Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Tnulqltoe.exe *32 - multiple copies running - just won't stop!


  • This topic is locked This topic is locked

#1
HotTub1

HotTub1

    New Member

  • Member
  • Pip
  • 2 posts

Help!

 

I have multiple copies of something called Tnulqltoe.exe *32 running on my computer and eating up huge chunks of my CPU and physical memory.  It claims to have Google Chrome as a source.  I have uninstalled Google Chrome, but Tnulqltoe is still running.  What the heck is this...and how do I get rid of it?

 

I found one other post on here about this issue, but the solution given was extremely specific to that individual's computer and came with a warning not to attempt the solution on any other computer.  My computer is a HP Pavilion g7 running Windows 7 Home Premium.


  • 0

Advertisements


#2
Nevan

Nevan

    Trusted Helper

  • Malware Removal
  • 1,765 posts
Hello, HotTub1. Welcome to Geeks to Go! My nickname is Nevan and I will be helping you getting your system back on its electronic feet.

Before we get started, please keep these things in mind:
  • Always read every part of my post carefully. If you don't, you may do something wrong and there could be more problems to solve.
  • If your security programs give you any warnings when using tools I asked you to, don't be afraid. Every tool I provide to you is 100% safe.
  • Only run tools that I ask you to. Some of them can be dangerous to your system as they have much power.
  • You should save or print my instructions. It is possible that we will be using Safe mode, which will cut you off from your internet connection and without access to them, you might be stuck.
  • Malware removal is a complicated process that takes multiple steps to be completed. Don't give up, be patient.
  • The tools we are going to use and your software may cause unwanted interactions. Because of that, I recommend you to make backups of any important files from your machine before proceeding as they might be lost.
  • I recommend you to stay with me until I tell you that we are done. It is important because when your system does not show any bad symptoms anymore it does not mean that it is 100% clean.
  • Your time to reply is limited. If you don't reply within 3 days, your topic will be closed and you will have to request it to be reopened by contacting one of Moderator group members with the link to this topic.
  • Every program I ask you to download should be saved to and run from desktop. If you don't know how to choose the direction of where a download is saved, check this site. You can also just copy these programs to your desktop manually and then run them from there.
  • Remember that the fixes I give you are only for your machine. Using it on other systems may (and probably will) cause problems.
  • Finally, if you have any questions or are unsure about something, just ask. I will not blame you for it. It is better to ask rather than regret it later.
Also, please note that I'm currently in training, so my answers to you will have to be checked first by an experienced helper before I can post them. This can lengthen the time between my answers to you, but in return you will have an extra person reviewing your log.

Let's get started :)

 
First, I'd like to have a look at your system. Please, do the following:

FRST Scan

Download Farbar Recovery Scan Tool and save it to your Desktop. There are two different versions:
  • Click here to download the 32-bit version.
  • Click here to download the 64-bit version.
If you don't know which version you should use, download one of them and check if it's working or not. If it doesn't, download the second one. Once you have the right one, perform the instructions below.
  • Right click FRST.exe (or FRST64.exe) and click Run as administrator. When the tool opens click Yes to disclaimer.
  • Make sure that Addition.txt is checked and press the Scan button.
  • It will produce two logs - one called FRST.txt and another one called Addition.txt in the same directory the tool is run from.
  • Select all (CTRL+A) the content of the logs, copy them (CTRL+C) and paste (CTRL+V) them into your next reply.
 
Things that should appear in your next post:
  • FRST.txt log content
  • Addition.txt log content

  • 0

#3
HotTub1

HotTub1

    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts

Here ya' go....

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-01-2015
Ran by Bryan (administrator) on BRYAN-HP on 28-01-2015 17:46:05
Running from C:\Users\Bryan\Desktop
Loaded Profiles: Bryan (Available profiles: Bryan)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(HP) C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(HP) C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
() C:\Program Files (x86)\Backblaze\bzserv.exe
(SOS Online Backup) C:\Program Files (x86)\SOS Online Backup\SUpdateNotifier.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(HP) C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\n360.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\n360.exe
() C:\Program Files (x86)\Amazon Browser Bar\ToolbarUpdaterService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe
(SecureKey Technologies Inc.) C:\Users\Bryan\AppData\Local\SecureKey\SKDeviceAccess\2.0.6777.6940\skdevicemonitorwin.exe
(PC Drivers Headquarters) C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe
(Microsoft Corporation) C:\Windows\System32\regsvr32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\regsvr32.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPNetworkCommunicator.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(SOS Online Backup) C:\Program Files (x86)\SOS Online Backup\SMessaging.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(WildTangent, Inc.) C:\Program Files (x86)\HP Games\Bejeweled 3\bejeweled3-WT.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_16_0_0_296_ActiveX.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\39.0.2171.99\nacl64.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exe
(Google Inc.) C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exe

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2799912 2011-06-09] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1424896 2011-09-08] (IDT, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-06-16] (Adobe Systems Incorporated)
HKLM\...\Run: [SetDefault] => C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe [44880 2011-12-19] (Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [HPQuickWebProxy] => C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [169528 2011-10-07] (Hewlett-Packard Company)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [578944 2012-03-05] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [SOSUAUI] => C:\Program Files (x86)\SOS Online Backup\sosuploadagent.exe [55680 2013-03-07] (SOS Online Backup)
HKLM-x32\...\Run: [SMessaging] => C:\Program Files (x86)\SOS Online Backup\SMessaging.exe [66432 2013-03-07] (SOS Online Backup)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-08-19] (Hewlett-Packard)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-22227049-1486026924-1849314948-1000\...\Run: [HP Deskjet 3050A J611 series (NET)] => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe [2547048 2011-03-30] (Hewlett-Packard Co.)
HKU\S-1-5-21-22227049-1486026924-1849314948-1000\...\Run: [] => C:\Users\Bryan\AppData\Local\SecureKey\SKDeviceAccess\2.0.6777.6940\skdevicemonitorwin.exe [447488 2013-01-22] (SecureKey Technologies Inc.)
HKU\S-1-5-21-22227049-1486026924-1849314948-1000\...\Run: [Backblaze] => C:\Program Files (x86)\Backblaze\bzbui.exe [493672 2014-11-22] ()
HKU\S-1-5-21-22227049-1486026924-1849314948-1000\...\Run: [Driver Support] => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [4785504 2014-05-07] (PC Drivers Headquarters)
HKU\S-1-5-21-22227049-1486026924-1849314948-1000\...\Run: [Otgpuozkwdji] => regsvr32.exe /s "C:\Users\Bryan\AppData\Local\{060B4D46-5A49-4A24-B141-6FFEB600D16D}\Otgpuozkwdji.dll" <===== ATTENTION
HKU\S-1-5-21-22227049-1486026924-1849314948-1000\...\MountPoints2: {570be2e1-b2e1-11e1-bb17-806e6f6e6963} - F:\HWMenu.exe
HKU\S-1-5-21-22227049-1486026924-1849314948-1000\...\MountPoints2: {c043137b-b55e-11e1-ba56-80c16e44a3de} - H:\LaunchU3.exe -a
HKU\S-1-5-18\...\Run: [Backblaze] => C:\Program Files (x86)\Backblaze\bzbui.exe [493672 2014-11-22] ()
AppInit_DLLs: C:\PROGRA~2\Amazon\AMAZON~1\AMAZON~2.DLL => C:\Program Files (x86)\Amazon\Amazon1ButtonApp\AmazonExtIE64.dll [155456 2013-12-15] ()
AppInit_DLLs-x32: C:\PROGRA~2\Amazon\AMAZON~1\\AMAZON~3.DLL => C:\Program Files (x86)\Amazon\Amazon1ButtonApp\\AmazonExtIE.dll [138048 2013-12-15] ()
Startup: C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\buShell.dll (Symantec Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-22227049-1486026924-1849314948-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
HKU\S-1-5-21-22227049-1486026924-1849314948-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
URLSearchHook: HKLM-x32 - MixiDJ V8 Toolbar - {e4c3a8b6-7724-45d1-a629-17b69118ebcd} - C:\Program Files (x86)\MixiDJ_V8\prxtbMixi.dll (Conduit Ltd.)
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...rc=IE-SearchBox
SearchScopes: HKLM -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.co...&l=dis&o=HPNTDF
SearchScopes: HKLM -> {AA035470-E3CA-48E3-9386-6F3A5E19784E} URL = http://www.amazon.co...ds={searchTerms}
SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://search.yahoo....psg&type=HPNTDF
SearchScopes: HKLM -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia....ch={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.co...kw={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...rc=IE-SearchBox
SearchScopes: HKLM-x32 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.co...&l=dis&o=HPNTDF
SearchScopes: HKLM-x32 -> {AA035470-E3CA-48E3-9386-6F3A5E19784E} URL = http://www.amazon.co...ds={searchTerms}
SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://search.yahoo....psg&type=HPNTDF
SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia....ch={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.co...kw={searchTerms}
SearchScopes: HKU\S-1-5-21-22227049-1486026924-1849314948-1000 -> DefaultScope {B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} URL = http://www.amazon.co...ry={searchTerms}
SearchScopes: HKU\S-1-5-21-22227049-1486026924-1849314948-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...rc=IE-SearchBox
SearchScopes: HKU\S-1-5-21-22227049-1486026924-1849314948-1000 -> {0EDAFD03-373B-465B-B061-78F3025E0BC0} URL = http://search.condui...9605908343&UM=2
SearchScopes: HKU\S-1-5-21-22227049-1486026924-1849314948-1000 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.co...&l=dis&o=HPNTDF
SearchScopes: HKU\S-1-5-21-22227049-1486026924-1849314948-1000 -> {AA035470-E3CA-48E3-9386-6F3A5E19784E} URL = http://www.amazon.co...ds={searchTerms}
SearchScopes: HKU\S-1-5-21-22227049-1486026924-1849314948-1000 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = http://nortonsafe.se...t=kwd&qsrc=2869
SearchScopes: HKU\S-1-5-21-22227049-1486026924-1849314948-1000 -> {B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} URL = http://www.amazon.co...ry={searchTerms}
SearchScopes: HKU\S-1-5-21-22227049-1486026924-1849314948-1000 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = http://search.yahoo....psg&type=HPNTDF
SearchScopes: HKU\S-1-5-21-22227049-1486026924-1849314948-1000 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia....ch={searchTerms}
SearchScopes: HKU\S-1-5-21-22227049-1486026924-1849314948-1000 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.co...kw={searchTerms}
BHO: The Amazon 1Button App for IE -> {26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} -> C:\Program Files (x86)\Amazon\Amazon1ButtonApp\AmazonAppIE64.dll (Amazon Inc.)
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\coIEPlg.dll (Symantec Corporation)
BHO: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll (HP)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO: Systweak Toolbar for Internet Explorer -> {F0D6F486-7230-3139-1997-CB2FBCF4E080} -> C:\Program Files\Systweak Toolbar\systweak-64.dll (Systweak Software)
BHO-x32: The Amazon 1Button App for IE -> {26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} -> C:\Program Files (x86)\Amazon\Amazon1ButtonApp\AmazonAppIE.dll (Amazon Inc.)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\coIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll (HP)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO-x32: No Name -> {D40C654D-7C51-4EB3-95B2-1E23905C2A2D} ->  No File
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: MixiDJ V8 Toolbar -> {e4c3a8b6-7724-45d1-a629-17b69118ebcd} -> C:\Program Files (x86)\MixiDJ_V8\prxtbMixi.dll (Conduit Ltd.)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
BHO-x32: Systweak Toolbar for Internet Explorer -> {F0D6F486-7230-3139-1997-CB2FBCF4E080} -> C:\Program Files\Systweak Toolbar\systweak-32.dll (Systweak Software)
Toolbar: HKLM - Systweak Toolbar for Internet Explorer - {F0D6F486-7230-3139-1997-CB2FBCF4E080} - C:\Program Files\Systweak Toolbar\systweak-64.dll (Systweak Software)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - MixiDJ V8 Toolbar - {e4c3a8b6-7724-45d1-a629-17b69118ebcd} - C:\Program Files (x86)\MixiDJ_V8\prxtbMixi.dll (Conduit Ltd.)
Toolbar: HKLM-x32 - Systweak Toolbar for Internet Explorer - {F0D6F486-7230-3139-1997-CB2FBCF4E080} - C:\Program Files\Systweak Toolbar\systweak-32.dll (Systweak Software)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\coIEPlg.dll (Symantec Corporation)
Toolbar: HKU\S-1-5-21-22227049-1486026924-1849314948-1000 -> No Name - {E4C3A8B6-7724-45D1-A629-17B69118EBCD} -  No File
Toolbar: HKU\S-1-5-21-22227049-1486026924-1849314948-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-22227049-1486026924-1849314948-1000 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.6.0.32\coIEPlg.dll (Symantec Corporation)
DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.micros...n/ieawsdc32.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-22227049-1486026924-1849314948-1000: @securekey.com/DeviceAccess,version=1.0.0.0 -> C:\Users\Bryan\AppData\Local\SecureKey\SKDeviceAccess\2.0.6777.6940\npSKDeviceAccess.dll (SecureKey)
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.5.0.19\IPSFF
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.5.0.19\IPSFF [2014-08-27]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.5.0.19\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.5.0.19\coFFPlgn [2015-01-28]

Chrome:
=======
CHR Profile: C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (No Name) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-21]
CHR Extension: (No Name) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfmogjcijkfeahcajecmmegieipfbdcc [2014-01-21]
CHR Extension: (No Name) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof [2014-01-21]
CHR Extension: (No Name) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2014-01-21]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path
CHR HKLM\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\Exts\Chrome.crx [2014-10-03]
CHR HKU\S-1-5-21-22227049-1486026924-1849314948-1000\...\Chrome\Extension: [pbjikboenpfhbbejgkoklgkhjpfogcam] - C:\Program Files (x86)\Amazon\ABB\AmazonChrome-bds-amzn.crx [2014-01-31]
CHR HKLM-x32\...\Chrome\Extension: [bfmogjcijkfeahcajecmmegieipfbdcc] - C:\Program Files (x86)\HP SimplePass 2011\tschrome.crx [2011-08-18]
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path
CHR HKLM-x32\...\Chrome\Extension: [kiplfnciaokpcennlkldkdaeaaomamof] - C:\Users\Bryan\AppData\Local\Torch\Plugins\TorchPlugin.crx [2013-01-17]
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\Exts\Chrome.crx [2014-10-03]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeActiveFileMonitor10.0; C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [169624 2011-09-14] (Adobe Systems Incorporated)
R2 bzserv; C:\Program Files (x86)\Backblaze\bzserv.exe [234600 2014-11-22] ()
S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-03-11] (WildTangent)
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed]
R2 N360; C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\N360.exe [265040 2014-09-21] (Symantec Corporation)
R2 Updater Service for AMZN; C:\Program Files (x86)\Amazon Browser Bar\ToolbarUpdaterService.exe [222368 2013-03-21] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\21.5.0.19\Definitions\BASHDefs\20150106.001\BHDrvx64.sys [1622744 2015-01-06] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1506000.020\ccSetx64.sys [162392 2014-02-20] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-12-11] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142640 2014-12-11] (Symantec Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\21.5.0.19\Definitions\IPSDefs\20150127.001\IDSvia64.sys [668888 2015-01-14] (Symantec Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\21.5.0.19\Definitions\VirusDefs\20150127.040\ENG64.SYS [129752 2015-01-20] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\21.5.0.19\Definitions\VirusDefs\20150127.040\EX64.SYS [2137304 2015-01-20] (Symantec Corporation)
R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1506000.020\SRTSP64.SYS [876248 2014-08-25] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1506000.020\SRTSPX64.SYS [37592 2014-08-25] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\1506000.020\SYMDS64.SYS [493656 2014-07-22] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\1506000.020\SYMEFA64.SYS [1148120 2014-07-22] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2014-08-27] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\1506000.020\Ironx64.SYS [266968 2014-08-06] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1506000.020\SYMNETS.SYS [593112 2014-07-22] (Symantec Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-28 17:46 - 2015-01-28 17:47 - 00028916 _____ () C:\Users\Bryan\Desktop\FRST.txt
2015-01-28 17:44 - 2015-01-28 17:46 - 00000000 ____D () C:\FRST
2015-01-28 17:42 - 2015-01-28 17:43 - 02130432 _____ (Farbar) C:\Users\Bryan\Desktop\FRST64.exe
2015-01-24 13:55 - 2014-12-12 23:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-01-24 13:55 - 2014-12-12 21:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-01-23 07:12 - 2015-01-23 07:12 - 00000000 ____D () C:\Windows\system32\appraiser
2015-01-23 06:32 - 2014-10-17 20:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-01-23 06:32 - 2014-10-17 19:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2015-01-23 06:32 - 2014-07-06 20:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2015-01-23 06:32 - 2014-07-06 20:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2015-01-23 06:32 - 2014-07-06 20:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2015-01-23 06:32 - 2014-07-06 20:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2015-01-23 06:32 - 2014-07-06 19:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2015-01-23 06:32 - 2014-07-06 19:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2015-01-23 06:32 - 2014-07-06 19:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2015-01-23 06:32 - 2014-07-06 19:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2015-01-22 07:44 - 2014-12-03 20:50 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-01-22 07:44 - 2014-12-03 20:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-01-22 07:44 - 2014-12-03 20:50 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-01-22 07:44 - 2014-12-03 20:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-01-22 07:44 - 2014-12-03 20:50 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-01-22 07:44 - 2014-12-03 20:44 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-01-22 07:44 - 2014-12-01 17:28 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2015-01-21 11:06 - 2015-01-21 11:30 - 00000000 ____D () C:\Users\Bryan\Documents\JOP
2015-01-21 08:08 - 2014-11-26 19:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-01-21 08:08 - 2014-11-26 19:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-01-21 08:08 - 2014-11-21 21:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-01-21 08:08 - 2014-11-21 21:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-01-21 08:08 - 2014-11-21 21:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-01-21 08:08 - 2014-11-21 20:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-01-21 08:08 - 2014-11-21 20:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-01-21 08:08 - 2014-11-21 20:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-01-21 08:08 - 2014-11-21 20:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-01-21 08:08 - 2014-11-21 20:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-01-21 08:08 - 2014-11-21 20:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-01-21 08:08 - 2014-11-21 20:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-01-21 08:08 - 2014-11-21 20:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-01-21 08:08 - 2014-11-21 20:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-01-21 08:08 - 2014-11-21 20:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-01-21 08:08 - 2014-11-21 20:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-01-21 08:08 - 2014-11-21 20:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-01-21 08:08 - 2014-11-21 20:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-01-21 08:08 - 2014-11-21 20:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-01-21 08:08 - 2014-11-21 20:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-01-21 08:08 - 2014-11-21 20:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-01-21 08:08 - 2014-11-21 20:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-01-21 08:08 - 2014-11-21 20:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-01-21 08:08 - 2014-11-21 20:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-01-21 08:08 - 2014-11-21 20:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-01-21 08:08 - 2014-11-21 20:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-01-21 08:08 - 2014-11-21 20:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-01-21 08:08 - 2014-11-21 20:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-01-21 08:08 - 2014-11-21 20:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-01-21 08:08 - 2014-11-21 19:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-01-21 08:08 - 2014-11-21 19:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-01-21 08:08 - 2014-11-21 19:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-01-21 08:08 - 2014-11-21 19:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-01-21 08:08 - 2014-11-21 19:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-01-21 08:08 - 2014-11-21 19:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-01-21 08:08 - 2014-11-21 19:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-01-21 08:08 - 2014-11-21 19:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-01-21 08:08 - 2014-11-21 19:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-01-21 08:08 - 2014-11-21 19:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-01-21 08:08 - 2014-11-21 19:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-01-21 08:08 - 2014-11-21 19:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-01-21 08:08 - 2014-11-21 19:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-01-21 08:08 - 2014-11-21 19:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-01-21 08:08 - 2014-11-21 19:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-01-21 08:08 - 2014-11-21 19:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-01-21 08:08 - 2014-11-21 19:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-01-21 08:08 - 2014-11-21 19:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-01-21 08:08 - 2014-11-21 19:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-01-21 08:08 - 2014-11-21 19:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-01-21 08:08 - 2014-11-21 19:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-01-21 08:08 - 2014-11-21 19:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-01-21 08:08 - 2014-11-21 19:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-01-21 08:08 - 2014-11-21 18:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-01-21 08:08 - 2014-11-21 18:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-01-21 08:08 - 2014-11-10 21:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-01-21 08:08 - 2014-11-10 20:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-01-21 08:08 - 2014-11-10 19:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2015-01-21 08:07 - 2014-11-07 21:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-01-21 08:07 - 2014-11-07 20:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2015-01-21 08:07 - 2014-10-29 20:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2015-01-21 08:07 - 2014-10-29 19:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2015-01-21 08:07 - 2014-10-02 20:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2015-01-21 08:07 - 2014-10-02 20:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2015-01-21 08:07 - 2014-10-02 20:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2015-01-21 08:07 - 2014-10-02 20:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2015-01-21 08:07 - 2014-10-02 20:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2015-01-21 08:07 - 2014-10-02 19:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2015-01-21 08:07 - 2014-10-02 19:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2015-01-21 08:07 - 2014-10-02 19:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2015-01-21 08:07 - 2014-10-02 19:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2015-01-21 08:07 - 2014-10-02 19:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2015-01-20 09:44 - 2015-01-20 09:44 - 00000000 ____D () C:\Users\Bryan\AppData\Roaming\com.StudioCloud.Desktop.3
2015-01-20 09:27 - 2015-01-20 09:27 - 00000036 _____ () C:\Users\Bryan\.StudioCloudDesktop.log
2015-01-20 09:27 - 2015-01-20 09:27 - 00000000 ____D () C:\Users\Bryan\Documents\StudioCloud Invoices
2015-01-20 09:27 - 2015-01-20 09:27 - 00000000 ____D () C:\Users\Bryan\AppData\Roaming\com.StudioCloud.Desktop.3.F2DAE273367737D97F8409B8C86CCCEDC39FC38E.1
2015-01-20 09:24 - 2015-01-20 17:27 - 00000000 ____D () C:\Program Files (x86)\StudioCloud 3.0
2015-01-20 09:24 - 2015-01-20 09:24 - 00000955 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StudioCloud 3.0.lnk
2015-01-20 09:24 - 2015-01-20 09:24 - 00000943 _____ () C:\Users\Public\Desktop\StudioCloud 3.0.lnk
2015-01-20 09:21 - 2015-01-20 09:21 - 29038888 _____ () C:\Users\Bryan\Downloads\StudioCloudDesktop.air
2015-01-16 21:50 - 2015-01-16 21:50 - 00010447 _____ () C:\Users\Bryan\Documents\Bonsai.xlsx
2015-01-16 15:13 - 2015-01-28 16:58 - 00210857 _____ () C:\Users\Bryan\Documents\JOP SENIORS.xlsx
2015-01-15 18:12 - 2014-12-18 19:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 17:24 - 2014-12-18 21:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 17:24 - 2014-12-11 23:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 17:24 - 2014-12-11 23:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-14 17:24 - 2014-12-11 23:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-14 17:24 - 2014-12-11 23:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-14 17:24 - 2014-12-11 23:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 17:24 - 2014-12-11 23:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 17:24 - 2014-12-11 23:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-14 17:24 - 2014-12-11 11:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 17:24 - 2014-12-05 22:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 17:24 - 2014-12-05 21:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 17:24 - 2014-12-05 21:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-11 11:53 - 2015-01-23 12:19 - 20247043 _____ () C:\Users\Bryan\Documents\$ $  MONEY  $ $.xlsx
2014-12-29 00:14 - 2015-01-27 22:57 - 00185782 _____ () C:\Users\Bryan\Documents\JUST DO IT ! ! ! 2015.xlsx

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-28 17:45 - 2011-12-12 02:31 - 01196840 _____ () C:\Windows\WindowsUpdate.log
2015-01-28 17:18 - 2012-07-21 08:16 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-28 16:05 - 2013-03-04 10:04 - 00000486 _____ () C:\Windows\Tasks\SOS Online Backup - [email protected]
2015-01-28 16:05 - 2013-03-04 09:51 - 00000000 ____D () C:\ProgramData\SOS Online Backup
2015-01-28 15:33 - 2011-12-12 02:41 - 00000000 ____D () C:\Program Files (x86)\HP SimplePass 2011
2015-01-28 12:01 - 2012-06-28 11:19 - 00000000 ____D () C:\Users\Bryan\AppData\Local\CrashDumps
2015-01-28 10:34 - 2012-06-13 14:14 - 00000000 ___RD () C:\Users\Bryan\Documents\AAA Writing
2015-01-28 07:46 - 2014-01-21 05:26 - 00000000 ____D () C:\Program Files (x86)\Google
2015-01-28 07:19 - 2009-07-13 22:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-28 07:19 - 2009-07-13 22:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-28 07:02 - 2012-06-13 11:44 - 00057856 _____ () C:\Users\Bryan\Documents\Z Bogey.xls
2015-01-28 06:54 - 2014-01-21 05:27 - 00000000 ____D () C:\ProgramData\Google
2015-01-28 06:54 - 2014-01-21 05:26 - 00000000 ____D () C:\Users\Bryan\AppData\Local\Google
2015-01-28 06:41 - 2009-07-13 23:13 - 00795858 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-28 06:34 - 2013-03-04 09:51 - 00000454 _____ () C:\Windows\Tasks\Online Backup Update Notifier.job
2015-01-28 06:34 - 2012-06-19 10:36 - 00000332 _____ () C:\Windows\Tasks\HPCeeScheduleForBryan.job
2015-01-28 06:34 - 2010-11-20 21:47 - 00970246 _____ () C:\Windows\PFRO.log
2015-01-28 06:34 - 2009-07-13 23:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-28 06:34 - 2009-07-13 22:51 - 00064516 _____ () C:\Windows\setupact.log
2015-01-27 23:26 - 2014-04-19 18:15 - 00000000 ____D () C:\Users\Bryan\Documents\Games
2015-01-27 23:01 - 2012-07-21 12:32 - 00000000 ____D () C:\Users\Bryan\AppData\Local\{060B4D46-5A49-4A24-B141-6FFEB600D16D}
2015-01-27 19:00 - 2012-06-09 08:00 - 00003926 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{3812758F-4DDE-43B6-95A5-43BB0A3B9765}
2015-01-26 23:17 - 2012-06-19 10:36 - 00003186 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForBryan
2015-01-25 21:15 - 2012-07-21 08:16 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-25 21:15 - 2012-07-21 08:16 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-25 21:15 - 2011-10-29 21:21 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-23 07:19 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\NDF
2015-01-23 07:12 - 2014-05-07 17:34 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-01-23 07:12 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-01-23 06:43 - 2012-06-11 21:12 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-01-21 07:53 - 2013-08-08 13:00 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-20 09:27 - 2012-06-09 07:53 - 00000000 ____D () C:\Users\Bryan
2015-01-20 09:08 - 2012-06-17 09:08 - 00000000 ____D () C:\Users\Bryan\AppData\Local\Adobe
2015-01-06 11:37 - 2014-01-11 08:05 - 00304074 _____ () C:\Users\Bryan\Documents\JUST DO IT ! ! !.xlsx
2014-12-31 13:12 - 2013-03-27 07:31 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

==================== Files in the root of some directories =======

2013-10-16 18:30 - 2013-10-16 18:30 - 0000093 _____ () C:\Users\Bryan\AppData\Local\fusioncache.dat
2012-06-29 16:24 - 2012-06-29 16:24 - 0000057 _____ () C:\ProgramData\Ament.ini

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2015-01-06 07:47

==================== End Of Log ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-01-2015
Ran by Bryan at 2015-01-28 17:48:55
Running from C:\Users\Bryan\Desktop
Boot Mode: Normal
==========================================================

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton 360 (Disabled - Up to date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB}
AS: Norton 360 (Enabled - Up to date) {631E4324-D31C-783F-EC5C-35AD42B18466}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Norton 360 (Enabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

AceMoney Lite (HKLM-x32\...\AceMoney Lite_is1) (Version:  - MechCAD Software)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 16.0.0.245 - Adobe Systems Incorporated)
Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.5.23 - Adobe Systems Incorporated.)
Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2 - Adobe Systems Incorporated)
Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Photoshop Elements 10 (HKLM-x32\...\Adobe Photoshop Elements 10) (Version: 10.0 - Adobe Systems Incorporated)
Adobe Photoshop.com Inspiration Browser (HKLM-x32\...\PhotoshopdotcomInspirationBrowser.4C35C4D325D350FE0114230CBADCA2DDD0AC8D25.1) (Version: 3.07 - Adobe Systems Incorporated)
Adobe Reader X (10.1.8) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.8 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.1.629 - Adobe Systems, Inc.)
Amazon 1Button App (HKLM-x32\...\Amazon Browser Settings) (Version: 3.0 - Amazon)
Amazon 1Button App (x32 Version: 1.0.4 - Amazon) Hidden
AuthenTec TrueAPI (Version: 1.3.0.139 - AuthenTec, Inc.) Hidden
Backblaze (HKLM-x32\...\Backblaze) (Version:  - Backblaze, Inc)
Bejeweled 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Bing Bar (HKLM-x32\...\{9FA13759-5C2B-4177-9DDC-0038F8B5BEFD}) (Version: 7.0.826.0 - Microsoft Corporation)
Blackhawk Striker 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
Blio (HKLM-x32\...\{741006D1-7B2B-4E33-B2B0-831F282EEF64}) (Version: 2.2.8188 - K-NFB Reading Technology, Inc.)
calibre (HKLM-x32\...\{D9A3B393-72E7-44FD-B4B4-A463A0C2CC0F}) (Version: 0.9.30 - Kovid Goyal)
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Cradle of Rome 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.0.4528 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dora's World Adventure (x32 Version: 2.2.0.95 - WildTangent) Hidden
Driver Support (HKLM-x32\...\{597FB4A5-DD86-4316-A410-7E8074CC2CCE}) (Version: 8.1 - Driver Support)
Elements 10 Organizer (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
ESU for Microsoft Windows 7 SP1 (HKLM-x32\...\{E96CAA2A-0244-4A2A-8403-0C3C9534778B}) (Version: 2.1.1 - Hewlett-Packard)
Evernote v. 4.2.3 (HKLM-x32\...\{F761359C-9CED-45AE-9A51-9D6605CD55C4}) (Version: 4.2.3.22 - Evernote Corp.)
Farm Frenzy (x32 Version: 2.2.0.98 - WildTangent) Hidden
Farmscapes (x32 Version: 2.2.0.98 - WildTangent) Hidden
FATE (x32 Version: 2.2.0.97 - WildTangent) Hidden
Final Drive Fury (x32 Version: 2.2.0.95 - WildTangent) Hidden
GameSpy Comrade (HKLM-x32\...\{176B3593-72F1-459C-829C-5E9671E2CB35}) (Version: 1.4.3.154 - GameSpy)
Garmin USB Drivers (HKLM-x32\...\{3D5D6CFC-3097-425A-8D8F-7EAF5D57641D}) (Version: 2.3.1.0 - Garmin Ltd or its subsidiaries)
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
Homeworld (HKLM-x32\...\Homeworld) (Version:  - )
Hoyle Card Games (x32 Version: 2.2.0.95 - WildTangent) Hidden
HP Application Assistant (HKLM\...\{6032497A-4479-462B-ADB8-A0A372BB9A23}) (Version: 1.0.409.3882 - Hewlett-Packard)
HP Deskjet 3050A J611 series Basic Device Software (HKLM\...\{B6A3EAE4-3727-46A4-A659-8576BF7C8C8D}) (Version: 23.0.504.0 - Hewlett-Packard Co.)
HP Deskjet 3050A J611 series Help (HKLM-x32\...\{97DDCAB8-B770-4089-A10F-67568069D78A}) (Version: 140.0.2.2 - Hewlett Packard)
HP Documentation (HKLM-x32\...\{BC6CB499-9F29-4B41-8B8B-FA7248525256}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.2.5 - WildTangent)
HP Launch Box (HKLM\...\{5A847522-375C-4D05-BD3D-88C450CC047F}) (Version: 1.1.5 - Hewlett-Packard Company)
HP MovieStore (HKLM-x32\...\{9008D736-35CA-40DB-A2BE-5F32D954E5AA}) (Version: 2.1.21091.0 - Hewlett-Packard Company)
HP On Screen Display (HKLM-x32\...\{ED1BD69A-07E3-418C-91F1-D856582581BF}) (Version: 1.3.5 - Hewlett-Packard Company)
HP Power Manager (HKLM-x32\...\{7E799992-5DA0-4A1A-9443-B1836B063FEC}) (Version: 1.4.8 - Hewlett-Packard Company)
HP Quick Launch (HKLM-x32\...\{53B17A98-5BF0-40BC-AAFF-850A357975AC}) (Version: 2.7.2 - Hewlett-Packard Company)
HP QuickWeb (HKLM-x32\...\{BB4FC2AD-DF12-4EE1-8AA7-2C0A26B5E2FB}) (Version: 3.1.1.10197 - Hewlett-Packard Company)
HP Security Assistant (HKLM\...\{562608FE-2051-4488-BF22-8CE4C03046AC}) (Version: 1.0.12 - Hewlett-Packard)
HP Setup (HKLM-x32\...\{F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1}) (Version: 9.0.15076.3891 - Hewlett-Packard Company)
HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.2.14901.3869 - Hewlett-Packard Company)
HP SimplePass PE 2011 (HKLM-x32\...\{4741965C-AFD0-4D00-81D1-1039F96D4DC3}) (Version: 5.3.0.264 - Hewlett-Packard)
HP Software Framework (HKLM-x32\...\{675D093B-815D-47FD-AB2C-192EC751E8E2}) (Version: 4.6.10.1 - Hewlett-Packard Company)
HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company)
ICC Profile Update (HKLM-x32\...\{29FA84BB-0405-4E36-8C03-F3CDDCC8F86B}) (Version:  - )
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6365.0 - IDT)
iLivid (HKLM-x32\...\iLivid) (Version: 4.0.0.2410 - Bandoo Media Inc) <==== ATTENTION
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Identity Protection Technology 1.1.2.0 (HKLM-x32\...\{C01A86F5-56E7-101F-9BC9-E3F1025EB779}) (Version: 1.1.2.0 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2559 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.5.0.1026 - Intel Corporation)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.510 - Oracle)
Jewel Match 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Jewel Quest Mysteries: The Seventh Gate Collector's Edition (x32 Version: 2.2.0.98 - WildTangent) Hidden
John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Letters from Nowhere 2 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Luxor HD (x32 Version: 2.2.0.98 - WildTangent) Hidden
Mah Jong Medley (x32 Version: 2.2.0.95 - WildTangent) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 1.1 (HKLM-x32\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Age of Empires II (HKLM-x32\...\Age of Empires 2.0) (Version:  - )
Microsoft Age of Empires II: The Conquerors Expansion (HKLM-x32\...\Age of Empires II: The Conquerors Expansion 1.0) (Version:  - )
Microsoft Camera Codec Pack (HKLM\...\{601B8608-C901-428C-8125-53585CA54124}) (Version: 16.3.1483.0410 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
MixiDJ V8 Toolbar (HKLM-x32\...\MixiDJ_V8 Toolbar) (Version: 6.11.2.6 - MixiDJ V8) <==== ATTENTION
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Norton 360 (HKLM-x32\...\N360) (Version: 21.6.0.32 - Symantec Corporation)
opensource (x32 Version: 1.0.14960.3876 - Your Company Name) Hidden
Penguins! (x32 Version: 2.2.0.98 - WildTangent) Hidden
Pin It (HKLM-x32\...\Pin It_is1) (Version: 0.0.4 - Pinterest)
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
Poker Superstars III (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Polar Golfer (x32 Version: 2.2.0.98 - WildTangent) Hidden
PSE10 STI Installer (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
Ralink RT5390 802.11b/g/n WiFi Adapter (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 3.2.13.0 - Ralink)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.48.823.2011 - Realtek)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.85 - Realtek Semiconductor Corp.)
RollerCoaster Tycoon 3: Platinum (x32 Version: 2.2.0.98 - WildTangent) Hidden
SecureKey Device Access Platform (HKU\S-1-5-21-22227049-1486026924-1849314948-1000\...\SecureKey SKDeviceAccess) (Version: 2.0.6777.6940 - SecureKey Technologies Inc.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Sid Meier's Civilization 4 Gold (HKLM-x32\...\{55502C49-F061-428C-BF26-06ECDFB3AC29}) (Version: 1.72 - Firaxis Games)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
SOS Online Backup (HKLM-x32\...\{F8EA0505-6D38-4889-A3C1-5AB2DCC9BE25}) (Version: 5.7.1.3837 - SOS Online Backup, Inc.)
StudioCloud 3.0 (HKLM-x32\...\com.StudioCloud.Desktop.3.F2DAE273367737D97F8409B8C86CCCEDC39FC38E.1) (Version: 3.1.257 - StudioCloud International Inc.)
StudioCloud 3.0 (x32 Version: 3.1.257 - StudioCloud International Inc.) Hidden
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics TouchPad Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.11.0 - Synaptics Incorporated)
Systweak Toolbar (HKLM-x32\...\Systweak Toolbar) (Version: 1.0.1.8 - Systweak Software)
The Treasures of Mystery Island: The Ghost Ship (x32 Version: 2.2.0.98 - WildTangent) Hidden
Torch (HKU\S-1-5-21-22227049-1486026924-1849314948-1000\...\Torch) (Version: 2.0.0.2062 - Torch Media Inc.) <==== ATTENTION
Torchlight (x32 Version: 2.2.0.98 - WildTangent) Hidden
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
VIP Access SDK (1.0.1.2)  (HKLM-x32\...\VIP Access SDK) (Version: 1.0.1.2 - Symantec Inc.)
Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.98 - WildTangent) Hidden
When Pigs Fly! 3D Screensaver v2.0 Trial Version (HKLM-x32\...\WhenPigsFly3D) (Version:  - )
WildTangent Games App for HP (x32 Version: 4.0.11.2 - WildTangent) Hidden
Windows Driver Package - Garmin (grmnusb) GARMIN Devices  (04/19/2012 2.3.1.0) (HKLM\...\98157A226B40B173301B0F53C8E98C47805D5152) (Version: 04/19/2012 2.3.1.0 - Garmin)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Zuma's Revenge (x32 Version: 2.2.0.98 - WildTangent) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

==================== Restore Points  =========================

28-12-2014 14:49:56 Restore Operation
06-01-2015 07:47:42 Scheduled Checkpoint
18-01-2015 14:16:56 Scheduled Checkpoint
21-01-2015 07:42:04 Windows Update
23-01-2015 06:26:00 Windows Modules Installer
23-01-2015 06:27:22 Windows Modules Installer
23-01-2015 06:31:55 Windows Modules Installer
27-01-2015 23:27:44 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 20:34 - 2009-06-10 15:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {114F7E39-6487-4ADB-873F-509E295AB350} - System32\Tasks\Driver Support-RTMRules => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [2014-05-07] (PC Drivers Headquarters)
Task: {15D7179D-C502-4287-862D-4E116654A38A} - System32\Tasks\HPCeeScheduleForBryan => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard)
Task: {23F04AED-B27E-4A86-A97D-5F42E79F9AF8} - System32\Tasks\SecureKey Sofware Update => C:\Users\Bryan\AppData\Local\SecureKey\SKDeviceAccess\2.0.6777.6940\skupdaterwin.exe [2013-01-22] (SecureKey Technologies Inc.)
Task: {26ED8211-68C7-4827-B2FF-7B104718EE4A} - System32\Tasks\AdobeAAMUpdater-1.0-Bryan-HP-Bryan => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2011-06-16] (Adobe Systems Incorporated)
Task: {29C60B55-325F-41E0-B831-374234D4841B} - System32\Tasks\SOS Online Backup - [email protected] => C:\Program Files (x86)\SOS Online Backup\sosuploadagent.exe [2013-03-07] (SOS Online Backup)
Task: {30B8A3BA-811C-47F4-8A0A-51DA553DE176} - System32\Tasks\Online Backup Update Notifier => C:\Program Files (x86)\SOS Online Backup\SUpdateNotifier.exe [2013-03-07] (SOS Online Backup)
Task: {3FDDCB43-4FC1-4E0F-A41E-B0266708A58B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company)
Task: {44C76201-4DC5-453A-B95C-E3C635798AF2} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {463A8FBC-033F-4BFF-A5BF-AD70471C0670} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {537FBA63-DB0E-4D6B-88A0-346FB0ACF67F} - System32\Tasks\{DDD2CED7-5CE2-4BE5-A602-E18EF4B1CA51} => pcalua.exe -a "C:\Users\Bryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0EQZ284G\install_backblaze_oliphint442a33.exe" -d C:\Users\Bryan\Desktop
Task: {5750DB85-B059-47EE-830C-DD652FB286D3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-10-21] (Hewlett-Packard)
Task: {5F6213CC-403F-4F83-9060-ABA9E445CC35} - System32\Tasks\Driver Support-RTMScan => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [2014-05-07] (PC Drivers Headquarters)
Task: {67F2B921-6DFD-4597-9326-16B294A0041A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {6A12387F-2070-4055-8F53-D7A873AE70FA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_CN15R4C50Q => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-10-21] (Hewlett-Packard)
Task: {73D36E6A-BCB2-4A56-8C65-31A79C1716D4} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {7F908994-07B8-4F5B-9D0E-33A804F18CD7} - System32\Tasks\PinItAutoUpdate => C:\Program Files (x86)\Pinterest\Pin It\AutoUpdater.exe [2013-10-17] ()
Task: {959C9385-8EE7-4A11-894C-0D4FB3713D3C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-25] (Adobe Systems Incorporated)
Task: {95C78478-9798-4BA2-ADDF-7FBF7530623B} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-09-28] (CyberLink)
Task: {B2C3408B-3FAB-4753-B688-BF17B8100E0D} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation)
Task: {BAD05BB4-7AA3-4759-A288-99287FA30043} - System32\Tasks\Driver Support-RTMUpdater => C:\Program Files (x86)\Driver Support\Driver Support\DriverSupport.exe [2014-05-07] (PC Drivers Headquarters)
Task: {BFEEB20F-AA5A-489F-AC95-EA709E1691CF} - System32\Tasks\{F7DC30E2-0D37-48F5-B12C-19BD825E75E8} => pcalua.exe -a C:\Users\Bryan\Downloads\install_backblaze_oliphint442a33.exe -d C:\Users\Bryan\Desktop
Task: {DB9212B7-DA1E-4353-B805-DBDE8A15806D} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\WSCStub.exe [2014-09-21] (Symantec Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\HPCeeScheduleForBryan.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\Windows\Tasks\Online Backup Update Notifier.job => C:\Program Files (x86)\SOS Online Backup\SUpdateNotifier.exe
Task: C:\Windows\Tasks\SOS Online Backup - [email protected] => C:\Program Files (x86)\SOS Online Backup\sosuploadagent.exe

==================== Loaded Modules (whitelisted) =============

2014-08-27 15:09 - 2014-11-22 05:57 - 00234600 _____ () C:\Program Files (x86)\Backblaze\bzserv.exe
2011-03-16 03:29 - 2011-03-16 03:29 - 02673000 _____ () C:\Windows\system32\HPScanTRDrv_DJ3050A_J611.dll
2013-03-21 12:24 - 2013-03-21 12:24 - 00222368 _____ () C:\Program Files (x86)\Amazon Browser Bar\ToolbarUpdaterService.exe
2011-08-26 13:53 - 2011-08-26 13:53 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2014-05-07 12:31 - 2014-05-07 12:31 - 00428424 _____ () C:\Program Files (x86)\Driver Support\Driver Support\Agent.Communication.XmlSerializers.dll
2013-03-07 13:49 - 2013-03-07 13:49 - 00028544 _____ () C:\Program Files (x86)\SOS Online Backup\SOS.Contracts.CentralManagement.dll
2013-12-15 07:25 - 2013-12-15 07:25 - 00155456 _____ () C:\Program Files (x86)\Amazon\Amazon1ButtonApp\AmazonExtIE64.dll
2014-10-17 05:03 - 2014-10-17 05:03 - 00172544 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\c152a64e30c5b94894d75ac86aa7aad2\IsdiInterop.ni.dll
2011-12-12 02:29 - 2011-04-30 02:28 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll
2015-01-27 23:05 - 2015-01-27 23:05 - 09009480 _____ () C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\39.0.2171.99\pdf.dll
2015-01-27 23:05 - 2015-01-27 23:05 - 01677128 _____ () C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\39.0.2171.99\ffmpegsumo.dll
2015-01-27 23:05 - 2015-01-27 23:05 - 14913352 _____ () C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\39.0.2171.99\PepperFlash\pepflashplayer.dll
2013-12-15 08:12 - 2013-12-15 08:12 - 00138048 _____ () C:\Program Files (x86)\Amazon\Amazon1ButtonApp\AmazonExtIE.dll
2015-01-27 23:05 - 2015-01-27 23:05 - 01077064 _____ () C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\39.0.2171.99\libglesv2.dll
2015-01-27 23:05 - 2015-01-27 23:05 - 00211272 _____ () C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\39.0.2171.99\libegl.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: Comrade.exe => C:\Program Files (x86)\GameSpy\Comrade\Comrade.exe

========================= Accounts: ==========================

Administrator (S-1-5-21-22227049-1486026924-1849314948-500 - Administrator - Disabled)
ASPNET (S-1-5-21-22227049-1486026924-1849314948-1004 - Limited - Enabled)
Bryan (S-1-5-21-22227049-1486026924-1849314948-1000 - Administrator - Enabled) => C:\Users\Bryan
Guest (S-1-5-21-22227049-1486026924-1849314948-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-22227049-1486026924-1849314948-1002 - Limited - Enabled)

==================== Faulty Device Manager Devices =============

==================== Event log errors: =========================

Application errors:
==================
Error: (01/28/2015 00:01:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Tnulqltoe.exe, version: 39.0.2171.99, time stamp: 0x54aef409
Faulting module name: chrome_child.dll, version: 39.0.2171.99, time stamp: 0x54aef3cc
Exception code: 0xc0000005
Fault offset: 0x00f10689
Faulting process id: 0x1a58
Faulting application start time: 0xTnulqltoe.exe0
Faulting application path: Tnulqltoe.exe1
Faulting module path: Tnulqltoe.exe2
Report Id: Tnulqltoe.exe3

Error: (01/28/2015 10:44:29 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Tnulqltoe.exe, version: 39.0.2171.99, time stamp: 0x54aef409
Faulting module name: chrome_child.dll, version: 39.0.2171.99, time stamp: 0x54aef3cc
Exception code: 0xc0000005
Fault offset: 0x00f10689
Faulting process id: 0x24a0
Faulting application start time: 0xTnulqltoe.exe0
Faulting application path: Tnulqltoe.exe1
Faulting module path: Tnulqltoe.exe2
Report Id: Tnulqltoe.exe3

Error: (01/28/2015 10:08:41 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Tnulqltoe.exe, version: 39.0.2171.99, time stamp: 0x54aef409
Faulting module name: chrome_child.dll, version: 39.0.2171.99, time stamp: 0x54aef3cc
Exception code: 0xc0000005
Fault offset: 0x0032491c
Faulting process id: 0x2780
Faulting application start time: 0xTnulqltoe.exe0
Faulting application path: Tnulqltoe.exe1
Faulting module path: Tnulqltoe.exe2
Report Id: Tnulqltoe.exe3

Error: (01/28/2015 06:34:57 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/27/2015 00:30:18 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program POWERPNT.EXE version 14.0.7138.5000 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 3908

Start Time: 01d03a5f38f30842

Termination Time: 0

Application Path: C:\Program Files (x86)\Microsoft Office\Office14\POWERPNT.EXE

Report Id: 83f87b2f-a652-11e4-8d74-80c16e44a3de

Error: (01/27/2015 00:29:51 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program POWERPNT.EXE version 14.0.7138.5000 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1948

Start Time: 01d03a5f1e89e1e1

Termination Time: 0

Application Path: C:\Program Files (x86)\Microsoft Office\Office14\POWERPNT.EXE

Report Id: 6fa21a6e-a652-11e4-8d74-80c16e44a3de

Error: (01/27/2015 00:28:50 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program POWERPNT.EXE version 14.0.7138.5000 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 44c0

Start Time: 01d03a5ec6dd52e9

Termination Time: 31

Application Path: C:\Program Files (x86)\Microsoft Office\Office14\POWERPNT.EXE

Report Id: 4ede9619-a652-11e4-8d74-80c16e44a3de

Error: (01/25/2015 07:00:33 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program POWERPNT.EXE version 14.0.7138.5000 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 2720

Start Time: 01d039035a7ccbc0

Termination Time: 0

Application Path: C:\Program Files (x86)\Microsoft Office\Office14\POWERPNT.EXE

Report Id: b255bd13-a4f6-11e4-8d74-80c16e44a3de

Error: (01/23/2015 09:09:56 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/23/2015 10:03:41 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program EXCEL.EXE version 14.0.7140.5000 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1718

Start Time: 01d037137fc0b95c

Termination Time: 0

Application Path: C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE

Report Id: 4ad78aea-a319-11e4-af78-80c16e44a3de

System errors:
=============
Error: (01/28/2015 05:39:11 PM) (Source: DCOM) (EventID: 10016) (User: Bryan-HP)
Description: application-specificLocalActivation{E60687F7-01A1-40AA-86AC-DB1CBF673334}{653C5148-4DCE-4905-9CFD-1B23662D3D9E}Bryan-HPBryanS-1-5-21-22227049-1486026924-1849314948-1000LocalHost (Using LRPC)

Error: (01/28/2015 05:38:39 PM) (Source: DCOM) (EventID: 10016) (User: Bryan-HP)
Description: application-specificLocalActivation{E60687F7-01A1-40AA-86AC-DB1CBF673334}{653C5148-4DCE-4905-9CFD-1B23662D3D9E}Bryan-HPBryanS-1-5-21-22227049-1486026924-1849314948-1000LocalHost (Using LRPC)

Error: (01/28/2015 05:01:39 PM) (Source: DCOM) (EventID: 10016) (User: Bryan-HP)
Description: application-specificLocalActivation{D3DCB472-7261-43CE-924B-0704BD730D5F}{D3DCB472-7261-43CE-924B-0704BD730D5F}Bryan-HPBryanS-1-5-21-22227049-1486026924-1849314948-1000LocalHost (Using LRPC)

Error: (01/28/2015 05:01:39 PM) (Source: DCOM) (EventID: 10016) (User: Bryan-HP)
Description: application-specificLocalActivation{145B4335-FE2A-4927-A040-7C35AD3180EF}{145B4335-FE2A-4927-A040-7C35AD3180EF}Bryan-HPBryanS-1-5-21-22227049-1486026924-1849314948-1000LocalHost (Using LRPC)

Error: (01/28/2015 02:42:28 PM) (Source: DCOM) (EventID: 10016) (User: Bryan-HP)
Description: application-specificLocalActivation{D3DCB472-7261-43CE-924B-0704BD730D5F}{D3DCB472-7261-43CE-924B-0704BD730D5F}Bryan-HPBryanS-1-5-21-22227049-1486026924-1849314948-1000LocalHost (Using LRPC)

Error: (01/28/2015 02:42:28 PM) (Source: DCOM) (EventID: 10016) (User: Bryan-HP)
Description: application-specificLocalActivation{145B4335-FE2A-4927-A040-7C35AD3180EF}{145B4335-FE2A-4927-A040-7C35AD3180EF}Bryan-HPBryanS-1-5-21-22227049-1486026924-1849314948-1000LocalHost (Using LRPC)

Error: (01/28/2015 02:39:28 PM) (Source: DCOM) (EventID: 10016) (User: Bryan-HP)
Description: application-specificLocalActivation{D3DCB472-7261-43CE-924B-0704BD730D5F}{D3DCB472-7261-43CE-924B-0704BD730D5F}Bryan-HPBryanS-1-5-21-22227049-1486026924-1849314948-1000LocalHost (Using LRPC)

Error: (01/28/2015 02:39:27 PM) (Source: DCOM) (EventID: 10016) (User: Bryan-HP)
Description: application-specificLocalActivation{145B4335-FE2A-4927-A040-7C35AD3180EF}{145B4335-FE2A-4927-A040-7C35AD3180EF}Bryan-HPBryanS-1-5-21-22227049-1486026924-1849314948-1000LocalHost (Using LRPC)

Error: (01/28/2015 06:35:42 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (01/27/2015 11:56:05 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 20.

Microsoft Office Sessions:
=========================
Error: (01/28/2015 00:01:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Tnulqltoe.exe39.0.2171.9954aef409chrome_child.dll39.0.2171.9954aef3ccc000000500f106891a5801d03b236c4f71f7C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exeC:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\39.0.2171.99\chrome_child.dll9ed6f26a-a717-11e4-a725-80c16e44a3de

Error: (01/28/2015 10:44:29 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Tnulqltoe.exe39.0.2171.9954aef409chrome_child.dll39.0.2171.9954aef3ccc000000500f1068924a001d03b18a509f334C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exeC:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\39.0.2171.99\chrome_child.dllecd4aba4-a70c-11e4-a725-80c16e44a3de

Error: (01/28/2015 10:08:41 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Tnulqltoe.exe39.0.2171.9954aef409chrome_child.dll39.0.2171.9954aef3ccc00000050032491c278001d03b138a639397C:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\Tnulqltoe.exeC:\Users\Bryan\AppData\LocalLow\EmieBrowserModeList\Ptiepmgjdo\Siawesfwt\39.0.2171.99\chrome_child.dllecbc0d3d-a707-11e4-a725-80c16e44a3de

Error: (01/28/2015 06:34:57 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/27/2015 00:30:18 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: POWERPNT.EXE14.0.7138.5000390801d03a5f38f308420C:\Program Files (x86)\Microsoft Office\Office14\POWERPNT.EXE83f87b2f-a652-11e4-8d74-80c16e44a3de

Error: (01/27/2015 00:29:51 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: POWERPNT.EXE14.0.7138.5000194801d03a5f1e89e1e10C:\Program Files (x86)\Microsoft Office\Office14\POWERPNT.EXE6fa21a6e-a652-11e4-8d74-80c16e44a3de

Error: (01/27/2015 00:28:50 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: POWERPNT.EXE14.0.7138.500044c001d03a5ec6dd52e931C:\Program Files (x86)\Microsoft Office\Office14\POWERPNT.EXE4ede9619-a652-11e4-8d74-80c16e44a3de

Error: (01/25/2015 07:00:33 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: POWERPNT.EXE14.0.7138.5000272001d039035a7ccbc00C:\Program Files (x86)\Microsoft Office\Office14\POWERPNT.EXEb255bd13-a4f6-11e4-8d74-80c16e44a3de

Error: (01/23/2015 09:09:56 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/23/2015 10:03:41 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: EXCEL.EXE14.0.7140.5000171801d037137fc0b95c0C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE4ad78aea-a319-11e4-af78-80c16e44a3de

==================== Memory info ===========================

Processor: Intel® Core™ i3-2350M CPU @ 2.30GHz
Percentage of memory in use: 66%
Total physical RAM: 4043.86 MB
Available physical RAM: 1342.47 MB
Total Pagefile: 8085.9 MB
Available Pagefile: 3479.43 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:441.63 GB) (Free:235.77 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (Recovery) (Fixed) (Total:19.97 GB) (Free:2.15 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (HP_TOOLS) (Fixed) (Total:3.96 GB) (Free:1.08 GB) FAT32
Drive f: (HOMEWORLD) (CDROM) (Total:0.66 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: E861ED1B)
Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=441.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=20 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=4 GB) - (Type=0C)

==================== End Of Log ============================


  • 0

#4
Nevan

Nevan

    Trusted Helper

  • Malware Removal
  • 1,765 posts
Hello, HotTub1.

Let's get rid of the infection.

Step #1
Uninstall programs

Go to Start Menu>Control Panel>Programs>Uninstall a program (or Control Panel>Programs and Features if using icon view) and remove the following programs:
  • Driver Support
  • iLivid
  • MixiDJ V8 Toolbar
  • Systweak Toolbar
  • Torch
 
Step #2
FRST Fix
  • Download attached fixlist.txt file to your desktop.
    Attached File  fixlist.txt   3.51KB   143 downloads
    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
  • Right click FRST64.exe on your desktop and click Run as administrator. When the tool opens click Yes to disclaimer.
  • Press the Fix button just once and wait.
    NOTE: It's important that both FRST64.exe and fixlist.txt are in the same location or the fix will not work.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished, FRST will generate a log on the desktop (Fixlog.txt). Select all (CTRL+A) the content of the log, copy it (CTRL+C) and paste (CTRL+V) it into your next reply.
 
Step #3
FRST Scan
  • Right click FRST64.exe and click Run as administrator. When the tool opens click Yes to disclaimer.
  • Make sure that Addition.txt is checked and press the Scan button.
  • It will produce two logs - one called FRST.txt and another one called Addition.txt in the same directory the tool is run from.
  • Select all (CTRL+A) the content of the logs, copy them (CTRL+C) and paste (CTRL+V) them into your next reply.
 
Things that should appear in your next post:
  • Fixlog.txt log content
  • FRST.txt log content
  • Addition.txt log content

  • 0

#5
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP