Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Script errors, invalid destination errors, adobe flash crashing even w


  • This topic is locked This topic is locked

#16
Biscuithd

Biscuithd

    Trusted Helper

  • Malware Removal
  • 2,573 posts

Ok, here are your next steps. Feel free to post the logs as you finish the scans. Once all scans and fixes are complete, let me know how the machine is running.

 

51a612a8b27e2-Zoek.png Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.


 

  • Right-click on 51a612a8b27e2-Zoek.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
    createsrpoint;
    emptyalltemp;
    iedefaults;
    FFdefaults;
    chrdefaults;
    firefoxlook;
    chromelook;
    autoruns;
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)

 

Post its content into your next reply.

 

adwcleaner_new.png Scan with AdwCleaner
 
Please download AdwCleaner by Xplode and save the file to your desktop.
 
  • Right-click on adwcleaner_new.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Follow the prompts and click Scan.
  • Upon completion, click Report. A log (AdwCleaner[R*].txt) will open.
 
Please include the contents of that file in your reply.
 
adwcleaner_new.png Scan with AdwCleaner
 
Please download AdwCleaner by Xplode and save the file to your desktop.
 
  • Right-click on adwcleaner_new.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Follow the prompts and click Scan.
  • Upon completion, click Report. A log (AdwCleaner[R*].txt) will open.
 
Please include the contents of that file in your reply.

 

FRST.gif Scan with Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool x64 and save it to your Desktop.


  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • When the tool opens click Yes to disclaimer.
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please copy and paste their content into your next reply.

 

 


  • 0

Advertisements


#17
sheyennelilly

sheyennelilly

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts

Zoek log:

 

Zoek.exe v5.0.0.0 Updated 03-December-2014
Tool run by Sheyenne Alvarez on Thu 12/04/2014 at 15:45:21.76.
Microsoft Windows 7 Home Premium  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Sheyenne Alvarez\Desktop\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2014-12-04-165605.log    91099 bytes

==== System Restore Info ======================

12/4/2014 3:48:59 PM Zoek.exe System Restore Point Created Succesfully.

==== FireFox Fix ======================

Deleted from C:\Users\DARIOJ~1\AppData\Roaming\Mozilla\Firefox\Profiles\jxnoht0o.default\prefs.js:

Added to C:\Users\DARIOJ~1\AppData\Roaming\Mozilla\Firefox\Profiles\jxnoht0o.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.co...le Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.co...le Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

Deleted from C:\Users\GABRIE~1\AppData\Roaming\Mozilla\Firefox\Profiles\fdnb7ntl.default\prefs.js:

Added to C:\Users\GABRIE~1\AppData\Roaming\Mozilla\Firefox\Profiles\fdnb7ntl.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.co...le Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.co...le Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

Deleted from C:\Users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\ivj6ttxk.default\prefs.js:

Added to C:\Users\Roman\AppData\Roaming\Mozilla\Firefox\Profiles\ivj6ttxk.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.co...le Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.co...le Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

Deleted from C:\Users\SHEYEN~1\AppData\Roaming\Mozilla\Firefox\Profiles\btxhxadl.default-1415987071767\prefs.js:
user_pref("browser.startup.homepage", "https://my.yahoo.com/");
user_pref("browser.search.defaultenginename", "Bing");
user_pref("browser.search.selectedEngine", "Bing");

Added to C:\Users\SHEYEN~1\AppData\Roaming\Mozilla\Firefox\Profiles\btxhxadl.default-1415987071767\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.co...le Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.co...le Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}"="C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension" [02/18/2011 10:23 PM]

==== Firefox Extensions ======================

ProfilePath: C:\Users\DARIOJ~1\AppData\Roaming\Mozilla\Firefox\Profiles\jxnoht0o.default
- Undetermined - C:\Users\Dario Jr\AppData\Roaming\Mozilla\Firefox\Profiles\jxnoht0o.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}

ProfilePath: C:\Users\GABRIE~1\AppData\Roaming\Mozilla\Firefox\Profiles\fdnb7ntl.default
- Undetermined - C:\Users\Gabriella\AppData\Roaming\Mozilla\Firefox\Profiles\fdnb7ntl.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Sheyenne Alvarez\AppData\Roaming\Mozilla\Firefox\Profiles\btxhxadl.default-1415987071767
8303B3CEC05500F763B4FA75210598BB    - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll -    Shockwave Flash
D6ED6EB98E759460AD8C66DE23070132    - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll -    Microsoft Office 2013
18CF51689186AEB9D1D149AEB0E92D03    - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL -    Microsoft Office 2013
E638C845403AB63112673A0C72C07789    - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll -    RealNetworks™ RealPlayer Chrome Background Extension Plug-In (32-bit)
0C316A33BBE35CD1097936393A177656    - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll -    RealPlayer™ HTML5VideoShim Plug-In (32-bit)


==== Chromium Startpages ======================

C:\Users\Sheyenne Alvarez\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "http://www.google.com/",
"urls_to_restore_on_startup": [ "http://www.google.com/" ]


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page Restore"="http://go.microsoft..../?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page Restore"="http://go.microsoft..../?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google  Url="http://www.google.co...={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="http://www.bing.com/...ox&FORM=IE8SRC"
{A95C09AC-0593-4FEF-898E-A147C363BCAB} Google  Url="http://www.google.co...rlz=1I7ADSA_en"
{d43b3890-80c7-4010-a95d-1e77b5924dc3} Wikipedia  Url="http://en.wikipedia....={searchTerms}"
{d944bb61-2e34-4dbf-a683-47e505c587dc} eBay  Url="http://rover.ebay.co...}&mfe=Desktops"
{ec29edf6-ad3c-4e1c-a087-d6cb81400c43} Bing  Url="http://www.bing.com/...c=IE-SearchBox"

==== Reset Google Chrome ======================

C:\Users\Sheyenne Alvarez\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Sheyenne Alvarez\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Sysinternals Autoruns Log ======================

HKLM\System\CurrentControlSet\Services
   ABBYY.Licensing.FineReader.Sprint.9.0
     "C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe" -service
     This service is required for the operation of the ABBYY FineReader 9.0 Express Edition licensing mechanism.
     ABBYY
     1.0.0.375
     c:\program files (x86)\common files\abbyy\finereadersprint\9.00\licensing\networklicenseserver.exe
     5/14/2009 8:07 AM
   AdobeARMservice
     "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
     Adobe Acrobat Updater keeps your Adobe software up to date.
     Adobe Systems Incorporated
     1.701.8.51
     c:\program files (x86)\common files\adobe\arm\1.0\armsvc.exe
     8/21/2014 10:27 AM
   AdobeFlashPlayerUpdateSvc
     C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
     This service keeps your Adobe Flash Player installation up to date with the latest enhancements and security fixes.
     Adobe Systems Incorporated
     15.0.0.239
     c:\windows\syswow64\macromed\flash\flashplayerupdateservice.exe
     11/19/2014 4:30 PM
   Apple Mobile Device
     "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
     Provides the interface to Apple mobile devices.
     Apple Inc.
     17.327.4.24
     c:\program files (x86)\common files\apple\mobile device support\applemobiledeviceservice.exe
     2/11/2014 7:26 AM
   DeviceMonitorService
     "C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe"
     This service supports to  NGP for getting device information
     Nero AG
     1.0.13.0
     c:\program files (x86)\motorola media link\lite\nserviceentry.exe
     4/20/2010 12:19 AM
   Fabs
     C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe /DisableUI
     Watches filechanges, does automatic backups and configuration stuff.
     MAGIX AG
     2.1.27.0
     c:\program files (x86)\common files\magix services\database\bin\fabs.exe
     8/27/2009 9:09 AM
   Fitbit Connect
     C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe
     Uploads your Fitbit's data to Fitbit.com in the background
     Fitbit, Inc.
     1.0.3.5511
     c:\program files (x86)\fitbit connect\fitbitconnectservice.exe
     5/19/2014 6:03 AM
   gupdate
     "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc
     Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.
     Google Inc.
     1.3.21.103
     c:\program files (x86)\google\update\googleupdate.exe
     2/15/2012 8:43 PM
   gupdatem
     "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc
     Keeps your Google software up to date. If this service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work. This service uninstalls itself when there is no Google software using it.
     Google Inc.
     1.3.21.103
     c:\program files (x86)\google\update\googleupdate.exe
     2/15/2012 8:43 PM
   gusvc
     "C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe"
     Google Updater keeps your Google software up to date. If Google Updater Service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work.
     Google
     2.4.1441.4352
     c:\program files (x86)\google\common\google updater\googleupdaterservice.exe
     12/12/2008 1:18 PM
   iPod Service
     "C:\Program Files\iPod\bin\iPodService.exe"
     iPod hardware management services
     Apple Inc.
     11.2.2.3
     c:\program files\ipod\bin\ipodservice.exe
     5/26/2014 7:38 PM
   LBTServ
     C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
     Logitech Bluetooth Service
     Logitech, Inc.
     4.80.103.0
     c:\program files\common files\logishrd\bluetooth\lbtserv.exe
     7/20/2009 1:15 PM
   MBAMScheduler
     "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
     Malwarebytes Anti-Malware scheduler
     Malwarebytes Corporation
     3.1.1.0
     c:\program files (x86)\malwarebytes anti-malware\mbamscheduler.exe
     9/11/2014 7:29 PM
   MBAMService
     "C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
     Malwarebytes Anti-Malware service
     Malwarebytes Corporation
     3.0.8.1
     c:\program files (x86)\malwarebytes anti-malware\mbamservice.exe
     11/20/2014 2:08 PM
   Motorola Device Manager
     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
     MotoHelper Service
     2.2.35.0
     c:\program files (x86)\motorola mobility\motorola device manager\motohelperservice.exe
     10/2/2012 12:45 PM
   MozillaMaintenance
     "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe"
     The Mozilla Maintenance Service ensures that you have the latest and most secure version of Mozilla Firefox on your computer. Keeping Firefox up to date is very important for your online security, and Mozilla strongly recommends that you keep this service enabled.
     Mozilla Foundation
     34.0.5.5443
     c:\program files (x86)\mozilla maintenance service\maintenanceservice.exe
     11/26/2014 7:33 AM
   NOBU
     "C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe" SERVICE
     Norton Online Backup Service
     Symantec Corporation
     2.1.17869.0
     c:\program files (x86)\symantec\norton online backup\nobuagent.exe
     6/1/2010 1:31 PM
   npggsvc
     C:\Windows\system32\GameMon.des -service
     nProtect GameGuard Service
     INCA Internet Co., Ltd.
     2014.5.21.1
     c:\windows\syswow64\gamemon.des
     5/20/2014 7:34 PM
   NTI BackupNowEZSvr
     C:\Program Files (x86)\NTI\NTI Backup Now EZ\BackupNowEZSvr.exe
     NTI BackupNowEZ Manage backup/Sync jobs and  etc...
     NTI Corporation
     3.0.2.32
     c:\program files (x86)\nti\nti backup now ez\backupnowezsvr.exe
     2/4/2013 8:06 PM
   PST Service
     C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe
     Route and execute the requests/commands from PST
     Motorola
     1.0.0.0
     c:\program files (x86)\motorola\motforwarddaemon\forwarddaemon.exe
     8/10/2011 1:44 AM
   RichVideo64
     "C:\Program Files\CyberLink\Shared files\RichVideo64.exe"
     RichVideo Module
     2.0.1.7413
     c:\program files\cyberlink\shared files\richvideo64.exe
     2/12/2012 8:44 PM
   SBSDWSCService
     C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
     Spybot-S&D Security Center integration
     Safer Networking Ltd.
     1.0.0.12
     c:\program files (x86)\spybot - search & destroy\sdwinsec.exe
     6/19/1992 4:22 PM

HKLM\System\CurrentControlSet\Services
   adp94xx
     \SystemRoot\system32\DRIVERS\adp94xx.sys
     Adaptec Windows SAS/SATA Storport Driver
     Adaptec, Inc.
     1.6.6.4
     c:\windows\system32\drivers\adp94xx.sys
     12/5/2008 5:54 PM
   adpahci
     \SystemRoot\system32\DRIVERS\adpahci.sys
     Adaptec Windows SATA Storport Driver
     Adaptec, Inc.
     1.6.6.1
     c:\windows\system32\drivers\adpahci.sys
     5/1/2007 11:30 AM
   adpu320
     \SystemRoot\system32\DRIVERS\adpu320.sys
     Adaptec StorPort Ultra320 SCSI Driver (X64)
     Adaptec, Inc.
     7.2.0.0
     c:\windows\system32\drivers\adpu320.sys
     2/27/2007 6:04 PM
   aliide
     \SystemRoot\system32\drivers\aliide.sys
     ALi mini IDE Driver
     Acer Laboratories Inc.
     1.2.0.0
     c:\windows\system32\drivers\aliide.sys
     7/13/2009 5:19 PM
   amdkmdag
     system32\DRIVERS\atikmdag.sys
     ATI Radeon Kernel Mode Driver
     ATI Technologies Inc.
     8.1.1.1030
     c:\windows\system32\drivers\atikmdag.sys
     5/11/2010 7:40 PM
   amdkmdap
     system32\DRIVERS\atikmpag.sys
     AMD multi-vendor Miniport Driver
     Advanced Micro Devices, Inc.
     8.14.1.6113
     c:\windows\system32\drivers\atikmpag.sys
     5/11/2010 7:24 PM
   amdsata
     \SystemRoot\system32\drivers\amdsata.sys
     AHCI 1.2 Device Driver
     Advanced Micro Devices
     1.1.2.5
     c:\windows\system32\drivers\amdsata.sys
     3/18/2010 6:45 PM
   amdsbs
     \SystemRoot\system32\DRIVERS\amdsbs.sys
     AMD Technology AHCI Compatible Controller Driver for Windows - AMD64 platform
     AMD Technologies Inc.
     3.6.1540.127
     c:\windows\system32\drivers\amdsbs.sys
     3/20/2009 12:36 PM
   amdxata
     system32\drivers\amdxata.sys
     Storage Filter Driver
     Advanced Micro Devices
     1.1.2.5
     c:\windows\system32\drivers\amdxata.sys
     3/19/2010 10:18 AM
   amd_sata
     system32\DRIVERS\amd_sata.sys
     AHCI 1.2 Device Driver
     Advanced Micro Devices
     1.2.1.238
     c:\windows\system32\drivers\amd_sata.sys
     8/13/2010 5:35 PM
   amd_xata
     system32\DRIVERS\amd_xata.sys
     Stor Filter Driver
     Advanced Micro Devices
     1.2.1.238
     c:\windows\system32\drivers\amd_xata.sys
     8/13/2010 5:35 PM
   Andbus
     system32\DRIVERS\lgandbus64.sys
     File not found: system32\DRIVERS\lgandbus64.sys
     
   AndDiag
     system32\DRIVERS\lganddiag64.sys
     LGE Android Platform USB Serial Port
     File not found: system32\DRIVERS\lganddiag64.sys
     
   AndGps
     system32\DRIVERS\lgandgps64.sys
     LGE Android Platform USB GPS NMEA Port
     File not found: system32\DRIVERS\lgandgps64.sys
     
   ANDModem
     system32\DRIVERS\lgandmodem64.sys
     LGE Android Platform Mobile Support
     File not found: system32\DRIVERS\lgandmodem64.sys
     
   androidusb
     System32\Drivers\lgandadb.sys
     File not found: System32\Drivers\lgandadb.sys
     
   arc
     \SystemRoot\system32\DRIVERS\arc.sys
     Adaptec RAID Storport Driver
     Adaptec, Inc.
     5.2.0.10384
     c:\windows\system32\drivers\arc.sys
     5/24/2007 3:27 PM
   arcsas
     \SystemRoot\system32\DRIVERS\arcsas.sys
     Adaptec SAS RAID WS03 Driver
     Adaptec, Inc.
     5.2.0.16119
     c:\windows\system32\drivers\arcsas.sys
     1/14/2009 1:27 PM
   AtiPcie
     system32\DRIVERS\AtiPcie64.sys
     AMD PCIE Filter Driver for ATI PCIE chipset
     Advanced Micro Devices Inc.
     1.3.3.70
     c:\windows\system32\drivers\atipcie64.sys
     3/10/2010 8:33 AM
   A_USBETHMP
     System32\Drivers\usbethmp.sys
     USB PowerPacket Network Adapter
     Intellon Corporation
     2.2.1.0
     c:\windows\system32\drivers\usbethmp.sys
     10/20/2008 11:22 PM
   b06bdrv
     \SystemRoot\system32\DRIVERS\bxvbda.sys
     Broadcom NetXtreme II GigE VBD
     Broadcom Corporation
     4.8.2.0
     c:\windows\system32\drivers\bxvbda.sys
     2/13/2009 4:18 PM
   b57nd60a
     system32\DRIVERS\b57nd60a.sys
     Broadcom NetXtreme Gigabit Ethernet NDIS6.x Unified Driver.
     Broadcom Corporation
     10.100.4.0
     c:\windows\system32\drivers\b57nd60a.sys
     4/26/2009 5:14 AM
   BrFiltLo
     \SystemRoot\system32\DRIVERS\BrFiltLo.sys
     Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver
     Brother Industries, Ltd.
     1.10.0.2
     c:\windows\system32\drivers\brfiltlo.sys
     8/6/2006 7:51 PM
   BrFiltUp
     \SystemRoot\system32\DRIVERS\BrFiltUp.sys
     Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver
     Brother Industries, Ltd.
     1.4.0.1
     c:\windows\system32\drivers\brfiltup.sys
     8/6/2006 7:51 PM
   Brserid
     \SystemRoot\System32\Drivers\Brserid.sys
     Brotehr Serial I/F Driver (WDM)
     Brother Industries Ltd.
     1.0.1.6
     c:\windows\system32\drivers\brserid.sys
     8/6/2006 7:51 PM
   BrSerWdm
     \SystemRoot\System32\Drivers\BrSerWdm.sys
     Brother Serial driver (WDM version)
     Brother Industries Ltd.
     1.0.0.20
     c:\windows\system32\drivers\brserwdm.sys
     8/6/2006 7:51 PM
   BrUsbMdm
     \SystemRoot\System32\Drivers\BrUsbMdm.sys
     Brother USB MDM Driver
     Brother Industries Ltd.
     1.0.0.12
     c:\windows\system32\drivers\brusbmdm.sys
     8/6/2006 7:51 PM
   BrUsbSer
     \SystemRoot\System32\Drivers\BrUsbSer.sys
     Brother USB Serial Driver
     Brother Industries Ltd.
     1.0.1.3
     c:\windows\system32\drivers\brusbser.sys
     8/9/2006 6:11 AM
   cmdide
     \SystemRoot\system32\drivers\cmdide.sys
     CMD PCI IDE Bus Driver
     CMD Technology, Inc.
     2.0.7.0
     c:\windows\system32\drivers\cmdide.sys
     7/13/2009 5:19 PM
   DFUBTUSB
     System32\Drivers\frmupgr.sys
     Flash Upgrade Driver for Bluetooth USB Device
     Broadcom Corporation.
     6.0.1.2300
     c:\windows\system32\drivers\frmupgr.sys
     10/6/2006 3:34 PM
   ebdrv
     \SystemRoot\system32\DRIVERS\evbda.sys
     Broadcom NetXtreme II 10 GigE VBD
     Broadcom Corporation
     4.8.13.0
     c:\windows\system32\drivers\evbda.sys
     12/31/2008 10:29 AM
   elxstor
     \SystemRoot\system32\DRIVERS\elxstor.sys
     Storport Miniport Driver for LightPulse HBAs
     Emulex
     7.2.10.211
     c:\windows\system32\drivers\elxstor.sys
     2/3/2009 4:52 PM
   GEARAspiWDM
     system32\DRIVERS\GEARAspiWDM.sys
     CD DVD Filter
     GEAR Software Inc.
     2.2.3.0
     c:\windows\system32\drivers\gearaspiwdm.sys
     5/3/2012 1:56 PM
   hcw85cir
     \SystemRoot\system32\drivers\hcw85cir.sys
     Hauppauge WinTV 885 Consumer IR Driver for eHome
     Hauppauge Computer Works, Inc.
     1.31.27127.0
     c:\windows\system32\drivers\hcw85cir.sys
     5/11/2009 2:26 AM
   HpSAMD
     \SystemRoot\system32\drivers\HpSAMD.sys
     Smart Array SAS/SATA Controller Media Driver
     Hewlett-Packard Company
     6.12.6.64
     c:\windows\system32\drivers\hpsamd.sys
     4/20/2010 12:32 PM
   iaStorV
     \SystemRoot\system32\drivers\iaStorV.sys
     Intel Matrix Storage Manager driver - x64
     Intel Corporation
     8.6.2.1014
     c:\windows\system32\drivers\iastorv.sys
     6/10/2010 6:46 PM
   iirsp
     \SystemRoot\system32\DRIVERS\iirsp.sys
     Intel/ICP Raid Storport Driver
     Intel Corp./ICP vortex GmbH
     5.4.22.0
     c:\windows\system32\drivers\iirsp.sys
     12/13/2005 3:47 PM
   IntcAzAudAddService
     system32\drivers\RTKVHD64.sys
     Realtek® High Definition Audio Function Driver
     Realtek Semiconductor Corp.
     6.0.1.6196
     c:\windows\system32\drivers\rtkvhd64.sys
     9/7/2010 5:17 AM
   LHidFilt
     system32\DRIVERS\LHidFilt.Sys
     Logitech HID Filter Driver.
     Logitech, Inc.
     4.82.4.0
     c:\windows\system32\drivers\lhidfilt.sys
     6/17/2009 10:49 AM
   LMouFilt
     system32\DRIVERS\LMouFilt.Sys
     Logitech Mouse Filter Driver.
     Logitech, Inc.
     4.82.4.0
     c:\windows\system32\drivers\lmoufilt.sys
     6/17/2009 10:49 AM
   LSI_FC
     \SystemRoot\system32\DRIVERS\lsi_fc.sys
     LSI Fusion-MPT FC Driver (StorPort)
     LSI Corporation
     1.28.3.52
     c:\windows\system32\drivers\lsi_fc.sys
     12/9/2008 4:46 PM
   LSI_SAS
     \SystemRoot\system32\DRIVERS\lsi_sas.sys
     LSI Fusion-MPT SAS Driver (StorPort)
     LSI Corporation
     1.28.3.52
     c:\windows\system32\drivers\lsi_sas.sys
     5/18/2009 6:20 PM
   LSI_SAS2
     \SystemRoot\system32\DRIVERS\lsi_sas2.sys
     LSI SAS Gen2 Driver (StorPort)
     LSI Corporation
     2.0.2.71
     c:\windows\system32\drivers\lsi_sas2.sys
     5/18/2009 6:31 PM
   LSI_SCSI
     \SystemRoot\system32\DRIVERS\lsi_scsi.sys
     LSI Fusion-MPT SCSI Driver (StorPort)
     LSI Corporation
     1.28.3.67
     c:\windows\system32\drivers\lsi_scsi.sys
     4/16/2009 4:13 PM
   MBAMProtector
     \??\C:\Windows\system32\drivers\mbam.sys
     Malwarebytes Anti-Malware
     Malwarebytes Corporation
     0.1.15.0
     c:\windows\system32\drivers\mbam.sys
     9/3/2014 11:50 AM
   MBAMSwissArmy
     \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
     Malwarebytes Anti-Malware
     Malwarebytes Corporation
     0.2.13.0
     c:\windows\system32\drivers\mbamswissarmy.sys
     9/19/2014 4:14 PM
   MBAMWebAccessControl
     \??\C:\Windows\system32\drivers\mwac.sys
     Malwarebytes Web Access Control
     Malwarebytes Corporation
     1.0.6.0
     c:\windows\system32\drivers\mwac.sys
     6/17/2014 8:06 PM
   megasas
     \SystemRoot\system32\DRIVERS\megasas.sys
     MEGASAS RAID Controller Driver for Windows 7\Server 2008 R2 for x64
     LSI Corporation
     4.5.1.64
     c:\windows\system32\drivers\megasas.sys
     5/18/2009 7:09 PM
   MegaSR
     \SystemRoot\system32\DRIVERS\MegaSR.sys
     LSI MegaRAID Software RAID Driver
     LSI Corporation, Inc.
     13.5.409.2009
     c:\windows\system32\drivers\megasr.sys
     5/18/2009 7:25 PM
   Netaapl
     system32\DRIVERS\netaapl64.sys
     Apple Mobile Device Ethernet
     Apple Inc.
     1.8.5.1
     c:\windows\system32\drivers\netaapl64.sys
     7/15/2013 4:39 PM
   netr28x
     system32\DRIVERS\netr28x.sys
     Ralink 802.11 Wireless Adapter Driver
     Ralink Technology, Corp.
     3.1.9.0
     c:\windows\system32\drivers\netr28x.sys
     7/21/2010 5:39 AM
   nfrd960
     \SystemRoot\system32\DRIVERS\nfrd960.sys
     IBM ServeRAID Controller Driver
     IBM Corporation
     7.10.0.0
     c:\windows\system32\drivers\nfrd960.sys
     6/6/2006 3:11 PM
   NTIDrvr
     \??\C:\Windows\system32\drivers\NTIDrvr.sys
     NTI CD-ROM Filter Driver
     NewTech Infosystems, Inc.
     1.0.0.9
     c:\windows\system32\drivers\ntidrvr.sys
     3/24/2009 9:09 PM
   nvraid
     \SystemRoot\system32\drivers\nvraid.sys
     NVIDIAr nForce™ RAID Driver
     NVIDIA Corporation
     10.6.0.18
     c:\windows\system32\drivers\nvraid.sys
     3/19/2010 2:59 PM
   nvstor
     \SystemRoot\system32\drivers\nvstor.sys
     NVIDIAr nForce™ Sata Performance Driver
     NVIDIA Corporation
     10.6.0.18
     c:\windows\system32\drivers\nvstor.sys
     3/19/2010 2:45 PM
   ql2300
     \SystemRoot\system32\DRIVERS\ql2300.sys
     QLogic Fibre Channel Stor Miniport Driver
     QLogic Corporation
     9.1.8.6
     c:\windows\system32\drivers\ql2300.sys
     1/22/2009 5:05 PM
   ql40xx
     \SystemRoot\system32\DRIVERS\ql40xx.sys
     QLogic iSCSI Storport Miniport Driver
     QLogic Corporation
     2.1.3.20
     c:\windows\system32\drivers\ql40xx.sys
     5/18/2009 7:18 PM
   RTL8167
     system32\DRIVERS\Rt64win7.sys
     Realtek 8136/8168/8169 NDIS 6.20 64-bit Driver                
     Realtek                                            
     7.26.902.2010
     c:\windows\system32\drivers\rt64win7.sys
     9/2/2010 11:58 PM
   secdrv
     secdrv
     Macrovision SECURITY Driver
     Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.
     4.3.86.0
     c:\windows\system32\drivers\secdrv.sys
     9/13/2006 7:18 AM
   Ser2pl
     system32\DRIVERS\ser2pl64.sys
     USB-to-Serial Cable Driver
     Prolific Technology Inc.
     3.0.1.0
     c:\windows\system32\drivers\ser2pl64.sys
     2/12/2007 3:56 AM
   SiSRaid2
     \SystemRoot\system32\DRIVERS\SiSRaid2.sys
     SiS RAID Stor Miniport Driver
     Silicon Integrated Systems Corp.
     5.1.1039.2600
     c:\windows\system32\drivers\sisraid2.sys
     9/24/2008 12:28 PM
   SiSRaid4
     \SystemRoot\system32\DRIVERS\sisraid4.sys
     SiS AHCI Stor-Miniport Driver
     Silicon Integrated Systems
     5.1.1039.3600
     c:\windows\system32\drivers\sisraid4.sys
     10/1/2008 3:56 PM
   sscdbus
     system32\DRIVERS\sscdbus.sys
     SAMSUNG USB Composite Device Driver
     MCCI Corporation
     5.16.0.2
     c:\windows\system32\drivers\sscdbus.sys
     11/10/2010 3:37 PM
   stexstor
     \SystemRoot\system32\DRIVERS\stexstor.sys
     Promise  SuperTrak EX Series Driver for Windows
     Promise Technology
     5.0.1.1
     c:\windows\system32\drivers\stexstor.sys
     2/17/2009 5:03 PM
   UBHelper
     \??\C:\Windows\system32\drivers\UBHelper.sys
     NTI CDROM Filter Driver
     NewTech Infosystems Corporation
     2.0.0.11
     c:\windows\system32\drivers\ubhelper.sys
     4/27/2009 2:48 AM
   USBAAPL64
     System32\Drivers\usbaapl64.sys
     Apple Mobile Device USB Driver
     Apple, Inc.
     1.64.0.0
     c:\windows\system32\drivers\usbaapl64.sys
     11/27/2012 5:38 PM
   usbfilter
     \SystemRoot\system32\DRIVERS\usbfilter.sys
     AMD USB Filter Driver
     Advanced Micro Devices
     1.0.15.99
     c:\windows\system32\drivers\usbfilter.sys
     12/22/2009 2:26 AM
   viaide
     \SystemRoot\system32\drivers\viaide.sys
     VIA Generic PCI IDE Bus Driver
     VIA Technologies, Inc.
     6.0.6000.170
     c:\windows\system32\drivers\viaide.sys
     7/13/2009 5:19 PM
   vsmraid
     \SystemRoot\system32\DRIVERS\vsmraid.sys
     VIA RAID DRIVER FOR AMD-X86-64
     VIA Technologies Inc.,Ltd
     6.0.6000.6210
     c:\windows\system32\drivers\vsmraid.sys
     1/30/2009 7:18 PM
   WDC_SAM
     system32\DRIVERS\wdcsam64.sys
     Manages WD external storage products.
     Western Digital Technologies
     1.0.7.2
     c:\windows\system32\drivers\wdcsam64.sys
     4/16/2008 2:39 AM
   WLRAWMp50x64
     System32\Drivers\WLRAWMp50x64.sys
     PCAUSA NDIS 5.0 MPR Protocol Driver (AMD64)
     Logitech, Inc.
     5.60.19.0
     c:\windows\system32\drivers\wlrawmp50x64.sys
     4/16/2009 2:57 PM
   WLRAWSp50x64
     System32\Drivers\WLRAWSp50x64.sys
     PCAUSA NDIS 5.0 SPR Protocol Driver (AMD64)
     Logitech, Inc.
     5.60.19.0
     c:\windows\system32\drivers\wlrawsp50x64.sys
     4/16/2009 2:56 PM
   ZCinema_TSHD_x64
     system32\drivers\ZCinema_SRS_amd64.sys
     Z Cin‚ma
     SRS Labs, Inc.
     1.4.2.0
     c:\windows\system32\drivers\zcinema_srs_amd64.sys
     8/15/2007 1:28 PM

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
   DK_DKADGQ
     DKADGQLANG.DLL
     Printer Communication System
      
     12.1.36.0
     c:\windows\system32\dkadgqlang.dll
     9/6/2012 7:20 AM
   DK_DKFX1N
     DKFX1NLANG.DLL
     Printer Communication System
      
     12.1.34.0
     c:\windows\system32\dkfx1nlang.dll
     8/13/2012 1:37 AM
   Fax Dell V715w Port
     DLEEPMON.DLL
     c:\windows\system32\dleepmon.dll
     11/26/2009 12:09 AM
   PDFC
     pdfc_port.dll
     PDF Complete Print Monitor
     PDF Complete, Inc.
     0.3.1.5
     c:\windows\system32\pdfc_port.dll
     5/6/2011 9:56 AM

HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms
   rdpclip
     rdpclip
     File not found: rdpclip
     

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
   Kernel and Hardware Abstraction Layer
     KHALMNPR.EXE
     Logitech KHAL Main Process
     Logitech, Inc.
     4.82.4.0
     c:\windows\khalmnpr.exe
     6/17/2009 10:47 AM
   Bluetooth Connection Assistant
     LBTWIZ.EXE -silent
     Bluetooth Services
     Logitech Inc.
     1.0.0.1
     C:\Program Files\Logitech\SetPoint\LBTWiz.exe
     7/20/2009 1:17 PM
   DKADGmon
     "C:\Program Files (x86)\Dell V520 Series\DKADGmon.exe"
     Printer Device Monitor
     0.1.25.0
     c:\program files (x86)\dell v520 series\dkadgmon.exe
     9/7/2012 1:39 AM

HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
   Norton Online Backup
     C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
     Norton Online Backup Service
     Symantec Corporation
     2.1.17869.0
     c:\program files (x86)\symantec\norton online backup\nobuclient.exe
     6/1/2010 1:33 PM
   Adobe ARM
     "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
     Adobe Reader and Acrobat Manager
     Adobe Systems Incorporated
     1.701.8.51
     c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe
     8/21/2014 10:27 AM
   BackupNowEZtray
     "C:\Program Files (x86)\NTI\NTI Backup Now EZ\BackupNowEZtray.exe" -k
     NTI Backup Now EZ
     NTI Corporation
     3.0.2.32
     c:\program files (x86)\nti\nti backup now ez\backupnoweztray.exe
     2/4/2013 8:06 PM
   DKADGmon
     "C:\Program Files (x86)\Dell V520 Series\DKADGmon.exe"
     Printer Device Monitor
     0.1.25.0
     c:\program files (x86)\dell v520 series\dkadgmon.exe
     9/7/2012 1:39 AM
   QuickTime Task
     "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
     QuickTime Task
     Apple Inc.
     7.7.5.0
     c:\program files (x86)\quicktime\qttask.exe
     1/13/2014 7:15 PM
   iTunesHelper
     "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
     iTunesHelper
     Apple Inc.
     11.2.2.3
     c:\program files (x86)\itunes\ituneshelper.exe
     5/26/2014 7:38 PM
   Fitbit Connect
     "C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe" /autorun
     Fitbit Connect Desktop Client
     Fitbit, Inc.
     1.0.3.5511
     c:\program files (x86)\fitbit connect\fitbit connect.exe
     5/19/2014 6:04 AM
   SunJavaUpdateSched
     "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
     Java™ Update Scheduler
     Oracle Corporation
     2.1.67.1
     c:\program files (x86)\common files\java\java update\jusched.exe
     7/25/2014 12:29 PM

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
   CineForm Status.lnk
     C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CineForm Status.lnk
     GoPro/CineForm Status Viewer
     GoPro
     1.0.0.0
     c:\program files (x86)\cineform\tools\goprocineformstatusviewer.exe
     1/29/2014 1:00 PM
   Logitech SetPoint.lnk
     C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
     Logitech SetPoint Event Manager (UNICODE)
     Logitech, Inc.
     4.80.103.0
     c:\program files\logitech\setpoint\setpoint.exe
     7/20/2009 1:07 PM

HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components
   Internet Explorer
     C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
     File not found: C:\Windows\system32\ie4uinit.exe
     
   n/a
     C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
     File not found: C:\Windows\system32\ie4uinit.exe
     
   n/a
     C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
     File not found: C:\Windows\system32\ie4uinit.exe
     
   Offline Browsing Pack
     C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
     File not found: C:\Windows\system32\ie4uinit.exe
     

Task Scheduler
   \Adobe Flash Player Updater
     "C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe"
     Adober Flashr Player Update Service 15.0 r0
     Adobe Systems Incorporated
     15.0.0.239
     c:\windows\syswow64\macromed\flash\flashplayerupdateservice.exe
     11/19/2014 4:30 PM
   \DellPUDCTask
     "C:\Program Files\Dell\ProductUpdate\DKprodupdate.exe" /s
     Product Update
     1.1.12.3
     c:\program files\dell\productupdate\dkprodupdate.exe
     9/11/2012 12:22 AM
   \GoogleUpdateTaskMachineCore
     "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
     Google Installer
     Google Inc.
     1.3.21.103
     c:\program files (x86)\google\update\googleupdate.exe
     2/15/2012 8:43 PM
   \GoogleUpdateTaskMachineUA
     "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /ua /installsource scheduler
     Google Installer
     Google Inc.
     1.3.21.103
     c:\program files (x86)\google\update\googleupdate.exe
     2/15/2012 8:43 PM
   \HPCeeScheduleForSheyenne Alvarez
     "C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe" HPCeeScheduleForSheyenne Alvarez (null)
     HP Ceement
     Hewlett-Packard
     6.0.1.7
     c:\program files (x86)\hewlett-packard\hp ceement\hpcee.exe
     9/13/2010 11:11 PM
   \HPCeeScheduleForSHEYENNEALVAREZ$
     "C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe" HPCeeScheduleForSHEYENNEALVAREZ$ (null)
     HP Ceement
     Hewlett-Packard
     6.0.1.7
     c:\program files (x86)\hewlett-packard\hp ceement\hpcee.exe
     9/13/2010 11:11 PM
   \MotoCast Update
     "C:\Program Files (x86)\Motorola Mobility\MotoCast\LiveUpdate\MotoCastUpdate.exe" -d -silent
     MotoCastUpdate
     1.3.0.0
     c:\program files (x86)\motorola mobility\motocast\liveupdate\motocastupdate.exe
     3/5/2012 6:19 PM
   \Motorola Device Manager Engine
     "C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe" -r
     Motorola Device Management Update
     2.2.33.0
     c:\program files (x86)\motorola mobility\motorola device manager\motoroladevicemanagerupdate.exe
     9/28/2012 1:26 PM
   \Motorola Device Manager Initial Update
     "C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe" -d -silent
     Motorola Device Management Update
     2.2.33.0
     c:\program files (x86)\motorola mobility\motorola device manager\motoroladevicemanagerupdate.exe
     9/28/2012 1:26 PM
   \Motorola Device Manager Update
     "C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe" -d -silent
     Motorola Device Management Update
     2.2.33.0
     c:\program files (x86)\motorola mobility\motorola device manager\motoroladevicemanagerupdate.exe
     9/28/2012 1:26 PM
   \RealDownloaderDownloaderScheduledTaskS-1-5-21-3854915487-3061028145-266851286-1000
     "C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe" /bgrecordaliveevent
     File not found: C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe
     
   \RealDownloaderRealUpgradeLogonTaskS-1-5-21-3854915487-3061028145-266851286-1000
     "C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe" /logoncheck
     File not found: C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe
     
   \RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3854915487-3061028145-266851286-1000
     "C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe" /scheduledcheck
     File not found: C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe
     
   \RealPlayerRealUpgradeLogonTaskS-1-5-21-3854915487-3061028145-266851286-1000
     "C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe" /logoncheck
     File not found: C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
     
   \RealPlayerRealUpgradeScheduledTaskS-1-5-21-3854915487-3061028145-266851286-1000
     "C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe" /scheduledcheck
     File not found: C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
     
   \RealUpgradeLogonTaskS-1-5-21-3854915487-3061028145-266851286-1000
     "C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe" /logoncheck
     File not found: C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
     
   \RealUpgradeScheduledTaskS-1-5-21-3854915487-3061028145-266851286-1000
     "C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe" /scheduledcheck
     File not found: C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
     
   \Registration
     "C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe" Registration ShowMessageTask2D
     ESAdvRemIntegrator
     8.4.4400.3525
     c:\program files (x86)\hewlett-packard\hp setup\remengine.exe
     9/27/2010 5:29 AM
   \Windows Codec Update Service
     "C:\Program Files (x86)\Essentials Codec Pack\WECPUpdate.exe" -s
     WECP Auto Update Service
     MediaCodec.Org
     4.0.0.0
     c:\program files (x86)\essentials codec pack\wecpupdate.exe
     2/3/2012 3:14 AM
   \Hewlett-Packard\HP Support Assistant\GetAssistance Maintenance Events
     "%programfiles(x86)%\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\HPSAObjUtil.exe" /NOCONSOLE getassistfix
     HPSAObjUtil
     HP
     1.0.5.2
     c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\hpsaobjutil.exe
     11/18/2010 11:34 AM
   \Hewlett-Packard\HP Support Assistant\PC Health Analysis
     "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe" /L Analysis
     HP Support Assistant
     Hewlett-Packard Company
     5.1.8.12
     c:\program files (x86)\hewlett-packard\hp support framework\hpsf.exe
     9/17/2010 10:18 AM
   \Hewlett-Packard\HP Support Assistant\PC Tuneup
     "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe" /L TuneupTimer
     HP Support Assistant
     Hewlett-Packard Company
     5.1.8.12
     c:\program files (x86)\hewlett-packard\hp support framework\hpsf.exe
     9/17/2010 10:18 AM
   \Microsoft\Windows\NetTrace\GatherNetworkInfo
     "%windir%\system32\gatherNetworkInfo.vbs"
     c:\windows\system32\gathernetworkinfo.vbs
     6/10/2009 2:36 PM

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
   Dell Toolbar
     HKCR\CLSID\{09B71986-2AC5-482d-B6CB-42EA34F4F85B}
     1.8.12.0
     c:\program files\dell printable web\toolband.dll
     12/10/2008 3:10 AM
   Spybot-S&D IE Protection
     HKCR\CLSID\{53707962-6F74-2D53-2644-206D7942484F}
     SBSD IE Protection
     Safer Networking Limited
     1.6.2.14
     c:\program files (x86)\spybot - search & destroy\sdhelper.dll
     6/19/1992 4:22 PM
   Java™ Plug-In SSV Helper
     HKCR\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
     Java™ Platform SE binary
     Oracle Corporation
     10.67.2.1
     c:\program files (x86)\java\jre7\bin\ssv.dll
     7/25/2014 12:45 PM
   Java™ Plug-In 2 SSV Helper
     HKCR\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}
     Java™ Platform SE binary
     Oracle Corporation
     10.67.2.1
     c:\program files (x86)\java\jre7\bin\jp2ssv.dll
     7/25/2014 12:45 PM

HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
   Dell Toolbar
     HKCR\CLSID\{09B71986-2AC5-482d-B6CB-42EA34F4F85B}
     1.8.12.0
     c:\program files\dell printable web\toolband.dll
     12/10/2008 3:10 AM
   Spybot-S&D IE Protection
     HKCR\CLSID\{53707962-6F74-2D53-2644-206D7942484F}
     SBSD IE Protection
     Safer Networking Limited
     1.6.2.14
     c:\program files (x86)\spybot - search & destroy\sdhelper.dll
     6/19/1992 4:22 PM
   Java™ Plug-In SSV Helper
     HKCR\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
     Java™ Platform SE binary
     Oracle Corporation
     10.67.2.1
     c:\program files (x86)\java\jre7\bin\ssv.dll
     7/25/2014 12:45 PM
   Java™ Plug-In 2 SSV Helper
     HKCR\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}
     Java™ Platform SE binary
     Oracle Corporation
     10.67.2.1
     c:\program files (x86)\java\jre7\bin\jp2ssv.dll
     7/25/2014 12:45 PM

HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers
   PhotoStreamsExt
     HKCR\CLSID\{89D984B3-813B-406A-8298-118AFA3A22AE}
     c:\program files\common files\apple\internet services\shellstreams64.dll
     12/17/2012 6:38 PM
   UAContextMenu
     HKCR\CLSID\{A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75}
     File not found: C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUAShell.dll
     

HKLM\Software\Wow6432Node\Classes\*\ShellEx\ContextMenuHandlers
   PhotoStreamsExt
     HKCR\CLSID\{89D984B3-813B-406A-8298-118AFA3A22AE}
     ShellStreams.dll
     Apple Inc.
     7.7.1.3
     c:\program files (x86)\common files\apple\internet services\shellstreams.dll
     12/17/2012 6:49 PM
   Yahoo! Mail
     HKCR\CLSID\{5464D816-CF16-4784-B9F3-75C0DB52B499}
     File not found: C:\Program Files (x86)\Yahoo!\Common\YMMAPI.dll
     

HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers
   MBAMShlExt
     HKCR\CLSID\{57CE581A-0CB6-4266-9CA0-19364C90A0B3}
     Malwarebytes Anti-Malware
     Malwarebytes Corporation
     3.0.6.0
     c:\program files (x86)\malwarebytes anti-malware\mbamext.dll
     7/7/2014 3:02 PM

HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers
   ACE
     HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}
     AMD Desktop Control Panel
     Advanced Micro Devices, Inc.
     6.14.10.2001
     c:\program files (x86)\ati technologies\ati.ace\core-static\atiacm64.dll
     5/11/2010 7:46 PM
   UAContextMenu
     HKCR\CLSID\{A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75}
     File not found: C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUAShell.dll
     

HKLM\Software\Wow6432Node\Classes\Folder\Shellex\ColumnHandlers
   PDF Shell Extension
     HKCR\CLSID\{F9DB5320-233E-11D1-9F84-707F02C10627}
     PDF Shell Extension
     Adobe Systems, Inc.
     11.0.3.37
     c:\program files (x86)\common files\adobe\acrobat\activex\pdfshell.dll
     5/11/2013 3:34 AM

HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers
   MBAMShlExt
     HKCR\CLSID\{57CE581A-0CB6-4266-9CA0-19364C90A0B3}
     Malwarebytes Anti-Malware
     Malwarebytes Corporation
     3.0.6.0
     c:\program files (x86)\malwarebytes anti-malware\mbamext.dll
     7/7/2014 3:02 PM
   UAContextMenu
     HKCR\CLSID\{A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75}
     File not found: C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUAShell.dll
     

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
   DropboxExt1
     HKCR\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}
     Dropbox Shell Extension
     Dropbox, Inc.
     1.0.0.24
     c:\users\sheyenne alvarez\appdata\roaming\dropbox\bin\dropboxext64.24.dll
     6/23/2014 6:32 PM
   DropboxExt2
     HKCR\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}
     Dropbox Shell Extension
     Dropbox, Inc.
     1.0.0.24
     c:\users\sheyenne alvarez\appdata\roaming\dropbox\bin\dropboxext64.24.dll
     6/23/2014 6:32 PM
   DropboxExt3
     HKCR\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}
     Dropbox Shell Extension
     Dropbox, Inc.
     1.0.0.24
     c:\users\sheyenne alvarez\appdata\roaming\dropbox\bin\dropboxext64.24.dll
     6/23/2014 6:32 PM
   DropboxExt4
     HKCR\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}
     Dropbox Shell Extension
     Dropbox, Inc.
     1.0.0.24
     c:\users\sheyenne alvarez\appdata\roaming\dropbox\bin\dropboxext64.24.dll
     6/23/2014 6:32 PM

HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
   "DropboxExt1"
     HKCR\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}
     Dropbox Shell Extension
     Dropbox, Inc.
     1.0.0.24
     c:\users\sheyenne alvarez\appdata\roaming\dropbox\bin\dropboxext.24.dll
     6/23/2014 6:31 PM
   "DropboxExt2"
     HKCR\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}
     Dropbox Shell Extension
     Dropbox, Inc.
     1.0.0.24
     c:\users\sheyenne alvarez\appdata\roaming\dropbox\bin\dropboxext.24.dll
     6/23/2014 6:31 PM
   "DropboxExt3"
     HKCR\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}
     Dropbox Shell Extension
     Dropbox, Inc.
     1.0.0.24
     c:\users\sheyenne alvarez\appdata\roaming\dropbox\bin\dropboxext.24.dll
     6/23/2014 6:31 PM
   "DropboxExt4"
     HKCR\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}
     Dropbox Shell Extension
     Dropbox, Inc.
     1.0.0.24
     c:\users\sheyenne alvarez\appdata\roaming\dropbox\bin\dropboxext.24.dll
     6/23/2014 6:31 PM
   "DropboxExt5"
     HKCR\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}
     Dropbox Shell Extension
     Dropbox, Inc.
     1.0.0.24
     c:\users\sheyenne alvarez\appdata\roaming\dropbox\bin\dropboxext.24.dll
     6/23/2014 6:31 PM
   "DropboxExt6"
     HKCR\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}
     Dropbox Shell Extension
     Dropbox, Inc.
     1.0.0.24
     c:\users\sheyenne alvarez\appdata\roaming\dropbox\bin\dropboxext.24.dll
     6/23/2014 6:31 PM
   "DropboxExt7"
     HKCR\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}
     Dropbox Shell Extension
     Dropbox, Inc.
     1.0.0.24
     c:\users\sheyenne alvarez\appdata\roaming\dropbox\bin\dropboxext.24.dll
     6/23/2014 6:31 PM
   "DropboxExt8"
     HKCR\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}
     Dropbox Shell Extension
     Dropbox, Inc.
     1.0.0.24
     c:\users\sheyenne alvarez\appdata\roaming\dropbox\bin\dropboxext.24.dll
     6/23/2014 6:31 PM

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar
   Dell Toolbar
     HKCR\CLSID\{09B71986-2AC5-482d-B6CB-42EA34F4F85B}
     1.8.12.0
     c:\program files\dell printable web\toolband.dll
     12/10/2008 3:10 AM

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Extensions
   Spybot - Search && Destroy Configuration
     C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
     SBSD IE Protection
     Safer Networking Limited
     1.6.2.14
     c:\program files (x86)\spybot - search & destroy\sdhelper.dll
     6/19/1992 4:22 PM

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
   msacm.l3acm
     C:\Windows\System32\l3codeca.acm
     MPEG Layer-3 Audio Codec for MSACM
     Fraunhofer Institut Integrierte Schaltungen IIS
     1.9.0.401
     c:\windows\system32\l3codeca.acm
     7/13/2009 7:28 PM
   vidc.ffds
     ff_vfw.dll
     ffdshow VFW
     1.2.4422.0
     c:\windows\system32\ff_vfw.dll
     4/8/2012 4:47 PM
   vidc.lags
     lagarith.dll
     Lagarith
      
     1.3.27.0
     c:\windows\system32\lagarith.dll
     12/7/2011 6:37 PM
   VIDC.CFHD
     CFHD.dll
     CineForm VFW CODEC
     CineForm Inc.
     8.6.3.670
     c:\windows\system32\cfhd.dll
     1/29/2014 12:55 PM

HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32
   msacm.l3acm
     C:\Windows\SysWOW64\l3codeca.acm
     MPEG Layer-3 Audio Codec for MSACM
     Fraunhofer Institut Integrierte Schaltungen IIS
     1.9.0.401
     c:\windows\syswow64\l3codeca.acm
     7/13/2009 7:06 PM
   vidc.cvid
     iccvid.dll
     Cinepakr Codec
     Radius Inc.
     1.10.0.13
     c:\windows\syswow64\iccvid.dll
     11/20/2010 5:59 AM
   vidc.ffds
     ff_vfw.dll
     ffdshow VFW
     1.2.4422.0
     c:\windows\syswow64\ff_vfw.dll
     4/8/2012 4:40 PM
   vidc.xvid
     xvidvfw.dll
     c:\windows\syswow64\xvidvfw.dll
     5/30/2011 7:42 AM
   vidc.lags
     lagarith.dll
     Lagarith
      
     1.3.27.0
     c:\windows\syswow64\lagarith.dll
     12/7/2011 6:32 PM
   msacm.ac3filter
     ac3filter.acm
     c:\windows\syswow64\ac3filter.acm
     8/11/2009 11:18 AM
   msacm.divxa32
     DivXa32.acm
     DivX;-) Audio Codec
     Packed With Joy !
     4.1.0.3920
     c:\windows\syswow64\divxa32.acm
     1/11/2000 8:19 PM
   msacm.lameacm
     LameACM.acm
     Lame MP3 codec engine
     http://www.mp3dev.org/
     0.9.1.0
     c:\windows\syswow64\lameacm.acm
     9/24/2008 1:41 PM
   VIDC.CFHD
     CFHD.DLL
     CineForm VFW CODEC
     CineForm Inc.
     8.6.3.670
     c:\windows\syswow64\cfhd.dll
     1/29/2014 12:52 PM

HKLM\Software\Classes\Filter
   MainConcept MPEG Demultiplexer
     HKCR\CLSID\{136DCBF5-3874-4B70-AE3E-15997D6334F7}
     MPEG-1/2 Demultiplexer
     MainConcept GmbH
     8.0.0.45479
     c:\program files (x86)\common files\magix shared\mpeg2 decoder\mc_demux_mp2_ds.ax
     6/2/2009 1:08 PM
   MainConcept AMR Decoder
     HKCR\CLSID\{17CAD714-24C4-474E-97D4-4C5A50046791}
     File not found: C:\Program Files (x86)\Common Files\MAGIX Shared\MCMP4V7\mcamrd.ax
     
   LAME MPEG Layer III Audio Encoder
     HKCR\CLSID\{B8D27088-DF5F-4B7C-98DC-0E91A1696286}
     c:\windows\syswow64\lame_dshow.ax
     8/8/2001 3:19 AM

HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance
   ffdshow Video Decoder
     HKCR\CLSID\{04FE9017-F873-410E-871E-AB91661A4EF7}
     DirectShow and VFW video and audio decoding/encoding/processing filter
     1.2.4436.0
     c:\windows\system32\ffdshow.ax
     4/22/2012 1:14 PM
   ffdshow DXVA Video Decoder
     HKCR\CLSID\{0B0EFF97-C750-462C-9488-B10E7D87F1A6}
     DirectShow and VFW video and audio decoding/encoding/processing filter
     1.2.4436.0
     c:\windows\system32\ffdshow.ax
     4/22/2012 1:14 PM
   ffdshow raw video filter
     HKCR\CLSID\{0B390488-D80F-4A68-8408-48DC199F0E97}
     DirectShow and VFW video and audio decoding/encoding/processing filter
     1.2.4436.0
     c:\windows\system32\ffdshow.ax
     4/22/2012 1:14 PM
   ffdshow Audio Decoder
     HKCR\CLSID\{0F40E1E5-4F79-4988-B1A9-CC98794E6B55}
     DirectShow and VFW video and audio decoding/encoding/processing filter
     1.2.4436.0
     c:\windows\system32\ffdshow.ax
     4/22/2012 1:14 PM
   LAV Splitter
     HKCR\CLSID\{171252A0-8820-4AFE-9DF8-5C92B2D66B04}
     LAV Splitter - DirectShow Media Splitter
     1f0.de - Hendrik Leppkes
     0.50.1.0
     c:\windows\system32\lavsplitter.ax
     3/29/2012 7:23 AM
   MPC Flv Splitter
     HKCR\CLSID\{47E792CF-0BBE-4F7A-859C-194B0768650A}
     FLV Splitter
     MPC-HC Team
     1.6.0.4014
     c:\windows\system32\flvsplitter.ax
     1/30/2012 2:30 PM
   Haali Media Splitter
     HKCR\CLSID\{55DA30FC-F16B-49FC-BAA5-AE59FC65F82D}
     Haali Media Splitter
     1.11.287.23
     c:\windows\system32\splitter.x64.ax
     9/8/2011 7:59 AM
   Haali Media Splitter (AR)
     HKCR\CLSID\{564FD788-86C9-4444-971E-CC4A243DA150}
     Haali Media Splitter
     1.11.287.23
     c:\windows\system32\splitter.x64.ax
     9/8/2011 7:59 AM
   Haali Video Renderer
     HKCR\CLSID\{760A8F35-97E7-479D-AAF5-DA9EFF95D751}
     c:\windows\system32\dxr.x64.dll
     9/8/2011 7:59 AM
   Haali Simple Media Splitter
     HKCR\CLSID\{8F43B7D9-9D6B-4F48-BE18-4D787C795EEA}
     Haali Media Splitter
     1.11.287.23
     c:\windows\system32\splitter.x64.ax
     9/8/2011 7:59 AM
   DirectVobSub
     HKCR\CLSID\{93A22E7A-5091-45EF-BA61-6DA26156A5D0}
     VobSub & TextSub filter for DirectShow/VirtualDub/Avisynth
     MPC-HC Team
     1.6.1.4074
     c:\windows\system32\vsfilter.dll
     2/15/2012 4:09 AM
   DirectVobSub (auto-loading version)
     HKCR\CLSID\{9852A670-F845-491B-9BE6-EBD841B8A613}
     VobSub & TextSub filter for DirectShow/VirtualDub/Avisynth
     MPC-HC Team
     1.6.1.4074
     c:\windows\system32\vsfilter.dll
     2/15/2012 4:09 AM
   Haali Matroska Muxer
     HKCR\CLSID\{A28F324B-DDC5-4999-AA25-D3A7E25EF7A8}
     Haali Media Splitter
     1.11.287.23
     c:\windows\system32\splitter.x64.ax
     9/8/2011 7:59 AM
   AC3Filter
     HKCR\CLSID\{A753A1EC-973E-4718-AF8E-A3F554D45C44}
     ac3filter
     1.3.1.0
     c:\windows\system32\ac3filter64.ax
     8/11/2009 11:22 AM
   ffdshow Audio Processor
     HKCR\CLSID\{B86F6BEE-E7C0-4D03-8D52-5B4430CF6C88}
     DirectShow and VFW video and audio decoding/encoding/processing filter
     1.2.4436.0
     c:\windows\system32\ffdshow.ax
     4/22/2012 1:14 PM
   LAV Splitter Source
     HKCR\CLSID\{B98D13E7-55DB-4385-A33D-09FD1BA26338}
     LAV Splitter - DirectShow Media Splitter
     1f0.de - Hendrik Leppkes
     0.50.1.0
     c:\windows\system32\lavsplitter.ax
     3/29/2012 7:23 AM
   MPC Flv Source
     HKCR\CLSID\{C9ECE7B3-1D8E-41F5-9F24-B255DF16C087}
     FLV Splitter
     MPC-HC Team
     1.6.0.4014
     c:\windows\system32\flvsplitter.ax
     1/30/2012 2:30 PM
   MPC - CDXA Reader
     HKCR\CLSID\{D367878E-F3B8-4235-A968-F378EF1B9A44}
     CDXA Reader Filter
     MPC-HC Team
     1.6.0.4014
     c:\windows\system32\cdxareader.ax
     1/30/2012 2:30 PM
   ffdshow subtitles filter
     HKCR\CLSID\{DBF9000E-F08C-4858-B769-C914A0FBB1D7}
     DirectShow and VFW video and audio decoding/encoding/processing filter
     1.2.4436.0
     c:\windows\system32\ffdshow.ax
     4/22/2012 1:14 PM
   LAV Audio Decoder
     HKCR\CLSID\{E8E73B6B-4CB3-44A4-BE99-4F7BCB96E491}
     LAV Audio Decoder - DirectShow Audio Decoder
     1f0.de - Hendrik Leppkes
     0.50.1.0
     c:\windows\system32\lavaudio.ax
     3/29/2012 7:23 AM
   LAV Video Decoder
     HKCR\CLSID\{EE30215D-164F-4A92-A4EB-9D4C13390F9F}
     LAV Video Decoder - DirectShow Video Decoder
     1f0.de - Hendrik Leppkes
     0.50.1.0
     c:\windows\system32\lavvideo.ax
     3/29/2012 7:23 AM
   Haali Video Sink
     HKCR\CLSID\{F13D3732-96BD-4108-AFEB-E85F68FF64DC}
     Haali Media Splitter
     1.11.287.23
     c:\windows\system32\splitter.x64.ax
     9/8/2011 7:59 AM

HKLM\Software\Wow6432Node\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance
   CyberLink Audio Decoder (HP)
     HKCR\CLSID\{01E52E20-FB77-4F3D-B74A-3D7990C2A34E}
     CyberLink Audio Decoder Filter
     CyberLink Corp.
     8.4.0.3223
     c:\program files (x86)\hewlett-packard\media\dvd\kernel\movie\claud.ax
     8/23/2010 1:41 AM
   ffdshow Video Decoder
     HKCR\CLSID\{04FE9017-F873-410E-871E-AB91661A4EF7}
     DirectShow and VFW video and audio decoding/encoding/processing filter
     1.0.7.3135
     c:\program files (x86)\essentials codec pack\ffdshow\ffdshow.ax
     12/8/2009 11:50 AM
   MSDVD Audio Wizard (HP)
     HKCR\CLSID\{06AA3FCB-BC9A-4694-BC20-7533E1207312}
     CyberLink Audio Wizard Filter
     CyberLink Corp.
     1.0.0.4414
     c:\program files (x86)\hewlett-packard\media\dvd\kernel\movie\claudwizard.ax
     8/14/2009 7:26 AM
   AMR Audio Decoder Filter
     HKCR\CLSID\{095732B9-F36C-41CD-B49F-D2F8FFD0B547}
     AMRv1 DirectShow Filters
     1.0.2.1
     c:\windows\syswow64\amrdsf.dll
     4/24/2005 3:19 AM
   CyberLink MPEG Video Encoder
     HKCR\CLSID\{09C8D515-5C6A-434D-AD92-FEF7EB153310}
     CyberLink MPEG Video Encoder                               
     CyberLink Corp.                                            
     6.0.1.2226
     c:\program files (x86)\cyberlink\power2go\p2gvidenc.ax
     10/26/2005 5:41 AM
   CineForm VideoChange
     HKCR\CLSID\{09FA6191-EB28-4368-9701-A264F9487BDB}
     3.1.0.56
     c:\program files (x86)\gopro\tools\cfvideochange.ax
     1/28/2014 8:30 PM
   ffdshow DXVA Video Decoder
     HKCR\CLSID\{0B0EFF97-C750-462C-9488-B10E7D87F1A6}
     DirectShow and VFW video and audio decoding/encoding/processing filter
     1.2.4436.0
     c:\windows\syswow64\ffdshow.ax
     4/22/2012 1:14 PM
   ffdshow raw video filter
     HKCR\CLSID\{0B390488-D80F-4A68-8408-48DC199F0E97}
     DirectShow and VFW video and audio decoding/encoding/processing filter
     1.0.7.3135
     c:\program files (x86)\essentials codec pack\ffdshow\ffdshow.ax
     12/8/2009 11:50 AM
   FunBox Sample Grabber Filter
     HKCR\CLSID\{0B61F676-DAA6-4124-BA43-D681B0AF793D}
     FunBox SampleGrabber Filter
     1.0.0.3
     c:\windows\syswow64\funsamplegrabberfilter.ax
     8/7/2006 2:40 AM
   CineForm TempoChange
     HKCR\CLSID\{0BD8F1CE-5F36-4A2B-B8E6-B3466F8EF8C2}
     1.1.5.4
     c:\program files (x86)\gopro\tools\cftempochange.ax
     1/28/2014 8:29 PM
   FunBox Ogg Decoder Filter
     HKCR\CLSID\{0BF089EC-E512-4AA0-8244-07A0A0CB6674}
     FunOggDecFilter Dynamic Link Library
     Mobile Leader
     1.0.0.1
     c:\windows\syswow64\funoggdecfilter.ax
     8/7/2006 2:42 AM
   ffdshow Audio Decoder
     HKCR\CLSID\{0F40E1E5-4F79-4988-B1A9-CC98794E6B55}
     DirectShow and VFW video and audio decoding/encoding/processing filter
     1.0.7.3135
     c:\program files (x86)\essentials codec pack\ffdshow\ffdshow.ax
     12/8/2009 11:50 AM
   CyberLink MP3/WAV Wrapper
     HKCR\CLSID\{11A947C3-BABC-466E-A678-1FFEC95EB2F8}
     CyberLink MP3 Wrapper
     CyberLink Corp.
     3.7.0.1314
     c:\program files (x86)\cyberlink\power2go\p2gmp3wrap.ax
     1/13/2008 8:30 PM
   FunBox Subtitle Filter
     HKCR\CLSID\{11FB3571-B10A-45F2-9309-2F620535E878}
     FunBox Subtitle Filter
     Mobile Leader
     1.0.0.3
     c:\windows\syswow64\funsubfilter.ax
     8/17/2006 2:11 AM
   CyberLink Line21 Decoder Filter (HP)
     HKCR\CLSID\{1236D0E1-9937-4110-8392-57B2356353DA}
     CyberLink Line21 Decoder Filter
     CyberLink Corp.
     4.0.0.10324
     c:\program files (x86)\hewlett-packard\media\dvd\kernel\movie\clline21.ax
     7/23/2009 8:21 PM
   MainConcept MPEG Demultiplexer
     HKCR\CLSID\{136DCBF5-3874-4B70-AE3E-15997D6334F7}
     MPEG-1/2 Demultiplexer
     MainConcept GmbH
     8.0.0.45479
     c:\program files (x86)\common files\magix shared\mpeg2 decoder\mc_demux_mp2_ds.ax
     6/2/2009 1:08 PM
   CyberLink AudioCD Filter
     HKCR\CLSID\{15C2BA5D-111A-4139-82A4-21A36546C8B4}
     CyberLink AudioCD Filter
     CyberLink Corp.
     5.0.0.1321
     c:\program files (x86)\cyberlink\power2go\p2gaudiocd.ax
     1/21/2008 4:35 AM
   LAV Splitter
     HKCR\CLSID\{171252A0-8820-4AFE-9DF8-5C92B2D66B04}
     LAV Splitter - DirectShow Media Splitter
     1f0.de - Hendrik Leppkes
     0.50.1.0
     c:\windows\syswow64\lavsplitter.ax
     3/29/2012 7:21 AM
   MainConcept AMR Decoder
     HKCR\CLSID\{17CAD714-24C4-474E-97D4-4C5A50046791}
     File not found: C:\Program Files (x86)\Common Files\MAGIX Shared\MCMP4V7\mcamrd.ax
     
   MainConcept AAC Decoder
     HKCR\CLSID\{19987CEE-DEE8-49DC-98EC-F21380AA9E68}
     File not found: C:\Program Files (x86)\Common Files\MAGIX Shared\MCMP4V7\mcdaac.ax
     
   Wafian QuickTime Mux
     HKCR\CLSID\{1B5715C6-3EBD-47BF-830A-4C91A6B5E0EE}
     1.4.0.9
     c:\program files (x86)\gopro\tools\wafian.qtmux.dll
     1/29/2014 1:00 PM
   GoPro-CineForm Encoder (Multicore)
     HKCR\CLSID\{1C4F9736-ED6B-4303-8014-FCBEBFF0A0AA}
     8.6.3.670
     c:\program files (x86)\gopro\tools\cfencoder2.ax
     1/29/2014 12:50 PM
   CyberLink Editing Service 3.0 (Source)
     HKCR\CLSID\{1FFBD0F1-80CD-4452-8AC4-8FBEED892AFD}
     CES Kernel
     CyberLink Corp.
     3.0.0.2911
     c:\program files (x86)\cyberlink\power2go\p2gedtkrn.dll
     5/3/2007 12:18 AM
   RealVideo Decoder
     HKCR\CLSID\{238D0F23-5DC9-45A6-9BE2-666160C324DD}
     RealMedia Splitter
     Gabest
     1.0.1.2
     c:\program files (x86)\essentials codec pack\realmediasplitter.ax
     9/18/2007 8:27 AM
   MainConcept Layer II Audio Decoder
     HKCR\CLSID\{2F75E451-A88C-4939-BFE5-D92D48C102F2}
     Layer II Audio Decoder
     MainConcept GmbH
     8.0.0.45479
     c:\program files (x86)\common files\magix shared\mpeg2 decoder\mc_dec_mpa_ds.ax
     6/2/2009 1:06 PM
   P2G Video Decoder
     HKCR\CLSID\{3484F78F-F8CE-4CF3-914F-10F1A76BF0D5}
     CyberLink Video/SP Filter
     CyberLink Corp.
     6.0.0.2310
     c:\program files (x86)\cyberlink\power2go\p2gvsd.ax
     11/10/2005 6:36 AM
   MPEG Video Decoder (Gabest)
     HKCR\CLSID\{39F498AF-1A09-4275-B193-673B0BA3D478}
     MPEG-1/2 Decoder Filter for DirectShow
     Gabest
     1.0.0.4
     c:\program files (x86)\essentials codec pack\mpeg2decfilter.ax
     9/18/2007 8:31 AM
   CineForm JPG2Stream Filter
     HKCR\CLSID\{3A555849-2398-4D61-9B88-CA43CC659585}
     1.2.2.5
     c:\program files (x86)\gopro\tools\jpegs2stream.dll
     1/28/2014 8:34 PM
   MPC Flv Splitter
     HKCR\CLSID\{47E792CF-0BBE-4F7A-859C-194B0768650A}
     FLV Splitter
     MPC-HC Team
     1.6.0.4014
     c:\windows\syswow64\flvsplitter.ax
     1/30/2012 2:29 PM
   CyberLink Video Regulator
     HKCR\CLSID\{4814F96F-AA42-495B-B6CD-04502698DEED}
     CLRGL
     Cyberlink
     2.0.0.3328
     c:\program files (x86)\cyberlink\power2go\p2grgl.ax
     9/28/2005 4:42 AM
   P2G Audio Decoder
     HKCR\CLSID\{49C53741-6362-47C9-90BE-CCB767141222}
     CyberLink Audio Decoder Filter
     CyberLink Corp.
     6.1.0.3601
     c:\program files (x86)\cyberlink\power2go\p2gaud.ax
     11/30/2006 11:59 PM
   FunBox MPEG Decoder Filter
     HKCR\CLSID\{4B698225-0A8F-4E94-ADE5-844291056AAE}
     FunBox Decoder Filter
     Mobile Leader
     1.0.3.2
     c:\windows\syswow64\fundecfilter.ax
     11/15/2007 8:28 PM
   FunBox Video Codec Filter2
     HKCR\CLSID\{500ED0EB-7EC4-4DD4-9F7E-AE37C5927F72}
     FunBox Video Codec Filter
     Mobile Leader
     1.0.0.6
     c:\windows\syswow64\funvideocodecfilter2.ax
     1/17/2008 2:21 AM
   CyberLink Video Effect
     HKCR\CLSID\{53CAF9E4-0048-4CF5-A624-C11083C641C6}
     CLVidFx
     CyberLink
     1.0.0.2030
     c:\program files (x86)\cyberlink\power2go\p2gvidfx.ax
     8/29/2005 10:01 PM
   Intelr Media Codecs H264 LPCM MOV Muxer
     HKCR\CLSID\{55CB3F70-42A2-4B2D-BA9C-040059B124B2}
     c:\program files (x86)\gopro\tools\h264lpcmmovmux.dll
     8/16/2013 6:20 PM
   Haali Media Splitter
     HKCR\CLSID\{55DA30FC-F16B-49FC-BAA5-AE59FC65F82D}
     Haali Media Splitter
     1.10.262.12
     c:\program files (x86)\essentials codec pack\haali\splitter.ax
     8/14/2010 2:44 AM
   Haali Media Splitter (AR)
     HKCR\CLSID\{564FD788-86C9-4444-971E-CC4A243DA150}
     Haali Media Splitter
     1.10.262.12
     c:\program files (x86)\essentials codec pack\haali\splitter.ax
     8/14/2010 2:44 AM
   Cyberlink SubTitle(HP)
     HKCR\CLSID\{568D4E93-0E06-4E57-8309-44389223115B}
     CLSubTitle.ax
     CyberLink Corp.
     1.0.1.7222
     c:\program files (x86)\hewlett-packard\media\dvd\kernel\movie\clsubtitle.ax
     12/22/2009 7:08 AM
   FunBox Avi Source
     HKCR\CLSID\{56FDBC25-391D-4238-AEBA-80759FBB248A}
     Avi Splitter
     Gabest
     1.0.0.7
     c:\windows\syswow64\funavisplitter2.ax
     1/15/2008 8:26 PM
   MainConcept (Consumer) AVC/H.264 Video Decoder
     HKCR\CLSID\{5A157B06-E2F2-4109-994D-49398207FF22}
     File not found: C:\Program Files (x86)\Common Files\MAGIX Shared\MCMP4V7\mcstdavcvd.ax
     
   FunBox Video Codec Filter
     HKCR\CLSID\{5A1D5854-88A6-489C-917E-181A7766222D}
     FunBox Video Codec Filter
     Mobile Leader
     1.0.0.3
     c:\windows\syswow64\funvideocodecfilter.ax
     8/7/2006 2:43 AM
   EVRC Audio Decoder Filter
     HKCR\CLSID\{5B9DA495-5DE7-47E4-B78F-5C91E391F795}
     AMRv1 DirectShow Filters
     1.0.2.1
     c:\windows\syswow64\amrdsf.dll
     4/24/2005 3:19 AM
   CyberLink Audio Noise Reduction
     HKCR\CLSID\{5E479EF1-9BDB-42AA-B273-6004D83C9212}
     CLAuNR
     CyberLink Corp.
     2.0.0.1017
     c:\program files (x86)\cyberlink\power2go\p2gaunrwrapper.ax
     10/16/2005 8:34 PM
   CyberLink Load Image Filter
     HKCR\CLSID\{61665621-5523-11D4-A717-80E5A24FE52B}
     CLImage
     CyberLink
     3.0.0.2307
     c:\program files (x86)\cyberlink\shared files\climage.ax
     11/6/2006 10:16 PM
   CyberLink MPEG-2 Splitter
     HKCR\CLSID\{6263C176-0876-4B04-8DE0-44AB74489D72}
     CyberLink MPEG Splitter
     CyberLink Corp.
     2.4.0.2301
     c:\program files (x86)\cyberlink\power2go\p2gm2spliter.ax
     12/3/2007 9:10 PM
   CyberLink Audio VolumeBooster
     HKCR\CLSID\{66855507-19B6-45B0-A83A-78178247CADC}
     CyberLink Audio Volume Booster Filter
     CyberLink Corp.
     1.0.0.1008
     c:\program files (x86)\cyberlink\power2go\p2gvb.ax
     10/8/2004 2:36 AM
   FunBox Avi Splitter
     HKCR\CLSID\{6A2BF08C-64B8-4709-9787-E0B78E705D7A}
     Avi Splitter
     Gabest
     1.0.0.7
     c:\windows\syswow64\funavisplitter2.ax
     1/15/2008 8:26 PM
   Cyberlink Dump Dispatch Filter
     HKCR\CLSID\{6E0EED5F-4B78-455F-B688-073E3E5D1079}
     Cyberlink File Dump Dispatch Filter
     CyberLink Corp.
     1.2.1.2412
     c:\program files (x86)\cyberlink\power2go\p2gdumpdispatch.ax
     12/12/2003 1:01 AM
   Wafian QuickTime DeMux
     HKCR\CLSID\{6F5BAD7B-9AE3-4937-B0B2-4CD4672523F7}
     1.4.0.9
     c:\program files (x86)\gopro\tools\wafian.qtdemux.dll
     8/16/2013 6:02 PM
   Intelr Media SDK H.264 Encoder
     HKCR\CLSID\{71183C45-F4FA-4B10-9E04-F9040CB19139}
     Intelr Media SDK H.264 Encoder
     Intel Corporation
     3.12.8.4
     c:\program files (x86)\gopro\tools\h264_enc_filter.dll
     8/16/2013 6:21 PM
   CyberLink Audio Effect (HP)
     HKCR\CLSID\{7209C68A-7D23-485A-93AA-B2BD03442275}
     CyberLink Audio Effect Filter
     CyberLink Corporation
     6.0.0.7209
     c:\program files (x86)\hewlett-packard\media\dvd\kernel\movie\claudfx.ax
     12/8/2009 8:51 PM
   CyberLink Audio Resampler
     HKCR\CLSID\{74DA3201-9816-42E9-88F6-8E0B72E639E0}
     CLAuRsmpl.ax
     CyberLink Corp.
     1.0.0.2625
     c:\program files (x86)\cyberlink\power2go\p2gaursmpl.ax
     2/24/2005 8:41 PM
   Haali Video Renderer
     HKCR\CLSID\{760A8F35-97E7-479D-AAF5-DA9EFF95D751}
     c:\program files (x86)\essentials codec pack\haali\dxr.dll
     8/14/2010 2:45 AM
   RealMedia Source
     HKCR\CLSID\{765035B3-5944-4A94-806B-20EE3415F26F}
     RealMedia Splitter
     Gabest
     1.0.1.2
     c:\program files (x86)\essentials codec pack\realmediasplitter.ax
     9/18/2007 8:27 AM
   CyberLink MPEG-1 Splitter
     HKCR\CLSID\{7D9070AB-371A-4614-A964-D21BDFE1030B}
     CyberLink MPEG Splitter
     CyberLink Corp.
     2.4.0.2301
     c:\program files (x86)\cyberlink\power2go\p2gm1spliter.ax
     12/3/2007 9:11 PM
   FunBox Mpg Grab Filter
     HKCR\CLSID\{80B7C1D1-08C0-4B4B-8339-C1E4554D1929}
     FunMpgGrabFilter Dynamic Link Library
     Mobile Leader
     1.0.0.1
     c:\windows\syswow64\funmpggrabfilter.ax
     3/2/2006 10:37 PM
   CyberLink Tzan Filter (HP)
     HKCR\CLSID\{80BCECD7-BB20-41E7-A213-FBECC7C36015}
     Cyberlink Tzan Filter
     CyberLink Corp.
     3.5.0.2913
     c:\program files (x86)\hewlett-packard\media\dvd\kernel\movie\cltzan.ax
     5/13/2010 5:01 AM
   FunBox Image Decoder Filter
     HKCR\CLSID\{816C69E9-E106-47B9-ACAB-156874F27DA3}
     FunImgFilter Dynamic Link Library
     Mobile Leader
     1.0.0.3
     c:\windows\syswow64\funimgfilter.ax
     9/20/2006 11:54 PM
   Mpeg-4 NV Decoder
     HKCR\CLSID\{823FFD55-CC4F-442A-A432-6D4B36CD64F0}
     MPEG-4 DirectShow Filters
     1.0.2.1
     c:\windows\syswow64\mpeg4dsf.dll
     6/5/2005 9:12 AM
   FunBox Mp3 Decoder Filter
     HKCR\CLSID\{885405B9-8A84-4734-B7E2-00F430DC1E91}
     FunMpgDecFilter Dynamic Link Library
     Mobile Leader
     1.0.0.1
     c:\windows\syswow64\funmp3decfilter.ax
     8/2/2006 8:31 PM
   FunBox Audio Codec Filter2
     HKCR\CLSID\{88E2D3D0-939A-44A7-BA3F-37EFFBF818A5}
     FunBox Audio Codec Filter
     Mobile Leader
     1.0.0.2
     c:\windows\syswow64\funaudiocodecfilter2.ax
     12/13/2007 9:13 PM
   FunBox Video Resize Filter
     HKCR\CLSID\{8A241582-BBDF-4D09-8D3E-2CE6ADDEDD7D}
     FunBox Video Resize Filter
     Mobile Leader
     1.0.0.4
     c:\windows\syswow64\funvideoresizefilter.ax
     8/7/2006 2:43 AM
   Cyberlink File Reader (Async.)
     HKCR\CLSID\{8C56B364-6CD9-4907-B5C1-30A4B03D35B8}
     Cyberlink MPEG File Reader
     CyberLink Corp.
     3.0.0.3016
     c:\program files (x86)\cyberlink\power2go\p2greader.ax
     6/15/2003 9:35 PM
   CyberLink M2V Writer
     HKCR\CLSID\{8D508C0D-E1C3-4C85-A7B6-7B5CD4392105}
     CLM2VWriter
     CyberLink
     1.3.0.2017
     c:\program files (x86)\cyberlink\power2go\p2gm2vwriter.ax
     8/17/2005 8:45 AM
   Intelr Media SDK AAC Decoder
     HKCR\CLSID\{8DA364BE-DF1D-43F9-9A86-CC06F53C082C}
     Intelr Media SDK AAC Decoder
     Intel Corporation
     3.12.7.27
     c:\program files (x86)\gopro\tools\imc_aac_dec_ds.dll
     7/27/2012 1:11 PM
   Haali Simple Media Splitter
     HKCR\CLSID\{8F43B7D9-9D6B-4F48-BE18-4D787C795EEA}
     Haali Media Splitter
     1.10.262.12
     c:\program files (x86)\essentials codec pack\haali\splitter.ax
     8/14/2010 2:44 AM
   DirectVobSub
     HKCR\CLSID\{93A22E7A-5091-45EF-BA61-6DA26156A5D0}
     VobSub & TextSub filter for DirectShow/VirtualDub/Avisynth
     MPC-HC Team
     1.6.1.4074
     c:\windows\syswow64\vsfilter.dll
     2/15/2012 4:08 AM
   Cyberlink Dump Filter
     HKCR\CLSID\{93D04A3E-1510-4FBF-9AAF-F1F09C3BC71E}
     Cyberlink File Dump Filter
     CyberLink Corp.
     3.0.0.7122
     c:\program files (x86)\cyberlink\power2go\p2gdump.ax
     11/22/2006 6:15 AM
   RealAudio Decoder
     HKCR\CLSID\{941A4793-A705-4312-8DFC-C11CA05F397E}
     RealMedia Splitter
     Gabest
     1.0.1.2
     c:\program files (x86)\essentials codec pack\realmediasplitter.ax
     9/18/2007 8:27 AM
   FunBox MPEG Encoder Filter
     HKCR\CLSID\{94E4F19C-03FB-4869-BA51-EE5B844BF70D}
     FunBox Encoder Filter
     Mobile Leader
     1.0.1.9
     c:\windows\syswow64\funencfilter.ax
     8/23/2006 2:14 AM
   CyberLink Video Stabilizer
     HKCR\CLSID\{94F20D00-59CE-4FF7-BFB8-E6BF852AD4B0}
     CLVideoDeShaking
     CyberLink
     1.0.0.1017
     c:\program files (x86)\cyberlink\power2go\p2gvideostabilizer.ax
     10/17/2005 12:28 AM
   AMR Audio Encoder Filter
     HKCR\CLSID\{95B9C637-BCD2-4F51-9F60-FCA727478C62}
     AMRv1 DirectShow Filters
     1.0.2.1
     c:\windows\syswow64\amrdsf.dll
     4/24/2005 3:19 AM
   DirectVobSub (auto-loading version)
     HKCR\CLSID\{9852A670-F845-491B-9BE6-EBD841B8A613}
     VobSub & TextSub filter for DirectShow/VirtualDub/Avisynth
     MPC-HC Team
     1.6.1.4074
     c:\windows\syswow64\vsfilter.dll
     2/15/2012 4:08 AM
   CyberLink DVD Navigator (HP)
     HKCR\CLSID\{9993DDD5-F9EC-461E-B94E-B4859FB505E1}
     CyberLink DVD Navigation Filter
     CyberLink Corp.
     8.0.0.4023
     c:\program files (x86)\hewlett-packard\media\dvd\kernel\movie\clnavx.ax
     4/23/2010 3:05 AM
   Mpeg-4 Demultiplexor
     HKCR\CLSID\{99EC0C72-4D1B-411B-AB1F-D561EE049D94}
     MPEG-4 DirectShow Filters
     1.0.2.1
     c:\windows\syswow64\mpeg4dsf.dll
     6/5/2005 9:12 AM
   Mpeg-4 Bitstream Writer
     HKCR\CLSID\{9A6D2136-5630-481F-99D3-BC61FC2B55F6}
     MPEG-4 DirectShow Filters
     1.0.2.1
     c:\windows\syswow64\mpeg4dsf.dll
     6/5/2005 9:12 AM
   Mpeg-4 Multiplexor
     HKCR\CLSID\{9A8F5414-A5DC-4597-9CB4-0D0D998518D1}
     MPEG-4 DirectShow Filters
     1.0.2.1
     c:\windows\syswow64\mpeg4dsf.dll
     6/5/2005 9:12 AM
   CyberLink PCM Wrapper
     HKCR\CLSID\{9B16BA00-C8B5-48F6-BF4A-DE3E5E587BF0}
     CyberLink PCM Wrapper
     CyberLink Corp.
     1.1.0.321
     c:\program files (x86)\cyberlink\power2go\p2gpcmenc.ax
     3/20/2002 11:54 PM
   CineForm Stereo Fixer
     HKCR\CLSID\{9C3913B7-EB91-427D-8404-D0EE84484250}
     1.1.4.21
     c:\program files (x86)\gopro\tools\cfstereofixer.ax
     1/29/2014 1:03 PM
   Mpeg-4 NA Decoder
     HKCR\CLSID\{9FFC2AC2-D87D-431E-A916-66EAA5787182}
     MPEG-4 DirectShow Filters
     1.0.2.1
     c:\windows\syswow64\mpeg4dsf.dll
     6/5/2005 9:12 AM
   Haali Matroska Muxer
     HKCR\CLSID\{A28F324B-DDC5-4999-AA25-D3A7E25EF7A8}
     Haali Media Splitter
     1.10.262.12
     c:\program files (x86)\essentials codec pack\haali\splitter.ax
     8/14/2010 2:44 AM
   Intelr Media Codecs MP4 Splitter
     HKCR\CLSID\{A2A6B846-D118-4300-AE07-F31860887BC2}
     Intelr Media Codecs MPEG-4 Splitter
     Intel Corporation
     1.13.8.16
     c:\program files (x86)\gopro\tools\imc_mp4_spl_ds.dll
     8/16/2013 6:19 PM
   AC3Filter
     HKCR\CLSID\{A753A1EC-973E-4718-AF8E-A3F554D45C44}
     ac3filter
     1.3.1.0
     c:\windows\syswow64\ac3filter.ax
     8/11/2009 11:19 AM
   DC-Bass Source
     HKCR\CLSID\{ABE7B1D9-4B3E-4ACD-A0D1-92611D3A4492}
     DirectShowT Audio Decoder
     http://www.dsp-worx.de
     1.3.0.0
     c:\windows\syswow64\dcbasssource.ax
     6/19/1992 4:22 PM
   GoPro-CineForm Decoder-2
     HKCR\CLSID\{AD83011E-01D1-4623-91FD-6B75F183C5A9}
     CineForm DirectShow Decoder
     CineForm Inc.
     8.6.3.670
     c:\program files (x86)\gopro\tools\cfdecode2.ax
     1/28/2014 8:01 PM
   ffdshow Audio Processor
     HKCR\CLSID\{B86F6BEE-E7C0-4D03-8D52-5B4430CF6C88}
     DirectShow and VFW video and audio decoding/encoding/processing filter
     1.0.7.3135
     c:\program files (x86)\essentials codec pack\ffdshow\ffdshow.ax
     12/8/2009 11:50 AM
   LAME MPEG Layer III Audio Encoder
     HKCR\CLSID\{B8D27088-DF5F-4B7C-98DC-0E91A1696286}
     c:\windows\syswow64\lame_dshow.ax
     8/8/2001 3:19 AM
   LAV Splitter Source
     HKCR\CLSID\{B98D13E7-55DB-4385-A33D-09FD1BA26338}
     LAV Splitter - DirectShow Media Splitter
     1f0.de - Hendrik Leppkes
     0.50.1.0
     c:\windows\syswow64\lavsplitter.ax
     3/29/2012 7:21 AM
   MainConcept MPEG-2 Video Decoder
     HKCR\CLSID\{BC4EB321-771F-4E9F-AF67-37C631ECA106}
     MPEG-2 Video Decoder
     MainConcept GmbH
     8.0.0.45479
     c:\program files (x86)\common files\magix shared\mpeg2 decoder\mc_dec_mp2v_ds.ax
     6/2/2009 1:07 PM
   FunBox Conversion Filter
     HKCR\CLSID\{C246C9F2-0B6B-48AC-80FB-A921E3C43A60}
     FunBox Conversion Filter
     Mobile Leader
     1.0.0.1
     c:\windows\syswow64\funconvfilter.ax
     8/2/2006 8:28 PM
   MPC Flv Source
     HKCR\CLSID\{C9ECE7B3-1D8E-41F5-9F24-B255DF16C087}
     FLV Splitter
     MPC-HC Team
     1.6.0.4014
     c:\windows\syswow64\flvsplitter.ax
     1/30/2012 2:29 PM
   Intelr Media Codecs MP4 Muxer
     HKCR\CLSID\{CB488050-23B8-411D-B861-D00BA44B8D02}
     Intelr Media Codecs MP4 Muxer
     Intel Corporation
     1.13.8.16
     c:\program files (x86)\gopro\tools\imc_mp4_mux_ds.dll
     8/16/2013 6:19 PM
   InterObject I/E Melody source filter
     HKCR\CLSID\{CBDD2FC6-9079-42E9-89D2-E707023F08E4}
     I/E Melody DirectShow source filter
     InterObject Ltd.
     1.7.196.1
     c:\windows\syswow64\melodysource.ax
     7/16/2003 7:25 AM
   CyberLink TimeStretch Filter (CES)
     HKCR\CLSID\{CC29DF71-ECDE-4C60-BCD7-7503557AAB54}
     CLAuTS.ax
     CyberLink Corp.
     1.0.0.2212
     c:\program files (x86)\cyberlink\power2go\p2gauts.ax
     10/12/2004 8:32 AM
   Intelr Media SDK H.264 Decoder
     HKCR\CLSID\{CCCE52FD-02CB-482C-AC81-1E55EF1D61EE}
     Intelr Media SDK H.264 Decoder
     Intel Corporation
     3.12.8.4
     c:\program files (x86)\gopro\tools\h264_dec_filter.dll
     8/16/2013 6:21 PM
   FunBox Audio Codec Filter
     HKCR\CLSID\{CDA07D44-0191-428A-B19A-0AD7737B529F}
     FunBox Audio Codec Filter
     Mobile Leader
     1.0.0.1
     c:\windows\syswow64\funaudiocodecfilter.ax
     8/2/2006 8:27 PM
   CyberLink TL MPEG Splitter
     HKCR\CLSID\{CDCFDBB0-6518-4239-8085-A16AD63488AE}
     CyberLink MPEG Splitter
     CyberLink Corp.
     3.2.0.2219
     c:\program files (x86)\cyberlink\power2go\p2gtlmsplter.ax
     10/18/2006 11:33 PM
   CyberLink MPEG Muxer
     HKCR\CLSID\{CF6ED441-FC79-4F1A-9D91-4AE01C570B81}
     MpgMux
     CyberLink
     5.1.0.1723
     c:\program files (x86)\cyberlink\power2go\p2gmpgmux.ax
     5/23/2008 1:27 AM
   CyberLink Video/SP Decoder (HP)
     HKCR\CLSID\{D0478853-ADAF-435E-8D04-E985A1A268D5}
     CyberLink Video/SP Filter
     CyberLink Corp.
     8.4.0.1724
     c:\program files (x86)\hewlett-packard\media\dvd\kernel\movie\clvsd.ax
     5/23/2010 9:31 PM
   CineForm SampleRate
     HKCR\CLSID\{D2C12C78-9398-4ECA-9F88-2FE4D8C7A539}
     1.2.0.21
     c:\program files (x86)\gopro\tools\cfsamplerate.ax
     1/28/2014 8:32 PM
   MPC - CDXA Reader
     HKCR\CLSID\{D367878E-F3B8-4235-A968-F378EF1B9A44}
     CDXA Reader Filter
     MPC-HC Team
     1.6.0.4014
     c:\windows\syswow64\cdxareader.ax
     1/30/2012 2:29 PM
   CineForm Stereo Mux Filter
     HKCR\CLSID\{D8F506E3-899D-4E83-BA28-3139D6C71CE8}
     1.2.2.5
     c:\program files (x86)\gopro\tools\cfstereomux.ax
     1/29/2014 1:03 PM
   ffdshow subtitles filter
     HKCR\CLSID\{DBF9000E-F08C-4858-B769-C914A0FBB1D7}
     DirectShow and VFW video and audio decoding/encoding/processing filter
     1.0.7.3135
     c:\program files (x86)\essentials codec pack\ffdshow\ffdshow.ax
     12/8/2009 11:50 AM
   FunBox Mpg Decoder Filter
     HKCR\CLSID\{DC2867D7-EEA7-4A0F-A495-8EBE2E0C3417}
     FunMpgDecFilter Dynamic Link Library
     Mobile Leader
     1.0.0.2
     c:\windows\syswow64\funmpgdecfilter.ax
     6/6/2006 8:45 PM
   MainConcept Stream Parser
     HKCR\CLSID\{DEE56715-7081-4D57-91A7-984AE2712268}
     MPEG-1/2 Demultiplexer
     MainConcept GmbH
     8.0.0.45479
     c:\program files (x86)\common files\magix shared\mpeg2 decoder\mc_demux_mp2_ds.ax
     6/2/2009 1:08 PM
   RealMedia Splitter
     HKCR\CLSID\{E21BE468-5C18-43EB-B0CC-DB93A847D769}
     RealMedia Splitter
     Gabest
     1.0.1.2
     c:\program files (x86)\essentials codec pack\realmediasplitter.ax
     9/18/2007 8:27 AM
   Intelr Media Codecs AAC Encoder
     HKCR\CLSID\{E51EF49D-DDB0-4874-A873-C5100171146F}
     Intelr Media Codecs AAC Encoder
     Intel Corporation
     1.13.8.16
     c:\program files (x86)\gopro\tools\imc_aac_enc_ds.dll
     8/16/2013 6:19 PM
   P2G Video Regulator
     HKCR\CLSID\{E5B455E5-098A-4B65-B2A8-871274FF51CE}
     CyberLink Video Regulator
     CyberLink
     2.5.0.1818
     c:\program files (x86)\cyberlink\power2go\p2gresample.ax
     6/17/2002 9:32 PM
   LAV Audio Decoder
     HKCR\CLSID\{E8E73B6B-4CB3-44A4-BE99-4F7BCB96E491}
     LAV Audio Decoder - DirectShow Audio Decoder
     1f0.de - Hendrik Leppkes
     0.50.1.0
     c:\windows\syswow64\lavaudio.ax
     3/29/2012 7:21 AM
   P2G Audio Encoder
     HKCR\CLSID\{E8F36981-7D45-4AF4-ACA2-E7D960D5AD6F}
     CyberLink Audio Encoder Filter
     Cyberlink Corp.
     2.0.0.4815
     c:\program files (x86)\cyberlink\power2go\p2gaudenc.ax
     12/20/2006 3:20 AM
   LAV Video Decoder
     HKCR\CLSID\{EE30215D-164F-4A92-A4EB-9D4C13390F9F}
     LAV Video Decoder - DirectShow Video Decoder
     1f0.de - Hendrik Leppkes
     0.50.1.0
     c:\windows\syswow64\lavvideo.ax
     3/29/2012 7:21 AM
   Haali Video Sink
     HKCR\CLSID\{F13D3732-96BD-4108-AFEB-E85F68FF64DC}
     Haali Media Splitter
     1.10.262.12
     c:\program files (x86)\essentials codec pack\haali\splitter.ax
     8/14/2010 2:44 AM
   FunBox Video Adjust Filter
     HKCR\CLSID\{F65ACF5A-A9C7-45BA-9BB8-01CF948BADA7}
     FunBox Video Adjust Filter
     Mobile Leader
     1.0.0.8
     c:\windows\syswow64\funvideoadjustfilter.ax
     8/7/2006 2:42 AM
   FunBox Audio EQ Filter
     HKCR\CLSID\{FA1EFAEA-8EF2-4705-8114-F14FAA5EAC24}
     FunBox Audio Equalizer Filter
     Mobile Leader
     1.0.0.7
     c:\windows\syswow64\funeqfilter.ax
     8/17/2006 2:12 AM
   MainConcept MPEG-4 Video Decoder
     HKCR\CLSID\{FC86AD6C-894A-44E9-A283-4B5A9DD6CA65}
     File not found: C:\Program Files (x86)\Common Files\MAGIX Shared\MCMP4V7\mcm4vd.ax
     
   CyberLink MPEG Decoder
     HKCR\CLSID\{FF1715E9-885B-47A8-8F76-16C44539309B}
     CyberLink Video/SP Filter
     CyberLink Corp.
     5.0.0.929
     c:\program files (x86)\cyberlink\power2go\p2gmvd.ax
     9/29/2003 7:50 AM

C:\Users\Sheyenne Alvarez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
   Amazon Cloud Drive.appref-ms
     C:\Users\Sheyenne Alvarez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Amazon Cloud Drive.appref-ms
     c:\users\sheyenne alvarez\appdata\roaming\microsoft\windows\start menu\programs\startup\amazon cloud drive.appref-ms
     12/4/2014 1:14 PM
   Dropbox.lnk
     C:\Users\Sheyenne Alvarez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
     Dropbox
     Dropbox, Inc.
     2.10.52.0
     c:\users\sheyenne alvarez\appdata\roaming\dropbox\bin\dropbox.exe
     10/20/2014 10:57 PM
   Z Cinema.lnk
     C:\Users\Sheyenne Alvarez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Z Cinema.lnk
     InstallShield
     Macrovision Corporation
     12.0.0.58849
     c:\users\sheyenne alvarez\appdata\roaming\microsoft\installer\{6e166235-49f3-4dfa-a102-1e86675abd11}\startupshortcut_6e16623549f34dfaa1021e86675abd11.exe
     1/20/2007 12:15 AM

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
   SpybotSD TeaTimer
     C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
     System settings protector
     Safer-Networking Ltd.
     1.6.6.32
     c:\program files (x86)\spybot - search & destroy\teatimer.exe
     6/19/1992 4:22 PM
   MotoCast
     "C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk"
     c:\program files (x86)\motorola mobility\motocast\motolauncher.lnk
     8/19/2013 7:07 PM
   DKab1err
     "C:\Program Files (x86)\Dell\ErrorApp\DKab1err.exe"
     2.4.4.0
     c:\program files (x86)\dell\errorapp\dkab1err.exe
     8/7/2012 6:38 AM
   DKADGmon
     "C:\Program Files (x86)\Dell V520 Series\DKADGmon.exe"
     Printer Device Monitor
     0.1.25.0
     c:\program files (x86)\dell v520 series\dkadgmon.exe
     9/7/2012 1:39 AM
   Google+ Auto Backup
     "C:\Users\Sheyenne Alvarez\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe" /autostart
     File not found: C:\Users\Sheyenne Alvarez\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe
     
   Fitbit Connect
     "C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe" /autorun
     Fitbit Connect Desktop Client
     Fitbit, Inc.
     1.0.3.5511
     c:\program files (x86)\fitbit connect\fitbit connect.exe
     5/19/2014 6:04 AM
   Amazon Music
     "C:\Users\Sheyenne Alvarez\AppData\Local\Amazon Music\Amazon Music Helper.exe"
     c:\users\sheyenne alvarez\appdata\local\amazon music\amazon music helper.exe
     10/14/2014 11:21 PM

HKCU\Software\Classes\*\ShellEx\ContextMenuHandlers
   DropboxExt
     HKCR\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}
     Dropbox Shell Extension
     Dropbox, Inc.
     1.0.0.24
     c:\users\sheyenne alvarez\appdata\roaming\dropbox\bin\dropboxext64.24.dll
     6/23/2014 6:32 PM

HKCU\Software\Classes\Directory\ShellEx\ContextMenuHandlers
   DropboxExt
     HKCR\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}
     Dropbox Shell Extension
     Dropbox, Inc.
     1.0.0.24
     c:\users\sheyenne alvarez\appdata\roaming\dropbox\bin\dropboxext64.24.dll
     6/23/2014 6:32 PM

HKCU\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers
   DropboxExt
     HKCR\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}
     Dropbox Shell Extension
     Dropbox, Inc.
     1.0.0.24
     c:\users\sheyenne alvarez\appdata\roaming\dropbox\bin\dropboxext64.24.dll
     6/23/2014 6:32 PM

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Dario Jr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Dario Jr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Gabriella\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Gabriella\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Roman\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Roman\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Sheyenne Alvarez\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Sheyenne Alvarez\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\Dario Jr\AppData\Local\Mozilla\Firefox\Profiles\jxnoht0o.default\Cache emptied successfully
C:\Users\Gabriella\AppData\Local\Mozilla\Firefox\Profiles\fdnb7ntl.default\Cache emptied successfully
C:\Users\Roman\AppData\Local\Mozilla\Firefox\Profiles\ivj6ttxk.default\Cache emptied successfully
C:\Users\Roman\AppData\Local\Mozilla\Firefox\Profiles\ivj6ttxk.default\cache2 emptied successfully
C:\Users\Sheyenne Alvarez\AppData\Local\Mozilla\Firefox\Profiles\btxhxadl.default-1415987071767\cache2 emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Sheyenne Alvarez\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=598 folders=113 2377200097 bytes)

==== Empty Temp Folders ======================

C:\Users\Dario Jr\AppData\Local\Temp emptied successfully
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Gabriella\AppData\Local\Temp emptied successfully
C:\Users\Roman\AppData\Local\Temp emptied successfully
C:\Users\Sheyenne Alvarez\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\SHEYEN~1\AppData\Local\Temp successfully emptied

==== EOF on Thu 12/04/2014 at 15:53:42.16 ======================
 


  • 0

#18
sheyennelilly

sheyennelilly

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts

I can't go forward with the other ones.  The icons say they are just png files.  This happened with the OTL earlier, but I just went back to another post given to me and did it from there.  Will you repost the active icons please?  Thank you.


  • 0

#19
Biscuithd

Biscuithd

    Trusted Helper

  • Malware Removal
  • 2,573 posts

Let's see if you can run this... (In actuality, the icons are fine, the malware has changed the associations)

 

Reset File Associations:

Please download to your Desktop FixExec from here. <-- Download the 64-Bit Version.

Double-click on FixExec.exe >> Follow the prompts.

When completed there should a notepad file on your desktop named FixExec.txt, post that in your next reply please.

 

If it's blocked from running or the association is blocked, there are suggestions on the page, such as changing the extension to .com. Try those if needed.
 


  • 0

#20
sheyennelilly

sheyennelilly

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts

Yes, I've been having an issue shutting down and it says explorer.exe is what is stopping it.  Does that have to do with this? 

 

Here is the notepad log:

 

FixExec by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about FixExec can be found at this link:
 http://www.bleepingc...ilities/fixexec

Program started at: 12/05/2014 09:17:45 AM in x64 mode.
Windows Version: Windows 7

Checking for processes to terminate before fixing executable associations.
 * C:\Users\Sheyenne Alvarez\AppData\Local\Amazon Music\Amazon Music Helper.exe (5572) [Terminated].
 * C:\Users\Sheyenne Alvarez\AppData\Roaming\Dropbox\bin\Dropbox.exe (2388) [Terminated].
 * C:\Users\Sheyenne Alvarez\AppData\Local\Apps\2.0\C52Q8JWR.CDD\6A344DJW.HND\amaz..tion_f2fa081ea2183235_0002.0004_9f25fd1982bf3008\AmazonCloudDrive.exe (520) [Terminated].
 * C:\Users\Sheyenne Alvarez\AppData\Local\Apps\2.0\C52Q8JWR.CDD\6A344DJW.HND\amaz..tion_f2fa081ea2183235_0002.0004_9f25fd1982bf3008\LocalServiceJre\bin\AmazonCloudDriveW.exe (3872) [Terminated].

4 proccesses terminated!

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.


Program finished at: 12/05/2014 09:18:01 AM
Execution time: 0 hours(s), 0 minute(s), and 15 seconds(s)
 


  • 0

#21
Biscuithd

Biscuithd

    Trusted Helper

  • Malware Removal
  • 2,573 posts

Are you able to do the scans from post #16? I have adwCleaner in there twice. That was a mistake. The second scan should be JRT and I'll post it here.

 

So do adwCleaner, JRT (Junkware Removal Tool) and FRST.

 

JRTbythisisu.png Fix with Junkware Removal Tool
 
Please download JRT by Thisisu and save the file to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.
 
  • Right-click on JRTbythisisu.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Follow the prompts and let this process run uninterrupted.
  • This scan can take a while, depending on your System specs.
  • Upon completion, a log (JRT.txt) will open on your desktop.
  •  
    Please include the contents of that file in your reply.
     
    Do not forget to re-enable your previously switched off protection software!
    Please also manually reboot your machine after this procedure.

    • 0

    #22
    sheyennelilly

    sheyennelilly

      Member

    • Topic Starter
    • Member
    • PipPip
    • 65 posts

    Okay, I am a dummy.  I was right clicking on the icons you posted without clicking on the links to download.  Sorry about that.  Embarrassing.

     

    And then I ran AdwCleaner without running as administrator (another oversight by me).  So I'm posting the log and then right after it I'm posting the log run as administrator.  I hope I didn't mess anything up...

     

    # AdwCleaner v4.104 - Report created 05/12/2014 at 09:26:39
    # Updated 05/12/2014 by Xplode
    # Database : 2014-12-03.1 [Live]
    # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
    # Username : Sheyenne Alvarez - SHEYENNEALVAREZ
    # Running from : C:\Users\Sheyenne Alvarez\Downloads\AdwCleaner(1).exe
    # Option : Scan

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****

    Folder Found : C:\Users\Sheyenne Alvarez\Documents\DownloadManager

    ***** [ Scheduled Tasks ] *****


    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****

    Key Found : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\ask.com
    Key Found : HKCU\Software\wscontb
    Key Found : HKCU\Software\YahooPartnerToolbar
    Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
    Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EC29EDF6-AD3C-4E1C-A087-D6CB81400C43}
    Key Found : [x64] HKCU\Software\wscontb
    Key Found : [x64] HKCU\Software\YahooPartnerToolbar
    Key Found : HKLM\SOFTWARE\Classes\speedupmypc
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner
    Key Found : HKLM\SOFTWARE\Uniblue
    Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
    Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EC29EDF6-AD3C-4E1C-A087-D6CB81400C43}

    ***** [ Browsers ] *****

    -\\ Internet Explorer v11.0.9600.17420

     

    Now this is as administrator:

    # AdwCleaner v4.104 - Report created 05/12/2014 at 09:36:45
    # Updated 05/12/2014 by Xplode
    # Database : 2014-12-03.1 [Live]
    # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
    # Username : Sheyenne Alvarez - SHEYENNEALVAREZ
    # Running from : C:\Users\Sheyenne Alvarez\Desktop\AdwCleaner(1).exe
    # Option : Scan

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****

    Folder Found : C:\Users\Sheyenne Alvarez\Documents\DownloadManager

    ***** [ Scheduled Tasks ] *****


    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****

    Key Found : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\ask.com
    Key Found : HKCU\Software\wscontb
    Key Found : HKCU\Software\YahooPartnerToolbar
    Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
    Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EC29EDF6-AD3C-4E1C-A087-D6CB81400C43}
    Key Found : [x64] HKCU\Software\wscontb
    Key Found : [x64] HKCU\Software\YahooPartnerToolbar
    Key Found : HKLM\SOFTWARE\Classes\speedupmypc
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner
    Key Found : HKLM\SOFTWARE\Uniblue
    Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
    Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EC29EDF6-AD3C-4E1C-A087-D6CB81400C43}

    ***** [ Browsers ] *****

    -\\ Internet Explorer v11.0.9600.17420


     


    • 0

    #23
    sheyennelilly

    sheyennelilly

      Member

    • Topic Starter
    • Member
    • PipPip
    • 65 posts

    JRT scan results:

     

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Thisisu
    Version: 6.4.0 (11.29.2014:1)
    OS: Windows 7 Home Premium x64
    Ran by Sheyenne Alvarez on Fri 12/05/2014 at  9:48:40.18
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




    ~~~ Services



    ~~~ Registry Values



    ~~~ Registry Keys

    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskInstallChecker-1_RASAPI32
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskInstallChecker-1_RASMANCS
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\HPSF_Tasks_RASAPI32
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\HPSF_Tasks_RASMANCS
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_pivot-stickfigure-animator[1]_RASAPI32
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_pivot-stickfigure-animator[1]_RASMANCS
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskInstallChecker-1_RASAPI32
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskInstallChecker-1_RASMANCS
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\HPSF_Tasks_RASAPI32
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\HPSF_Tasks_RASMANCS
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_pivot-stickfigure-animator[1]_RASAPI32
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_pivot-stickfigure-animator[1]_RASMANCS



    ~~~ Files



    ~~~ Folders



    ~~~ FireFox

    Emptied folder: C:\Users\Sheyenne Alvarez\AppData\Roaming\mozilla\firefox\profiles\btxhxadl.default-1415987071767\minidumps [2 files]



    ~~~ Event Viewer Logs were cleared





    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on Fri 12/05/2014 at  9:52:11.52
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     


    • 0

    #24
    sheyennelilly

    sheyennelilly

      Member

    • Topic Starter
    • Member
    • PipPip
    • 65 posts

    FRST log:

     

    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-12-2014
    Ran by Sheyenne Alvarez (administrator) on SHEYENNEALVAREZ on 05-12-2014 09:55:58
    Running from C:\Users\Sheyenne Alvarez\Desktop
    Loaded Profile: Sheyenne Alvarez (Available profiles: Sheyenne Alvarez & Gabriella & Dario Jr & Roman)
    Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
    Internet Explorer Version 11
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
    (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
    (ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
    (Nero AG) C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe
    (MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
    (Fitbit, Inc.) C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
    () C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
    (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
    (NTI Corporation) C:\Program Files (x86)\NTI\NTI Backup Now EZ\BackupNowEZSvr.exe
    (Motorola) C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe
    () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    (Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe
    (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
    (Logitech Inc.) C:\Program Files\Logitech\SetPoint\LBTWiz.exe
    () C:\Program Files (x86)\Dell V520 Series\DKADGmon.exe
    (Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
    (Microsoft Corporation) C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
    () C:\Program Files (x86)\Dell\ErrorApp\dkab1err.exe
    (Fitbit, Inc.) C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe
    (GoPro) C:\Program Files (x86)\CineForm\Tools\GoProCineFormStatusViewer.exe
    (Logitech, Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe
    (NTI Corporation) C:\Program Files (x86)\NTI\NTI Backup Now EZ\BackupNowEZtray.exe
    (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
    (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    () C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
    (Motorola Mobility Inc.) C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoCast.exe
    () C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe
    (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
    (Logitech©) C:\Program Files\Logitech\Z Cinema\Z Cinema.exe
    () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe
    (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe


    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
    HKLM\...\Run: [Kernel and Hardware Abstraction Layer] => C:\Windows\KHALMNPR.EXE [130576 2009-06-17] (Logitech, Inc.)
    HKLM\...\Run: [Bluetooth Connection Assistant] => LBTWIZ.EXE -silent
    HKLM\...\Run: [DKADGmon] => C:\Program Files (x86)\Dell V520 Series\DKADGmon.exe [951656 2012-11-07] ()
    HKLM\...\Run: [IntelliPoint] => C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2417032 2011-08-01] (Microsoft Corporation)
    HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [BackupNowEZtray] => C:\Program Files (x86)\NTI\NTI Backup Now EZ\BackupNowEZtray.exe [581624 2013-02-05] (NTI Corporation)
    HKLM-x32\...\Run: [DKADGmon] => C:\Program Files (x86)\Dell V520 Series\DKADGmon.exe [951656 2012-11-07] ()
    HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
    HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.)
    HKLM-x32\...\Run: [Fitbit Connect] => C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [3414560 2014-05-19] (Fitbit, Inc.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
    Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
    HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\Run: [SpybotSD TeaTimer] => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
    HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\Run: [MotoCast] => C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk [2013 2013-08-19] ()
    HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\Run: [DKab1err] => C:\Program Files (x86)\Dell\ErrorApp\DKab1err.exe [644456 2012-11-07] ()
    HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\Run: [DKADGmon] => C:\Program Files (x86)\Dell V520 Series\DKADGmon.exe [951656 2012-11-07] ()
    HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\Run: [Google+ Auto Backup] => "C:\Users\Sheyenne Alvarez\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe" /autostart
    HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\Run: [Fitbit Connect] => C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [3414560 2014-05-19] (Fitbit, Inc.)
    HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\Run: [Amazon Music] => C:\Users\Sheyenne Alvarez\AppData\Local\Amazon Music\Amazon Music Helper.exe [6281024 2014-10-14] ()
    HKU\S-1-5-18\...\RunOnce: [panda2_0dn] => reg.exe delete "HKCU\Software\AppDataLow\Software\panda2_0dn" /f
    HKU\S-1-5-18\...\RunOnce: [panda2_0dn_XP] => reg.exe delete "HKCU\Software\panda2_0dn" /f
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CineForm Status.lnk
    ShortcutTarget: CineForm Status.lnk -> C:\Program Files (x86)\CineForm\Tools\GoProCineFormStatusViewer.exe (GoPro)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
    ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
    Startup: C:\Users\Sheyenne Alvarez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Amazon Cloud Drive.appref-ms ()
    Startup: C:\Users\Sheyenne Alvarez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
    ShortcutTarget: Dropbox.lnk -> C:\Users\Sheyenne Alvarez\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
    Startup: C:\Users\Sheyenne Alvarez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
    ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
    Startup: C:\Users\Sheyenne Alvarez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Z Cinema.lnk
    ShortcutTarget: Z Cinema.lnk -> C:\Users\Sheyenne Alvarez\AppData\Roaming\Microsoft\Installer\{6E166235-49F3-4DFA-A102-1E86675ABD11}\StartupShortcut_6E16623549F34DFAA1021E86675ABD11.exe (Macrovision Corporation)
    ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
    ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
    ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
    GroupPolicyUsers\S-1-5-21-3854915487-3061028145-266851286-1003\User: Group Policy restriction detected <======= ATTENTION

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    HKU\S-1-5-21-3854915487-3061028145-266851286-1000\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
    HKU\S-1-5-21-3854915487-3061028145-266851286-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
    SearchScopes: HKLM -> DefaultScope value is missing.
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia....h={searchTerms}
    SearchScopes: HKLM -> {d944bb61-2e34-4dbf-a683-47e505c587dc} URL = http://rover.ebay.co...s}&mfe=Desktops
    SearchScopes: HKLM -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = http://www.bing.com/...rc=IE-SearchBox
    SearchScopes: HKLM-x32 -> DefaultScope value is missing.
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia....h={searchTerms}
    SearchScopes: HKLM-x32 -> {d944bb61-2e34-4dbf-a683-47e505c587dc} URL = http://rover.ebay.co...s}&mfe=Desktops
    SearchScopes: HKLM-x32 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = http://www.bing.com/...rc=IE-SearchBox
    SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1000 -> ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
    SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.co...q={searchTerms}
    SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1000 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia....h={searchTerms}
    SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1000 -> {d944bb61-2e34-4dbf-a683-47e505c587dc} URL = http://rover.ebay.co...s}&mfe=Desktops
    SearchScopes: HKU\S-1-5-21-3854915487-3061028145-266851286-1000 -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = http://www.bing.com/...rc=IE-SearchBox
    BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
    BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
    BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
    BHO-x32: Dell Toolbar -> {09B71986-2AC5-482d-B6CB-42EA34F4F85B} -> C:\Program Files\Dell Printable Web\toolband.dll ()
    BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll (Microsoft Corporation)
    BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
    BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
    BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
    BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
    BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
    BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    Toolbar: HKLM-x32 - Dell Toolbar - {09B71986-2AC5-482d-B6CB-42EA34F4F85B} - C:\Program Files\Dell Printable Web\toolband.dll ()
    DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab
    DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab
    DPF: HKLM-x32 {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files (x86)\Yahoo!\Common\Yinsthelper.dll
    DPF: HKLM-x32 {924B4927-D3BA-41EA-9F7E-8A89194AB3AC} http://panda-plugin..../p3dactivex.cab
    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

    FireFox:
    ========
    FF ProfilePath: C:\Users\Sheyenne Alvarez\AppData\Roaming\Mozilla\Firefox\Profiles\btxhxadl.default-1415987071767
    FF NewTab: hxxp://www.google.com/
    FF DefaultSearchEngine: Bing
    FF DefaultSearchUrl: hxxp://www.google.com/search?btnG=Google+Search&q=
    FF SearchEngineOrder.1: Google
    FF SelectedSearchEngine: Google
    FF Homepage: hxxp://www.google.com
    FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
    FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll ()
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
    FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
    FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
    FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=12.0.1.652 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
    FF Plugin-x32: @real.com/nprphtml5videoshim;version=12.0.1.652 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF Plugin HKU\S-1-5-21-3854915487-3061028145-266851286-1000: @yahoo.com/BrowserPlus,version=2.9.8 -> C:\Users\Sheyenne Alvarez\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
    FF Plugin HKU\S-1-5-21-3854915487-3061028145-266851286-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101710.dll (Amazon.com, Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
    FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
    FF HKLM-x32\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension
    FF Extension: Default Manager - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2011-02-18]

    Chrome:
    =======
    CHR Profile: C:\Users\Sheyenne Alvarez\AppData\Local\Google\Chrome\User Data\Default

    ==================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
    R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2443960 2014-10-30] (Microsoft Corporation)
    R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1253376 2009-08-27] (MAGIX AG) [File not signed]
    S4 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®) [File not signed]
    R2 Fitbit Connect; C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [1436192 2014-05-19] (Fitbit, Inc.)
    S4 LightScribeService; c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-11-22] (Hewlett-Packard Company) [File not signed]
    R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
    R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
    R2 Motorola Device Manager; C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [120728 2012-10-02] ()
    R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
    S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
    R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
    S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3377568 2014-05-25] (INCA Internet Co., Ltd.)
    R2 NTI BackupNowEZSvr; C:\Program Files (x86)\NTI\NTI Backup Now EZ\BackupNowEZSvr.exe [46072 2013-02-05] (NTI Corporation)
    S4 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-05-06] (PDF Complete Inc)
    R2 PST Service; C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [65657 2011-09-02] (Motorola) [File not signed]
    R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390672 2012-09-11] ()
    R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    S3 A_USBETHMP; C:\Windows\System32\Drivers\usbethmp.sys [32280 2009-07-09] (Intellon Corporation)
    R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
    R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-12-05] (Malwarebytes Corporation)
    R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
    R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
    S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
    S3 WLRAWMp50x64; C:\Windows\System32\Drivers\WLRAWMp50x64.sys [35352 2013-10-31] (Logitech, Inc.)
    S3 WLRAWMp50x64; C:\Windows\SysWOW64\Drivers\WLRAWMp50x64.sys [35352 2013-10-31] (Logitech, Inc.)
    S3 WLRAWSp50x64; C:\Windows\System32\Drivers\WLRAWSp50x64.sys [34328 2013-10-31] (Logitech, Inc.)
    S3 WLRAWSp50x64; C:\Windows\SysWOW64\Drivers\WLRAWSp50x64.sys [34328 2013-10-31] (Logitech, Inc.)
    R3 ZCinema_TSHD_x64; C:\Windows\System32\drivers\ZCinema_SRS_amd64.sys [21648 2007-08-22] (SRS Labs, Inc.)
    S3 Andbus; system32\DRIVERS\lgandbus64.sys [X]
    S3 AndDiag; system32\DRIVERS\lganddiag64.sys [X]
    S3 AndGps; system32\DRIVERS\lgandgps64.sys [X]
    S3 ANDModem; system32\DRIVERS\lgandmodem64.sys [X]
    S3 androidusb; System32\Drivers\lgandadb.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


    ==================== One Month Created Files and Folders ========

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2014-12-05 09:55 - 2014-12-05 09:56 - 00024175 _____ () C:\Users\Sheyenne Alvarez\Desktop\FRST.txt
    2014-12-05 09:55 - 2014-12-05 09:56 - 00000000 ____D () C:\FRST
    2014-12-05 09:55 - 2014-12-05 09:55 - 02117632 _____ (Farbar) C:\Users\Sheyenne Alvarez\Desktop\FRST64.exe
    2014-12-05 09:52 - 2014-12-05 09:52 - 00002326 _____ () C:\Users\Sheyenne Alvarez\Desktop\JRT.txt
    2014-12-05 09:48 - 2014-12-05 09:48 - 00000000 ____D () C:\Windows\ERUNT
    2014-12-05 09:47 - 2014-12-05 09:47 - 01707646 _____ (Thisisu) C:\Users\Sheyenne Alvarez\Desktop\JRT.exe
    2014-12-05 09:26 - 2014-12-05 09:37 - 00000000 ____D () C:\AdwCleaner
    2014-12-05 09:26 - 2014-12-05 09:36 - 00000165 _____ () C:\AdwCleanerDebug.txt
    2014-12-05 09:25 - 2014-12-05 09:25 - 02153472 _____ () C:\Users\Sheyenne Alvarez\Desktop\AdwCleaner(1).exe
    2014-12-05 09:17 - 2014-12-05 09:18 - 00002362 _____ () C:\Users\Sheyenne Alvarez\Desktop\FixExec.txt
    2014-12-05 09:10 - 2014-12-05 09:10 - 00457632 _____ (Bleeping Computer, LLC) C:\Users\Sheyenne Alvarez\Downloads\FixExec.exe
    2014-12-05 07:15 - 2014-12-05 07:15 - 00000000 __SHD () C:\Users\Dario Jr\AppData\Local\EmieBrowserModeList
    2014-12-04 15:51 - 2014-12-04 15:45 - 00024064 _____ () C:\Windows\zoek-delete.exe
    2014-12-04 15:48 - 2014-12-04 10:56 - 00091099 _____ () C:\zoek-results2014-12-04-165605.log
    2014-12-04 14:41 - 2014-12-04 14:41 - 00186431 _____ () C:\Users\Sheyenne Alvarez\Documents\bookmarks.html
    2014-12-04 13:07 - 2014-12-04 13:08 - 00244104 _____ () C:\Users\Sheyenne Alvarez\Downloads\Firefox Setup Stub 34.0.5.exe
    2014-12-04 12:42 - 2014-12-05 09:56 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
    2014-12-04 12:42 - 2014-12-04 12:42 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2014-12-04 12:42 - 2014-12-04 12:42 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2014-12-04 12:42 - 2014-12-04 12:42 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
    2014-12-04 10:18 - 2014-12-04 15:53 - 00090828 _____ () C:\zoek-results.log
    2014-12-04 10:13 - 2014-12-04 10:46 - 00000000 ____D () C:\zoek_backup
    2014-12-04 10:09 - 2014-12-04 10:09 - 01295360 _____ () C:\Users\Sheyenne Alvarez\Desktop\zoek.exe
    2014-12-04 09:39 - 2014-12-04 09:39 - 00000000 ____D () C:\_OTL
    2014-12-02 13:09 - 2014-12-02 13:09 - 00102176 _____ () C:\Users\Sheyenne Alvarez\Downloads\Extras.Txt
    2014-12-02 13:08 - 2014-12-02 13:08 - 00145552 _____ () C:\Users\Sheyenne Alvarez\Downloads\OTL.Txt
    2014-12-02 12:47 - 2014-12-02 12:47 - 00602112 _____ (OldTimer Tools) C:\Users\Sheyenne Alvarez\Downloads\OTL.exe
    2014-12-02 09:23 - 2014-12-02 09:23 - 00011484 _____ () C:\Users\Sheyenne Alvarez\Documents\My Assistant Start-Up Costs.xlsx
    2014-12-01 21:52 - 2014-12-01 21:52 - 00137540 _____ () C:\Users\Sheyenne Alvarez\Documents\Sheyenne Resume for Bus. Plan class.dotx
    2014-11-29 16:28 - 2014-11-29 16:41 - 00054376 _____ () C:\Users\Sheyenne Alvarez\Downloads\Result.txt
    2014-11-29 16:26 - 2014-11-29 16:26 - 00401920 _____ (Farbar) C:\Users\Sheyenne Alvarez\Downloads\MiniToolBox.exe
    2014-11-25 14:25 - 2014-11-25 14:27 - 13087456 _____ (Microsoft Corporation) C:\Users\Sheyenne Alvarez\Downloads\Silverlight_x64(3).exe
    2014-11-23 17:31 - 2014-11-23 19:48 - 00170563 _____ () C:\Users\Sheyenne Alvarez\Documents\OB PRESENTATION-1-1 edits by Sheyenne.pptx
    2014-11-23 17:26 - 2014-11-23 17:26 - 00178464 _____ () C:\Users\Sheyenne Alvarez\Downloads\OB PRESENTATION-1-1.pptx
    2014-11-21 14:55 - 2014-11-21 14:55 - 01120240 _____ () C:\Users\Sheyenne Alvarez\Downloads\Calendar_Sheyenne_Alvarez.ics
    2014-11-20 16:24 - 2014-11-20 16:25 - 01174891 _____ () C:\Users\Sheyenne Alvarez\Downloads\finalized presentation.pptx
    2014-11-20 13:27 - 2014-11-20 13:27 - 00077536 _____ () C:\Users\Sheyenne Alvarez\Downloads\yahoo_contacts.csv
    2014-11-20 10:06 - 2014-11-20 10:06 - 00039066 _____ () C:\Users\Sheyenne Alvarez\Documents\My Assistant Financials - Income and Balance.xlsx
    2014-11-20 10:04 - 2014-11-20 10:04 - 00037767 _____ () C:\Users\Sheyenne Alvarez\Downloads\Financials - Income and Balance.xlsx
    2014-11-20 10:04 - 2014-11-20 10:04 - 00032615 _____ () C:\Users\Sheyenne Alvarez\Downloads\Financials - Cash Flow.xlsx
    2014-11-19 10:27 - 2014-11-10 21:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
    2014-11-19 10:27 - 2014-11-10 21:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
    2014-11-19 10:27 - 2014-11-10 20:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
    2014-11-19 10:27 - 2014-11-10 20:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
    2014-11-18 14:20 - 2014-11-18 14:20 - 00029187 _____ () C:\Users\Sheyenne Alvarez\Documents\My Assistant Financials.xlsx
    2014-11-18 12:51 - 2014-11-18 14:13 - 00029172 _____ () C:\Users\Sheyenne Alvarez\Downloads\Financials.xlsx
    2014-11-17 11:22 - 2014-11-17 11:22 - 01173439 _____ () C:\Users\Sheyenne Alvarez\Documents\finalized presentation - suggestions from Sheyenne.pptx
    2014-11-17 10:52 - 2014-11-17 10:52 - 00126043 _____ () C:\Users\Sheyenne Alvarez\Documents\OB PRESENTATION - suggestions by Sheyenne.pptx
    2014-11-17 09:26 - 2014-11-17 09:26 - 00123651 _____ () C:\Users\Sheyenne Alvarez\Documents\OB PRESENTATION.pptx
    2014-11-17 09:21 - 2014-11-17 09:21 - 00126234 _____ () C:\Users\Sheyenne Alvarez\Downloads\OB PRESENTATION.pptx
    2014-11-16 15:46 - 2014-11-16 15:52 - 00035328 _____ () C:\Users\Sheyenne Alvarez\Documents\My Assistant SimplyMap by Sheyenne.xls
    2014-11-16 15:41 - 2014-11-16 15:41 - 00010752 _____ () C:\Users\Sheyenne Alvarez\Downloads\standard_report.xls
    2014-11-14 21:06 - 2014-11-14 21:06 - 13087456 _____ (Microsoft Corporation) C:\Users\Sheyenne Alvarez\Downloads\Silverlight_x64(2).exe
    2014-11-14 21:05 - 2014-11-14 21:05 - 13087456 _____ (Microsoft Corporation) C:\Users\Sheyenne Alvarez\Downloads\Silverlight_x64(1).exe
    2014-11-14 11:55 - 2014-11-14 11:55 - 01080496 _____ (Unity Technologies ApS) C:\Users\Sheyenne Alvarez\Downloads\UnityWebPlayer.exe
    2014-11-14 11:44 - 2014-11-14 11:44 - 00000000 ____D () C:\Users\Sheyenne Alvarez\Desktop\Old Firefox Data
    2014-11-12 05:41 - 2014-11-07 13:49 - 00388272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2014-11-12 05:41 - 2014-11-07 13:23 - 00341168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2014-11-12 05:41 - 2014-11-05 22:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2014-11-12 05:41 - 2014-11-05 22:03 - 25110016 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2014-11-12 05:41 - 2014-11-05 22:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2014-11-12 05:41 - 2014-11-05 21:47 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2014-11-12 05:41 - 2014-11-05 21:46 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2014-11-12 05:41 - 2014-11-05 21:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2014-11-12 05:41 - 2014-11-05 21:44 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2014-11-12 05:41 - 2014-11-05 21:43 - 02884096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2014-11-12 05:41 - 2014-11-05 21:36 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2014-11-12 05:41 - 2014-11-05 21:35 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2014-11-12 05:41 - 2014-11-05 21:31 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2014-11-12 05:41 - 2014-11-05 21:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2014-11-12 05:41 - 2014-11-05 21:30 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2014-11-12 05:41 - 2014-11-05 21:29 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2014-11-12 05:41 - 2014-11-05 21:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2014-11-12 05:41 - 2014-11-05 21:23 - 06040064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2014-11-12 05:41 - 2014-11-05 21:20 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2014-11-12 05:41 - 2014-11-05 21:16 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2014-11-12 05:41 - 2014-11-05 21:13 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2014-11-12 05:41 - 2014-11-05 21:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2014-11-12 05:41 - 2014-11-05 21:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2014-11-12 05:41 - 2014-11-05 21:10 - 19781632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2014-11-12 05:41 - 2014-11-05 21:10 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2014-11-12 05:41 - 2014-11-05 21:07 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2014-11-12 05:41 - 2014-11-05 21:05 - 02277376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2014-11-12 05:41 - 2014-11-05 21:04 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2014-11-12 05:41 - 2014-11-05 21:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2014-11-12 05:41 - 2014-11-05 21:02 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2014-11-12 05:41 - 2014-11-05 21:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2014-11-12 05:41 - 2014-11-05 21:00 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2014-11-12 05:41 - 2014-11-05 20:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2014-11-12 05:41 - 2014-11-05 20:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2014-11-12 05:41 - 2014-11-05 20:57 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2014-11-12 05:41 - 2014-11-05 20:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2014-11-12 05:41 - 2014-11-05 20:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2014-11-12 05:41 - 2014-11-05 20:41 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2014-11-12 05:41 - 2014-11-05 20:41 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2014-11-12 05:41 - 2014-11-05 20:39 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
    2014-11-12 05:41 - 2014-11-05 20:38 - 02124288 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2014-11-12 05:41 - 2014-11-05 20:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2014-11-12 05:41 - 2014-11-05 20:36 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2014-11-12 05:41 - 2014-11-05 20:34 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2014-11-12 05:41 - 2014-11-05 20:30 - 14390272 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2014-11-12 05:41 - 2014-11-05 20:22 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2014-11-12 05:41 - 2014-11-05 20:21 - 04298240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2014-11-12 05:41 - 2014-11-05 20:21 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2014-11-12 05:41 - 2014-11-05 20:20 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2014-11-12 05:41 - 2014-11-05 20:17 - 02365440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2014-11-12 05:41 - 2014-11-05 20:04 - 01550336 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2014-11-12 05:41 - 2014-11-05 20:03 - 12819456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2014-11-12 05:41 - 2014-11-05 19:53 - 00799232 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2014-11-12 05:41 - 2014-11-05 19:52 - 01892864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2014-11-12 05:41 - 2014-11-05 19:48 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2014-11-12 05:41 - 2014-11-05 19:47 - 00708096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2014-11-12 05:41 - 2014-11-05 11:56 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
    2014-11-12 05:41 - 2014-11-05 11:56 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
    2014-11-12 05:41 - 2014-11-05 11:52 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
    2014-11-12 05:41 - 2014-10-13 20:16 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
    2014-11-12 05:41 - 2014-10-13 20:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
    2014-11-12 05:41 - 2014-10-13 20:12 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
    2014-11-12 05:41 - 2014-10-13 20:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
    2014-11-12 05:41 - 2014-10-13 20:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
    2014-11-12 05:41 - 2014-10-13 19:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2014-11-12 05:41 - 2014-10-13 19:49 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    2014-11-12 05:41 - 2014-10-13 19:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
    2014-11-12 05:41 - 2014-10-13 19:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
    2014-11-12 05:40 - 2014-10-24 19:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
    2014-11-12 05:40 - 2014-10-24 19:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
    2014-11-12 05:40 - 2014-10-13 20:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
    2014-11-12 05:40 - 2014-10-13 19:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
    2014-11-12 05:40 - 2014-10-09 18:57 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2014-11-12 05:40 - 2014-10-02 20:12 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
    2014-11-12 05:40 - 2014-10-02 20:11 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
    2014-11-12 05:40 - 2014-10-02 20:11 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
    2014-11-12 05:40 - 2014-10-02 20:11 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
    2014-11-12 05:40 - 2014-10-02 20:11 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
    2014-11-12 05:40 - 2014-10-02 19:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
    2014-11-12 05:40 - 2014-10-02 19:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
    2014-11-12 05:40 - 2014-10-02 19:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
    2014-11-12 05:40 - 2014-09-19 03:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
    2014-11-12 05:40 - 2014-09-19 03:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
    2014-11-12 05:40 - 2014-09-19 03:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
    2014-11-12 05:40 - 2014-09-19 03:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
    2014-11-12 05:40 - 2014-09-19 03:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
    2014-11-12 05:40 - 2014-09-19 03:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
    2014-11-12 05:40 - 2014-09-19 03:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
    2014-11-12 05:40 - 2014-09-19 03:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2014-11-12 05:40 - 2014-09-19 03:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2014-11-12 05:40 - 2014-09-19 03:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
    2014-11-12 05:40 - 2014-09-19 03:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
    2014-11-12 05:40 - 2014-09-19 03:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
    2014-11-12 05:40 - 2014-08-21 00:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
    2014-11-12 05:40 - 2014-08-21 00:40 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
    2014-11-12 05:40 - 2014-08-21 00:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
    2014-11-12 05:40 - 2014-08-21 00:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
    2014-11-12 05:40 - 2014-08-11 20:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
    2014-11-12 05:40 - 2014-08-11 19:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
    2014-11-12 05:39 - 2014-10-17 20:05 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
    2014-11-12 05:39 - 2014-10-17 19:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
    2014-11-11 13:05 - 2014-11-11 13:05 - 00162901 _____ () C:\Users\Sheyenne Alvarez\Downloads\Calendar_Gabby.ics
    2014-11-11 13:05 - 2014-11-11 13:05 - 00107158 _____ () C:\Users\Sheyenne Alvarez\Downloads\Calendar_Dario_Jr..ics
    2014-11-11 13:05 - 2014-11-11 13:05 - 00081923 _____ () C:\Users\Sheyenne Alvarez\Downloads\Calendar_Roman.ics
    2014-11-11 13:05 - 2014-11-11 13:05 - 00018271 _____ () C:\Users\Sheyenne Alvarez\Downloads\Calendar_Out_of_town.ics
    2014-11-11 12:50 - 2014-11-11 12:50 - 00147247 _____ () C:\Users\Sheyenne Alvarez\Downloads\Calendar_classes.ics
    2014-11-11 12:48 - 2014-11-11 12:49 - 00071237 _____ () C:\Users\Sheyenne Alvarez\Downloads\Calendar_Birthdays.ics
    2014-11-11 12:45 - 2014-11-11 12:45 - 00196799 _____ () C:\Users\Sheyenne Alvarez\Downloads\Calendar_Action_item.ics
    2014-11-10 08:38 - 2014-12-04 13:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
    2014-11-08 21:06 - 2014-11-08 21:06 - 00001252 _____ () C:\Users\Sheyenne Alvarez\Desktop\Amazon Music.lnk
    2014-11-08 21:04 - 2014-11-08 21:05 - 40117016 _____ (Amazon) C:\Users\Sheyenne Alvarez\Downloads\AmazonMusicInstaller.exe

    ==================== One Month Modified Files and Folders =======

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2014-12-05 09:46 - 2014-03-29 19:12 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2014-12-05 08:31 - 2014-09-02 18:34 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2014-12-05 08:23 - 2011-08-05 12:42 - 00000000 ____D () C:\Users\Sheyenne Alvarez\AppData\Local\Deployment
    2014-12-05 07:25 - 2013-08-19 19:08 - 00000000 ____D () C:\Users\Sheyenne Alvarez\.gstreamer-0.10
    2014-12-05 07:25 - 2013-08-19 19:04 - 00000000 ____D () C:\Users\Sheyenne Alvarez\AppData\Roaming\MotoCast
    2014-12-05 07:24 - 2013-12-16 19:02 - 00000000 ___RD () C:\Users\Sheyenne Alvarez\Dropbox
    2014-12-05 07:24 - 2013-12-16 18:55 - 00000000 ____D () C:\Users\Sheyenne Alvarez\AppData\Roaming\Dropbox
    2014-12-05 07:23 - 2014-03-29 19:12 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2014-12-05 07:23 - 2012-01-17 14:15 - 00000000 ____D () C:\TEMP
    2014-12-05 07:23 - 2011-02-18 21:54 - 01557891 _____ () C:\Windows\WindowsUpdate.log
    2014-12-05 07:16 - 2009-07-13 22:45 - 00018736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2014-12-05 07:16 - 2009-07-13 22:45 - 00018736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2014-12-05 07:14 - 2012-03-14 08:22 - 00156656 _____ () C:\Users\Dario Jr\AppData\Local\GDIPFONTCACHEV1.DAT
    2014-12-05 07:14 - 2012-03-14 08:22 - 00000008 __RSH () C:\Users\Dario Jr\ntuser.pol
    2014-12-05 07:14 - 2012-03-14 08:22 - 00000000 ____D () C:\Users\Dario Jr
    2014-12-05 07:09 - 2012-08-18 09:35 - 00123726 _____ () C:\Windows\setupact.log
    2014-12-05 07:09 - 2009-07-13 23:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
    2014-12-04 15:52 - 2011-02-19 01:01 - 01195902 _____ () C:\Windows\PFRO.log
    2014-12-04 13:12 - 2012-07-18 19:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
    2014-12-04 13:09 - 2012-07-18 19:14 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
    2014-12-04 13:09 - 2012-07-18 19:14 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
    2014-12-04 12:42 - 2014-08-21 21:28 - 00000000 ____D () C:\Users\Sheyenne Alvarez\AppData\Local\Adobe
    2014-12-04 10:54 - 2012-03-10 00:18 - 00000008 __RSH () C:\Users\Sheyenne Alvarez\ntuser.pol
    2014-12-04 10:54 - 2011-03-05 23:03 - 00000000 ____D () C:\Users\Sheyenne Alvarez
    2014-12-04 10:39 - 2009-07-13 21:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
    2014-12-04 10:39 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
    2014-12-04 10:02 - 2012-05-08 13:55 - 00000000 ____D () C:\Users\Sheyenne Alvarez\AppData\Roaming\Mozilla
    2014-12-04 09:33 - 2013-01-04 16:58 - 00000000 ____D () C:\Program Files (x86)\FileHippo.com
    2014-12-04 09:30 - 2011-03-20 13:02 - 00000000 ____D () C:\Program Files (x86)\MAGIX
    2014-12-04 09:28 - 2011-03-06 16:38 - 00000000 ____D () C:\Users\Sheyenne Alvarez\AppData\Local\Google
    2014-12-04 09:24 - 2014-01-14 16:08 - 00000000 ____D () C:\Users\Sheyenne Alvarez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup
    2014-12-02 17:43 - 2014-09-29 16:29 - 00000376 _____ () C:\Windows\Tasks\HPCeeScheduleForSheyenne Alvarez.job
    2014-12-02 12:50 - 2014-09-02 18:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2014-12-02 12:50 - 2014-09-02 18:33 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
    2014-12-02 12:50 - 2012-12-24 08:55 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2014-12-01 17:15 - 2014-09-29 16:29 - 00003252 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForSheyenne Alvarez
    2014-11-30 21:04 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\L2Schemas
    2014-11-29 12:32 - 2011-02-18 22:02 - 00000000 ____D () C:\ProgramData\Temp
    2014-11-29 12:29 - 2011-02-18 22:24 - 00157778 _____ () C:\Windows\DirectX.log
    2014-11-29 01:27 - 2011-03-06 20:06 - 00000000 ____D () C:\Users\Sheyenne Alvarez\AppData\Local\Microsoft Help
    2014-11-29 01:27 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\registration
    2014-11-28 14:18 - 2009-07-13 23:13 - 02223910 _____ () C:\Windows\system32\PerfStringBackup.INI
    2014-11-24 16:54 - 2011-03-24 17:29 - 00000000 ____D () C:\Users\Sheyenne Alvarez\AppData\Local\CrashDumps
    2014-11-23 19:48 - 2012-02-01 08:24 - 00511488 ___SH () C:\Users\Sheyenne Alvarez\Documents\Thumbs.db
    2014-11-23 19:47 - 2012-01-25 17:24 - 01224704 ___SH () C:\Users\Sheyenne Alvarez\Downloads\Thumbs.db
    2014-11-21 06:14 - 2014-09-02 18:33 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
    2014-11-21 06:14 - 2014-09-02 18:33 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2014-11-21 06:14 - 2012-12-24 08:55 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
    2014-11-16 05:02 - 2011-03-06 20:06 - 00000000 ____D () C:\ProgramData\Microsoft Help
    2014-11-16 04:58 - 2014-05-24 19:46 - 00000000 ____D () C:\Program Files\Microsoft Office 15
    2014-11-14 18:37 - 2011-05-25 08:06 - 00003232 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForSHEYENNEALVAREZ$
    2014-11-14 18:37 - 2011-05-25 08:06 - 00000356 _____ () C:\Windows\Tasks\HPCeeScheduleForSHEYENNEALVAREZ$.job
    2014-11-14 12:41 - 2014-03-29 19:12 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
    2014-11-14 12:41 - 2014-03-29 19:12 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
    2014-11-14 11:30 - 2013-12-16 19:02 - 00001061 _____ () C:\Users\Sheyenne Alvarez\Desktop\Dropbox.lnk
    2014-11-14 11:30 - 2013-12-16 18:57 - 00000000 ____D () C:\Users\Sheyenne Alvarez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
    2014-11-13 07:19 - 2011-03-05 23:06 - 00156656 _____ () C:\Users\Sheyenne Alvarez\AppData\Local\GDIPFONTCACHEV1.DAT
    2014-11-13 04:24 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\rescache
    2014-11-13 03:34 - 2009-07-13 22:45 - 00525504 _____ () C:\Windows\system32\FNTCACHE.DAT
    2014-11-13 03:32 - 2014-04-30 02:01 - 00000000 ___SD () C:\Windows\system32\CompatTel
    2014-11-13 03:10 - 2013-08-14 00:28 - 00000000 ____D () C:\Windows\system32\MRT
    2014-11-13 03:02 - 2011-08-03 14:15 - 103374192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2014-11-11 14:35 - 2009-07-13 23:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
    2014-11-08 20:28 - 2013-05-09 06:06 - 00000000 ____D () C:\Users\Sheyenne Alvarez\Cloud Drive
    2014-11-07 09:06 - 2013-02-02 16:13 - 00249897 _____ () C:\ProgramData\DKADGscan.log
    2014-11-05 08:51 - 2014-11-02 21:58 - 00166563 _____ () C:\Users\Sheyenne Alvarez\Documents\Sheyenne Resume.dotx

    Files to move or delete:
    ====================
    C:\Users\Sheyenne Alvarez\jobq.dat


    Some content of TEMP:
    ====================
    C:\Users\Sheyenne Alvarez\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpfru8as.dll
    C:\Users\Sheyenne Alvarez\AppData\Local\Temp\jna4748053063287358990.dll
    C:\Users\Sheyenne Alvarez\AppData\Local\Temp\jna5357521240366749379.dll
    C:\Users\Sheyenne Alvarez\AppData\Local\Temp\sqlite-3.6.20-sqlitejdbc.dll
    C:\Users\Sheyenne Alvarez\AppData\Local\Temp\sqlite-3.7.2-sqlitejdbc.dll


    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\System32\winlogon.exe => File is digitally signed
    C:\Windows\System32\wininit.exe => File is digitally signed
    C:\Windows\SysWOW64\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\System32\services.exe => File is digitally signed
    C:\Windows\System32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\System32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed
    C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
    ATTENTION: ====> ZeroAccess. Use DeleteJunctionsIndirectory: C:\Windows\system64


    LastRegBack: 2014-11-25 00:57

    ==================== End Of Log ============================

     

    Addition log:

    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-12-2014
    Ran by Sheyenne Alvarez at 2014-12-05 09:57:08
    Running from C:\Users\Sheyenne Alvarez\Desktop
    Boot Mode: Normal
    ==========================================================


    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Microsoft Security Essentials (Disabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
    AS: Microsoft Security Essentials (Disabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
    AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    ABBYY FineReader 6.0 Sprint (HKLM-x32\...\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.2146.41621 - ABBYY Software House)
    ABBYY FineReader 9.0 Sprint (HKLM-x32\...\ABBYY FineReader 9.0 Sprint) (Version: 9.00.595.5857 - ABBYY)
    ABBYY FineReader 9.0 Sprint (x32 Version: 9.00.595.5857 - ABBYY) Hidden
    ActiveCheck component for HP Active Support Library (x32 Version: 3.0.0.3 - Hewlett-Packard) Hidden
    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
    Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.239 - Adobe Systems Incorporated)
    Adobe Reader XI (11.0.09) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
    Amazon Cloud Drive (HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\23ab716f18849b6f) (Version: 2.4.2013.3290 - Amazon)
    Amazon MP3 Downloader 1.0.17 (HKLM-x32\...\Amazon MP3 Downloader) (Version: 1.0.17 - Amazon Services LLC)
    Amazon Music (HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\Amazon Amazon Music) (Version: 3.6.0.671 - Amazon Services LLC)
    Amazon Music Importer (HKLM-x32\...\com.amazon.music.uploader) (Version: 2.0.1 - Amazon Services LLC)
    Amazon Music Importer (x32 Version: 2.0.1 - Amazon Services LLC) Hidden
    Apple Application Support (HKLM-x32\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
    ATI Catalyst Install Manager (HKLM\...\{7C7A5A92-046C-A38C-AE0F-8F9CCA0F67A8}) (Version: 3.0.774.0 - ATI Technologies, Inc.)
    Bing Rewards Client Installer (x32 Version: 16.0.345.0 - Microsoft Corporation) Hidden
    ccc-core-static (x32 Version: 2010.0511.2153.37435 - ATI) Hidden
    CDDRV_Installer (Version: 4.60 - Logitech) Hidden
    ClipGrab 3.4.7 (HKLM-x32\...\{8A1033B0-EF33-4FB5-97A1-C47A7DCDD7E6}_is1) (Version:  - Philipp Schmieder Medien)
    CyberLink DVD Suite Deluxe (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 7.0.3210 - CyberLink Corp.)
    CyberLink PowerDirector 11 (HKLM-x32\...\InstallShield_{551F492A-01B0-4DC4-866F-875EC4EDC0A8}) (Version: 11.0.0.2321 - CyberLink Corp.)
    CyberLink PowerDirector 11 (Version: 11.0.0.2321 - CyberLink Corp.) Hidden
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    Dell Driver Download Manager (HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\f031ef6ac137efc5) (Version: 2.1.0.0 - Dell Inc.)
    Dell Toolbar (HKLM-x32\...\{09B71986-2AC5-482d-B6CB-42EA34F4F85B}) (Version: 1.8.12.0 - )
    Dell V520 Series Uninstaller (HKLM\...\Dell V520 Series) (Version:  - Dell, Inc.)
    Dropbox (HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\Dropbox) (Version: 2.10.52 - Dropbox, Inc.)
    DVD Menu Pack for HP MediaSmart Video (HKLM-x32\...\InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}) (Version: 4.2.4412 - Hewlett-Packard)
    DVD Menu Pack for HP MediaSmart Video (x32 Version: 4.2.4412 - Hewlett-Packard) Hidden
    erLT (x32 Version: 1.20.0137 - Logitech, Inc.) Hidden
    FamilySearch Indexing 3.24.2 (HKLM-x32\...\0591-8077-9297-0833) (Version: 3.24.2 - FamilySearch)
    Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{34EB6245-C8D0-4D8A-B8D8-EEBFF7A91485}) (Version: 2.1.27.0 - MAGIX AG)
    Fitbit Connect (HKLM-x32\...\{D3CD091B-296B-48E9-9F0F-E9FE53E02E41}) (Version: 1.0.3.5511 - Fitbit Inc.)
    Flyff (HKLM-x32\...\{48E3D369-48AA-4585-AE91-E64667682508}_is1) (Version: Flyff - WEBZEN Inc)
    Free Realms (HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\SOE-Free Realms) (Version:  - Sony Online Entertainment)
    Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
    Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
    Google+ Auto Backup (HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\Google+ Auto Backup) (Version: 1.0.26.151 - Google, Inc.)
    GoPro Studio 2.0.1 (HKLM-x32\...\GoPro Studio) (Version: 2.0.1 - WoodmanLabs Inc. d.b.a. GoPro)
    HP MediaSmart DVD (HKLM-x32\...\InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}) (Version: 4.2.4725 - Hewlett-Packard)
    HP MediaSmart Music (HKLM-x32\...\InstallShield_{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}) (Version: 4.2.4517 - Hewlett-Packard)
    HP MediaSmart Photo (HKLM-x32\...\InstallShield_{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}) (Version: 4.2.4513 - Hewlett-Packard)
    HP MediaSmart SmartMenu (HKLM\...\{A40F60B1-F1E1-452E-96A5-FF97F9A2D102}) (Version: 3.1.2.4 - Hewlett-Packard)
    HP MediaSmart Video (HKLM-x32\...\InstallShield_{D12E3E7F-1B13-4933-A915-16C7DD37A095}) (Version: 4.2.4522 - Hewlett-Packard)
    HP MediaSmart/TouchSmart Netflix (HKLM-x32\...\{2EA3D6B2-157E-4112-A3AB-BF17E16661C3}) (Version: 1.0.4.0 - Hewlett-Packard)
    HP MovieStore (HKLM-x32\...\{9008D736-35CA-40DB-A2BE-5F32D954E5AA}) (Version: 2.0.2 - Hewlett-Packard)
    HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard)
    HP Setup (HKLM-x32\...\{53469506-A37E-4314-A9D9-38724EC23A75}) (Version: 8.4.4400.3525 - Hewlett-Packard Company)
    HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.0.12844.3519 - Hewlett-Packard Company)
    HP Support Assistant (HKLM-x32\...\{B1A4A13D-4665-4ED3-9DFE-F845725FBBD8}) (Version: 5.1.8.12 - Hewlett-Packard Company)
    HP Support Information (HKLM-x32\...\{7F2A11F4-EAE8-4325-83EC-E3E99F85169E}) (Version: 10.1.1000 - Hewlett-Packard)
    HP Update (HKLM-x32\...\{DE77FE3F-A33D-499A-87AD-5FC406617B40}) (Version: 5.002.003.003 - Hewlett-Packard)
    HP Vision Hardware Diagnostics (HKLM\...\{D79A02E9-6713-4335-9668-AAC7474C0C0E}) (Version: 2.1.6.0 - Hewlett-Packard)
    HPAsset component for HP Active Support Library (x32 Version: 3.0.0.3 - Hewlett-Packard) Hidden
    iCloud (HKLM\...\{D0CB24F4-084F-40DE-B6B9-A03626E682F0}) (Version: 2.1.1.3 - Apple Inc.)
    Intel® Integrated Performance Primitives Run-Time Installer 5.1 for Windows* on IA-32 Intel® Architecture (x32 Version: 5.1.0.0 - Intel Corporation) Hidden
    Internet TV for Windows Media Center (HKLM-x32\...\{9D318C86-AF4C-409F-A6AC-7183FF4CF424}) (Version: 4.2.2.0 - Microsoft Corporation)
    iTunes (HKLM\...\{5A68A656-979F-4168-8795-E2E368AA4DC2}) (Version: 11.2.2.3 - Apple Inc.)
    Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.670 - Oracle)
    Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    KhalInstallWrapper (Version: 2.00.0000 - Logitech) Hidden
    Kobo (HKLM-x32\...\Kobo) (Version: 1.6 - Kobo Inc.)
    LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3130 - CyberLink Corp.)
    LabelPrint (x32 Version: 2.5.3130 - CyberLink Corp.) Hidden
    LightScribe System Software (HKLM-x32\...\{FD7F0DB8-0E96-4D64-AD4D-9B5A936AF2A8}) (Version: 1.18.20.1 - LightScribe)
    Logitech Alert Commander (HKLM-x32\...\{9C815CCE-8A56-4C1E-A3CA-D1BA519882BC}) (Version: 3.5.97 - Logitech)
    Logitech SetPoint (HKLM-x32\...\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}) (Version: 4.80 - Logitech)
    Macromedia Director 7 (HKLM-x32\...\Macromedia Director 7) (Version:  - )
    MAGIX Speed 2 (MSI) (HKLM-x32\...\{0C667580-EA2C-4EC2-A233-D52468A1D7D9}) (Version: 6.0.1.2 - MAGIX AG)
    Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
    Media Player Codec Pack 4.2.0 (HKLM-x32\...\Media Player - Codec Pack) (Version: 4.2.0 - Media Player Codec Pack)
    Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
    Microsoft .NET Framework 4.5.1 (español) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 3082) (Version: 4.5.50938 - Microsoft Corporation)
    Microsoft .NET Framework 4.5.1 (Français) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1036) (Version: 4.5.50938 - Microsoft Corporation)
    Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
    Microsoft .NET Framework 4.5.1 (Italiano) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1040) (Version: 4.5.50938 - Microsoft Corporation)
    Microsoft .NET Framework 4.5.1 (Nederlands) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1043) (Version: 4.5.50938 - Microsoft Corporation)
    Microsoft IntelliPoint 8.2 (HKLM\...\Microsoft IntelliPoint 8.2) (Version: 8.20.468.0 - Microsoft Corporation)
    Microsoft Office 365 ProPlus - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 15.0.4667.1002 - Microsoft Corporation)
    Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
    Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    MotoCast (HKLM-x32\...\{5401CEE8-3C2D-4835-A802-213306537FF4}) (Version: 2.0.31 - Motorola Mobility)
    Motorola Device Manager (HKLM-x32\...\{28DB8373-C1BB-444F-A427-A55585A12ED7}) (Version: 2.2.35 - Motorola Mobility)
    Motorola Device Software Update (x32 Version: 1.0.41 - Motorola Mobility) Hidden
    MOTOROLA MEDIA LINK (x32 Version: 1.9.0002.0 - Motorola) Hidden
    Motorola Mobile Drivers Installation 5.9.0 (Version: 5.9.0 - Motorola Inc.) Hidden
    Movie Theme Pack for HP MediaSmart Video (HKLM-x32\...\InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}) (Version: 4.2.4412 - Hewlett-Packard)
    Movie Theme Pack for HP MediaSmart Video (x32 Version: 4.2.4412 - Hewlett-Packard) Hidden
    Mozilla Firefox 34.0.5 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 34.0.5 (x86 en-US)) (Version: 34.0.5 - Mozilla)
    Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 34.0.5 - Mozilla)
    MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
    MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
    MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
    MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
    Netflix in Windows Media Center (HKLM-x32\...\{0CA72D12-F6C6-4D43-A2A0-41F5AA17E2B6}) (Version: 3.3.101.0 - Microsoft Corporation)
    Newblue Art Effects for PowerDirector (HKLM\...\NewBlue Art Effects for PowerDirector) (Version: 2.0 - NewBlue)
    Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation)
    NTI Backup Now EZ (HKLM-x32\...\InstallShield_{B9ECA41B-55CC-4654-B6B5-6731D009EC69}) (Version: 3.0.2.32 - NTI Corporation)
    NTI Backup Now EZ (x32 Version: 3.0.2.32 - NTI Corporation) Hidden
    Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4667.1002 - Microsoft Corporation) Hidden
    Office 15 Click-to-Run Licensing Component (Version: 15.0.4667.1002 - Microsoft Corporation) Hidden
    Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4667.1002 - Microsoft Corporation) Hidden
    Pantech PCSuite (HKLM-x32\...\{69187EC5-F5CF-4B2C-B920-5A17F44D9685}) (Version: 1.0 - Pantech)
    Pantech PCSuite (x32 Version: 1.0 - Pantech) Hidden
    PDF Complete Special Edition (HKLM-x32\...\PDF Complete) (Version: 4.0.57 - PDF Complete, Inc)
    PhotoNow! (HKLM-x32\...\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.7717 - CyberLink Corp.)
    PhotoNow! (x32 Version: 1.1.7717 - CyberLink Corp.) Hidden
    Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
    PictureMover (HKLM-x32\...\{264FE20A-757B-492a-B0C3-4009E2997D8A}) (Version: 3.5.0.33 - Hewlett-Packard Company)
    PL-2303 Vista Driver Installer (HKLM-x32\...\{EEC010D0-1252-4E1D-BAD9-F1B8F414535C}) (Version: 3.0.1.0 - Prolific)
    PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
    PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
    Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.4329 - CyberLink Corp.)
    Power2Go (x32 Version: 6.1.4329 - CyberLink Corp.) Hidden
    PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.3129 - CyberLink Corp.)
    PowerDirector (Version: 11.0 - CyberLink Corp.) Hidden
    PowerDirector (x32 Version: 8.0.3129 - CyberLink Corp.) Hidden
    PressReader (HKLM-x32\...\{912CED74-88D3-4C5B-ACB0-13231864975E}) (Version: 5.10.1102.0 -  NewspaperDirect Inc.)
    Quicken WillMaker Plus 2008 (HKLM-x32\...\Quicken WillMaker Plus 2008) (Version:  - )
    QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
    Ralink RT2860 Wireless LAN Card (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309B0}) (Version:  - Ralink)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6196 - Realtek Semiconductor Corp.)
    Recovery Manager (x32 Version: 5.5.3219 - CyberLink Corp.) Hidden
    Riverpoint Writer (HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\FF389026-F961-42C5-BACD-B4A3AA73E0F3) (Version: 2.0.0.9 - Apollo Group, Inc.)
    RoxioNow Player (HKLM-x32\...\{0EDEB615-1A60-425E-8306-0E10519C7B55}) (Version: 1.9.5.101 - RoxioNow)
    Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
    SmartSound Quicktracks 5 (HKLM-x32\...\InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.8 - SmartSound Software Inc.)
    SmartSound Quicktracks 5 (x32 Version: 5.1.8 - SmartSound Software Inc.) Hidden
    Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
    SpyroPortalDriver (HKLM\...\{B2913230-094D-4F41-9EEF-CE9571C450D8}) (Version: 1.0.0 - FS)
    swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
    The Imagination Station (remove only) (HKLM-x32\...\The Imagination Station) (Version:  - )
    Windows Driver Package - GoPro (WinUSB) Universal Serial Bus devices  (03/07/2012 ) (HKLM\...\0B624A43DD66DBF5CF3EDFA9741A364E688062A4) (Version: 03/07/2012  - GoPro)
    Windows Essentials Media Codec Pack 4.0 [64-Bit] (HKLM-x32\...\Windows Essentials Media Codec Pack) (Version: 4.0 - Media Codec)
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
    Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version:  - )
    Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
    Wizard101 (HKLM-x32\...\{A9E27FF5-6294-46A8-B8FD-77B1DECA3021}) (Version: 1.0.0 - KingsIsle Entertainment, Inc.)
    Yahoo! BrowserPlus 2.9.8 (HKU\S-1-5-21-3854915487-3061028145-266851286-1000\...\Yahoo! BrowserPlus) (Version:  - Yahoo! Inc.)
    Yahoo! Install Manager (HKLM-x32\...\YInstHelper) (Version:  - )
    Yahoo! Internet Mail (HKLM-x32\...\Yahoo! Mail) (Version:  - )
    Yahoo! Mail Advisor (HKLM-x32\...\Yahoo! Mail Advisor) (Version:  - )
    Yahoo! Software Update (HKLM-x32\...\Yahoo! Software Update) (Version:  - )
    Yahoo! Toolbar (HKLM-x32\...\Yahoo! Companion) (Version:  - Yahoo! Inc.)
    Z Cinema (HKLM\...\{6E166235-49F3-4DFA-A102-1E86675ABD11}) (Version: 1.0.0 - Logitech)
    Zinio Reader 4 (HKLM-x32\...\ZinioReader4.9310D8F796442B71068C511E15D70529A702D19D.1) (Version: 4.0.3184 - Zinio LLC)
    Zinio Reader 4 (x32 Version: 4.0.3184 - Zinio LLC) Hidden

    ==================== Custom CLSID (selected items): ==========================

    (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

    CustomCLSID: HKU\S-1-5-21-3854915487-3061028145-266851286-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Sheyenne Alvarez\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-3854915487-3061028145-266851286-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Sheyenne Alvarez\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll No File
    CustomCLSID: HKU\S-1-5-21-3854915487-3061028145-266851286-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Sheyenne Alvarez\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll No File
    CustomCLSID: HKU\S-1-5-21-3854915487-3061028145-266851286-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Sheyenne Alvarez\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-3854915487-3061028145-266851286-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Sheyenne Alvarez\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-3854915487-3061028145-266851286-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Sheyenne Alvarez\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-3854915487-3061028145-266851286-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Sheyenne Alvarez\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-3854915487-3061028145-266851286-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Sheyenne Alvarez\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-3854915487-3061028145-266851286-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Sheyenne Alvarez\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-3854915487-3061028145-266851286-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Sheyenne Alvarez\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-3854915487-3061028145-266851286-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Sheyenne Alvarez\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)

    ==================== Restore Points  =========================

    03-12-2014 00:20:31 Scheduled Checkpoint
    04-12-2014 15:25:11 Removed Bonjour
    04-12-2014 15:26:16 Removed Apple Software Update
    04-12-2014 15:27:01 Removed MAGIX Screenshare
    04-12-2014 15:39:53 OTL Restore Point - 12/4/2014 9:39:53 AM
    04-12-2014 16:18:28 zoek.exe restore point
    04-12-2014 21:48:29 zoek.exe restore point
    05-12-2014 13:21:13 Windows Update

    ==================== Hosts content: ==========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-13 20:34 - 2012-11-29 09:34 - 00444933 ____R C:\Windows\system32\Drivers\etc\hosts
    127.0.0.1    www.007guard.com
    127.0.0.1    007guard.com
    127.0.0.1    008i.com
    127.0.0.1    www.008k.com
    127.0.0.1    008k.com
    127.0.0.1    www.00hq.com
    127.0.0.1    00hq.com
    127.0.0.1    010402.com
    127.0.0.1    www.032439.com
    127.0.0.1    032439.com
    127.0.0.1    www.0scan.com
    127.0.0.1    0scan.com
    127.0.0.1    www.1000gratisproben.com
    127.0.0.1    1000gratisproben.com
    127.0.0.1    1001namen.com
    127.0.0.1    www.1001namen.com
    127.0.0.1    100888290cs.com
    127.0.0.1    www.100888290cs.com
    127.0.0.1    www.100sexlinks.com
    127.0.0.1    100sexlinks.com
    127.0.0.1    www.10sek.com
    127.0.0.1    10sek.com
    127.0.0.1    www.1-2005-search.com
    127.0.0.1    1-2005-search.com
    127.0.0.1    www.123fporn.info
    127.0.0.1    123fporn.info
    127.0.0.1    123haustiereundmehr.com
    127.0.0.1    www.123haustiereundmehr.com
    127.0.0.1    123moviedownload.com

    There are 1000 more lines.


    ==================== Scheduled Tasks (whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

    Task: {04BC54FA-9152-4DE0-BE2E-444C3F5C9FCC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2010-09-17] (Hewlett-Packard Company)
    Task: {07E3A5CB-7883-4DD4-9F8D-302D89F38159} - System32\Tasks\HPCeeScheduleForSHEYENNEALVAREZ$ => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard)
    Task: {0806E14A-453F-4FF9-A1B7-C65830B86392} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-3854915487-3061028145-266851286-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
    Task: {1518CA21-D798-4D7D-BDFE-A4846C35F4BC} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2014-10-07] (Microsoft Corporation)
    Task: {16CEF4F9-5348-43EC-9DEA-A04A3E0AF686} - System32\Tasks\MotoCast Update => C:\Program Files (x86)\Motorola Mobility\MotoCast\LiveUpdate\MotoCastUpdate.exe [2012-07-24] ()
    Task: {37ADA287-5189-4B2D-B6C4-DCF146E479D7} - System32\Tasks\DellPUDCTask => C:\Program Files\Dell\ProductUpdate\DKprodupdate.exe [2012-11-07] ()
    Task: {37C98F16-457E-4EFE-AA8E-4B5ADC381088} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2010-09-17] (Hewlett-Packard Company)
    Task: {3DF218A0-9271-47F0-9589-ED10D0789564} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3854915487-3061028145-266851286-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
    Task: {3E6806B4-4026-409C-83DC-388BB1552B9B} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3854915487-3061028145-266851286-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
    Task: {40CF9C14-E835-4F9E-86F2-F02A60128147} - System32\Tasks\Microsoft_Hardware_Launch_IPoint_exe => C:\Program Files\Microsoft IntelliPoint\IPoint.exe [2011-08-01] (Microsoft Corporation)
    Task: {46EBDAC0-ECC5-4427-ACDE-B289F755CF44} - System32\Tasks\Registration => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-09-27] ()
    Task: {64064343-31C8-4872-9070-6C6E694C5F7C} - System32\Tasks\Windows Codec Update Service => C:\Program Files (x86)\Essentials Codec Pack\WECPUpdate.exe [2012-02-03] (MediaCodec.Org)
    Task: {652F4364-E38C-4E09-ACDA-3A4B6A3E75CB} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3854915487-3061028145-266851286-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe
    Task: {67126892-4345-41D5-9C73-A71B1217A0F4} - System32\Tasks\HPCeeScheduleForSheyenne Alvarez => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14] (Hewlett-Packard)
    Task: {6B2234F7-0C51-4A95-901A-1BD4EE6C1DFE} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3854915487-3061028145-266851286-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe
    Task: {6BCCEA1B-00D9-4562-9B5D-B5E6AC4DD94F} - System32\Tasks\Motorola Device Manager Update => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2012-09-28] ()
    Task: {6D87675B-A378-42E5-902A-69BEB3164068} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-29] (Google Inc.)
    Task: {7792E4E1-79B4-49F1-81A6-43C75CDE9709} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
    Task: {79C85E14-50A2-48E1-BCDC-F064107C839A} - System32\Tasks\Motorola Device Manager Initial Update => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2012-09-28] ()
    Task: {7C1981EC-C19C-4B48-AC80-B6971C48293C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-04] (Adobe Systems Incorporated)
    Task: {86876246-5D45-4CCD-BEFF-8BD4FFDD93CD} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3854915487-3061028145-266851286-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe
    Task: {885E255B-4297-4B3D-93C1-9517BC8815B0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-29] (Google Inc.)
    Task: {A5DF02EC-EFE3-4AA7-AAF5-DD87496B76EB} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-3854915487-3061028145-266851286-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe
    Task: {AF052DEA-23F9-42E7-BCD3-31B8243FB8B3} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-10-07] (Microsoft Corporation)
    Task: {D4922A31-5DF3-40A1-9910-10FCD2935166} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2014-10-22] (Microsoft Corporation)
    Task: {D54E9B9C-8923-4681-8912-B86756B50353} - System32\Tasks\Motorola Device Manager Engine => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2012-09-28] ()
    Task: {D69CCBC8-D4AF-4F37-998F-FD20E1626662} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2014-10-07] (Microsoft Corporation)
    Task: {F0BD8852-5026-4A5D-9173-86E5964E6742} - System32\Tasks\Hewlett-Packard\HP Support Assistant\GetAssistance Maintenance Events => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\HPSAObjUtil.exe [2011-06-15] (HP)
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\HPCeeScheduleForSheyenne Alvarez.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
    Task: C:\Windows\Tasks\HPCeeScheduleForSHEYENNEALVAREZ$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

    ==================== Loaded Modules (whitelisted) =============

    2011-03-05 23:13 - 2009-11-26 01:09 - 00053760 _____ () C:\Windows\System32\DLEEPMON.DLL
    2011-03-05 23:13 - 2009-01-13 07:15 - 05709824 _____ () C:\Windows\System32\DLEEOEM.DLL
    2014-05-24 19:46 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
    2012-10-02 12:45 - 2012-10-02 12:45 - 00120728 _____ () C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
    2014-06-05 11:06 - 2012-09-11 22:14 - 00390672 _____ () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
    2013-10-12 21:42 - 2012-08-23 02:17 - 00276992 _____ () C:\Program Files\Dell\DKADG\DKabmini.dll
    2013-10-12 21:39 - 2012-11-07 21:54 - 00951656 _____ () C:\Program Files (x86)\Dell V520 Series\DKADGmon.exe
    2013-10-12 21:38 - 2012-11-07 21:54 - 00644456 _____ () C:\Program Files (x86)\Dell\ErrorApp\dkab1err.exe
    2012-11-28 20:19 - 2009-07-20 12:35 - 00018960 _____ () C:\Program Files\Logitech\SetPoint\khalwrapper.dll
    2012-11-28 20:19 - 2009-07-20 04:00 - 00077824 _____ () C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
    2012-10-02 12:41 - 2012-10-02 12:41 - 00694168 _____ () C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe
    2012-10-19 13:46 - 2012-10-19 13:46 - 00240056 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe
    2014-11-16 04:56 - 2014-09-23 07:36 - 08897696 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
    2012-12-17 17:14 - 2012-12-17 17:14 - 00954848 _____ () C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll
    2014-04-23 15:05 - 2014-04-23 15:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    2014-04-23 15:04 - 2014-04-23 15:04 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    2012-09-07 20:35 - 2012-09-07 20:35 - 00128960 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\liveupdatetactics.dll
    2012-09-07 20:35 - 2012-09-07 20:35 - 00024496 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\DbAccess.dll
    2012-09-07 20:37 - 2012-09-07 20:37 - 00466256 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\sqlite3.dll
    2012-09-07 20:36 - 2012-09-07 20:36 - 00045992 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\NAdvLog.dll
    2012-09-07 20:36 - 2012-09-07 20:36 - 00034752 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\NFileCacheDBAccess.dll
    2012-09-26 15:57 - 2012-09-26 15:57 - 00172032 _____ () C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\css_core.dll
    2013-02-05 09:11 - 2013-02-05 09:11 - 00465824 _____ () C:\Program Files (x86)\NTI\NTI Backup Now EZ\sqlite3.dll
    2014-11-16 04:56 - 2014-09-23 05:43 - 08897696 _____ () C:\Program Files\Microsoft Office 15\root\Office15\1033\GrooveIntlResource.dll
    2013-10-12 21:39 - 2012-08-22 05:05 - 01490944 _____ () C:\Program Files (x86)\Dell V520 Series\dkabdrs.dll
    2013-10-12 21:38 - 2012-08-07 06:37 - 00217088 _____ () C:\Program Files (x86)\Dell\ErrorApp\dkab1err.dll
    2014-12-05 07:23 - 2014-12-05 07:23 - 00205824 ____N () C:\Users\Sheyenne Alvarez\AppData\Local\Temp\WindowsAPI.dll2846028355686454031.lib
    2014-12-04 15:54 - 2014-12-04 15:54 - 00509440 _____ () C:\Users\Sheyenne Alvarez\AppData\Local\Temp\sqlite-3.6.20-sqlitejdbc.dll
    2014-12-05 07:25 - 2014-12-05 07:25 - 00314368 ____N () C:\Users\Sheyenne Alvarez\AppData\Local\Temp\WindowsFolderWatcher.dll7211322632047957154.lib
    2014-12-05 07:25 - 2014-12-05 07:25 - 00160256 ____N () C:\Users\Sheyenne Alvarez\AppData\Local\Temp\ZumoLocalGateway.dll7735880139492256696.lib
    2014-12-05 07:31 - 2014-12-05 07:31 - 00553984 ____N () C:\Users\Sheyenne Alvarez\AppData\Local\Temp\zumotaglib.dll5206817284887686949.lib
    2012-10-19 13:46 - 2012-10-19 13:46 - 00699392 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstreamer-0.10.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 01396736 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libxml2-2.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00085504 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\z.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00030208 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstadder.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00471552 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\liborc-0.4-0.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00253440 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstbase-0.10.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00109568 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstaudio-0.10.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00053760 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstinterfaces-0.10.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00014848 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstadpcmdec.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00038400 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstaiff.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00018944 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstalaw.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00048640 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstalpha.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00126976 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstcontroller-0.10.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00038912 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstvideo-0.10.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00017920 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstalphacolor.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00020480 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstamrnb.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00248352 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libopencore-amrnb.0.1.1.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00014848 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstamrwbdec.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00123947 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libopencore-amrwb.0.1.1.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00015360 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstapetag.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00133120 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgsttag-0.10.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00098304 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstpbutils-0.10.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00078848 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstaudioconvert.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00020480 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstaudiorate.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00052224 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstaudioresample.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00019456 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstauparse.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00032256 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstautoconvert.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00029184 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstautodetect.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00123904 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstavi.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00041984 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstriff-0.10.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00212480 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstcoreelements.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00011776 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstcoreindexers.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00016896 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstcutter.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00086016 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstdecodebin2.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00091136 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstdshowdecwrapper.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00073216 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstdshowsrcwrapper.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00026624 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstequalizer.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00187904 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstffmpegcolorspace.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00069120 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflac.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00331264 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libFLAC-8.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00023552 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libogg-0.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 01694208 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstfluaacdec.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00122880 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstfluasfdemux.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 02009600 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstfluh264dec.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00033280 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflumcaacenc.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00036864 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflumch264enc.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00088064 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflummssrc.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 01376256 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflump3dec.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 01563136 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflump3enc.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00363008 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflumpeg2video.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00531968 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflumpeg4video.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00119296 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflumpegdemux.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00075776 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflv.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00029696 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstgdp.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00018944 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstdataprotocol-0.10.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00037888 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstgio.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00032256 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstid3demux.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00034304 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstid3tag.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00035840 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstinterleave.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00276480 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstisomp4.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00069632 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstrtp-0.10.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00059904 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstjpeg.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00276992 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libjpeg-8.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00019456 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstlevel.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00207872 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmatroska.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00047616 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmpegaudioparse.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00150528 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmpegdemux.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00039936 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmpegtsmux.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00024576 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmpegvideoparse.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00015360 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmulaw.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00020480 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmultifile.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00025088 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmultipart.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00132608 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstogg.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00029184 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstpng.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00190976 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libpng14-14.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00035328 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstreplaygain.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00011264 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstshift.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00054784 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstsmpte.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00051712 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstsubparse.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00061952 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgsttypefindfunctions.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00059904 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstvideobox.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00032768 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstvideocrop.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00024576 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstvideorate.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00075776 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstvideoscale.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00034304 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstvolume.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00053760 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstvorbis.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00162304 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libvorbis-0.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 01520128 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libvorbisenc-2.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00050688 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstwavpack.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00196608 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libwavpack-1.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00042496 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstwavparse.dll
    2012-10-19 13:46 - 2012-10-19 13:46 - 00013312 _____ () C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgsty4menc.dll
    2014-11-10 08:38 - 2014-11-26 10:40 - 03758192 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

    ==================== Alternate Data Streams (whitelisted) =========

    (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

    AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1

    ==================== Safe Mode (whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== EXE Association (whitelisted) =============

    (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


    ==================== MSCONFIG/TASK MANAGER disabled items =========

    (Currently there is no automatic fix for this section.)

    MSCONFIG\Services: AMD External Events Utility => 2
    MSCONFIG\Services: dleeCATSCustConnectService => 2
    MSCONFIG\Services: dlee_device => 2
    MSCONFIG\Services: FirebirdServerMAGIXInstance => 3
    MSCONFIG\Services: GameConsoleService => 3
    MSCONFIG\Services: gupdate => 2
    MSCONFIG\Services: gupdatem => 3
    MSCONFIG\Services: gusvc => 3
    MSCONFIG\Services: HP Health Check Service => 2
    MSCONFIG\Services: HPClientSvc => 2
    MSCONFIG\Services: HPDrvMntSvc.exe => 2
    MSCONFIG\Services: hpqwmiex => 3
    MSCONFIG\Services: LightScribeService => 2
    MSCONFIG\Services: NOBU => 2
    MSCONFIG\Services: pdfcDispatcher => 2
    MSCONFIG\Services: RoxioNow Service => 2
    MSCONFIG\Services: YahooAUService => 2
    MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Snapfish PictureMover.lnk => C:\Windows\pss\Snapfish PictureMover.lnk.CommonStartup
    MSCONFIG\startupreg: HP Software Update => c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
    MSCONFIG\startupreg: hpsysdrv => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
    MSCONFIG\startupreg: Microsoft Default Manager => "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
    MSCONFIG\startupreg: Norton Online Backup => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
    MSCONFIG\startupreg: PDF Complete => C:\Program Files (x86)\PDF Complete\pdfsty.exe
    MSCONFIG\startupreg: SmartMenu => C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background
    MSCONFIG\startupreg: StartCCC => "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

    ========================= Accounts: ==========================

    Administrator (S-1-5-21-3854915487-3061028145-266851286-500 - Administrator - Disabled)
    Dario Jr (S-1-5-21-3854915487-3061028145-266851286-1004 - Limited - Enabled) => C:\Users\Dario Jr
    Gabriella (S-1-5-21-3854915487-3061028145-266851286-1003 - Limited - Enabled) => C:\Users\Gabriella
    Guest (S-1-5-21-3854915487-3061028145-266851286-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-3854915487-3061028145-266851286-1002 - Limited - Enabled)
    Roman (S-1-5-21-3854915487-3061028145-266851286-1005 - Limited - Enabled) => C:\Users\Roman
    Sheyenne Alvarez (S-1-5-21-3854915487-3061028145-266851286-1000 - Administrator - Enabled) => C:\Users\Sheyenne Alvarez

    ==================== Faulty Device Manager Devices =============

    Name:
    Description:
    Class Guid:
    Manufacturer:
    Service:
    Problem: : The drivers for this device are not installed. (Code 28)
    Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (12/05/2014 09:55:31 AM) (Source: SideBySide) (EventID: 80) (User: )
    Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
    A component version required by the application conflicts with another component version already active.
    Conflicting components are:.
    Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
    Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.


    System errors:
    =============

    Microsoft Office Sessions:
    =========================
    Error: (12/05/2014 09:55:31 AM) (Source: SideBySide) (EventID: 80) (User: )
    Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Sheyenne Alvarez\Downloads\esetsmartinstaller_enu.exe


    ==================== Memory info ===========================

    Processor: AMD Phenom™ II X4 840T Processor
    Percentage of memory in use: 38%
    Total physical RAM: 3839.29 MB
    Available physical RAM: 2358.98 MB
    Total Pagefile: 7676.75 MB
    Available Pagefile: 5425.32 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.81 MB

    ==================== Drives ================================

    Drive c: (OS) (Fixed) (Total:918.5 GB) (Free:143.85 GB) NTFS
    Drive e: (HP_RECOVERY) (Fixed) (Total:12.92 GB) (Free:1.59 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    Drive k: (VERBATIM) (Fixed) (Total:465.65 GB) (Free:0 GB) FAT32

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 931.5 GB) (Disk ID: 3E71B14F)
    Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=918.5 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=12.9 GB) - (Type=07 NTFS)

    ========================================================
    Disk: 1 (Size: 465.8 GB) (Disk ID: 685B278B)
    Partition 1: (Not Active) - (Size=465.8 GB) - (Type=0C)

    ==================== End Of Log ============================


    • 0

    #25
    Biscuithd

    Biscuithd

      Trusted Helper

    • Malware Removal
    • 2,573 posts

    We're getting a little closer with each step. Run the fix. Post the results and let me know how the machine is working.

     

    FRST.gif Fix with Farbar Recovery Scan Tool



    icon_exclaim.gif This fix was created for this user for use on that particular machine. icon_exclaim.gif
    icon_exclaim.gif Running it on another one may cause damage and render the system unstable. icon_exclaim.gif

    Press the WindowsKey.png + R on your keyboard at the same time. Type Notepad and click OK.

    • Copy the entire content of the codebox below and paste into the Notepad document:
      start
      
      EmptyTemp:
      
      Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
      
      GroupPolicyUsers\S-1-5-21-3854915487-3061028145-266851286-1003\User: Group Policy restriction detected <======= ATTENTION
      
      ATTENTION: ====> ZeroAccess. Use DeleteJunctionsIndirectory: C:\Windows\system64
      
      AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1
      
      
      
      end
    • Click File, Save As and type fixlist.txt as the File Name.

    Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!


    • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
      (XP users click run after receipt of Windows Security Warning - Open File).
    • Press the Fix button just once and wait.
    • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
    • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

    Please post it to your reply.

     


    • 0

    Advertisements


    #26
    sheyennelilly

    sheyennelilly

      Member

    • Topic Starter
    • Member
    • PipPip
    • 65 posts

    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 03-12-2014
    Ran by Sheyenne Alvarez at 2014-12-05 14:40:01 Run:1
    Running from C:\Users\Sheyenne Alvarez\Desktop
    Loaded Profile: Sheyenne Alvarez (Available profiles: Sheyenne Alvarez & Gabriella & Dario Jr & Roman)
    Boot Mode: Normal
    ==============================================

    Content of fixlist:
    *****************
    start

    EmptyTemp:

    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt

    GroupPolicyUsers\S-1-5-21-3854915487-3061028145-266851286-1003\User: Group Policy restriction detected <======= ATTENTION

    ATTENTION: ====> ZeroAccess. Use DeleteJunctionsIndirectory: C:\Windows\system64

    AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1



    end
    *****************

    C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
    Hosts was reset successfully.
    C:\Windows\system32\GroupPolicyUsers\S-1-5-21-3854915487-3061028145-266851286-1003\User => Moved successfully.
    "C:\Windows\system64" => Deleting reparse point and unlocking started.
    "C:\Windows\system64" => Deleting reparse point and unlocking done.
    "C:\Windows\system64" => Deleting reparse point and unlocking completed.
    C:\ProgramData\Temp => ":D1B5B4F1" ADS removed successfully.
    EmptyTemp: => Removed 413.5 MB temporary data.


    The system needed a reboot.

    ==== End of Fixlog ====


    • 0

    #27
    Biscuithd

    Biscuithd

      Trusted Helper

    • Malware Removal
    • 2,573 posts

    ...and, how is the machine doing?


    • 0

    #28
    sheyennelilly

    sheyennelilly

      Member

    • Topic Starter
    • Member
    • PipPip
    • 65 posts

    It's doing okay. I'm still getting invalid destination popups and some script errors.  I'm also getting a java updater popup that comes up all the time.  I've declined to install it because before when I was accepting the updates, things would start going wrong and I had to go back and install an earlier version to get my comoputer to run correctly.  Of course, maybe that had to do with something else.  Should I be accepting all those?  The popups come pretty much every day, sometimes multiple times a day.  When I would install, it didn't seem to slow down the popups asking for an update.


    • 0

    #29
    Biscuithd

    Biscuithd

      Trusted Helper

    • Malware Removal
    • 2,573 posts

    None of that is good or normal. Let's attack in this way.

     

    • Step #2 Scan with RogueKiller
      Delete the RogueKiller icon from your Desktop.Download link for 64 bit system
      • Download Rogue Killer from one of the suitable links below to your Desktop. Since you are running a 64bit system, choose the second link. smile.gif.pagespeed.ce.8xZGdnoS_z3a203jIDownload link for 32 bit system
    • Let the pre-scan finish. After that click on Scan;
    • The scan won't take long;
    • A log has been created on your Desktop;
    • Copy and paste the content of the log in your next reply.
    • Step #3 Scan with Security Check
      • Download Security Check by screen317 to your Desktop from any of the following location;
      • Link 1
      • Link 2
    • Right click on the program and choose Run as Administrator;
    • After the checking a log will appear;
    • Copy and Paste the content of the log in your next reply.

    • 0

    #30
    sheyennelilly

    sheyennelilly

      Member

    • Topic Starter
    • Member
    • PipPip
    • 65 posts

    I ran Roguekiller but I don't see a log.  And I was a bit confused by the instructions.  You said to erase the Roguekiller icon but I didn't see one, so I just installed and ran the one off the second link you provided (the first one didn't work for me).  But the second one said 32 bit and I thought you said I had a 64 bit?  I downloaded the security check, but that one did have an icon already (did you mean to say that instead of Roguekiller?)  So I deleted the first icon after installing the second.  I hope I'm doing things right...

     

    Security check log:

     

     Results of screen317's Security Check version 0.99.91  
     Windows 7 Service Pack 1 x64 (UAC is enabled)  
     Internet Explorer 11  
    ``````````````Antivirus/Firewall Check:``````````````
     Windows Firewall Enabled!  
    Microsoft Security Essentials   
     Antivirus up to date!  
    `````````Anti-malware/Other Utilities Check:`````````
     Spybot - Search & Destroy
     Java 7 Update 67  
     Java version 32-bit out of Date!
     Adobe Flash Player 15.0.0.239  
     Adobe Reader XI  
     Mozilla Firefox (34.0.5)
    ````````Process Check: objlist.exe by Laurent````````  
     Microsoft Security Essentials MSMpEng.exe
     Microsoft Security Essentials msseces.exe
     Malwarebytes Anti-Malware mbamservice.exe  
     Malwarebytes Anti-Malware mbam.exe  
     Malwarebytes Anti-Malware mbamscheduler.exe   
     Symantec Norton Online Backup NOBuAgent.exe  
    `````````````````System Health check`````````````````
     Total Fragmentation on Drive C: 13% Defragment your hard drive soon! (Do NOT defrag if SSD!)
    ````````````````````End of Log``````````````````````
     


    • 0






    Similar Topics

    0 user(s) are reading this topic

    0 members, 0 guests, 0 anonymous users

    As Featured On:

    Microsoft Yahoo BBC MSN PC Magazine Washington Post HP