Here are the requested logs after completing those steps:
All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== OTL ==========
Process optimizer.exe killed successfully!
No active process named SmartDefrag.exe was found!
Service WindowsOptimizer_A1 stopped successfully!
Service WindowsOptimizer_A1 deleted successfully!
C:\Program Files (x86)\Windows Optimizer\A1\optimizer.exe moved successfully.
No active process named SmartDefrag.exe was found!
No active process named aspcheck.exe was found!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0B4A10D1-FBD6-451d-BFDA-F03252B05984}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B4A10D1-FBD6-451d-BFDA-F03252B05984}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0B4A10D1-FBD6-451d-BFDA-F03252B05984}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B4A10D1-FBD6-451d-BFDA-F03252B05984}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F962FE58-6C6D-4519-8D34-EE82F8529AC6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F962FE58-6C6D-4519-8D34-EE82F8529AC6}\ not found.
Prefs.js: "chr-greentree_ff&ilc=12&type=800236" removed from browser.search.param.yahoo-fr
Prefs.js: faststartff%40gmail.com:4.2.3 removed from extensions.enabledAddons
Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
[email protected] deleted successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}\META-INF folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}\components folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}\chrome folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760} folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{4D6A6C8E-1EB2-46e1-8CAA-40DAFDE3ED93} folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\META-INF folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\lib folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\defaults\preferences folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\defaults\custombuttons folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\defaults\contenthandling folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\defaults folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\chrome folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\defaults\preferences folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\defaults folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\chrome folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\staged\
[email protected]\content folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\staged\
[email protected] folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\staged\
[email protected]\content folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\staged\
[email protected] folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\staged\
[email protected]\content folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\staged\
[email protected] folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\staged\
[email protected]\content folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\staged\
[email protected] folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\staged folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\
[email protected]\lib folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\
[email protected]\defaults folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\
[email protected]\chrome\content\subscriptions folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\
[email protected]\chrome\content\scripts folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\
[email protected]\chrome\content\images folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\
[email protected]\chrome\content folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\
[email protected]\chrome folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\
[email protected]\cache folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\
[email protected]\bin folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\
[email protected] folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions folder moved successfully.
Registry value HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\
[email protected] deleted successfully.
File C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions not found.
Folder C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{4D6A6C8E-1EB2-46e1-8CAA-40DAFDE3ED93}\ not found.
Folder C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\
[email protected]\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F}\ deleted successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Setwallpaper deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{585f0ba6-5d8b-11e0-8180-20cf3031e46a}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{585f0ba6-5d8b-11e0-8180-20cf3031e46a}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{585f0ba6-5d8b-11e0-8180-20cf3031e46a}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{585f0ba6-5d8b-11e0-8180-20cf3031e46a}\ not found.
File D:\VZAccess_Manager.exe /z detect not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ac9af706-3758-11e4-bc11-20cf3031e46a}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ac9af706-3758-11e4-bc11-20cf3031e46a}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ac9af706-3758-11e4-bc11-20cf3031e46a}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ac9af706-3758-11e4-bc11-20cf3031e46a}\ not found.
File D:\VZW_Software_upgrade_assistant.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e32d324c-6957-11e0-8181-20cf3031e46a}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e32d324c-6957-11e0-8181-20cf3031e46a}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e32d324c-6957-11e0-8181-20cf3031e46a}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e32d324c-6957-11e0-8181-20cf3031e46a}\ not found.
File D:\VZAccess_Manager.exe /z detect not found.
C:\Program Files (x86)\RooyalShoppeRRApp folder moved successfully.
C:\Program Files (x86)\CoolPreviews folder moved successfully.
C:\ProgramData\9464223627215929160 folder moved successfully.
C:\ProgramData\KingCoaupon folder moved successfully.
C:\Users\Gina Riebel\AppData\Local\1d5ca609-c328-4f2c-948d-86e91142228f folder moved successfully.
C:\ProgramData\khnmnfcklebenegejfmkdpaklnncmhcl folder moved successfully.
C:\ProgramData\SoftCouPo folder moved successfully.
C:\ProgramData\8357ad3ecf107f48 folder moved successfully.
C:\ProgramData\deal2deaLiotu folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\IObit\Smart Defrag 2 folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\IObit\IObit Uninstaller\Log folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\IObit\IObit Uninstaller folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\IObit\IObit Malware Fighter folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\IObit\Advanced SystemCare V5\Boottime folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\IObit\Advanced SystemCare V5\Backup folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\IObit\Advanced SystemCare V5 folder moved successfully.
C:\Users\Gina Riebel\AppData\Roaming\IObit folder moved successfully.
========== REGISTRY ==========
Registry key HKey_Local_Machine\Software\Microsoft\WINDOWS NT\CurrentVersion\Image File Execution Options\ContentExplorer.exe\ deleted successfully.
Registry key HKey_Local_Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\internetenhancer.exe\ deleted successfully.
Registry key HKey_Local_Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\internetenhancerservice.exe\ deleted successfully.
Registry key HKey_Local_Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wajaminternetenhancer.exe\ deleted successfully.
Registry key HKey_Local_Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WajamInternetEnhancerApp.exe\ deleted successfully.
Registry key HKey_Local_Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WajamInternetEnhancerAppservice.exe\ deleted successfully.
Registry key HKey_Local_Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wajaminternetenhancerservice.exe\ deleted successfully.
Registry key HKey_Local_Machine\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ContentExplorer.exe\ not found.
Registry key HKey_Local_Machine\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\internetenhancer.exe\ not found.
Registry key HKey_Local_Machine\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\internetenhancerservice.exe\ not found.
Registry key HKey_Local_Machine\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wajaminternetenhancer.exe\ not found.
Registry key HKey_Local_Machine\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WajamInternetEnhancerApp.exe\ not found.
Registry key HKey_Local_Machine\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WajamInternetEnhancerAppservice.exe\ not found.
Registry key HKey_Local_Machine\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wajaminternetenhancerservice.exe\ not found.
========== FILES ==========
C:\Program Files (x86)\Windows Optimizer\P4\config folder moved successfully.
C:\Program Files (x86)\Windows Optimizer\P4 folder moved successfully.
C:\Program Files (x86)\Windows Optimizer\P2\config folder moved successfully.
C:\Program Files (x86)\Windows Optimizer\P2 folder moved successfully.
C:\Program Files (x86)\Windows Optimizer\A1\config folder moved successfully.
C:\Program Files (x86)\Windows Optimizer\A1 folder moved successfully.
C:\Program Files (x86)\Windows Optimizer folder moved successfully.
C:\Program Files (x86)\AspInfo folder moved successfully.
C:\Program Files (x86)\IObit\Smart Defrag 2\LatestNews folder moved successfully.
C:\Program Files (x86)\IObit\Smart Defrag 2\Freeware\FreeSoftwareDownload folder moved successfully.
C:\Program Files (x86)\IObit\Smart Defrag 2\Freeware folder moved successfully.
C:\Program Files (x86)\IObit\Smart Defrag 2 folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\Update folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\Quarantine Zone folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\log\scan folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\log\realtime folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\log folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\update\ADSRemoval\IE\db folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\update\ADSRemoval\IE folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\update\ADSRemoval folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\update folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\js folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\img folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\db folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Firefox\
[email protected]\lib folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Firefox\
[email protected]\defaults folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Firefox\
[email protected]\chrome\content\subscriptions folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Firefox\
[email protected]\chrome\content\scripts folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Firefox\
[email protected]\chrome\content\images folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Firefox\
[email protected]\chrome\content folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Firefox\
[email protected]\chrome folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Firefox\
[email protected]\bin folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Firefox\
[email protected] folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Firefox\
[email protected]\lib folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Firefox\
[email protected]\defaults folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Firefox\
[email protected]\chrome\content\subscriptions folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Firefox\
[email protected]\chrome\content\scripts folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Firefox\
[email protected]\chrome\content\images folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Firefox\
[email protected]\chrome\content folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Firefox\
[email protected]\chrome folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Firefox\
[email protected]\cache folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Firefox\
[email protected]\bin folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Firefox\
[email protected] folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Firefox folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Chrome\gkcefkcdkepgkpbgncjchhbjgoanleod\1.0.0_0\js folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Chrome\gkcefkcdkepgkpbgncjchhbjgoanleod\1.0.0_0\img folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Chrome\gkcefkcdkepgkpbgncjchhbjgoanleod\1.0.0_0\filtering folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Chrome\gkcefkcdkepgkpbgncjchhbjgoanleod\1.0.0_0\dll folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Chrome\gkcefkcdkepgkpbgncjchhbjgoanleod\1.0.0_0\db folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Chrome\gkcefkcdkepgkpbgncjchhbjgoanleod\1.0.0_0 folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Chrome\gkcefkcdkepgkpbgncjchhbjgoanleod folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Chrome\fopdddcinljmpmioaklghcalngfhbaen\1.0.0_0\js folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Chrome\fopdddcinljmpmioaklghcalngfhbaen\1.0.0_0\img folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Chrome\fopdddcinljmpmioaklghcalngfhbaen\1.0.0_0\filtering folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Chrome\fopdddcinljmpmioaklghcalngfhbaen\1.0.0_0\dll folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Chrome\fopdddcinljmpmioaklghcalngfhbaen\1.0.0_0\db folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Chrome\fopdddcinljmpmioaklghcalngfhbaen\1.0.0_0 folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Chrome\fopdddcinljmpmioaklghcalngfhbaen folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\Chrome folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval folder moved successfully.
C:\Program Files (x86)\IObit\IObit Malware Fighter folder moved successfully.
C:\Program Files (x86)\IObit\Advanced SystemCare 5\Update folder moved successfully.
C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCServiceLog folder moved successfully.
C:\Program Files (x86)\IObit\Advanced SystemCare 5 folder moved successfully.
C:\Program Files (x86)\IObit folder moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Gina Riebel
->Temp folder emptied: 78458669 bytes
->Temporary Internet Files folder emptied: 16729880 bytes
->FireFox cache emptied: 24853065 bytes
->Google Chrome cache emptied: 109912068 bytes
->Flash cache emptied: 0 bytes
User: Guest
User: HomeGroupUser$
User: MBC
->Temp folder emptied: 20480 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 15024237 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 42310724 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 274.00 mb
OTL by OldTimer - Version 3.2.69.0 log created on 02042015_191510
Files\Folders moved on Reboot...
C:\Users\Gina Riebel\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat scheduled to be moved on reboot.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
# AdwCleaner v4.109 - Report created 04/02/2015 at 20:10:56
# Updated 24/01/2015 by Xplode
# Database : 2015-02-04.1 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Gina Riebel - MBC-PC
# Running from : C:\Users\Gina Riebel\Desktop\AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Systweak
Folder Deleted : C:\Program Files (x86)\PC Speed Maximizer
Folder Deleted : C:\Program Files (x86)\System Optimizer Pro
Folder Deleted : C:\Users\Administrator\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Administrator\AppData\Local\torch
Folder Deleted : C:\Users\Gina Riebel\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Gina Riebel\AppData\Local\PackageAware
Folder Deleted : C:\Users\Gina Riebel\AppData\Local\torch
Folder Deleted : C:\Users\Gina Riebel\AppData\Roaming\Systweak
Folder Deleted : C:\Users\Guest\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Guest\AppData\Local\torch
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\torch
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\chbmaonjmappfdkbdeoooebpjlemcand
Folder Deleted : C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Extensions\chbmaonjmappfdkbdeoooebpjlemcand
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\chbmaonjmappfdkbdeoooebpjlemcand
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\chbmaonjmappfdkbdeoooebpjlemcand
Folder Deleted : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\chbmaonjmappfdkbdeoooebpjlemcand
Folder Deleted : C:\Users\Gina Riebel\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\chbmaonjmappfdkbdeoooebpjlemcand
Folder Deleted : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\chbmaonjmappfdkbdeoooebpjlemcand
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\chbmaonjmappfdkbdeoooebpjlemcand
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\chbmaonjmappfdkbdeoooebpjlemcand
Folder Deleted : C:\Users\Gina Riebel\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\chbmaonjmappfdkbdeoooebpjlemcand
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\chbmaonjmappfdkbdeoooebpjlemcand
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\chbmaonjmappfdkbdeoooebpjlemcand
[/!\] Not Deleted ( Junction ) : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\chbmaonjmappfdkbdeoooebpjlemcand
[/!\] Not Deleted ( Junction ) : C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Extensions\chbmaonjmappfdkbdeoooebpjlemcand
[/!\] Not Deleted ( Junction ) : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\chbmaonjmappfdkbdeoooebpjlemcand
[/!\] Not Deleted ( Junction ) : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\chbmaonjmappfdkbdeoooebpjlemcand
File Deleted : C:\Windows\System32\roboot64.exe
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E0D6077D-7186-48B2-A6C6-2F7C533E8CFF}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CC865B26-C31D-4D23-B17B-96548EEF03F6}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\RegisteredApplicationsEx
Key Deleted : HKCU\Software\systweak
Key Deleted : HKCU\Software\Wajam
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\SOFTWARE\systweak
Key Deleted : HKLM\SOFTWARE\V9Software
Key Deleted : HKLM\SOFTWARE\Wpm
Key Deleted : HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Key Deleted : HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
Key Deleted : [x64] HKLM\SOFTWARE\System Optimizer Pro
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17496
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [First Home Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [First Home Page]
-\\ Mozilla Firefox v
-\\ Google Chrome v39.0.2171.71
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.tb.ask.com/search/GGmain.jhtml?searchfor={searchTerms}&st=kwd&ptb=E5975FF7-2C1B-43A4-9BC6-286407211864&n=77fda211&ind=2013110801&p2=^AFA^xdm323^YYA^us&si=116253_ewera4wt_99_150536
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://groovorio.com/results.php?f=4&q={searchTerms}&a=grv_adk34_14_38&cd=2XzuyEtN2Y1L1QzuyCyE0DyE0D0AtDzzyEtD0CtD0EtByC0AtN0D0Tzu0StCtDyByEtN1L2XzutAtFyCtFtCtDtFtCtN1L1Czu1N1C2X1V1T1Q1JtAyE1VtCyE1VtAzztN1L1G1B1V1N2Y1L1Qzu2StC0DtC0C0F0C0CtBtG0F0B0FtCtGyD0CtByBtG0AzzzzyBtGyCyE0DtA0C0BtByBzyyEyE0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0AtA0FtBzyyCtBtG0A0FyCyEtGyEyCtB0CtG0BtD0EzztGzyyEzytB0D0CyEyC0CyDtByB2Q&cr=1834411846&ir=
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.v9.com/web/?type=dspp&ts=1418276648&from=vtt&uid=ST9500325AS_5VEBRDXFXXXX5VEBRDXF&i=psd&t=34d5bd797&q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.v9.com/web/?type=dspp&ts=1418276648&from=vtt&uid=ST9500325AS_5VEBRDXFXXXX5VEBRDXF&i=psd&t=34d5bd797&q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : hbcennhacfaagdopikcegfcobcadeocj
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : icdlfehblmklkikfigmjhbmmpmkmpooj
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : mhkaekfpcppmmioggniknbnbdbcigpkk
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : pfndaklgolladniicklehhancnlgocpp
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Startup_URLs] : hxxp://groovorio.com/?f=7&a=grv_adk34_14_38&cd=2XzuyEtN2Y1L1QzuyCyE0DyE0D0AtDzzyEtD0CtD0EtByC0AtN0D0Tzu0StCtDyByEtN1L2XzutAtFyCtFtCtDtFtCtN1L1Czu1N1C2X1V1T1Q1JtAyE1VtCyE1VtAzztN1L1G1B1V1N2Y1L1Qzu2StC0DtC0C0F0C0CtBtG0F0B0FtCtGyD0CtByBtG0AzzzzyBtGyCyE0DtA0C0BtByBzyyEyE0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0AtA0FtBzyyCtBtG0A0FyCyEtGyEyCtB0CtG0BtD0EzztGzyyEzytB0D0CyEyC0CyDtByB2Q&cr=1834411846&ir=
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Startup_URLs] : hxxp://www.v9.com/?type=hppp&ts=1418276657&from=vtt&uid=ST9500325AS_5VEBRDXFXXXX5VEBRDXF&i=psd&t=34d5bd7f1
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.tb.ask.com/search/GGmain.jhtml?searchfor={searchTerms}&st=kwd&ptb=E5975FF7-2C1B-43A4-9BC6-286407211864&n=77fda211&ind=2013110801&p2=^AFA^xdm323^YYA^us&si=116253_ewera4wt_99_150536
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://groovorio.com/results.php?f=4&q={searchTerms}&a=grv_adk34_14_38&cd=2XzuyEtN2Y1L1QzuyCyE0DyE0D0AtDzzyEtD0CtD0EtByC0AtN0D0Tzu0StCtDyByEtN1L2XzutAtFyCtFtCtDtFtCtN1L1Czu1N1C2X1V1T1Q1JtAyE1VtCyE1VtAzztN1L1G1B1V1N2Y1L1Qzu2StC0DtC0C0F0C0CtBtG0F0B0FtCtGyD0CtByBtG0AzzzzyBtGyCyE0DtA0C0BtByBzyyEyE0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0AtA0FtBzyyCtBtG0A0FyCyEtGyEyCtB0CtG0BtD0EzztGzyyEzytB0D0CyEyC0CyDtByB2Q&cr=1834411846&ir=
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.v9.com/web/?type=dspp&ts=1418276648&from=vtt&uid=ST9500325AS_5VEBRDXFXXXX5VEBRDXF&i=psd&t=34d5bd797&q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.v9.com/web/?type=dspp&ts=1418276648&from=vtt&uid=ST9500325AS_5VEBRDXFXXXX5VEBRDXF&i=psd&t=34d5bd797&q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : hbcennhacfaagdopikcegfcobcadeocj
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : icdlfehblmklkikfigmjhbmmpmkmpooj
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : mhkaekfpcppmmioggniknbnbdbcigpkk
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : pfndaklgolladniicklehhancnlgocpp
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Startup_URLs] : hxxp://groovorio.com/?f=7&a=grv_adk34_14_38&cd=2XzuyEtN2Y1L1QzuyCyE0DyE0D0AtDzzyEtD0CtD0EtByC0AtN0D0Tzu0StCtDyByEtN1L2XzutAtFyCtFtCtDtFtCtN1L1Czu1N1C2X1V1T1Q1JtAyE1VtCyE1VtAzztN1L1G1B1V1N2Y1L1Qzu2StC0DtC0C0F0C0CtBtG0F0B0FtCtGyD0CtByBtG0AzzzzyBtGyCyE0DtA0C0BtByBzyyEyE0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0AtA0FtBzyyCtBtG0A0FyCyEtGyEyCtB0CtG0BtD0EzztGzyyEzytB0D0CyEyC0CyDtByB2Q&cr=1834411846&ir=
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Startup_URLs] : hxxp://www.v9.com/?type=hppp&ts=1418276657&from=vtt&uid=ST9500325AS_5VEBRDXFXXXX5VEBRDXF&i=psd&t=34d5bd7f1
-\\ Comodo Dragon v
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.tb.ask.com/search/GGmain.jhtml?searchfor={searchTerms}&st=kwd&ptb=E5975FF7-2C1B-43A4-9BC6-286407211864&n=77fda211&ind=2013110801&p2=^AFA^xdm323^YYA^us&si=116253_ewera4wt_99_150536
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://groovorio.com/results.php?f=4&q={searchTerms}&a=grv_adk34_14_38&cd=2XzuyEtN2Y1L1QzuyCyE0DyE0D0AtDzzyEtD0CtD0EtByC0AtN0D0Tzu0StCtDyByEtN1L2XzutAtFyCtFtCtDtFtCtN1L1Czu1N1C2X1V1T1Q1JtAyE1VtCyE1VtAzztN1L1G1B1V1N2Y1L1Qzu2StC0DtC0C0F0C0CtBtG0F0B0FtCtGyD0CtByBtG0AzzzzyBtGyCyE0DtA0C0BtByBzyyEyE0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0AtA0FtBzyyCtBtG0A0FyCyEtGyEyCtB0CtG0BtD0EzztGzyyEzytB0D0CyEyC0CyDtByB2Q&cr=1834411846&ir=
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.v9.com/web/?type=dspp&ts=1418276648&from=vtt&uid=ST9500325AS_5VEBRDXFXXXX5VEBRDXF&i=psd&t=34d5bd797&q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.v9.com/web/?type=dspp&ts=1418276648&from=vtt&uid=ST9500325AS_5VEBRDXFXXXX5VEBRDXF&i=psd&t=34d5bd797&q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.tb.ask.com/search/GGmain.jhtml?searchfor={searchTerms}&st=kwd&ptb=E5975FF7-2C1B-43A4-9BC6-286407211864&n=77fda211&ind=2013110801&p2=^AFA^xdm323^YYA^us&si=116253_ewera4wt_99_150536
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://groovorio.com/results.php?f=4&q={searchTerms}&a=grv_adk34_14_38&cd=2XzuyEtN2Y1L1QzuyCyE0DyE0D0AtDzzyEtD0CtD0EtByC0AtN0D0Tzu0StCtDyByEtN1L2XzutAtFyCtFtCtDtFtCtN1L1Czu1N1C2X1V1T1Q1JtAyE1VtCyE1VtAzztN1L1G1B1V1N2Y1L1Qzu2StC0DtC0C0F0C0CtBtG0F0B0FtCtGyD0CtByBtG0AzzzzyBtGyCyE0DtA0C0BtByBzyyEyE0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0AtA0FtBzyyCtBtG0A0FyCyEtGyEyCtB0CtG0BtD0EzztGzyyEzytB0D0CyEyC0CyDtByB2Q&cr=1834411846&ir=
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.v9.com/web/?type=dspp&ts=1418276648&from=vtt&uid=ST9500325AS_5VEBRDXFXXXX5VEBRDXF&i=psd&t=34d5bd797&q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.v9.com/web/?type=dspp&ts=1418276648&from=vtt&uid=ST9500325AS_5VEBRDXFXXXX5VEBRDXF&i=psd&t=34d5bd797&q={searchTerms}
-\\ Chrome Canary v
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.tb.ask.com/search/GGmain.jhtml?searchfor={searchTerms}&st=kwd&ptb=E5975FF7-2C1B-43A4-9BC6-286407211864&n=77fda211&ind=2013110801&p2=^AFA^xdm323^YYA^us&si=116253_ewera4wt_99_150536
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://groovorio.com/results.php?f=4&q={searchTerms}&a=grv_adk34_14_38&cd=2XzuyEtN2Y1L1QzuyCyE0DyE0D0AtDzzyEtD0CtD0EtByC0AtN0D0Tzu0StCtDyByEtN1L2XzutAtFyCtFtCtDtFtCtN1L1Czu1N1C2X1V1T1Q1JtAyE1VtCyE1VtAzztN1L1G1B1V1N2Y1L1Qzu2StC0DtC0C0F0C0CtBtG0F0B0FtCtGyD0CtByBtG0AzzzzyBtGyCyE0DtA0C0BtByBzyyEyE0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0AtA0FtBzyyCtBtG0A0FyCyEtGyEyCtB0CtG0BtD0EzztGzyyEzytB0D0CyEyC0CyDtByB2Q&cr=1834411846&ir=
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.v9.com/web/?type=dspp&ts=1418276648&from=vtt&uid=ST9500325AS_5VEBRDXFXXXX5VEBRDXF&i=psd&t=34d5bd797&q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.v9.com/web/?type=dspp&ts=1418276648&from=vtt&uid=ST9500325AS_5VEBRDXFXXXX5VEBRDXF&i=psd&t=34d5bd797&q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.tb.ask.com/search/GGmain.jhtml?searchfor={searchTerms}&st=kwd&ptb=E5975FF7-2C1B-43A4-9BC6-286407211864&n=77fda211&ind=2013110801&p2=^AFA^xdm323^YYA^us&si=116253_ewera4wt_99_150536
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://groovorio.com/results.php?f=4&q={searchTerms}&a=grv_adk34_14_38&cd=2XzuyEtN2Y1L1QzuyCyE0DyE0D0AtDzzyEtD0CtD0EtByC0AtN0D0Tzu0StCtDyByEtN1L2XzutAtFyCtFtCtDtFtCtN1L1Czu1N1C2X1V1T1Q1JtAyE1VtCyE1VtAzztN1L1G1B1V1N2Y1L1Qzu2StC0DtC0C0F0C0CtBtG0F0B0FtCtGyD0CtByBtG0AzzzzyBtGyCyE0DtA0C0BtByBzyyEyE0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyE0AtA0FtBzyyCtBtG0A0FyCyEtGyEyCtB0CtG0BtD0EzztGzyyEzytB0D0CyEyC0CyDtByB2Q&cr=1834411846&ir=
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.v9.com/web/?type=dspp&ts=1418276648&from=vtt&uid=ST9500325AS_5VEBRDXFXXXX5VEBRDXF&i=psd&t=34d5bd797&q={searchTerms}
[C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.v9.com/web/?type=dspp&ts=1418276648&from=vtt&uid=ST9500325AS_5VEBRDXFXXXX5VEBRDXF&i=psd&t=34d5bd797&q={searchTerms}
*************************
AdwCleaner[R0].txt - [9701 octets] - [04/02/2015 20:07:29]
AdwCleaner[R1].txt - [15473 octets] - [04/02/2015 20:08:45]
AdwCleaner[S0].txt - [18638 octets] - [04/02/2015 20:10:56]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [18699 octets] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 7 Home Premium x64
Ran by Gina Riebel on Wed 02/04/2015 at 20:56:34.12
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6555D3DD-EC5F-46A2-BEFA-65F60796809E}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\best buy pc app"
Successfully deleted: [Folder] "C:\Users\Gina Riebel\appdata\local\best buy pc app"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 02/04/2015 at 21:00:11.85
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 7 Home Premium x64
Ran by Gina Riebel on Wed 02/04/2015 at 20:56:34.12
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6555D3DD-EC5F-46A2-BEFA-65F60796809E}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\best buy pc app"
Successfully deleted: [Folder] "C:\Users\Gina Riebel\appdata\local\best buy pc app"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 02/04/2015 at 21:00:11.85
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-02-2015 01
Ran by Gina Riebel (administrator) on MBC-PC on 04-02-2015 21:24:54
Running from C:\Users\Gina Riebel\Desktop
Loaded Profiles: Gina Riebel (Available profiles: Gina Riebel)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS CopyProtect\ASPG.exe
(ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
() C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Intel® Corporation) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Red Bend Ltd.) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel® Corporation) C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
() C:\Program Files (x86)\Blackboard\Blackboard IM\blackboardim.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\WimaxConsole.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Dropbox, Inc.) C:\Users\Gina Riebel\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(asus) C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
(ASUS) C:\Windows\AsScrPro.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [649608 2010-06-10] (ELAN Microelectronic Corp.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2009-11-19] ()
HKLM\...\Run: [IntelWirelessWiMAX] => C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe [1441792 2010-06-08] (Intel® Corporation)
HKLM\...\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1928976 2010-03-05] (Intel® Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-12-10] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [6806144 2010-06-24] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-05-03] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-07-02] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2011-01-31] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2239376 2014-02-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-4142645300-81699424-4017103561-1001\...\Run: [pronto] => C:\Program Files (x86)\Blackboard\Blackboard IM\blackboardim.exe [22778928 2011-09-20] ()
HKU\S-1-5-21-4142645300-81699424-4017103561-1001\...\Policies\Explorer: [HideSCAHealth] 1
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk.disabled
ShortcutTarget: FancyStart daemon.lnk.disabled -> C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GoPro Importer.lnk
ShortcutTarget: GoPro Importer.lnk -> C:\Program Files (x86)\GoPro\Tools\Importer\GoPro Importer.exe (GoPro)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SRS Premium Sound.lnk
ShortcutTarget: SRS Premium Sound.lnk -> C:\Windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe (Acresso Software Inc.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (No File)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (No File)
Startup: C:\Users\Gina Riebel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Gina Riebel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Gina Riebel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Gina Riebel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk
ShortcutTarget: Stardock ObjectDock.lnk -> C:\Program Files (x86)\Stardock\ObjectDockFree\ObjectDock.exe (No File)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [ADSMOverlayIcon] -> {A825576B-0042-4F0F-8FB0-93CE0F054E69} => C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt64.dll ()
ShellIconOverlayIdentifiers: [ADSMOverlayIcon1] -> {A8D448F4-0431-45AC-9F5E-E1B434AB2249} => C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll ()
ShellIconOverlayIdentifiers-x32: [ADSMOverlayIcon] -> {A825576B-0042-4F0F-8FB0-93CE0F054E69} => C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll ()
ShellIconOverlayIdentifiers-x32: [ADSMOverlayIcon1] -> {A8D448F4-0431-45AC-9F5E-E1B434AB2249} => C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live Family Safety Browser Helper Class -> {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} -> C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Windows Live Family Safety Browser Helper Class -> {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} -> C:\Program Files (x86)\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO-x32: Windows Live Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default
FF NewTab: about:newtab
FF DefaultSearchUrl: hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF NetworkProxy: "no_proxies_on", "*.local"
FF DefaultSearchEngine: Yahoo!
FF SelectedSearchEngine: Yahoo!
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8051.1204 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\avg_igeared.xml
FF HKLM-x32\...\Firefox\Extensions: [{b9bfaf1c-a63f-47cd-0829-29526ced3667}] - C:\Program Files (x86)\Win YouTube Downloader Ultimate\extension\\getvideosoft.xpi
FF Extension: No Name - C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760} [Not Found]
FF Extension: No Name - C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [Not Found]
FF Extension: No Name - C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\
[email protected] [Not Found]
FF Extension: No Name - C:\Users\Gina Riebel\AppData\Roaming\Mozilla\Firefox\Profiles\9y60w7s5.default\extensions\
[email protected] [Not Found]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-29]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-27]
CHR Extension: (YouTube) - C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-29]
CHR Extension: (Google Search) - C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-29]
CHR Extension: (Google Wallet) - C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-13]
CHR Extension: (Gmail) - C:\Users\Gina Riebel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-29]
StartMenuInternet: Google Chrome - chrome.exe
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 7c1130c3; c:\Program Files (x86)\TampaRunner\TampaRunner.dll [1606144 2015-02-04] () [File not signed]
R3 ADSMService; C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe [225280 2008-03-31] (ASUSTek Computer Inc.) [File not signed]
R2 DMAgent; C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [408576 2010-06-07] (Red Bend Ltd.) [File not signed]
R2 LMS; C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe [262144 2009-09-30] (Intel Corporation) [File not signed]
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-03-05] ()
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 UNS; C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2314240 2009-09-30] (Intel Corporation) [File not signed]
R2 WiMAXAppSrv; C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [911872 2010-06-07] (Intel® Corporation) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
S3 Netaapl; C:\Windows\System32\DRIVERS\netaapl64.sys [22528 2011-05-10] (Apple Inc.) [File not signed]
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1806400 2009-06-05] ()
S3 massfilter; system32\drivers\massfilter.sys [X]
S0 SmartDefragDriver; System32\Drivers\SmartDefragDriver.sys [X]
U3 tmlwf; No ImagePath
U3 tmwfp; No ImagePath
S3 ZTEusbgps; system32\DRIVERS\ZTEusbgps.sys [X]
S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X]
S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X]
S3 ZTEusbnmeaext; system32\DRIVERS\ZTEusbnmeaext.sys [X]
S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-04 21:24 - 2015-02-04 21:26 - 00022888 _____ () C:\Users\Gina Riebel\Desktop\FRST.txt
2015-02-04 21:24 - 2015-02-04 21:24 - 02131968 _____ (Farbar) C:\Users\Gina Riebel\Desktop\FRST64.exe
2015-02-04 21:24 - 2015-02-04 21:24 - 00000000 ____D () C:\FRST
2015-02-04 21:00 - 2015-02-04 21:00 - 00000938 _____ () C:\Users\Gina Riebel\Desktop\JRT.txt
2015-02-04 20:12 - 2015-02-04 20:12 - 00018804 _____ () C:\Users\Gina Riebel\Desktop\AdwCleaner[S0].txt
2015-02-04 19:22 - 2015-02-04 20:11 - 00000000 ____D () C:\AdwCleaner
2015-02-04 19:15 - 2015-02-04 19:15 - 00000000 ____D () C:\_OTL
2015-02-04 19:14 - 2015-02-04 19:14 - 01388274 _____ (Thisisu) C:\Users\Gina Riebel\Desktop\JRT.exe
2015-02-04 19:13 - 2015-02-04 19:13 - 02194432 _____ () C:\Users\Gina Riebel\Desktop\AdwCleaner.exe
2015-02-04 19:10 - 2015-02-04 19:10 - 00602112 _____ (OldTimer Tools) C:\Users\Gina Riebel\Desktop\OTL.exe
2015-02-04 15:04 - 2015-02-04 15:04 - 00071730 _____ () C:\Users\Gina Riebel\Downloads\Extras.Txt
2015-02-04 15:03 - 2015-02-04 15:03 - 00104136 _____ () C:\Users\Gina Riebel\Downloads\OTL.Txt
2015-02-04 14:53 - 2015-02-04 14:53 - 00602112 _____ (OldTimer Tools) C:\Users\Gina Riebel\Downloads\OTL.exe
2015-02-04 13:59 - 2015-02-04 13:59 - 00002367 _____ () C:\Users\Gina Riebel\Desktop\Google Chrome.lnk
2015-02-04 13:58 - 2015-02-04 14:01 - 00000020 _____ () C:\Users\Gina Riebel\AppData\Roaming\appdataFr3.bin
2015-02-04 13:48 - 2015-02-04 13:48 - 00003190 _____ () C:\Windows\System32\Tasks\{2A0516D3-2A34-4481-9C44-C94BF34E5D04}
2015-02-04 13:26 - 2015-02-04 13:26 - 00003216 _____ () C:\Windows\System32\Tasks\{9DAB43F3-3ED9-465F-8658-685F4C3FAA6C}
2015-02-04 13:22 - 2015-02-04 13:22 - 00000000 ____D () C:\Program Files (x86)\TampaRunner
2015-02-04 13:20 - 2015-02-04 13:20 - 00001770 _____ () C:\Windows\DPINST.LOG
2015-02-04 13:05 - 2015-02-04 14:26 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-04 13:05 - 2015-02-04 13:05 - 00001104 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-04 13:05 - 2015-02-04 13:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-04 13:05 - 2015-02-04 13:05 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-04 13:05 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-04 13:05 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-01-31 13:21 - 2014-12-11 23:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-31 13:21 - 2014-12-11 23:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-31 13:21 - 2014-12-11 23:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-31 13:21 - 2014-12-11 23:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-31 13:21 - 2014-12-11 23:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-31 13:21 - 2014-12-11 23:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-31 13:21 - 2014-12-11 23:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-23 21:14 - 2015-01-23 21:14 - 00003786 _____ () C:\Windows\System32\Tasks\RunTool
2015-01-23 20:52 - 2014-12-18 21:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-23 20:52 - 2014-12-18 19:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-23 20:52 - 2014-12-11 11:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-23 20:52 - 2014-12-05 22:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-23 20:52 - 2014-12-05 21:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-23 20:52 - 2014-12-05 21:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-07 18:38 - 2015-01-07 18:38 - 00000000 ____D () C:\Program Files (x86)\Software Update Services
2015-01-05 20:57 - 2015-01-05 20:57 - 00000000 ____D () C:\Windows\system32\appraiser
2015-01-05 20:39 - 2015-01-05 20:39 - 00022528 _____ () C:\Users\Gina Riebel\AppData\Local\dsisetup4068297652.exe
2015-01-05 20:39 - 2015-01-05 20:39 - 00000001 _____ () C:\Users\Gina Riebel\AppData\Local\DSI.DAT
2015-01-05 20:08 - 2014-12-12 23:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-01-05 20:08 - 2014-12-12 21:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-04 21:08 - 2013-04-27 19:50 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-04 20:40 - 2011-01-28 13:37 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-04 20:34 - 2014-12-19 16:20 - 00769559 _____ () C:\Windows\WindowsUpdate.log
2015-02-04 20:19 - 2009-07-13 22:45 - 00019056 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-04 20:19 - 2009-07-13 22:45 - 00019056 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-04 20:13 - 2014-08-25 12:11 - 00000000 ___RD () C:\Users\Gina Riebel\Dropbox
2015-02-04 20:13 - 2014-08-25 12:05 - 00000000 ____D () C:\Users\Gina Riebel\AppData\Roaming\Dropbox
2015-02-04 20:12 - 2011-02-26 23:00 - 00000418 _____ () C:\Windows\Tasks\AutoSmartDefrag.job
2015-02-04 20:12 - 2011-01-28 13:37 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-04 20:12 - 2010-08-18 11:59 - 00000050 _____ () C:\Windows\system32\SupplicantTest.log
2015-02-04 20:11 - 2014-12-19 16:17 - 00000896 _____ () C:\Windows\setupact.log
2015-02-04 20:11 - 2014-12-19 16:16 - 00095510 _____ () C:\Windows\PFRO.log
2015-02-04 20:11 - 2009-07-13 23:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-04 19:56 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\NDF
2015-02-04 14:39 - 2009-07-13 23:08 - 00032592 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-02-04 14:34 - 2011-01-28 13:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-02-04 14:31 - 2010-08-18 11:32 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-02-04 14:31 - 2010-08-18 11:31 - 00000000 ____D () C:\Program Files (x86)\CyberLink
2015-02-04 14:30 - 2011-02-26 15:12 - 00000000 ____D () C:\Users\Gina Riebel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite
2015-02-04 14:30 - 2010-08-18 11:32 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite
2015-02-04 14:30 - 2010-08-18 11:32 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite
2015-02-04 14:23 - 2010-08-18 12:08 - 00001478 _____ () C:\Windows\system32\ServiceFilter.ini
2015-02-04 14:20 - 2009-07-28 23:20 - 00000000 ____D () C:\Windows\ABLKSR
2015-02-04 13:48 - 2014-06-22 13:34 - 00000258 __RSH () C:\ProgramData\ntuser.pol
2015-02-04 13:48 - 2011-02-24 11:08 - 00000000 ____D () C:\Program Files\activePDF
2015-02-04 13:47 - 2011-01-28 13:33 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2015-02-04 13:47 - 2011-01-28 13:33 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy
2015-02-04 13:46 - 2011-02-24 11:17 - 00000000 ____D () C:\Program Files\Zune
2015-02-04 13:28 - 2011-02-26 15:15 - 00000000 ____D () C:\Users\Gina Riebel\AppData\Local\Deployment
2015-02-04 13:26 - 2010-08-18 12:09 - 00000000 ____D () C:\Windows\SysWOW64\K_Series_ScreenSaver_EN dir
2015-02-04 13:19 - 2014-06-23 14:14 - 00000552 _____ () C:\Windows\SysWOW64\schtasks.bin
2015-02-04 13:10 - 2013-04-27 19:50 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-04 13:10 - 2013-04-27 19:50 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-04 13:10 - 2013-04-27 19:50 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-02-04 13:06 - 2011-02-26 23:00 - 00000000 ____D () C:\Users\Gina Riebel\AppData\Local\Adobe
2015-02-04 13:05 - 2014-03-25 21:13 - 00000000 ____D () C:\Users\Gina Riebel\AppData\Roaming\Malwarebytes
2015-02-04 13:05 - 2011-02-24 10:51 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-04 13:05 - 2011-02-24 10:51 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2015-01-31 13:39 - 2014-12-19 16:39 - 00000135 _____ () C:\Users\Gina Riebel\AppData\Roaming\WB.CFG
2015-01-31 12:58 - 2013-08-29 19:49 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-31 12:58 - 2011-02-24 11:06 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-07 19:12 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\rescache
2015-01-05 20:57 - 2014-04-29 18:08 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-01-05 20:57 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\AppCompat
==================== Files in the root of some directories =======
2007-06-12 10:34 - 2007-06-12 10:34 - 0035822 _____ () C:\Program Files (x86)\Common Files\ASPG_icon.ico
2008-05-22 09:35 - 2008-05-22 09:35 - 0051962 _____ () C:\Program Files (x86)\Common Files\banner.jpg
2009-04-08 11:31 - 2009-04-08 11:31 - 0106496 _____ () C:\Program Files (x86)\Common Files\CPInstallAction.dll
2008-08-11 22:45 - 2008-08-11 22:45 - 0155648 _____ (ASUS) C:\Program Files (x86)\Common Files\MSIactionall.dll
2015-02-04 13:58 - 2015-02-04 14:01 - 0000020 _____ () C:\Users\Gina Riebel\AppData\Roaming\appdataFr3.bin
2012-12-17 14:00 - 2012-12-17 14:01 - 0000310 _____ () C:\Users\Gina Riebel\AppData\Roaming\APUSet.xml
2012-12-17 14:00 - 2012-12-17 14:01 - 0000285 _____ () C:\Users\Gina Riebel\AppData\Roaming\PrimoPDFSet.xml
2014-12-19 16:39 - 2015-01-31 13:39 - 0000135 _____ () C:\Users\Gina Riebel\AppData\Roaming\WB.CFG
2014-06-25 10:38 - 2014-06-29 17:30 - 0003584 _____ () C:\Users\Gina Riebel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-05 20:39 - 2015-01-05 20:39 - 0000001 _____ () C:\Users\Gina Riebel\AppData\Local\DSI.DAT
2015-01-05 20:39 - 2015-01-05 20:39 - 0022528 _____ () C:\Users\Gina Riebel\AppData\Local\dsisetup4068297652.exe
2010-08-18 11:32 - 2010-08-18 11:32 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2010-08-18 11:31 - 2010-08-18 11:32 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
Some content of TEMP:
====================
C:\Users\Gina Riebel\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpgyc4b8.dll
C:\Users\Gina Riebel\AppData\Local\Temp\Quarantine.exe
C:\Users\Gina Riebel\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-04 16:10
==================== End Of Log ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-02-2015 01
Ran by Gina Riebel at 2015-02-04 21:26:29
Running from C:\Users\Gina Riebel\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 2.4.0.348 - Adobe Systems Incorporated)
Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.0.32.18 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Photoshop CC (HKLM-x32\...\{2D99B50E-431D-4AA8-85C1-172A6F8BCF09}) (Version: 14.0 - Adobe Systems Incorporated)
Adobe Reader 9.4.2 MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.4.2 - Adobe Systems Incorporated)
Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ASUS AI Recovery (HKLM-x32\...\{06585B02-F20D-4AB2-9A64-86EF2AE0F8F0}) (Version: 1.0.10 - ASUS)
ASUS CopyProtect (HKLM-x32\...\{6B77A7F6-DD63-4F13-A6FF-83137A5AC354}) (Version: 1.0.0015 - ASUS)
ASUS Data Security Manager (HKLM-x32\...\{FA2092C5-7979-412D-A962-6485274AE1EE}) (Version: 1.00.0014 - ASUS)
ASUS FancyStart (HKLM-x32\...\{2B81872B-A054-48DA-BE3B-FA5C164C303A}) (Version: 1.0.8 - ASUSTeK Computer Inc.)
ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.20 - ASUS)
ASUS Live Update (HKLM-x32\...\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}) (Version: 2.5.9 - ASUS)
ASUS MultiFrame (HKLM-x32\...\{9D48531D-2135-49FC-BC29-ACCDA5396A76}) (Version: 1.0.0021 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{91EFE3A1-585E-4F66-B5F6-F118F56C4C47}) (Version: 1.1.37 - ASUS)
ASUS SmartLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0008 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0028 - ASUS)
ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.20 - asus)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0005 - ASUS)
Best Buy pc app (HKU\S-1-5-21-4142645300-81699424-4017103561-1001\...\48e4cff94f039634) (Version: 3.0.0.0 - Best Buy)
Best Buy pc app (Version: 3.0.0.0 - Best Buy) Hidden
Blackboard IM 4.0.1-C (HKLM-x32\...\Blackboard IM) (Version: 4.0.1-C - Blackboard)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Choice Guard (x32 Version: 1.2.87.0 - Microsoft Corporation) Hidden
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 4.111.0.63 - Conexant)
ControlDeck (HKLM-x32\...\{5B65EF64-1DFA-414A-8C94-7BB726158E21}) (Version: 1.0.7 - ASUS)
CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3602c - CyberLink Corp.)
Dropbox (HKU\S-1-5-21-4142645300-81699424-4017103561-1001\...\Dropbox) (Version: 3.0.3 - Dropbox, Inc.)
ETDWare PS/2-x64 7.0.5.12_WHQL (HKLM\...\Elantech) (Version: 7.0.5.12 - ELAN Microelectronics Corp.)
Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.5 - ASUS)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.71 - Google Inc.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
GoPro Studio 2.5.1 (HKLM-x32\...\GoPro Studio) (Version: 2.5.1 - GoPro, Inc.)
Intel WiMAX Tutorial (HKLM\...\{4F26C164-9373-4974-8F43-E0F2176AF937}) (Version: 1.5.3.1 - Intel Corporation)
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2125 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation)
Intel® PROSet/Wireless WiFi Software (HKLM\...\{1A8BA6CE-822D-4888-89E2-ACBF4308F271}) (Version: 13.02.0000 - Intel Corporation)
Intel® Wireless Display (HKLM\...\{C298FF86-AB23-4B58-AC53-A23383C07B3A}) (Version: 1.2.20.0 - Intel Corporation)
Intel® PROSet/Wireless WiMAX Software (HKLM\...\{6548B189-BEA4-4041-80E0-AEB60548E046}) (Version: 2.03.0005 - Intel Corporation)
iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
JMicron Ethernet Adapter NDIS Driver (HKLM-x32\...\{96DCEE2F-98EE-4F80-8C0F-7C04D1FB9D7F}) (Version: 6.0.17.1 - JMicron Technology Corp.)
JMicron Flash Media Controller Driver (HKLM-x32\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: 1.0.33.2 - JMicron Technology Corp.)
Junk Mail filter update (x32 Version: 14.0.8050.1202 - Microsoft Corporation) Hidden
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM-x32\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Sync Framework Services Native v1.0 (x86) (HKLM-x32\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
PDF Settings CC (x32 Version: 12.0 - Adobe Systems Incorporated) Hidden
QuickTime (HKLM-x32\...\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}) (Version: 7.73.80.64 - Apple Inc.)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
USB 2.0 VGA UVC WebCam (HKLM\...\USB 2.0 VGA UVC WebCam) (Version: - )
Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
Windows Driver Package - GoPro (WinUSB) Universal Serial Bus devices (03/07/2012 ) (HKLM\...\0B624A43DD66DBF5CF3EDFA9741A364E688062A4) (Version: 03/07/2012 - GoPro)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8050.1202 - Microsoft Corporation)
Windows Live Sign-in Assistant (HKLM-x32\...\{9422C8EA-B0C6-4197-B8FC-DC797658CA00}) (Version: 5.000.818.6 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\...\{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}) (Version: 14.0.8050.1202 - Microsoft Corporation)
Windows Live Upload Tool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.30.2 - ASUS)
Wireless Console 3 (HKLM-x32\...\{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}) (Version: 3.0.17 - ASUS)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-4142645300-81699424-4017103561-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Gina Riebel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4142645300-81699424-4017103561-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Gina Riebel\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4142645300-81699424-4017103561-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Gina Riebel\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4142645300-81699424-4017103561-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Gina Riebel\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4142645300-81699424-4017103561-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Gina Riebel\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4142645300-81699424-4017103561-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Gina Riebel\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4142645300-81699424-4017103561-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Gina Riebel\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4142645300-81699424-4017103561-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Gina Riebel\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-4142645300-81699424-4017103561-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Gina Riebel\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
==================== Restore Points =========================
25-11-2014 21:57:33 Windows Update
30-11-2014 21:40:29 Windows Update
10-12-2014 23:40:48 Windows Update
19-12-2014 16:36:13 Windows Update
05-01-2015 20:00:49 Windows Update
05-01-2015 20:57:23 Windows Update
23-01-2015 20:42:48 Windows Update
31-01-2015 12:57:22 Windows Update
04-02-2015 13:07:03 Windows Update
04-02-2015 14:28:57 Configured LabelPrint
04-02-2015 19:15:24 OTL Restore Point - 2/4/2015 7:15:22 PM
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 20:34 - 2011-02-24 10:57 - 00430182 ____R C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 007guard.com
127.0.0.1 www.007guard.com
127.0.0.1 008i.com
127.0.0.1 008k.com
127.0.0.1 www.008k.com
127.0.0.1 00hq.com
127.0.0.1 www.00hq.com
127.0.0.1 010402.com
127.0.0.1 032439.com
127.0.0.1 www.032439.com
127.0.0.1 0scan.com
127.0.0.1 www.0scan.com
127.0.0.1 1-2005-search.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-domains-registrations.com
127.0.0.1 www.1-domains-registrations.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info
127.0.0.1 123haustiereundmehr.com
There are 1000 more lines.
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {14757B6A-E279-46AF-B194-C147746E8471} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {4CA0397A-B677-4682-8A21-1811183F52B4} - System32\Tasks\{3E249018-8149-4FB1-9203-84FB71F3F269} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.)
Task: {4FD9E66E-769F-45C5-8657-F66244319CA5} - System32\Tasks\ASUSControlDeck => C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe [2010-05-17] (asus)
Task: {5F0F7602-9CD4-41AB-8312-2E67383891C4} - System32\Tasks\SmartDefrag_Startup => C:\Program Files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe
Task: {5F74126E-9F5A-4C97-BF20-C0DBEF5EB04D} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-05-28] (ATK)
Task: {6D17B890-958F-4860-9CE4-D1C6F78A88AA} - System32\Tasks\RunTool => C:\Users\Gina Riebel\AppData\Local\1d5ca609-c328-4f2c-948d-86e91142228f\sysad.exe
Task: {742FD810-A421-41F1-8368-80E82EA48D01} - System32\Tasks\ASPG => C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe [2009-06-29] (ASUS)
Task: {88ED527A-D1B2-4F44-8A66-C199FF068B95} - System32\Tasks\{9DAB43F3-3ED9-465F-8658-685F4C3FAA6C} => pcalua.exe -a "C:\Program Files (x86)\LucKyShoPPer\UVOftsp6CkC5Rl.exe" -c /s /n /i:"ExecuteCommands;UninstallCommands" ""
Task: {C12E171D-1A73-4168-ABBF-FA91DC376457} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2009-07-23] (ATK)
Task: {D4705411-9ECA-43D1-ADD4-6147ACB25BFF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {DD9267E0-A058-4362-BEFD-387DDBCFEDD9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {EAE397F4-B77E-4084-81EC-9DB050B7ECEA} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2009-07-31] (ASUS)
Task: {F71846B0-7017-4BFF-B3C5-5A84A58E2378} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe [2007-11-30] ()
Task: {F8F3214B-0BB3-4B77-A0B4-15AA8FC24CC2} - System32\Tasks\AutoSmartDefrag => C:\Program Files (x86)\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
Task: {FC1289CE-705C-4857-8144-5CB58798102A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-04] (Adobe Systems Incorporated)
Task: {FCF80CE1-A5B2-4D86-96FA-F605E0E099B5} - System32\Tasks\{2A0516D3-2A34-4481-9C44-C94BF34E5D04} => pcalua.exe -a C:\ProgramData\SoftCouPo\Z3uqYnV23x77oA.exe -c /s /n /i:"ExecuteCommands;UninstallCommands" ""
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AutoSmartDefrag.job => C:\Program Files (x86)\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) ==============
2010-03-05 10:21 - 2010-03-05 10:21 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2010-01-11 11:27 - 2010-01-11 11:27 - 00017920 _____ () C:\Program Files\P4G\DevMng.dll
2010-05-05 19:22 - 2010-05-05 19:22 - 00108544 _____ () C:\Program Files\P4G\OvrClk.dll
2008-10-01 00:02 - 2008-10-01 00:08 - 00011264 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2010-08-18 12:08 - 2007-11-30 12:20 - 00051768 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
2010-03-05 10:21 - 2010-03-05 10:21 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2011-09-20 13:22 - 2011-09-20 13:22 - 22778928 _____ () C:\Program Files (x86)\Blackboard\Blackboard IM\blackboardim.exe
2010-07-02 14:36 - 2010-07-02 14:36 - 01597440 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
2010-04-26 11:52 - 2010-04-26 11:52 - 00059904 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\WimaxConsole.exe
2014-01-31 16:45 - 2014-01-31 16:45 - 04989296 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
2014-01-31 16:45 - 2014-01-31 16:45 - 00643952 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
2014-02-12 19:58 - 2014-02-12 19:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-12 19:58 - 2014-02-12 19:58 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2010-07-01 12:21 - 2010-07-01 12:21 - 00204800 _____ () C:\Program Files (x86)\asus\VirtualCamera\virtualCamera.ax
2014-02-02 14:26 - 2014-02-02 14:26 - 32733080 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libcef.dll
2014-10-21 18:22 - 2014-10-21 18:22 - 00750080 _____ () C:\Users\Gina Riebel\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2015-02-04 20:12 - 2015-02-04 20:12 - 00043008 _____ () c:\Users\Gina Riebel\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpgyc4b8.dll
2014-10-21 18:22 - 2014-10-21 18:22 - 00047616 _____ () C:\Users\Gina Riebel\AppData\Roaming\Dropbox\bin\libEGL.dll
2014-10-21 18:22 - 2014-10-21 18:22 - 00863744 _____ () C:\Users\Gina Riebel\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
2014-10-21 18:22 - 2014-10-21 18:22 - 00200704 _____ () C:\Users\Gina Riebel\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
2010-02-23 16:14 - 2010-02-23 16:14 - 00071680 _____ () C:\Program Files (x86)\ASUS\ControlDeck\Brightness.dll
2010-02-23 16:11 - 2010-02-23 16:11 - 00076288 _____ () C:\Program Files (x86)\ASUS\ControlDeck\Volume.dll
2010-02-23 16:12 - 2010-02-23 16:12 - 00186880 _____ () C:\Program Files (x86)\ASUS\ControlDeck\Resolution.dll
2010-02-23 16:14 - 2010-02-23 16:14 - 00050688 _____ () C:\Program Files (x86)\ASUS\ControlDeck\P4GControl.dll
2009-11-02 15:20 - 2009-11-02 15:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2009-11-02 15:23 - 2009-11-02 15:23 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2007-06-15 11:28 - 2007-06-15 11:28 - 00147456 _____ () C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll
2007-06-01 18:08 - 2007-06-01 18:08 - 00143360 _____ () C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
2014-11-30 21:44 - 2014-11-25 00:39 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\libglesv2.dll
2014-11-30 21:44 - 2014-11-25 00:39 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\libegl.dll
2014-11-30 21:44 - 2014-11-25 00:39 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\pdf.dll
2014-11-30 21:44 - 2014-11-25 00:39 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.71\ffmpegsumo.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Registry Areas =====================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-4142645300-81699424-4017103561-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Gina Riebel\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: ADSMTray => C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe
MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
==================== Accounts: =============================
Administrator (S-1-5-21-4142645300-81699424-4017103561-500 - Administrator - Disabled)
Gina Riebel (S-1-5-21-4142645300-81699424-4017103561-1001 - Administrator - Enabled) => C:\Users\Gina Riebel
Guest (S-1-5-21-4142645300-81699424-4017103561-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-4142645300-81699424-4017103561-1003 - Limited - Enabled)
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Microsoft Office Sessions:
=========================
Error: (03/30/2013 09:09:03 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 33 seconds with 0 seconds of active time. This session ended with a crash.
Error: (03/30/2013 09:08:07 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 71 seconds with 60 seconds of active time. This session ended with a crash.
==================== Memory info ===========================
Processor: Intel® Core i3 CPU M 370 @ 2.40GHz
Percentage of memory in use: 46%
Total physical RAM: 3884.56 MB
Available physical RAM: 2072.34 MB
Total Pagefile: 7767.3 MB
Available Pagefile: 5601.1 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:446.23 GB) (Free:351.46 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (Untitled) (CDROM) (Total:3.58 GB) (Free:0 GB) UDF
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: E0C5913D)
Partition 1: (Not Active) - (Size=19.5 GB) - (Type=1C)
Partition 2: (Active) - (Size=446.2 GB) - (Type=07 NTFS)
==================== End Of Log ============================