\Users\LANCE\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\Receiver\Receiver.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [EeeStorageBackup] => C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [1732608 2009-11-26] ()
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1813288 2009-08-17] (Synaptics Incorporated)
HKLM\...\Run: [RunDLLEntry] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\AmbRunE.dll,RunDLLEntry
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [456704 2012-02-20] ()
HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe [6937216 2009-10-09] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe [170624 2009-08-20] (ASUS)
HKLM-x32\...\Run: [VolPanel] => C:\Program Files (x86)\Creative\SB Audigy\Volume Panel\VolPanlu.exe [237693 2008-12-29] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [CitrixReceiver] => "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk"
HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [395656 2013-10-01] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [153992 2013-10-01] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-07-30] (Oracle Corporation)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.)
HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-09-06] (Microsoft Corporation)
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\Run: [FileHippo.com] => C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe [307712 2012-11-23] (FileHippo.com)
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\Run: [HP Officejet Pro 8600 (NET)] => C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21653096 2014-07-24] (Skype Technologies S.A.)
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\Run: [GoogleChromeAutoLaunch_06652FE761E59AF1CD30EA9A61DFF3A9] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [852808 2014-08-28] (Google Inc.)
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-13] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\LANCE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\LANCE\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: AsusWSShellExt_B -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\service\AsusWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: AsusWSShellExt_O -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\service\AsusWSShellExt64.dll (eCareme Technologies, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_20\bin\ssv.dll (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_20\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default
FF DefaultSearchEngine: SafeFinder Search
FF SelectedSearchEngine: SafeFinder Search
FF Homepage: hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9howjcx7fZ0FW0FE0MeOOoZRxBPJEUsk-wpxHmB3CTiJ1nKG5c7zeDTgKQ7Ogd3N9Y1Lg9drO5_rPZZzRd0qYXWCc8vv0EK9znlBTsQV6jMzVXBkR2sd1TQ0vYUQjmFgWWtTQ_1sr9GauGszWuwkZNwZFhyTMq67_-ddQ,,
FF Keyword.URL: hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9howjcx7fZ0FW0FE0MeOOoZRxBPJEUsk-wpxHmB3CTiJ1nKG5c7zeDTgKQ7Ogd3N9Y1Lg9drO5_rPZZzRuT8eTPEaYy76HQTcnLyJ-HJP1OsSFx-MZoUgdqpvfLxocVtlrsBioiJTzm2v3pZh4YMzzd7fKgNMYkiF_n2A,,&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll ()
FF Plugin: @java.com/DTPlugin,version=11.20.2 -> C:\Program Files\Java\jre1.8.0_20\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.20.2 -> C:\Program Files\Java\jre1.8.0_20\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll (Citrix Systems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\searchplugins\SafeFinder Search.xml
FF Extension: Pocket - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\[email protected] [2014-07-22]
FF Extension: No Name - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\staged [2014-09-02]
FF Extension: WOT - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-12-08]
FF Extension: Cleanest Addon Manager - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\[email protected] [2013-09-05]
FF Extension: SkipScreen - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\[email protected] [2013-09-05]
FF Extension: Flagfox - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2014-03-10]
FF Extension: New Tab Homepage - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\{66E978CD-981F-47DF-AC42-E3CF417C1467}.xpi [2013-09-05]
FF Extension: NoScript - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-12-12]
FF Extension: Fasterfox - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\{c36177c0-224a-11da-8cd6-0800200c9a91}.xpi [2013-09-05]
FF Extension: Adblock Plus - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-09-05]
FF Extension: Download Statusbar - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi [2013-09-05]
FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]

Chrome:
=======
CHR HomePage: Default -> C636E567E0B7E5ED7CAA98DA48BAA6857D980A1F637CEC013514ECA70F1CA894
CHR DefaultSearchKeyword: Default -> 67F30E9B43E283EA7629FE09DED50A37EBB364E74050FDE018B2EC9664C40054
CHR DefaultSearchURL: Default -> 7B2991C89EB8228127EF9FEFBB687A003982395DC7AAA96084310E15C63755F3
CHR Profile: C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-22]
CHR Extension: (Google Drive) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-22]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-24]
CHR Extension: (WOT) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2014-05-22]
CHR Extension: (YouTube) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-22]
CHR Extension: (Google Search) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-22]
CHR Extension: (SuperSaiyanTheme) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\cplciigccgelconelnbdhnhpgibcbjfe [2014-05-22]
CHR Extension: (Netrunner Lookup) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\falbpbbdomlkdjlfippfjopgihdekanf [2014-05-22]
CHR Extension: (AdBlock) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-05-22]
CHR Extension: (Hola Better Internet) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2014-05-22]
CHR Extension: (Google Keep - notes and lists) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2014-05-22]
CHR Extension: (Social Fixer for Facebook) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifmhoabcaeehkljcfclfiieohkohdgbb [2014-05-22]
CHR Extension: (Disconnect) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeoacafpbcihiomhlakheieifhpjdfeo [2014-05-22]
CHR Extension: (The Great Suspender) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\klbibkeccnjlkjkiokjodocebajanakg [2014-05-22]
CHR Extension: (Google Wallet) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-22]
CHR Extension: (Gmail) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-22]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () [File not signed]
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2013-08-09] (Broadcom Corporation.)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2010-01-23] (Creative Labs) [File not signed]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2010-01-23] (Creative Labs) [File not signed]
R2 LMS; C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe [262144 2009-09-30] (Intel Corporation) [File not signed]
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 UNS; C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2314240 2009-09-30] (Intel Corporation) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASMMAP64; C:\Program Files\ATKGFNEX\ASMMAP64.sys [14904 2007-07-24] ()
S3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [170712 2013-08-09] (Broadcom Corporation.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-03-20] (Disc Soft Ltd)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1799680 2009-05-20] ()
U3 tmlwf; No ImagePath
U3 tmwfp; No ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-02 20:27 - 2014-09-02 20:27 - 00000000 ____D () C:\Users\LANCE\Downloads\FRST-OlderVersion
2014-09-02 19:49 - 2014-09-02 21:45 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-09-02 19:22 - 2014-09-02 19:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-09-02 17:10 - 2014-09-02 17:10 - 00139488 _____ () C:\Windows\SysWOW64\XMLOperations.xml
2014-09-01 20:57 - 2014-09-01 20:57 - 00000168 _____ () C:\Users\LANCE\defogger_reenable
2014-09-01 20:50 - 2014-09-01 20:50 - 00000344 _____ () C:\Users\LANCE\Downloads\defogger_enable.log
2014-09-01 20:47 - 2014-09-02 20:18 - 00000472 _____ () C:\Users\LANCE\Downloads\defogger_disable.log
2014-09-01 20:45 - 2014-09-01 20:45 - 00050477 _____ () C:\Users\LANCE\Downloads\Defogger.exe
2014-08-30 17:10 - 2014-08-30 17:11 - 00041747 _____ () C:\Users\LANCE\Downloads\Addition.txt
2014-08-30 17:09 - 2014-09-02 21:50 - 00022361 _____ () C:\Users\LANCE\Downloads\FRST.txt
2014-08-30 17:09 - 2014-09-02 21:50 - 00000000 ____D () C:\FRST
2014-08-30 17:09 - 2014-09-02 20:27 - 02104832 _____ (Farbar) C:\Users\LANCE\Downloads\FRST64.exe
2014-08-30 10:25 - 2014-08-30 10:25 - 00071084 _____ () C:\Users\LANCE\Downloads\Extras.Txt
2014-08-30 10:23 - 2014-08-30 10:23 - 00137872 _____ () C:\Users\LANCE\Downloads\OTL.Txt
2014-08-30 10:14 - 2014-08-30 10:14 - 00602112 _____ (OldTimer Tools) C:\Users\LANCE\Downloads\OTL.exe
2014-08-30 09:31 - 2014-08-30 09:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-08-30 09:30 - 2014-08-30 09:31 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-08-30 09:30 - 2014-08-30 09:31 - 00000000 ____D () C:\Program Files\iTunes
2014-08-30 09:30 - 2014-08-30 09:31 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-08-30 09:30 - 2014-08-30 09:30 - 00000000 ____D () C:\Program Files\iPod
2014-08-30 09:20 - 2014-08-30 09:20 - 00002088 _____ () C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2014-08-30 09:15 - 2014-08-30 09:15 - 00001726 _____ () C:\Users\Public\Desktop\Defraggler.lnk
2014-08-30 09:13 - 2014-08-30 09:13 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-08-30 09:10 - 2014-08-30 09:17 - 113492816 _____ (Apple Inc.) C:\Users\LANCE\Downloads\iTunes64Setup.exe
2014-08-30 09:10 - 2014-08-30 09:16 - 96138664 _____ (Oracle Corporation) C:\Users\LANCE\Downloads\jre-8u20-windows-x64.exe
2014-08-30 09:10 - 2014-08-30 09:12 - 26472832 _____ (Mozilla) C:\Users\LANCE\Downloads\Thunderbird Setup 31.0.exe
2014-08-30 09:10 - 2014-08-30 09:11 - 04901352 _____ (Piriform Ltd) C:\Users\LANCE\Downloads\ccsetup417.exe
2014-08-30 09:10 - 2014-08-30 09:11 - 04362512 _____ (Piriform Ltd) C:\Users\LANCE\Downloads\dfsetup218.exe
2014-08-30 09:09 - 2014-08-30 09:10 - 18743160 _____ (Adobe Systems Inc.) C:\Users\LANCE\Downloads\AdobeAIRInstaller.exe
2014-08-29 17:01 - 2014-08-22 22:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-29 17:01 - 2014-08-22 21:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-29 17:01 - 2014-08-22 20:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 10:20 - 2014-09-02 21:41 - 00105479 _____ () C:\Users\LANCE\Desktop\Sinai Grand Rounds.pptx
2014-08-19 21:34 - 2014-08-19 21:34 - 00000962 _____ () C:\Users\Public\Desktop\calibre - E-book management.lnk
2014-08-19 21:15 - 2014-08-19 21:16 - 56419840 _____ () C:\Users\LANCE\Downloads\calibre-1.48.0.msi
2014-08-19 21:11 - 2014-09-02 18:29 - 00000000 ____D () C:\Users\LANCE\Downloads\Book Requests
2014-08-17 11:48 - 2014-08-17 13:05 - 00000000 ____D () C:\Users\LANCE\Desktop\Grand Rounds
2014-08-15 12:36 - 2014-09-02 21:42 - 00003170 _____ () C:\Windows\System32\Tasks\P4GIntlCtrl
2014-08-15 10:45 - 2013-10-01 22:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-08-15 10:45 - 2013-10-01 22:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-08-15 10:45 - 2013-10-01 22:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-08-15 10:45 - 2013-10-01 21:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-08-15 10:45 - 2013-10-01 21:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-08-15 10:45 - 2013-10-01 21:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-08-15 10:45 - 2013-10-01 21:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-08-15 10:45 - 2013-10-01 20:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2014-08-15 10:45 - 2013-10-01 20:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2014-08-15 10:45 - 2013-10-01 20:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-08-15 10:45 - 2013-10-01 20:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-08-15 10:45 - 2013-10-01 19:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-08-15 10:45 - 2013-10-01 19:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-08-15 10:45 - 2013-10-01 18:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-08-15 10:45 - 2013-10-01 16:57 - 06578176 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-08-15 10:45 - 2013-10-01 16:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-08-15 10:44 - 2013-10-01 20:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-08-15 10:44 - 2013-10-01 19:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2014-08-15 10:27 - 2014-06-30 18:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-15 10:27 - 2014-06-30 18:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-15 10:27 - 2014-03-09 17:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-15 10:27 - 2014-03-09 17:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-15 10:27 - 2014-03-09 17:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-15 10:27 - 2014-03-09 17:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-15 10:26 - 2014-06-06 02:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-15 10:26 - 2014-06-06 02:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-15 10:26 - 2013-12-03 22:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-08-15 10:26 - 2013-12-03 22:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-08-15 10:26 - 2013-12-03 22:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-08-15 10:26 - 2013-12-03 22:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-08-15 10:26 - 2013-12-03 22:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-08-15 10:26 - 2013-12-03 21:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-08-15 10:26 - 2013-12-03 21:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-08-15 10:26 - 2013-12-03 21:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-08-15 10:26 - 2013-12-03 21:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-08-15 10:25 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-08-15 10:25 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-08-15 10:25 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-08-15 10:25 - 2014-07-08 22:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-08-15 10:25 - 2014-07-08 22:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-08-15 10:25 - 2014-07-08 21:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-08-15 10:25 - 2014-07-08 21:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-08-15 10:25 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-08-15 10:25 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-08-15 10:25 - 2014-07-08 21:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-08-15 10:25 - 2014-07-08 18:38 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-08-15 10:25 - 2014-07-08 18:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
2014-08-15 10:25 - 2014-06-24 22:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-15 10:25 - 2014-06-24 21:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-15 10:25 - 2014-05-30 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-08-15 10:25 - 2014-05-30 04:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-08-15 10:25 - 2014-05-30 04:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-08-15 10:25 - 2014-05-30 04:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-08-15 10:25 - 2014-05-30 04:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-08-15 10:25 - 2014-05-30 04:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-08-15 10:25 - 2014-05-30 04:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-08-15 10:25 - 2014-05-30 03:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-08-15 10:25 - 2014-05-30 03:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-08-15 10:25 - 2014-05-30 03:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-08-15 10:25 - 2014-05-30 03:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-08-15 10:25 - 2014-05-30 03:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-08-15 10:25 - 2014-05-30 03:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-08-15 10:25 - 2014-05-30 03:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-08-15 10:25 - 2014-02-03 22:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-08-15 10:25 - 2014-02-03 22:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-08-15 10:25 - 2014-02-03 22:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-08-15 10:25 - 2014-02-03 22:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-08-15 10:25 - 2014-02-03 22:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-08-15 10:25 - 2014-01-27 22:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-08-15 10:25 - 2014-01-23 22:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-08-15 10:25 - 2013-12-03 22:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-08-15 10:25 - 2013-12-03 22:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-08-15 10:25 - 2013-12-03 22:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-08-15 10:25 - 2013-12-03 22:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-08-15 10:25 - 2013-12-03 22:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-08-15 10:25 - 2013-12-03 22:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-08-15 10:25 - 2013-12-03 22:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-08-15 10:25 - 2013-12-03 22:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-08-15 10:25 - 2013-12-03 22:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-08-15 10:25 - 2013-09-24 22:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-08-15 10:25 - 2013-09-24 21:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-08-15 10:23 - 2014-02-03 22:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-08-15 10:23 - 2014-02-03 22:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-08-15 10:19 - 2014-07-15 23:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-15 10:19 - 2014-07-15 22:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-15 10:18 - 2014-07-31 19:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-15 10:18 - 2014-07-31 19:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-15 10:18 - 2014-07-25 10:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-15 10:18 - 2014-07-25 10:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-15 10:18 - 2014-07-25 10:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-15 10:18 - 2014-07-25 09:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-15 10:18 - 2014-07-25 09:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-15 10:18 - 2014-07-25 09:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-15 10:18 - 2014-07-25 09:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-15 10:18 - 2014-07-25 09:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-15 10:18 - 2014-07-25 09:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-15 10:18 - 2014-07-25 09:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-15 10:18 - 2014-07-25 09:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-15 10:18 - 2014-07-25 09:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-15 10:18 - 2014-07-25 09:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-15 10:18 - 2014-07-25 09:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-15 10:18 - 2014-07-25 09:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-15 10:18 - 2014-07-25 08:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-15 10:18 - 2014-07-25 08:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-15 10:18 - 2014-07-25 08:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-15 10:18 - 2014-07-25 08:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-15 10:18 - 2014-07-25 08:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-15 10:18 - 2014-07-25 08:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-15 10:18 - 2014-07-25 08:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-15 10:18 - 2014-07-25 08:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-15 10:18 - 2014-07-25 08:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-15 10:18 - 2014-07-25 08:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-15 10:18 - 2014-07-25 08:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-15 10:18 - 2014-07-25 08:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-15 10:18 - 2014-07-25 08:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-15 10:18 - 2014-07-25 08:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-15 10:18 - 2014-07-25 08:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-15 10:18 - 2014-07-25 08:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-15 10:18 - 2014-07-25 08:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-15 10:18 - 2014-07-25 08:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-15 10:18 - 2014-07-25 08:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-15 10:18 - 2014-07-25 07:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-15 10:18 - 2014-07-25 07:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-15 10:18 - 2014-07-25 07:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-15 10:18 - 2014-07-25 07:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-15 10:18 - 2014-07-25 07:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-15 10:18 - 2014-07-25 07:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-15 10:18 - 2014-07-25 07:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-15 10:18 - 2014-07-25 07:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-15 10:18 - 2014-07-25 07:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-15 10:18 - 2014-07-25 07:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-15 10:18 - 2014-07-25 07:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-15 10:18 - 2014-07-25 07:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-15 10:18 - 2014-07-25 07:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-08-15 10:18 - 2014-07-25 07:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-15 10:18 - 2014-07-25 06:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-15 10:18 - 2014-07-25 06:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-15 10:18 - 2014-07-25 06:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-15 10:18 - 2014-07-25 06:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-15 10:18 - 2014-07-25 06:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-15 10:18 - 2014-07-25 06:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-15 10:18 - 2014-06-15 22:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-15 10:18 - 2014-06-03 06:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-15 10:18 - 2014-06-03 06:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-15 10:18 - 2014-06-03 06:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-15 10:18 - 2014-06-03 06:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-15 10:18 - 2014-06-03 05:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-15 10:18 - 2014-06-03 05:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-15 10:18 - 2014-06-03 05:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-15 10:16 - 2014-07-13 22:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-15 10:16 - 2014-07-13 21:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-02 21:51 - 2014-08-30 17:09 - 00022361 _____ () C:\Users\LANCE\Downloads\FRST.txt
2014-09-02 21:50 - 2014-08-30 17:09 - 00000000 ____D () C:\FRST
2014-09-02 21:49 - 2009-07-14 00:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-02 21:49 - 2009-07-14 00:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-02 21:48 - 2013-09-05 21:58 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-02 21:45 - 2014-09-02 19:49 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-09-02 21:45 - 2013-09-05 20:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-02 21:44 - 2014-01-19 14:09 - 00000000 ___RD () C:\Users\LANCE\Dropbox
2014-09-02 21:44 - 2013-09-05 21:41 - 00000000 ____D () C:\Users\LANCE\AppData\Roaming\Skype
2014-09-02 21:43 - 2014-01-19 14:08 - 00000000 ____D () C:\Users\LANCE\AppData\Roaming\Dropbox
2014-09-02 21:42 - 2014-08-15 12:36 - 00003170 _____ () C:\Windows\System32\Tasks\P4GIntlCtrl
2014-09-02 21:42 - 2014-05-22 21:27 - 00000892 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-02 21:42 - 2013-11-12 07:53 - 00382162 _____ () C:\Windows\PFRO.log
2014-09-02 21:42 - 2013-11-10 02:00 - 00014782 _____ () C:\Windows\setupact.log
2014-09-02 21:42 - 2010-01-23 14:50 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-09-02 21:42 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-02 21:41 - 2014-08-22 10:20 - 00105479 _____ () C:\Users\LANCE\Desktop\Sinai Grand Rounds.pptx
2014-09-02 21:41 - 2010-01-23 13:44 - 01602474 _____ () C:\Windows\WindowsUpdate.log
2014-09-02 21:37 - 2014-05-22 21:27 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-02 21:26 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-02 20:27 - 2014-09-02 20:27 - 00000000 ____D () C:\Users\LANCE\Downloads\FRST-OlderVersion
2014-09-02 20:27 - 2014-08-30 17:09 - 02104832 _____ (Farbar) C:\Users\LANCE\Downloads\FRST64.exe
2014-09-02 20:24 - 2014-05-22 21:34 - 00000000 ____D () C:\Users\LANCE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-09-02 20:18 - 2014-09-01 20:47 - 00000472 _____ () C:\Users\LANCE\Downloads\defogger_disable.log
2014-09-02 19:23 - 2014-09-02 19:22 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-09-02 18:29 - 2014-08-19 21:11 - 00000000 ____D () C:\Users\LANCE\Downloads\Book Requests
2014-09-02 17:10 - 2014-09-02 17:10 - 00139488 _____ () C:\Windows\SysWOW64\XMLOperations.xml
2014-09-01 20:57 - 2014-09-01 20:57 - 00000168 _____ () C:\Users\LANCE\defogger_reenable
2014-09-01 20:57 - 2013-09-05 20:03 - 00000000 ____D () C:\Users\LANCE
2014-09-01 20:50 - 2014-09-01 20:50 - 00000344 _____ () C:\Users\LANCE\Downloads\defogger_enable.log
2014-09-01 20:45 - 2014-09-01 20:45 - 00050477 _____ () C:\Users\LANCE\Downloads\Defogger.exe
2014-08-30 17:11 - 2014-08-30 17:10 - 00041747 _____ () C:\Users\LANCE\Downloads\Addition.txt
2014-08-30 10:25 - 2014-08-30 10:25 - 00071084 _____ () C:\Users\LANCE\Downloads\Extras.Txt
2014-08-30 10:23 - 2014-08-30 10:23 - 00137872 _____ () C:\Users\LANCE\Downloads\OTL.Txt
2014-08-30 10:14 - 2014-08-30 10:14 - 00602112 _____ (OldTimer Tools) C:\Users\LANCE\Downloads\OTL.exe
2014-08-30 09:31 - 2014-08-30 09:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-08-30 09:31 - 2014-08-30 09:30 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-08-30 09:31 - 2014-08-30 09:30 - 00000000 ____D () C:\Program Files\iTunes
2014-08-30 09:31 - 2014-08-30 09:30 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-08-30 09:30 - 2014-08-30 09:30 - 00000000 ____D () C:\Program Files\iPod
2014-08-30 09:28 - 2013-09-05 20:55 - 00000000 ____D () C:\Users\LANCE\AppData\Local\Thunderbird
2014-08-30 09:21 - 2014-01-16 21:00 - 00000000 ____D () C:\Program Files\Java
2014-08-30 09:20 - 2014-08-30 09:20 - 00002088 _____ () C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2014-08-30 09:20 - 2013-09-05 20:54 - 00002100 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
2014-08-30 09:19 - 2014-01-16 21:00 - 00319912 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-08-30 09:19 - 2014-01-16 21:00 - 00191400 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-08-30 09:19 - 2014-01-16 21:00 - 00190888 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-08-30 09:19 - 2014-01-16 21:00 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-08-30 09:19 - 2013-11-03 14:41 - 00000000 ____D () C:\ProgramData\Oracle
2014-08-30 09:17 - 2014-08-30 09:10 - 113492816 _____ (Apple Inc.) C:\Users\LANCE\Downloads\iTunes64Setup.exe
2014-08-30 09:16 - 2014-08-30 09:10 - 96138664 _____ (Oracle Corporation) C:\Users\LANCE\Downloads\jre-8u20-windows-x64.exe
2014-08-30 09:15 - 2014-08-30 09:15 - 00001726 _____ () C:\Users\Public\Desktop\Defraggler.lnk
2014-08-30 09:15 - 2013-09-05 21:30 - 00000000 ____D () C:\Program Files\Defraggler
2014-08-30 09:13 - 2014-08-30 09:13 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-08-30 09:13 - 2013-09-05 21:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-08-30 09:13 - 2013-09-05 21:31 - 00000000 ____D () C:\Program Files\CCleaner
2014-08-30 09:12 - 2014-08-30 09:10 - 26472832 _____ (Mozilla) C:\Users\LANCE\Downloads\Thunderbird Setup 31.0.exe
2014-08-30 09:11 - 2014-08-30 09:10 - 04901352 _____ (Piriform Ltd) C:\Users\LANCE\Downloads\ccsetup417.exe
2014-08-30 09:11 - 2014-08-30 09:10 - 04362512 _____ (Piriform Ltd) C:\Users\LANCE\Downloads\dfsetup218.exe
2014-08-30 09:10 - 2014-08-30 09:09 - 18743160 _____ (Adobe Systems Inc.) C:\Users\LANCE\Downloads\AdobeAIRInstaller.exe
2014-08-30 08:07 - 2009-07-14 00:45 - 00479072 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-27 19:45 - 2013-09-05 21:57 - 00000000 ____D () C:\Users\LANCE\AppData\Local\Adobe
2014-08-27 19:18 - 2013-09-05 21:58 - 00699568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-27 19:18 - 2013-09-05 21:58 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-27 19:18 - 2013-09-05 21:58 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-08-26 11:42 - 2013-09-11 18:14 - 00000099 _____ () C:\Users\Public\LMDebug.log
2014-08-22 22:07 - 2014-08-29 17:01 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-22 21:45 - 2014-08-29 17:01 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-22 20:59 - 2014-08-29 17:01 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-19 21:34 - 2014-08-19 21:34 - 00000962 _____ () C:\Users\Public\Desktop\calibre - E-book management.lnk
2014-08-19 21:34 - 2013-09-05 21:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre - E-book Management
2014-08-19 21:34 - 2013-09-05 21:53 - 00000000 ____D () C:\Program Files (x86)\Calibre2
2014-08-19 21:24 - 2009-07-14 01:13 - 00781298 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-19 21:16 - 2014-08-19 21:15 - 56419840 _____ () C:\Users\LANCE\Downloads\calibre-1.48.0.msi
2014-08-19 21:15 - 2013-09-05 21:53 - 00000000 ____D () C:\Users\LANCE\AppData\Roaming\calibre
2014-08-17 13:29 - 2013-09-16 07:33 - 00000000 ____D () C:\Users\LANCE\AppData\Roaming\vlc
2014-08-17 13:05 - 2014-08-17 11:48 - 00000000 ____D () C:\Users\LANCE\Desktop\Grand Rounds
2014-08-15 21:43 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\rescache
2014-08-15 12:37 - 2014-01-19 14:09 - 00000000 ____D () C:\Users\LANCE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-08-15 12:36 - 2013-09-05 21:36 - 00000000 ____D () C:\ProgramData\Skype
2014-08-15 12:30 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-08-15 12:30 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-08-15 12:30 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-15 10:48 - 2010-01-23 13:55 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-15 10:38 - 2013-09-05 21:54 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-15 10:35 - 2013-09-05 21:54 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

Some content of TEMP:
====================
C:\Users\LANCE\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpefpuzg.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-08-27 18:58

==================== End Of Log ============================


  • 0

#8
dbreeze

dbreeze

    Trusted Helper

  • Malware Removal
  • 2,216 posts

LANCE1313,

 

DeFogger ran fine; I needed to make sure that none of the emulation software would interfer with our scans.  The Fixlist script ran fine and I will get the next step ready, approved and to you as soon as possible.  The uninstalls helped a great deal and the next few steps will clean up the left overs that I see.  Thanks.


  • 0

#9
dbreeze

dbreeze

    Trusted Helper

  • Malware Removal
  • 2,216 posts

LANCE1313,

Looks like the IE parts are gone but I erred and did not clean the FF / Chrome entries. The Fixlist below will clear those and then we can start looking at parts that don't show in FRST.

First>>>>

Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy. Paste this into the open notepad. Save it to your desktop as fixlist.txt
 

start
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\Run: [GoogleChromeAutoLaunch_06652FE761E59AF1CD30EA9A61DFF3A9] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [852808 2014-08-28] (Google Inc.)
FF DefaultSearchEngine: SafeFinder Search
FF SelectedSearchEngine: SafeFinder Search
FF Homepage: hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9howjcx7fZ0FW0FE0MeOOoZRxBPJEUsk-wpxHmB3CTiJ1nKG5c7zeDTgKQ7Ogd3N9Y1Lg9drO5_rPZZzRd0qYXWCc8vv0EK9znlBTsQV6jMzVXBkR2sd1TQ0vYUQjmFgWWtTQ_1sr9GauGszWuwkZNwZFhyTMq67_-ddQ,,
FF Keyword.URL: hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9howjcx7fZ0FW0FE0MeOOoZRxBPJEUsk-wpxHmB3CTiJ1nKG5c7zeDTgKQ7Ogd3N9Y1Lg9drO5_rPZZzRuT8eTPEaYy76HQTcnLyJ-HJP1OsSFx-MZoUgdqpvfLxocVtlrsBioiJTzm2v3pZh4YMzzd7fKgNMYkiF_n2A,,&q=
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF SearchPlugin: C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\searchplugins\SafeFinder Search.xml
C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\searchplugins\SafeFinder Search.xml
FF Extension: No Name - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\staged [2014-09-02]
C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\staged
CHR HomePage: Default -> C636E567E0B7E5ED7CAA98DA48BAA6857D980A1F637CEC013514ECA70F1CA894
CHR DefaultSearchKeyword: Default -> 67F30E9B43E283EA7629FE09DED50A37EBB364E74050FDE018B2EC9664C40054
CHR DefaultSearchURL: Default -> 7B2991C89EB8228127EF9FEFBB687A003982395DC7AAA96084310E15C63755F3
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-24]
C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
CHR Extension: (Google Search) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-22]
C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
U3 tmlwf; No ImagePath
U3 tmwfp; No ImagePath
EmptyTemp:
end


NOTE. It's important that both files, FRST64.exe and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST64.exe and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

Next >>>>

AdwCleaner by Xplode

Download AdwCleaner from here or from here. Save the file to the desktop.


NOTE: If you are using IE 8 or above you may get a warning that stops the program from downloading. Just click on the warning and allow the download to complete.

Close all open windows and browsers.

  • XP users: Double click the AdwCleaner icon to start the program.
  • Vista/7/8 users: Right click the AdwCleaner icon on the desktop, click Run as administrator and accept the UAC prompt to run AdwCleaner.
    You will see the following console:

    AdwScan.jpg?
  • Click the Scan button and wait for the scan to finish.
  • After the Scan has finished the window may or may not show what it found and above, in the progress bar, you will see: Pending. Please uncheck elements you don't want to remove. Please Do Not delete anything at this time.
  • Click the Report button to get the log.
  • Copy and Paste it into your next reply. This report is also saved to C:\AdwCleaner\AdwCleaner[R0].txt.
  • Click the X in the upper right corner of the program or click the File menu and click Exit to close the program.

Optional:

NOTE: If you see AVG Secure Search being targeted for deletion, Here's Why and Here. You can always Reinstall it when we are done cleaning.

Things to reply with ----

  • The latest Fixlog.txt log
  • The AdwCleaner[R#].txt log
  • How is the system running now?

  • 0

#10
LANCE1313

LANCE1313

    Member

  • Topic Starter
  • Member
  • PipPip
  • 42 posts

Here are the logs.  The system does seem better. I no longer boot up to safefinder.  It appears that this may have been caused by the VLC update I did from filehippo.  Do you have any experience with this? I always thought filehippo and VLC were both quite reputable.  Thoughts?

 

Thanks

 

 

 

# AdwCleaner v3.309 - Report created 03/09/2014 at 20:26:13
# Updated 02/09/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : LANCE - LANCE-PC
# Running from : C:\Users\LANCE\Downloads\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Found : C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio
Folder Found : C:\Users\LANCE\AppData\Local\PackageAware
Folder Found : C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\[email protected]

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\InstallCore
Key Found : HKCU\Software\SmartBar
Key Found : [x64] HKCU\Software\InstallCore
Key Found : [x64] HKCU\Software\SmartBar
Key Found : HKLM\SOFTWARE\DeviceVM
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SafeFinder_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SafeFinder_RASMANCS
Key Found : [x64] HKLM\SOFTWARE\DeviceVM
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17239

Setting Found : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL] - hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9howjcx7fZ0FW0FE0MeOOoZRxBPJEUsk-wpxHmB3CTiJ1nKG5c7zeDTgKQ7Ogd3N9Y1Lg9drO5_rPZZzRuT8eTPEaYy76HQTcnLyJ-HJP1OsSFx-MZoUgdqpvfLxocVtlrsBioiJTzm2v3pZh4YMzzd7fKgNMYkiF_n2A,,&q={searchTerms}
Setting Found : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant] - hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9howjcx7fZ0FW0FE0MeOOoZRxBPJEUsk-wpxHmB3CTiJ1nKG5c7zeDTgKQ7Ogd3N9Y1Lg9drO5_rPZZzRuT8eTPEaYy76HQTcnLyJ-HJP1OsSFx-MZoUgdqpvfLxocVtlrsBioiJTzm2v3pZh4YMzzd7fKgNMYkiF_n2A,,&q={searchTerms}
Setting Found : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default] - hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9howjcx7fZ0FW0FE0MeOOoZRxBPJEUsk-wpxHmB3CTiJ1nKG5c7zeDTgKQ7Ogd3N9Y1Lg9drO5_rPZZzRuT8eTPEaYy76HQTcnLyJ-HJP1OsSFx-MZoUgdqpvfLxocVtlrsBioiJTzm2v3pZh4YMzzd7fKgNMYkiF_n2A,,&q={searchTerms}
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default] - hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9howjcx7fZ0FW0FE0MeOOoZRxBPJEUsk-wpxHmB3CTiJ1nKG5c7zeDTgKQ7Ogd3N9Y1Lg9drO5_rPZZzRuT8eTPEaYy76HQTcnLyJ-HJP1OsSFx-MZoUgdqpvfLxocVtlrsBioiJTzm2v3ukSFscWH28gaHu6721ChbSA,,&q={searchTerms}

-\\ Mozilla Firefox v32.0 (x86 en-US)

[ File : C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\prefs.js ]

Line Found : user_pref("extensions.helperbar.DockingPositionDown", false);
Line Found : user_pref("extensions.helperbar.SmartbarDisabled", false);
Line Found : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Line Found : user_pref("extensions.helperbar.Visibility", false);
Line Found : user_pref("extensions.helperbar.backPageCapacity", 3);
Line Found : user_pref("extensions.helperbar.backPageCounter", 0);
Line Found : user_pref("extensions.helperbar.backPageDay", 30);
Line Found : user_pref("extensions.helperbar.backPageLastEvent", "1409234499688");
Line Found : user_pref("extensions.helperbar.backPageMinInterval", 15);
Line Found : user_pref("extensions.helperbar.barcodeid", "144150");
Line Found : user_pref("extensions.helperbar.countryiso", "ca");
Line Found : user_pref("extensions.helperbar.downloadprovider", "irssf");
Line Found : user_pref("extensions.helperbar.externalJsFiles", "{\"d\":\"[{\\\"ExcludeDomains\\\":[],\\\"hxxpInjection\\\":\\\"hxxp:\\\\\\/\\\\\\/az412617.vo.msecnd.net\\\\\\/scripts\\\\\\/crt.js\\\",\\\"hxxpsInje[...]
Line Found : user_pref("extensions.helperbar.fromautoupdate", "false");
Line Found : user_pref("extensions.helperbar.installationid", "f33c613b-851e-a627-440b-ac974e123ffc");
Line Found : user_pref("extensions.helperbar.installdate", "30/08/2014");
Line Found : user_pref("extensions.helperbar.iswinxp", "false");
Line Found : user_pref("extensions.helperbar.keepAliveLastevent", "1409407298");
Line Found : user_pref("extensions.helperbar.lastExternalJsUpdate", "1409692295797");
Line Found : user_pref("extensions.helperbar.publisher", "irssf");
Line Found : user_pref("extensions.skipscreen.hostMatchStr", "hxxp://www.4shared.com/(get|audio|file|document|dir)/.*|hxxp://.*depositfiles.com/(([a-z]{2})/files/|auth-).*|hxxp://(www.)*digg.com/(.{5}|.{6})$|hxxp:[...]
Line Found : user_pref("lightweightThemes.usedThemes", "[{\"id\":\"184622\",\"name\":\"spiderman crawler up\",\"headerURL\":\"hxxps://addons.mozilla.org/_files/144472/SpidermanCrawlerup.jpg?1271280036\",\"footerUR[...]

-\\ Google Chrome v37.0.2062.102

[ File : C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Found [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
Found [Extension] : bopakagnckmlgajfccecajhnimjiiedh
Found [Extension] : gkojfkhlekighikafcpjkiklfbnlmeio

*************************

AdwCleaner[R0].txt - [5281 octets] - [03/09/2014 20:26:13]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [5341 octets] ##########

 

 

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 03-09-2014
Ran by LANCE at 2014-09-03 20:18:09 Run:2
Running from C:\Users\LANCE\Downloads
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
HKU\S-1-5-21-2552895503-36244919-2108235947-1001\...\Run: [GoogleChromeAutoLaunch_06652FE761E59AF1CD30EA9A61DFF3A9] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [852808 2014-08-28] (Google Inc.)
FF DefaultSearchEngine: SafeFinder Search
FF SelectedSearchEngine: SafeFinder Search
FF Homepage: hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9howjcx7fZ0FW0FE0MeOOoZRxBPJEUsk-wpxHmB3CTiJ1nKG5c7zeDTgKQ7Ogd3N9Y1Lg9drO5_rPZZzRd0qYXWCc8vv0EK9znlBTsQV6jMzVXBkR2sd1TQ0vYUQjmFgWWtTQ_1sr9GauGszWuwkZNwZFhyTMq67_-ddQ,,
FF Keyword.URL: hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9howjcx7fZ0FW0FE0MeOOoZRxBPJEUsk-wpxHmB3CTiJ1nKG5c7zeDTgKQ7Ogd3N9Y1Lg9drO5_rPZZzRuT8eTPEaYy76HQTcnLyJ-HJP1OsSFx-MZoUgdqpvfLxocVtlrsBioiJTzm2v3pZh4YMzzd7fKgNMYkiF_n2A,,&q=
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF SearchPlugin: C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\searchplugins\SafeFinder Search.xml
C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\searchplugins\SafeFinder Search.xml
FF Extension: No Name - C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\staged [2014-09-02]
C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\staged
CHR HomePage: Default -> C636E567E0B7E5ED7CAA98DA48BAA6857D980A1F637CEC013514ECA70F1CA894
CHR DefaultSearchKeyword: Default -> 67F30E9B43E283EA7629FE09DED50A37EBB364E74050FDE018B2EC9664C40054
CHR DefaultSearchURL: Default -> 7B2991C89EB8228127EF9FEFBB687A003982395DC7AAA96084310E15C63755F3
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-24]
C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
CHR Extension: (Google Search) - C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-22]
C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
U3 tmlwf; No ImagePath
U3 tmwfp; No ImagePath
EmptyTemp:
end
*****************

HKU\S-1-5-21-2552895503-36244919-2108235947-1001\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_06652FE761E59AF1CD30EA9A61DFF3A9 => value deleted successfully.
Firefox DefaultSearchEngine deleted successfully.
Firefox SelectedSearchEngine deleted successfully.
Firefox homepage deleted successfully.
Firefox Keyword.URL deleted successfully.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\searchplugins\SafeFinder Search.xml => Moved successfully.
"C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\searchplugins\SafeFinder Search.xml" => File/Directory not found.
C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\staged => Moved successfully.
"C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\staged" => File/Directory not found.
Chrome HomePage deleted successfully.
Chrome DefaultSearchKeyword deleted successfully.
Chrome DefaultSearchURL deleted successfully.
C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn => Moved successfully.
"C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn" => File/Directory not found.
C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf => Moved successfully.
"C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf" => File/Directory not found.
tmlwf => Service deleted successfully.
tmwfp => Service deleted successfully.
EmptyTemp: => Removed 433.7 MB temporary data.


The system needed a reboot.

==== End of Fixlog ====
 


  • 0

Advertisements


#11
dbreeze

dbreeze

    Trusted Helper

  • Malware Removal
  • 2,216 posts

FileHippo is usually very nice file site BUT even the best of them can get some questionable files uploaded to them.  And what we are dealing with is a gray area of PUP / PUA type applications.  PUP = Potentially Unwanted Program  PUA = Potentially Unwanted Application  Both of these types are open to individual interpretations (at least that is what some Anti-virus / Anti-malware vendors say); one person may say some of the files / hijacks are ok, another person may object to them.

 

I will go over the logs you provided and get back as soon as approved.  Glad to hear that SafeFinder is not coming up when you boot up.


  • 0

#12
dbreeze

dbreeze

    Trusted Helper

  • Malware Removal
  • 2,216 posts

Alright LANCE1313; making progress!! 
 
First>>>>

Re-run AdwCleaner

Close all open windows and browsers.

  • Double click the AdwCleaner icon to run AdwCleaner. (Vista and 7 users) Right click the AdwCleaner icon, click Run as administrator and accept the UAC prompt to run AdwCleaner.
  • Click the Scan button and wait for the scan to complete.
  • When the Scan has finished the Scan button will be grayed out and the Clean button will be activated.
  • Click the Clean button.
  • Everything checked will be deleted.
  • When the program has finished cleaning a report appears.
  • Once done it will ask to reboot, allow this (if it asks)

    adwcleaner_delete_restart.jpg
  • On reboot a log will be produced please copy / paste that in your next reply. This report is also saved to C:\AdwCleaner\AdwCleaner[S0].txt

Next>>>>>
 
Junkware Removal Tool
Please download JRT from here to your desktop.

Note: Temporarily disable/shut down your protection software now to avoid potential conflicts, how to do so can be read here.

Double click the JRT.exe file to run the application.

The application will open an Command Prompt window and run from there (this is normal for this program, so not to be alarmed).

When it is asked, press any key to allow the program to continue / run.

This will create a log on the desktop; please copy and paste the JRT.txt log text in your next post.

Note: After the log file is created, please enable your protection software / reboot your system and verify your protection software is enabled.

 

 

Progress Checks

  1. The AdwCleaner cleaning log.
  2. The JRT.txt log.
  3. How is your system running now?

  • 0

#13
LANCE1313

LANCE1313

    Member

  • Topic Starter
  • Member
  • PipPip
  • 42 posts

Things seem good

 

# AdwCleaner v3.309 - Report created 05/09/2014 at 16:42:19
# Updated 02/09/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : LANCE - LANCE-PC
# Running from : C:\Users\LANCE\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Users\LANCE\AppData\Local\PackageAware
Folder Deleted : C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\Extensions\[email protected]

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SafeFinder_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SafeFinder_RASMANCS
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\SmartBar
Key Deleted : HKLM\SOFTWARE\DeviceVM
Key Deleted : [x64] HKLM\SOFTWARE\DeviceVM
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17239

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]

-\\ Mozilla Firefox v32.0 (x86 en-US)

[ File : C:\Users\LANCE\AppData\Roaming\Mozilla\Firefox\Profiles\7riwwbxu.default\prefs.js ]

Line Deleted : user_pref("extensions.helperbar.DockingPositionDown", false);
Line Deleted : user_pref("extensions.helperbar.SmartbarDisabled", false);
Line Deleted : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Line Deleted : user_pref("extensions.helperbar.Visibility", false);
Line Deleted : user_pref("extensions.helperbar.backPageCapacity", 3);
Line Deleted : user_pref("extensions.helperbar.backPageCounter", 0);
Line Deleted : user_pref("extensions.helperbar.backPageDay", 30);
Line Deleted : user_pref("extensions.helperbar.backPageLastEvent", "1409234499688");
Line Deleted : user_pref("extensions.helperbar.backPageMinInterval", 15);
Line Deleted : user_pref("extensions.helperbar.barcodeid", "144150");
Line Deleted : user_pref("extensions.helperbar.countryiso", "ca");
Line Deleted : user_pref("extensions.helperbar.downloadprovider", "irssf");
Line Deleted : user_pref("extensions.helperbar.externalJsFiles", "{\"d\":\"[{\\\"ExcludeDomains\\\":[],\\\"hxxpInjection\\\":\\\"hxxp:\\\\\\/\\\\\\/az412617.vo.msecnd.net\\\\\\/scripts\\\\\\/crt.js\\\",\\\"hxxpsInje[...]
Line Deleted : user_pref("extensions.helperbar.fromautoupdate", "false");
Line Deleted : user_pref("extensions.helperbar.installationid", "f33c613b-851e-a627-440b-ac974e123ffc");
Line Deleted : user_pref("extensions.helperbar.installdate", "30/08/2014");
Line Deleted : user_pref("extensions.helperbar.iswinxp", "false");
Line Deleted : user_pref("extensions.helperbar.keepAliveLastevent", "1409407298");
Line Deleted : user_pref("extensions.helperbar.lastExternalJsUpdate", "1409692295797");
Line Deleted : user_pref("extensions.helperbar.publisher", "irssf");
Line Deleted : user_pref("extensions.skipscreen.hostMatchStr", "hxxp://www.4shared.com/(get|audio|file|document|dir)/.*|hxxp://.*depositfiles.com/(([a-z]{2})/files/|auth-).*|hxxp://(www.)*digg.com/(.{5}|.{6})$|hxxp:[...]
Line Deleted : user_pref("lightweightThemes.usedThemes", "[{\"id\":\"184622\",\"name\":\"spiderman crawler up\",\"headerURL\":\"hxxps://addons.mozilla.org/_files/144472/SpidermanCrawlerup.jpg?1271280036\",\"footerUR[...]

-\\ Google Chrome v37.0.2062.103

[ File : C:\Users\LANCE\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}

*************************

AdwCleaner[R0].txt - [5437 octets] - [03/09/2014 20:26:13]
AdwCleaner[R1].txt - [5268 octets] - [05/09/2014 16:39:07]
AdwCleaner[R2].txt - [5328 octets] - [05/09/2014 16:41:00]
AdwCleaner[S0].txt - [4220 octets] - [05/09/2014 16:42:19]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4280 octets] ##########
 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by LANCE on 05/09/2014 at 16:49:46.72
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ FireFox

Successfully deleted the following from C:\Users\LANCE\AppData\Roaming\mozilla\firefox\profiles\7riwwbxu.default\prefs.js

user_pref("extensions.skipscreen.hostMatchStr", "hxxp://www.4shared.com/(get|audio|file|document|dir)/.*|hxxp://.*depositfiles.com/(([a-z]{2})/files/|auth-).*|hxxp://(www.)*di
user_pref("services.sync.clients.syncID", "mgMV9DvIHv-2");
Emptied folder: C:\Users\LANCE\AppData\Roaming\mozilla\firefox\profiles\7riwwbxu.default\minidumps [28 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 05/09/2014 at 16:57:34.48
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 


  • 0

#14
dbreeze

dbreeze

    Trusted Helper

  • Malware Removal
  • 2,216 posts

Hi LANCE1313,

Thinks are looking good now and it's great to here the system is running better. Couple of second opinion scans and we should be in the ole' home stretch from there.

First>>>>
bf_new.gifMalwareBytes AntiMalware

I notice you already have version 1.7 of this installed. Please start the program by going to Start (Windows Orb) > All Programs > MalwareBytes AntiMalware > MalwareBytes AntiMalware. We only want a scan to see what it finds; the log will be examined to make sure there are no false positives or entries that might pose dangerous to remove.

  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The program will check for definition updates, download them and then start the scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Click on Save Logfile and save the file to your desktop.
  • Copy&Paste the entire report in your next reply.

You may want to come here and post the MBAM log before moving onto step 2.


Second>>>>

ESET Online Scanner:

Note: You will need to disable your current installed Anti-Virus for the duration of the online scan, how to do so can be read here. Also, please note that this scan can take a while to run.

  • Please go here to run the scan and click on Run ESET Online Scanner
  • abfacb96-0c99-4b59-b9e9-9298aa0ee3ec_zps
  • The next screen will be the ESET Online Scanner installer
  • Getinstallerpopup_zps569f8772.png
  • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer and select Save File
  • downloadsave_zpsb758563f.png
  • Save the file to your desktop; you should see a file like this when the download is finished
  • desktopfile_zps98a1ee89.png Double click on this to start the installation of the ESET Online Scanner
  • In the new window that appears select the option YES, I accept the Terms of Use then click on Start
  • TOU_zps4ecd3406.png
  • Now in the Computer scan settings window that appears:-
  • Make sure that the option Enable detection of potentially unwanted applications is selected.
  • Now click on Advanced Settings and configure the options as follows:
    • Remove found threats is Not checked
    • Scan archives is checked
    • Scan for potentially unsafe applications is checked
    • Enable Anti-Stealth Technology is checked
  • Now click on: Start
  • Loadsettings_2014-08-23_zps3f2d0c88.png
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • Downloadingsignatures_zps36c38587.png
  • When completed the Online Scan will begin automatically.
  • Scanningdisplay_zpsec3aac14.png
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed, if any malware was detected, the summary screen will show a warning.
  • Threatsfound_zpsfe95fb4e.png
  • On the Scan results detail window, select to Export to text file, name the file ESET scan results.txt and save it to your desktop.
  • Exporttotextfile_zps16cb487f.png
  • Click <<Back once the file is saved, select 'Uninstall application on close' and click on Finish.
  • UninstallcheckedandFinish_zps6fb26ad8.pn
  • Use Notepad to open the logfile you save on your desktop.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!


  • 0

#15
LANCE1313

LANCE1313

    Member

  • Topic Starter
  • Member
  • PipPip
  • 42 posts

Step 1

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 09/09/2014
Scan Time: 8:05:51 PM
Logfile: malwarebytes.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.09.09.07
Rootkit Database: v2014.08.21.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: LANCE

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 349525
Time Elapsed: 10 min, 37 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 1
PUP.Optional.Snapdo.T, HKU\S-1-5-21-2552895503-36244919-2108235947-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, , [9b00effcc8b341f53f5318a4768c49b7],

Registry Values: 0
(No malicious items detected)

Registry Data: 6
PUP.Optional.SafeFinder.A, HKU\S-1-5-21-2552895503-36244919-2108235947-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://feed.safefind...Qp4CtkJPsHJj1Eg, Good: (www.google.com), Bad: (http://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9howjcx7fZ0FW0FE0MeOOoZRxBPJEUsk-wpxHmB3CTiJ1nKG5c7zeDTgKQ7Ogd3N9Y1Lg9drO5_rPZZzRd0qYXWCc8vv0EK9znlBTsQV6jMzVXBkR2sd1TQ0vYUQjmFgWWtTQ_1sr9GauGrGFoMjjvQp4CtkJPsHJj1Eg,),,[306b9f4c156662d488baa8437193629e]
PUP.Optional.SafeFinder.A, HKU\S-1-5-21-2552895503-36244919-2108235947-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, http://feed.safefind...u6721ChbSA,,&q={searchTerms}, Good: (www.google.com), Bad: (http://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9howjcx7fZ0FW0FE0MeOOoZRxBPJEUsk-wpxHmB3CTiJ1nKG5c7zeDTgKQ7Ogd3N9Y1Lg9drO5_rPZZzRuT8eTPEaYy76HQTcnLyJ-HJP1OsSFx-MZoUgdqpvfLxocVtlrsBioiJTzm2v3ukSFscWH28gaHu6721ChbSA,,&q={searchTerms}),,[72295695b5c6d5611433b536f50fca36]
PUP.Optional.SafeFinder.A, HKU\S-1-5-21-2552895503-36244919-2108235947-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://feed.safefind...u6721ChbSA,,&q={searchTerms}, Good: (www.google.com), Bad: (http://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9howjcx7fZ0FW0FE0MeOOoZRxBPJEUsk-wpxHmB3CTiJ1nKG5c7zeDTgKQ7Ogd3N9Y1Lg9drO5_rPZZzRuT8eTPEaYy76HQTcnLyJ-HJP1OsSFx-MZoUgdqpvfLxocVtlrsBioiJTzm2v3ukSFscWH28gaHu6721ChbSA,,&q={searchTerms}),,[a8f38f5cb8c38fa71431b9324fb557a9]
PUP.Optional.SafeFinder.A, HKU\S-1-5-21-2552895503-36244919-2108235947-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, http://feed.safefind...u6721ChbSA,,&q={searchTerms}, Good: (www.google.com), Bad: (http://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9howjcx7fZ0FW0FE0MeOOoZRxBPJEUsk-wpxHmB3CTiJ1nKG5c7zeDTgKQ7Ogd3N9Y1Lg9drO5_rPZZzRuT8eTPEaYy76HQTcnLyJ-HJP1OsSFx-MZoUgdqpvfLxocVtlrsBioiJTzm2v3ukSFscWH28gaHu6721ChbSA,,&q={searchTerms}),,[9803c724aecdcf67103ab13a58ac748c]
PUP.Optional.SafeFinder.A, HKU\S-1-5-21-2552895503-36244919-2108235947-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, http://feed.safefind...u6721ChbSA,,&q={searchTerms}, Good: (www.google.com), Bad: (http://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9howjcx7fZ0FW0FE0MeOOoZRxBPJEUsk-wpxHmB3CTiJ1nKG5c7zeDTgKQ7Ogd3N9Y1Lg9drO5_rPZZzRuT8eTPEaYy76HQTcnLyJ-HJP1OsSFx-MZoUgdqpvfLxocVtlrsBioiJTzm2v3ukSFscWH28gaHu6721ChbSA,,&q={searchTerms}),,[6a31717a443739fd9bb04e9dd72d0bf5]
PUP.Optional.SafeFinder.A, HKU\S-1-5-21-2552895503-36244919-2108235947-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, http://feed.safefind...u6721ChbSA,,&q={searchTerms}, Good: (www.google.com), Bad: (http://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9howjcx7fZ0FW0FE0MeOOoZRxBPJEUsk-wpxHmB3CTiJ1nKG5c7zeDTgKQ7Ogd3N9Y1Lg9drO5_rPZZzRuT8eTPEaYy76HQTcnLyJ-HJP1OsSFx-MZoUgdqpvfLxocVtlrsBioiJTzm2v3ukSFscWH28gaHu6721ChbSA,,&q={searchTerms}),,[138820cb4338b87eb796a9428a7a4cb4]

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP