Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Stormfall (and other?) ad window popping up in Chrome [Solved]

stormfall adware camstudio chrome

  • This topic is locked This topic is locked

#1
drmomentum

drmomentum

    Member

  • Member
  • PipPip
  • 12 posts

Hi,

 

I installed Camstudio free screen recording software the other day in the hopes of using it to create a tutorial, and along the way it appears to have given me a case of the adwares.

 

Specifically, it has installed a Stormfall -- adware that opens an unwanted window in Chrome. I'm sure you're familiar.

 

I thought I would ask the knowledgeable people here for assistance before mucking it up myself. There may be other unwanted things I haven't noticed yet.

I have several start up programs I run intentionally, including Pushbullet, PhraseExpress, and Garmin software. I am running 

avast! antivirus.

 

Thank you for any help you might be able to provide.

 

-James

 

Here is the quick scan log from OTL:

 

 

OTL logfile created on: 9/25/2014 6:30:33 AM - Run 2
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\James\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16521)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
11.98 Gb Total Physical Memory | 3.67 Gb Available Physical Memory | 30.62% Memory free
23.96 Gb Paging File | 9.64 Gb Available in Paging File | 40.25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.51 Gb Total Space | 460.33 Gb Free Space | 49.42% Space Free | Partition Type: NTFS
Drive E: | 232.88 Gb Total Space | 138.05 Gb Free Space | 59.28% Space Free | Partition Type: NTFS
 
Computer Name: EDO | User Name: James | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/09/25 06:06:39 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\James\Desktop\OTL.exe
PRC - [2014/09/23 23:30:48 | 006,621,752 | ---- | M] (Spotify Ltd) -- C:\Users\James\AppData\Roaming\Spotify\spotify.exe
PRC - [2014/09/23 23:30:45 | 000,610,872 | ---- | M] () -- C:\Users\James\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
PRC - [2014/09/13 13:49:29 | 001,465,616 | ---- | M] (SanDisk Corporation) -- C:\Users\James\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
PRC - [2014/09/12 20:52:04 | 036,414,624 | ---- | M] (Dropbox, Inc.) -- C:\Users\James\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2014/09/08 03:40:53 | 000,156,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Zotero Standalone\zotero.exe
PRC - [2014/08/28 14:53:44 | 000,822,320 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\pushbullet_app.exe
PRC - [2014/08/28 11:06:02 | 000,043,336 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\ATH.exe
PRC - [2014/08/26 16:47:14 | 001,110,880 | ---- | M] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) -- C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
PRC - [2014/08/14 16:48:01 | 004,085,896 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2014/08/14 16:47:46 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014/08/07 08:52:52 | 000,438,616 | ---- | M] (Garmin Ltd or its subsidiaries) -- C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
PRC - [2014/07/31 12:15:54 | 000,043,816 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
PRC - [2014/07/29 14:24:46 | 000,043,336 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
PRC - [2014/07/22 18:23:04 | 007,631,872 | ---- | M] (Google Inc.) -- C:\Users\James\AppData\Local\Programs\Google\MusicManager\MusicManager.exe
PRC - [2014/07/22 16:46:06 | 003,356,480 | ---- | M] () -- C:\Users\James\AppData\Local\Amazon Music\Amazon Music Helper.exe
PRC - [2014/07/22 16:39:51 | 009,449,280 | ---- | M] (Amazon) -- C:\Users\James\AppData\Local\Amazon Music\Amazon Music.exe
PRC - [2014/07/17 21:04:38 | 000,051,016 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome Remote Desktop\37.0.2062.28\remoting_host.exe
PRC - [2014/06/21 12:34:14 | 000,230,792 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
PRC - [2014/06/17 17:56:02 | 000,242,216 | ---- | M] (Foxit Corporation) -- C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
PRC - [2014/04/08 13:47:10 | 000,096,320 | ---- | M] (Foxit Corporation) -- C:\Program Files (x86)\Foxit Software\Foxit Reader\Shell Extensions\FoxitPrevhost.exe
PRC - [2013/12/21 02:04:50 | 003,478,392 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
PRC - [2013/12/18 14:42:32 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/12/09 16:01:58 | 000,881,440 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
PRC - [2013/10/15 19:06:12 | 001,016,712 | ---- | M] (Flux Software LLC) -- C:\Users\James\AppData\Local\FluxSoftware\Flux\flux.exe
PRC - [2013/06/14 11:42:16 | 014,125,776 | ---- | M] (Bartels Media GmbH) -- C:\Program Files (x86)\PhraseExpress\phraseexpress.exe
PRC - [2012/12/20 03:24:24 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012/07/16 20:09:04 | 000,046,080 | ---- | M] (TechSmith Corporation) -- C:\Program Files (x86)\TechSmith\Camtasia Studio 8\TscHelp.exe
PRC - [2012/02/20 15:54:08 | 001,666,560 | ---- | M] (AimerSoft) -- C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
PRC - [2011/10/27 18:56:35 | 000,470,528 | ---- | M] (Livescribe) -- C:\Program Files (x86)\Common Files\Livescribe\PenComm\PenCommService.exe
PRC - [2010/09/15 15:01:20 | 000,065,536 | ---- | M] () -- C:\Program Files (x86)\Brother\BRAdmin Professional 3\bratimer.exe
PRC - [2010/04/12 13:46:14 | 009,520,472 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\Canon\MP Navigator EX 4.0\mpnex40.exe
PRC - [2010/04/02 10:18:54 | 001,185,112 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
PRC - [2009/11/30 18:04:48 | 000,192,512 | ---- | M] () -- C:\Program Files (x86)\FarStone\TotalRecovery\Client\CBP\DCSchdler.exe
PRC - [2009/11/26 18:24:12 | 000,077,824 | ---- | M] () -- C:\Program Files (x86)\FarStone\TotalRecovery\Client\DCNTranProc.exe
PRC - [2009/06/30 21:24:46 | 000,762,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\vVX3000.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/09/23 23:30:48 | 036,966,968 | ---- | M] () -- C:\Users\James\AppData\Roaming\Spotify\Data\libcef.dll
MOD - [2014/09/23 23:30:47 | 000,108,600 | ---- | M] () -- C:\Users\James\AppData\Roaming\Spotify\Data\libEGL.dll
MOD - [2014/09/23 23:30:46 | 000,886,840 | ---- | M] () -- C:\Users\James\AppData\Roaming\Spotify\Data\libGLESv2.dll
MOD - [2014/09/23 23:30:46 | 000,867,896 | ---- | M] () -- C:\Users\James\AppData\Roaming\Spotify\Data\ffmpegsumo.dll
MOD - [2014/09/23 23:30:45 | 000,610,872 | ---- | M] () -- C:\Users\James\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
MOD - [2014/09/17 22:52:34 | 000,043,008 | ---- | M] () -- c:\Users\James\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpxn8vh2.dll
MOD - [2014/09/12 20:20:58 | 003,610,624 | ---- | M] () -- C:\Users\James\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
MOD - [2014/09/08 03:40:55 | 003,711,392 | ---- | M] () -- C:\Program Files (x86)\Zotero Standalone\xulrunner\mozjs.dll
MOD - [2014/08/28 14:53:44 | 000,822,320 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\pushbullet_app.exe
MOD - [2014/08/26 16:47:16 | 000,436,576 | ---- | M] () -- C:\Program Files (x86)\Evernote\Evernote\libxml2.dll
MOD - [2014/08/26 16:47:16 | 000,318,304 | ---- | M] () -- C:\Program Files (x86)\Evernote\Evernote\libtidy.dll
MOD - [2014/08/14 16:47:46 | 019,329,904 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014/08/14 16:47:46 | 000,301,152 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\aswProperty.dll
MOD - [2014/07/22 18:02:06 | 000,253,440 | ---- | M] () -- C:\Users\James\AppData\Local\Programs\Google\MusicManager\libid3tag.dll
MOD - [2014/07/22 18:01:32 | 000,231,936 | ---- | M] () -- C:\Users\James\AppData\Local\Programs\Google\MusicManager\libmpgdec.dll
MOD - [2014/07/22 18:01:28 | 000,117,248 | ---- | M] () -- C:\Users\James\AppData\Local\Programs\Google\MusicManager\libaacdec.dll
MOD - [2014/07/22 18:01:24 | 000,344,064 | ---- | M] () -- C:\Users\James\AppData\Local\Programs\Google\MusicManager\libaudioenc.dll
MOD - [2014/07/22 16:46:06 | 003,356,480 | ---- | M] () -- C:\Users\James\AppData\Local\Amazon Music\Amazon Music Helper.exe
MOD - [2014/07/22 16:21:12 | 001,348,608 | ---- | M] () -- C:\Users\James\AppData\Local\Amazon Music\tag.dll
MOD - [2014/07/22 16:21:12 | 000,880,128 | ---- | M] () -- C:\Users\James\AppData\Local\Amazon Music\libGLESv2.dll
MOD - [2014/07/22 16:21:11 | 038,700,544 | ---- | M] () -- C:\Users\James\AppData\Local\Amazon Music\libcef.dll
MOD - [2014/07/22 16:21:11 | 000,102,400 | ---- | M] () -- C:\Users\James\AppData\Local\Amazon Music\libEGL.dll
MOD - [2014/07/12 14:10:22 | 000,026,624 | ---- | M] () -- C:\Users\James\AppData\Local\Programs\Google\MusicManager\imageformats\qgif4.dll
MOD - [2014/07/12 14:10:14 | 010,683,392 | ---- | M] () -- C:\Users\James\AppData\Local\Programs\Google\MusicManager\QtWebKit4.dll
MOD - [2014/07/12 14:10:12 | 007,741,952 | ---- | M] () -- C:\Users\James\AppData\Local\Programs\Google\MusicManager\QtGui4.dll
MOD - [2014/07/12 14:10:12 | 001,681,408 | ---- | M] () -- C:\Users\James\AppData\Local\Programs\Google\MusicManager\QtNetwork4.dll
MOD - [2014/07/12 14:10:10 | 002,248,192 | ---- | M] () -- C:\Users\James\AppData\Local\Programs\Google\MusicManager\QtCore4.dll
MOD - [2014/04/30 06:56:04 | 000,050,176 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\gevent._semaphore.pyd
MOD - [2014/04/30 06:55:56 | 000,208,384 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\gevent.core.pyd
MOD - [2014/01/26 09:49:20 | 000,167,936 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\win32gui.pyd
MOD - [2014/01/26 09:49:18 | 000,099,328 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\win32api.pyd
MOD - [2014/01/26 09:48:52 | 000,110,592 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\pywintypes27.dll
MOD - [2014/01/20 14:17:04 | 000,073,544 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2014/01/20 14:16:40 | 000,237,384 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
MOD - [2014/01/20 14:16:38 | 001,044,808 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2014/01/07 08:09:08 | 000,019,456 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\greenlet.pyd
MOD - [2014/01/04 14:29:56 | 000,733,184 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\wx._misc_.pyd
MOD - [2014/01/04 14:29:48 | 001,067,520 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\wx._controls_.pyd
MOD - [2014/01/04 14:29:38 | 000,815,616 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\wx._windows_.pyd
MOD - [2014/01/04 14:29:30 | 000,806,400 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\wx._gdi_.pyd
MOD - [2014/01/04 14:29:10 | 001,176,576 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\wx._core_.pyd
MOD - [2013/12/21 02:04:26 | 003,989,888 | ---- | M] () -- C:\Program Files (x86)\Adobe\Acrobat 11.0\PDFMaker\Common\AdobePDFMakerX.dll
MOD - [2013/11/10 19:24:54 | 000,899,584 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\_ssl.pyd
MOD - [2013/11/10 19:24:52 | 000,358,400 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\_hashlib.pyd
MOD - [2013/11/10 19:24:34 | 000,010,240 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\select.pyd
MOD - [2013/11/10 19:24:32 | 000,087,552 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\_ctypes.pyd
MOD - [2013/11/10 19:24:28 | 000,047,616 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\_sqlite3.pyd
MOD - [2013/11/10 19:24:26 | 000,044,544 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\_socket.pyd
MOD - [2013/11/10 19:24:24 | 000,686,080 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\unicodedata.pyd
MOD - [2013/11/10 19:23:44 | 000,426,496 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\sqlite3.dll
MOD - [2013/08/23 15:01:44 | 025,100,288 | ---- | M] () -- C:\Users\James\AppData\Roaming\Dropbox\bin\libcef.dll
MOD - [2013/08/07 15:25:24 | 000,093,696 | ---- | M] () -- C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
MOD - [2013/07/10 19:07:22 | 000,756,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL
MOD - [2013/06/14 11:42:12 | 000,442,064 | ---- | M] () -- C:\Program Files (x86)\PhraseExpress\pexlang.dll
MOD - [2012/06/04 11:03:48 | 000,603,136 | ---- | M] () -- C:\Program Files (x86)\Pushbullet\pysqlite2._sqlite.pyd
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2014/08/14 16:47:46 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2014/03/11 12:34:10 | 000,347,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2014/03/11 12:34:10 | 000,023,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2014/03/01 00:33:34 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013/05/27 01:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2012/12/19 15:56:00 | 000,240,640 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2012/12/16 07:25:38 | 000,123,664 | ---- | M] (SANDBOXIE L.T.D) [Auto | Running] -- C:\Program Files\Sandboxie\SbieSvc.exe -- (SbieSvc)
SRV:64bit: - [2011/06/29 07:34:16 | 000,311,296 | ---- | M] (WDC) [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe -- (WDDMService)
SRV:64bit: - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/05/20 15:26:28 | 000,199,536 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft LifeCam\MSCamS64.exe -- (MSCamSvc)
SRV:64bit: - [2009/07/13 21:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2014/09/24 01:44:08 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/08/25 01:04:38 | 002,175,264 | ---- | M] (IObit) [Auto | Stopped] -- C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe -- (LiveUpdateSvc)
SRV - [2014/08/22 20:06:42 | 000,833,728 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2014/08/10 16:37:03 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/08/07 08:52:52 | 000,438,616 | ---- | M] (Garmin Ltd or its subsidiaries) [Auto | Running] -- C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe -- (Garmin Core Update Service)
SRV - [2014/07/17 21:04:38 | 000,051,016 | ---- | M] (Google Inc.) [Auto | Running] -- C:\Program Files (x86)\Google\Chrome Remote Desktop\37.0.2062.28\remoting_host.exe -- (chromoting)
SRV - [2014/06/17 17:56:02 | 000,242,216 | ---- | M] (Foxit Corporation) [Auto | Running] -- C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe -- (FoxitCloudUpdateService)
SRV - [2013/12/18 14:42:32 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/12/09 16:01:58 | 000,881,440 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe -- (AdvancedSystemCareService7)
SRV - [2013/09/11 21:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2012/12/20 03:24:24 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2011/10/27 18:56:35 | 000,470,528 | ---- | M] (Livescribe) [Auto | Running] -- C:\Program Files (x86)\Common Files\Livescribe\PenComm\PenCommService.exe -- (PenCommService)
SRV - [2010/11/20 23:24:51 | 000,397,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS)
SRV - [2010/11/20 23:24:51 | 000,397,824 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (W3SVC)
SRV - [2010/11/20 23:24:51 | 000,061,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc)
SRV - [2010/09/15 15:01:20 | 000,065,536 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Brother\BRAdmin Professional 3\bratimer.exe -- (BRA_Scheduler)
SRV - [2010/01/11 15:13:20 | 000,086,016 | ---- | M] (Farstone Technology Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\FarStone\TotalRecovery\Client\Efb\FBPAgent.exe -- (FBAgent)
SRV - [2009/11/26 18:24:30 | 000,104,976 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\FarStone\TotalRecovery\Client\CBP\DCSchdlerSRVC.exe -- (DCScheduler)
SRV - [2009/11/26 18:24:12 | 000,077,824 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\FarStone\TotalRecovery\Client\DCNTranProc.exe -- (Tran_Process_Proc)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014/08/14 16:47:59 | 000,427,360 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswsp.sys -- (aswSP)
DRV:64bit: - [2014/08/14 16:47:48 | 001,041,168 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2014/08/14 16:47:48 | 000,224,896 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2014/08/14 16:47:48 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2014/08/14 16:47:48 | 000,092,008 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
DRV:64bit: - [2014/08/14 16:47:48 | 000,079,184 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2014/08/14 16:47:48 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2014/08/14 16:47:48 | 000,029,208 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:64bit: - [2014/07/28 14:52:00 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2014/03/11 09:52:30 | 000,133,928 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2013/11/25 13:03:00 | 000,413,888 | ---- | M] (EldoS Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\cbfs5.sys -- (cbfs5)
DRV:64bit: - [2013/05/19 13:10:05 | 000,231,376 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\truecrypt.sys -- (truecrypt)
DRV:64bit: - [2013/02/06 07:42:10 | 000,203,544 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:64bit: - [2013/02/06 07:42:08 | 000,102,936 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2012/12/19 16:48:48 | 011,278,336 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012/12/19 15:32:54 | 000,552,960 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012/12/16 07:25:34 | 000,202,632 | ---- | M] (SANDBOXIE L.T.D) [Kernel | On_Demand | Running] -- C:\Program Files\Sandboxie\SbieDrv.sys -- (SbieDrv)
DRV:64bit: - [2012/12/15 09:02:34 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012/12/15 09:02:34 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2012/12/15 09:02:34 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/11/06 07:11:52 | 000,096,256 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/04/18 15:05:16 | 000,019,304 | ---- | M] (GARMIN Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\grmnusb.sys -- (grmnusb)
DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/08/15 14:32:10 | 000,146,736 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys -- (VBoxNetAdp)
DRV:64bit: - [2011/08/11 18:04:17 | 000,026,112 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\PulseUsb.sys -- (PulseUsb)
DRV:64bit: - [2011/08/01 15:59:06 | 000,045,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)
DRV:64bit: - [2011/07/28 18:37:10 | 000,052,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d)
DRV:64bit: - [2011/04/26 11:07:36 | 000,557,848 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/03/07 12:01:44 | 000,313,136 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mvs91xx.sys -- (mvs91xx)
DRV:64bit: - [2011/03/07 12:01:44 | 000,024,880 | ---- | M] (Marvell Semiconductor Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mv91cons.sys -- (mv91cons)
DRV:64bit: - [2011/01/26 14:53:12 | 000,052,304 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\megasas2.sys -- (megasas2)
DRV:64bit: - [2010/11/20 23:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 09:34:04 | 000,360,832 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcvmm.sys -- (vpcvmm)
DRV:64bit: - [2010/11/20 09:34:04 | 000,194,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpchbus.sys -- (vpcbus)
DRV:64bit: - [2010/11/20 07:35:34 | 000,095,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpcusb.sys -- (vpcusb)
DRV:64bit: - [2010/11/20 07:35:26 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpcuxd.sys -- (vpcuxd)
DRV:64bit: - [2010/11/20 07:35:22 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcnfltr.sys -- (vpcnfltr)
DRV:64bit: - [2010/11/18 08:10:00 | 000,090,296 | R--- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2010/11/15 07:05:02 | 000,364,520 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\asmtxhci.sys -- (asmtxhci)
DRV:64bit: - [2010/11/15 07:05:00 | 000,121,832 | ---- | M] (ASMedia Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\asmthub3.sys -- (asmthub3)
DRV:64bit: - [2010/10/25 23:08:08 | 000,406,632 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010/10/19 16:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010/08/27 13:53:22 | 000,297,000 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mv91xx.sys -- (mv91xx)
DRV:64bit: - [2010/06/14 17:09:18 | 000,465,488 | ---- | M] (LSI Corporation, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\MegaSR1.sys -- (MegaSR1)
DRV:64bit: - [2010/04/26 21:30:52 | 000,184,968 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2010/04/26 21:29:54 | 000,083,080 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2010/04/13 16:08:00 | 000,340,008 | ---- | M] (Silicon Image, Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Si3124r5.sys -- (Si3124r5)
DRV:64bit: - [2010/04/13 16:08:00 | 000,022,568 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SiWinAcc.sys -- (SiFilter)
DRV:64bit: - [2010/04/13 16:08:00 | 000,016,936 | ---- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SiRemFil.sys -- (SiRemFil)
DRV:64bit: - [2009/11/26 18:26:16 | 000,023,056 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\FarMntIo.sys -- (FARMNTIO)
DRV:64bit: - [2009/11/26 18:25:16 | 000,091,152 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\dcsnap.sys -- (dcsnap)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 20:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2009/06/30 21:24:50 | 002,060,144 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VX3000.sys -- (VX3000)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2008/12/17 22:46:12 | 000,533,760 | ---- | M] (Digital Camera) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\Ca1528av.sys -- (Ca1528av)
DRV:64bit: - [2008/06/28 23:43:02 | 000,014,848 | ---- | M] (SunPlus) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Bulk1528.sys -- (Bulk1528)
DRV:64bit: - [2008/05/06 16:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
DRV:64bit: - [2007/12/19 17:44:44 | 000,209,424 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ahcix64s.sys -- (ahcix64s)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.velocitymicro.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?...l_date=20110823
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.velocitymicro.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {502F4341-15D2-4A62-BD9E-F45E914211BE}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IESR02
IE - HKCU\..\SearchScopes\{502F4341-15D2-4A62-BD9E-F45E914211BE}: "URL" = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\..\SearchScopes\{63140ECF-C629-BE59-8F0E-90B4FF340C03}: "URL" = http://www.bing.com/...eferrer:source}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...Box&FORM=IESR02
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig"
FF - prefs.js..extensions.enabledAddons: autofillForms%40blueimp.net:0.9.9.0
FF - prefs.js..extensions.enabledAddons: zoteroWinWordIntegration%40zotero.org:3.1.16
FF - prefs.js..extensions.enabledAddons: isreaditlater%40ideashower.com:3.0.5
FF - prefs.js..extensions.enabledAddons: zotero%40chnm.gmu.edu:4.0.21.5
FF - prefs.js..extensions.enabledAddons: ascsurfingprotection%40iobit.com:1.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:31.0
FF - prefs.js..keyword.URL: "http://www.bing.com/...te=20110823&q="
 
FF - user.js..extensions.enabledAddons: [email protected]:0.9.8.3
FF - user.js..extensions.enabledAddons: [email protected]:6.0.1367
FF - user.js..extensions.enabledAddons: [email protected]:3.0.3
FF - user.js..extensions.enabledAddons: [email protected]:3.1.6
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_39: C:\Windows\system32\npdeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files (x86)\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Plus Web Player Plug-In,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.60.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.60.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.8:  File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.1:  File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.2:  File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.3:  File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\@doubletwist.com/NPPodcast: C:\Program Files (x86)\Common Files\doubleTwist\NPPodcast.dll File not found
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\James\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\James\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\James\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\James\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\James\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101710.dll (Amazon.com, Inc.)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2014/08/14 16:47:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Virtual Account Numbers [2013/07/08 08:43:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013/07/09 11:48:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2014/03/24 21:33:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 31.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014/08/10 16:36:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 31.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Waterfox 18.0.1\extensions\\Components: C:\Program Files\\Waterfox\components [2014/07/19 20:19:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Waterfox 18.0.1\extensions\\Plugins: C:\Program Files\\Waterfox\plugins [2014/07/19 20:19:30 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 31.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014/08/10 16:36:58 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 31.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
 
[2011/09/03 12:47:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\James\AppData\Roaming\Mozilla\Extensions
[2011/09/03 12:47:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\James\AppData\Roaming\Mozilla\Extensions\[email protected]
[2014/08/19 16:55:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\extensions
[2014/01/23 20:14:08 | 000,000,000 | ---D | M] (Advanced SystemCare Surfing Protection) -- C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\extensions\[email protected]
[2012/12/14 10:53:29 | 000,000,000 | ---D | M] (Free Download Manager plugin) -- C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\extensions\[email protected]
[2014/07/08 16:54:16 | 000,000,000 | ---D | M] (Pocket) -- C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\extensions\[email protected]
[2014/06/22 11:09:25 | 000,000,000 | ---D | M] (Zotero Word for Windows Integration) -- C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\extensions\[email protected]
[2013/01/06 13:20:02 | 000,149,045 | ---- | M] () (No name found) -- C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\extensions\[email protected]
[2014/08/19 16:55:23 | 004,221,812 | ---- | M] () (No name found) -- C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\extensions\[email protected]
[2014/07/08 16:54:16 | 005,564,713 | ---- | M] () (No name found) -- C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\extensions\[email protected]
[2011/01/31 03:03:10 | 000,011,787 | ---- | M] () (No name found) -- C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\zotero\storage\AG2A9WAZ\[email protected]
[2014/08/07 00:35:56 | 000,552,060 | ---- | M] () (No name found) -- C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\zotero\storage\H4MCH5WQ\Karp et al_2014_13 Rules That Expire.pdf
[2011/08/22 22:47:04 | 000,001,945 | ---- | M] () -- C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\searchplugins\bing-zugo.xml
[2014/08/10 16:36:58 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/08/10 16:37:04 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
 
========== Chrome  ==========
 
CHR - default_search_provider:  (Enabled)
CHR - default_search_provider: search_url = 
CHR - default_search_provider: suggest_url = 
CHR - plugin: Error reading preferences file
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif\6.7.9.2_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\3.4.9_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\alelhddbbhepgpmgidjdcjakblofbmce\3.7.17_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\2.5.16_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj\3.0.2.2_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd\14.826.0.6_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\bocmleclimfnadgmcdgecijlblfcmfnm\1.20_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdonhidhobjahdhlcegfakicbcgnkokh\1.3.2_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekbgkmeapobkbadclnkjfjdbpbcaobd\0.31_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.8.5_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgmnfnmlficgeijcalkgnnkigkefkbhd\1.6.2_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\chlffgpmiacpedhhbkiomidkjlcfhogd\112_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ciagpekplgpbepdgggflgmahnjgiaced\1.0.0.10_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmfcdkambpljcndgdmaccaagladfnepa\0.1.0_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddpephnhacfpgcemhioaejgenlgadnnh\1.4.0_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkigkllnlkoblfbgfnfngfcnhmndonjm\10.1.2_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn\4.5.3_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekhagklcjbdpajgpjgmbionohlpdbjgc\4.0.21_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi\1.235.2_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi\1.236.0_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp\37.0.2062.61_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl\1.1.4_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\hejjjnnbamjillkkomahknangbpjfdpd\1.0.2_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhfkcobomkalfdlmkongnhnhahkmnaad\1.1.3_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjdoplcnndgiblooccencgcggcoihigg\1.0.7_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkhggnncdpfibdhinjiegagmopldibha\17.4.16_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlkkjgfbfgdcdjnddamlmgbipgbhgppk\1.2_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki\2.0.14385.564_1\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\iabeihobmhlgpkcgjiloemdbofjbdcic\2.0.132_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\iblijlcdoidgdpfknkckljiocdbnlagk\0.7.8_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd\1.7.0.1_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\icppfcnhkcmnfdhfhphakoifcfokfdhg\5.3_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\iggpfpnahkgpnindfkdncknoldgnccdg\5.2.1_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\imlbbglginccpmlaekkdnleoachjadka\3.1_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\immpkjjlgappgfkkfieppnmlhakdmaab\0.9.8.14_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeoacafpbcihiomhlakheieifhpjdfeo\5.18.15_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkkenjlnjfemconejajakbijbheoffli\0.2.7.32_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb\4.5.1_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcnhkahnjcbndmmehfkdnkjomaanaooo\2.4.4_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\kghdjdlccddmkepckhfgjdeohkcabahl\3.4_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\klbibkeccnjlkjkiokjodocebajanakg\4.74_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\laankejkbhbdhmipfmgcngdelahlfoji\1.5.5_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade\1.5_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\lghjfnfolmcikomdjmoiemllfnlmmoko\3.9.45_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\3.1_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcceagdollnkjlogmdckgjakjapmkdjf\4.0.0.2_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\mllceaiaedaingchlgolnfiibippgkmj\0.7.1_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb\1.1.10_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\nckgahadagoaajjgafhacjanaoiihapd\2014.910.433.1_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj\1.9.3_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\njhgeimnepehieioinbhmfpphfoocmng\2.5.1109.21_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\nknebiagdodnminbdpflhpkgfpeijdbf\1.0_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco\2.3.3_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocnieghejiknjhadhngmmnbfjocbbfpm\0.9.5.0_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\oeopbcgkkoapgobdbedcemjljbihmemj\17.2.7_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg\6.7.1_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg\6.7_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ompiailgknfdndiefoaoiligalphfdae\2.6.7_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb\6.2.2_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp\8.6_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgphcomnlaojlmmcjmiddhdapjpbgeoc\1.16_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc\6.2.4_0\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
CHR - Extension: No name found = C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppcocpoeoiajndepaaimnnglicichmbb\1.2_0\
 
O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (ExplorerWnd Helper) - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)
O2:64bit: - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2:64bit: - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Adobe Acrobat Create PDF Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2:64bit: - BHO: (Adobe Acrobat Create PDF from Selection) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Virtual Account Numbers Helper) - {17424104-1444-4810-85D7-B4DA413C5A9A} - C:\Program Files (x86)\Virtual Account Numbers\CitiVANHelper.dll (Orbiscom Ltd. All rights reserved.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Evernote extension) - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
O2 - BHO: (Adobe Acrobat Create PDF Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Advanced SystemCare Browser Protection) - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Adobe Acrobat Create PDF from Selection) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (no name) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (Adobe Acrobat Create PDF Toolbar) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (no name) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe Acrobat Create PDF Toolbar) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Virtual Account Numbers) - {7A21A046-B886-4A62-9D69-EF2059B0A27B} - C:\Program Files (x86)\Virtual Account Numbers\CitiVANToolbar.dll (Orbiscom Ltd. All rights reserved.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Adobe Acrobat Create PDF Toolbar) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe Acrobat Create PDF Toolbar) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [Bitcasa] C:\Program Files\Bitcasa\BitcasaBoot.exe ()
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [VX3000] C:\Windows\vVX3000.exe (Microsoft Corporation)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Aimersoft Helper Compact.exe] C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe (AimerSoft)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [KeePass 2 PreLoad] C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe (Dominik Reichl)
O4 - HKLM..\Run: [LifeCam] C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Virtual Account Numbers] C:\Program Files (x86)\Virtual Account Numbers\CitiVAN.exe (Orbiscom Ltd. All rights reserved.)
O4 - HKCU..\Run: [Advanced SystemCare 7] C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe (IObit)
O4 - HKCU..\Run: [Amazon Music] C:\Users\James\AppData\Local\Amazon Music\Amazon Music Helper.exe ()
O4 - HKCU..\Run: [DE24DAEE86D33FB70CF774307B0E31290C5D8D40._service_run] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKCU..\Run: [f.lux] C:\Users\James\AppData\Local\FluxSoftware\Flux\flux.exe (Flux Software LLC)
O4 - HKCU..\Run: [GarminExpressTrayApp] C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe (Garmin Ltd or its subsidiaries)
O4 - HKCU..\Run: [Google+ Auto Backup] C:\Users\James\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe (Google Inc.)
O4 - HKCU..\Run: [GoogleChromeAutoLaunch_6B06BCEFC97BCF192292AD16DB5D7A73] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKCU..\Run: [MusicManager] C:\Users\James\AppData\Local\Programs\Google\MusicManager\MusicManager.exe (Google Inc.)
O4 - HKCU..\Run: [Pushbullet] C:\Program Files (x86)\Pushbullet\pushbullet_app.exe ()
O4 - HKCU..\Run: [SansaDispatch] C:\Users\James\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\James\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKCU..\Run: [uTorrent] C:\Users\James\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
O4 - HKCU..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - Startup: C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\James\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
O4 - Startup: C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iSyncr.lnk = C:\Users\James\AppData\Roaming\Microsoft\Installer\{8E1F956D-631A-4146-B893-185E150D5BBD}\_C1F574CEC66419C15C9588.exe ()
O4 - Startup: C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Vitamin D Video.exe - Shortcut.lnk = C:\Program Files (x86)\Vitamin D Video\Vitamin D Video.exe (Vitamin D Video, LLC)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Clip bookmark - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=0 File not found
O8:64bit: - Extra context menu item: Clip image - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=4 File not found
O8:64bit: - Extra context menu item: Clip selection - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=3 File not found
O8:64bit: - Extra context menu item: Clip this page - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=1 File not found
O8:64bit: - Extra context menu item: Clip URL - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0 File not found
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: New note - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\NewNote.html ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Clip bookmark - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=0 File not found
O8 - Extra context menu item: Clip image - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=4 File not found
O8 - Extra context menu item: Clip selection - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=3 File not found
O8 - Extra context menu item: Clip this page - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=1 File not found
O8 - Extra context menu item: Clip URL - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0 File not found
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: New note - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\NewNote.html ()
O9:64bit: - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\AddNote.html ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIERes\AddNote.html ()
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html ()
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\OLIEResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.60.2)
O16 - DPF: {CAFEEFAC-0017-0000-0060-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_60)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_60)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{69A6B4E3-74A8-4473-918A-F3483A973E48}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: EldosMountNotificator-cbfs5 - {F09F617B-6C64-47D1-92DF-E6D7F57DE3BA} - C:\Windows\SysNative\cbfsMntNtf5.dll (EldoS Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: EldosMountNotificator-cbfs5 - {F09F617B-6C64-47D1-92DF-E6D7F57DE3BA} - C:\Windows\SysWOW64\cbfsMntNtf5.dll (EldoS Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O22:64bit: - SharedTaskScheduler: {F09F617B-6C64-47D1-92DF-E6D7F57DE3BA} - Virtual Storage Mount Notification - C:\Windows\SysNative\cbfsMntNtf5.dll (EldoS Corporation)
O22 - SharedTaskScheduler: {F09F617B-6C64-47D1-92DF-E6D7F57DE3BA} - Virtual Storage Mount Notification - C:\Windows\SysWOW64\cbfsMntNtf5.dll (EldoS Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{e317eea8-c907-11e0-a778-f46d04259911}\Shell - "" = AutoRun
O33 - MountPoints2\{e317eea8-c907-11e0-a778-f46d04259911}\Shell\AutoRun\command - "" = J:\unlock.exe autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/09/25 06:31:02 | 000,000,000 | ---D | C] -- C:\Users\James\Desktop\oldotl
[2014/09/25 06:06:46 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\James\Desktop\OTL.exe
[2014/09/24 00:07:28 | 000,000,000 | ---D | C] -- C:\Users\James\Documents\My CamStudio Videos
[2014/09/24 00:07:18 | 000,000,000 | ---D | C] -- C:\Users\James\Documents\My CamStudio Temp Files
[2014/09/24 00:03:43 | 000,000,000 | ---D | C] -- C:\ProgramData\374311380
[2014/09/24 00:02:46 | 000,000,000 | ---D | C] -- C:\Users\James\AppData\Roaming\StormFall
[2014/09/24 00:02:46 | 000,000,000 | ---D | C] -- C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
[2014/09/24 00:02:45 | 000,000,000 | ---D | C] -- C:\Users\James\AppData\Local\StormFall
[2014/09/24 00:02:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CamStudio 2.7
[2014/09/24 00:02:42 | 000,000,000 | ---D | C] -- C:\Program Files\CamStudio 2.7
[2014/09/22 15:26:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pushbullet
[2014/09/22 15:26:41 | 000,000,000 | ---D | C] -- C:\Users\James\AppData\Roaming\pushbullet
[2014/09/22 15:26:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pushbullet
[2014/09/22 04:15:07 | 000,000,000 | ---D | C] -- C:\Users\James\Desktop\013336075X_ppt
[2014/09/21 14:38:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
[2014/09/16 16:46:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gargoyle
[2014/09/16 16:46:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Gargoyle
[2014/09/16 16:31:45 | 000,000,000 | ---D | C] -- C:\Users\James\Documents\TADS
[2014/09/14 21:01:06 | 000,000,000 | ---D | C] -- C:\Users\James\AppData\Roaming\FlacSquisher
[2014/09/14 20:56:59 | 000,000,000 | ---D | C] -- C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FlacSquisher
[2014/09/14 20:56:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FlacSquisher
[2014/09/13 13:51:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
[2014/09/13 13:49:39 | 000,000,000 | ---D | C] -- C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SanDisk
[2014/09/13 13:49:10 | 000,000,000 | ---D | C] -- C:\Users\James\AppData\Roaming\SanDisk
[2014/09/11 20:15:57 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2014/09/11 11:40:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\KeePass Password Safe
[2014/09/10 18:05:31 | 000,000,000 | ---D | C] -- C:\Users\James\AppData\Local\{95C73209-B10A-4AE0-B660-034DD8C3E1ED}
[2014/08/26 23:12:00 | 000,000,000 | ---D | C] -- C:\Users\James\AppData\Local\{56D22F07-14B4-4069-AD79-8272BB9E0895}
 
========== Files - Modified Within 30 Days ==========
 
[2014/09/25 06:19:52 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2304217476-3085346115-1509824866-1001UA.job
[2014/09/25 06:06:39 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\James\Desktop\OTL.exe
[2014/09/25 05:44:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/09/25 05:39:00 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/09/24 16:19:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2304217476-3085346115-1509824866-1001Core.job
[2014/09/24 12:39:00 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/09/24 00:11:21 | 000,004,537 | ---- | M] () -- C:\Users\James\AppData\Roaming\CamStudio.cfg
[2014/09/24 00:11:21 | 000,000,408 | ---- | M] () -- C:\Users\James\AppData\Roaming\CamShapes.ini
[2014/09/24 00:11:21 | 000,000,408 | ---- | M] () -- C:\Users\James\AppData\Roaming\CamLayout.ini
[2014/09/24 00:11:21 | 000,000,103 | ---- | M] () -- C:\Users\James\AppData\Roaming\Camdata.ini
[2014/09/24 00:07:09 | 000,000,096 | ---- | M] () -- C:\Users\James\AppData\Roaming\version2.xml
[2014/09/24 00:02:46 | 000,002,454 | ---- | M] () -- C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\StormFall.lnk
[2014/09/23 23:56:41 | 1122,731,520 | ---- | M] () -- C:\Users\James\Desktop\Piano.avi
[2014/09/22 06:28:58 | 000,111,979 | ---- | M] () -- C:\Users\James\Desktop\capture00.jpeg
[2014/09/17 22:52:35 | 000,001,044 | ---- | M] () -- C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2014/09/16 16:31:03 | 000,122,584 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/09/16 14:45:10 | 000,071,647 | ---- | M] () -- C:\Users\James\Desktop\Pearson_Account_Code.PNG
[2014/09/15 07:34:14 | 000,819,142 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/09/15 07:34:14 | 000,692,328 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/09/15 07:34:14 | 000,130,490 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/09/13 13:51:53 | 000,002,180 | ---- | M] () -- C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk
[2014/09/11 20:16:35 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2014/09/07 21:37:00 | 000,299,008 | ---- | M] () -- C:\Users\James\Documents\Database1.accdb
[2014/09/03 22:11:17 | 000,001,387 | ---- | M] () -- C:\Users\James\Desktop\Student Work - Shortcut.lnk
[2014/08/31 15:36:26 | 000,022,128 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/08/31 15:36:26 | 000,022,128 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/08/30 09:29:32 | 000,002,283 | ---- | M] () -- C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2014/08/30 09:13:37 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/08/30 09:13:26 | 1058,975,742 | -HS- | M] () -- C:\hiberfil.sys
 
========== Files Created - No Company Name ==========
 
[2014/09/24 00:05:47 | 000,004,537 | ---- | C] () -- C:\Users\James\AppData\Roaming\CamStudio.cfg
[2014/09/24 00:05:47 | 000,000,408 | ---- | C] () -- C:\Users\James\AppData\Roaming\CamShapes.ini
[2014/09/24 00:05:47 | 000,000,408 | ---- | C] () -- C:\Users\James\AppData\Roaming\CamLayout.ini
[2014/09/24 00:05:47 | 000,000,103 | ---- | C] () -- C:\Users\James\AppData\Roaming\Camdata.ini
[2014/09/24 00:03:23 | 000,000,096 | ---- | C] () -- C:\Users\James\AppData\Roaming\version2.xml
[2014/09/24 00:02:46 | 000,002,454 | ---- | C] () -- C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\StormFall.lnk
[2014/09/23 23:57:06 | 1122,731,520 | ---- | C] () -- C:\Users\James\Desktop\Piano.avi
[2014/09/22 06:28:58 | 000,111,979 | ---- | C] () -- C:\Users\James\Desktop\capture00.jpeg
[2014/09/16 14:45:10 | 000,071,647 | ---- | C] () -- C:\Users\James\Desktop\Pearson_Account_Code.PNG
[2014/09/13 13:51:53 | 000,002,180 | ---- | C] () -- C:\Users\James\Application Data\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk
[2014/09/11 11:40:54 | 000,001,107 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeePass.lnk
[2014/09/07 21:33:02 | 000,299,008 | ---- | C] () -- C:\Users\James\Documents\Database1.accdb
[2014/09/03 22:11:17 | 000,001,387 | ---- | C] () -- C:\Users\James\Desktop\Student Work - Shortcut.lnk
[2014/08/18 17:38:11 | 000,000,218 | ---- | C] () -- C:\Users\James\.recently-used.xbel
[2014/07/21 22:18:14 | 000,000,841 | ---- | C] () -- C:\Users\James\AppData\Local\recently-used.xbel
[2014/04/21 16:57:17 | 000,000,262 | ---- | C] () -- C:\Users\James\drmomentum.inkyp
[2013/11/27 20:47:08 | 000,000,059 | ---- | C] () -- C:\Users\James\.gitconfig
[2013/09/15 20:16:55 | 001,065,984 | ---- | C] () -- C:\Users\James\AppData\Local\file__0.localstorage
[2013/09/03 07:55:29 | 000,017,345 | ---- | C] () -- C:\Users\James\STEAM - receipt for your key subscription.pdf
[2013/08/28 10:27:37 | 000,108,378 | ---- | C] () -- C:\Users\James\cmd=file&file=chatFra.pdf
[2013/07/15 23:55:11 | 055,297,160 | ---- | C] () -- C:\Users\James\MyPencastPDF.pdf
[2013/07/15 23:10:13 | 055,138,765 | ---- | C] () -- C:\Users\James\1-Subject Notebook 1 pp. 17~20.pdf
[2013/06/21 10:58:25 | 000,000,167 | ---- | C] () -- C:\Users\James\AppData\Roaming\.ptbt0
[2013/04/04 20:16:00 | 000,000,051 | ---- | C] () -- C:\Users\James\AppData\Roaming\Fraction Bars Settings
[2012/12/20 03:24:26 | 000,281,688 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012/12/20 03:24:24 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012/12/19 21:47:11 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012/10/25 18:35:24 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2012/05/23 07:48:52 | 000,001,526 | ---- | C] () -- C:\Users\James\AppData\Roaming\Sketchpad 5 Preferences.dat
[2011/09/21 09:38:24 | 000,008,704 | ---- | C] () -- C:\Users\James\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/09/20 18:56:28 | 000,000,108 | ---- | C] () -- C:\Users\James\webct_upload_applet.properties
[2011/08/25 21:24:10 | 000,007,651 | ---- | C] () -- C:\Users\James\AppData\Local\Resmon.ResmonCfg
 
========== ZeroAccess Check ==========
 
[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/07/25 22:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/25 21:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 21:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 23:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 21:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2014/01/27 09:32:06 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\.minecraft
[2013/04/13 22:22:50 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\2BrightSparks
[2012/12/18 13:46:27 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\6Wunderkinder
[2012/08/09 09:41:19 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Amazon
[2014/07/19 18:29:36 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Audacity
[2013/12/02 15:40:49 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\AVAST Software
[2014/05/03 22:40:00 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Battle.net
[2014/05/07 10:01:25 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Bitcasa
[2012/09/10 18:26:36 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Canon
[2013/12/25 13:56:58 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\com.amazon.music.uploader
[2014/05/01 21:24:26 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\com.bitcasa.Bitcasa
[2013/08/29 14:27:58 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\com.focusboosterapp.focusbooster
[2013/03/06 19:47:03 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\com.focusboosterapp.focusbooster.8E5F79C899747AD22E21DB62AA496926DA6BBC64.1
[2011/09/13 03:25:22 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\com.livescribe.LivescribeConnect
[2013/07/24 20:06:59 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\com.webkinesis.PicasaUploaderDesktop
[2012/09/12 17:11:30 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Digiarty
[2014/09/17 22:52:37 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Dropbox
[2012/07/17 14:38:56 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\EndNote
[2014/01/23 19:50:27 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\FileZilla
[2014/09/14 21:01:06 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\FlacSquisher
[2011/09/03 12:47:49 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Flickr
[2012/11/08 19:32:57 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Fox Dgital Copy
[2014/04/14 22:54:58 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Foxit Software
[2012/10/29 20:12:33 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Freeplane
[2013/10/25 21:27:40 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\GARMIN
[2013/11/27 20:47:36 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\GitHub
[2014/07/11 00:45:48 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Goofball
[2013/07/04 18:34:00 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\gtk-2.0
[2014/02/26 13:33:58 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\HandBrake
[2012/09/14 15:40:30 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\ImgBurn
[2014/08/18 17:26:31 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\inkscape
[2011/09/07 17:18:11 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\InqScribe
[2014/01/23 20:10:05 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\IObit
[2012/10/01 18:27:30 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\IrfanView
[2013/05/26 08:34:50 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\JRT Studio
[2014/09/11 11:40:18 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\KeePass
[2012/06/26 16:24:10 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Leadertech
[2012/03/06 18:23:40 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\LOVE
[2014/04/18 00:10:43 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Mark of the Old Ones
[2014/03/14 10:55:35 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\MPEG Streamclip
[2014/06/23 12:17:59 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Notepad++
[2014/05/29 14:01:10 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Oracle
[2011/12/14 15:41:14 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\PhotoScape
[2013/03/20 11:37:06 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\PhraseExpress
[2014/08/25 01:05:48 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\ProductData
[2014/09/22 15:26:56 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\pushbullet
[2014/08/03 11:06:23 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\QuickScan
[2014/09/13 13:49:41 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\SanDisk
[2012/10/05 12:54:30 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Scribus
[2012/09/10 20:03:25 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Skinux
[2013/08/28 17:04:17 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\SolidDocuments
[2013/11/02 19:41:11 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\SomePDF
[2014/09/25 06:35:53 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Spotify
[2014/09/24 00:02:46 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\StormFall
[2013/05/01 22:26:04 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Sublime Text 2
[2013/09/10 19:13:47 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\SumatraPDF
[2013/07/15 10:49:12 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\System
[2013/12/11 17:00:24 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\SYSTEMAX Software Development
[2014/08/22 21:38:47 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Talisman
[2012/10/05 13:09:38 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\TechSmith
[2012/09/30 22:22:38 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Titanium
[2014/07/22 04:30:46 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\TrueCrypt
[2013/10/08 05:25:30 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\TuneUpMedia
[2014/05/06 11:05:55 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Unity
[2014/09/15 10:24:29 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\uTorrent
[2012/09/10 20:03:11 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Vonage
[2013/01/30 14:11:51 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Waterfox Limited
[2013/08/14 23:15:33 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\WinPatrol
[2013/07/15 11:08:35 | 000,000,000 | -HSD | M] -- C:\Users\James\AppData\Roaming\wyUpdate AU
[2013/03/05 15:12:56 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\XMind
[2012/02/10 15:26:48 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\Zotero
[2011/10/07 11:16:26 | 000,000,000 | ---D | M] -- C:\Users\James\AppData\Roaming\ZumoDrive
 
========== Purity Check ==========
 
 
 
< End of report >
 

  • 0

Advertisements


#2
Biscuithd

Biscuithd

    Trusted Helper

  • Malware Removal
  • 2,573 posts

Sorry that it has taken so long to reply.

 

Sometimes we get quite busy and this is one of those times.

 

Do you still require help?


  • 0

#3
drmomentum

drmomentum

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

Hi. Yes, I still have the problem. The Stormfall ad is coming up (intermittently). 

 

I don't know if it's related, but Chrome is now crashing multiple times per day. So I know something is up (although I'm using the new 64 bit version which may just be unstable). 

 

Thanks for any help you can provide.

 

-James


  • 0

#4
Biscuithd

Biscuithd

    Trusted Helper

  • Malware Removal
  • 2,573 posts

At a quick glance, Chrome does look a litte...wonky :)

 

Let's have a look with this tool also.

 

FRST.gif Scan with Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool and save it to your Desktop.


  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • When the tool opens click Yes to disclaimer.
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please copy and paste their content into your next reply.

 


  • 0

#5
drmomentum

drmomentum

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

Here are the two results of that tool's run (I had to use the 64 bit version):

 

------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-09-2014 02
Ran by James (administrator) on EDO on 29-09-2014 16:37:44
Running from C:\Users\James\Desktop
Loaded Profile: James (Available profiles: James & Walternate & DefaultAppPool)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(SANDBOXIE L.T.D) C:\Program Files\Sandboxie\SbieSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\Brother\BRAdmin Professional 3\bratimer.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\37.0.2062.28\remoting_host.exe
() C:\Program Files (x86)\FarStone\TotalRecovery\Client\CBP\DCSchdler.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\37.0.2062.28\remoting_host.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe
(Livescribe) C:\Program Files (x86)\Common Files\Livescribe\PenComm\PenCommService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Program Files (x86)\FarStone\TotalRecovery\Client\DCNTranProc.exe
(WDC) C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\vVX3000.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\old_chrome.exe
(Flux Software LLC) C:\Users\James\AppData\Local\FluxSoftware\Flux\flux.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Bartels Media GmbH) C:\Program Files (x86)\PhraseExpress\phraseexpress.exe
(AimerSoft) C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Dominik Reichl) C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmprph.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
(Mozilla Foundation) C:\Program Files (x86)\Zotero Standalone\zotero.exe
(SanDisk Corporation) C:\Users\James\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
(Foxit Corporation) C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\old_chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\old_chrome.exe
(Dropbox, Inc.) C:\Users\James\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunes.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\old_chrome.exe
() C:\Program Files (x86)\Pushbullet\pushbullet_app.exe
(Google Inc.) C:\Users\James\AppData\Local\Programs\Google\MusicManager\MusicManager.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\POWERPNT.EXE
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Camtasia Studio 8\TscHelp.exe
(Foxit Corporation) C:\Program Files (x86)\Foxit Software\Foxit Reader\Shell Extensions\FoxitPrevhost.exe
(Spotify Ltd) C:\Users\James\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
() C:\Users\James\AppData\Local\Amazon Music\Amazon Music Helper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\ATH.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\MDCrashReportTool.exe
(Microsoft Corporation) C:\Windows\System32\SnippingTool.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [VX3000] => C:\Windows\vVX3000.exe [762224 2009-06-30] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11860072 2011-06-09] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [Bitcasa] => C:\Program Files\Bitcasa\Bitcasa.exe [4357632 2014-02-21] ()
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [LifeCam] => C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [119152 2010-05-20] (Microsoft Corporation)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1185112 2010-04-02] (CANON INC.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Aimersoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe [1666560 2012-02-20] (AimerSoft)
HKLM-x32\...\Run: [KeePass 2 PreLoad] => C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2099200 2014-04-13] (Dominik Reichl)
HKLM-x32\...\Run: [Virtual Account Numbers] => C:\Program Files (x86)\Virtual Account Numbers\CitiVAN.exe [398336 2013-03-04] (Orbiscom Ltd. All rights reserved.)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-05-19] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1263952 2013-02-12] ()
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3478392 2013-12-21] (Adobe Systems Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-08-14] (AVAST Software)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM Group Policy restriction on software: *.divx.exe <====== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin\*\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin\*\*\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.docx.com <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.txt.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp.com <====== ATTENTION
HKLM Group Policy restriction on software: *.rar.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xls.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wav.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.zip.exe <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pub.com <====== ATTENTION
HKLM Group Policy restriction on software: *.doc.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.divx.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.png.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.docx.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.divx.scr <====== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin\*\*\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wma.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.txt.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf.com <====== ATTENTION
HKLM Group Policy restriction on software: *.doc.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.txt.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.avi.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.gif.com <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv.scr <====== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin\*\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin\*\*\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.gif.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3.exe <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.avi.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg.scr <====== ATTENTION
HKLM Group Policy restriction on software: *‮* <====== ATTENTION
HKLM Group Policy restriction on software: *.7z.com <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wma.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.rar.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wma.com <====== ATTENTION
HKLM Group Policy restriction on software: *.xls.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg.exe <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.gif.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.zip.scr <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv.com <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.docx.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.doc.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.png.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.png.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.png.pif <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.avi.com <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf.com <====== ATTENTION
HKLM Group Policy restriction on software: *.rar.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.xls.com <====== ATTENTION
HKLM Group Policy restriction on software: *.7z.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.zip.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx.com <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx.com <====== ATTENTION
HKLM Group Policy restriction on software: *.docx.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wav.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.7z.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3.com <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx.exe <====== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wav.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.txt.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.zip.com <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf.pif <====== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin\*\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin\*\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf.exe <====== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin\*\*\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.avi.pif <====== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.7z.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.rar.com <====== ATTENTION
HKLM Group Policy restriction on software: *.pub.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pub.exe <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wma.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.gif.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.divx.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv.exe <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.xls.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.doc.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wav.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pub.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\spotify\spotifylauncher.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\utorrent\utorrent.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\spotify\spotify_new.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\utorrent\utorrent.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\spotify\spotify_new.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\utorrent\utorrent.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\spotify\spotify.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\spotify\spotifylauncher.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\spotify\spotifylauncher.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\spotify\spotify_new.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\spotify\spotify.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\spotify\spotify.exe <====== ATTENTION
HKU\S-1-5-21-2304217476-3085346115-1509824866-1001\...\Run: [MusicManager] => C:\Users\James\AppData\Local\Programs\Google\MusicManager\MusicManager.exe [7631872 2014-07-22] (Google Inc.)
HKU\S-1-5-21-2304217476-3085346115-1509824866-1001\...\Run: [DE24DAEE86D33FB70CF774307B0E31290C5D8D40._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [912200 2014-09-22] (Google Inc.)
HKU\S-1-5-21-2304217476-3085346115-1509824866-1001\...\Run: [Google Update] => C:\Users\James\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-08-17] (Google Inc.)
HKU\S-1-5-21-2304217476-3085346115-1509824866-1001\...\Run: [WinPatrol] => C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe [439360 2013-08-12] (BillP Studios)
HKU\S-1-5-21-2304217476-3085346115-1509824866-1001\...\Run: [Spotify Web Helper] => C:\Users\James\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1245752 2014-09-23] (Spotify Ltd)
HKU\S-1-5-21-2304217476-3085346115-1509824866-1001\...\Run: [f.lux] => C:\Users\James\AppData\Local\FluxSoftware\Flux\flux.exe [1016712 2013-10-15] (Flux Software LLC)
HKU\S-1-5-21-2304217476-3085346115-1509824866-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2014-08-07] (Garmin Ltd or its subsidiaries)
HKU\S-1-5-21-2304217476-3085346115-1509824866-1001\...\Run: [Google+ Auto Backup] => C:\Users\James\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe [3746120 2014-08-12] (Google Inc.)
HKU\S-1-5-21-2304217476-3085346115-1509824866-1001\...\Run: [Advanced SystemCare 7] => C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2285344 2013-12-18] (IObit)
HKU\S-1-5-21-2304217476-3085346115-1509824866-1001\...\Run: [Amazon Music] => C:\Users\James\AppData\Local\Amazon Music\Amazon Music Helper.exe [6281536 2014-09-05] ()
HKU\S-1-5-21-2304217476-3085346115-1509824866-1001\...\Run: [uTorrent] => C:\Users\James\AppData\Roaming\uTorrent\uTorrent.exe [1416016 2014-09-26] (BitTorrent Inc.)
HKU\S-1-5-21-2304217476-3085346115-1509824866-1001\...\Run: [GoogleChromeAutoLaunch_6B06BCEFC97BCF192292AD16DB5D7A73] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [912200 2014-09-22] (Google Inc.)
HKU\S-1-5-21-2304217476-3085346115-1509824866-1001\...\Run: [SansaDispatch] => C:\Users\James\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe [1465616 2014-09-13] (SanDisk Corporation)
HKU\S-1-5-21-2304217476-3085346115-1509824866-1001\...\Run: [Pushbullet] => C:\Program Files (x86)\Pushbullet\pushbullet_app.exe [822320 2014-08-28] ()
HKU\S-1-5-21-2304217476-3085346115-1509824866-1001\...\MountPoints2: {e317eea8-c907-11e0-a778-f46d04259911} - J:\unlock.exe autoplay=true
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PhraseExpress.lnk
ShortcutTarget: PhraseExpress.lnk -> C:\Program Files (x86)\PhraseExpress\phraseexpress.exe (Bartels Media GmbH)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WD Quick View.lnk
ShortcutTarget: WD Quick View.lnk -> C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (Western Digital Technologies, Inc.)
Startup: C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\James\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
Startup: C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iSyncr.lnk
ShortcutTarget: iSyncr.lnk -> C:\Users\James\AppData\Roaming\Microsoft\Installer\{8E1F956D-631A-4146-B893-185E150D5BBD}\_C1F574CEC66419C15C9588.exe ()
Startup: C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Vitamin D Video.exe - Shortcut.lnk
ShortcutTarget: Vitamin D Video.exe - Shortcut.lnk -> C:\Program Files (x86)\Vitamin D Video\Vitamin D Video.exe (Vitamin D Video, LLC)
SSODL: EldosMountNotificator-cbfs5 - {F09F617B-6C64-47D1-92DF-E6D7F57DE3BA} - C:\Windows\system32\cbfsMntNtf5.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator-cbfs5 - {F09F617B-6C64-47D1-92DF-E6D7F57DE3BA} - C:\Windows\SysWOW64\cbfsMntNtf5.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: 1EldosIconOverlay-cbfs5 -> {84411CEC-0B2D-4607-AEB3-544253D9B500} => C:\Windows\system32\cbfsMntNtf5.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: 2EldosIconOverlay-cbfs5 -> {42FE20CA-AA91-42DF-8A17-5856CA43EA2A} => C:\Windows\system32\cbfsMntNtf5.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: BitcasaBadFileOverlay -> {EC168C82-5053-422A-BB08-3CD9ACA22E85} => C:\Program Files\Bitcasa\ExplorerMenu.dll ()
ShellIconOverlayIdentifiers: BitcasaIconOverlay -> {A6975448-A999-49BB-B3E4-7730CF6A82C0} => C:\Program Files\Bitcasa\ExplorerMenu.dll ()
ShellIconOverlayIdentifiers: BitcasaMirrorOverlay -> {8C403C00-4544-4A53-879B-1949390CDE13} => C:\Program Files\Bitcasa\ExplorerMenu.dll ()
ShellIconOverlayIdentifiers: BitcasaNotMirrored -> {775CDDED-E6D2-4DD8-8C1F-158BEF44B62A} => C:\Program Files\Bitcasa\ExplorerMenu.dll ()
ShellIconOverlayIdentifiers: BitcasaProgressOverlay -> {6FB8D52A-0064-45B2-B687-F596FEAD09C2} => C:\Program Files\Bitcasa\ExplorerMenu.dll ()
ShellIconOverlayIdentifiers: EldosIconOverlay-cbfs5 -> {05673CC1-E592-4A4F-9EF7-D5694EE98BD5} => C:\Windows\system32\cbfsMntNtf5.dll (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: 1EldosIconOverlay-cbfs5 -> {84411CEC-0B2D-4607-AEB3-544253D9B500} => C:\Windows\SysWOW64\cbfsMntNtf5.dll (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: 2EldosIconOverlay-cbfs5 -> {42FE20CA-AA91-42DF-8A17-5856CA43EA2A} => C:\Windows\SysWOW64\cbfsMntNtf5.dll (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: EldosIconOverlay-cbfs5 -> {05673CC1-E592-4A4F-9EF7-D5694EE98BD5} => C:\Windows\SysWOW64\cbfsMntNtf5.dll (EldoS Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?...l_date=20110823
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.velocitymicro.com
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.velocitymicro.com
SearchScopes: HKCU - {63140ECF-C629-BE59-8F0E-90B4FF340C03} URL = http://www.bing.com/...eferrer:source}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={sear
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)
BHO: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} ->  No File
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Virtual Account Numbers Helper -> {17424104-1444-4810-85D7-B4DA413C5A9A} -> C:\Program Files (x86)\Virtual Account Numbers\CitiVANHelper.dll (Orbiscom Ltd. All rights reserved.)
BHO-x32: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Advanced SystemCare Browser Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKLM-x32 - Virtual Account Numbers - {7A21A046-B886-4A62-9D69-EF2059B0A27B} - C:\Program Files (x86)\Virtual Account Numbers\CitiVANToolbar.dll (Orbiscom Ltd. All rights reserved.)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
 
FireFox:
========
FF ProfilePath: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com/ig
FF Keyword.URL: hxxp://www.bing.com/search?pc=Z128&form=ZGAADF&install_date=20110823&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=1.6.0_39 -> C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/MycameraPlugin -> C:\Program Files (x86)\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll No File
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: @doubletwist.com/NPPodcast -> C:\Program Files (x86)\Common Files\doubleTwist\NPPodcast.dll No File
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin -> C:\Users\James\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin -> C:\Users\James\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 -> C:\Users\James\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 -> C:\Users\James\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\James\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101710.dll (Amazon.com, Inc.)
FF user.js: detected! => C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\user.js
FF Plugin ProgramFiles/Appdata: C:\Users\James\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\James\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF SearchPlugin: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\searchplugins\bing-zugo.xml
FF Extension: Advanced SystemCare Surfing Protection - C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\Extensions\[email protected] [2014-01-23]
FF Extension: Free Download Manager plugin - C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\Extensions\[email protected] [2012-12-14]
FF Extension: Pocket - C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\Extensions\[email protected] [2014-07-08]
FF Extension: Zotero Word for Windows Integration - C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\Extensions\[email protected] [2014-06-22]
FF Extension: Autofill Forms - C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\Extensions\[email protected] [2011-11-29]
FF Extension: Firebug - C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\Extensions\[email protected] [2013-05-02]
FF Extension: Zotero - C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\Extensions\[email protected] [2013-04-08]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-03-15]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Virtual Account Numbers
FF Extension: Virtual Account Numbers for Firefox - C:\Program Files (x86)\Virtual Account Numbers [2013-07-08]
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013-07-09]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2013-08-05]
 
Chrome: 
=======
CHR Profile: C:\Users\James\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Magic Actions for YouTube™) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2014-08-03]
CHR Extension: (Entanglement Web App) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd [2014-04-17]
CHR Extension: (Angry Birds) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2014-04-17]
CHR Extension: (Awesome Screenshot: Capture & Annotate) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\alelhddbbhepgpmgidjdcjakblofbmce [2014-06-02]
CHR Extension: (Google Docs) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-17]
CHR Extension: (Google Drive) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-17]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-10]
CHR Extension: (WOT) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2014-04-17]
CHR Extension: (YouTube) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-17]
CHR Extension: (Honey) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2014-04-17]
CHR Extension: (Google Cast) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd [2014-04-17]
CHR Extension: (HelloFax: 50 Free Fax Pages) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\bocmleclimfnadgmcdgecijlblfcmfnm [2014-04-17]
CHR Extension: (Memonic Web Clipper) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdonhidhobjahdhlcegfakicbcgnkokh [2014-04-17]
CHR Extension: (Copy Without Formatting) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekbgkmeapobkbadclnkjfjdbpbcaobd [2014-04-17]
CHR Extension: (Last updated at $time$ on $date$) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-04-17]
CHR Extension: (Strict Workflow) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgmnfnmlficgeijcalkgnnkigkefkbhd [2014-04-17]
CHR Extension: (Pushbullet) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\chlffgpmiacpedhhbkiomidkjlcfhogd [2014-09-17]
CHR Extension: (Add to Amazon Wish List) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ciagpekplgpbepdgggflgmahnjgiaced [2014-04-28]
CHR Extension: (Gif Delayer) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmfcdkambpljcndgdmaccaagladfnepa [2014-04-17]
CHR Extension: (Google Search) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-17]
CHR Extension: (Video Title Adder) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddpephnhacfpgcemhioaejgenlgadnnh [2014-04-17]
CHR Extension: (Rather) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkigkllnlkoblfbgfnfngfcnhmndonjm [2014-04-17]
CHR Extension: (Google Calendar) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2014-04-17]
CHR Extension: (Zotero Connector) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekhagklcjbdpajgpjgmbionohlpdbjgc [2014-04-17]
CHR Extension: (No Name) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2014-08-17]
CHR Extension: (Chrome Remote Desktop) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2014-04-20]
CHR Extension: (TinEye Reverse Image Search) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl [2014-04-17]
CHR Extension: (Memonic) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\hejjjnnbamjillkkomahknangbpjfdpd [2014-04-17]
CHR Extension: (Voice Search) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhfkcobomkalfdlmkongnhnhahkmnaad [2014-04-17]
CHR Extension: (Terms of Service; Didn’t Read) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjdoplcnndgiblooccencgcggcoihigg [2014-08-03]
CHR Extension: (Checker Plus for Google Calendar™) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkhggnncdpfibdhinjiegagmopldibha [2014-04-17]
CHR Extension: (Don't Break the Chain) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlkkjgfbfgdcdjnddamlmgbipgbhgppk [2014-05-02]
CHR Extension: (Google Keep - notes and lists) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2014-04-17]
CHR Extension: (Bitly | Unleash the power of the link) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\iabeihobmhlgpkcgjiloemdbofjbdcic [2014-04-17]
CHR Extension: (goo.gl URL Shortener) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\iblijlcdoidgdpfknkckljiocdbnlagk [2014-04-17]
CHR Extension: (Kindle Cloud Reader) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2014-07-29]
CHR Extension: (Google Play Music) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\icppfcnhkcmnfdhfhphakoifcfokfdhg [2014-04-17]
CHR Extension: (Looper for YouTube) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\iggpfpnahkgpnindfkdncknoldgnccdg [2014-04-17]
CHR Extension: (Cloze - Keep Tabs on Contacts) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\imlbbglginccpmlaekkdnleoachjadka [2014-04-17]
CHR Extension: (Deathamns) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\immpkjjlgappgfkkfieppnmlhakdmaab [2014-06-01]
CHR Extension: (Disconnect) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeoacafpbcihiomhlakheieifhpjdfeo [2014-04-17]
CHR Extension: (Yoono - Twitter, Facebook, LinkedIn, YouTube™) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkkenjlnjfemconejajakbijbheoffli [2014-04-17]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2014-04-17]
CHR Extension: (Google Voice (by Google)) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcnhkahnjcbndmmehfkdnkjomaanaooo [2014-04-17]
CHR Extension: (RSS Web Subscriber) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\kghdjdlccddmkepckhfgjdeohkcabahl [2014-08-13]
CHR Extension: (The Great Suspender) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\klbibkeccnjlkjkiokjodocebajanakg [2014-04-17]
CHR Extension: (StayFocusd) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\laankejkbhbdhmipfmgcngdelahlfoji [2014-04-17]
CHR Extension: (Webcam Toy) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade [2014-04-17]
CHR Extension: (InvisibleHand) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\lghjfnfolmcikomdjmoiemllfnlmmoko [2014-04-17]
CHR Extension: (Poppit!) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi [2014-04-17]
CHR Extension: (Download Master) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcceagdollnkjlogmdckgjakjapmkdjf [2014-04-17]
CHR Extension: (Reddit Check) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\mllceaiaedaingchlgolnfiibippgkmj [2014-04-17]
CHR Extension: (Google Play Books) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2014-07-29]
CHR Extension: (Hangouts) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2014-06-05]
CHR Extension: (Save to Pocket) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj [2014-04-17]
CHR Extension: (Springpad Extension) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\njhgeimnepehieioinbhmfpphfoocmng [2014-04-17]
CHR Extension: (Google Drive Client Native Proxy) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\nknebiagdodnminbdpflhpkgfpeijdbf [2014-08-19]
CHR Extension: (Google Wallet) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-17]
CHR Extension: (Google Chrome to Phone Extension) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco [2014-04-17]
CHR Extension: (rbutr) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocnieghejiknjhadhngmmnbfjocbbfpm [2014-06-18]
CHR Extension: (Checker Plus for Gmail™) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\oeopbcgkkoapgobdbedcemjljbihmemj [2014-04-17]
CHR Extension: (Enhanced Steam) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg [2014-04-17]
CHR Extension: (chromeIPass) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ompiailgknfdndiefoaoiligalphfdae [2014-04-17]
CHR Extension: (Picasa) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2014-04-17]
CHR Extension: (Click&Clean App) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2014-08-03]
CHR Extension: (Send from Gmail (by Google)) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgphcomnlaojlmmcjmiddhdapjpbgeoc [2014-04-17]
CHR Extension: (Evernote Web Clipper) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2014-04-17]
CHR Extension: (Gmail) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-17]
CHR Extension: (Space Planet) - C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppcocpoeoiajndepaaimnnglicichmbb [2014-04-17]
CHR HKCU\...\Chrome\Extension: [nknebiagdodnminbdpflhpkgfpeijdbf] - C:\Users\James\AppData\Local\Google\Drive\nknebiagdodnminbdpflhpkgfpeijdbf_live.crx [2014-08-07]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2014-08-07]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-08-14]
CHR HKLM-x32\...\Chrome\Extension: [nfengeggddojhakldhlpjdlddgkkjkdd] - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASC_GhromePlugin.crx [2014-01-23]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2013-05-06]
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-01-25] (Adobe Systems) [File not signed]
R2 AdvancedSystemCareService7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [881440 2013-12-09] (IObit)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-08-14] (AVAST Software)
R2 BRA_Scheduler; C:\Program Files (x86)\Brother\BRAdmin Professional 3\bratimer.exe [65536 2010-09-15] () [File not signed]
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\37.0.2062.28\remoting_host.exe [51016 2014-07-17] (Google Inc.)
S2 DCScheduler; C:\Program Files (x86)\FarStone\TotalRecovery\Client\cbp\DCSchdlerSRVC.exe [104976 2009-11-26] ()
S4 FBAgent; C:\Program Files (x86)\FarStone\TotalRecovery\Client\Efb\FBPAgent.exe [86016 2010-01-11] (Farstone Technology Inc.) [File not signed]
R2 FoxitCloudUpdateService; C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\Foxit Cloud\FCUpdateService.exe [242216 2014-06-17] (Foxit Corporation)
R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [438616 2014-08-07] (Garmin Ltd or its subsidiaries)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2175264 2014-08-25] (IObit)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 PenCommService; C:\Program Files (x86)\Common Files\Livescribe\PenComm\PenCommService.exe [470528 2011-10-27] (Livescribe) [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2012-12-20] ()
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [123664 2012-12-16] (SANDBOXIE L.T.D)
R2 Tran_Process_Proc; C:\Program Files (x86)\FarStone\TotalRecovery\Client\DCNTranProc.exe [77824 2009-11-26] () [File not signed]
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)
R2 WDDMService; C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [311296 2011-06-29] (WDC) [File not signed]
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 ahcix64s; C:\Windows\system32\drivers\ahcix64s.sys [209424 2007-12-19] (AMD Technologies Inc.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-08-14] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-08-14] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-08-14] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-08-14] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-08-14] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-08-14] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-08-14] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-08-14] ()
S3 Bulk1528; C:\Windows\System32\Drivers\Bulk1528.sys [14848 2008-06-28] (SunPlus)
S2 Ca1528av; C:\Windows\System32\Drivers\Ca1528av.sys [533760 2008-12-17] (Digital Camera)
R1 cbfs5; C:\Windows\system32\drivers\cbfs5.sys [413888 2013-11-25] (EldoS Corporation)
R0 dcsnap; C:\Windows\System32\Drivers\dcsnap.sys [91152 2009-11-26] ()
S3 FARMNTIO; c:\windows\system32\drivers\farmntio.sys [23056 2009-11-26] ()
S3 megasas2; C:\Windows\system32\drivers\megasas2.sys [52304 2011-01-26] (LSI Corporation)
S3 MegaSR1; C:\Windows\system32\drivers\MegaSR1.sys [465488 2010-06-14] (LSI Corporation, Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R0 nvrd64; C:\Windows\System32\drivers\nvrd64.sys [151848 2007-04-15] (NVIDIA Corporation)
S3 PulseUsb; C:\Windows\System32\DRIVERS\PulseUsb.sys [26112 2011-08-11] (Windows ® Win 7 DDK provider)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [202632 2012-12-16] (SANDBOXIE L.T.D)
S3 Si3124r5; C:\Windows\system32\drivers\Si3124r5.sys [340008 2010-04-13] (Silicon Image, Inc)
R0 SiFilter; C:\Windows\System32\drivers\SiWinAcc.sys [22568 2010-04-13] (Silicon Image, Inc.)
R0 SiRemFil; C:\Windows\System32\drivers\SiRemFil.sys [16936 2010-04-13] (Silicon Image, Inc.)
S2 iPodDrv; \??\C:\Windows\system32\drivers\iPodDrv.sys [X]
S4 NVHDA; system32\drivers\nvhda64v.sys [X]
S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-09-29 16:37 - 2014-09-29 16:38 - 00061940 _____ () C:\Users\James\Desktop\FRST.txt
2014-09-29 16:37 - 2014-09-29 16:37 - 00000000 ____D () C:\FRST
2014-09-29 16:36 - 2014-09-29 16:36 - 02108928 _____ (Farbar) C:\Users\James\Desktop\FRST64.exe
2014-09-28 22:19 - 2014-09-28 22:19 - 00011243 _____ () C:\Users\James\Downloads\Homework 1_dfarnsworth71_attempt_2014-09-20-14-39-25_Computer Hardware.svg
2014-09-28 22:12 - 2014-09-28 22:12 - 00000000 ____D () C:\Users\James\AppData\Roaming\OpenOffice
2014-09-28 22:10 - 2014-09-28 22:11 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1
2014-09-28 22:10 - 2014-09-28 22:10 - 00001112 _____ () C:\Users\Public\Desktop\OpenOffice 4.1.1.lnk
2014-09-28 22:09 - 2014-09-28 22:10 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4
2014-09-28 22:07 - 2014-09-28 22:07 - 00000000 ____D () C:\Users\James\Desktop\OpenOffice 4.1.1 (en-US) Installation Files
2014-09-28 22:04 - 2014-09-28 22:06 - 140852175 _____ () C:\Users\James\Downloads\Apache_OpenOffice_4.1.1_Win_x86_install_en-US.exe
2014-09-28 08:32 - 2014-09-28 08:34 - 00000000 ____D () C:\Users\James\Grading Temp
2014-09-26 12:15 - 2014-09-26 12:16 - 29914370 _____ () C:\Users\James\Downloads\files (4).zip
2014-09-26 12:13 - 2014-09-26 12:14 - 24860870 _____ () C:\Users\James\Downloads\files (3).zip
2014-09-26 11:34 - 2014-09-26 11:34 - 00029598 _____ () C:\Users\James\Downloads\Coding_B0824_Milkshake.xlsx
2014-09-26 11:34 - 2014-09-26 11:34 - 00028900 _____ () C:\Users\James\Downloads\Coding_G0131_Milkshake.xlsx
2014-09-25 20:53 - 2014-09-25 20:59 - 02888100 _____ () C:\Users\James\Desktop\chasing.a2w
2014-09-25 20:53 - 2014-09-25 20:59 - 00000000 ____D () C:\Users\James\Desktop\Backups of chasing
2014-09-25 20:17 - 2014-09-25 20:50 - 00000000 ____D () C:\Users\James\Desktop\CustomGallery
2014-09-25 20:13 - 2014-09-25 20:13 - 00661175 _____ () C:\Users\James\Downloads\Exponential.k8.n100.web.mov
2014-09-25 06:39 - 2014-09-25 06:39 - 00181488 _____ () C:\Users\James\Desktop\OTL.Txt
2014-09-25 06:31 - 2014-09-25 06:31 - 00000000 ____D () C:\Users\James\Desktop\oldotl
2014-09-25 06:06 - 2014-09-25 06:06 - 00602112 _____ (OldTimer Tools) C:\Users\James\Downloads\OTL.exe
2014-09-25 06:06 - 2014-09-25 06:06 - 00602112 _____ (OldTimer Tools) C:\Users\James\Desktop\OTL.exe
2014-09-24 00:07 - 2014-09-24 00:10 - 00000000 ____D () C:\Users\James\Documents\My CamStudio Temp Files
2014-09-24 00:05 - 2014-09-24 00:11 - 00004537 _____ () C:\Users\James\AppData\Roaming\CamStudio.cfg
2014-09-24 00:05 - 2014-09-24 00:11 - 00000408 _____ () C:\Users\James\AppData\Roaming\CamShapes.ini
2014-09-24 00:05 - 2014-09-24 00:11 - 00000408 _____ () C:\Users\James\AppData\Roaming\CamLayout.ini
2014-09-24 00:05 - 2014-09-24 00:11 - 00000103 _____ () C:\Users\James\AppData\Roaming\Camdata.ini
2014-09-24 00:03 - 2014-09-24 00:07 - 00000096 _____ () C:\Users\James\AppData\Roaming\version2.xml
2014-09-24 00:03 - 2014-09-24 00:03 - 00004016 _____ () C:\Windows\System32\Tasks\LaunchSignup
2014-09-24 00:03 - 2014-09-24 00:03 - 00000000 ____D () C:\ProgramData\374311380
2014-09-24 00:02 - 2014-09-24 00:02 - 00711585 _____ () C:\Users\James\Downloads\CamStudioSetup_v2.7.2.zip
2014-09-24 00:02 - 2014-09-24 00:02 - 00003674 _____ () C:\Windows\System32\Tasks\StormFall TW2
2014-09-24 00:02 - 2014-09-24 00:02 - 00003674 _____ () C:\Windows\System32\Tasks\StormFall TW1
2014-09-24 00:02 - 2014-09-24 00:02 - 00000000 ____D () C:\Users\James\AppData\Roaming\StormFall
2014-09-24 00:02 - 2014-09-24 00:02 - 00000000 ____D () C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
2014-09-24 00:02 - 2014-09-24 00:02 - 00000000 ____D () C:\Users\James\AppData\Local\StormFall
2014-09-24 00:02 - 2014-09-24 00:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CamStudio 2.7
2014-09-24 00:02 - 2014-09-24 00:02 - 00000000 ____D () C:\Program Files\CamStudio 2.7
2014-09-23 23:57 - 2014-09-23 23:56 - 1122731520 _____ () C:\Users\James\Desktop\Piano.avi
2014-09-22 15:40 - 2014-09-22 15:40 - 00005772 _____ () C:\Users\James\Downloads\Pseudocode in Space.downloadlong.xls
2014-09-22 15:26 - 2014-09-22 15:26 - 00000000 ____D () C:\Users\James\AppData\Roaming\pushbullet
2014-09-22 15:26 - 2014-09-22 15:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pushbullet
2014-09-22 15:26 - 2014-09-22 15:26 - 00000000 ____D () C:\Program Files (x86)\Pushbullet
2014-09-22 15:23 - 2014-09-22 15:23 - 08970080 _____ (Pushbullet Inc ) C:\Users\James\Downloads\pb_install (1).exe
2014-09-22 06:28 - 2014-09-22 06:28 - 00111979 _____ () C:\Users\James\Desktop\capture00.jpeg
2014-09-22 04:15 - 2014-09-22 04:15 - 00000000 ____D () C:\Users\James\Desktop\013336075X_ppt
2014-09-21 14:38 - 2014-09-21 14:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
2014-09-18 11:21 - 2014-09-18 11:21 - 05415547 _____ () C:\Users\James\Downloads\C418 - 0x10c.zip
2014-09-18 11:15 - 2014-09-18 11:15 - 01357949 _____ () C:\Users\James\Downloads\FIIL2K1I05F4C9O.m4v
2014-09-18 11:15 - 2014-09-18 11:15 - 00749545 _____ () C:\Users\James\Downloads\FCD2VW3I05F4BYT.m4v
2014-09-18 05:57 - 2014-09-18 05:57 - 08968528 _____ (Pushbullet Inc ) C:\Users\James\Downloads\pb_install.exe
2014-09-16 17:51 - 2014-09-16 17:53 - 137069435 _____ () C:\Users\James\Downloads\TMBG_First-Album-Live-320kbps-MP3.zip
2014-09-16 16:46 - 2014-09-16 16:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gargoyle
2014-09-16 16:46 - 2014-09-16 16:46 - 00000000 ____D () C:\Program Files (x86)\Gargoyle
2014-09-16 16:31 - 2014-09-16 16:31 - 00000000 ____D () C:\Users\James\Documents\TADS
2014-09-16 16:28 - 2014-09-16 16:28 - 02142120 _____ () C:\Users\James\Downloads\pksetup.exe
2014-09-16 16:28 - 2014-09-16 16:28 - 00151894 _____ () C:\Users\James\Downloads\bmch.zip
2014-09-15 06:59 - 2014-09-15 06:59 - 00198144 _____ () C:\Users\James\Downloads\viewapowerpointpresentationaboutactivedirectory.ppt
2014-09-14 21:01 - 2014-09-14 21:01 - 00000000 ____D () C:\Users\James\AppData\Roaming\FlacSquisher
2014-09-14 20:56 - 2014-09-14 20:56 - 00000000 ____D () C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FlacSquisher
2014-09-14 20:56 - 2014-09-14 20:56 - 00000000 ____D () C:\Program Files (x86)\FlacSquisher
2014-09-14 20:48 - 2014-09-14 20:48 - 01984824 _____ () C:\Users\James\Downloads\FlacSquisher-1.3.1-Installer.exe
2014-09-14 16:30 - 2014-09-14 16:30 - 02382005 _____ () C:\Users\James\Downloads\tweets.zip
2014-09-13 13:52 - 2014-09-13 13:52 - 00000000 ____D () C:\Users\Public\Foxit Software
2014-09-13 13:51 - 2014-09-13 13:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
2014-09-13 13:49 - 2014-09-13 13:49 - 00000000 ____D () C:\Users\James\AppData\Roaming\SanDisk
2014-09-13 13:49 - 2014-09-13 13:49 - 00000000 ____D () C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SanDisk
2014-09-13 13:47 - 2014-09-13 13:47 - 02070832 _____ (SanDisk Corporation) C:\Users\James\Downloads\SansaUpdaterInstall.exe
2014-09-13 05:29 - 2014-09-13 05:30 - 39401336 _____ (Apple Inc.) C:\Users\James\Downloads\QuickTimeInstaller.exe
2014-09-11 20:15 - 2014-09-11 20:16 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-09-11 15:15 - 2014-09-11 15:15 - 30108353 _____ () C:\Users\James\Downloads\google_5000000.7z
2014-09-11 11:40 - 2014-09-11 11:40 - 01891395 _____ (Dominik Reichl ) C:\Users\James\Downloads\KeePass-1.27-Setup.exe
2014-09-11 11:40 - 2014-09-11 11:40 - 00001107 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeePass.lnk
2014-09-11 11:40 - 2014-09-11 11:40 - 00000000 ____D () C:\Program Files (x86)\KeePass Password Safe
2014-09-10 18:05 - 2014-09-10 18:05 - 00000000 ____D () C:\Users\James\AppData\Local\{95C73209-B10A-4AE0-B660-034DD8C3E1ED}
2014-09-07 21:35 - 2014-09-07 21:35 - 01158144 _____ () C:\Users\James\Downloads\MicrosoftFixit50978.msi
2014-09-07 21:33 - 2014-09-07 21:37 - 00299008 _____ () C:\Users\James\Documents\Database1.accdb
2014-09-07 21:23 - 2014-09-07 21:23 - 00072666 _____ () C:\Users\James\Downloads\CIS-160_Con_Ques.csv
2014-09-03 22:11 - 2014-09-03 22:11 - 00001387 _____ () C:\Users\James\Desktop\Student Work - Shortcut.lnk
2014-09-03 00:21 - 2014-09-03 00:21 - 00003892 _____ () C:\Users\James\Downloads\CIS-160 Confidential Questionnaire.downloadlong.xls
2014-09-03 00:19 - 2014-09-03 00:19 - 00005318 _____ () C:\Users\James\Downloads\CIS-160 Confidential Questionnaire.download.xls
2014-09-03 00:08 - 2014-09-03 00:08 - 00005517 _____ () C:\Users\James\Downloads\Survey_ExportFile_CIS160-2014_CIS-160 Confidential Questionnaire.zip
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-09-29 16:22 - 2012-10-20 15:41 - 00000000 ____D () C:\Users\James\AppData\Local\CrashDumps
2014-09-29 16:19 - 2011-08-17 15:55 - 00000908 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2304217476-3085346115-1509824866-1001UA.job
2014-09-29 16:19 - 2011-08-17 15:55 - 00000856 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2304217476-3085346115-1509824866-1001Core.job
2014-09-29 15:44 - 2012-06-01 05:42 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-29 15:39 - 2011-10-17 11:18 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-29 12:39 - 2011-10-17 11:18 - 00000892 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-29 09:26 - 2011-08-15 14:54 - 02006070 _____ () C:\Windows\WindowsUpdate.log
2014-09-29 07:12 - 2014-08-19 18:44 - 00000000 ____D () C:\Users\James\.alice2
2014-09-28 22:20 - 2011-08-17 15:56 - 00123496 _____ () C:\Users\James\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-28 08:32 - 2011-08-17 15:37 - 00000000 ____D () C:\Users\James
2014-09-28 01:40 - 2014-05-03 22:34 - 00000000 ____D () C:\Users\James\AppData\Local\Battle.net
2014-09-28 00:33 - 2014-05-03 22:36 - 00000000 ____D () C:\Program Files (x86)\Hearthstone
2014-09-28 00:18 - 2013-01-03 05:49 - 00000000 ____D () C:\Users\James\AppData\Roaming\vlc
2014-09-27 23:03 - 2011-11-25 16:33 - 00000000 ____D () C:\Users\James\AppData\Roaming\uTorrent
2014-09-26 12:21 - 2013-02-01 01:03 - 00000000 ____D () C:\Users\James\Downloads\TorrentStuff
2014-09-26 10:12 - 2013-01-23 19:51 - 00000000 ____D () C:\Users\James\AppData\Roaming\Spotify
2014-09-24 07:32 - 2013-01-23 20:24 - 00000000 ____D () C:\Users\James\AppData\Local\Spotify
2014-09-24 01:44 - 2012-06-01 05:42 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-24 01:44 - 2012-06-01 05:41 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-24 01:44 - 2011-08-17 15:52 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-22 12:37 - 2012-03-24 17:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft ICE
2014-09-22 02:42 - 2010-11-20 23:27 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-09-17 22:52 - 2011-09-11 16:33 - 00000000 ___RD () C:\Users\James\Dropbox
2014-09-17 22:52 - 2011-09-11 16:31 - 00000000 ____D () C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-09-17 22:52 - 2011-09-11 16:31 - 00000000 ____D () C:\Users\James\AppData\Roaming\Dropbox
2014-09-16 16:31 - 2014-07-30 21:07 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-16 15:07 - 2014-05-03 22:34 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-09-15 07:34 - 2009-07-14 01:13 - 00819142 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-14 00:59 - 2014-08-17 08:54 - 00000000 ____D () C:\Users\James\Downloads\SaveTorrents
2014-09-11 20:16 - 2014-01-30 10:59 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-09-11 20:16 - 2013-10-23 15:50 - 00001783 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-09-11 20:16 - 2012-04-05 06:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-09-11 20:16 - 2012-04-05 06:44 - 00000000 ____D () C:\Program Files\iTunes
2014-09-11 11:40 - 2013-01-21 12:38 - 00000000 ____D () C:\Users\James\AppData\Roaming\KeePass
2014-09-11 10:35 - 2012-12-08 13:58 - 00000000 ____D () C:\Users\James\AppData\Local\Vitamin D Video
2014-09-11 10:07 - 2013-05-02 19:51 - 00000000 ____D () C:\Users\James\Documents\JRT Studio
2014-09-11 10:06 - 2013-03-20 09:48 - 00000000 ____D () C:\Users\James\Documents\PhraseExpress
2014-09-09 14:09 - 2012-04-25 14:33 - 00000000 ___RD () C:\Users\James\Google Drive
2014-09-08 04:43 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-08 03:40 - 2012-02-10 15:26 - 00000000 ____D () C:\Program Files (x86)\Zotero Standalone
2014-09-07 21:34 - 2011-09-02 21:31 - 00000000 ____D () C:\Users\James\AppData\Local\Microsoft Help
2014-09-07 21:26 - 2011-09-02 21:31 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-09-05 00:25 - 2012-05-15 08:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-09-05 00:23 - 2012-05-15 08:55 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-09-05 00:23 - 2012-05-15 08:55 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-08-31 15:36 - 2009-07-14 00:45 - 00022128 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-31 15:36 - 2009-07-14 00:45 - 00022128 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-30 09:30 - 2014-03-20 00:01 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-08-30 09:15 - 2014-01-23 20:14 - 00000000 ____D () C:\ProgramData\ProductData
2014-08-30 09:13 - 2014-04-02 13:07 - 00103362 _____ () C:\Windows\PFRO.log
2014-08-30 09:13 - 2014-03-30 01:00 - 00001924 _____ () C:\Windows\setupact.log
2014-08-30 09:13 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
 
Some content of TEMP:
====================
C:\Users\James\AppData\Local\Temp\CloudBackup4939.exe
C:\Users\James\AppData\Local\Temp\CountInstallation.exe
C:\Users\James\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpxn8vh2.dll
C:\Users\James\AppData\Local\Temp\Foxit Reader Updater.exe
C:\Users\James\AppData\Local\Temp\Foxit Updater.exe
C:\Users\James\AppData\Local\Temp\npp.6.6.6.Installer.exe
C:\Users\James\AppData\Local\Temp\optprosetup.exe
C:\Users\James\AppData\Local\Temp\PicasaUpdater_121.exe
C:\Users\James\AppData\Local\Temp\PicasaUpdater_355a.exe
C:\Users\James\AppData\Local\Temp\PicasaUpdater_3c25.exe
C:\Users\James\AppData\Local\Temp\PicasaUpdater_40f0.exe
C:\Users\James\AppData\Local\Temp\PicasaUpdater_5ae5.exe
C:\Users\James\AppData\Local\Temp\PicasaUpdater_636e.exe
C:\Users\James\AppData\Local\Temp\PicasaUpdater_78b1.exe
C:\Users\James\AppData\Local\Temp\PicasaUpdater_b38.exe
C:\Users\James\AppData\Local\Temp\PicasaUpdater_c7d.exe
C:\Users\James\AppData\Local\Temp\sqlite-3.7.2-sqlitejdbc.dll
C:\Users\James\AppData\Local\Temp\vcredist_x64.exe
C:\Users\James\AppData\Local\Temp\vlc-2.1.5-win32.exe
C:\Users\James\AppData\Local\Temp\xmlUpdater.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-09-26 00:20
 
==================== End Of Log ============================
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-09-2014 02
Ran by James at 2014-09-29 16:38:33
Running from C:\Users\James\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Disabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
AS: Microsoft Security Essentials (Disabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
 Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version:  - Microsoft)
µTorrent (HKCU\...\uTorrent) (Version: 3.4.2.34024 - BitTorrent Inc.)
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Acrobat XI Pro (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-000000000006}) (Version: 11.0.06 - Adobe Systems)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 4.0.0.1390 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 4.0.0.1390 - Adobe Systems Incorporated) Hidden
Adobe Bridge 1.0 (x32 Version: 001.000.000 - Adobe Systems) Hidden
Adobe Common File Installer (x32 Version: 1.00.0000 - Adobe System Incorporated) Hidden
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.167 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Help Center 1.0 (x32 Version: 001.000.000 - Adobe Systems) Hidden
Adobe Photoshop CS2 (HKLM-x32\...\Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}) (Version: 9.0 - Adobe Systems, Inc.)
Adobe Photoshop CS2 (x32 Version: 9.0 - Adobe Systems, Inc.) Hidden
Adobe Reader X (10.1.10) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.0.626 - Adobe Systems, Inc.)
Adobe Stock Photos 1.0 (x32 Version: 001.000.000 - Adobe Systems) Hidden
Advanced SystemCare 7 (HKLM-x32\...\Advanced SystemCare 7_is1) (Version: 7.1.0 - IObit)
Aimersoft DVD Creator(Build 2.6.5) (HKLM-x32\...\Aimersoft DVD Creator_is1) (Version:  - Wondershare)
Amazon Cloud Drive (HKCU\...\23ab716f18849b6f) (Version: 2.4.2013.3290 - Amazon)
Amazon Kindle (HKCU\...\Amazon Kindle) (Version:  - Amazon)
Amazon MP3 Downloader 1.0.17 (HKLM-x32\...\Amazon MP3 Downloader) (Version: 1.0.17 - Amazon Services LLC)
Amazon Music (HKCU\...\Amazon Amazon Music) (Version: 3.4.0.628 - Amazon Services LLC)
Amazon Music Importer (HKLM-x32\...\com.amazon.music.uploader) (Version: 2.1.0 - Amazon Services LLC)
Amazon Music Importer (x32 Version: 2.1.0 - Amazon Services LLC) Hidden
AMD Accelerated Video Transcoding (Version: 12.5.100.21219 - Advanced Micro Devices, Inc.) Hidden
AMD APP SDK Runtime (Version: 10.0.1084.4 - Advanced Micro Devices Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{5E03A267-415E-5383-FA8F-3CE4145663B9}) (Version: 8.0.903.0 - Advanced Micro Devices, Inc.)
AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden
AMD Media Foundation Decoders (Version: 1.0.71219.1540 - Advanced Micro Devices, Inc.) Hidden
ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Audacity 1.3.13 (Unicode) (HKLM-x32\...\Audacity 1.3 Beta (Unicode)_is1) (Version:  - Audacity Team)
Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team)
Audiosurf (HKLM-x32\...\Steam App 12900) (Version:  - BestGameEver)
avast! Free Antivirus (HKLM-x32\...\avast) (Version: 9.0.2021 - AVAST Software)
Awesomenauts (HKLM-x32\...\Steam App 204300) (Version:  - Ronimo Games)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
BioShock Infinite (HKLM-x32\...\Steam App 8870) (Version:  - Irrational Games)
Bitcasa version 1.1.6.18 (HKLM\...\{EDA09459-AD7D-4434-BA0C-647F6703EA12}_is1) (Version: 1.1.6.18 - Bitcasa Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version:  - Gearbox Software)
BRAdmin Professional 3 (HKLM-x32\...\{75C885D4-C758-4896-A3B4-90DA34B44C31}) (Version: 3.42.0007 - Brother)
Braid (HKLM-x32\...\Steam App 26800) (Version:  - Number None, Inc.)
CamStudio 2.7.2 (HKLM\...\{04B83666-3A62-452B-85D3-70F8117F2329}_is1) (Version: 2.7.2 - CamStudio Open Source)
CamStudio OSS Desktop Recorder (HKLM-x32\...\{FD9C31B6-F572-414D-81E3-89368C97A125}_is1) (Version: 2.6 Beta r294 - CamStudio Open Source Dev Team)
Camtasia Studio 8 (HKLM-x32\...\{2EB28256-1D66-49F1-AF66-691BF9A27C79}) (Version: 8.0.2.918 - TechSmith Corporation)
Canon CanoScan LiDE 110 User Registration (HKLM-x32\...\Canon CanoScan LiDE 110 User Registration) (Version:  - )
CANON iMAGE GATEWAY Task for ZoomBrowser EX (HKLM-x32\...\CANON iMAGE GATEWAY Task) (Version: 1.7.2.11 - Canon Inc.)
Canon Internet Library for ZoomBrowser EX (HKLM-x32\...\Canon Internet Library for ZoomBrowser EX) (Version: 1.6.3.9 - Canon Inc.)
Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version:  - )
Canon Solution Menu EX (HKLM-x32\...\CanonSolutionMenuEX) (Version:  - )
Canon Utilities CameraWindow (HKLM-x32\...\CameraWindowLauncher) (Version: 7.4.0.7 - Canon Inc.)
Canon Utilities CameraWindow DC 8 (HKLM-x32\...\CameraWindowDC8) (Version: 8.1.0.11 - Canon Inc.)
Canon Utilities MyCamera (HKLM-x32\...\MyCamera) (Version: 7.3.0.5 - Canon Inc.)
Canon Utilities ZoomBrowser EX (HKLM-x32\...\ZoomBrowser EX) (Version: 6.5.1.15 - Canon Inc.)
Canon ZoomBrowser EX Memory Card Utility (HKLM-x32\...\ZoomBrowser EX Memory Card Utility) (Version: 1.3.0.4 - Canon Inc.)
CanoScan LiDE 110 Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ2414) (Version:  - )
CanoScan LiDE 200 Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ4807) (Version:  - )
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.07 - Piriform)
Chrome Remote Desktop Host (HKLM-x32\...\{7D2C319D-3907-472D-9B55-EC1F240962FC}) (Version: 37.0.2062.28 - Google Inc.)
ChromecastApp (HKCU\...\{079ede36-133d-44b0-8053-c7c1fa8d2e0d}_is1) (Version: 1.5.316.0 - Google Inc.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{5971CA1F-6BDE-498F-952C-9F2BF94070A4}) (Version:  - Microsoft)
Deus Ex: Game of the Year Edition (HKLM-x32\...\Steam App 6910) (Version:  - Ion Storm)
DivX Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.44 - DivX, LLC)
D-Link Powerline AV Utility (HKLM-x32\...\D-Link Powerline AV Utility) (Version: 2.12.0.0 - D-Link Corporation.)
D-Link ShareCenter (DNS-320) Setup Wizard (HKLM-x32\...\{0975A8CC-C180-4980-94B8-E58D69BE3BD7}) (Version: 1.0.3.0 - D-Link Corporation)
Dropbox (HKCU\...\Dropbox) (Version: 2.10.30 - Dropbox, Inc.)
DVD Shrink 3.2 (HKLM-x32\...\DVD Shrink_is1) (Version:  - DVD Shrink)
Elevated Installer (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden
EndNote X5 (HKLM-x32\...\{86B3F2D6-AC2B-0015-8AE1-F2F77F781B0C}) (Version: 15.0.1.5774 - Thomson Reuters)
Evernote v. 5.6.4 (HKLM-x32\...\{DFDF0BE2-2D71-11E4-9454-00163E98E7D6}) (Version: 5.6.4.4632 - Evernote Corp.)
f.lux (HKCU\...\Flux) (Version:  - )
Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.04 - Ubisoft)
ffdshow [rev 2527] [2008-12-19] (HKLM-x32\...\ffdshow_is1) (Version: 1.0 - )
FFmpeg v0.6.2 for Audacity (HKLM-x32\...\FFmpeg for Audacity_is1) (Version:  - )
FileZilla Client 3.7.3 (HKCU\...\FileZilla Client) (Version: 3.7.3 - Tim Kosse)
FlacSquisher 1.3.1 (HKLM-x32\...\FlacSquisher) (Version: 1.3.1 - FlacSquisher)
Flickr Uploadr 3.2.1 (HKLM-x32\...\Flickr Uploadr) (Version:  - )
focus booster (HKLM-x32\...\com.focusboosterapp.focusbooster.8E5F79C899747AD22E21DB62AA496926DA6BBC64.1) (Version: 1.2 - The Memphis Agency)
focus booster (x32 Version: 1.2 - The Memphis Agency) Hidden
Folder Size 1.9.5.0 (HKLM-x32\...\{2DFA85ED-588F-4CE3-A175-29E52C3804A8}}_is1) (Version: 1.9.5.0 - MindGems, Inc.)
Formatted SD Card Recovery Pro 2.7.1 (HKLM-x32\...\{AADD15F8-50D4-6D48-9D04-7B7DFB5BA467}_is1) (Version: 2.7.1 - LionSea SoftWare)
Foxit Cloud (HKLM-x32\...\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 1.5.129.617 - Foxit Corporation)
Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 6.2.3.815 - Foxit Corporation)
Fraction Bars (HKLM-x32\...\Product_Name) (Version:  - )
FreeMind (HKLM-x32\...\B991B020-2968-11D8-AF23-444553540000_is1) (Version: 0.9.0 - )
FreeOCR v4.2 (HKLM-x32\...\freeocr_is1) (Version:  - )
Freeplane (HKLM\...\{D3941722-C4DD-4509-88C4-0E87F675A859}_is1) (Version: 1.2.20 - Open source)
Freeplane (HKLM-x32\...\{D3941722-C4DD-4509-88C4-0E87F675A859}_is1) (Version: 1.1.3 - Open source)
FTL: Faster Than Light (HKLM-x32\...\Steam App 212680) (Version:  - Subset Games)
Gargoyle (HKLM-x32\...\Gargoyle) (Version:  - )
Garmin Communicator Plugin (HKLM-x32\...\{647BB978-2876-487B-9B0E-FDB73F0EA4A2}) (Version: 4.0.4 - Garmin Ltd or its subsidiaries)
Garmin Communicator Plugin x64 (HKLM\...\{237D687E-9E50-4A30-B810-262764CC491B}) (Version: 4.0.4 - Garmin Ltd or its subsidiaries)
Garmin Communicator Plugin x64 (HKLM\...\{D2DB454C-645C-448A-A0B9-B6F6C1D75BA8}) (Version: 4.0.3 - Garmin Ltd or its subsidiaries)
Garmin Express (HKLM-x32\...\{b43ffffb-1adc-4bcb-b277-7844ebff94da}) (Version: 3.2.17.0 - Garmin Ltd or its subsidiaries)
Garmin Express (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (x32 Version: 3.2.17.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Training Center (HKLM-x32\...\{7D542452-84EB-47C0-97BA-735C523AB555}) (Version: 3.6.5 - Garmin Ltd or its subsidiaries)
Garmin USB Drivers (HKLM-x32\...\{3D5D6CFC-3097-425A-8D8F-7EAF5D57641D}) (Version: 2.3.1.0 - Garmin Ltd or its subsidiaries)
Garmin WebUpdater (HKLM-x32\...\{CCB71FF8-DE82-469C-8641-44378F4443EB}) (Version: 2.5.4 - Garmin Ltd or its subsidiaries)
GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team)
GitHub (HKCU\...\5f7eb300e2ea4ebf) (Version: 1.2.3.0 - GitHub, Inc.)
Goat Simulator (HKLM-x32\...\Steam App 265930) (Version:  - Coffee Stain Studios)
Goofball Goals (HKLM-x32\...\Goofball Goals) (Version:  - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.124 - Google Inc.)
Google Drive (HKLM-x32\...\{C6640705-7479-4EE5-BC86-879F05F65E74}) (Version: 1.17.7290.4094 - Google, Inc.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Talk Plugin (HKLM-x32\...\{C1E3DFE7-4EAD-3E9E-A826-E06055BA5921}) (Version: 5.4.2.18903 - Google)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
Google+ Auto Backup (HKCU\...\Google+ Auto Backup) (Version: 1.0.26.151 - Google, Inc.)
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
GPL Ghostscript (HKLM-x32\...\GPL Ghostscript 9.05) (Version: 9.05 - Artifex Software Inc.)
Group Shot (HKLM-x32\...\{895F4870-FDD0-4725-9DE2-5D35CFD1F89F}) (Version: 1.0.3 - Microsoft Research)
HandBrake 0.9.9.1 (HKLM-x32\...\HandBrake) (Version: 0.9.9.1 - )
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
HFSExplorer 0.21 (HKLM-x32\...\HFSExplorer) (Version: 0.21 - Catacombae Software)
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.7.0 - LIGHTNING UK!)
Inkscape 0.48.2 (HKLM-x32\...\Inkscape) (Version: 0.48.2 - )
Inky (HKCU\...\Inky) (Version: 1.0 - Arcode Corporation)
InqScribe 2.1 (HKLM-x32\...\InqScribe_is1) (Version:  - Inquirium, LLC)
Instant Eyedropper 1.75 (HKLM-x32\...\Instant Eyedropper_is1) (Version:  - )
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 3.3.8.2663 - IObit)
IPCamSetup (HKLM-x32\...\{02C39DE9-B03A-4FE7-89F9-61E224FE65CC}) (Version: 1.00.0000 - FOSCAM)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.35 - Irfan Skiljan)
iSyncr (HKLM-x32\...\{8E1F956D-631A-4146-B893-185E150D5BBD}) (Version: 4.0.10 - JRT Studio)
iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.)
Java 7 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.600 - Oracle)
Java Auto Updater (x32 Version: 2.1.60.19 - Oracle, Inc.) Hidden
JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Jing (HKLM-x32\...\{22800204-9E53-45C7-B6F3-5BB0F1C1A147}) (Version: 2.8.13007.1 - TechSmith Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
KeePass Password Safe 1.27 (HKLM-x32\...\KeePass Password Safe_is1) (Version: 1.27 - Dominik Reichl)
KeePass Password Safe 2.26 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.26 - Dominik Reichl)
Kerbal Space Program (HKLM-x32\...\Steam App 220200) (Version:  - Squad)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version:  - Valve)
Livescribe Connect (HKLM-x32\...\com.livescribe.LivescribeConnect) (Version: 1.2.1.58498 - Livescribe Inc)
Livescribe Connect (x32 Version: 1.2.1 - Livescribe Inc) Hidden
Livescribe Desktop (HKLM-x32\...\Livescribe Desktop 2.8.3) (Version: 2.8.3 - Livescribe Inc)
Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Memonic Desktop (HKLM-x32\...\{9CD06A3B-ADA5-4FDD-9D92-0445DC9C54D4}) (Version: 1.0.0 - None provided)
Mendeley Desktop 1.1.3 (HKLM-x32\...\Mendeley Desktop) (Version: 1.1.3 - Mendeley Ltd.)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Corporation (Version: 9.1.0.0 - Microsoft Corporation) Hidden
Microsoft Corporation (x32 Version: 9.1.0.0 - Microsoft Corporation) Hidden
Microsoft Image Composite Editor (HKLM\...\{B821CDAA-34DE-46FD-87C9-E6EE7158DB5D}) (Version: 1.4.4 - Microsoft Corporation)
Microsoft LifeCam (HKLM\...\{6965A8D2-465D-4F98-9FAA-0E9E2348F329}) (Version: 3.22.270.0 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Access MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Groove MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Publisher MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Visio 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Visio MUI (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SkyDrive (HKCU\...\SkyDriveSetup.exe) (Version: 17.0.2006.0314 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Sync Framework 2.0 Core Components (x64) ENU  (HKLM\...\{8CCBEC22-D2DB-4DC9-A58A-E1A1F3A38C8A}) (Version: 2.0.1578.0 - Microsoft Corporation)
Microsoft Sync Framework 2.0 Provider Services (x64) ENU  (HKLM\...\{03AC245F-4C64-425C-89CF-7783C1D3AB2C}) (Version: 2.0.1578.0 - Microsoft Corporation)
Microsoft Visio Professional 2010 (HKLM-x32\...\Office14.VISIOR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden
Mozilla Firefox 31.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 en-US)) (Version: 31.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
Music Manager (HKCU\...\MusicManager) (Version:  - Google, Inc.)
Node.js (HKLM\...\{CA802827-F661-4AD8-ADFD-ED73BED22008}) (Version: 0.10.5 - Joyent, Inc. and other Node contributors)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.6.6 - Notepad++ Team)
NVIDIA Install Application (Version: 2.1002.85.551 - NVIDIA Corporation) Hidden
OpenOffice 4.1.1 (HKLM-x32\...\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
Oracle VM VirtualBox 4.1.2 (HKLM\...\{9B9E4031-ED35-4BE0-A397-BEC2CC88C471}) (Version: 4.1.2 - Oracle Corporation)
Paint.NET v3.5.11 (HKLM\...\{72EF03F5-0507-4861-9A44-D99FD4C41418}) (Version: 3.61.0 - dotPDN LLC)
Peggle Deluxe (HKLM-x32\...\Steam App 3480) (Version:  - PopCap)
Peggle Nights (HKLM-x32\...\Steam App 3540) (Version:  - PopCap)
PhotoScape (HKLM-x32\...\PhotoScape) (Version:  - )
PhraseExpress v9.1.41 (HKLM-x32\...\PhraseExpress_is1) (Version: 9.1.41 - Bartels Media GmbH)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Picasa Uploader (HKLM-x32\...\com.webkinesis.PicasaUploaderDesktop) (Version: 0.7 - UNKNOWN)
Picasa Uploader (x32 Version: 0.7 - UNKNOWN) Hidden
Pinball FX2 (HKLM-x32\...\Steam App 226980) (Version:  - Zen Studios)
Plants vs. Zombies: Game of the Year (HKLM-x32\...\Steam App 3590) (Version:  - PopCap)
Plex Media Server (HKLM-x32\...\{9eb61479-6f2f-43c4-bfe8-12a7ea9d1acb}) (Version: 0.9.914 - Plex, Inc.)
Plex Media Server (x32 Version: 0.9.914 - Plex, Inc.) Hidden
Poker Night 2 (HKLM-x32\...\Steam App 234710) (Version:  - Telltale Games)
Portal 2 - The Final Hours (HKLM-x32\...\Steam App 104600) (Version:  - Geoff Keighley)
Portal 2 (HKLM-x32\...\Steam App 620) (Version:  - Valve)
Proteus (HKLM-x32\...\Steam App 219680) (Version:  - )
Prototype (HKLM-x32\...\Steam App 10150) (Version:  - Radical Entertainment)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
Pushbullet version 102 (HKLM-x32\...\{7578F204-49E7-4830-B051-14C23F408BFE}_is1) (Version: 102 - Pushbullet Inc)
Python 2.7.3 (HKLM-x32\...\{C0C31BCC-56FB-42a7-8766-D29E1BD74C7C}) (Version: 2.7.3150 - Python Software Foundation)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.31.1025.2010 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6392 - Realtek Semiconductor Corp.)
ResearchSoft Direct Export Helper (HKLM-x32\...\ResearchSoft Direct Export Helper) (Version:  - )
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.14.0 - SAMSUNG Electronics Co., Ltd.)
Sandboxie 3.76 (64-bit) (HKLM\...\Sandboxie) (Version: 3.76 - SANDBOXIE L.T.D)
Sansa Updater (HKCU\...\Sansa Updater) (Version: 1.407 - SanDisk Corporation)
Scribus 1.4.1 (HKLM-x32\...\Scribus 1.4.1) (Version: 1.4.1 - The Scribus Team)
Scrivener Update (HKLM-x32\...\Scrivener 1570) (Version: 1610 - Literature and Latte)
SDFormatter (HKLM-x32\...\{179324FF-7B16-4BA8-9836-055CAAEE4F08}) (Version: 4.0.0 - SD Association)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{359ADBEC-068A-4CC9-9174-77AB8EDB867A}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version:  - Microsoft) Hidden
SES Driver (HKLM\...\{D8CC254C-C671-4664-9A38-FA368D1E2C97}) (Version: 1.0.0 - Western Digital)
Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version:  - 2K Games, Inc.)
SimCalc MathWorlds for Computers (HKLM-x32\...\{132CFEBA-9AB6-4AF1-8FA9-80F898936A15}) (Version: 3.0.16 - SimCalc Projects)
Sketchpad (HKLM-x32\...\Sketchpad) (Version:  - )
SPCA1528 PC Driver (HKLM-x32\...\{570C2A84-A145-4DF0-AE9D-012584DF09DC}) (Version: 2.2.3.7 - )
Spotify (HKCU\...\Spotify) (Version: 0.9.12.10.g89b2a4fc - Spotify AB)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Sublime Text 2.0.2 (HKLM\...\Sublime Text 2_is1) (Version:  - )
SumatraPDF (HKLM-x32\...\SumatraPDF) (Version: 2.3.2 - Krzysztof Kowalczyk)
Surfing Protection (HKLM-x32\...\IObit Surfing Protection_is1) (Version: 1.0 - IObit)
Swarm Arena (HKLM-x32\...\Steam App 46600) (Version:  - )
SyncBackFree (HKLM-x32\...\SyncBackFree_is1) (Version: 6.3.13.0 - 2BrightSparks)
SyncToy 2.1 (x64) (HKLM\...\{88DAAF05-5A72-46D2-A7C5-C3759697E943}) (Version: 2.1.0 - Microsoft)
Talisman: Digital Edition (HKLM-x32\...\Steam App 247000) (Version:  - Nomad Games Limited)
Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version:  - Valve)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
TinkerPlots 2 (HKLM-x32\...\TinkerPlots 2) (Version:  - Key Curriculum Press)
TotalRecovery Pro (HKLM-x32\...\{74449814-B2A1-41FB-890C-60CF2FD0DA96}) (Version: 7.00.0000 - FarStone Inc.)
TrueCrypt (HKLM-x32\...\TrueCrypt) (Version: 7.1a - TrueCrypt Foundation)
Unity Web Player (HKCU\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Universe Sandbox (HKLM-x32\...\Steam App 72200) (Version:  - Giant Army)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version:  - Microsoft)
Update for Microsoft Office 2007 Help for Common Features (KB963673) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{AB365889-0395-4FAD-B702-CA5985D53D42}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6FAA03BD-2B51-4029-9AD9-64A3B8E3C84C}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.VISIOR_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.VISIOR_{5E8EB600-8B94-429E-873E-98369C6DC1BC}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.VISIOR_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version:  - Microsoft)
Update for Microsoft Office Access 2007 Help (KB963663) (HKLM-x32\...\{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{6B76A18A-AA1E-42AB-A7AD-6C84BBB43987}) (Version:  - Microsoft)
Update for Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{199DF7B6-169C-448C-B511-1054101BE9C9}) (Version:  - Microsoft)
Update for Microsoft Office Infopath 2007 Help (KB963662) (HKLM-x32\...\{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{716B81B8-B13C-41DF-8EAC-7A2F656CAB63}) (Version:  - Microsoft)
Update for Microsoft Office OneNote 2007 Help (KB963670) (HKLM-x32\...\{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2744EF05-38E1-4D5D-B333-E021EDAEA245}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{ED38F8A3-4F61-494E-8BCA-E3AC7760C924}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{0451F231-E3E3-4943-AB9F-58EB96171784}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2878297) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{9B1DEEA3-B4ED-49F0-9EF7-4A820EEEA7F1}) (Version:  - Microsoft)
Update for Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{397B1D4F-ED7B-4ACA-A637-43B670843876}) (Version:  - Microsoft)
Update for Microsoft Office Publisher 2007 Help (KB963667) (HKLM-x32\...\{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2E40DE55-B289-4C8B-8901-5D369B16814F}) (Version:  - Microsoft)
Update for Microsoft Office Script Editor Help (KB963671) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{CD11C6A2-FFC6-4271-8EAB-79C3582F505C}) (Version:  - Microsoft)
Update for Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{80E762AA-C921-4839-9D7D-DB62A72C0726}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version:  - Microsoft)
Update for Microsoft Visio 2010 (KB2553444) 32-Bit Edition (HKLM-x32\...\{90140000-0054-0409-0000-0000000FF1CE}_Office14.VISIOR_{51EBE89D-6C1B-4D57-8FEC-87B45DE0F39C}) (Version:  - Microsoft)
Update for Microsoft Visio 2010 (KB2553444) 32-Bit Edition (HKLM-x32\...\{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{799005D3-9B70-4219-AFE0-BC479614CC4D}) (Version:  - Microsoft)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Virtual Account Numbers (HKLM-x32\...\{DE700910-58F7-4D2E-B7E6-3BA2DA1B6806}) (Version: 3.8.0.0 - Citi)
Virtual Account Numbers (x32 Version: 1.0.6.0 - Citi) Hidden
Vitamin D Video 1.4.2 (HKLM-x32\...\Vitamin D Video_is1) (Version:  - Vitamin D Video, LLC)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Vonage Companion (HKLM-x32\...\{BBE7C512-07DF-480F-A0A1-0FC3192020CD}) (Version: 1.0 - Vonage)
VueScan (HKLM\...\VueScan) (Version:  - )
Waterfox (HKLM\...\{FD7DEB7B-8CEA-44E5-AB2D-7C66786C0563}) (Version: 18.0.1 - Waterfox Limited)
WD SmartWare Drive Manager (HKLM\...\{BEC2EFB7-93E4-4F5F-B056-602ACEC2B759}) (Version: 1.5.0 - Western Digital)
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Garmin (grmnusb) GARMIN Devices  (04/19/2012 2.3.1.0) (HKLM\...\98157A226B40B173301B0F53C8E98C47805D5152) (Version: 04/19/2012 2.3.1.0 - Garmin)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Windows Driver Package - Western Digital Technologies (WDC_SAM) WDC_SAM  (01/19/2011 1.0.0009.0) (HKLM\...\4CA7CFBB29889F25ACB3DF6E3A42BAE29EB43B20) (Version: 01/19/2011 1.0.0009.0 - Western Digital Technologies)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows XP Mode (HKLM\...\{1374CC63-B520-4f3f-98E8-E9020BF01CFF}) (Version: 1.3.7600.16423 - Microsoft Corporation)
WinPatrol (HKLM\...\{4BB7A109-FDB5-45E3-9DB9-ECB2EA7B80EE}) (Version: 28.6.2013.0 - BillP Studios)
WinX DVD Ripper 5.5.7 (HKLM-x32\...\WinX DVD Ripper_is1) (Version:  - Digiarty Software, Inc.)
WinX HD Video Converter Deluxe 4.0.0 (HKLM-x32\...\WinX HD Video Converter Deluxe_is1) (Version:  - Digiarty Software, Inc.)
Wunderlist (HKLM-x32\...\{64d93c40-f16c-49f0-93f1-e7304a8cb538}) (Version: 2.2.1.20 - 6 Wunderkinder GmbH)
Wunderlist (x32 Version: 2.2.1.20 - 6 Wunderkinder GmbH) Hidden
XCOM: Enemy Unknown (HKLM-x32\...\Steam App 200510) (Version:  - Firaxis Games)
Zero Assumption Recovery Version 9 (HKLM-x32\...\Zero Assumption Recovery_is1) (Version:  - )
Zotero Standalone 4.0.22 (x86 en-US) (HKLM-x32\...\Zotero Standalone 4.0.22 (x86 en-US)) (Version: 4.0.22 - Zotero)
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\James\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\James\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\James\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\James\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\James\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\James\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\James\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\James\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\James\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\amd64\FileSyncApi64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\James\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\James\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\James\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\James\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\James\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\James\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\James\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\James\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\James\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File
 
==================== Restore Points  =========================
 
22-09-2014 13:23:19 Windows Update
26-09-2014 08:25:19 Windows Update
29-09-2014 02:08:03 Installed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
29-09-2014 02:09:39 Installed OpenOffice 4.1.1
29-09-2014 13:23:44 Windows Update
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 22:34 - 2009-06-10 17:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {16BC54D2-70D9-4E45-BA16-48F1810434A3} - System32\Tasks\StormFall TW1 => Chrome.exe --app=http://plarium.com/p...sherID=2_1_2_72 --app-window-size=1680,1050
Task: {174EDB21-4261-4CB9-86E6-22FDAF57A88F} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-08-14] (AVAST Software)
Task: {1D0ADE47-9BA3-47A1-BE0A-E9B759B2C8D2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2304217476-3085346115-1509824866-1001Core => C:\Users\James\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-17] (Google Inc.)
Task: {2C8B9ACA-3F4A-4692-BFA2-4A6B9B93789C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2304217476-3085346115-1509824866-1001UA => C:\Users\James\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-17] (Google Inc.)
Task: {3A112D96-B713-4EF9-83A1-377169C22FB7} - System32\Tasks\2BrightSparks\SyncBackFree\Edo-James\SyncBackFree Music Backup to 221B => C:\Program Files (x86)\2BrightSparks\SyncBackFree\SyncBackFree.exe [2013-02-25] (2BrightSparks Pte Ltd)
Task: {3AB71D6E-0D06-4FE0-95B6-94183F266C14} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-10-21] (Piriform Ltd)
Task: {4DCF02F9-0371-48D9-B616-6FF693B88C4A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-17] (Google Inc.)
Task: {576DF159-05D4-4801-ACC4-3ED2202EFD59} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2014-08-25] (IObit)
Task: {5928C809-F9AD-4353-91A4-B83AE959591E} - System32\Tasks\ASC7_SkipUac_James => C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASC.exe [2014-01-08] (IObit)
Task: {5AC6A9C6-363E-42AD-B333-E27D1B9F6371} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {5F9E0AB7-B170-4633-B724-DA4BC9BADE41} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => c:\Program Files\Microsoft IntelliPoint\IPoint.exe
Task: {6E2EB5CF-AC11-4537-AC81-71EE001D4F13} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express Self Updater\ExpressSelfUpdater.exe [2014-08-07] ()
Task: {A6B2FA0A-3C26-4DDD-A302-66B82779AF00} - System32\Tasks\2BrightSparks\SyncBackFree\Edo-James\SyncBackFree Dropbox Backup to 221B => C:\Program Files (x86)\2BrightSparks\SyncBackFree\SyncBackFree.exe [2013-02-25] (2BrightSparks Pte Ltd)
Task: {C106DB04-34D3-42F5-A888-5C66E2D8D720} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: {C67E34F8-A1EB-41C3-80BF-2BB7683B060B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-17] (Google Inc.)
Task: {DF5286E9-78FF-42ED-ACDD-E05920ECDABB} - System32\Tasks\StormFall TW2 => Chrome.exe --app=http://plarium.com/p...sherID=2_1_2_72 --app-window-size=1680,1050
Task: {E23F3AFE-F905-47B0-AC09-422E7CE4E84B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-24] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2304217476-3085346115-1509824866-1001Core.job => C:\Users\James\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2304217476-3085346115-1509824866-1001UA.job => C:\Users\James\AppData\Local\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) =============
 
2011-08-21 14:18 - 2010-09-15 15:01 - 00065536 _____ () C:\Program Files (x86)\Brother\BRAdmin Professional 3\bratimer.exe
2012-06-27 22:28 - 2009-11-30 18:04 - 00192512 _____ () C:\Program Files (x86)\FarStone\TotalRecovery\Client\cbp\DCSchdler.exe
2012-12-20 03:24 - 2012-12-20 03:24 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2009-11-26 18:24 - 2009-11-26 18:24 - 00077824 _____ () C:\Program Files (x86)\FarStone\TotalRecovery\Client\DCNTranProc.exe
2014-05-01 21:23 - 2014-02-21 13:17 - 00313856 _____ () C:\Program Files\Bitcasa\ExplorerMenu.dll
2014-05-01 21:23 - 2014-02-21 13:06 - 02064384 _____ () C:\Program Files\Bitcasa\bitcasaui.dll
2014-09-22 15:26 - 2014-08-28 14:53 - 00822320 _____ () C:\Program Files (x86)\Pushbullet\pushbullet_app.exe
2010-01-02 10:42 - 2010-01-02 10:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2014-09-22 15:26 - 2014-07-07 16:18 - 00050176 _____ () C:\Program Files (x86)\Pushbullet\ctx\pushbullet_ctx.dll
2014-05-12 05:49 - 2014-05-12 05:49 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2014-06-14 22:15 - 2014-09-05 20:54 - 06281536 _____ () C:\Users\James\AppData\Local\Amazon Music\Amazon Music Helper.exe
2014-09-24 23:42 - 2014-09-22 23:15 - 01442120 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\libglesv2.dll
2014-09-24 23:42 - 2014-09-22 23:15 - 00168264 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\libegl.dll
2014-09-24 23:42 - 2014-09-22 23:15 - 10328904 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\pdf.dll
2014-09-24 23:42 - 2014-09-22 23:15 - 00405320 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\ppGoogleNaClPluginChrome.dll
2014-09-24 23:42 - 2014-09-22 23:15 - 01831752 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\ffmpegsumo.dll
2014-09-24 23:42 - 2014-09-22 23:15 - 00339272 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\libexif.dll
2014-09-24 23:42 - 2014-09-22 23:15 - 26697032 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\PepperFlash\pepflashplayer.dll
2014-01-23 20:13 - 2013-10-25 13:08 - 00517408 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\sqlite3.dll
2012-06-27 22:28 - 2009-12-02 16:02 - 00073800 _____ () C:\Program Files (x86)\FarStone\TotalRecovery\Client\cbp\DCNLog.dll
2012-06-27 22:28 - 2009-12-14 11:31 - 00053330 _____ () C:\Program Files (x86)\FarStone\TotalRecovery\Client\cbp\jobCancel.dll
2011-10-27 18:56 - 2011-10-27 18:56 - 00276992 _____ () C:\Program Files (x86)\Common Files\Livescribe\PenComm\PenCommSdk.dll
2009-11-26 18:24 - 2009-11-26 18:24 - 00077824 _____ () C:\Program Files (x86)\FarStone\TotalRecovery\Client\TransferManager.dll
2009-11-26 18:24 - 2009-11-26 18:24 - 00057344 _____ () C:\Program Files (x86)\FarStone\TotalRecovery\Client\CommonFun.dll
2010-03-04 19:57 - 2010-03-04 19:57 - 00036952 _____ () C:\Program Files (x86)\FarStone\TotalRecovery\Client\FTPFunModule.dll
2009-11-26 18:24 - 2009-11-26 18:24 - 00170496 _____ () C:\Program Files (x86)\FarStone\TotalRecovery\Client\FtpPipeModule.dll
2009-11-26 18:26 - 2009-11-26 18:26 - 00057344 _____ () C:\Program Files (x86)\FarStone\TotalRecovery\Client\ibpfiles\DCNIBPLogHelper.dll
2013-03-20 09:47 - 2013-06-14 11:42 - 00442064 _____ () C:\Program Files (x86)\PhraseExpress\pexlang.dll
2014-08-14 16:47 - 2014-08-14 16:47 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-08-14 16:47 - 2014-08-14 16:47 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll
2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2012-02-10 15:26 - 2014-09-08 03:40 - 03711392 _____ () C:\Program Files (x86)\Zotero Standalone\xulrunner\mozjs.dll
2014-09-17 22:52 - 2014-09-17 22:52 - 00043008 _____ () c:\users\james\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpxn8vh2.dll
2013-08-23 15:01 - 2013-08-23 15:01 - 25100288 _____ () C:\Users\James\AppData\Roaming\Dropbox\bin\libcef.dll
2014-01-20 14:16 - 2014-01-20 14:16 - 00237384 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
2013-08-07 15:25 - 2013-08-07 15:25 - 00093696 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
2014-09-21 12:00 - 2014-09-21 12:00 - 02864640 _____ () C:\Program Files\AVAST Software\Avast\defs\14092100\algo.dll
2014-09-21 14:38 - 2014-09-21 14:38 - 02864640 _____ () C:\Program Files\AVAST Software\Avast\defs\14092101\algo.dll
2014-09-29 14:53 - 2014-09-29 14:53 - 02867200 _____ () C:\Program Files\AVAST Software\Avast\defs\14092901\algo.dll
2014-08-26 16:47 - 2014-08-26 16:47 - 00436576 _____ () C:\Program Files (x86)\Evernote\Evernote\libxml2.dll
2014-08-26 16:47 - 2014-08-26 16:47 - 00318304 _____ () C:\Program Files (x86)\Evernote\Evernote\libtidy.dll
2014-09-22 15:26 - 2014-01-07 08:09 - 00019456 _____ () C:\Program Files (x86)\Pushbullet\greenlet.pyd
2014-09-22 15:26 - 2014-04-30 06:56 - 00050176 _____ () C:\Program Files (x86)\Pushbullet\gevent._semaphore.pyd
2014-09-22 15:26 - 2013-11-10 19:24 - 00087552 _____ () C:\Program Files (x86)\Pushbullet\_ctypes.pyd
2014-09-22 15:26 - 2014-01-26 09:49 - 00099328 _____ () C:\Program Files (x86)\Pushbullet\win32api.pyd
2014-09-22 15:26 - 2014-01-26 09:48 - 00110592 _____ () C:\Program Files (x86)\Pushbullet\pywintypes27.dll
2014-09-22 15:26 - 2013-11-10 19:24 - 00044544 _____ () C:\Program Files (x86)\Pushbullet\_socket.pyd
2014-09-22 15:26 - 2013-11-10 19:24 - 00899584 _____ () C:\Program Files (x86)\Pushbullet\_ssl.pyd
2014-09-22 15:26 - 2013-11-10 19:24 - 00010240 _____ () C:\Program Files (x86)\Pushbullet\select.pyd
2014-09-22 15:26 - 2013-11-10 19:24 - 00358400 _____ () C:\Program Files (x86)\Pushbullet\_hashlib.pyd
2014-09-22 15:26 - 2013-11-10 19:24 - 00047616 _____ () C:\Program Files (x86)\Pushbullet\_sqlite3.pyd
2014-09-22 15:26 - 2013-11-10 19:23 - 00426496 _____ () C:\Program Files (x86)\Pushbullet\sqlite3.dll
2014-09-22 15:26 - 2012-06-04 11:03 - 00603136 _____ () C:\Program Files (x86)\Pushbullet\pysqlite2._sqlite.pyd
2014-09-22 15:26 - 2014-01-04 14:29 - 01176576 _____ () C:\Program Files (x86)\Pushbullet\wx._core_.pyd
2014-09-22 15:26 - 2014-01-04 14:29 - 00806400 _____ () C:\Program Files (x86)\Pushbullet\wx._gdi_.pyd
2014-09-22 15:26 - 2014-01-04 14:29 - 00815616 _____ () C:\Program Files (x86)\Pushbullet\wx._windows_.pyd
2014-09-22 15:26 - 2014-01-04 14:29 - 01067520 _____ () C:\Program Files (x86)\Pushbullet\wx._controls_.pyd
2014-09-22 15:26 - 2014-01-04 14:29 - 00733184 _____ () C:\Program Files (x86)\Pushbullet\wx._misc_.pyd
2014-09-22 15:26 - 2014-04-30 06:55 - 00208384 _____ () C:\Program Files (x86)\Pushbullet\gevent.core.pyd
2014-09-22 15:26 - 2013-11-10 19:24 - 00686080 _____ () C:\Program Files (x86)\Pushbullet\unicodedata.pyd
2014-09-22 15:26 - 2014-01-26 09:49 - 00167936 _____ () C:\Program Files (x86)\Pushbullet\win32gui.pyd
2014-07-12 14:10 - 2014-07-12 14:10 - 10683392 _____ () C:\Users\James\AppData\Local\Programs\Google\MusicManager\QtWebKit4.dll
2014-07-12 14:10 - 2014-07-12 14:10 - 07741952 _____ () C:\Users\James\AppData\Local\Programs\Google\MusicManager\QtGui4.dll
2014-07-12 14:10 - 2014-07-12 14:10 - 02248192 _____ () C:\Users\James\AppData\Local\Programs\Google\MusicManager\QtCore4.dll
2014-07-12 14:10 - 2014-07-12 14:10 - 01681408 _____ () C:\Users\James\AppData\Local\Programs\Google\MusicManager\QtNetwork4.dll
2014-07-22 18:01 - 2014-07-22 18:01 - 00117248 _____ () C:\Users\James\AppData\Local\Programs\Google\MusicManager\libaacdec.dll
2014-07-22 18:01 - 2014-07-22 18:01 - 00231936 _____ () C:\Users\James\AppData\Local\Programs\Google\MusicManager\libmpgdec.dll
2014-07-22 18:02 - 2014-07-22 18:02 - 00253440 _____ () C:\Users\James\AppData\Local\Programs\Google\MusicManager\libid3tag.dll
2014-07-22 18:01 - 2014-07-22 18:01 - 00344064 _____ () C:\Users\James\AppData\Local\Programs\Google\MusicManager\libaudioenc.dll
2014-07-12 14:10 - 2014-07-12 14:10 - 00026624 _____ () C:\Users\James\AppData\Local\Programs\Google\MusicManager\imageformats\qgif4.dll
2013-07-10 19:07 - 2013-07-10 19:07 - 00756888 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL
2013-12-21 02:04 - 2013-12-21 02:04 - 03989888 _____ () C:\Program Files (x86)\Adobe\Acrobat 11.0\PDFMaker\Common\AdobePDFMakerX.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (whitelisted) =============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
==================== MSCONFIG/TASK MANAGER disabled items =========
 
(Currently there is no automatic fix for this section.)
 
 
========================= Accounts: ==========================
 
Administrator (S-1-5-21-2304217476-3085346115-1509824866-500 - Administrator - Disabled)
Guest (S-1-5-21-2304217476-3085346115-1509824866-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-2304217476-3085346115-1509824866-1011 - Limited - Enabled)
James (S-1-5-21-2304217476-3085346115-1509824866-1001 - Administrator - Enabled) => C:\Users\James
Walternate (S-1-5-21-2304217476-3085346115-1509824866-1012 - Limited - Enabled) => C:\Users\Walternate
 
==================== Faulty Device Manager Devices =============
 
Name: iPodDrv
Description: iPodDrv
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: iPodDrv
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
Name: VirtualBox Host-Only Ethernet Adapter
Description: VirtualBox Host-Only Ethernet Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Oracle Corporation
Service: VBoxNetAdp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (09/29/2014 03:49:09 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 37.0.2062.124, time stamp: 0x5420dbc4
Faulting module name: chrome.dll, version: 37.0.2062.124, time stamp: 0x5420d7f7
Exception code: 0x80000003
Fault offset: 0x0000000000052efa
Faulting process id: 0xc8fc
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
 
Error: (09/29/2014 09:33:46 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 37.0.2062.124, time stamp: 0x5420dbc4
Faulting module name: chrome.dll, version: 37.0.2062.124, time stamp: 0x5420d7f7
Exception code: 0x80000003
Fault offset: 0x0000000000052efa
Faulting process id: 0x7024
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
 
Error: (09/29/2014 04:31:48 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Acrobat.exe, version: 11.0.6.70, time stamp: 0x52b52919
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x8d082454
Faulting process id: 0xc3c4
Faulting application start time: 0xAcrobat.exe0
Faulting application path: Acrobat.exe1
Faulting module path: Acrobat.exe2
Report Id: Acrobat.exe3
 
Error: (09/29/2014 04:00:07 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 37.0.2062.124, time stamp: 0x5420dbc4
Faulting module name: chrome.dll, version: 37.0.2062.124, time stamp: 0x5420d7f7
Exception code: 0x80000003
Fault offset: 0x0000000000052efa
Faulting process id: 0xc03c
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
 
Error: (09/29/2014 03:40:53 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 37.0.2062.124, time stamp: 0x5420dbc4
Faulting module name: chrome.dll, version: 37.0.2062.124, time stamp: 0x5420d7f7
Exception code: 0x80000003
Fault offset: 0x0000000000052efa
Faulting process id: 0x6fb0
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
 
Error: (09/29/2014 03:11:53 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 37.0.2062.124, time stamp: 0x5420dbc4
Faulting module name: chrome.dll, version: 37.0.2062.124, time stamp: 0x5420d7f7
Exception code: 0x80000003
Fault offset: 0x0000000000052efa
Faulting process id: 0xbf78
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
 
Error: (09/29/2014 00:03:07 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 37.0.2062.124, time stamp: 0x5420dbc4
Faulting module name: chrome.dll, version: 37.0.2062.124, time stamp: 0x5420d7f7
Exception code: 0x80000003
Fault offset: 0x0000000000052efa
Faulting process id: 0xb428
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
 
Error: (09/28/2014 04:19:19 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 37.0.2062.124, time stamp: 0x5420dbc4
Faulting module name: chrome.dll, version: 37.0.2062.124, time stamp: 0x5420d7f7
Exception code: 0x80000003
Fault offset: 0x0000000000052efa
Faulting process id: 0x88d8
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
 
Error: (09/27/2014 06:49:11 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 37.0.2062.124, time stamp: 0x5420dbc4
Faulting module name: chrome.dll, version: 37.0.2062.124, time stamp: 0x5420d7f7
Exception code: 0x80000003
Fault offset: 0x0000000000052efa
Faulting process id: 0x9bb8
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
 
Error: (09/25/2014 11:48:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 37.0.2062.124, time stamp: 0x5420dbc4
Faulting module name: chrome.dll, version: 37.0.2062.124, time stamp: 0x5420d7f7
Exception code: 0x80000003
Fault offset: 0x0000000000052efa
Faulting process id: 0xa950
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
 
 
System errors:
=============
Error: (09/29/2014 07:39:54 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 70. The internal error state is 105.
 
Error: (09/23/2014 10:31:35 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {ED1D0FDF-4414-470A-A56D-CFB68623FC58}
 
Error: (09/18/2014 11:19:43 PM) (Source: RasSstp) (EventID: 1) (User: )
Description: CoId={937678CA-6D61-4DDF-A6BA-3BA592D98CD6}:The initial Secure Socket Tunneling Protocol request could not be successfully sent to the server. This can be due to network connectivity issues or certificate (trust) issues. The detailed error message is provided below. Correct the problem and try again.
 
A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.
 
Error: (09/18/2014 11:17:51 PM) (Source: RasSstp) (EventID: 1) (User: )
Description: CoId={DDA8E7A4-9F9C-4EFC-B869-ACA86D6645D7}:The initial Secure Socket Tunneling Protocol request could not be successfully sent to the server. This can be due to network connectivity issues or certificate (trust) issues. The detailed error message is provided below. Correct the problem and try again.
 
A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.
 
Error: (09/18/2014 11:15:59 PM) (Source: RasSstp) (EventID: 1) (User: )
Description: CoId={AED0C448-7CC2-423B-97CA-EDE18B1AAFCC}:The initial Secure Socket Tunneling Protocol request could not be successfully sent to the server. This can be due to network connectivity issues or certificate (trust) issues. The detailed error message is provided below. Correct the problem and try again.
 
A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.
 
Error: (09/18/2014 11:14:07 PM) (Source: RasSstp) (EventID: 1) (User: )
Description: CoId={45DC0492-71AE-4426-B1DB-1B27BAE737D5}:The initial Secure Socket Tunneling Protocol request could not be successfully sent to the server. This can be due to network connectivity issues or certificate (trust) issues. The detailed error message is provided below. Correct the problem and try again.
 
A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.
 
Error: (09/13/2014 01:51:56 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The Foxit Cloud Safe Update Service service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.
 
Error: (09/03/2014 09:25:03 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.183.1368.0
 
Update Source: %NT AUTHORITY59
 
Update Stage: 4.5.0216.00
 
Source Path: 4.5.0216.01
 
Signature Type: %NT AUTHORITY602
 
Update Type: %NT AUTHORITY604
 
User: NT AUTHORITY\SYSTEM
 
Current Engine Version: %NT AUTHORITY605
 
Previous Engine Version: %NT AUTHORITY606
 
Error code: %NT AUTHORITY607
 
Error description: %NT AUTHORITY608
 
Error: (08/30/2014 09:14:35 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The iPodDrv service failed to start due to the following error: 
%%2
 
Error: (08/30/2014 09:14:04 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The SPCA1528 Video Camera Service service failed to start due to the following error: 
%%1058
 
 
Microsoft Office Sessions:
=========================
Error: (09/27/2012 05:00:38 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 13429 seconds with 2760 seconds of active time.  This session ended with a crash.
 
 
CodeIntegrity Errors:
===================================
  Date: 2014-03-20 00:12:44.587
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files\Common Files\ATI Technologies\Multimedia\AMDMFTDecoder_64.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-10-27 22:43:40.659
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-08-28 21:58:18.400
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-08-28 17:52:45.350
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-08-28 17:46:45.311
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-08-28 17:35:44.076
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-08-28 16:25:46.237
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-08-28 16:16:52.676
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-08-28 15:45:45.419
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2012-08-27 15:11:15.628
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-2300 CPU @ 2.80GHz
Percentage of memory in use: 66%
Total physical RAM: 12269.23 MB
Available physical RAM: 4087.13 MB
Total Pagefile: 24536.63 MB
Available Pagefile: 10675.07 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:931.51 GB) (Free:436.98 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive e: (NeutralZone) (Fixed) (Total:232.88 GB) (Free:138.05 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: E8342C9D)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 232.9 GB) (Disk ID: 0ACE9005)
Partition 1: (Not Active) - (Size=232.9 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================
 
 
 
 

  • 0

#6
Biscuithd

Biscuithd

    Trusted Helper

  • Malware Removal
  • 2,573 posts

Hi James,

 

Still working through your logs. A quick quesiton...have you ever run CryptoPrevent on this machine? It wouldn't be "bad" if you did, it would just confirm a few things that I'm seeing. :)


  • 0

#7
drmomentum

drmomentum

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

I don't remember doing it, but it looks like last year I did download CryptoPrevent, and I probably ran it.

 

I do research with this machine, and I keep important data on it, so I was probably paranoid about getting hit with a cryptolocker infestation. I keep regular backups, but I did not want to be put in the situation of possibly losing any of my analysis, which would put my graduate work in jeopardy.

 

Thanks for your help.


  • 0

#8
Biscuithd

Biscuithd

    Trusted Helper

  • Malware Removal
  • 2,573 posts
You did exactly the right thing. I didn't mean to imply otherwise! Just wanted to make sure what I was looking at is all :)
  • 0

#9
drmomentum

drmomentum

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

Biscuithd,

Good to know! Thanks. 

-James


  • 0

#10
Biscuithd

Biscuithd

    Trusted Helper

  • Malware Removal
  • 2,573 posts
warning.gif P2P warning!

  • P2P programs, as they are legal itself, are often used to obtain some illegal downloads. Currently it's one of the best ways to get infected. There have been some extreme cases in which passwords, private or financial data was exposed to file sharing network because of bad P2P configuration.

I strongly recommend full uninstallation of any P2P apps. To do so:
  • Press the WindowsKey.png + R on your keyboard at the same time. Type appwiz.cpl and click OK.
  • Search for previously mentioned program(s), right-click the entry and click Uninstall.


FRST.gif Fix with Farbar Recovery Scan Tool

 

icon_exclaim.gif This fix was created for this user for use on that particular machine. icon_exclaim.gif
icon_exclaim.gif Running it on another one may cause damage and render the system unstable. icon_exclaim.gif

Press the WindowsKey.png + R on your keyboard at the same time. Type Notepad and click OK.
  • Copy the entire content of the codebox below and paste into the Notepad document:
    start
    
    HKLM-x32\...\Run: [] => [X]
    
    HKU\S-1-5-21-2304217476-3085346115-1509824866-1001\...\Run: [uTorrent] => C:\Users\James\AppData\Roaming\uTorrent\uTorrent.exe [1416016 2014-09-26] (BitTorrent Inc.)
    
    BHO: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File
    
    BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
    
    Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
    
    Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
    
    FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll No File
    
    FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll No File
    
    FF Plugin HKCU: @doubletwist.com/NPPodcast -> C:\Program Files (x86)\Common Files\doubleTwist\NPPodcast.dll No File
    
    2014-09-24 00:02 - 2014-09-24 00:02 - 00003674 _____ () C:\Windows\System32\Tasks\StormFall TW2
    
    2014-09-24 00:02 - 2014-09-24 00:02 - 00003674 _____ () C:\Windows\System32\Tasks\StormFall TW1
    
    2014-09-24 00:02 - 2014-09-24 00:02 - 00000000 ____D () C:\Users\James\AppData\Roaming\StormFall
    
    2014-09-24 00:02 - 2014-09-24 00:02 - 00000000 ____D () C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
    
    2014-09-24 00:02 - 2014-09-24 00:02 - 00000000 ____D () C:\Users\James\AppData\Local\StormFall
    
    CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\James\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
    
    CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\James\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File
    
    Task: {16BC54D2-70D9-4E45-BA16-48F1810434A3} - System32\Tasks\StormFall TW1 => Chrome.exe --app=http://plarium.com/p...sherID=2_1_2_72 --app-window-size=1680,1050
    
    Task: {DF5286E9-78FF-42ED-ACDD-E05920ECDABB} - System32\Tasks\StormFall TW2 => Chrome.exe --app=http://plarium.com/p...sherID=2_1_2_72 --app-window-size=1680,1050
    
    C:\Windows\System32\Tasks\StormFall TW2
    
    C:\Windows\System32\Tasks\StormFall TW1
    
    C:\Users\James\AppData\Roaming\StormFall
    
    C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
    
    end
  • Click File, Save As and type fixlist.txt as the File Name.
Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!
  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please post it to your reply.
 
adwcleaner_new.png Scan with AdwCleaner
 
Please download AdwCleaner by Xplode and save the file to your desktop.
 
  • Right-click on adwcleaner_new.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  •  
  • Follow the prompts and click Scan.
  •  
  • Upon completion, click Report. A log (AdwCleaner[R*].txt) will open.
 
Please include the contents of that file in your reply.

 

 

JRTbythisisu.png Fix with Junkware Removal Tool
 
Please download JRT by Thisisu and save the file to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.
 
  • Right-click on JRTbythisisu.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Follow the prompts and let this process run uninterrupted.
  • This scan can take a while, depending on your System specs.
  • Upon completion, a log (JRT.txt) will open on your desktop.
 
Please include the contents of that file in your reply.
 
Do not forget to re-enable your previously switched off protection software!
Please also manually reboot your machine after this procedure.

 

51a612a8b27e2-Zoek.png Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.



  • Right-click on 51a612a8b27e2-Zoek.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
    createsrpoint;
    
    process;
    
    services-list;
    
    systemspecs;
    
    startupall;
    
    skipfix-iedefaults;
    
    firefoxlook;
    
    chromelook;
    
    filesrcm;
    
    installedprogs;
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)

Post its content into your next reply.

 

 

 


  • 0

Advertisements


#11
drmomentum

drmomentum

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

Thanks! I ran these tools and will observe my system to see if the behavior of Chrome changes. 

 

Here are the logs you requested I post, in order of the tools I ran, so you can see how it looks.

 

I think I'm going to do some selective uninstalling as well of programs I don't use, just for my own sanity.

 

 

------------------------------------------------------------------------------------------------------------------------------------------------


------------------------------------------------------------------------------------------------------------------------------------------------

 

 

 

 

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-09-2014 02
Ran by James at 2014-10-02 11:16:18 Run:1
Running from C:\Users\James\Desktop
Loaded Profile: James (Available profiles: James & Walternate & DefaultAppPool)
Boot Mode: Normal
==============================================
 
Content of fixlist:
*****************
start
 
HKLM-x32\...\Run: [] => [X]
 
HKU\S-1-5-21-2304217476-3085346115-1509824866-1001\...\Run: [uTorrent] => C:\Users\James\AppData\Roaming\uTorrent\uTorrent.exe [1416016 2014-09-26] (BitTorrent Inc.)
 
BHO: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File
 
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
 
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
 
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
 
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll No File
 
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll No File
 
FF Plugin HKCU: @doubletwist.com/NPPodcast -> C:\Program Files (x86)\Common Files\doubleTwist\NPPodcast.dll No File
 
2014-09-24 00:02 - 2014-09-24 00:02 - 00003674 _____ () C:\Windows\System32\Tasks\StormFall TW2
 
2014-09-24 00:02 - 2014-09-24 00:02 - 00003674 _____ () C:\Windows\System32\Tasks\StormFall TW1
 
2014-09-24 00:02 - 2014-09-24 00:02 - 00000000 ____D () C:\Users\James\AppData\Roaming\StormFall
 
2014-09-24 00:02 - 2014-09-24 00:02 - 00000000 ____D () C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
 
2014-09-24 00:02 - 2014-09-24 00:02 - 00000000 ____D () C:\Users\James\AppData\Local\StormFall
 
CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\James\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
 
CustomCLSID: HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\James\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File
 
Task: {16BC54D2-70D9-4E45-BA16-48F1810434A3} - System32\Tasks\StormFall TW1 => Chrome.exe --app=http://plarium.com/p...sherID=2_1_2_72 --app-window-size=1680,1050
 
Task: {DF5286E9-78FF-42ED-ACDD-E05920ECDABB} - System32\Tasks\StormFall TW2 => Chrome.exe --app=http://plarium.com/p...sherID=2_1_2_72 --app-window-size=1680,1050
 
C:\Windows\System32\Tasks\StormFall TW2
 
C:\Windows\System32\Tasks\StormFall TW1
 
C:\Users\James\AppData\Roaming\StormFall
 
C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
 
end
*****************
 
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
HKU\S-1-5-21-2304217476-3085346115-1509824866-1001\Software\Microsoft\Windows\CurrentVersion\Run\\uTorrent => value deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}" => Key deleted successfully.
"HKCR\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully.
"HKCR\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully.
"HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value deleted successfully.
"HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}" => Key not found.
"HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin" => Key deleted successfully.
"HKCU\Software\MozillaPlugins\@doubletwist.com/NPPodcast" => Key deleted successfully.
C:\Program Files (x86)\Common Files\doubleTwist\NPPodcast.dll not found.
C:\Windows\System32\Tasks\StormFall TW2 => Moved successfully.
C:\Windows\System32\Tasks\StormFall TW1 => Moved successfully.
C:\Users\James\AppData\Roaming\StormFall => Moved successfully.
C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall => Moved successfully.
C:\Users\James\AppData\Local\StormFall => Moved successfully.
"HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}" => Key deleted successfully.
"HKU\S-1-5-21-2304217476-3085346115-1509824866-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{16BC54D2-70D9-4E45-BA16-48F1810434A3}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{16BC54D2-70D9-4E45-BA16-48F1810434A3}" => Key deleted successfully.
C:\Windows\System32\Tasks\StormFall TW1 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\StormFall TW1" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DF5286E9-78FF-42ED-ACDD-E05920ECDABB}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DF5286E9-78FF-42ED-ACDD-E05920ECDABB}" => Key deleted successfully.
C:\Windows\System32\Tasks\StormFall TW2 not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\StormFall TW2" => Key deleted successfully.
"C:\Windows\System32\Tasks\StormFall TW2" => File/Directory not found.
"C:\Windows\System32\Tasks\StormFall TW1" => File/Directory not found.
"C:\Users\James\AppData\Roaming\StormFall" => File/Directory not found.
"C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall" => File/Directory not found.
 
==== End of Fixlog ====
 

# AdwCleaner v3.311 - Report created 02/10/2014 at 11:26:56
# Updated 30/09/2014 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : James - EDO
# Running from : C:\Users\James\Downloads\adwcleaner_3.311.exe
# Option : Clean
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\ProgramData\374311380 
Folder Deleted : C:\Users\James\Documents\Updater
Folder Deleted : C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\Extensions\[email protected]
Folder Deleted : C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj
Folder Deleted : C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\iabeihobmhlgpkcgjiloemdbofjbdcic
Folder Deleted : C:\Users\Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\iabeihobmhlgpkcgjiloemdbofjbdcic
[!] Folder Deleted : C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\Extensions\iabeihobmhlgpkcgjiloemdbofjbdcic
[!] Folder Deleted : C:\Users\Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\iabeihobmhlgpkcgjiloemdbofjbdcic
File Deleted : C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\user.js
 
***** [ Scheduled Tasks ] *****
 
Task Deleted : LaunchSignup
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Headlight
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\Zugo
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : [x64] HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4BB7A109-FDB5-45E3-9DB9-ECB2EA7B80EE}
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v11.0.9600.16521
 
 
-\\ Mozilla Firefox v31.0 (x86 en-US)
 
[ File : C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default\prefs.js ]
 
Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.style", ".WRCN {display:none} #yui-main .tsrc_vnru .title + .WRCN, #yui-main #teoma-results .title + .WRCN {display:inline !important; background: url(\"I[...]
Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");
Line Deleted : user_pref("extensions.wrc.SearchRules.rambler.ru.style", ".WRCN {display:none} .search-results .title + .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
 
-\\ Google Chrome v37.0.2062.124
 
[ File : C:\Users\James\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
 
[ File : C:\Users\Walternate\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
Deleted [Search Provider] : hxxp://www.factcheck.org/archives/search-results?cx=000672474746801930868%3Aa87hh_euyka&cof=FORID%3A11%3BNB%3A1&ie=UTF-8&q={searchTerms}&sa=Search
Deleted [Search Provider] : hxxp://blekko.com/ws/+{searchTerms}
Deleted [Search Provider] : hxxp://movies.netflix.com/WiSearch?oq=example&ac_posn=-1&ac_rec=false&ac_count=-1&ac_match=false&v1={searchTerms}&search_submit=
Deleted [Extension] : iabeihobmhlgpkcgjiloemdbofjbdcic
Deleted [Extension] : kdcnnmifdmlmjffdgeieikcokcogpbej
Deleted [Extension] : kincjchfokkeneeofpeefomkikfkiedl
 
*************************
 
AdwCleaner[R0].txt - [4264 octets] - [02/10/2014 11:24:38]
AdwCleaner[S0].txt - [4145 octets] - [02/10/2014 11:26:56]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4205 octets] ##########
 
 
 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.2.6 (10.02.2014:1)
OS: Windows 7 Professional x64
Ran by James on Thu 10/02/2014 at 11:38:22.72
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{000A15BD-4EA6-431D-9F24-261ACBE8D778}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{026878E3-C822-40D9-A63E-99A669BB558F}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{0C4C7378-FC48-444A-AAB6-239F3A3A8568}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{19980C9E-776A-4311-90D9-0DEEBE058E2E}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{19A6896B-6D37-46DD-9640-300935A794A8}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{27309A4A-E06C-4A1D-97FC-CFBA1A0B5DAD}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{332E8A21-7A2A-418D-8BEC-178616215A3C}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{35913061-5E81-472E-BA9E-FD85FCC8B1AF}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{3E616BAC-2F65-444F-A097-648BAF89B293}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{4079A036-CBBF-4ADC-9BD4-36B8A6ABF7EE}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{4A24F104-EFA2-4240-8B9C-44F38DD5542A}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{4D66F1E4-C78E-47ED-8147-B0EF569C8A32}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{4D9E9E47-1332-4FDC-BCF9-18013B6AE752}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{56D22F07-14B4-4069-AD79-8272BB9E0895}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{5C4DA1AD-1CEE-4BA4-8274-AD3EECA50745}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{6437C3BA-E26D-4EB4-A274-5287901CECCB}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{682F3CE4-EDEC-41EF-91A0-330035B3F80D}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{7555F323-96E0-480F-B766-1CBCA8ED3D3A}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{75F87D0C-BD1C-46BA-BDA5-75D1C2F8E111}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{7BB43A39-D1BF-49CE-94D7-0451ECD7EB1D}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{90A58C28-1344-47F0-B31F-B356BED52D9F}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{95C176A3-4884-4C28-9CEF-55269CBAFF99}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{95C73209-B10A-4AE0-B660-034DD8C3E1ED}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{9F65E290-EA60-4C66-8B68-08438C9DCA60}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{A5F816D9-B71D-40D3-B3F5-B0D318A3FAB3}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{A64B8B49-2A2C-4978-A9D5-3C0BB106B92A}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{B6116B18-5356-42F6-8F95-D152F6641E3F}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{BDB20F47-E9B0-4225-96B3-5AB91D857010}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{BDC2177D-E022-4126-B425-52E21D961096}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{C21AF54D-DB09-43D1-9211-A4C83182D652}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{DBEF1625-7304-4E2B-9BC5-88B722D20A57}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{E426E762-94BD-4606-B93F-5B3C6AD9A2E8}
Successfully deleted: [Empty Folder] C:\Users\James\appdata\local\{E5CF6EF1-BAE9-44D0-812B-16399CD4DAE1}
 
 
 
~~~ FireFox
 
Successfully deleted: [File] C:\Users\James\AppData\Roaming\mozilla\firefox\profiles\89o7p0no.default\searchplugins\bing-zugo.xml
Emptied folder: C:\Users\James\AppData\Roaming\mozilla\firefox\profiles\89o7p0no.default\minidumps [2 files]
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 10/02/2014 at 11:42:49.61
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 

 
Zoek.exe v5.0.0.0 Updated 30-09-2014
Tool run by James on Thu 10/02/2014 at 11:49:56.75.
Microsoft Windows 7 Professional  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\James\Desktop\zoek.exe [Scan all users] [Script inserted] 
 
==== System Restore Info ======================
 
10/2/2014 11:54:02 AM Zoek.exe System Restore Point Created Succesfully.
 
==== Installed Programs ======================
 
 Update for Microsoft Office 2007 (KB2508958)  
æTorrent  
7-Zip 9.20 (x64 edition)  
Adobe Acrobat XI Pro  
Adobe AIR  
Adobe Bridge 1.0  
Adobe Common File Installer  
Adobe Flash Player 15 ActiveX  
Adobe Flash Player 15 Plugin  
Adobe Help Center 1.0  
Adobe Photoshop CS2  
Adobe Reader X (10.1.10)  
Adobe Shockwave Player 11.6  
Adobe Stock Photos 1.0  
Advanced SystemCare 7  
Aimersoft DVD Creator(Build 2.6.5)  
Amazon Cloud Drive  
Amazon Kindle  
Amazon MP3 Downloader 1.0.17  
Amazon Music  
Amazon Music Importer  
AMD Accelerated Video Transcoding  
AMD APP SDK Runtime  
AMD Catalyst Install Manager  
AMD Drag and Drop Transcoding  
AMD Media Foundation Decoders  
ANT Drivers Installer x64  
Apple Application Support  
Apple Mobile Device Support  
Apple Software Update  
Audacity 1.3.13 (Unicode)  
Audacity 2.0.5  
Audiosurf  
avast Free Antivirus  
Awesomenauts  
Battle.net  
BioShock Infinite  
Bitcasa version 1.1.6.18  
Bonjour  
Borderlands 2  
BRAdmin Professional 3  
Braid  
CamStudio 2.7.2  
CamStudio OSS Desktop Recorder  
Camtasia Studio 8  
Canon CanoScan LiDE 110 User Registration  
CANON iMAGE GATEWAY Task for ZoomBrowser EX  
Canon Internet Library for ZoomBrowser EX  
Canon MP Navigator EX 4.0  
Canon Solution Menu EX  
Canon Utilities CameraWindow  
Canon Utilities CameraWindow DC 8  
Canon Utilities MyCamera  
Canon Utilities ZoomBrowser EX  
Canon ZoomBrowser EX Memory Card Utility  
CanoScan LiDE 110 Scanner Driver  
CanoScan LiDE 200 Scanner Driver  
Catalyst Control Center - Branding  
Catalyst Control Center  
Catalyst Control Center Graphics Previews Common  
Catalyst Control Center InstallProxy  
Catalyst Control Center Localization All  
ccc-utility64  
CCC Help Chinese Standard  
CCC Help Chinese Traditional  
CCC Help Czech  
CCC Help Danish  
CCC Help Dutch  
CCC Help English  
CCC Help Finnish  
CCC Help French  
CCC Help German  
CCC Help Greek  
CCC Help Hungarian  
CCC Help Italian  
CCC Help Japanese  
CCC Help Korean  
CCC Help Norwegian  
CCC Help Polish  
CCC Help Portuguese  
CCC Help Russian  
CCC Help Spanish  
CCC Help Swedish  
CCC Help Thai  
CCC Help Turkish  
CCleaner  
Chrome Remote Desktop Host  
ChromecastApp  
D-Link Powerline AV Utility  
D-Link ShareCenter (DNS-320) Setup Wizard  
D3DX10  
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition  
Deus Ex: Game of the Year Edition  
DivX Setup  
Dropbox  
DVD Shrink 3.2  
Elevated Installer  
EndNote X5  
Evernote v. 5.6.4  
f.lux  
Far Cry 3  
ffdshow [rev 2527] [2008-12-19]  
FFmpeg v0.6.2 for Audacity  
FileZilla Client 3.7.3  
FlacSquisher 1.3.1  
Flickr Uploadr 3.2.1  
focus booster  
Folder Size 1.9.5.0  
Formatted SD Card Recovery Pro 2.7.1  
Foxit Cloud  
Foxit Reader  
Fraction Bars  
FreeMind  
FreeOCR v4.2  
Freeplane  
FTL: Faster Than Light  
Gargoyle  
Garmin Communicator Plugin  
Garmin Communicator Plugin x64  
Garmin Express  
Garmin Express Tray  
Garmin Training Center  
Garmin USB Drivers  
Garmin WebUpdater  
GIMP 2.8.10  
GitHub  
Goat Simulator  
Goofball Goals  
Google Chrome  
Google Drive  
Google Earth  
Google Talk Plugin  
Google Update Helper  
Google+ Auto Backup  
GPL Ghostscript  
Group Shot  
HandBrake 0.9.9.1  
Hearthstone  
HFSExplorer 0.21  
ImgBurn  
Inkscape 0.48.2  
Inky  
InqScribe 2.1  
Instant Eyedropper 1.75  
Intel® Control Center  
Intel® Management Engine Components  
IObit Uninstaller  
IPCamSetup  
IrfanView (remove only)  
iSyncr  
iTunes  
Java 7 Update 60  
Java Auto Updater  
JavaFX 2.1.1  
Jing  
Junk Mail filter update  
KeePass Password Safe 1.27  
KeePass Password Safe 2.26  
Kerbal Space Program  
LAME v3.99.3 (for Windows)  
Left 4 Dead 2  
Livescribe Connect  
Livescribe Desktop  
Malwarebytes Anti-Malware version 2.0.2.1012  
Memonic Desktop  
Mendeley Desktop 1.1.3  
Mesh Runtime  
Microsoft .NET Framework 4.5.1  
Microsoft Application Error Reporting  
Microsoft Corporation  
Microsoft Image Composite Editor  
Microsoft LifeCam  
Microsoft Office 2007 Service Pack 3 (SP3)  
Microsoft Office Access MUI (English) 2007  
Microsoft Office Access Setup Metadata MUI (English) 2007  
Microsoft Office Enterprise 2007  
Microsoft Office Excel MUI (English) 2007  
Microsoft Office File Validation Add-In  
Microsoft Office Groove MUI (English) 2007  
Microsoft Office Groove Setup Metadata MUI (English) 2007  
Microsoft Office InfoPath MUI (English) 2007  
Microsoft Office Office 64-bit Components 2007  
Microsoft Office Office 64-bit Components 2010  
Microsoft Office OneNote MUI (English) 2007  
Microsoft Office Outlook MUI (English) 2007  
Microsoft Office PowerPoint MUI (English) 2007  
Microsoft Office Proof (English) 2007  
Microsoft Office Proof (English) 2010  
Microsoft Office Proof (French) 2007  
Microsoft Office Proof (French) 2010  
Microsoft Office Proof (Spanish) 2007  
Microsoft Office Proof (Spanish) 2010  
Microsoft Office Proofing (English) 2007  
Microsoft Office Proofing (English) 2010  
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)  
Microsoft Office Publisher MUI (English) 2007  
Microsoft Office Shared 64-bit MUI (English) 2007  
Microsoft Office Shared 64-bit MUI (English) 2010  
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007  
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010  
Microsoft Office Shared MUI (English) 2007  
Microsoft Office Shared MUI (English) 2010  
Microsoft Office Shared Setup Metadata MUI (English) 2007  
Microsoft Office Shared Setup Metadata MUI (English) 2010  
Microsoft Office Visio 2010  
Microsoft Office Visio MUI (English) 2010  
Microsoft Office Word MUI (English) 2007  
Microsoft Security Client  
Microsoft Security Essentials  
Microsoft Silverlight  
Microsoft SkyDrive  
Microsoft SQL Server 2005 Compact Edition [ENU]  
Microsoft Sync Framework 2.0 Core Components (x64) ENU   
Microsoft Sync Framework 2.0 Provider Services (x64) ENU   
Microsoft Visio Professional 2010  
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053  
Microsoft Visual C++ 2005 Redistributable  
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17  
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161  
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17  
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148  
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161  
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219  
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219  
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005  
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005  
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005  
Mozilla Firefox 31.0 (x86 en-US)  
Mozilla Maintenance Service  
MSVCRT  
MSVCRT_amd64  
Music Manager  
Node.js  
Notepad++  
NVIDIA Install Application  
OpenOffice 4.1.1  
Oracle VM VirtualBox 4.1.2  
Paint.NET v3.5.11  
Peggle Deluxe  
Peggle Nights  
PhotoScape  
PhraseExpress v9.1.41  
Picasa 3  
Picasa Uploader  
Pinball FX2  
Plants vs. Zombies: Game of the Year  
Plex Media Server  
Poker Night 2  
Portal 2 - The Final Hours  
Portal 2  
Proteus  
Prototype  
Pushbullet version 102  
Python 2.7.3  
QuickTime 7  
Realtek Ethernet Controller Driver  
Realtek High Definition Audio Driver  
ResearchSoft Direct Export Helper  
Revo Uninstaller 1.95  
Safari  
SAMSUNG USB Driver for Mobile Phones  
Sandboxie 3.76 (64-bit)  
Sansa Updater  
Scribus 1.4.1  
Scrivener Update  
SDFormatter  
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition   
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition   
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition  
Security Update for Microsoft Office 2007 suites (KB2596825) 32-Bit Edition   
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition  
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition  
Security Update for Microsoft Office 2007 suites (KB2597973) 32-Bit Edition   
Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition   
Security Update for Microsoft Office 2007 suites (KB2760411) 32-Bit Edition   
Security Update for Microsoft Office 2007 suites (KB2760415) 32-Bit Edition   
Security Update for Microsoft Office 2007 suites (KB2760585) 32-Bit Edition   
Security Update for Microsoft Office 2007 suites (KB2760591) 32-Bit Edition   
Security Update for Microsoft Office 2007 suites (KB2817641) 32-Bit Edition   
Security Update for Microsoft Office 2007 suites (KB2827326) 32-Bit Edition   
Security Update for Microsoft Office 2007 suites (KB2850022) 32-Bit Edition   
Security Update for Microsoft Office 2007 suites (KB2878236) 32-Bit Edition   
Security Update for Microsoft Office 2010 (KB2553284) 32-Bit Edition  
Security Update for Microsoft Office 2010 (KB2687423) 32-Bit Edition  
Security Update for Microsoft Office 2010 (KB2826023) 32-Bit Edition  
Security Update for Microsoft Office 2010 (KB2850016) 32-Bit Edition  
Security Update for Microsoft Office Excel 2007 (KB2827324) 32-Bit Edition   
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition   
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition  
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition  
Security Update for Microsoft Office Publisher 2007 (KB2817565) 32-Bit Edition   
Security Update for Microsoft Office Word 2007 (KB2878237) 32-Bit Edition   
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition  
SES Driver  
Sid Meier's Civilization V  
SimCalc MathWorlds for Computers  
Sketchpad  
SPCA1528 PC Driver  
Spotify  
Spybot - Search & Destroy  
Steam  
Sublime Text 2.0.2  
SumatraPDF  
Surfing Protection  
Swarm Arena  
SyncBackFree  
SyncToy 2.1 (x64)  
Talisman: Digital Edition  
Team Fortress 2  
The Elder Scrolls V: Skyrim  
TinkerPlots 2  
TotalRecovery Pro  
TrueCrypt  
Unity Web Player  
Universe Sandbox  
Update for 2007 Microsoft Office System (KB967642)  
Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition  
Update for Microsoft Office 2007 Help for Common Features (KB963673)  
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition  
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition  
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition  
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition  
Update for Microsoft Office 2010 (KB2494150)  
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition  
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition  
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition  
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition  
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition  
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition  
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition  
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition  
Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition  
Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition  
Update for Microsoft Office Access 2007 Help (KB963663)  
Update for Microsoft Office Excel 2007 Help (KB963678)  
Update for Microsoft Office Infopath 2007 Help (KB963662)  
Update for Microsoft Office OneNote 2007 Help (KB963670)  
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition  
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition  
Update for Microsoft Office Outlook 2007 Help (KB963677)  
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2878297) 32-Bit Edition  
Update for Microsoft Office Powerpoint 2007 Help (KB963669)  
Update for Microsoft Office Publisher 2007 Help (KB963667)  
Update for Microsoft Office Script Editor Help (KB963671)  
Update for Microsoft Office Word 2007 Help (KB963665)  
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition  
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition  
Update for Microsoft Visio 2010 (KB2553444) 32-Bit Edition  
Uplay  
VC80CRTRedist - 8.0.50727.6195  
Virtual Account Numbers  
Vitamin D Video 1.4.2  
VLC media player  
Vonage Companion  
VueScan  
Waterfox  
WD SmartWare Drive Manager  
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201)  
Windows Driver Package - Garmin (grmnusb) GARMIN Devices  (04/19/2012 2.3.1.0)  
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1)  
Windows Driver Package - Western Digital Technologies (WDC_SAM) WDC_SAM  (01/19/2011 1.0.0009.0)  
Windows Live Communications Platform  
Windows Live Essentials  
Windows Live ID Sign-in Assistant  
Windows Live Installer  
Windows Live Language Selector  
Windows Live Mail  
Windows Live Mesh  
Windows Live Mesh ActiveX Control for Remote Connections  
Windows Live MIME IFilter  
Windows Live Movie Maker  
Windows Live Photo Common  
Windows Live Photo Gallery  
Windows Live PIMT Platform  
Windows Live Remote Client  
Windows Live Remote Client Resources  
Windows Live Remote Service  
Windows Live Remote Service Resources  
Windows Live SOXE  
Windows Live SOXE Definitions  
Windows Live UX Platform  
Windows Live UX Platform Language Pack  
Windows Live Writer  
Windows Live Writer Resources  
Windows XP Mode  
WinX DVD Ripper 5.5.7  
WinX HD Video Converter Deluxe 4.0.0  
Wunderlist  
XCOM: Enemy Unknown  
Zero Assumption Recovery Version 9  
Zotero Standalone 4.0.22 (x86 en-US)  
 
==== Running Processes ======================
 
C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Brother\BRAdmin Professional 3\bratimer.exe
C:\Program Files (x86)\Google\Chrome Remote Desktop\38.0.2125.9\remoting_host.exe
C:\Program Files (x86)\Google\Chrome Remote Desktop\38.0.2125.9\remoting_host.exe
C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\Foxit Cloud\FCUpdateService.exe
C:\Program Files (x86)\FarStone\TotalRecovery\Client\cbp\DCSchdler.exe
C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
C:\Program Files (x86)\Common Files\Livescribe\PenComm\PenCommService.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\FarStone\TotalRecovery\Client\DCNTranProc.exe
C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
C:\Windows\vVX3000.exe
C:\Users\James\AppData\Local\Programs\Google\MusicManager\MusicManager.exe
C:\Users\James\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Users\James\AppData\Local\FluxSoftware\Flux\flux.exe
C:\Users\James\AppData\Local\Amazon Music\Amazon Music Helper.exe
C:\Users\James\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\PhraseExpress\phraseexpress.exe
C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Users\James\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
C:\Users\James\AppData\Roaming\pushbullet\pushbullet_103\pushbullet_app.exe
C:\Users\James\Desktop\zoek.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cmd.exe
 
==== Services (whitelist) ======================
Powered by E Dev
 
R2 - [AdobeARMservice] - Adobe Acrobat Update Service - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
R2 - [AMD External Events Utility] - AMD External Events Utility - C:\Windows\system32\atiesrxx.exe
R2 - [Apple Mobile Device] - Apple Mobile Device - "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
R2 - [Bonjour Service] - Bonjour Service - "C:\Program Files\Bonjour\mDNSResponder.exe"
R2 - [BRA_Scheduler] - Brother BRAdminPro Scheduler - C:\Program Files (x86)\Brother\BRAdmin Professional 3\bratimer.exe
R2 - [chromoting] - Chrome Remote Desktop Service - "C:\Program Files (x86)\Google\Chrome Remote Desktop\38.0.2125.9\remoting_host.exe" --type=daemon --host-config="C:\ProgramData\Google\Chrome Remote Desktop\host.json"
R2 - [Garmin Core Update Service] - Garmin Core Update Service - "C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe"
R2 - [MSCamSvc] - MSCamSvc - "C:\Program Files\Microsoft LifeCam\MSCamS64.exe"
R2 - [MsMpSvc] - Microsoft Antimalware Service - "c:\Program Files\Microsoft Security Client\MsMpEng.exe"
R2 - [PenCommService] - Livescribe Pulse Smartpen Service - C:\Program Files (x86)\Common Files\Livescribe\PenComm\PenCommService.exe
R2 - [PnkBstrA] - PnkBstrA - C:\Windows\system32\PnkBstrA.exe
R2 - [SbieSvc] - Sandboxie Service - "C:\Program Files\Sandboxie\SbieSvc.exe"
R2 - [WDDMService] - WDDMService - "C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe"
R2 - [wlidsvc] - Windows Live ID Sign-in Assistant - "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
R2 - [WSearch] - Windows Search - C:\Windows\system32\SearchIndexer.exe /Embedding
R3 - [iPod Service] - iPod Service - "C:\Program Files\iPod\bin\iPodService.exe"
R3 - [VSS] - Volume Shadow Copy - C:\Windows\system32\vssvc.exe
R3 - [WMPNetworkSvc] - Windows Media Player Network Sharing Service - "C:\Program Files\Windows Media Player\wmpnetwk.exe"
S2 - [clr_optimization_v4.0.30319_32] - Microsoft .NET Framework NGEN v4.0.30319_X86 - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
S2 - [clr_optimization_v4.0.30319_64] - Microsoft .NET Framework NGEN v4.0.30319_X64 - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
S2 - [DCScheduler] - DCScheduler - C:\Program Files (x86)\FarStone\TotalRecovery\Client\cbp\DCSchdlerSRVC.exe
S2 - [gupdate] - Google Update Service (gupdate) - "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc
S2 - [LiveUpdateSvc] - LiveUpdate - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
S2 - [sppsvc] - Software Protection - C:\Windows\system32\sppsvc.exe
S3 - [Adobe LM Service] - Adobe LM Service - "C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"
S3 - [AdobeFlashPlayerUpdateSvc] - Adobe Flash Player Update Service - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
S3 - [ALG] - Application Layer Gateway Service - C:\Windows\System32\alg.exe
S3 - [aspnet_state] - ASP.NET State Service - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
S3 - [clr_optimization_v2.0.50727_32] - Microsoft .NET Framework NGEN v2.0.50727_X86 - C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
S3 - [clr_optimization_v2.0.50727_64] - Microsoft .NET Framework NGEN v2.0.50727_X64 - C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
S3 - [COMSysApp] - COM+ System Application - C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
S3 - [ehRecvr] - Windows Media Center Receiver Service - C:\Windows\ehome\ehRecvr.exe
S3 - [ehSched] - Windows Media Center Scheduler Service - C:\Windows\ehome\ehsched.exe
S3 - [Fax] - Fax - C:\Windows\system32\fxssvc.exe
S3 - [FontCache3.0.0.0] - Windows Presentation Foundation Font Cache 3.0.0.0 - C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
S3 - [gupdatem] - Google Update Service (gupdatem) - "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc
S3 - [gusvc] - Google Updater Service - "C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe"
S3 - [IEEtwCollectorService] - Internet Explorer ETW Collector Service - C:\Windows\system32\IEEtwCollector.exe /V
S3 - [Microsoft Office Groove Audit Service] - Microsoft Office Groove Audit Service - "C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe"
S3 - [MozillaMaintenance] - Mozilla Maintenance Service - "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe"
S3 - [MSDTC] - Distributed Transaction Coordinator - C:\Windows\System32\msdtc.exe
S3 - [msiserver] - Windows Installer - C:\Windows\system32\msiexec.exe /V
S3 - [NisSrv] - Microsoft Network Inspection - "c:\Program Files\Microsoft Security Client\NisSrv.exe"
S3 - [odserv] - Microsoft Office Diagnostics Service - "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE"
S3 - [ose] - Office  Source Engine - "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
S3 - [osppsvc] - Office Software Protection Platform - "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
S3 - [PerfHost] - Performance Counter DLL Host - C:\Windows\SysWow64\perfhost.exe
S3 - [RpcLocator] - Remote Procedure Call (RPC) Locator - C:\Windows\system32\locator.exe
S3 - [Steam Client Service] - Steam Client Service - "C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
S3 - [TrustedInstaller] - Windows Modules Installer - C:\Windows\servicing\TrustedInstaller.exe
S3 - [vds] - Virtual Disk - C:\Windows\System32\vds.exe
S3 - [WatAdminSvc] - Windows Activation Technologies Service - C:\Windows\system32\Wat\WatAdminSvc.exe
S3 - [wbengine] - Block Level Backup Engine Service - "C:\Windows\system32\wbengine.exe"
S3 - [wmiApSrv] - WMI Performance Adapter - C:\Windows\system32\wbem\WmiApSrv.exe
S4 - [SNMPTRAP] - SNMP Trap - C:\Windows\System32\snmptrap.exe
S4 - [wlcrasvc] - Windows Live Mesh remote connections service - "C:\Program Files\Windows Live\Mesh\wlcrasvc.exe"
 
==== System Specs ======================
 
Windows: Windows 7 Professional Edition (64-bit) Service Pack 1 (Build 7601)
Memory (RAM): 12270 MB
CPU Info: Intel® Core™ i5-2300 CPU @ 2.80GHz
CPU Speed: 2796.0 MHz
Sound Card: Speakers (Realtek High Definiti | 
Realtek Digital Output (Realtek | 
Realtek Digital Output(Optical) | 
Display Adapters: AMD Radeon HD 7800 Series | AMD Radeon HD 7800 Series | AMD Radeon HD 7800 Series | AMD Radeon HD 7800 Series | AMD Radeon HD 7800 Series | AMD Radeon HD 7800 Series | RDPDD Chained DD | RDP Encoder Mirror Driver | RDP Reflector Display Driver
Monitors: 1x; Generic PnP Monitor | 
Screen Resolution: 1680 X 1050 - 32 bit
Network: Network Present
Network Adapters: Realtek PCIe GBE Family Controller
CD / DVD Drives: 1x (D: | ) D: ATAPI   iHAS224   B
Ports: COM1 LPT Port NOT Present. 
Mouse: 5 Button Wheel Mouse Present
Hard Disks: C:  931.5GB | E:  232.9GB
Hard Disks - Free: C:  439.0GB | E:  138.0GB
Manufacturer *: American Megatrends Inc.
BIOS Info: AT/AT COMPATIBLE | 02/05/10 | VELOCI - 1072009
Time Zone: Eastern Standard Time
Motherboard *: ASUSTeK Computer INC. P8P67 LE
Country: United States 
Language: ENU 
 
==== System Specs (Software) ======================
 
Anti-Virus: Microsoft Security Essentials On-access scanning disabled (Outdated)
Anti-Virus: avast! Antivirus On-access scanning disabled (Outdated)
Anti-Spyware: Windows Defender disabled (Outdated)
Anti-Spyware: avast! Antivirus disabled (Outdated)
Anti-Spyware: Microsoft Security Essentials disabled (Outdated)
Default Browser: Google Chrome 37.0.2062.124
Internet Explorer Version: 11.0.9600.16521 
Mozilla Firefox version: 31.0 (x86 en-US)
Google Chrome version: 37.0.2062.124
Adobe Reader version: 10.1.10.18
Sun Java version: 1.7.0_60 (32-bit) 
Flash Player version: 15.0.0.152
Shockwave Player version: 11.6r626
 
==== Files Recently Created / Modified ======================
 
====== C:\Windows ====
====== C:\Users\James\AppData\Local\Temp ====
2014-10-02 15:38:03 E0DC8C6BBC787B972A9A468648DBFD85 1008128 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\libiconv2.dll
2014-10-02 15:38:03 D202BAA425176287017FFE1FB5D1B77C 103424 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\libintl3.dll
2014-10-02 15:38:03 57CAC848FA14AE38F14F9441F8933282 140288 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\pcre3.dll
2014-10-02 15:38:03 547C43567AB8C08EB30F6C6BACB479A3 79360 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\regex2.dll
2014-10-02 15:37:15 2E0323A94915FAAB10A25F3BABF82584 157696 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
2014-10-02 15:31:46 4E566FEA83FCEEAF2873702806B55006 43008 ----a-w- C:\Users\James\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpi8cgoc.dll
2014-09-24 04:03:12 2326A296B010B19225826A09818E1F13 21340160 ----a-w- C:\Users\James\AppData\Local\Temp\is1955396272\7DD354DE_stp.EXE
2014-09-24 04:02:53 40395C175553CB14D2050888EFCCDF00 4961800 ----a-w- C:\Users\James\AppData\Local\Temp\vcredist_x64.exe
2014-09-24 04:02:47 24BCAF1BBB1F29E0245416B5D2873E46 5777584 ----a-w- C:\Users\James\AppData\Local\Temp\optprosetup.exe
2014-09-24 04:02:46 CD5E46297DE66DFF69EDC00499068EA8 5601864 ----a-w- C:\Users\James\AppData\Local\Temp\CloudBackup4939.exe
2014-09-24 04:02:33 272F3B7EFC6DF7E9E249724AFB4AB84A 11567116 ----a-w- C:\Users\James\AppData\Local\Temp\is1955396272\43BD3C70_stp.EXE
====== Java Cache =====
====== C:\Windows\SysWOW64 =====
2014-10-02 15:25:27 0DC5AF80D059DEC792B665ED598C6567 536576 ----a-w- C:\Windows\SysWOW64\sqlite3.dll
====== C:\Windows\SysWOW64\drivers =====
====== C:\Windows\Sysnative =====
====== C:\Windows\Sysnative\drivers =====
====== C:\Windows\Tasks ======
====== C:\Windows\Temp ======
======= C:\Program Files =====
2014-09-24 04:02:42 -------- d-----w- C:\Program Files\CamStudio 2.7
======= C:\PROGRA~2 =====
2014-09-29 02:09:56 -------- d-----w- C:\PROGRA~2\OpenOffice 4
2014-09-22 19:26:41 -------- d-----w- C:\PROGRA~2\Pushbullet
2014-09-16 20:46:47 -------- d-----w- C:\PROGRA~2\Gargoyle
2014-09-15 00:56:59 -------- d-----w- C:\PROGRA~2\FlacSquisher
2014-09-11 15:40:53 -------- d-----w- C:\PROGRA~2\KeePass Password Safe
======= C: =====
====== C:\Users\James\AppData\Roaming ======
2014-09-29 02:12:30 -------- d-----w- C:\Users\James\AppData\Roaming\OpenOffice
2014-09-24 04:05:47 C3EFD2706023A9DDB1FB44C1C9122B68 103 ----a-w- C:\Users\James\AppData\Roaming\Camdata.ini
2014-09-24 04:05:47 B393A0C70992706F6EA7FC82D6666DC2 4537 ----a-w- C:\Users\James\AppData\Roaming\CamStudio.cfg
2014-09-24 04:05:47 24E830C49941FBB79552DEEDDFD8A288 408 ----a-w- C:\Users\James\AppData\Roaming\CamLayout.ini
2014-09-24 04:05:47 1882BC910A226828989905C118F31C7C 408 ----a-w- C:\Users\James\AppData\Roaming\CamShapes.ini
2014-09-24 04:03:23 9E3D46FEA2CB93CF7CBA1E216DC5E68A 96 ----a-w- C:\Users\James\AppData\Roaming\version2.xml
2014-09-22 19:26:41 -------- d-----w- C:\Users\James\AppData\Roaming\pushbullet
2014-09-15 01:01:06 -------- d-----w- C:\Users\James\AppData\Roaming\FlacSquisher
2014-09-15 00:56:59 -------- d-----w- C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FlacSquisher
2014-09-13 17:49:39 -------- d-----w- C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SanDisk
2014-09-13 17:49:10 -------- d-----w- C:\Users\James\AppData\Roaming\SanDisk
====== C:\Users\James ======
2014-10-02 15:36:08 12EFD5FA51597F188E5DB50BE20EE597 1375089 ----a-w- C:\Users\James\Downloads\adwcleaner_3.311 (1).exe
2014-10-02 15:23:31 12EFD5FA51597F188E5DB50BE20EE597 1375089 ----a-w- C:\Users\James\Downloads\adwcleaner_3.311.exe
2014-09-29 20:36:48 FA414E9439D1F7A0BB9AF745C8D76BA1 2108928 ----a-w- C:\Users\James\Desktop\FRST64.exe
2014-09-29 02:10:50 -------- d-s---w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1
2014-09-29 02:04:20 40FC525BC8B26AC7E1A7CEF0E02A08F3 140852175 ----a-w- C:\Users\James\Downloads\Apache_OpenOffice_4.1.1_Win_x86_install_en-US.exe
2014-09-28 12:32:47 -------- d-----w- C:\Users\James\Grading Temp
2014-09-25 10:06:46 4ADCFEE16EE9978F06157634669D36FB 602112 ----a-w- C:\Users\James\Desktop\OTL.exe
2014-09-25 10:06:35 4ADCFEE16EE9978F06157634669D36FB 602112 ----a-w- C:\Users\James\Downloads\OTL.exe
2014-09-24 04:02:45 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CamStudio 2.7
2014-09-22 19:26:44 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pushbullet
2014-09-22 19:23:03 44A7DF158931A0C4BF97DB6556CAC1DE 8970080 ----a-w- C:\Users\James\Downloads\pb_install (1).exe
2014-09-21 18:38:35 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
2014-09-16 20:46:49 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gargoyle
2014-09-13 17:52:03 -------- d-----w- C:\Users\Public\Foxit Software
2014-09-13 17:51:50 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
2014-09-12 00:15:57 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
 
====== C: exe-files ==
2014-10-02 15:37:41 5EC93A5380699468F88330882AB64B26 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-2304217476-3085346115-1509824866-1001\$IAV2LGB.exe
2014-09-29 20:37:12 3F5C1CF035675B542611CFEFA5FF648D 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-2304217476-3085346115-1509824866-1001\$I6WG26N.exe
2014-09-29 20:37:12 383E458904E4BB472490813F1C4B69BF 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-2304217476-3085346115-1509824866-1001\$IU3PZ6N.exe
2014-09-29 20:36:50 933BA2AB12079BCE45861A8D668CA47E 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-2304217476-3085346115-1509824866-1001\$II4XDOM.exe
2014-09-29 20:36:13 59E8DA429E91985EB7B62C1BAEB103E5 1100288 ----a-w- C:\$Recycle.Bin\S-1-5-21-2304217476-3085346115-1509824866-1001\$RU3PZ6N.exe
2014-09-29 20:35:21 59E8DA429E91985EB7B62C1BAEB103E5 1100288 ----a-w- C:\$Recycle.Bin\S-1-5-21-2304217476-3085346115-1509824866-1001\$RI4XDOM.exe
2014-09-29 20:35:13 59E8DA429E91985EB7B62C1BAEB103E5 1100288 ----a-w- C:\$Recycle.Bin\S-1-5-21-2304217476-3085346115-1509824866-1001\$R6WG26N.exe
=== C: other files ==
2014-10-02 15:38:03 4D80C7010E2CE44AB25FA25B013649E4 8085 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\mws.bat
2014-10-02 15:37:15 DD1E4D974B1672ABD09EFFB225791C4A 1230 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\TDL4.bat
2014-10-02 15:37:15 C8ED22053029FF15F1771F30330F1F54 8054 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\runvalues.bat
2014-10-02 15:37:15 B153A7FE10DC117A719F0F97E3BE32F6 14815 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\get.bat
2014-10-02 15:37:15 AD2F52DC72B10AF331692E4A4DD80DFC 18670 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\medfos.bat
2014-10-02 15:37:15 A87CD1BAC46CAC0EEEDB571F07077032 8104 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\modules.bat
2014-10-02 15:37:15 8E6020C14F982CF11B3FE7DBB0CB8EDE 24738 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\searchlnk.bat
2014-10-02 15:37:15 86707BCE5CBB65D9B1C41E249B4423BA 152733 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\firefox.bat
2014-10-02 15:37:15 83F691D8398F0E37E71E9355BF730DB9 719 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\ev_clear.bat
2014-10-02 15:37:15 654E9FE74B930A454EE5BDE165794B65 85 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\delorphans.bat
2014-10-02 15:37:15 5B71358F97544D9DE58A9A0893079506 39458 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\prelim.bat
2014-10-02 15:37:15 53B191266B30D57F2F835ABBF54C68C5 13963 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\chrome.bat
2014-10-02 15:37:15 38A0BDF322ACCC968B0A824C38D50157 29635 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\ask.bat
2014-10-02 15:37:15 335DFF8F23E5EC02B5426362F0F8509B 31401 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\iexplore.bat
2014-10-02 15:37:15 2F80D807DB405C8F6E0F3706B9FED710 10161 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\JRT.bat
2014-10-02 15:37:15 24DA003A1113A0628430DE5C5071C874 162649 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\misc.bat
2014-10-02 15:37:15 0D08FBD2E6F6C6AC6A504712C4CE6CE3 1226 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\FWPolicy.bat
2014-10-02 15:37:15 0C4649A62845AB5D5DBCC4998477FF6D 1813 ----a-w- C:\Users\James\AppData\Local\Temp\jrt\delfolders.bat
2014-09-28 12:34:11 7D36A2D50F2752E5B9BA4F4C65AEA9FE 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-2304217476-3085346115-1509824866-1001\$I3H9BMI.zip
2014-09-28 12:33:46 8C8995E011B14F8EF46451F035D8AA67 4507546 ----a-w- C:\$Recycle.Bin\S-1-5-21-2304217476-3085346115-1509824866-1001\$R3H9BMI.zip
2014-09-26 16:22:56 5F69DC312C7A5C87E0A0FA560EFFE1A6 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-2304217476-3085346115-1509824866-1001\$IM5108Y.zip
2014-09-26 16:22:44 0C5AD8D2363DF6678257545B0B4BD023 29914370 ----a-w- C:\$Recycle.Bin\S-1-5-21-2304217476-3085346115-1509824866-1001\$RM5108Y.zip
2014-09-26 16:15:05 99D461E7AB5C0F4CC503CA4CCDF6CF95 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-2304217476-3085346115-1509824866-1001\$IMFGQWZ.zip
2014-09-26 16:14:45 3DEEB1DE690472F5679EC3CEB2C34EE5 24860870 ----a-w- C:\$Recycle.Bin\S-1-5-21-2304217476-3085346115-1509824866-1001\$RMFGQWZ.zip
 
==== Startup Registry Enabled ======================
 
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
 
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"
 
[HKEY_USERS\S-1-5-21-2304217476-3085346115-1509824866-1001\Software\Microsoft\Windows\CurrentVersion\Run]
"MusicManager"="C:\Users\James\AppData\Local\Programs\Google\MusicManager\MusicManager.exe"
"DE24DAEE86D33FB70CF774307B0E31290C5D8D40._service_run"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --type=service"
"Google Update"="C:\Users\James\AppData\Local\Google\Update\GoogleUpdate.exe /c"
"WinPatrol"="C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot"
"Spotify Web Helper"="C:\Users\James\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
"f.lux"="C:\Users\James\AppData\Local\FluxSoftware\Flux\flux.exe /noshow"
"GarminExpressTrayApp"="C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
"Google+ Auto Backup"="C:\Users\James\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe /autostart"
"Advanced SystemCare 7"="C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe /Auto"
"Amazon Music"="C:\Users\James\AppData\Local\Amazon Music\Amazon Music Helper.exe"
"GoogleChromeAutoLaunch_6B06BCEFC97BCF192292AD16DB5D7A73"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --no-startup-window"
"SansaDispatch"="C:\Users\James\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe"
"Pushbullet"="C:\Program Files (x86)\Pushbullet\pushbullet_app.exe"
 
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
 
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun"
"LifeCam"="C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
"GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
"CanonSolutionMenuEx"="C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon"
"APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Aimersoft Helper Compact.exe"="C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe"
"KeePass 2 PreLoad"="C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe --preload"
"Virtual Account Numbers"="C:\PROGRA~2\VIRTUA~1\CitiVAN.exe /lang=en_RG /dontopenmycards"
"DivXMediaServer"="C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe"
"DivXUpdate"="C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe /CHECKNOW"
"Acrobat Assistant 8.0"="C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe"
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui"
"QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime"
 
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MusicManager"="C:\Users\James\AppData\Local\Programs\Google\MusicManager\MusicManager.exe"
"DE24DAEE86D33FB70CF774307B0E31290C5D8D40._service_run"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --type=service"
"Google Update"="C:\Users\James\AppData\Local\Google\Update\GoogleUpdate.exe /c"
"WinPatrol"="C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot"
"Spotify Web Helper"="C:\Users\James\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
"f.lux"="C:\Users\James\AppData\Local\FluxSoftware\Flux\flux.exe /noshow"
"GarminExpressTrayApp"="C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
"Google+ Auto Backup"="C:\Users\James\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe /autostart"
"Advanced SystemCare 7"="C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe /Auto"
"Amazon Music"="C:\Users\James\AppData\Local\Amazon Music\Amazon Music Helper.exe"
"GoogleChromeAutoLaunch_6B06BCEFC97BCF192292AD16DB5D7A73"="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --no-startup-window"
"SansaDispatch"="C:\Users\James\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe"
"Pushbullet"="C:\Program Files (x86)\Pushbullet\pushbullet_app.exe"
 
==== Startup Registry Enabled x64 ======================
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VX3000"="C:\Windows\vVX3000.exe"
"RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s"
"MSC"="c:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey"
"AdobeAAMUpdater-1.0"="C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
"Bitcasa"="C:\Program Files\Bitcasa\BitcasaBoot.exe C:\Program Files\Bitcasa\Bitcasa.exe /startup"
 
==== Startup Folders ======================
 
2014-01-25 21:53:00 1385 ----a-w- C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
2013-03-05 18:05:09 1044 ----a-w- C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
2013-03-05 18:09:29 1131 ----a-w- C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk
2013-05-02 23:50:38 3009 ----a-w- C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iSyncr.lnk
2013-03-05 18:09:29 1578 ----a-w- C:\Users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Vitamin D Video.exe - Shortcut.lnk
2013-03-20 13:47:49 1089 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PhraseExpress.lnk
2013-03-05 18:09:29 1346 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WD Quick View.lnk
 
==== Task Scheduler Jobs ======================
 
C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [09/24/2014 01:44 AM]
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ [Undetermined Task]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [10/17/2011 11:17 AM]
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2304217476-3085346115-1509824866-1001Core.job --a------ C:\Users\James\AppData\LoC:al\Google\Update\GoogleUpdate.exe []
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2304217476-3085346115-1509824866-1001UA.job --a------ C:\Users\James\AppData\LoC:al\Google\Update\GoogleUpdate.exe []
 
==== Other Scheduled Tasks ======================
 
"C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\Windows\SysNative\tasks\ASC7_SkipUac_James" [C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASC.exe /SkipUac]
"C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"]
"C:\Windows\SysNative\tasks\GarminUpdaterTask" [C:\Program Files (x86)\Garmin\Express Self Updater\ExpressSelfUpdater.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-2304217476-3085346115-1509824866-1001Core" [C:\Users\James\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-2304217476-3085346115-1509824866-1001UA" [C:\Users\James\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\Windows\SysNative\tasks\Uninstaller_SkipUac_Administrator" [C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe]
"C:\Windows\SysNative\tasks\2BrightSparks\SyncBackFree\Edo-James\SyncBackFree Dropbox Backup to 221B" [C:\Program Files (x86)\2BrightSparks\SyncBackFree\SyncBackFree.exe]
"C:\Windows\SysNative\tasks\2BrightSparks\SyncBackFree\Edo-James\SyncBackFree Music Backup to 221B" [C:\Program Files (x86)\2BrightSparks\SyncBackFree\SyncBackFree.exe]
"C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe]
"C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc]
 
==== Firefox Extensions Registry ======================
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"[email protected]"="C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn" [03/24/2014 09:33 PM]
 
==== Firefox Extensions ======================
 
ProfilePath: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default
- Undetermined - C:\Program Files (x86)\IObit Apps Toolbar\FF
- Advanced SystemCare Surfing Protection - %ProfilePath%\extensions\[email protected]
- Free Download Manager plugin - %ProfilePath%\extensions\[email protected]
- Zotero Word for Windows Integration - %ProfilePath%\extensions\[email protected]
- Autofill Forms - %ProfilePath%\extensions\[email protected]
- Firebug - %ProfilePath%\extensions\[email protected]
- Zotero - %ProfilePath%\extensions\[email protected]
 
ProfilePath: C:\Users\James\AppData\Roaming\Zotero\Zotero\Profiles\8ji5omul.default
- Zotero LibreOffice Integration - C:\Program Files (x86)\Zotero Standalone\extensions\[email protected]
- Zotero Word for Windows Integration - C:\Program Files (x86)\Zotero Standalone\extensions\[email protected]
- ZotFile - %ProfilePath%\extensions\[email protected]
 
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
 
==== Firefox Plugins ======================
 
Profilepath: C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\89o7p0no.default
DFC9460CC37E5C414DC4680B10C19E7A - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll - Shockwave Flash
FB5621842FDABF9F8359775573498FBC - C:\Users\James\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll - Google Update
5CB01CF141E021DAAE96991A5BA57944 - C:\Users\James\AppData\Roaming\Mozilla\plugins\npo1d.dll - Google Talk Plugin Video Renderer
DD31F0C436E4F5E6FA9783FF8A80ADC1 - C:\Users\James\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll - Google Talk Plugin
65C1D9F74004E775F9A8598476ABE5EE - C:\Users\James\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
87132527E2256CF6683A18C4EB34DD3B - C:\Windows\system32\Wat\npWatWeb.dll - Windows Activation Technologies
B6A800D881A0176C544988870861E798 - C:\Windows\SysWoW64\Adobe\Director\np32dsw.dll - Shockwave for Director / Shockwave for Director
 
 
==== Chromium Look ======================
 
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
efaidnbmnnnibpcajpcglclefindmkaj - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx[]
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[08/14/2014 04:47 PM]
nfengeggddojhakldhlpjdlddgkkjkdd - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASC_GhromePlugin.crx[10/12/2013 02:04 PM]
nneajnkjbffgblleaoojgaacokifdkhm - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx[05/06/2013 04:12 AM]
 
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
nknebiagdodnminbdpflhpkgfpeijdbf - C:\Users\James\AppData\Local\Google\Drive\nknebiagdodnminbdpflhpkgfpeijdbf_live.crx[08/07/2014 07:40 PM]
 
Magic Actions for YouTube - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif
Entanglement Web App - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd
Angry Birds - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
Awesome Screenshot: Capture Annotate - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\alelhddbbhepgpmgidjdcjakblofbmce
Google Docs - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
Google Voice Search Hotword (Beta) - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
WOT - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp
YouTube - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Honey - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj
Google Cast - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\boadgeojelhgndaghljhdicfkmllpafd
HelloFax 50 Free Fax Pages - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\bocmleclimfnadgmcdgecijlblfcmfnm
Memonic Web Clipper - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdonhidhobjahdhlcegfakicbcgnkokh
Copy Without Formatting - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekbgkmeapobkbadclnkjfjdbpbcaobd
Last updated at time on date - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb
Strict Workflow - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgmnfnmlficgeijcalkgnnkigkefkbhd
Pushbullet - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\chlffgpmiacpedhhbkiomidkjlcfhogd
Add to Amazon Wish List - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ciagpekplgpbepdgggflgmahnjgiaced
Gif Delayer - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmfcdkambpljcndgdmaccaagladfnepa
Google Search - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Video Title Adder - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddpephnhacfpgcemhioaejgenlgadnnh
Rather - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkigkllnlkoblfbgfnfngfcnhmndonjm
Google Calendar - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn
Zotero Connector - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekhagklcjbdpajgpjgmbionohlpdbjgc
NUM plural =0 days ago=1 day agoother days ago - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi
1 out-of-date - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp
TinEye Reverse Image Search - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl
Memonic - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\hejjjnnbamjillkkomahknangbpjfdpd
Restore Defaults - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhfkcobomkalfdlmkongnhnhahkmnaad
Terms of Service; Didn’t Read - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjdoplcnndgiblooccencgcggcoihigg
Checker Plus for Google Calendarâ„¢ - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkhggnncdpfibdhinjiegagmopldibha
Don't Break the Chain - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlkkjgfbfgdcdjnddamlmgbipgbhgppk
Google Keep - notes and lists - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki
goo.gl URL Shortener - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\iblijlcdoidgdpfknkckljiocdbnlagk
Kindle Cloud Reader - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd
Google Play Music - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\icppfcnhkcmnfdhfhphakoifcfokfdhg
Looper for YouTube - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\iggpfpnahkgpnindfkdncknoldgnccdg
Cloze - Keep Tabs on Contacts - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\imlbbglginccpmlaekkdnleoachjadka
Imagus - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\immpkjjlgappgfkkfieppnmlhakdmaab
Disconnect - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeoacafpbcihiomhlakheieifhpjdfeo
Yoono - Twitter Facebook LinkedIn YouTubeâ„¢ - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkkenjlnjfemconejajakbijbheoffli
Reddit Enhancement Suite - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb
Google Voice (by Google) - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcnhkahnjcbndmmehfkdnkjomaanaooo
RSS Web Subscriber - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\kghdjdlccddmkepckhfgjdeohkcabahl
The Great Suspender - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\klbibkeccnjlkjkiokjodocebajanakg
StayFocusd - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\laankejkbhbdhmipfmgcngdelahlfoji
Webcam Toy - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade
InvisibleHand - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\lghjfnfolmcikomdjmoiemllfnlmmoko
Poppit - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi
Download Master - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcceagdollnkjlogmdckgjakjapmkdjf
Reddit Check - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\mllceaiaedaingchlgolnfiibippgkmj
Play Books - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb
Hangouts - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\nckgahadagoaajjgafhacjanaoiihapd
Springpad Extension - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\njhgeimnepehieioinbhmfpphfoocmng
Google Drive Client Native Proxy - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\nknebiagdodnminbdpflhpkgfpeijdbf
Google Wallet - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Google Chrome to Phone Extension - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco
rbutr - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocnieghejiknjhadhngmmnbfjocbbfpm
Checker Plus for Gmailâ„¢ - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\oeopbcgkkoapgobdbedcemjljbihmemj
Enhanced Steam - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\okadibdjfemgnhjiembecghcbfknbfhg
chromeIPass - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ompiailgknfdndiefoaoiligalphfdae
Picasa - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb
ClickClean App - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp
Send from Gmail (by Google) - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgphcomnlaojlmmcjmiddhdapjpbgeoc
Evernote Web Clipper - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc
Gmail - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
Space Planet - James\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppcocpoeoiajndepaaimnnglicichmbb
Entanglement - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd
RedditHider - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\aihhijdghhnhkgigamdkendgdnecpigi
Angry Birds - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
Google Docs - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
Toodledo Tasks - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\ballhmoamkbbfadiealjmgmhbbnellbc
QR-Code Tag Extension - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcfddoencoiedfjgepnlhcpfikgaogdg
Missing e - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcjbagclppcgdbpobcpoojdjdmcjhpid
WOT - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp
YouTube - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
HelloFax - Free Online Faxing & Signing - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\bocmleclimfnadgmcdgecijlblfcmfnm
Memonic Web Clipper - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdonhidhobjahdhlcegfakicbcgnkokh
Strict Pomodoro - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgmnfnmlficgeijcalkgnnkigkefkbhd
Add to Amazon Wish List - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\ciagpekplgpbepdgggflgmahnjgiaced
Nanny for Google Chrome ™ - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\cljcgchbnolheggdgaeclffeagnnmhno
Google Search - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Unbaby.me - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkigkllnlkoblfbgfnfngfcnhmndonjm
CloudMagic - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\eeabeiioncmgphlgcgnmhjahjjmimkmp
Google Calendar - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn
Zotero Connector - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekhagklcjbdpajgpjgmbionohlpdbjgc
DoNotTrackMe - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\epanfjkfahimkgomnigadpkobaefekcd
AdBlock - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
Cut the Rope - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkddaofiamhgfjmaccfcfpfolpgbeomj
TinEye Reverse Image Search - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl
TweetDeck - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbdpomandigafcibbmofojjchbcdagbl
Memonic - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\hejjjnnbamjillkkomahknangbpjfdpd
Rapportive - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\hihakjfhbmlmjdnnhegiciffjplmdhin
Checker Plus for Google Calendar™ - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkhggnncdpfibdhinjiegagmopldibha
avast WebRep - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
Social Fixer - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifmhoabcaeehkljcfclfiieohkohdgbb
Yoono - Twitter Facebook LinkedIn YouTube™ - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkkenjlnjfemconejajakbijbheoffli
Reddit Enhancement Suite - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb
Google Voice (by Google) - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcnhkahnjcbndmmehfkdnkjomaanaooo
StayFocusd - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\laankejkbhbdhmipfmgcngdelahlfoji
Webcam Toy - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade
InvisibleHand - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\lghjfnfolmcikomdjmoiemllfnlmmoko
Scraper - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbigbapnjcgaffohmbkdlecaccepngjd
Poppit - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi
Download Master - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcceagdollnkjlogmdckgjakjapmkdjf
Awesome New Tab Page - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgmiemnjjchgkmgbeljfocdjjnpjnmcg
Reddit Check - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\mllceaiaedaingchlgolnfiibippgkmj
EXIF Viewer - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafpfdcmppffipmhcpkbplhkoiekndck
ChromeReloadPlus - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbbpjdmdkcmpimmhloehkojhbhjlboog
Springpad Extension - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\njhgeimnepehieioinbhmfpphfoocmng
+Photo Zoom - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\njoglkofocgopmdfjnbifnicbickbola
Google Chrome to Phone Extension - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco
Checker Plus for Gmail™ - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\oeopbcgkkoapgobdbedcemjljbihmemj
ChromeIPass - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\ompiailgknfdndiefoaoiligalphfdae
Evernote Web Clipper - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc
Gmail - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
unedditreddit - Walternate\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppgcnpiddlbiemncalhbpgkcgecfofpj
 
==== Chromium Startpages ======================
 
C:\Users\Walternate\AppData\Local\Google\Chrome\User Data\Default\Preferences
 
 
==== IE Start and Search Settings ======================
 
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page Restore"="http://www.velocitymicro.com"
"Search Page"="http://www.google.com"
"Default_Page_URL"="http://www.velocitymicro.com"
"Default_Search_URL"="http://www.google.com/ie"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com/ie"
"Default_Search_URL"="http://www.google.com/ie"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
 
==== All HKCU SearchScopes ======================
 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="http://www.bing.com/...ox&FORM=IE8SRC"
{502F4341-15D2-4A62-BD9E-F45E914211BE} Google  Url="http://www.google.co...e=utf8&oe=utf8"
{63140ECF-C629-BE59-8F0E-90B4FF340C03} Bing  Url="http://www.bing.com/...ferrer:source}"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Goo  Url="http://www.google.com/search?q={sear"
 
==== C:\zoek_backup content ======================
 
C:\zoek_backup (files=0 folders=0 0 bytes)
 
==== EOF on Thu 10/02/2014 at 12:02:12.81 ======================
 
 
 

  • 0

#12
Biscuithd

Biscuithd

    Trusted Helper

  • Malware Removal
  • 2,573 posts

I think I'm going to do some selective uninstalling as well of programs I don't use, just for my own sanity.

Probably a good idea. They do accumulate quickly don't they? :)

 

Yes, let me know if we've solved the problem or not.


  • 0

#13
drmomentum

drmomentum

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

It really appears that the problem is solved. The crashes in Chrome are clearly gone (with nothing strange happening in the last 24 hours).

 

Sending a tip along. Appreciate the help.


  • 0

#14
Biscuithd

Biscuithd

    Trusted Helper

  • Malware Removal
  • 2,573 posts

It really appears that the problem is solved.

 

Great news!!

 

Thanks very much for the Tip!! :thumbsup:

 

Before we close things up, let's do a couple more things.

We'll search for some remnants that might be hiding.
 
Please download Malwarebytes Anti-Malware and save it to your desktop.
  • Install the progam and select update
 
  • Once it has updated select Settings > Detection and Protection >Tick Scan for rootkits

MBAMsettings.JPG

 
  • Go back to the Dashboard and select Scan Now

MBAMScan.JPG

 
  • If threats are detected, click the Apply Actions button, MBAM will ask for a reboot

MBAMReboot.JPG

  
  • On completion of the scan (or after the reboot) select View Detailed Log
Select Export > Select text file and save to the desktop.

MBAMLog.JPG

 
 
Please post that log for my review.
 
ESETOnline.png Scan with ESET Online Scanner

This step can only be done using Internet Explorer, Google Chrome or Mozilla Firefox.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.
Please visit ESET Online Scanner website.
Click there Run ESET Online Scanner.

If using Internet Explorer:
  • Accept the Terms of Use and click Start.
  • Allow the running of add-on.
If using Mozilla Firefox or Google Chrome:
  • Download esetsmartinstaller_enu.exe that you'll be given link to.
  • Double click esetsmartinstaller_enu.exe.
  • Allow the Terms of Use and click Start.
To perform the scan:
  • Make sure that Remove found threats is unchecked.
  • Scan archives is checked.
  • In Advanced Settings: Scan for potentially unwanted applications, Scan for potentially unsafe applications and Enable Anti-Stealth technology are checked.
  • Click Start
  • The program will begin to download it's virus database. The speed may vary depending on your Internet connection.
  • When completed, the program will begin to scan. ESET is doing a deep scan, so, Please, be patient.
  • Do not do anything on your machine as it may interrupt the scan.
  • When the scan is done, click Finish.
  • A logfile will be created at C:\Program Files (x86)\ESET\ESET Online Scanner. Open it using Notepad.
Please include this logfile in your next reply.

Don't forget to re-enable previously switched-off protection software!

 

Once these two finish and assuming nothing wonky happens, feel free to run Delfix to remove all the tools we used.

 

51a5ce45263de-delfix.png Clean with DelFix
 
Please download DelFix by Xplode and save it to your desktop.
 
  • Right-click on 51a5ce45263de-delfix.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Ensure that Remove disinfection tools, Purge system restore and Reset system settings are checked.
  • Push Run.
  • When finished, it will display a notepad report.
 
Be sure to post the logs

  • 0

#15
drmomentum

drmomentum

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

I will go through this process today and report back.


  • 0






Similar Topics


Also tagged with one or more of these keywords: stormfall, adware, camstudio, chrome

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP