Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Unable to delete boostwebapp (adware) folder [Solved]

malware virus help cmd boostwebapp

  • This topic is locked This topic is locked

#1
crazyfrank39

crazyfrank39

    Member

  • Member
  • PipPip
  • 12 posts
Hello,

This is my first time posting so please bear with me.

So recently I have gotten a serious adware virus on my computer. What it does is whenever I open internet explorer and go on some site I get interrupted with an ad pop up that links me to who knows where. I tried going to on the IE ad-free browser, but I get the same pop ups.
So I looked and deleted unwanted programs from the control panel, also I did the same with the program files, and it still didn't go away. I reseted IE and same ads pop up. So after a scan with Kaspersky (spelled something like that) I saw that the ads were comming from certain .exe programs in a folder called " boostwebapp ". So I found it in my PrograData and I tried deleting it, but it did not work. The message I get is...

This file is too large to delete.

(it went something like that, im not at my computer right now, phone)

so I found a way through a video on how to get around the large file part with cmd. I used...

" rmdir /q /s C:\ProgramData\boostwebapp "

but it gave me the following...

" The Parameter is incorrect "

I got
error if I tried opening the file itself. Its just not accesable for some reason.
So I need help on how to delete this boostwebapp folder. I am quite knowledgable about computers, but not with things like
this, so any help is apprieciated, Thanks!
-Frank
  • 0

Advertisements


#2
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts

Minion%20Welcome.jpg


My name's Naathim and I'm a GeekU Minion! Now that we are mates and will be working together to clean your machine out of any junkware, feel free to call me Naat :)

Before we start please note the following:

icon_arrow.gif Analysis and research take some time, also sometimes real life gets in the way, please be patient.
icon_arrow.gif Limit your internet access to posting here, some infections just wait to steal typed-in passwords.
icon_arrow.gif Don't run any scripts or tools on your own, unsupervised usage may cause more harm than good.
icon_arrow.gif Paste the logs in your posts, attachments make my work harder and more complicated.
icon_arrow.gif Stay with me to the end, the absence of symtoms doesn't mean that your machine is fully operational.
icon_arrow.gif Note that we may live in totally different time zones, what may cause some delays between answers.

icon_idea.gif I can't foresee everything, so if anything unexpected happens, please stop and inform me!
icon_idea.gif There are no silly questions. Never be afraid to ask if in doubt!

Let's start and enjoy the fight! :)



This is a new infection around, so I'd like to see a set of diagnostic reports.




FRST.gif Scan with Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool and save it to your Desktop.
There will be two versions to download: 32-bit and 64-bit. Please download the one that is designed for your system. If you don't know which one should it be, download both of them and try each other out. Only one will run - this is the right one. Please leave it and delete the other.
  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    > XP users click run after receipt of Windows Security Warning - Open File.
    > 8 users will be prompted about Windows SmartScreen protection - click More information and Run.
  • When the tool opens click Yes to disclaimer.
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please include their content in your next reply.
  • 1

#3
crazyfrank39

crazyfrank39

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-05-2015
Ran by isaiah (administrator) on ISAIAH-PC on 06-05-2015 08:13:11
Running from C:\Users\isaiah\Desktop
Loaded Profiles: isaiah (Available profiles: isaiah)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(ArcSoft, Inc.) C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Brand Affinity Technologies) C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Updater\FantapperUpdater.exe
() C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031\nsbD48C.tmpfs
() C:\ProgramData\boostwebapp\1.1.0.31\gefwucu.EXE
() C:\ProgramData\boostwebapp\1.1.0.31\gefaucu.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\ProgramData\boostwebapp\1.1.0.31\XebbaEwyn.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Ulead Systems, Inc.) C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031\jnsm42CF.tmp
(Red Bend Ltd.) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\ProgramData\boostwebapp\1.1.0.31\Juanenodra.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
() C:\ProgramData\boostwebapp\1.1.0.31\gefducu.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Akamai Technologies, Inc.) C:\Users\isaiah\AppData\Local\Akamai\netsession_win.exe
(BitTorrent Inc.) C:\Users\isaiah\AppData\Roaming\uTorrent\uTorrent.exe
(Akamai Technologies, Inc.) C:\Users\isaiah\AppData\Local\Akamai\netsession_win.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
() C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
() C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Aeria Games & Entertainment) C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\Andy\HandyAndy.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
() C:\Program Files\Andy\AndyPriorityMgr.exe
(Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.2.1.1\Lightshot.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_17_0_0_169_ActiveX.exe
(Mozilla Corporation) C:\Users\isaiah\Desktop\Tor Browser\Browser\firefox.exe
() C:\Users\isaiah\Desktop\Tor Browser\Browser\TorBrowser\Tor\tor.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-25] (IDT, Inc.)
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [609144 2011-04-12] (Alps Electric Co., Ltd.)
HKLM\...\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1933584 2010-12-17] (Intel(R) Corporation)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [DellStage] => C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe [2195824 2012-02-01] ()
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-05] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [RoxWatchTray] => c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\...\Run: [Desktop Disc Tool] => c:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe [514544 2010-11-17] ()
HKLM-x32\...\Run: [Dell Registration] => C:\Program Files (x86)\System Registration\prodreg.exe [3926528 2010-08-23] (Dell, Inc.)
HKLM-x32\...\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
HKLM-x32\...\Run: [UVS10 Preload] => C:\Program Files (x86)\Ulead Systems\Ulead VideoStudio SE DVD\uvPL.exe [36864 2006-08-09] (Ulead Systems, Inc.)
HKLM-x32\...\Run: [AccuWeatherWidget] => C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe [968048 2012-02-01] ()
HKLM-x32\...\Run: [AVP] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356376 2012-12-24] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [Aeria Ignite] => C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-06] (Aeria Games & Entertainment)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226560 2014-11-18] ()
HKLM-x32\...\Run: [Andy] => C:\Program Files\Andy\HandyAndy.exe [896904 2014-10-22] ()
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [17418928 2012-07-13] (Skype Technologies S.A.)
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3492504 2012-12-24] (Electronic Arts)
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2889408 2015-04-13] (Valve Corporation)
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3674320 2013-01-08] (DT Soft Ltd)
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Run: [Akamai NetSession Interface] => C:\Users\isaiah\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-30] (Akamai Technologies, Inc.)
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Run: [uTorrent] => C:\Users\isaiah\AppData\Roaming\uTorrent\uTorrent.exe [1378640 2014-12-18] (BitTorrent Inc.)
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Run: [LightShot] => C:\Users\isaiah\AppData\Local\Skillbrains\lightshot\Lightshot.exe
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\MountPoints2: F - F:\INSTALL.EXE
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\MountPoints2: {3a94db90-8157-11e2-b692-ac7289429fb8} - E:\INSTALL.EXE
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Savant Web Server.lnk [2015-04-20]
ShortcutTarget: Savant Web Server.lnk -> C:\Savant\Savant.exe (Developed by Michael Lamont)
Startup: C:\Users\isaiah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk [2014-02-22]
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\isaiah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hqghumeaylnlf.lnk [2015-05-03]
ShortcutTarget: hqghumeaylnlf.lnk -> C:\ProgramData\{7112a4ab-4f5b-5213-7112-2a4ab4f592ad}\hqghumeaylnlf.exe (No File)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchy.easylifeapp.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://searchy.easylifeapp.com/
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=adknlg&chnl=adknlg&cd=2XzuyEtN2Y1L1Qzu0A0CyBtBzzzyyEtBzy0F0BzzzzyC0DyEtN0D0Tzu0CtBtDtCtN1L2XzutBtFtCtFtDtFtAtDtC&cr=304164244
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=adknlg&chnl=adknlg&cd=2XzuyEtN2Y1L1Qzu0A0CyBtBzzzyyEtBzy0F0BzzzzyC0DyEtN0D0Tzu0CtBtDtCtN1L2XzutBtFtCtFtDtFtAtDtC&cr=304164244
SearchScopes: HKLM -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL = http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
SearchScopes: HKLM-x32 -> Backup.Old.DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
SearchScopes: HKLM-x32 -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL = http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000 -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-03-10] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-03-10] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-03-10] (Microsoft Corporation)
BHO: NeWuSAveer -> {de3fbf61-62a0-4957-9460-bd3f936940ab} -> C:\Program Files (x86)\NeWuSAveer\LlL8WKoPVDgDEV.x64.dll No File
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-03-10] (Microsoft Corporation)
BHO-x32: NeWuSAveer -> {de3fbf61-62a0-4957-9460-bd3f936940ab} -> C:\Program Files (x86)\NeWuSAveer\LlL8WKoPVDgDEV.dll No File
Toolbar: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000 -> No Name - {687578B9-7132-4A7A-80E4-30EE31099E03} -  No File
Toolbar: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000 -> No Name - {9CF43840-9957-4411-9CCB-D996CD24A45A} -  No File
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2011-11-03] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
Winsock: Catalog9 01 C:\windows\SysWOW64\Juanenodra.dll [329216 2015-05-03] ()
Winsock: Catalog9 02 C:\windows\SysWOW64\Juanenodra.dll [329216 2015-05-03] ()
Winsock: Catalog9 03 C:\windows\SysWOW64\Juanenodra.dll [329216 2015-05-03] ()
Winsock: Catalog9 04 C:\windows\SysWOW64\Juanenodra.dll [329216 2015-05-03] ()
Winsock: Catalog9 16 C:\windows\SysWOW64\Juanenodra.dll [329216 2015-05-03] ()
Winsock: Catalog9-x64 01 C:\windows\system32\Juanenodra64.dll [398336 2015-05-03] ()
Winsock: Catalog9-x64 02 C:\windows\system32\Juanenodra64.dll [398336 2015-05-03] ()
Winsock: Catalog9-x64 03 C:\windows\system32\Juanenodra64.dll [398336 2015-05-03] ()
Winsock: Catalog9-x64 04 C:\windows\system32\Juanenodra64.dll [398336 2015-05-03] ()
Winsock: Catalog9-x64 16 C:\windows\system32\Juanenodra64.dll [398336 2015-05-03] ()
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2013-12-15] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-12-15] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2013-04-08] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2013-12-30] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2013-12-30] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll [2010-03-31] ( Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpWinExt,version=5.0 -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll [2010-08-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-10-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin-x32: @vizzed.com/VizzedRGR -> C:\Program Files (x86)\Vizzed\Vizzed Retro Game Room\NpVizzedRgr.dll [2013-01-11] (Vizzed.com)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-02] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4152253128-2157246082-1293380562-1000: @nsroblox.roblox.com/launcher -> C:\Users\isaiah\AppData\Local\Roblox\Versions\version-221a4807685c44e7\\NPRobloxProxy.dll [2012-05-24] ( Roblox Corporation)
FF Plugin HKU\S-1-5-21-4152253128-2157246082-1293380562-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\isaiah\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-03-24] (Unity Technologies ApS)
FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\Web Assistant\Firefox
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox
FF Extension: Bing Bar - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2011-08-23]
FF HKLM-x32\...\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension
FF Extension: Search Helper Extension - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension [2011-08-23]
FF HKLM-x32\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension
FF Extension: Default Manager - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2011-08-23]
FF HKLM-x32\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\Web Assistant\Firefox
FF HKLM-x32\...\Firefox\Extensions: [vi[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\[email protected]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2012-12-24]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2012-12-24]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF Extension: Content Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2012-12-24]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2012-12-24]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2012-12-24]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\BetterSurf\ff
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Better-Surf\ff
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha646\ff
FF HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Firefox\Extensions: [[email protected]] - C:\Users\isaiah\AppData\Roaming\Mozilla\Firefox\Profiles\profile\extensions\[email protected]
FF Extension: SpecialSavings - C:\Users\isaiah\AppData\Roaming\Mozilla\Firefox\Profiles\profile\extensions\[email protected] [2012-09-01]
FF Extension: No Name - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha646\ff [Not Found]

Chrome: 
=======
CHR StartupUrls: Default -> "https://www.google.com/"
CHR Profile: C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-05-04]
CHR Extension: (Google Docs) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-04]
CHR Extension: (Google Drive) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-04]
CHR Extension: (YouTube) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-04]
CHR Extension: (Google Search) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-04]
CHR Extension: (Google Sheets) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-05-04]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-04]
CHR Extension: (Google Wallet) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-05-04]
CHR Extension: (Gmail) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-04]
CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx [Not Found]
CHR HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pacgpkgadgmibnhpdidcnfafllnmeomc] - C:\Users\isaiah\AppData\Local\CRE\pacgpkgadgmibnhpdidcnfafllnmeomc.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [lmgdincpppijbgecdpafkaonihahdaof] - C:\ProgramData\wxDfast\lmgdincpppijbgecdpafkaonihahdaof.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [ohgcjecomkebbohfjgmncelbhogbbokf] - C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Player\\Fantapper.crx [2012-05-12]
CHR HKLM-x32\...\Chrome\Extension: [pacgpkgadgmibnhpdidcnfafllnmeomc] - C:\Users\isaiah\AppData\Local\CRE\pacgpkgadgmibnhpdidcnfafllnmeomc.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [poheodfamflhhhdcmjfeggbgigeefaco] - C:\Program Files (x86)\Better-Surf\ch\Chrome.crx [Not Found]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

Locked "imhmypneta" service could not be unlocked. <===== ATTENTION
Locked "jylvirmid" service could not be unlocked. <===== ATTENTION
Locked "QumbaFyvu" service could not be unlocked. <===== ATTENTION
Locked "tammgF119" service could not be unlocked. <===== ATTENTION
Locked "tammgR119" service could not be unlocked. <===== ATTENTION

R2 74e9abac; c:\Program Files (x86)\SoftwareHelp\SoftwareHelp.dll [1622528 2015-02-08] () [File not signed]
R2 ADExchange; C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [44736 2013-10-24] (ArcSoft, Inc.)
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-02-22] (Adobe Systems) [File not signed]
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356376 2012-12-24] (Kaspersky Lab ZAO)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [967040 2015-04-02] ()
R2 Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [897088 2010-11-03] (Intel Corporation) [File not signed]
R3 Bluetooth Media Service; C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [1298496 2010-11-03] (Intel Corporation) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2719928 2015-04-22] (Microsoft Corporation)
R2 DMAgent; C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [498688 2011-06-14] (Red Bend Ltd.) [File not signed]
R2 FTSvc; C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Updater\FantapperUpdater.exe [16896 2013-01-23] (Brand Affinity Technologies) [File not signed]
R3 Juanenodra; C:\ProgramData\boostwebapp\1.1.0.31\Juanenodra.exe [0 ] () <==== ATTENTION (zero size file/folder)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [399432 2012-09-29] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [676936 2012-09-29] (Malwarebytes Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-12-17] ()
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [998640 2015-04-05] (Overwolf LTD)
R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [75064 2014-11-20] ()
S4 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-13] (Microsoft Corporation)
R2 UleadBurningHelper; C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-09-28] (Ulead Systems, Inc.) [File not signed]
R2 WiMAXAppSrv; C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [986112 2011-06-14] (Intel(R) Corporation) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
R2 wyzicyjy; C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031\jnsm42CF.tmp [224768 2015-05-03] () [File not signed]
S2 DellDigitalDelivery; "C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe" [X]
R2 fyqeguzo; C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031\nsbD48C.tmpfs [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-02-27] (DT Soft Ltd)
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [458584 2012-06-19] (Kaspersky Lab ZAO)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [90208 2013-04-23] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [620128 2013-04-23] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [28504 2012-08-02] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29016 2012-10-25] (Kaspersky Lab)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29528 2012-10-25] (Kaspersky Lab)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54368 2013-06-18] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178448 2013-04-23] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25928 2012-09-29] (Malwarebytes Corporation)
S3 pfc; C:\Windows\SysWOW64\drivers\pfc.sys [10368 2003-09-19] (Padus, Inc.) [File not signed]
S3 PSMNBUS; C:\Windows\System32\DRIVERS\PSMNBUS.sys [107272 2013-11-21] (DEVGURU Co., LTD.)
S3 PSMNMDM; C:\Windows\System32\DRIVERS\PSMNMDM.sys [187144 2013-11-21] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 PSMNVSP; C:\Windows\System32\DRIVERS\PSMNVSP.sys [187144 2013-11-21] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 StkCMini; C:\Windows\System32\Drivers\StkCMini.sys [1917576 2010-06-07] (Syntek)
R5 tammgF119; C:\Windows\System32\Drivers\tammgF119.sys [34952 2015-05-03] () [File not signed]
R5 tammgR119; C:\Windows\System32\Drivers\tammgR119.sys [37000 2015-05-03] () [File not signed]
R5 imhmypneta;  <===== ATTENTION Locked Service
R5 jylvirmid;  <===== ATTENTION Locked Service
R5 QumbaFyvu;  <===== ATTENTION Locked Service
R5 tammgF119;  <===== ATTENTION Locked Service
R5 tammgR119;  <===== ATTENTION Locked Service
S3 VBoxDrv; \??\c:\Program Files\Oracle\VirtualBox\VBoxDrv.sys [X]
S3 X6va017; \??\C:\windows\SysWOW64\Drivers\X6va017 [X]
S3 xhunter1; \??\C:\windows\xhunter1.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-06 08:13 - 2015-05-06 08:13 - 00032729 _____ () C:\Users\isaiah\Desktop\FRST.txt
2015-05-06 08:12 - 2015-05-06 08:13 - 00000000 ____D () C:\FRST
2015-05-06 08:11 - 2015-05-06 08:11 - 02101760 _____ (Farbar) C:\Users\isaiah\Desktop\FRST64.exe
2015-05-05 16:37 - 2015-05-05 16:37 - 02960802 _____ () C:\windows\shost.bin
2015-05-04 21:39 - 2015-05-04 21:39 - 00797232 _____ (Generic ) C:\Users\isaiah\Downloads\java_runtime_enviroment_setup.exe
2015-05-04 21:27 - 2015-05-04 21:27 - 00002261 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-05-04 21:27 - 2015-05-04 21:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-05-03 22:10 - 2015-05-03 22:10 - 00000000 ____D () C:\Users\isaiah\AppData\Roaming\dlg
2015-05-03 22:08 - 2015-05-03 22:08 - 00000000 _____ () C:\END
2015-05-03 22:07 - 2015-05-03 22:07 - 00000000 ____D () C:\Users\isaiah\AppData\Local\SearchProtect
2015-05-03 22:07 - 2015-05-03 22:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD CODEC
2015-05-03 22:00 - 2015-05-03 22:00 - 00003464 _____ () C:\windows\System32\Tasks\ProPCCleaner_Popup
2015-05-03 22:00 - 2015-05-03 22:00 - 00003200 _____ () C:\windows\System32\Tasks\ProPCCleaner_Start
2015-05-03 21:59 - 2015-05-03 22:05 - 00000000 ____D () C:\Users\isaiah\AppData\Local\4C4C4544-1430690388-5A10-8058-C8C04F4C5031
2015-05-03 21:59 - 2015-05-03 21:59 - 00000000 ____D () C:\Users\isaiah\AppData\Local\Pro_PC_Cleaner
2015-05-03 21:53 - 2015-05-06 07:39 - 00004816 _____ () C:\windows\SysWOW64\Juanenodra.ini
2015-05-03 21:53 - 2015-05-06 07:39 - 00002720 _____ () C:\windows\SysWOW64\JuanenodraOff.ini
2015-05-03 21:53 - 2015-05-06 07:39 - 00002720 _____ () C:\windows\system32\JuanenodraOff.ini
2015-05-03 21:53 - 2015-05-05 22:33 - 00000000 ____D () C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031
2015-05-03 21:53 - 2015-05-03 21:53 - 00037000 _____ () C:\windows\system32\Drivers\tammgR119.sys
2015-05-03 21:53 - 2015-05-03 21:53 - 00034952 _____ () C:\windows\system32\Drivers\tammgF119.sys
2015-05-03 21:53 - 2015-05-03 21:53 - 00000000 ____D () C:\ProgramData\boostwebapp
2015-05-03 21:53 - 2015-05-03 17:13 - 00398336 _____ () C:\windows\system32\Juanenodra64.dll
2015-05-03 21:53 - 2015-05-03 17:12 - 00329216 _____ () C:\windows\SysWOW64\Juanenodra.dll
2015-04-29 20:04 - 2015-04-29 20:41 - 00000000 ____D () C:\Users\isaiah\Desktop\Music Sheets
2015-04-29 20:02 - 2015-04-29 20:02 - 00014281 _____ () C:\Users\isaiah\Downloads\Kirby Super Star - The Halberd.mid
2015-04-29 20:02 - 2015-04-29 20:02 - 00012331 _____ () C:\Users\isaiah\Downloads\Kirby Super Star - Cavios.mid
2015-04-22 20:06 - 2015-04-22 20:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot
2015-04-20 20:06 - 2015-04-20 20:06 - 00000000 ____D () C:\Savant
2015-04-20 20:06 - 2015-04-20 20:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Savant Web Server
2015-04-20 20:01 - 2015-04-20 20:03 - 01269567 _____ (Michael Lamont ) C:\Users\isaiah\Downloads\Savant31.exe
2015-04-19 20:52 - 2015-04-19 20:54 - 34404626 _____ () C:\Users\isaiah\Downloads\torbrowser-install-4.0.8_en-US.exe
2015-04-15 03:40 - 2015-04-15 03:41 - 01059952 _____ () C:\windows\Minidump\041515-109512-01.dmp
2015-04-14 18:49 - 2015-03-24 20:24 - 03298816 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 02553856 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00696320 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00191488 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00098304 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-04-14 18:49 - 2015-03-24 20:23 - 00135168 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-04-14 18:49 - 2015-03-24 20:23 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-04-14 18:49 - 2015-03-24 20:23 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2015-04-14 18:49 - 2015-03-24 20:00 - 00566784 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-04-14 18:49 - 2015-03-24 20:00 - 00173056 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-04-14 18:49 - 2015-03-24 20:00 - 00092672 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-04-14 18:49 - 2015-03-24 20:00 - 00033792 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-04-14 18:49 - 2015-03-24 20:00 - 00029696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-04-14 18:49 - 2015-03-22 20:25 - 00769536 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-04-14 18:49 - 2015-03-22 20:25 - 00726528 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-04-14 18:49 - 2015-03-22 20:24 - 00957952 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-04-14 18:49 - 2015-03-22 20:24 - 00419840 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-04-14 18:49 - 2015-03-22 20:24 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-04-14 18:49 - 2015-03-22 20:24 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2015-04-14 18:49 - 2015-03-22 20:24 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-04-14 18:49 - 2015-03-22 20:17 - 01111552 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-04-14 18:49 - 2015-03-16 22:22 - 05557696 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-04-14 18:49 - 2015-03-16 22:22 - 00155576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-04-14 18:49 - 2015-03-16 22:22 - 00095672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-04-14 18:49 - 2015-03-16 22:19 - 01727904 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-04-14 18:49 - 2015-03-16 22:17 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2015-04-14 18:49 - 2015-03-16 22:17 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00341504 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-04-14 18:49 - 2015-03-16 22:16 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-04-14 18:49 - 2015-03-16 22:15 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-04-14 18:49 - 2015-03-16 22:01 - 03976632 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-04-14 18:49 - 2015-03-16 22:01 - 03920824 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-04-14 18:49 - 2015-03-16 21:59 - 01309696 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2015-04-14 18:49 - 2015-03-16 21:57 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-04-14 18:49 - 2015-03-16 21:57 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-04-14 18:49 - 2015-03-16 21:57 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-04-14 18:49 - 2015-03-16 21:57 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-04-14 18:49 - 2015-03-16 21:56 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2015-04-14 18:49 - 2015-03-09 20:25 - 01882624 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2015-04-14 18:49 - 2015-03-09 20:21 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2015-04-14 18:49 - 2015-03-09 20:08 - 01237504 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2015-04-14 18:49 - 2015-03-09 20:05 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2015-04-14 18:49 - 2015-03-04 22:12 - 00404480 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2015-04-14 18:49 - 2015-03-04 21:05 - 00311808 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2015-04-14 18:48 - 2015-04-01 17:17 - 00389808 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-04-14 18:48 - 2015-04-01 16:49 - 00342704 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-04-14 18:48 - 2015-03-16 22:17 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-04-14 18:48 - 2015-03-16 22:16 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2015-04-14 18:48 - 2015-03-16 22:15 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-04-14 18:48 - 2015-03-16 22:15 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-04-14 18:48 - 2015-03-16 22:13 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-04-14 18:48 - 2015-03-16 22:13 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:57 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-04-14 18:48 - 2015-03-16 21:57 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-04-14 18:48 - 2015-03-16 21:57 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-04-14 18:48 - 2015-03-16 21:57 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-04-14 18:48 - 2015-03-16 21:57 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2015-04-14 18:48 - 2015-03-16 21:56 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2015-04-14 18:48 - 2015-03-16 21:56 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-04-14 18:48 - 2015-03-16 21:56 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2015-04-14 18:48 - 2015-03-16 21:56 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2015-04-14 18:48 - 2015-03-16 21:56 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-04-14 18:48 - 2015-03-16 21:56 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2015-04-14 18:48 - 2015-03-16 21:53 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-04-14 18:48 - 2015-03-16 21:53 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 20:45 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2015-04-14 18:48 - 2015-03-16 20:45 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2015-04-14 18:48 - 2015-03-16 20:43 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 20:43 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 20:43 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 20:43 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-04-14 18:48 - 2015-03-12 21:32 - 24980480 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-04-14 18:48 - 2015-03-12 21:25 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-04-14 18:48 - 2015-03-12 21:25 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-04-14 18:48 - 2015-03-12 21:09 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-04-14 18:48 - 2015-03-12 21:08 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-04-14 18:48 - 2015-03-12 21:08 - 00417280 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-04-14 18:48 - 2015-03-12 21:08 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-04-14 18:48 - 2015-03-12 21:07 - 02886144 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-04-14 18:48 - 2015-03-12 21:06 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-04-14 18:48 - 2015-03-12 21:00 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-04-14 18:48 - 2015-03-12 20:59 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-04-14 18:48 - 2015-03-12 20:55 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-04-14 18:48 - 2015-03-12 20:54 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-04-14 18:48 - 2015-03-12 20:54 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-04-14 18:48 - 2015-03-12 20:53 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-04-14 18:48 - 2015-03-12 20:50 - 06025216 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-04-14 18:48 - 2015-03-12 20:44 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-04-14 18:48 - 2015-03-12 20:42 - 19695616 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-04-14 18:48 - 2015-03-12 20:42 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-04-14 18:48 - 2015-03-12 20:40 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-04-14 18:48 - 2015-03-12 20:32 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-04-14 18:48 - 2015-03-12 20:28 - 00503296 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-04-14 18:48 - 2015-03-12 20:28 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-04-14 18:48 - 2015-03-12 20:27 - 00340992 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-04-14 18:48 - 2015-03-12 20:27 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-04-14 18:48 - 2015-03-12 20:27 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-04-14 18:48 - 2015-03-12 20:26 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-04-14 18:48 - 2015-03-12 20:26 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-04-14 18:48 - 2015-03-12 20:23 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-04-14 18:48 - 2015-03-12 20:22 - 02278400 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-04-14 18:48 - 2015-03-12 20:20 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-04-14 18:48 - 2015-03-12 20:20 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-04-14 18:48 - 2015-03-12 20:17 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-04-14 18:48 - 2015-03-12 20:16 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-04-14 18:48 - 2015-03-12 20:15 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-04-14 18:48 - 2015-03-12 20:08 - 00720384 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-04-14 18:48 - 2015-03-12 20:07 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-04-14 18:48 - 2015-03-12 20:06 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-04-14 18:48 - 2015-03-12 20:05 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-04-14 18:48 - 2015-03-12 20:05 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-04-14 18:48 - 2015-03-12 20:01 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-04-14 18:48 - 2015-03-12 20:00 - 14397440 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-04-14 18:48 - 2015-03-12 19:57 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-04-14 18:48 - 2015-03-12 19:56 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-04-14 18:48 - 2015-03-12 19:54 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-04-14 18:48 - 2015-03-12 19:49 - 04305408 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-04-14 18:48 - 2015-03-12 19:45 - 02358784 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-04-14 18:48 - 2015-03-12 19:44 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-04-14 18:48 - 2015-03-12 19:43 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-04-14 18:48 - 2015-03-12 19:42 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-04-14 18:48 - 2015-03-12 19:34 - 12825600 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-04-14 18:48 - 2015-03-12 19:33 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-04-14 18:48 - 2015-03-12 19:22 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-04-14 18:48 - 2015-03-12 19:20 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-04-14 18:48 - 2015-03-12 19:16 - 01311232 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-04-14 18:48 - 2015-03-12 19:14 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-04-14 18:48 - 2015-02-24 20:18 - 00754688 _____ (Microsoft Corporation) C:\windows\system32\Drivers\http.sys
2015-04-14 18:45 - 2015-03-03 21:55 - 00367552 _____ (Microsoft Corporation) C:\windows\system32\clfs.sys
2015-04-14 18:45 - 2015-03-03 21:41 - 00079360 _____ (Microsoft Corporation) C:\windows\system32\clfsw32.dll
2015-04-14 18:45 - 2015-03-03 21:10 - 00058880 _____ (Microsoft Corporation) C:\windows\SysWOW64\clfsw32.dll
2015-04-11 20:00 - 2015-04-11 20:05 - 01035272 _____ () C:\windows\Minidump\041115-35537-01.dmp

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-06 08:13 - 2013-02-25 20:47 - 00000000 ____D () C:\Users\isaiah\AppData\Roaming\uTorrent
2015-05-06 08:11 - 2014-01-25 14:48 - 00000390 _____ () C:\windows\Tasks\update-S-1-5-21-4152253128-2157246082-1293380562-1000.job
2015-05-06 08:03 - 2011-12-29 18:20 - 00000000 ____D () C:\Users\isaiah\AppData\Roaming\Skype
2015-05-06 08:02 - 2012-12-06 19:32 - 00000000 ____D () C:\Program Files (x86)\Origin
2015-05-06 07:50 - 2009-07-13 21:45 - 00028576 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-06 07:50 - 2009-07-13 21:45 - 00028576 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-06 07:46 - 2011-08-23 01:23 - 01860962 _____ () C:\windows\WindowsUpdate.log
2015-05-06 07:44 - 2012-12-24 13:12 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2015-05-06 07:42 - 2012-12-22 11:38 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-05-06 07:41 - 2012-09-12 18:15 - 00000894 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore1cd914d439221f3.job
2015-05-06 07:39 - 2012-12-24 11:46 - 00040679 _____ () C:\windows\setupact.log
2015-05-06 07:39 - 2009-07-13 22:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-05-06 07:38 - 2010-11-20 20:47 - 00339612 _____ () C:\windows\PFRO.log
2015-05-05 23:18 - 2012-09-12 18:15 - 00000898 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA1cd914d43dfa6d6.job
2015-05-05 23:15 - 2012-08-20 18:02 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-05-05 21:08 - 2014-01-25 14:48 - 00000390 _____ () C:\windows\Tasks\update-sys.job
2015-05-05 16:49 - 2014-10-09 21:15 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2015-05-04 21:27 - 2011-12-31 10:52 - 00000000 ____D () C:\Users\isaiah\AppData\Local\Google
2015-05-04 21:27 - 2011-12-31 10:52 - 00000000 ____D () C:\Program Files (x86)\Google
2015-05-04 21:16 - 2009-07-13 22:13 - 00823564 _____ () C:\windows\system32\PerfStringBackup.INI
2015-05-04 18:18 - 2012-04-17 18:25 - 00000506 _____ () C:\windows\Tasks\SystemToolsDailyTest.job
2015-05-03 21:01 - 2009-07-13 20:20 - 00000000 ____D () C:\windows\system32\NDF
2015-04-28 20:17 - 2015-02-08 21:41 - 00000000 ____D () C:\ProgramData\5551195122105854317
2015-04-28 20:04 - 2015-02-08 21:40 - 00000000 ____D () C:\ProgramData\{8613789a-ab6e-b73f-8613-3789aab6e26a}
2015-04-23 16:51 - 2011-12-24 22:45 - 00000000 ____D () C:\Users\isaiah\AppData\Roaming\Adobe
2015-04-22 20:06 - 2014-01-25 14:48 - 00003266 _____ () C:\windows\System32\Tasks\update-S-1-5-21-4152253128-2157246082-1293380562-1000
2015-04-22 20:06 - 2014-01-25 14:48 - 00000424 _____ () C:\Users\isaiah\AppData\Local\UserProducts.xml
2015-04-19 20:54 - 2013-12-21 22:08 - 00000000 ____D () C:\Users\isaiah\Desktop\Tor Browser
2015-04-16 18:15 - 2012-08-20 18:02 - 00778416 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-04-16 18:15 - 2012-08-20 18:02 - 00142512 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-16 18:15 - 2012-08-20 18:02 - 00003768 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-04-15 05:33 - 2009-07-13 20:20 - 00000000 ____D () C:\windows\rescache
2015-04-15 05:25 - 2009-07-13 20:20 - 00000000 ____D () C:\windows\AppCompat
2015-04-15 03:40 - 2013-03-28 10:11 - 603850817 _____ () C:\windows\MEMORY.DMP
2015-04-15 03:40 - 2013-03-28 10:11 - 00000000 ____D () C:\windows\Minidump
2015-04-15 03:27 - 2014-12-10 22:00 - 00000000 ____D () C:\windows\system32\appraiser
2015-04-15 03:27 - 2014-04-29 22:07 - 00000000 ___SD () C:\windows\system32\CompatTel
2015-04-15 03:27 - 2009-07-13 20:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2015-04-15 03:10 - 2011-08-23 01:36 - 00816178 _____ () C:\windows\SysWOW64\PerfStringBackup.INI
2015-04-15 03:08 - 2013-08-08 03:01 - 00000000 ____D () C:\windows\system32\MRT
2015-04-15 03:03 - 2012-01-23 20:22 - 128913832 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-04-11 12:10 - 2015-01-06 16:02 - 00000000 ____D () C:\Program Files (x86)\Overwolf

==================== Files in the root of some directories =======

2005-05-30 08:19 - 2012-12-23 03:14 - 0004115 ____H () C:\Users\isaiah\AppData\Roaming\isaiahlog.dat
2011-12-31 19:44 - 2014-11-30 01:31 - 0016896 _____ () C:\Users\isaiah\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-05 23:36 - 2015-01-10 02:01 - 0007606 _____ () C:\Users\isaiah\AppData\Local\Resmon.ResmonCfg
2014-01-25 14:48 - 2014-01-25 14:48 - 0000003 _____ () C:\Users\isaiah\AppData\Local\updater.log
2014-01-25 14:48 - 2015-04-22 20:06 - 0000424 _____ () C:\Users\isaiah\AppData\Local\UserProducts.xml
2012-12-24 13:15 - 2012-12-24 13:15 - 0017408 _____ () C:\Users\isaiah\AppData\Local\WebpageIcons.db

Some content of TEMP:
====================
C:\Users\isaiah\AppData\Local\Temp\0927BA7B.dll
C:\Users\isaiah\AppData\Local\Temp\2100.exe
C:\Users\isaiah\AppData\Local\Temp\226380_199177.exe
C:\Users\isaiah\AppData\Local\Temp\3faig5ns.dll
C:\Users\isaiah\AppData\Local\Temp\4c2459bebc146bfd821d90e28a2411ab.dll
C:\Users\isaiah\AppData\Local\Temp\6_Offer_12.exe
C:\Users\isaiah\AppData\Local\Temp\81c992b.exe
C:\Users\isaiah\AppData\Local\Temp\83929-92631-microsoft-office-2010.exe
C:\Users\isaiah\AppData\Local\Temp\a15154fd9009bc6f9bea0d0659312534.dll
C:\Users\isaiah\AppData\Local\Temp\bitool.dll
C:\Users\isaiah\AppData\Local\Temp\bpygdfsv.dll
C:\Users\isaiah\AppData\Local\Temp\CheatEngine62Clean.exe
C:\Users\isaiah\AppData\Local\Temp\conduitinstaller.exe
C:\Users\isaiah\AppData\Local\Temp\couponamazing.exe
C:\Users\isaiah\AppData\Local\Temp\cvtres.exe
C:\Users\isaiah\AppData\Local\Temp\DM1394570410.exe
C:\Users\isaiah\AppData\Local\Temp\fbyho1hu.dll
C:\Users\isaiah\AppData\Local\Temp\i4jdel0.exe
C:\Users\isaiah\AppData\Local\Temp\ICReinstall_donkey-kong.exe
C:\Users\isaiah\AppData\Local\Temp\IminentSetup.exe
C:\Users\isaiah\AppData\Local\Temp\instloffer.exe
C:\Users\isaiah\AppData\Local\Temp\InternetTurboSetup__1814_i1675065_il1537.exe
C:\Users\isaiah\AppData\Local\Temp\lnd15xiv.dll
C:\Users\isaiah\AppData\Local\Temp\nsb4CAB.tmp.exe
C:\Users\isaiah\AppData\Local\Temp\oi_{74E8797E-56B6-42A9-8C89-469757A0DC67}.exe
C:\Users\isaiah\AppData\Local\Temp\PCFixSpeedSetup.exe
C:\Users\isaiah\AppData\Local\Temp\photostage_1.0.0.50_1.5.0.130_update_all.exe
C:\Users\isaiah\AppData\Local\Temp\safeguard.exe
C:\Users\isaiah\AppData\Local\Temp\somoto_HD CODEC_1.0.exe
C:\Users\isaiah\AppData\Local\Temp\SpOrder.dll
C:\Users\isaiah\AppData\Local\Temp\supoptsetup.exe
C:\Users\isaiah\AppData\Local\Temp\tbcpa0.dll
C:\Users\isaiah\AppData\Local\Temp\UNINSTALL.EXE
C:\Users\isaiah\AppData\Local\Temp\Updater.exe
C:\Users\isaiah\AppData\Local\Temp\utt88CD.tmp.exe
C:\Users\isaiah\AppData\Local\Temp\winziprosetup-WZRO6_20130221.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-05-05 17:17

==================== End Of Log ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06-05-2015
Ran by isaiah at 2015-05-06 08:14:10
Running from C:\Users\isaiah\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-4152253128-2157246082-1293380562-500 - Administrator - Disabled)
Guest (S-1-5-21-4152253128-2157246082-1293380562-501 - Limited - Disabled)
isaiah (S-1-5-21-4152253128-2157246082-1293380562-1000 - Administrator - Enabled) => C:\Users\isaiah

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Kaspersky Internet Security (Enabled - Out of date) {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
AS: Kaspersky Internet Security (Enabled - Up to date) {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\uTorrent) (Version: 3.4.2.36802 - BitTorrent Inc.)
AdBlocker Manger (HKLM-x32\...\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version:  - AdBlocker Manger) <==== ATTENTION
Adobe Acrobat 5.0 (HKLM-x32\...\Adobe Acrobat 5.0) (Version: 5.0 - Adobe Systems, Inc.)
Adobe Flash Player 10 Plugin (HKLM-x32\...\{4ED0DB47-769D-4B71-8724-E7A5BFEA1D51}) (Version: 10.3.181.22 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Photoshop CS2 (HKLM-x32\...\Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}) (Version: 9.0 - Adobe Systems, Inc.)
Adobe Reader XI (11.0.10) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.3.633 - Adobe Systems, Inc.)
Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
Aeria Ignite (HKLM-x32\...\Aeria Ignite 1.13.3296) (Version: 1.13.3296 - Aeria Games & Entertainment)
Aeria Ignite (HKLM-x32\...\Aeria Ignite) (Version: 1.13.3296 - Aeria Games & Entertainment)
Aeria Ignite (x32 Version: 1.13.3296 - Aeria Games & Entertainment) Hidden
Akamai NetSession Interface (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Akamai) (Version:  - Akamai Technologies, Inc)
Alliance of Valiant Arms (HKLM-x32\...\Alliance of Valiant Arms) (Version:  - )
AMD Catalyst Install Manager (HKLM\...\{7071F235-9C2C-ACDE-36CC-E18034946DD7}) (Version: 8.0.891.0 - Advanced Micro Devices, Inc.)
Andy OS (HKLM-x32\...\Andy OS) (Version: 0.41 - Andy OS, Inc)
Anime Studio Debut 6.1 (HKLM-x32\...\Anime Studio Debut_is1) (Version:  - Smith Micro Software, Inc.)
AnyTrans 3.6.6 (HKLM-x32\...\{E580ED1F-AAF8-4F7E-B174-54BFA2B94E0B}}_is1) (Version: 3.6.6 - iMobie Inc.)
Apple Application Support (HKLM-x32\...\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2F72F540-1F60-4266-9506-952B21D6640D}) (Version: 6.1.0.13 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcSoft MediaConverter 8 (HKLM-x32\...\{2CAD3C16-ACD0-43E5-81DA-7E56C3E5336C}) (Version: 8.0.0.21 - ArcSoft)
ARMA 2 (HKLM-x32\...\Steam App 33900) (Version:  - Bohemia Interactive)
Ask Toolbar Updater (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.2.0.20007 - Ask.com) <==== ATTENTION
AssaultCube v1.1.0.4 (HKLM-x32\...\AssaultCube_v1.1.0.4) (Version: v1.1.0.4 - )
Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team)
AVS Video Converter 8.5 (HKLM-x32\...\AVS4YOU Video Converter 7_is1) (Version: 8.5.1.551 - Online Media Technologies Ltd.)
Battlefield: Bad Company 2 (HKLM-x32\...\Steam App 24960) (Version:  - DICE)
BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version:  - )
BattlEye Uninstall (HKLM-x32\...\BattlEye for A2) (Version:  - )
Bing Bar (HKLM-x32\...\{08234a0d-cf39-4dca-99f0-0c5cb496da81}) (Version: 6.0.2282.0 - Microsoft Corporation)
Bing Bar Platform (x32 Version: 6.0.2282.0 - Microsoft Corporation) Hidden
Bing Rewards Client Installer (x32 Version: 16.0.345.0 - Microsoft Corporation) Hidden
Blender (HKLM\...\Blender) (Version: 2.65a-release - Blender Foundation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
boostwebapp (HKLM-x32\...\{0E376CD8-8982-4BE6-b505-91881F3B3343}) (Version: 1.1.0.31 - boostwebapp) <==== ATTENTION
CamStudio version 2.6b (HKLM-x32\...\{2793F5A3-509A-4CB6-B014-1E0E0794351A}_is1) (Version: 2.6b - Download Freely, LLC)
Canon MP495 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP495_series) (Version:  - )
Cheat Engine 6.2 (HKLM-x32\...\Cheat Engine 6.2_is1) (Version:  - Dark Byte)
Club Penguin Money Maker (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\a87d8e93174496f4) (Version: 1.2.0.0 - ClubPenguinCP)
Cool AVI To WAV Converter 1.0 (HKLM-x32\...\Cool AVI To WAV Converter_is1) (Version:  - A Software Plus)
Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version:  - Valve)
CreaToon 3.0 (HKLM-x32\...\CreaToon 3.0) (Version:  - )
Cross Fire En (HKLM-x32\...\Cross Fire_is1) (Version:  - Z8Games.com)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.46.1.0328 - DT Soft Ltd)
DayZ (HKLM-x32\...\Steam App 221100) (Version:  - Bohemia Interactive)
DayZ Commander (HKLM-x32\...\{0B74EC0B-2A85-4542-A167-3DE2132E7DAA}) (Version: 0.92.85 - Dotjosh Studios)
DealNoDeal (HKLM-x32\...\{37476589-E48E-439E-A706-56189E2ED4C4}) (Version:  - DealNoDeal) <==== ATTENTION
Dell Digital Delivery (HKLM-x32\...\{31045ECE-019D-4DDF-A5C8-5C51A3FE50EE}) (Version: 1.7.4501.0 - Dell Products, LP)
Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Dell Getting Started Guide (HKLM-x32\...\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell MusicStage (HKLM-x32\...\{91AF2672-F5BC-42CF-8037-A9D2F92BBCC0}) (Version: 1.5.201.0 - Fingertapps)
Dell Perks Webslice IE8 (HKLM-x32\...\{CF67ED0C-F85D-4791-AED3-3FE882EDB45D}) (Version: 8.0 - Nextjump Inc)
Dell PhotoStage (HKLM-x32\...\{E4335E82-17B3-460F-9E70-39D9BC269DB3}) (Version: 1.5.0.65 - ArcSoft)
Dell Product Registration (HKLM-x32\...\{2A0F2CC5-3065-492C-8380-B03AA7106B1A}) (Version: 1.0.3 - Dell Inc.)
Dell Stage (HKLM-x32\...\{FE182796-F6BA-486A-8590-89B7E8D1D60F}) (Version: 1.7.209.0 - Fingertapps)
Dell Support Center (HKLM\...\Dell Support Center) (Version: 3.1.5907.23 - Dell Inc.)
Dell Support Center (Version: 3.1.5907.23 - PC-Doctor, Inc.) Hidden
Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.1209.101.204 - ALPS ELECTRIC CO., LTD.)
Dell VideoStage  (HKLM-x32\...\InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}) (Version: 1.2.0.1712 - CyberLink Corp.)
Dell VideoStage  (x32 Version: 1.2.0.1712 - CyberLink Corp.) Hidden
Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 2.00.44 - Creative Technology Ltd)
Dev-C++ (HKLM-x32\...\Dev-C++) (Version: 5.4.2 - )
DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden
DiscJuggler (HKLM-x32\...\{C3C538E5-524C-4253-AA74-0EEEF34990EA}) (Version: 4.10 - Padus, Inc.)
Doom Builder 2.1 (HKLM-x32\...\Doom Builder 2_is1) (Version:  - CodeImp)
Dystopia (HKLM-x32\...\Steam App 17580) (Version:  - Dystopia Team)
Explorer Suite IV (HKLM\...\Explorer Suite_is1) (Version:  - )
Fallout Mod Manager 0.12.6 (HKLM-x32\...\Fallout Mod Manager_is1) (Version:  - Timeslip, Q)
Fallout Mod Manager 0.13.21 (HKLM-x32\...\Generic Mod Manager_is1) (Version:  - Q, Timeslip)
Fantapper Player (HKLM-x32\...\{CDACD4C9-F984-409A-9D26-DF77E003FD89}) (Version: 2.0.3 - Brand Affinity Technologies)
Fantapper Updater (HKLM-x32\...\{57570C54-7615-4925-8219-895F01EBB16B}) (Version: 2.0.2 - Brand Affinity Technologies)
FileViewPro (HKLM\...\FileViewPro_is1) (Version: 4.0 - Solvusoft Corporation)
Finale NotePad 2007 (HKLM-x32\...\Finale NotePad 2007) (Version: 12.0.13 - MakeMusic)
Fraps (HKLM-x32\...\Fraps) (Version:  - )
Free AVI To MP3 Converter (HKLM-x32\...\{2A0E555E-1533-468E-B49E-4A39050FB562}) (Version: 1.0.0 - Convert Audio Free)
FreeOTFE Explorer (HKLM-x32\...\FreeOTFE Explorer) (Version:  - Sarah Dean)
GameMaker-Studio 1.1 (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\GameMaker-Studio11) (Version:  - YoYo Games Ltd.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 42.0.2311.135 - Google Inc.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
GTA San Andreas (HKLM-x32\...\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6324.0 - IDT)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Display Audio Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3097 - Intel Corporation)
Intel(R) Driver Update Utility 2.0 (x32 Version: 2.0.0.29 - Intel) Hidden
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{7CE8BE79-ABC3-4B2C-9543-28ED2B0A9EA8}) (Version: 1.0.0.0454 - Intel Corporation)
Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{290D4DB2-F1B4-4B8E-918D-D71EF29A001B}) (Version: 14.00.1000 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation)
Intel(R) Turbo Boost Technology Monitor 2.0 (HKLM\...\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.1.23.0 - Intel)
Intel(R) WiDi (HKLM-x32\...\{25680C01-6753-4FE9-A891-7857F26457C1}) (Version: 2.1.35.0 - Intel Corporation)
Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
Intel® Driver Update Utility (HKLM-x32\...\{8409c4f7-2340-4933-a304-5d37db4fb48b}) (Version: 2.0.0.29 - Intel)
Intel® PROSet/Wireless WiMAX Software (HKLM\...\{5C1DA3D9-F590-4317-A4FB-274F658E504B}) (Version: 6.05.0000 - Intel Corporation)
Internet Explorer (x32 Version: 8 - Microsoft Corporation) Hidden
iPhoneBrowser (HKLM-x32\...\{C1FCDCA1-2759-4E5E-84EE-3A665BB2F513}) (Version: 1.9.3 - Cranium Consulting and Custom Software)
iTunes (HKLM\...\{427174C0-096E-40D9-9684-9C109BEE2CBF}) (Version: 11.0.5.5 - Apple Inc.)
Java 7 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417045FF}) (Version: 7.0.450 - Oracle)
Java 7 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.450 - Oracle)
Java SE Development Kit 7 Update 45 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170450}) (Version: 1.7.0.450 - Oracle)
Java(TM) 6 Update 24 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416024FF}) (Version: 6.0.240 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Kaspersky Internet Security 2013 (HKLM-x32\...\InstallWIX_{560985FB-4B76-4121-9189-7A2CDC7886D6}) (Version: 13.0.1.4190 - Kaspersky Lab)
Kaspersky Internet Security 2013 (x32 Version: 13.0.1.4190 - Kaspersky Lab) Hidden
Lightshot-5.2.1.1 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.2.1.1 - Skillbrains)
Macromedia Flash 5 (HKLM-x32\...\{4C93C363-414E-11D4-9756-00C04F8EEB39}) (Version: 5 - Macromedia)
Malwarebytes Anti-Malware version 1.65.1.1000 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.65.1.1000 - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Help Viewer 1.0 (HKLM\...\Microsoft Help Viewer 1.0) (Version: 1.0.30319 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\OneDriveSetup.exe) (Version: 17.0.4023.1211 - Microsoft Corporation)
Microsoft OneNote 2013 - en-us (HKLM\...\OneNoteFreeRetail - en-us) (Version: 15.0.4711.1003 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 (HKLM-x32\...\{B7E38540-E355-3503-AFD7-635B2F2F76E1}) (Version: 9.0.30729.4974 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Express - ENU (HKLM-x32\...\Microsoft Visual C++ 2010 Express - ENU) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Express Prerequisites x64 - ENU (HKLM\...\{BCA26999-EC22-3007-BB79-638913079C9A}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
MonkeyJam 3_050529 (HKLM-x32\...\MonkeyJam_is1) (Version:  - GiantScreamingRobotMonkeys)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4711.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4711.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4711.1003 - Microsoft Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Oracle VM VirtualBox 4.3.18 (HKLM\...\{74B7E6F9-DCAC-4ADB-B2D0-EEFDD1B5AC25}) (Version: 4.3.18 - Oracle Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.1.3.2637 - Electronic Arts, Inc.)
Overwolf (HKLM-x32\...\Overwolf) (Version: 0.84.95.0 - Overwolf Ltd.)
Pantech PCSuite (HKLM-x32\...\{9BC95D0F-EE60-43FB-ACE8-7D91A2ED33F3}) (Version: 1.1 - Pantech)
Pantech PCSuite (x32 Version: 1.1 - Pantech) Hidden
Pantech Unified USB Driver Ver1 (HKLM\...\{19E88D03-44D4-46aa-9F3C-D6CFC035BFE6}) (Version: 4.14.2.0 - Pantech)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.0 - Frank Heindörfer, Philip Chinery)
PFConfig 1.0.296 (HKLM-x32\...\PFConfig) (Version: 1.0.296 - Portforward.com)
PhotoShowExpress (x32 Version: 2.0.063 - Sonic Solutions) Hidden
Picmeta PhotoTracker v1.5 (HKLM-x32\...\Picmeta PhotoTracker_is1) (Version:  - Picmeta Systems)
Pivot Animator version 4.1.5 (HKLM-x32\...\Pivot Animator_is1) (Version: 4.1.5 - Motus Software Ltd)
Play withSIX (HKLM-x32\...\{D7F3EEAD-183C-47DE-BDC5-593539573F97}) (Version: 1.30.0476 - SIX Networks)
Portforward Static IP Address 1.0.47 (HKLM-x32\...\Portforward Static IP Address) (Version: 1.0.47 - Portforward.com)
Powerbullet Presenter  1.44 (HKLM-x32\...\Powerbullet Presenter_is1) (Version: 1.44 - DDD Pty Ltd)
PowerISO (HKLM-x32\...\PowerISO) (Version: 5.5 - Power Software Ltd)
PremiumSctructure (HKLM-x32\...\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{74e9abac}) (Version:  - PremiumSctructure) <==== ATTENTION
Project Zomboid Demo (HKLM-x32\...\Steam App 264910) (Version:  - Indie Stone Studios)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.988 - Even Balance, Inc.)
PX3 Presets Manager (HKLM-x32\...\{83030E21-76C9-4EFB-8182-EBC9B851B631}) (Version: 1.00.0000 - Turtle Beach)
Pyware 3D Performer's Practice Tools (HKLM-x32\...\Pyware 3D Performer's Practice Tools) (Version: 1.0.0.0 - Pygraphics)
Quick SEO  PageRank Backlinks  Alexa Tool (HKLM-x32\...\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}) (Version:  - ) <==== ATTENTION
RBVirtualFolder64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.31.1025.2010 - Realtek)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30126 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden
Roadkil's Unstoppable Copier Version 5.2 (HKLM-x32\...\{A306FD29-7D3A-4287-91AC-9A0180931395}_is1) (Version:  - Roadkil.Net)
Roblox for isaiah (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version:  - ROBLOX Corporation)
Roxio Creator Starter (HKLM-x32\...\{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}) (Version: 12.1.77.0 - Roxio)
Roxio File Backup (Version: 1.3.2 - Roxio) Hidden
Savant Web Server (HKLM-x32\...\Savant Web Server) (Version:  - )
Sibelius 6 Demo (HKLM-x32\...\{A67C4EF9-725D-4C83-A67A-BB7B7DE96CF4}) (Version: 6.0.0 - Sibelius Software)
SketchUp 2015 (HKLM-x32\...\{D0A0BE3D-8D66-4BE9-87C4-D30CA5AA93A3}) (Version: 15.3.330 - Trimble Navigation Limited)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 5.10 (HKLM-x32\...\{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}) (Version: 5.10.116 - Skype Technologies S.A.)
SlimDX Runtime .NET 2.0 (January 2012) (HKLM-x32\...\{014A2868-BE56-4888-A16C-693989B8F153}) (Version: 2.0.13.43 - SlimDX Group)
Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0 - Sonic Solutions) Hidden
Sothink SWF Decompiler (HKLM-x32\...\{BCDB856C-D247-4DEE-9132-89C02F4D6B8C}_is1) (Version: 7.3 - SourceTec Software Co., LTD)
Sound Forge Audio Studio 10.0 (HKLM-x32\...\{7A263871-BEEC-11E1-AC53-F04DA23A5C58}) (Version: 10.0.178 - Sony)
Source SDK (HKLM-x32\...\Steam App 211) (Version:  - Valve)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synfig Studio (HKLM-x32\...\synfigstudio) (Version: 0.63.05 - )
Synthesia (HKLM-x32\...\Synthesia) (Version: 8.5 - Synthesia LLC)
TeamSpeak 3 Client (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
The Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.42.130 - Electronic Arts)
TrustedID (HKLM-x32\...\{C16A92EF-017B-4839-9C75-FBADB5A1FA27}) (Version: 5.0 - TrustedID)
Ulead VideoStudio SE DVD (HKLM-x32\...\{8F8D9297-FDD2-405A-97E7-E52C7B2F97B3}) (Version: 10.0 - Ulead Systems)
Unisales (HKLM-x32\...\{4CEE92A3-9F0C-51AB-ADC0-34EC24AD7B7E}) (Version:  - ) <==== ATTENTION
Unity Web Player (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Unturned (HKLM-x32\...\Steam App 304930) (Version:  - Nelson Sexton)
USB2.0 Grabber (HKLM-x32\...\{45518B6D-9DDF-4144-83E4-A56762524F35}) (Version: 7.12.000.003 - Youyan)
USB2.0 Grabber (HKLM-x32\...\USB2.0 Grabber) (Version:  - )
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Vectorian Giotto 3.0.0 (HKLM-x32\...\Vectorian Giotto_is1) (Version:  - Vectorian Inc.)
Vegas Pro 11.0 (HKLM-x32\...\{B5B98340-0296-11E2-8B8E-F04DA23A5C58}) (Version: 11.0.700 - Sony)
Vizzed Retro Game Room (HKLM-x32\...\{6D9F35D2-1D6F-4E17-A79F-991A7BD24AAD}) (Version: 2.0.0 - Vizzed)
Watcom C/C++ 11.0c update (HKLM-x32\...\Watcom C/C++ 11.0c update) (Version:  - )
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
youtubeadblocker (HKLM-x32\...\{4820778D-AB0D-6D18-C316-52A6A0E1D507}) (Version:  - ) <==== ATTENTION

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\isaiah\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\isaiah\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\isaiah\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000_Classes\CLSID\{D45F043D-F17F-4e8a-8435-70971D9FA46D}\InprocServer32 -> C:\Program Files (x86)\Blender Foundation\Blender\BlendThumb64.dll ()
CustomCLSID: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\isaiah\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\isaiah\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\amd64\FileSyncApi64.dll (Microsoft Corporation)

==================== Restore Points  =========================

18-04-2015 21:22:55 Windows Update
24-04-2015 17:36:40 Windows Update
28-04-2015 19:49:07 Windows Update
28-04-2015 20:04:05 Windows Defender Checkpoint
02-05-2015 12:10:48 Windows Update
03-05-2015 22:02:15 Removed GeekBuddy.
03-05-2015 22:02:54 Removed GeekBuddy.

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 19:34 - 2009-06-10 14:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {009B39B9-D515-4222-9460-ED6785F4F071} - System32\Tasks\{2C364901-AA06-473D-A052-32F3F54F358F} => Chrome.exe 
Task: {09B760B5-3E15-486B-803B-EBE7E5B8A0D3} - System32\Tasks\0 => Iexplore.exe  <==== ATTENTION
Task: {0CEA552C-DEAC-4671-B3DA-621912592E15} - System32\Tasks\ProPCCleaner_Start => C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe <==== ATTENTION
Task: {0E51396B-770C-49BF-B1FA-676C467BB053} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {1533A718-3DD0-4CFB-884A-70FF635052B2} - System32\Tasks\{BA9B55D6-7F65-49D3-8DCB-061312A7342A} => pcalua.exe -a C:\watcom\WiseUpdt.exe
Task: {16FFA2EA-4B1F-4705-9797-24D152B7851B} - System32\Tasks\PCDEventLauncher => C:\Program Files\Dell Support Center\sessionchecker.exe [2012-04-12] (PC-Doctor, Inc.)
Task: {17455F81-AA8B-4290-9AD3-4224EA489A1E} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-24] (Microsoft Corporation)
Task: {30BFFF48-6CB9-4A1E-A459-69A36ECDCAFF} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-16] (Adobe Systems Incorporated)
Task: {40116C0B-5DE3-4E6B-8AFF-9EA10912B79E} - System32\Tasks\{2EC56597-00C3-4963-BC6D-ADE8D82FDEBA} => Chrome.exe 
Task: {402BF172-310F-4192-8621-30EE4F975021} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {49893E45-C793-41C8-A1E1-A0B3910F8FA1} - System32\Tasks\{6BAF6CF2-946F-4DA5-B798-6AB61E5D5E42} => pcalua.exe -a C:\Users\isaiah\Downloads\Video_AMD_W7W8_A01_Setup-HC6HJ_ZPE.exe -d C:\Users\isaiah\Downloads
Task: {652FECDA-01D6-4EA7-9041-71F8CBFF3250} - System32\Tasks\GoogleUpdateTaskMachineCore1cd914d439221f3 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-27] (Google Inc.)
Task: {66D27535-5824-48D3-BFB1-2C1EB6EC9E4C} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell Support Center\uaclauncher.exe [2012-04-12] (PC-Doctor, Inc.)
Task: {66F5E966-1F44-4B93-9815-E10CC8369415} - System32\Tasks\ProPCCleaner_Popup => C:\Program Files (x86)\Pro PC Cleaner\Splash.exe <==== ATTENTION
Task: {740F64E3-6804-4B65-BDEF-6B6079B6E1FA} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {85E5AA2C-0306-40C7-A15A-A74CFD01E346} - System32\Tasks\4804 => Wscript.exe C:\Users\isaiah\AppData\Local\Temp\launchie.vbs //B <==== ATTENTION
Task: {89F5D76B-44D0-4720-AA22-E4F0F748C937} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-04-22] (Microsoft Corporation)
Task: {9C0A281A-97FD-4069-9D3D-BDEE01F2A06D} - System32\Tasks\{2FCE4873-A2D4-4E7B-B47C-ADAE461EF62F} => pcalua.exe -a "C:\Dell\drivers\HC6HJ\9.003 WHQL W7 W8-PX4-121025a-155179C-Dell\Bin\ATISetup.exe" -d "C:\Dell\drivers\HC6HJ\9.003 WHQL W7 W8-PX4-121025a-155179C-Dell\Bin"
Task: {B61ED734-AEC9-42D8-9DB3-F23E666292A7} - System32\Tasks\{25DFC93A-00C6-4C5E-8A9A-BB58662B5618} => pcalua.exe -a "C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\BEsetup\Setup_BattlEyeARMA2OA.exe" -d "C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead" -c [email protected] -nosplash
Task: {BFC33A76-8AB6-4709-A53B-C8395B903833} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-04-22] (Microsoft Corporation)
Task: {C6EEAD65-894F-496C-A4F8-CA70AD8E32E4} - System32\Tasks\update-S-1-5-21-4152253128-2157246082-1293380562-1000 => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [2014-03-25] ()
Task: {CC20E6C7-257A-42EE-BA0E-998E308A1526} - System32\Tasks\update-sys => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [2014-03-25] ()
Task: {CEE40174-B983-473B-A23B-825539FBDD03} - System32\Tasks\{6D1CEE4C-F539-431C-A412-FC2054464041} => pcalua.exe -a "C:\Program Files (x86)\SelectRebates\SelectRebatesUninstall.exe"
Task: {D039104F-4509-4A6B-AC15-D5A07991011B} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2015-04-05] (Overwolf LTD)
Task: {D68C89CB-E545-46E2-8BA9-EA3087E1EAFF} - System32\Tasks\SystemToolsDailyTest => C:\Program Files\Dell Support Center\uaclauncher.exe [2012-04-12] (PC-Doctor, Inc.)
Task: {D6CB2D92-4982-47E2-9670-B905FC32D25D} - System32\Tasks\GoogleUpdateTaskMachineUA1cd914d43dfa6d6 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-27] (Google Inc.)
Task: {E561DE58-F951-47DC-9F53-04934CF99BD0} - System32\Tasks\{EADB7BAB-5FC3-4762-8ED3-C84EA699D41C} => pcalua.exe -a "C:\Program Files (x86)\Steam\steamapps\common\Arma 2\BEsetup\setup_BattlEyeARMA2.exe" -d "C:\Program Files (x86)\Steam\steamapps\common\Arma 2\BEsetup"
Task: {F17DD5FB-B78B-4831-A2C8-D843FB3CCEEA} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1cd914d439221f3.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA1cd914d43dfa6d6.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\PCDoctorBackgroundMonitorTask.job => C:\Program Files\Dell Support Center\uaclauncher.exeo-backgroundmon scripts\defaultscan.xml
Task: C:\windows\Tasks\SystemToolsDailyTest.job => C:\Program Files\Dell Support Center\uaclauncher.exe
Task: C:\windows\Tasks\update-S-1-5-21-4152253128-2157246082-1293380562-1000.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
Task: C:\windows\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe

==================== Loaded Modules (whitelisted) ==============

2015-05-03 21:53 - 2015-05-03 17:13 - 00398336 _____ () C:\windows\system32\Juanenodra64.dll
2010-12-17 11:53 - 2010-12-17 11:53 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2012-07-19 13:06 - 2005-03-12 00:07 - 00087040 _____ () C:\windows\System32\pdfcmnnt.dll
2014-10-09 21:15 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2015-05-03 21:53 - 2015-05-03 21:53 - 00141824 _____ () C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031\nsbD48C.tmpfs
2014-11-20 19:03 - 2014-11-20 19:03 - 00075064 _____ () C:\windows\SysWOW64\PnkBstrA.exe
2015-05-03 21:53 - 2015-05-03 21:54 - 00224768 _____ () C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031\jnsm42CF.tmp
2015-03-13 19:50 - 2015-01-27 08:29 - 08898720 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2011-08-23 04:00 - 2011-04-10 11:40 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2010-12-17 11:53 - 2010-12-17 11:53 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2010-11-17 08:35 - 2010-11-17 08:35 - 00514544 _____ () C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
2012-02-01 11:50 - 2012-02-01 11:50 - 00968048 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
2014-12-24 01:45 - 2014-10-22 16:36 - 00896904 _____ () C:\Program Files\Andy\HandyAndy.exe
2014-12-24 01:45 - 2014-10-20 15:34 - 00853896 _____ () C:\Program Files\Andy\AndyPriorityMgr.exe
1999-12-31 17:00 - 1999-12-31 17:00 - 01967616 _____ () C:\Users\isaiah\Desktop\Tor Browser\Browser\TorBrowser\Tor\tor.exe
2015-02-08 21:42 - 2015-02-08 21:42 - 01622528 _____ () c:\Program Files (x86)\SoftwareHelp\SoftwareHelp.dll
2013-04-21 21:44 - 2013-04-21 21:44 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2013-04-21 21:44 - 2013-04-21 21:44 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2012-08-17 22:39 - 2012-12-24 14:19 - 01310136 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\kpcengine.2.2.dll
2013-03-12 17:10 - 2015-03-09 23:37 - 00775680 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2015-01-19 19:03 - 2014-12-01 17:29 - 05002752 _____ () C:\Program Files (x86)\Steam\v8.dll
2015-01-19 19:03 - 2014-12-01 17:29 - 01612800 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2015-01-19 19:03 - 2014-12-01 17:29 - 01210368 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2014-05-21 16:39 - 2015-04-13 16:44 - 02371776 _____ () C:\Program Files (x86)\Steam\video.dll
2014-08-29 16:44 - 2014-12-01 14:31 - 02396672 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2014-08-29 16:44 - 2014-12-01 14:31 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2014-08-29 16:44 - 2014-12-01 14:31 - 00479744 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2014-08-29 16:44 - 2014-12-01 14:31 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2014-08-29 16:44 - 2014-12-01 14:31 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2013-08-01 14:49 - 2015-04-13 16:44 - 00702656 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2014-10-15 16:35 - 2014-10-15 16:35 - 00169472 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\93182e9779b8be0f688fd0784df6d7fb\IsdiInterop.ni.dll
2011-08-23 01:34 - 2010-11-05 21:50 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2010-11-24 20:44 - 2010-11-24 20:44 - 00375280 _____ () c:\program files (x86)\common files\roxio shared\dllshared\SQLite352.dll
2012-02-01 11:44 - 2012-02-01 11:44 - 08151040 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtGui4.dll
2012-02-01 11:44 - 2012-02-01 11:44 - 02278400 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtCore4.dll
2012-08-17 22:38 - 2012-08-17 22:38 - 00479160 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\dblite.dll
2012-08-17 22:40 - 2012-08-17 22:40 - 00068024 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\QtWebKit\qmlwebkitplugin4.dll
2013-08-01 14:49 - 2015-02-24 18:58 - 34641288 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
1999-12-31 17:00 - 1999-12-31 17:00 - 00091026 _____ () C:\Users\isaiah\Desktop\Tor Browser\Browser\libssp-0.dll
1999-12-31 17:00 - 1999-12-31 17:00 - 05057038 _____ () C:\Users\isaiah\Desktop\Tor Browser\Browser\mozjs.dll
1999-12-31 17:00 - 1999-12-31 17:00 - 00714452 _____ () C:\Users\isaiah\Desktop\Tor Browser\Browser\TorBrowser\Tor\libevent-2-0-5.dll
1999-12-31 17:00 - 1999-12-31 17:00 - 00091026 _____ () C:\Users\isaiah\Desktop\Tor Browser\Browser\TorBrowser\Tor\libssp-0.dll
1999-12-31 17:00 - 1999-12-31 17:00 - 00517814 _____ () C:\Users\isaiah\Desktop\Tor Browser\Browser\TorBrowser\Tor\libgcc_s_sjlj-1.dll
1999-12-31 17:00 - 1999-12-31 17:00 - 00110592 _____ () C:\Users\isaiah\Desktop\Tor Browser\Browser\TorBrowser\Tor\zlib1.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm
AlternateDataStreams: C:\Users\Public\DRM:احتضان

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Juanenodra => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, the associated entry will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\aeriagames.com -> hxxps://aeriagames.com
IE trusted site: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\aeriagames.com -> hxxp://aeriagames.com
IE trusted site: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\vizzed.com -> www.vizzed.com


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\isaiah\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.254

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: Dell Webcam Central => "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2

==================== FirewallRules (whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

FirewallRules: [{FB6C794F-7922-48D8-A3F1-A44404E84F12}] => (Allow) C:\Program Files (x86)\Dell\VideoStage\VideoStage.exe
FirewallRules: [{63854801-A57A-4ABB-81E7-5C4DC3157658}] => (Allow) C:\Program Files (x86)\Intel Corporation\Intel WiDi\WiDiApp.exe
FirewallRules: [{12585EEA-68D6-408D-8517-280CAA92E4A0}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{DD57CD94-27D6-4122-86EA-DB88430B1CB0}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{752E3E89-AF7E-4B59-8866-C7970C224C3C}] => (Allow) LPort=2869
FirewallRules: [{7A902977-647A-468E-8931-396ED9E71E84}] => (Allow) LPort=1900
FirewallRules: [{0F7E30EE-C410-4D29-B1F4-54FBE548FE97}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{CAE8A2FC-722C-48F6-A455-2FA259AE53A0}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{E9E30087-2443-4798-955C-EF1AA1491643}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{012CD4EF-672F-46AC-B9D0-F281B2AC810D}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{197528BE-073B-4AE2-8528-CD2CDD7362B3}] => (Allow) C:\Program Files\dell stage\dell stage\accuweather\accuweather.exe
FirewallRules: [{B5FC9064-61FB-4239-9AFE-850C68495823}] => (Allow) C:\Program Files\dell stage\musicstage\musicstageengine.exe
FirewallRules: [{A2D300F2-21DA-4A32-8699-FB1A6A12DDF4}] => (Allow) C:\Program Files\dell stage\dell stage\stage_primary.exe
FirewallRules: [{10ECBC56-DF4C-4E71-816C-83BA8FD49A89}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
FirewallRules: [{9CE7BF3D-062D-42AD-8664-A39A0C907B42}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
FirewallRules: [{C357C8ED-9A97-413B-89D6-CE4152DF55BB}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
FirewallRules: [{43AC5FE2-DDC5-43FA-9EB8-D615DA093668}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
FirewallRules: [{FAAB9E6F-CF0D-4E7F-BD82-71B6CB74C25E}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{E3A7C8B5-04AC-4D19-A2B2-95A2D17A9353}] => (Allow) C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\TroubleShooter.exe
FirewallRules: [{D60727C2-8C03-4F89-A2EB-5A3E44A14B91}] => (Allow) C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\TroubleShooter.exe
FirewallRules: [{C6A23999-B8F6-4CE2-97F6-00788ADE5CB8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{9317D26B-2F68-4672-8074-259E8E7D1338}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [TCP Query User{BB94525D-EC67-47B0-BE58-7BC5F9292A9C}C:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe] => (Allow) C:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe
FirewallRules: [UDP Query User{D2207485-A32A-4059-94F8-DFCA229F2841}C:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe] => (Allow) C:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe
FirewallRules: [TCP Query User{F6DFB93A-8C9A-45C9-A455-6A1072FC97E5}C:\users\isaiah\documents\arma 2\expansion\beta\arma2oa.exe] => (Allow) C:\users\isaiah\documents\arma 2\expansion\beta\arma2oa.exe
FirewallRules: [UDP Query User{941B0E54-6AA8-4A41-B666-1026F440C875}C:\users\isaiah\documents\arma 2\expansion\beta\arma2oa.exe] => (Allow) C:\users\isaiah\documents\arma 2\expansion\beta\arma2oa.exe
FirewallRules: [{96D96BA7-F17E-46E6-B4BF-F12C56B103FA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2\arma2.exe
FirewallRules: [{314B7D78-94A0-4349-BBC9-33624EC89331}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2\arma2.exe
FirewallRules: [{15895A70-9802-4D97-8898-400EC4C2D843}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\ArmA2OA.exe
FirewallRules: [{9EB13300-A4B1-4112-8910-036629D5D11A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\ArmA2OA.exe
FirewallRules: [{4836FCF4-9BB3-4902-8884-611EC0D21A28}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\BEsetup\Setup_BattlEyeARMA2OA.exe
FirewallRules: [{2E918AC1-DDFB-427D-BECB-1960AFC989D6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\BEsetup\Setup_BattlEyeARMA2OA.exe
FirewallRules: [TelnetServer-TlntSvr-TCP-In] => (Allow) %systemroot%\system32\tlntsvr.exe
FirewallRules: [TelnetServer-Tlntadmn-RPC-In] => (Allow) %systemroot%\system32\tlntsvr.exe
FirewallRules: [{B67463BB-F4A5-40AB-A436-C1D1D0880FBE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\Expansion\beta\Arma2OA.exe
FirewallRules: [{02540B9A-E497-451A-AFB6-CA886A07A548}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\Expansion\beta\Arma2OA.exe
FirewallRules: [{B5D857F8-0CEE-49B0-997E-7C48AD3E6325}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{A2F3C668-51FA-44F7-83AE-76F995FAA1D7}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{97D65CF0-84F6-4897-8A54-0C4420274BD8}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{03F4D284-2275-4B42-A6DC-986ADED7B968}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{86C04536-A007-4518-8A61-954D896FF24C}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{E6C8584E-37F7-4BB4-BB32-0414FDC000CC}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{45854D96-0B6E-4D00-95BA-8177382EF602}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{A8653AE9-C6A9-421C-8515-944A08409C68}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{3C3BCFAB-27C4-4293-B3DE-7B0E94B72CDD}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{E665FFC5-64AB-402F-BB02-C3F0CE12410B}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{B8512867-3199-4121-A49A-F5D5F7E1AF25}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{5F9F44AD-07FF-4299-A484-114C3CAEB1C4}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{2F3A8874-4A67-4D9A-BCCA-964FD36F3B5B}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{CDB939EB-A340-4729-BE7D-44E8A9584B54}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{FEF78855-BA7B-4BA2-AAB9-515515030BD0}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{C7BEAC9A-0718-4C6B-B0C9-648861548349}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{7B59DED9-4C84-4007-927D-DB2EEEE88ED6}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{D039FF42-7318-47AD-B987-1EBE71796652}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{EBEBD8A7-6048-4AA0-AED5-827C8783B484}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{1A1B1F5E-005A-486B-A9BC-D023C75C52A4}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{CED5EF5E-F614-4000-9F8A-C01E287FA528}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{64825B42-1996-49FF-A530-520AE090353D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{FF107C82-1939-4E90-9FC2-42224DF53860}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{28A958BD-7A82-431B-A2E2-9ED38A202C02}] => (Allow) C:\Users\isaiah\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{66C60478-1894-49A8-A443-F93E1368FF4C}] => (Allow) C:\Users\isaiah\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{C1A54FC1-C9B0-4491-B1E1-F8F36CE7FC3A}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{CCF76574-D646-45D1-82D3-2F1DCC3D34C0}] => (Allow) C:\Program Files (x86)\Sibelius Software\Sibelius 6 Demo\RegTool.exe
FirewallRules: [{BF8FC548-2863-4DD2-A9F4-AD96930853E2}] => (Allow) C:\Program Files (x86)\Sibelius Software\Sibelius 6 Demo\RegTool.exe
FirewallRules: [{A3715BD5-99B3-4818-B574-83BB0AE01B69}] => (Allow) C:\Program Files (x86)\Sibelius Software\Sibelius 6 Demo\Sibelius.exe
FirewallRules: [{9AADF8FE-3BB8-47BD-ADCA-377D0D6B6395}] => (Allow) C:\Program Files (x86)\Sibelius Software\Sibelius 6 Demo\Sibelius.exe
FirewallRules: [{E71C00F4-3C19-4CB6-9E9F-32C75850A280}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{E59972B6-F43D-45ED-A604-632CE54F8DEF}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{AD135AE5-93C1-4D3A-8B2C-959381FD9587}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{E69A4F65-9A83-4F50-9A77-3D01E82F25FC}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{9DBAD9EF-6D2A-45E5-9538-D9DCDB39A92A}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{54FE5C8B-7914-4EA7-9C12-5C47A6831CA6}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{5D6F0DD1-0361-476F-BBF9-CEF5AB0435EF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{1CD9158C-F9B2-477D-9964-5CBE968D8994}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{D147D394-73CD-4BB4-AFAF-D779C7868421}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{96435E38-7774-4E5D-954B-3A64449F753A}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{CE675344-42FD-40D9-BCF5-A56473C60EDD}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{DE895E9C-8FA0-4E94-864B-54A00980054A}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{50ECF78E-F2E1-44DC-9516-7C62377A07B7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dystopia\hl2.exe
FirewallRules: [{806EA9CC-A6BB-493E-AB32-90F1DDB0E631}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dystopia\hl2.exe
FirewallRules: [{397B6D36-497C-4868-A41A-40E03E1D9679}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{908AF1B7-82D9-4BB0-B47F-43AB55B88D88}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{FCE00889-A54B-47DA-93BB-AF20C9CD332C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{8B4B2CE7-3120-472D-8F7F-0DA54C027108}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{2A2E1B5C-545E-4013-B8BD-E6CF18A27DB6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{D268BEE6-1B40-4FDD-B133-0B13295A08E8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{A66DFEA2-A32F-4E6D-8672-687C606C27B1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{F3C0C2E5-100F-4083-AFCC-06C138B9EDD1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{2DB11E19-D773-4A30-A496-62D9F084FCAC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{46652C7F-B004-46A3-AF01-3B59029AE1FB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{7783C636-6DAA-4EE7-8B19-AA31FFCF1624}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{D49951CB-4AEC-40E6-9C0E-F63428F5F43B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{EF7C9F41-2702-4BBE-95B9-259E7FBA2200}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SourceSDK\bin\SDKLauncher.exe
FirewallRules: [{A24A339E-327E-4C4F-9F83-47F8A8964802}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SourceSDK\bin\SDKLauncher.exe
FirewallRules: [{D399BE08-1177-4881-9E93-1D73B67D225D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{178133F8-17F7-46D0-8FDF-B2FD7FC56135}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{C20197EE-C991-4084-B38A-2E8EFBE0C71E}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{7DCE9768-2811-4544-9195-FFF15C99CF1A}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{61DC4E84-48CA-41CC-81EC-8EE92BD69293}C:\users\isaiah\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\isaiah\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{FE3A2764-CDAD-45F4-A927-7696FF33B0C4}C:\users\isaiah\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\isaiah\appdata\local\akamai\netsession_win.exe
FirewallRules: [TCP Query User{15A3C15A-BA7C-4E64-9198-CF90BCAF2E60}C:\users\isaiah\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\isaiah\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{1EF7FB12-39FE-41EE-A725-9A9488E3439F}C:\users\isaiah\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\isaiah\appdata\local\akamai\netsession_win.exe
FirewallRules: [{4FDA637A-3EDA-4493-8BFA-B1BC41469C68}] => (Allow) C:\Users\isaiah\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{C3970759-44FA-45BE-A160-2C4E60B09FED}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Battlefield Bad Company 2\BFBC2Game.exe
FirewallRules: [{FD45BFEC-D668-4B4B-ABE1-F11199BA8940}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Battlefield Bad Company 2\BFBC2Game.exe
FirewallRules: [{7F4B2C0C-090E-4FEA-A11A-6FAC869CEA39}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{2521313E-7A6A-43F9-9AC7-8A936ECD0E41}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{024290EF-CCC1-4CAB-9744-75B05D31E44C}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{8DE86DB8-B999-49F5-A4F1-BBC16EFA8D39}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [TCP Query User{F8E7BA2B-C07C-45EA-A75E-F94337AA896F}C:\program files (x86)\starcraft\starcraft.exe] => (Block) C:\program files (x86)\starcraft\starcraft.exe
FirewallRules: [UDP Query User{4E49E8C7-0AC8-4AC0-A1C0-C29713D2F3B9}C:\program files (x86)\starcraft\starcraft.exe] => (Block) C:\program files (x86)\starcraft\starcraft.exe
FirewallRules: [{8A124A1B-6883-4FCB-AD6D-81040F867678}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ_BE.exe
FirewallRules: [{9D6830DA-BD7C-45D1-BABA-770F7957788A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ_BE.exe
FirewallRules: [TCP Query User{C3684451-AA8F-40BB-A78E-BF0E27D29CFE}C:\program files\java\jre7\bin\javaw.exe] => (Block) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{A5DE10FA-3FE8-423F-AFA6-7C9B743E710D}C:\program files\java\jre7\bin\javaw.exe] => (Block) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{12F07043-9EC9-43F2-B5B8-4110A638B150}C:\program files\andy\andy.exe] => (Allow) C:\program files\andy\andy.exe
FirewallRules: [UDP Query User{C6CAF11B-BDFD-407D-9536-9477D2431CA5}C:\program files\andy\andy.exe] => (Allow) C:\program files\andy\andy.exe
FirewallRules: [{204DD4E8-C91E-4992-A36D-F405E3E5235C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Project Zomboid Demo\ProjectZomboid64.exe
FirewallRules: [{1C10656A-C6E8-474F-ACD6-8882831063DB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Project Zomboid Demo\ProjectZomboid64.exe
FirewallRules: [TCP Query User{C8631496-3840-4660-8622-93DD79861543}C:\program files (x86)\the elder scrolls v skyrim\creationkit.exe] => (Allow) C:\program files (x86)\the elder scrolls v skyrim\creationkit.exe
FirewallRules: [UDP Query User{5C40F815-7D04-4652-9CA8-6565450F2384}C:\program files (x86)\the elder scrolls v skyrim\creationkit.exe] => (Allow) C:\program files (x86)\the elder scrolls v skyrim\creationkit.exe
FirewallRules: [TCP Query User{0FBA8A7A-C340-49AF-9637-A245740934D9}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{A78E5463-1B90-4D63-AD09-B4BCFA8553C4}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{08EA1A3E-B831-4F5D-999C-CB26DEEC2406}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{6CCF437F-603D-4C73-B9E6-73F8376AA5E0}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{DFE02089-F143-4BAE-A36E-510BB05E09C6}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{A5C7614C-3DD0-4BC7-9E50-D378C090B17C}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [{4FC4C42C-7832-4953-A273-799E62AE3633}] => (Allow) C:\Users\isaiah\AppData\Local\Temp\nsbE299.tmp\CnetInstaller-10257337.exe
FirewallRules: [{1E0CBCB6-D74A-430A-B754-A6D68B7FB243}] => (Allow) C:\Users\isaiah\AppData\Local\Temp\nsbE299.tmp\CnetInstaller-10257337.exe
FirewallRules: [TCP Query User{D27C5782-3133-4774-805A-A95F829BFAA9}C:\savant\savant.exe] => (Allow) C:\savant\savant.exe
FirewallRules: [UDP Query User{E364D1FE-4A01-476A-A0A8-B7B0882A7E2A}C:\savant\savant.exe] => (Allow) C:\savant\savant.exe
FirewallRules: [TCP Query User{4837C4D3-D04B-47AA-9145-C5B6ED44DD08}C:\savant\savant.exe] => (Block) C:\savant\savant.exe
FirewallRules: [UDP Query User{2EEC6FEB-3185-479B-B5DF-4E51F567E380}C:\savant\savant.exe] => (Block) C:\savant\savant.exe
FirewallRules: [{45C3E57E-1FF9-4BF7-8F48-25B0218C5D21}] => (Allow) C:\ProgramData\boostwebapp\1.1.0.31\gefaucu.EXE
FirewallRules: [{73B92472-2AFC-40AF-93B2-2B13839636C5}] => (Allow) C:\ProgramData\boostwebapp\1.1.0.31\gefaucu.EXE
FirewallRules: [{6EFFD7E9-B50D-450A-90D3-2AD488622840}] => (Allow) C:\ProgramData\boostwebapp\1.1.0.31\gefaucu.EXE
FirewallRules: [{7C55DD14-179F-4F6E-B947-3E8B8B51E8F3}] => (Allow) C:\ProgramData\boostwebapp\1.1.0.31\gefaucu.EXE
FirewallRules: [{906C62C6-360B-4E6B-B3BC-BE85F4D0EE64}] => (Allow) C:\ProgramData\boostwebapp\1.1.0.31\gefaucu.EXE
FirewallRules: [{EAB59816-4E3C-47B8-B5DF-5F10D9F6264A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============

Name: VirtualBox Host-Only Ethernet Adapter
Description: VirtualBox Host-Only Ethernet Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Oracle Corporation
Service: VBoxNetAdp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (05/06/2015 08:05:19 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program iexplore.exe version 11.0.9600.17728 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1be8

Start Time: 01d0880de34cb934

Termination Time: 3

Application Path: C:\Program Files\Internet Explorer\iexplore.exe

Report Id:

Error: (05/06/2015 07:39:55 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/05/2015 08:36:36 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (05/05/2015 08:36:35 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1".Error in manifest or policy file "C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2" on line C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Component 2: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Error: (05/05/2015 08:36:35 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (05/05/2015 08:36:34 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (05/05/2015 08:36:34 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (05/05/2015 05:18:30 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Activation context generation failed for "1".Error in manifest or policy file "2" on line 3.
Invalid Xml syntax.

Error: (05/05/2015 04:50:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/05/2015 04:36:58 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (05/06/2015 07:42:37 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Dell Digital Delivery Service service failed to start due to the following error: 
%%2

Error: (05/06/2015 07:42:18 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (05/06/2015 07:38:57 AM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \SystemRoot\SysWow64\drivers\pfc.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

Error: (05/06/2015 07:38:55 AM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \SystemRoot\SysWow64\drivers\pfc.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

Error: (05/05/2015 09:42:40 PM) (Source: DCOM) (EventID: 10016) (User: isaiah-PC)
Description: machine-defaultLocalActivation{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}isaiah-PCisaiahS-1-5-21-4152253128-2157246082-1293380562-1000LocalHost (Using LRPC)

Error: (05/05/2015 09:42:37 PM) (Source: DCOM) (EventID: 10016) (User: isaiah-PC)
Description: machine-defaultLocalActivation{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}isaiah-PCisaiahS-1-5-21-4152253128-2157246082-1293380562-1000LocalHost (Using LRPC)

Error: (05/05/2015 09:38:39 PM) (Source: DCOM) (EventID: 10016) (User: isaiah-PC)
Description: machine-defaultLocalActivation{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}isaiah-PCisaiahS-1-5-21-4152253128-2157246082-1293380562-1000LocalHost (Using LRPC)

Error: (05/05/2015 09:38:34 PM) (Source: DCOM) (EventID: 10016) (User: isaiah-PC)
Description: machine-defaultLocalActivation{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}isaiah-PCisaiahS-1-5-21-4152253128-2157246082-1293380562-1000LocalHost (Using LRPC)

Error: (05/05/2015 09:38:26 PM) (Source: DCOM) (EventID: 10016) (User: isaiah-PC)
Description: machine-defaultLocalActivation{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}isaiah-PCisaiahS-1-5-21-4152253128-2157246082-1293380562-1000LocalHost (Using LRPC)

Error: (05/05/2015 04:38:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Dell Digital Delivery Service service failed to start due to the following error: 
%%2


Microsoft Office Sessions:
=========================
Error: (05/06/2015 08:05:19 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe11.0.9600.177281be801d0880de34cb9343C:\Program Files\Internet Explorer\iexplore.exe

Error: (05/06/2015 07:39:55 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/05/2015 08:36:36 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\isaiah\Downloads\SoftonicDownloader_for_freeotfe-explorer.exe

Error: (05/05/2015 08:36:35 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Users\isaiah\Downloads\SoftonicDownloader_for_mario-paint-composer.exe

Error: (05/05/2015 08:36:35 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\isaiah\Downloads\SoftonicDownloader_for_padus-discjuggler.exe

Error: (05/05/2015 08:36:34 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\isaiah\Downloads\SoftonicDownloader_for_sibelius.exe

Error: (05/05/2015 08:36:34 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\isaiah\Downloads\SoftonicDownloader_for_sony-vegas-video.exe

Error: (05/05/2015 05:18:30 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Box Extension\SrchBxEx.dllC:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Box Extension\SrchBxEx.dll2

Error: (05/05/2015 04:50:18 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/05/2015 04:36:58 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


CodeIntegrity Errors:
===================================
  Date: 2014-10-12 17:49:34.587
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-12 17:49:34.577
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-12 17:49:34.577
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-12 17:49:34.567
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-12 17:49:34.557
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-12 17:49:34.557
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-08 19:31:35.104
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-08 19:31:35.104
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-08 19:31:35.094
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-08 19:31:35.014
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i5-2410M CPU @ 2.30GHz
Percentage of memory in use: 38%
Total physical RAM: 6051.17 MB
Available physical RAM: 3702.52 MB
Total Pagefile: 12100.54 MB
Available Pagefile: 9300.77 MB
Total Virtual: 8192 MB
Available Virtual: 8191.79 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:581.42 GB) (Free:255.34 GB) NTFS
Drive e: (SKYRIM_EN) (CDROM) (Total:5.12 GB) (Free:0 GB) UDF

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596.2 GB) (Disk ID: D9D722B7)
Partition 1: (Not Active) - (Size=100 MB) - (Type=DE)
Partition 2: (Active) - (Size=14.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=581.4 GB) - (Type=07 NTFS)

==================== End Of Log ============================

  • 0

#4
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts
OK, time to give MBAR a whirl.


MalwarebytesAntiRootkit.png Scan with Malwarebytes' Anti-Rootkit

Please download Malwarebytes' Anti-Rootkit and save the file to your desktop.
Note that the tool is still in its BETA stage, therefore not all functionalities may be added.
  • Right-click on MalwarebytesAntiRootkit.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • It will ask you for an extraction place - make sure you will unpack it to your desktop.
  • After the extraction, the tool should start itself (no action required).
  • On the Introduction screen click Next.
  • On the Update screen click Update.
  • When prompted about the succesful update, click Next.
  • On the Scan System screen, make sure that all three options
    • Drivers
    • Sectors
    • System
    are checked for scanning and press Scan.
Wait patiently and don't do anything on your machine while MBAR goes through your system!
  • If no infection is found, just close the tool.
  • If an infection is found, make sure that Create Restore Point is checked, then select Cleanup button to remove threats. The process will start and your machine will prompt you to reboot upon completion.
When finished (either with or without cleanup), please navigate to the MBAR directory.
Search there for these two files:
> mbar-log-date(time).txt
> system-log.txt
Please include the content of both files in your reply.
  • 1

#5
crazyfrank39

crazyfrank39

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

I cleaned up like you said and I still get the same ads and popups... Here are my logs. 

Malwarebytes Anti-Rootkit BETA 1.09.1.1004
www.malwarebytes.org

Database version:
  main:    v2015.05.07.05
  rootkit: v2015.04.21.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.17728
isaiah :: ISAIAH-PC [administrator]

5/7/2015 8:55:50 PM
mbar-log-2015-05-07 (20-55-50).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 423182
Time elapsed: 51 minute(s), 13 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 2
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\tammgF119 (Rootkit.Agent.A) -> Delete on reboot. [bb16e2aed7b3ea4c0f56afb76f96e11f]
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\tammgR119 (Rootkit.Agent.A) -> Delete on reboot. [f3de840ce4a6c5717de8224453b22dd3]

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 2
C:\WINDOWS\SYSTEM32\drivers\tammgF119.sys (PUP.Optional.CoolApps24.A) -> Delete on reboot. [1c27c55497d65114413e9e913187404a]
C:\WINDOWS\SYSTEM32\drivers\tammgR119.sys (PUP.Optional.CoolApps24.A) -> Delete on reboot. [96e86959f4a8189311e7856109b399a9]

Physical Sectors Detected: 0
(No malicious items detected)

(end)
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.09.1.1004

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 11.0.9600.17728

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.294000 GHz
Memory total: 6345113600, free: 3753582592

=======================================


---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.09.1.1004

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 11.0.9600.17728

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.294000 GHz
Memory total: 6345113600, free: 3744735232

Downloaded database version: v2015.05.07.05
Downloaded database version: v2015.04.21.01
Downloaded database version: v2015.05.06.01
=======================================
Initializing...
------------ Kernel report ------------
     05/07/2015 19:43:22
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\system32\DRIVERS\kl1.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\compbatt.sys
\SystemRoot\system32\drivers\BATTC.SYS
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\DRIVERS\iaStor.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\msahci.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\PxHlpa64.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\drivers\disk.sys
\SystemRoot\system32\drivers\CLASSPNP.SYS
\SystemRoot\system32\DRIVERS\dtsoftbus01.sys
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\DRIVERS\klif.sys
\SystemRoot\system32\DRIVERS\klflt.sys
\??\C:\windows\system32\Drivers\tammgF119.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\DRIVERS\kltdi.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\drivers\ws2ifsl.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\klim6.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\DRIVERS\termdd.sys
\??\C:\windows\system32\Drivers\tammgR119.sys
\SystemRoot\System32\Drivers\SCDEmu.SYS
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\DRIVERS\mssmbios.sys
\SystemRoot\system32\DRIVERS\kneps.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\igdkmd64.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\DRIVERS\HECIx64.sys
\SystemRoot\system32\drivers\usbehci.sys
\SystemRoot\system32\drivers\USBPORT.SYS
\SystemRoot\system32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\DRIVERS\Rt64win7.sys
\SystemRoot\system32\DRIVERS\NETwNs64.sys
\SystemRoot\system32\DRIVERS\vwifibus.sys
\SystemRoot\system32\DRIVERS\nusb3xhc.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\i8042prt.sys
\SystemRoot\system32\DRIVERS\Apfiltr.sys
\SystemRoot\system32\DRIVERS\klmouflt.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\klkbdflt.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\CmBatt.sys
\SystemRoot\system32\DRIVERS\wmiacpi.sys
\SystemRoot\system32\DRIVERS\CompositeBus.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\VBoxNetFlt.sys
\SystemRoot\system32\DRIVERS\swenum.sys
\SystemRoot\system32\DRIVERS\ks.sys
\SystemRoot\system32\DRIVERS\iwdbus.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\DRIVERS\bpenum.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\system32\DRIVERS\nusb3hub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\DRIVERS\stwrt64.sys
\SystemRoot\system32\DRIVERS\portcls.sys
\SystemRoot\system32\DRIVERS\drmk.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\DRIVERS\IntcDAud.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_iaStor.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\system32\DRIVERS\iBtFltCoex.sys
\SystemRoot\system32\DRIVERS\btmhsf.sys
\SystemRoot\System32\Drivers\BTHUSB.sys
\SystemRoot\System32\Drivers\bthport.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\System32\Drivers\usbvideo.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\CtClsFlt.sys
\SystemRoot\system32\DRIVERS\rfcomm.sys
\SystemRoot\system32\drivers\BthEnum.sys
\SystemRoot\system32\DRIVERS\bthpan.sys
\SystemRoot\System32\Drivers\bpusb.sys
\SystemRoot\system32\DRIVERS\btmaux.sys
\SystemRoot\system32\drivers\usbaudio.sys
\SystemRoot\system32\DRIVERS\bpmp.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\drivers\luafv.sys
\??\C:\windows\system32\drivers\mbam.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\DRIVERS\TurboB.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\DRIVERS\vwifimp.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\system32\DRIVERS\udfs.sys
\SystemRoot\System32\Drivers\fastfat.SYS
\??\C:\windows\system32\drivers\mbamchameleon.sys
\??\C:\windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\user32.dll
----------- End -----------
Done!

Scan started
Database versions:
  main:    v2015.05.07.05
  rootkit: v2015.04.21.01

<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa8007886060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8007886b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8007886060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa80058e8530, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xfffffa80058e2050, DeviceName: \Device\Ide\IAAStorageDevice-1\, DriverName: \Driver\iaStor\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
File C:\WINDOWS\SYSTEM32\drivers\tammgF119.sys will be destroyed
Infected: C:\WINDOWS\SYSTEM32\drivers\tammgF119.sys --> [PUP.Optional.CoolApps24.A]
File C:\WINDOWS\SYSTEM32\drivers\tammgR119.sys will be destroyed
Infected: C:\WINDOWS\SYSTEM32\drivers\tammgR119.sys --> [PUP.Optional.CoolApps24.A]
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: D9D722B7

Partition information:

    Partition 0 type is Other (0xde)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 2048  Numsec = 204800

    Partition 1 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 206848  Numsec = 30720000
    Partition file system is NTFS
    Partition is bootable

    Partition 2 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 30926848  Numsec = 1219334832

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0

Disk Size: 640135028736 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1250243728-1250263728)...
Done!
Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\tammgF119 --> [Rootkit.Agent.A]
Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\tammgR119 --> [Rootkit.Agent.A]
Scan finished
Creating System Restore point...
Cleaning up...
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Removal scheduling successful. System shutdown needed.
System shutdown occurred
=======================================


---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.09.1.1004

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 11.0.9600.17728

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.294000 GHz
Memory total: 6345113600, free: 4310867968

=======================================
Initializing...
------------ Kernel report ------------
     05/07/2015 20:55:40
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\CLASSPNP.SYS
\SystemRoot\System32\drivers\imofugc.sys
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\system32\DRIVERS\kl1.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\compbatt.sys
\SystemRoot\system32\drivers\BATTC.SYS
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\DRIVERS\iaStor.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\msahci.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\PxHlpa64.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\drivers\disk.sys
\SystemRoot\system32\DRIVERS\dtsoftbus01.sys
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\DRIVERS\klif.sys
\SystemRoot\system32\DRIVERS\klflt.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\DRIVERS\kltdi.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\drivers\ws2ifsl.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\klim6.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\DRIVERS\termdd.sys
\SystemRoot\System32\Drivers\SCDEmu.SYS
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\DRIVERS\mssmbios.sys
\SystemRoot\system32\DRIVERS\kneps.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\igdkmd64.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\DRIVERS\HECIx64.sys
\SystemRoot\system32\drivers\usbehci.sys
\SystemRoot\system32\drivers\USBPORT.SYS
\SystemRoot\system32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\DRIVERS\Rt64win7.sys
\SystemRoot\system32\DRIVERS\NETwNs64.sys
\SystemRoot\system32\DRIVERS\vwifibus.sys
\SystemRoot\system32\DRIVERS\nusb3xhc.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\i8042prt.sys
\SystemRoot\system32\DRIVERS\Apfiltr.sys
\SystemRoot\system32\DRIVERS\klmouflt.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\klkbdflt.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\CmBatt.sys
\SystemRoot\system32\DRIVERS\wmiacpi.sys
\SystemRoot\system32\DRIVERS\CompositeBus.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\VBoxNetFlt.sys
\SystemRoot\system32\DRIVERS\swenum.sys
\SystemRoot\system32\DRIVERS\ks.sys
\SystemRoot\system32\DRIVERS\iwdbus.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\DRIVERS\bpenum.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\system32\DRIVERS\nusb3hub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\DRIVERS\stwrt64.sys
\SystemRoot\system32\DRIVERS\portcls.sys
\SystemRoot\system32\DRIVERS\drmk.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\DRIVERS\IntcDAud.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_iaStor.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\system32\DRIVERS\iBtFltCoex.sys
\SystemRoot\system32\DRIVERS\btmhsf.sys
\SystemRoot\System32\Drivers\BTHUSB.sys
\SystemRoot\System32\Drivers\bthport.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\Drivers\usbvideo.sys
\SystemRoot\system32\DRIVERS\CtClsFlt.sys
\SystemRoot\system32\DRIVERS\rfcomm.sys
\SystemRoot\system32\drivers\BthEnum.sys
\SystemRoot\system32\DRIVERS\bthpan.sys
\SystemRoot\System32\Drivers\bpusb.sys
\SystemRoot\system32\DRIVERS\btmaux.sys
\SystemRoot\system32\drivers\usbaudio.sys
\SystemRoot\system32\DRIVERS\bpmp.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\DRIVERS\TurboB.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\DRIVERS\vwifimp.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\??\C:\windows\system32\Drivers\tammgF119.sys
\??\C:\windows\system32\Drivers\tammgR119.sys
\SystemRoot\System32\Drivers\fastfat.SYS
\SystemRoot\system32\DRIVERS\udfs.sys
\??\C:\windows\system32\drivers\mbam.sys
\??\C:\windows\system32\drivers\mbamchameleon.sys
\??\C:\windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\iertutil.dll
\Windows\System32\sechost.dll
\Windows\System32\imagehlp.dll
\Windows\System32\Wldap32.dll
\Windows\System32\usp10.dll
\Windows\System32\ole32.dll
\Windows\System32\oleaut32.dll
\Windows\System32\shell32.dll
\Windows\System32\wininet.dll
\Windows\System32\msvcrt.dll
\Windows\System32\psapi.dll
\Windows\System32\nsi.dll
\Windows\System32\advapi32.dll
\Windows\System32\clbcatq.dll
\Windows\System32\ws2_32.dll
\Windows\System32\gdi32.dll
\Windows\System32\urlmon.dll
\Windows\System32\difxapi.dll
\Windows\System32\imm32.dll
\Windows\System32\msctf.dll
\Windows\System32\comdlg32.dll
\Windows\System32\user32.dll
\Windows\System32\rpcrt4.dll
\Windows\System32\lpk.dll
\Windows\System32\shlwapi.dll
\Windows\System32\kernel32.dll
\Windows\System32\normaliz.dll
\Windows\System32\setupapi.dll
\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
\Windows\System32\cfgmgr32.dll
\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
\Windows\System32\crypt32.dll
\Windows\System32\comctl32.dll
\Windows\System32\devobj.dll
\Windows\System32\userenv.dll
\Windows\System32\wintrust.dll
\Windows\System32\KernelBase.dll
\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
\Windows\System32\msasn1.dll
\Windows\System32\profapi.dll
----------- End -----------
Done!

Scan started
Database versions:
  main:    v2015.05.07.05
  rootkit: v2015.04.21.01

<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa80078a5060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa80078a5b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa80078a5060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa80059934c0, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xfffffa8005906050, DeviceName: \Device\Ide\IAAStorageDevice-1\, DriverName: \Driver\iaStor\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
File C:\WINDOWS\SYSTEM32\drivers\tammgF119.sys will be destroyed
Infected: C:\WINDOWS\SYSTEM32\drivers\tammgF119.sys --> [PUP.Optional.CoolApps24.A]
File C:\WINDOWS\SYSTEM32\drivers\tammgR119.sys will be destroyed
Infected: C:\WINDOWS\SYSTEM32\drivers\tammgR119.sys --> [PUP.Optional.CoolApps24.A]
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: D9D722B7

Partition information:

    Partition 0 type is Other (0xde)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 2048  Numsec = 204800

    Partition 1 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 206848  Numsec = 30720000
    Partition file system is NTFS
    Partition is bootable

    Partition 2 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 30926848  Numsec = 1219334832

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0

Disk Size: 640135028736 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-2047-1250243728-1250263728)...
Done!
Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\tammgF119 --> [Rootkit.Agent.A]
Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\tammgR119 --> [Rootkit.Agent.A]
Scan finished
Creating System Restore point...
Cleaning up...
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Removal scheduling successful. System shutdown needed.
System shutdown occurred
=======================================



Edited by crazyfrank39, 08 May 2015 - 08:47 PM.

  • 0

#6
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts
OK, MBAR caught the two watchdogs - let's see how the things look now.



FRST.gif Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool.
  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    > XP users click run after receipt of Windows Security Warning - Open File.
    > 8 users will be prompted about Windows SmartScreen protection - click More information and Run.
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please include their content in your next reply.
  • 1

#7
crazyfrank39

crazyfrank39

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-05-2015
Ran by isaiah (administrator) on ISAIAH-PC on 09-05-2015 14:34:53
Running from C:\Users\isaiah\Desktop
Loaded Profiles: isaiah (Available profiles: isaiah)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ArcSoft, Inc.) C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Brand Affinity Technologies) C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Updater\FantapperUpdater.exe
() C:\ProgramData\boostwebapp\1.1.0.31\gefwucu.EXE
() C:\ProgramData\boostwebapp\1.1.0.31\gefaucu.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031\nsu9557.tmp
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\ProgramData\boostwebapp\1.1.0.31\XebbaEwyn.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Ulead Systems, Inc.) C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(Intel® Corporation) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031\jnsm42CF.tmp
(Red Bend Ltd.) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\ProgramData\boostwebapp\1.1.0.31\Juanenodra.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
() C:\ProgramData\boostwebapp\1.1.0.31\gefducu.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Akamai Technologies, Inc.) C:\Users\isaiah\AppData\Local\Akamai\netsession_win.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Akamai Technologies, Inc.) C:\Users\isaiah\AppData\Local\Akamai\netsession_win.exe
() C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
(Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.2.1.1\Lightshot.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-25] (IDT, Inc.)
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [609144 2011-04-12] (Alps Electric Co., Ltd.)
HKLM\...\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1933584 2010-12-17] (Intel® Corporation)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [DellStage] => C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe [2195824 2012-02-01] ()
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-05] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [RoxWatchTray] => c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\...\Run: [Desktop Disc Tool] => c:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe [514544 2010-11-17] ()
HKLM-x32\...\Run: [Dell Registration] => C:\Program Files (x86)\System Registration\prodreg.exe [3926528 2010-08-23] (Dell, Inc.)
HKLM-x32\...\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation)
HKLM-x32\...\Run: [UVS10 Preload] => C:\Program Files (x86)\Ulead Systems\Ulead VideoStudio SE DVD\uvPL.exe [36864 2006-08-09] (Ulead Systems, Inc.)
HKLM-x32\...\Run: [AccuWeatherWidget] => C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe [968048 2012-02-01] ()
HKLM-x32\...\Run: [Aeria Ignite] => C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-06] (Aeria Games & Entertainment)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226560 2014-11-18] ()
HKLM-x32\...\Run: [Andy] => C:\Program Files\Andy\HandyAndy.exe [896904 2014-10-22] ()
HKLM-x32\...\Run: [AVP] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [218880 2012-08-17] (Kaspersky Lab ZAO)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [17418928 2012-07-13] (Skype Technologies S.A.)
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3492504 2012-12-24] (Electronic Arts)
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2889408 2015-04-13] (Valve Corporation)
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3674320 2013-01-08] (DT Soft Ltd)
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Run: [Akamai NetSession Interface] => C:\Users\isaiah\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-30] (Akamai Technologies, Inc.)
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Run: [uTorrent] => C:\Users\isaiah\AppData\Roaming\uTorrent\uTorrent.exe [1378640 2014-12-18] (BitTorrent Inc.)
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\MountPoints2: F - F:\INSTALL.EXE
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\MountPoints2: {3a94db90-8157-11e2-b692-ac7289429fb8} - E:\INSTALL.EXE
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Savant Web Server.lnk [2015-04-20]
ShortcutTarget: Savant Web Server.lnk -> C:\Savant\Savant.exe (Developed by Michael Lamont)
Startup: C:\Users\isaiah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk [2014-02-22]
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.funmood...tC&cr=304164244
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.funmood...tC&cr=304164244
SearchScopes: HKLM -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL = http://www.bing.com/...rc=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
SearchScopes: HKLM-x32 -> Backup.Old.DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
SearchScopes: HKLM-x32 -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL = http://www.bing.com/...rc=IE-SearchBox
SearchScopes: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000 -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL =
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-03-10] (Microsoft Corporation)
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2012-08-17] (Kaspersky Lab ZAO)
BHO: ExstrraSavoinigS -> {59060e68-247a-431b-a61b-78837e4e796c} -> C:\Program Files (x86)\ExstrraSavoinigS\FH2hvZY9buOuAQ.x64.dll No File
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2012-08-17] (Kaspersky Lab ZAO)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll [2012-08-17] (Kaspersky Lab ZAO)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-03-10] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-03-10] (Microsoft Corporation)
BHO: NeWuSAveer -> {de3fbf61-62a0-4957-9460-bd3f936940ab} -> C:\Program Files (x86)\NeWuSAveer\LlL8WKoPVDgDEV.x64.dll No File
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll [2012-08-17] (Kaspersky Lab ZAO)
BHO: ShopDroP -> {ef35e7f1-d0a0-4199-95c0-269459afa4a7} -> C:\Program Files (x86)\ShopDroP\fnlIDiD1Lp2qbr.x64.dll No File
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2012-08-17] (Kaspersky Lab ZAO)
BHO-x32: ExstrraSavoinigS -> {59060e68-247a-431b-a61b-78837e4e796c} -> C:\Program Files (x86)\ExstrraSavoinigS\FH2hvZY9buOuAQ.dll No File
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2012-08-17] (Kaspersky Lab ZAO)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll [2012-08-17] (Kaspersky Lab ZAO)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-03-10] (Microsoft Corporation)
BHO-x32: NeWuSAveer -> {de3fbf61-62a0-4957-9460-bd3f936940ab} -> C:\Program Files (x86)\NeWuSAveer\LlL8WKoPVDgDEV.dll No File
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll [2012-08-17] (Kaspersky Lab ZAO)
BHO-x32: ShopDroP -> {ef35e7f1-d0a0-4199-95c0-269459afa4a7} -> C:\Program Files (x86)\ShopDroP\fnlIDiD1Lp2qbr.dll No File
Toolbar: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000 -> No Name - {687578B9-7132-4A7A-80E4-30EE31099E03} -  No File
Toolbar: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000 -> No Name - {9CF43840-9957-4411-9CCB-D996CD24A45A} -  No File
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2011-11-03] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
Handler: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll No File
Winsock: Catalog9 01 C:\windows\SysWOW64\Juanenodra.dll [329216 2015-05-03] ()
Winsock: Catalog9 02 C:\windows\SysWOW64\Juanenodra.dll [329216 2015-05-03] ()
Winsock: Catalog9 03 C:\windows\SysWOW64\Juanenodra.dll [329216 2015-05-03] ()
Winsock: Catalog9 04 C:\windows\SysWOW64\Juanenodra.dll [329216 2015-05-03] ()
Winsock: Catalog9 16 C:\windows\SysWOW64\Juanenodra.dll [329216 2015-05-03] ()
Winsock: Catalog9-x64 01 C:\windows\system32\Juanenodra64.dll [398336 2015-05-03] ()
Winsock: Catalog9-x64 02 C:\windows\system32\Juanenodra64.dll [398336 2015-05-03] ()
Winsock: Catalog9-x64 03 C:\windows\system32\Juanenodra64.dll [398336 2015-05-03] ()
Winsock: Catalog9-x64 04 C:\windows\system32\Juanenodra64.dll [398336 2015-05-03] ()
Winsock: Catalog9-x64 16 C:\windows\system32\Juanenodra64.dll [398336 2015-05-03] ()
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2013-12-15] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-12-15] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2013-04-08] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2013-12-30] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2013-12-30] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll [2010-03-31] ( Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpWinExt,version=5.0 -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll [2010-08-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-10-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin-x32: @vizzed.com/VizzedRGR -> C:\Program Files (x86)\Vizzed\Vizzed Retro Game Room\NpVizzedRgr.dll [2013-01-11] (Vizzed.com)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-02] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4152253128-2157246082-1293380562-1000: @nsroblox.roblox.com/launcher -> C:\Users\isaiah\AppData\Local\Roblox\Versions\version-221a4807685c44e7\\NPRobloxProxy.dll [2012-05-24] ( Roblox Corporation)
FF Plugin HKU\S-1-5-21-4152253128-2157246082-1293380562-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\isaiah\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-03-24] (Unity Technologies ApS)
FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\Web Assistant\Firefox
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox
FF Extension: Bing Bar - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2011-08-23]
FF HKLM-x32\...\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension
FF Extension: Search Helper Extension - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension [2011-08-23]
FF HKLM-x32\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension
FF Extension: Default Manager - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2011-08-23]
FF HKLM-x32\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\Web Assistant\Firefox
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\[email protected]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\BetterSurf\ff
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Better-Surf\ff
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha646\ff
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2015-05-09]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2015-05-09]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF Extension: Content Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2015-05-09]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2015-05-09]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2015-05-09]
FF HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Firefox\Extensions: [[email protected]] - C:\Users\isaiah\AppData\Roaming\Mozilla\Firefox\Profiles\profile\extensions\[email protected]
FF Extension: SpecialSavings - C:\Users\isaiah\AppData\Roaming\Mozilla\Firefox\Profiles\profile\extensions\[email protected] [2012-09-01]
FF Extension: No Name - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha646\ff [Not Found]

Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR StartupUrls: Default -> "https://www.google.com/"
CHR Profile: C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-05-04]
CHR Extension: (Google Docs) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-04]
CHR Extension: (Google Drive) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-04]
CHR Extension: (YouTube) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-04]
CHR Extension: (Google Search) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-04]
CHR Extension: (Google Sheets) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-05-04]
CHR Extension: (Clear Cache Shortcut) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnajhcakejgchhbjlchkfmdidgjefleg [2015-05-07]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-04]
CHR Extension: (Google Wallet) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-05-04]
CHR Extension: (Trend Micro Toolbar) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohhcpmplhhiiaoiddkfboafbhiknefdf [2015-05-08]
CHR Extension: (Gmail) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-04]
CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx [Not Found]
CHR HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pacgpkgadgmibnhpdidcnfafllnmeomc] - C:\Users\isaiah\AppData\Local\CRE\pacgpkgadgmibnhpdidcnfafllnmeomc.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [lmgdincpppijbgecdpafkaonihahdaof] - C:\ProgramData\wxDfast\lmgdincpppijbgecdpafkaonihahdaof.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [ohgcjecomkebbohfjgmncelbhogbbokf] - C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Player\\Fantapper.crx [2012-05-12]
CHR HKLM-x32\...\Chrome\Extension: [pacgpkgadgmibnhpdidcnfafllnmeomc] - C:\Users\isaiah\AppData\Local\CRE\pacgpkgadgmibnhpdidcnfafllnmeomc.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [poheodfamflhhhdcmjfeggbgigeefaco] - C:\Program Files (x86)\Better-Surf\ch\Chrome.crx [Not Found]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

Locked "imhmypneta" service could not be unlocked. <===== ATTENTION
Locked "jylvirmid" service could not be unlocked. <===== ATTENTION
Locked "QumbaFyvu" service could not be unlocked. <===== ATTENTION
Locked "tammgF119" service could not be unlocked. <===== ATTENTION
Locked "tammgR119" service could not be unlocked. <===== ATTENTION

R2 ADExchange; C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [44736 2013-10-24] (ArcSoft, Inc.)
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-02-22] (Adobe Systems) [File not signed]
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [218880 2012-08-17] (Kaspersky Lab ZAO)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [967040 2015-04-02] ()
R2 Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [897088 2010-11-03] (Intel Corporation) [File not signed]
R3 Bluetooth Media Service; C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [1298496 2010-11-03] (Intel Corporation) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2719928 2015-04-22] (Microsoft Corporation)
R2 DMAgent; C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [498688 2011-06-14] (Red Bend Ltd.) [File not signed]
R2 FTSvc; C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Updater\FantapperUpdater.exe [16896 2013-01-23] (Brand Affinity Technologies) [File not signed]
R3 Juanenodra; C:\ProgramData\boostwebapp\1.1.0.31\Juanenodra.exe [0 ] () <==== ATTENTION (zero size file/folder)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [398184 2012-12-14] (Malwarebytes Corporation) [File not signed]
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [682344 2012-12-14] (Malwarebytes Corporation) [File not signed]
R2 mikikycu; C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031\nsu9557.tmp [117248 2015-05-08] () [File not signed]
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-12-17] ()
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [998640 2015-04-05] (Overwolf LTD)
R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [75064 2014-11-20] ()
S3 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-13] (Microsoft Corporation)
R2 UleadBurningHelper; C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-09-28] (Ulead Systems, Inc.) [File not signed]
R2 WiMAXAppSrv; C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [986112 2011-06-14] (Intel® Corporation) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
R2 wyzicyjy; C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031\jnsm42CF.tmp [224768 2015-05-03] () [File not signed]
S2 DellDigitalDelivery; "C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-02-27] (DT Soft Ltd)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458584 2012-06-19] (Kaspersky Lab ZAO)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [89432 2012-08-13] (Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [611160 2012-10-25] (Kaspersky Lab)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [28504 2012-08-02] (Kaspersky Lab ZAO)
S3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29016 2012-10-25] (Kaspersky Lab)
S3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29528 2012-10-25] (Kaspersky Lab)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54104 2012-06-08] (Kaspersky Lab)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178008 2012-08-13] (Kaspersky Lab)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [24176 2012-12-14] (Malwarebytes Corporation) [File not signed]
S3 pfc; C:\Windows\SysWOW64\drivers\pfc.sys [10368 2003-09-19] (Padus, Inc.) [File not signed]
S3 PSMNBUS; C:\Windows\System32\DRIVERS\PSMNBUS.sys [107272 2013-11-21] (DEVGURU Co., LTD.)
S3 PSMNMDM; C:\Windows\System32\DRIVERS\PSMNMDM.sys [187144 2013-11-21] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 PSMNVSP; C:\Windows\System32\DRIVERS\PSMNVSP.sys [187144 2013-11-21] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 StkCMini; C:\Windows\System32\Drivers\StkCMini.sys [1917576 2010-06-07] (Syntek)
R5 tammgF119; C:\Windows\System32\Drivers\tammgF119.sys [34952 2015-05-03] () [File not signed]
R5 tammgR119; C:\Windows\System32\Drivers\tammgR119.sys [37000 2015-05-03] () [File not signed]
R5 imhmypneta;  <===== ATTENTION Locked Service
R5 jylvirmid;  <===== ATTENTION Locked Service
R5 QumbaFyvu;  <===== ATTENTION Locked Service
R5 tammgF119;  <===== ATTENTION Locked Service
R5 tammgR119;  <===== ATTENTION Locked Service
S3 VBoxDrv; \??\c:\Program Files\Oracle\VirtualBox\VBoxDrv.sys [X]
S3 X6va017; \??\C:\windows\SysWOW64\Drivers\X6va017 [X]
S3 xhunter1; \??\C:\windows\xhunter1.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-09 14:34 - 2015-05-09 14:34 - 00000000 ____D () C:\Users\isaiah\Desktop\FRST-OlderVersion
2015-05-09 14:29 - 2015-05-09 14:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2013
2015-05-09 14:29 - 2015-05-09 14:28 - 00001148 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security 2013.lnk
2015-05-09 14:28 - 2012-07-11 17:09 - 00064856 _____ (Kaspersky Lab) C:\windows\system32\klfphc.dll
2015-05-09 14:27 - 2015-05-09 14:27 - 00000000 ____D () C:\windows\ELAMBKUP
2015-05-09 14:27 - 2015-05-09 14:27 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab
2015-05-09 14:27 - 2012-10-25 17:23 - 00611160 _____ (Kaspersky Lab) C:\windows\system32\Drivers\klif.sys
2015-05-09 14:27 - 2012-08-13 18:24 - 00089432 _____ (Kaspersky Lab) C:\windows\system32\Drivers\klflt.sys
2015-05-09 14:22 - 2015-05-09 14:22 - 00000000 ____D () C:\Program Files\Trend Micro
2015-05-08 21:58 - 2015-05-08 21:58 - 00725281 _____ (Malwarebytes Corp.) C:\Users\isaiah\Downloads\mbar-1.09.1.1004 (1).exe.sqk8lhs.partial
2015-05-08 20:46 - 2015-05-03 21:53 - 00037000 _____ () C:\windows\system32\Drivers\tammgR119.sys
2015-05-08 20:45 - 2015-05-03 21:53 - 00034952 _____ () C:\windows\system32\Drivers\tammgF119.sys
2015-05-08 20:44 - 2015-05-08 20:44 - 00000000 _____ () C:\windows\DCEBOOT.LOG
2015-05-08 19:56 - 2015-05-08 19:56 - 00000010 _____ () C:\Users\isaiah\AppData\Local\sponge.last.runtime.cache
2015-05-08 19:15 - 2015-05-09 14:17 - 00236080 _____ (Trend Micro Inc.) C:\windows\RegBootClean64.exe
2015-05-08 19:15 - 2015-05-08 19:16 - 00025136 _____ (Trend Micro Inc.) C:\windows\DCEBoot64.exe
2015-05-08 18:43 - 2015-05-09 14:21 - 00000000 ____D () C:\ProgramData\Trend Micro
2015-05-08 18:39 - 2015-05-08 18:39 - 00000036 _____ () C:\Users\isaiah\AppData\Local\housecall.guid.cache
2015-05-08 18:28 - 2015-05-08 18:28 - 06630552 _____ (Trend Micro Inc.) C:\Users\isaiah\Downloads\TrendMicro_TAV_8.0_US-en_Downloader.exe
2015-05-07 19:43 - 2015-05-09 13:45 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-05-07 19:37 - 2015-05-08 20:41 - 00000000 ____D () C:\Users\isaiah\Desktop\mbar
2015-05-07 19:37 - 2015-05-08 19:48 - 00107736 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-05-07 19:31 - 2015-05-07 19:37 - 16502728 _____ (Malwarebytes Corp.) C:\Users\isaiah\Downloads\mbar-1.09.1.1004.exe
2015-05-06 08:14 - 2015-05-09 14:14 - 00032156 _____ () C:\Users\isaiah\Desktop\Addition.txt
2015-05-06 08:13 - 2015-05-09 14:35 - 00034103 _____ () C:\Users\isaiah\Desktop\FRST.txt
2015-05-06 08:12 - 2015-05-09 14:34 - 00000000 ____D () C:\FRST
2015-05-06 08:11 - 2015-05-09 14:34 - 02102784 _____ (Farbar) C:\Users\isaiah\Desktop\FRST64.exe
2015-05-05 16:37 - 2015-05-05 16:37 - 02960802 _____ () C:\windows\shost.bin
2015-05-04 21:39 - 2015-05-04 21:39 - 00797232 _____ (Generic ) C:\Users\isaiah\Downloads\java_runtime_enviroment_setup.exe
2015-05-04 21:27 - 2015-05-04 21:27 - 00002261 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-05-04 21:27 - 2015-05-04 21:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-05-03 22:10 - 2015-05-03 22:10 - 00000000 ____D () C:\Users\isaiah\AppData\Roaming\dlg
2015-05-03 22:08 - 2015-05-03 22:08 - 00000000 _____ () C:\END
2015-05-03 22:07 - 2015-05-03 22:07 - 00000000 ____D () C:\Users\isaiah\AppData\Local\SearchProtect
2015-05-03 22:07 - 2015-05-03 22:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD CODEC
2015-05-03 22:00 - 2015-05-03 22:00 - 00003464 _____ () C:\windows\System32\Tasks\ProPCCleaner_Popup
2015-05-03 22:00 - 2015-05-03 22:00 - 00003200 _____ () C:\windows\System32\Tasks\ProPCCleaner_Start
2015-05-03 21:59 - 2015-05-03 22:05 - 00000000 ____D () C:\Users\isaiah\AppData\Local\4C4C4544-1430690388-5A10-8058-C8C04F4C5031
2015-05-03 21:59 - 2015-05-03 21:59 - 00000000 ____D () C:\Users\isaiah\AppData\Local\Pro_PC_Cleaner
2015-05-03 21:53 - 2015-05-09 14:24 - 00004816 _____ () C:\windows\SysWOW64\Juanenodra.ini
2015-05-03 21:53 - 2015-05-09 14:24 - 00002720 _____ () C:\windows\SysWOW64\JuanenodraOff.ini
2015-05-03 21:53 - 2015-05-09 14:24 - 00002720 _____ () C:\windows\system32\JuanenodraOff.ini
2015-05-03 21:53 - 2015-05-08 20:37 - 00000000 ____D () C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031
2015-05-03 21:53 - 2015-05-03 21:53 - 00000000 ____D () C:\ProgramData\boostwebapp
2015-05-03 21:53 - 2015-05-03 17:13 - 00398336 _____ () C:\windows\system32\Juanenodra64.dll
2015-05-03 21:53 - 2015-05-03 17:12 - 00329216 _____ () C:\windows\SysWOW64\Juanenodra.dll
2015-04-29 20:04 - 2015-04-29 20:41 - 00000000 ____D () C:\Users\isaiah\Desktop\Music Sheets
2015-04-29 20:02 - 2015-04-29 20:02 - 00014281 _____ () C:\Users\isaiah\Downloads\Kirby Super Star - The Halberd.mid
2015-04-29 20:02 - 2015-04-29 20:02 - 00012331 _____ () C:\Users\isaiah\Downloads\Kirby Super Star - Cavios.mid
2015-04-22 20:06 - 2015-04-22 20:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot
2015-04-20 20:06 - 2015-04-20 20:06 - 00000000 ____D () C:\Savant
2015-04-20 20:06 - 2015-04-20 20:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Savant Web Server
2015-04-20 20:01 - 2015-04-20 20:03 - 01269567 _____ (Michael Lamont ) C:\Users\isaiah\Downloads\Savant31.exe
2015-04-19 20:52 - 2015-04-19 20:54 - 34404626 _____ () C:\Users\isaiah\Downloads\torbrowser-install-4.0.8_en-US.exe
2015-04-15 03:40 - 2015-04-15 03:41 - 01059952 _____ () C:\windows\Minidump\041515-109512-01.dmp
2015-04-14 18:49 - 2015-03-24 20:24 - 03298816 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 02553856 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00696320 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00191488 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00098304 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-04-14 18:49 - 2015-03-24 20:23 - 00135168 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-04-14 18:49 - 2015-03-24 20:23 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-04-14 18:49 - 2015-03-24 20:23 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2015-04-14 18:49 - 2015-03-24 20:00 - 00566784 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-04-14 18:49 - 2015-03-24 20:00 - 00173056 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-04-14 18:49 - 2015-03-24 20:00 - 00092672 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-04-14 18:49 - 2015-03-24 20:00 - 00033792 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-04-14 18:49 - 2015-03-24 20:00 - 00029696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-04-14 18:49 - 2015-03-22 20:25 - 00769536 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-04-14 18:49 - 2015-03-22 20:25 - 00726528 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-04-14 18:49 - 2015-03-22 20:24 - 00957952 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-04-14 18:49 - 2015-03-22 20:24 - 00419840 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-04-14 18:49 - 2015-03-22 20:24 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-04-14 18:49 - 2015-03-22 20:24 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2015-04-14 18:49 - 2015-03-22 20:24 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-04-14 18:49 - 2015-03-22 20:17 - 01111552 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-04-14 18:49 - 2015-03-16 22:22 - 05557696 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-04-14 18:49 - 2015-03-16 22:22 - 00155576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-04-14 18:49 - 2015-03-16 22:22 - 00095672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-04-14 18:49 - 2015-03-16 22:19 - 01727904 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-04-14 18:49 - 2015-03-16 22:17 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2015-04-14 18:49 - 2015-03-16 22:17 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00341504 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-04-14 18:49 - 2015-03-16 22:16 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-04-14 18:49 - 2015-03-16 22:15 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-04-14 18:49 - 2015-03-16 22:01 - 03976632 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-04-14 18:49 - 2015-03-16 22:01 - 03920824 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-04-14 18:49 - 2015-03-16 21:59 - 01309696 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2015-04-14 18:49 - 2015-03-16 21:57 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-04-14 18:49 - 2015-03-16 21:57 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-04-14 18:49 - 2015-03-16 21:57 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-04-14 18:49 - 2015-03-16 21:57 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-04-14 18:49 - 2015-03-16 21:56 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2015-04-14 18:49 - 2015-03-09 20:25 - 01882624 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2015-04-14 18:49 - 2015-03-09 20:21 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2015-04-14 18:49 - 2015-03-09 20:08 - 01237504 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2015-04-14 18:49 - 2015-03-09 20:05 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2015-04-14 18:49 - 2015-03-04 22:12 - 00404480 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2015-04-14 18:49 - 2015-03-04 21:05 - 00311808 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2015-04-14 18:48 - 2015-04-01 17:17 - 00389808 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-04-14 18:48 - 2015-04-01 16:49 - 00342704 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-04-14 18:48 - 2015-03-16 22:17 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-04-14 18:48 - 2015-03-16 22:16 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2015-04-14 18:48 - 2015-03-16 22:15 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-04-14 18:48 - 2015-03-16 22:15 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-04-14 18:48 - 2015-03-16 22:13 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-04-14 18:48 - 2015-03-16 22:13 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:57 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-04-14 18:48 - 2015-03-16 21:57 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-04-14 18:48 - 2015-03-16 21:57 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-04-14 18:48 - 2015-03-16 21:57 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-04-14 18:48 - 2015-03-16 21:57 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2015-04-14 18:48 - 2015-03-16 21:56 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2015-04-14 18:48 - 2015-03-16 21:56 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-04-14 18:48 - 2015-03-16 21:56 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2015-04-14 18:48 - 2015-03-16 21:56 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2015-04-14 18:48 - 2015-03-16 21:56 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-04-14 18:48 - 2015-03-16 21:56 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2015-04-14 18:48 - 2015-03-16 21:53 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-04-14 18:48 - 2015-03-16 21:53 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 20:45 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2015-04-14 18:48 - 2015-03-16 20:45 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2015-04-14 18:48 - 2015-03-16 20:43 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 20:43 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 20:43 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 20:43 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-04-14 18:48 - 2015-03-12 21:32 - 24980480 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-04-14 18:48 - 2015-03-12 21:25 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-04-14 18:48 - 2015-03-12 21:25 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-04-14 18:48 - 2015-03-12 21:09 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-04-14 18:48 - 2015-03-12 21:08 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-04-14 18:48 - 2015-03-12 21:08 - 00417280 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-04-14 18:48 - 2015-03-12 21:08 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-04-14 18:48 - 2015-03-12 21:07 - 02886144 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-04-14 18:48 - 2015-03-12 21:06 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-04-14 18:48 - 2015-03-12 21:00 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-04-14 18:48 - 2015-03-12 20:59 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-04-14 18:48 - 2015-03-12 20:55 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-04-14 18:48 - 2015-03-12 20:54 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-04-14 18:48 - 2015-03-12 20:54 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-04-14 18:48 - 2015-03-12 20:53 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-04-14 18:48 - 2015-03-12 20:50 - 06025216 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-04-14 18:48 - 2015-03-12 20:44 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-04-14 18:48 - 2015-03-12 20:42 - 19695616 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-04-14 18:48 - 2015-03-12 20:42 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-04-14 18:48 - 2015-03-12 20:40 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-04-14 18:48 - 2015-03-12 20:32 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-04-14 18:48 - 2015-03-12 20:28 - 00503296 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-04-14 18:48 - 2015-03-12 20:28 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-04-14 18:48 - 2015-03-12 20:27 - 00340992 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-04-14 18:48 - 2015-03-12 20:27 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-04-14 18:48 - 2015-03-12 20:27 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-04-14 18:48 - 2015-03-12 20:26 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-04-14 18:48 - 2015-03-12 20:26 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-04-14 18:48 - 2015-03-12 20:23 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-04-14 18:48 - 2015-03-12 20:22 - 02278400 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-04-14 18:48 - 2015-03-12 20:20 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-04-14 18:48 - 2015-03-12 20:20 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-04-14 18:48 - 2015-03-12 20:17 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-04-14 18:48 - 2015-03-12 20:16 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-04-14 18:48 - 2015-03-12 20:15 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-04-14 18:48 - 2015-03-12 20:08 - 00720384 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-04-14 18:48 - 2015-03-12 20:07 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-04-14 18:48 - 2015-03-12 20:06 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-04-14 18:48 - 2015-03-12 20:05 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-04-14 18:48 - 2015-03-12 20:05 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-04-14 18:48 - 2015-03-12 20:01 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-04-14 18:48 - 2015-03-12 20:00 - 14397440 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-04-14 18:48 - 2015-03-12 19:57 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-04-14 18:48 - 2015-03-12 19:56 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-04-14 18:48 - 2015-03-12 19:54 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-04-14 18:48 - 2015-03-12 19:49 - 04305408 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-04-14 18:48 - 2015-03-12 19:45 - 02358784 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-04-14 18:48 - 2015-03-12 19:44 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-04-14 18:48 - 2015-03-12 19:43 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-04-14 18:48 - 2015-03-12 19:42 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-04-14 18:48 - 2015-03-12 19:34 - 12825600 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-04-14 18:48 - 2015-03-12 19:33 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-04-14 18:48 - 2015-03-12 19:22 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-04-14 18:48 - 2015-03-12 19:20 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-04-14 18:48 - 2015-03-12 19:16 - 01311232 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-04-14 18:48 - 2015-03-12 19:14 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-04-14 18:48 - 2015-02-24 20:18 - 00754688 _____ (Microsoft Corporation) C:\windows\system32\Drivers\http.sys
2015-04-14 18:45 - 2015-03-03 21:55 - 00367552 _____ (Microsoft Corporation) C:\windows\system32\clfs.sys
2015-04-14 18:45 - 2015-03-03 21:41 - 00079360 _____ (Microsoft Corporation) C:\windows\system32\clfsw32.dll
2015-04-14 18:45 - 2015-03-03 21:10 - 00058880 _____ (Microsoft Corporation) C:\windows\SysWOW64\clfsw32.dll
2015-04-11 20:00 - 2015-04-11 20:05 - 01035272 _____ () C:\windows\Minidump\041115-35537-01.dmp

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-09 14:33 - 2009-07-13 21:45 - 00028576 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-09 14:33 - 2009-07-13 21:45 - 00028576 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-09 14:30 - 2011-08-23 01:23 - 02027731 _____ () C:\windows\WindowsUpdate.log
2015-05-09 14:29 - 2012-12-24 13:12 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2015-05-09 14:27 - 2013-02-25 20:47 - 00000000 ____D () C:\Users\isaiah\AppData\Roaming\uTorrent
2015-05-09 14:26 - 2012-12-22 11:38 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-05-09 14:26 - 2011-12-29 18:20 - 00000000 ____D () C:\Users\isaiah\AppData\Roaming\Skype
2015-05-09 14:25 - 2012-12-06 19:32 - 00000000 ____D () C:\Program Files (x86)\Origin
2015-05-09 14:24 - 2012-09-12 18:15 - 00000894 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore1cd914d439221f3.job
2015-05-09 14:23 - 2012-12-24 11:46 - 00041127 _____ () C:\windows\setupact.log
2015-05-09 14:23 - 2010-11-20 20:47 - 01630352 _____ () C:\windows\PFRO.log
2015-05-09 14:23 - 2009-07-13 22:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-05-09 14:18 - 2012-09-12 18:15 - 00000898 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA1cd914d43dfa6d6.job
2015-05-09 14:15 - 2012-08-20 18:02 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-05-08 21:08 - 2014-01-25 14:48 - 00000390 _____ () C:\windows\Tasks\update-sys.job
2015-05-08 20:44 - 2015-02-08 21:42 - 00000000 ____D () C:\Program Files (x86)\SoftwareHelp
2015-05-08 20:11 - 2014-01-25 14:48 - 00000390 _____ () C:\windows\Tasks\update-S-1-5-21-4152253128-2157246082-1293380562-1000.job
2015-05-07 20:46 - 2012-12-24 10:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
2015-05-07 20:46 - 2012-12-24 10:39 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2015-05-07 19:42 - 2015-02-08 21:41 - 00000000 ____D () C:\ProgramData\5551195122105854317
2015-05-05 16:49 - 2014-10-09 21:15 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2015-05-04 21:27 - 2011-12-31 10:52 - 00000000 ____D () C:\Users\isaiah\AppData\Local\Google
2015-05-04 21:27 - 2011-12-31 10:52 - 00000000 ____D () C:\Program Files (x86)\Google
2015-05-04 21:16 - 2009-07-13 22:13 - 00823564 _____ () C:\windows\system32\PerfStringBackup.INI
2015-05-04 18:18 - 2012-04-17 18:25 - 00000506 _____ () C:\windows\Tasks\SystemToolsDailyTest.job
2015-05-03 21:01 - 2009-07-13 20:20 - 00000000 ____D () C:\windows\system32\NDF
2015-04-28 20:04 - 2015-02-08 21:40 - 00000000 ____D () C:\ProgramData\{8613789a-ab6e-b73f-8613-3789aab6e26a}
2015-04-23 16:51 - 2011-12-24 22:45 - 00000000 ____D () C:\Users\isaiah\AppData\Roaming\Adobe
2015-04-22 20:06 - 2014-01-25 14:48 - 00003266 _____ () C:\windows\System32\Tasks\update-S-1-5-21-4152253128-2157246082-1293380562-1000
2015-04-22 20:06 - 2014-01-25 14:48 - 00000424 _____ () C:\Users\isaiah\AppData\Local\UserProducts.xml
2015-04-19 20:54 - 2013-12-21 22:08 - 00000000 ____D () C:\Users\isaiah\Desktop\Tor Browser
2015-04-16 18:15 - 2012-08-20 18:02 - 00778416 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-04-16 18:15 - 2012-08-20 18:02 - 00142512 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-16 18:15 - 2012-08-20 18:02 - 00003768 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-04-15 05:33 - 2009-07-13 20:20 - 00000000 ____D () C:\windows\rescache
2015-04-15 05:25 - 2009-07-13 20:20 - 00000000 ____D () C:\windows\AppCompat
2015-04-15 03:40 - 2013-03-28 10:11 - 603850817 _____ () C:\windows\MEMORY.DMP
2015-04-15 03:40 - 2013-03-28 10:11 - 00000000 ____D () C:\windows\Minidump
2015-04-15 03:27 - 2014-12-10 22:00 - 00000000 ____D () C:\windows\system32\appraiser
2015-04-15 03:27 - 2014-04-29 22:07 - 00000000 ___SD () C:\windows\system32\CompatTel
2015-04-15 03:27 - 2009-07-13 20:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2015-04-15 03:10 - 2011-08-23 01:36 - 00816178 _____ () C:\windows\SysWOW64\PerfStringBackup.INI
2015-04-15 03:08 - 2013-08-08 03:01 - 00000000 ____D () C:\windows\system32\MRT
2015-04-15 03:03 - 2012-01-23 20:22 - 128913832 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-04-11 12:10 - 2015-01-06 16:02 - 00000000 ____D () C:\Program Files (x86)\Overwolf

==================== Files in the root of some directories =======

2005-05-30 08:19 - 2012-12-23 03:14 - 0004115 ____H () C:\Users\isaiah\AppData\Roaming\isaiahlog.dat
2011-12-31 19:44 - 2014-11-30 01:31 - 0016896 _____ () C:\Users\isaiah\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-05-08 18:39 - 2015-05-08 18:39 - 0000036 _____ () C:\Users\isaiah\AppData\Local\housecall.guid.cache
2015-01-05 23:36 - 2015-01-10 02:01 - 0007606 _____ () C:\Users\isaiah\AppData\Local\Resmon.ResmonCfg
2015-05-08 19:56 - 2015-05-08 19:56 - 0000010 _____ () C:\Users\isaiah\AppData\Local\sponge.last.runtime.cache
2014-01-25 14:48 - 2014-01-25 14:48 - 0000003 _____ () C:\Users\isaiah\AppData\Local\updater.log
2014-01-25 14:48 - 2015-04-22 20:06 - 0000424 _____ () C:\Users\isaiah\AppData\Local\UserProducts.xml
2012-12-24 13:15 - 2012-12-24 13:15 - 0017408 _____ () C:\Users\isaiah\AppData\Local\WebpageIcons.db

Some content of TEMP:
====================
C:\Users\isaiah\AppData\Local\Temp\2100.exe
C:\Users\isaiah\AppData\Local\Temp\226380_199177.exe
C:\Users\isaiah\AppData\Local\Temp\3faig5ns.dll
C:\Users\isaiah\AppData\Local\Temp\4c2459bebc146bfd821d90e28a2411ab.dll
C:\Users\isaiah\AppData\Local\Temp\6_Offer_12.exe
C:\Users\isaiah\AppData\Local\Temp\81c992b.exe
C:\Users\isaiah\AppData\Local\Temp\83929-92631-microsoft-office-2010.exe
C:\Users\isaiah\AppData\Local\Temp\a15154fd9009bc6f9bea0d0659312534.dll
C:\Users\isaiah\AppData\Local\Temp\bitool.dll
C:\Users\isaiah\AppData\Local\Temp\bpygdfsv.dll
C:\Users\isaiah\AppData\Local\Temp\CheatEngine62Clean.exe
C:\Users\isaiah\AppData\Local\Temp\conduitinstaller.exe
C:\Users\isaiah\AppData\Local\Temp\couponamazing.exe
C:\Users\isaiah\AppData\Local\Temp\cvtres.exe
C:\Users\isaiah\AppData\Local\Temp\DM1394570410.exe
C:\Users\isaiah\AppData\Local\Temp\fbyho1hu.dll
C:\Users\isaiah\AppData\Local\Temp\i4jdel0.exe
C:\Users\isaiah\AppData\Local\Temp\ICReinstall_donkey-kong.exe
C:\Users\isaiah\AppData\Local\Temp\IminentSetup.exe
C:\Users\isaiah\AppData\Local\Temp\instloffer.exe
C:\Users\isaiah\AppData\Local\Temp\InternetTurboSetup__1814_i1675065_il1537.exe
C:\Users\isaiah\AppData\Local\Temp\lnd15xiv.dll
C:\Users\isaiah\AppData\Local\Temp\nsb4CAB.tmp.exe
C:\Users\isaiah\AppData\Local\Temp\oi_{74E8797E-56B6-42A9-8C89-469757A0DC67}.exe
C:\Users\isaiah\AppData\Local\Temp\PCFixSpeedSetup.exe
C:\Users\isaiah\AppData\Local\Temp\photostage_1.0.0.50_1.5.0.130_update_all.exe
C:\Users\isaiah\AppData\Local\Temp\safeguard.exe
C:\Users\isaiah\AppData\Local\Temp\somoto_HD CODEC_1.0.exe
C:\Users\isaiah\AppData\Local\Temp\SpOrder.dll
C:\Users\isaiah\AppData\Local\Temp\supoptsetup.exe
C:\Users\isaiah\AppData\Local\Temp\tbcpa0.dll
C:\Users\isaiah\AppData\Local\Temp\UNINSTALL.EXE
C:\Users\isaiah\AppData\Local\Temp\Updater.exe
C:\Users\isaiah\AppData\Local\Temp\utt88CD.tmp.exe
C:\Users\isaiah\AppData\Local\Temp\winziprosetup-WZRO6_20130221.exe

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2015-05-05 17:17

==================== End Of Log ============================

 

 

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-05-2015
Ran by isaiah at 2015-05-09 14:35:47
Running from C:\Users\isaiah\Desktop
Boot Mode: Normal
==========================================================

==================== Accounts: =============================

Administrator (S-1-5-21-4152253128-2157246082-1293380562-500 - Administrator - Disabled)
Guest (S-1-5-21-4152253128-2157246082-1293380562-501 - Limited - Disabled)
isaiah (S-1-5-21-4152253128-2157246082-1293380562-1000 - Administrator - Enabled) => C:\Users\isaiah

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Kaspersky Internet Security (Enabled - Up to date) {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
AS: Kaspersky Internet Security (Enabled - Up to date) {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\uTorrent) (Version: 3.4.2.36802 - BitTorrent Inc.)
AdBlocker Manger (HKLM-x32\...\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version:  - AdBlocker Manger) <==== ATTENTION
Adobe Acrobat 5.0 (HKLM-x32\...\Adobe Acrobat 5.0) (Version: 5.0 - Adobe Systems, Inc.)
Adobe Flash Player 10 Plugin (HKLM-x32\...\{4ED0DB47-769D-4B71-8724-E7A5BFEA1D51}) (Version: 10.3.181.22 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Photoshop CS2 (HKLM-x32\...\Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}) (Version: 9.0 - Adobe Systems, Inc.)
Adobe Reader XI (11.0.10) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.3.633 - Adobe Systems, Inc.)
Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
Aeria Ignite (HKLM-x32\...\Aeria Ignite 1.13.3296) (Version: 1.13.3296 - Aeria Games & Entertainment)
Aeria Ignite (HKLM-x32\...\Aeria Ignite) (Version: 1.13.3296 - Aeria Games & Entertainment)
Aeria Ignite (x32 Version: 1.13.3296 - Aeria Games & Entertainment) Hidden
Akamai NetSession Interface (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Akamai) (Version:  - Akamai Technologies, Inc)
Alliance of Valiant Arms (HKLM-x32\...\Alliance of Valiant Arms) (Version:  - )
AMD Catalyst Install Manager (HKLM\...\{7071F235-9C2C-ACDE-36CC-E18034946DD7}) (Version: 8.0.891.0 - Advanced Micro Devices, Inc.)
Andy OS (HKLM-x32\...\Andy OS) (Version: 0.41 - Andy OS, Inc)
Anime Studio Debut 6.1 (HKLM-x32\...\Anime Studio Debut_is1) (Version:  - Smith Micro Software, Inc.)
AnyTrans 3.6.6 (HKLM-x32\...\{E580ED1F-AAF8-4F7E-B174-54BFA2B94E0B}}_is1) (Version: 3.6.6 - iMobie Inc.)
Apple Application Support (HKLM-x32\...\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2F72F540-1F60-4266-9506-952B21D6640D}) (Version: 6.1.0.13 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcSoft MediaConverter 8 (HKLM-x32\...\{2CAD3C16-ACD0-43E5-81DA-7E56C3E5336C}) (Version: 8.0.0.21 - ArcSoft)
ARMA 2 (HKLM-x32\...\Steam App 33900) (Version:  - Bohemia Interactive)
Ask Toolbar Updater (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.2.0.20007 - Ask.com) <==== ATTENTION
AssaultCube v1.1.0.4 (HKLM-x32\...\AssaultCube_v1.1.0.4) (Version: v1.1.0.4 - )
Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team)
AVS Video Converter 8.5 (HKLM-x32\...\AVS4YOU Video Converter 7_is1) (Version: 8.5.1.551 - Online Media Technologies Ltd.)
Battlefield: Bad Company 2 (HKLM-x32\...\Steam App 24960) (Version:  - DICE)
BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version:  - )
BattlEye Uninstall (HKLM-x32\...\BattlEye for A2) (Version:  - )
Bing Bar (HKLM-x32\...\{08234a0d-cf39-4dca-99f0-0c5cb496da81}) (Version: 6.0.2282.0 - Microsoft Corporation)
Bing Bar Platform (x32 Version: 6.0.2282.0 - Microsoft Corporation) Hidden
Bing Rewards Client Installer (x32 Version: 16.0.345.0 - Microsoft Corporation) Hidden
Blender (HKLM\...\Blender) (Version: 2.65a-release - Blender Foundation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
boostwebapp (HKLM-x32\...\{0E376CD8-8982-4BE6-b505-91881F3B3343}) (Version: 1.1.0.31 - boostwebapp) <==== ATTENTION
CamStudio version 2.6b (HKLM-x32\...\{2793F5A3-509A-4CB6-B014-1E0E0794351A}_is1) (Version: 2.6b - Download Freely, LLC)
Canon MP495 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP495_series) (Version:  - )
Cheat Engine 6.2 (HKLM-x32\...\Cheat Engine 6.2_is1) (Version:  - Dark Byte)
Clear Cache Shortcut (HKLM-x32\...\{AF992111-52BE-832B-5882-8477E4A3C99A}) (Version:  - "") <==== ATTENTION
Club Penguin Money Maker (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\a87d8e93174496f4) (Version: 1.2.0.0 - ClubPenguinCP)
Cool AVI To WAV Converter 1.0 (HKLM-x32\...\Cool AVI To WAV Converter_is1) (Version:  - A Software Plus)
Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version:  - Valve)
CreaToon 3.0 (HKLM-x32\...\CreaToon 3.0) (Version:  - )
Cross Fire En (HKLM-x32\...\Cross Fire_is1) (Version:  - Z8Games.com)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.46.1.0328 - DT Soft Ltd)
DayZ (HKLM-x32\...\Steam App 221100) (Version:  - Bohemia Interactive)
DayZ Commander (HKLM-x32\...\{0B74EC0B-2A85-4542-A167-3DE2132E7DAA}) (Version: 0.92.85 - Dotjosh Studios)
DealNoDeal (HKLM-x32\...\{37476589-E48E-439E-A706-56189E2ED4C4}) (Version:  - DealNoDeal) <==== ATTENTION
Dell Digital Delivery (HKLM-x32\...\{31045ECE-019D-4DDF-A5C8-5C51A3FE50EE}) (Version: 1.7.4501.0 - Dell Products, LP)
Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Dell Getting Started Guide (HKLM-x32\...\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell MusicStage (HKLM-x32\...\{91AF2672-F5BC-42CF-8037-A9D2F92BBCC0}) (Version: 1.5.201.0 - Fingertapps)
Dell Perks Webslice IE8 (HKLM-x32\...\{CF67ED0C-F85D-4791-AED3-3FE882EDB45D}) (Version: 8.0 - Nextjump Inc)
Dell PhotoStage (HKLM-x32\...\{E4335E82-17B3-460F-9E70-39D9BC269DB3}) (Version: 1.5.0.65 - ArcSoft)
Dell Product Registration (HKLM-x32\...\{2A0F2CC5-3065-492C-8380-B03AA7106B1A}) (Version: 1.0.3 - Dell Inc.)
Dell Stage (HKLM-x32\...\{FE182796-F6BA-486A-8590-89B7E8D1D60F}) (Version: 1.7.209.0 - Fingertapps)
Dell Support Center (HKLM\...\Dell Support Center) (Version: 3.1.5907.23 - Dell Inc.)
Dell Support Center (Version: 3.1.5907.23 - PC-Doctor, Inc.) Hidden
Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.1209.101.204 - ALPS ELECTRIC CO., LTD.)
Dell VideoStage  (HKLM-x32\...\InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}) (Version: 1.2.0.1712 - CyberLink Corp.)
Dell VideoStage  (x32 Version: 1.2.0.1712 - CyberLink Corp.) Hidden
Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 2.00.44 - Creative Technology Ltd)
Dev-C++ (HKLM-x32\...\Dev-C++) (Version: 5.4.2 - )
DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden
DiscJuggler (HKLM-x32\...\{C3C538E5-524C-4253-AA74-0EEEF34990EA}) (Version: 4.10 - Padus, Inc.)
Doom Builder 2.1 (HKLM-x32\...\Doom Builder 2_is1) (Version:  - CodeImp)
Dystopia (HKLM-x32\...\Steam App 17580) (Version:  - Dystopia Team)
EnjooyCooupOn (HKLM-x32\...\{2DF3E224-05CD-4113-AA7A-86F2F6607B46}) (Version:  - "") <==== ATTENTION
Explorer Suite IV (HKLM\...\Explorer Suite_is1) (Version:  - )
ExstrraSavoinigS (HKLM-x32\...\{C637A71C-A4B2-4B47-1B2A-1042A8D525A3}) (Version:  - "") <==== ATTENTION
Fallout Mod Manager 0.12.6 (HKLM-x32\...\Fallout Mod Manager_is1) (Version:  - Timeslip, Q)
Fallout Mod Manager 0.13.21 (HKLM-x32\...\Generic Mod Manager_is1) (Version:  - Q, Timeslip)
Fantapper Player (HKLM-x32\...\{CDACD4C9-F984-409A-9D26-DF77E003FD89}) (Version: 2.0.3 - Brand Affinity Technologies)
Fantapper Updater (HKLM-x32\...\{57570C54-7615-4925-8219-895F01EBB16B}) (Version: 2.0.2 - Brand Affinity Technologies)
FileViewPro (HKLM\...\FileViewPro_is1) (Version: 4.0 - Solvusoft Corporation)
Finale NotePad 2007 (HKLM-x32\...\Finale NotePad 2007) (Version: 12.0.13 - MakeMusic)
Fraps (HKLM-x32\...\Fraps) (Version:  - )
Free AVI To MP3 Converter (HKLM-x32\...\{2A0E555E-1533-468E-B49E-4A39050FB562}) (Version: 1.0.0 - Convert Audio Free)
FreeOTFE Explorer (HKLM-x32\...\FreeOTFE Explorer) (Version:  - Sarah Dean)
GameMaker-Studio 1.1 (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\GameMaker-Studio11) (Version:  - YoYo Games Ltd.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 42.0.2311.135 - Google Inc.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
GTA San Andreas (HKLM-x32\...\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6324.0 - IDT)
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Display Audio Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3097 - Intel Corporation)
Intel® Driver Update Utility 2.0 (x32 Version: 2.0.0.29 - Intel) Hidden
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation)
Intel® PROSet/Wireless Software for Bluetooth® Technology (HKLM\...\{7CE8BE79-ABC3-4B2C-9543-28ED2B0A9EA8}) (Version: 1.0.0.0454 - Intel Corporation)
Intel® PROSet/Wireless WiFi Software (HKLM\...\{290D4DB2-F1B4-4B8E-918D-D71EF29A001B}) (Version: 14.00.1000 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation)
Intel® Turbo Boost Technology Monitor 2.0 (HKLM\...\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.1.23.0 - Intel)
Intel® WiDi (HKLM-x32\...\{25680C01-6753-4FE9-A891-7857F26457C1}) (Version: 2.1.35.0 - Intel Corporation)
Intel® Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
Intel® Driver Update Utility (HKLM-x32\...\{8409c4f7-2340-4933-a304-5d37db4fb48b}) (Version: 2.0.0.29 - Intel)
Intel® PROSet/Wireless WiMAX Software (HKLM\...\{5C1DA3D9-F590-4317-A4FB-274F658E504B}) (Version: 6.05.0000 - Intel Corporation)
Internet Explorer (x32 Version: 8 - Microsoft Corporation) Hidden
iPhoneBrowser (HKLM-x32\...\{C1FCDCA1-2759-4E5E-84EE-3A665BB2F513}) (Version: 1.9.3 - Cranium Consulting and Custom Software)
iTunes (HKLM\...\{427174C0-096E-40D9-9684-9C109BEE2CBF}) (Version: 11.0.5.5 - Apple Inc.)
Java 7 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417045FF}) (Version: 7.0.450 - Oracle)
Java 7 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.450 - Oracle)
Java SE Development Kit 7 Update 45 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170450}) (Version: 1.7.0.450 - Oracle)
Java™ 6 Update 24 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416024FF}) (Version: 6.0.240 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Kaspersky Internet Security 2013 (HKLM-x32\...\InstallWIX_{560985FB-4B76-4121-9189-7A2CDC7886D6}) (Version: 13.0.1.4190 - Kaspersky Lab)
Kaspersky Internet Security 2013 (x32 Version: 13.0.1.4190 - Kaspersky Lab) Hidden
Lightshot-5.2.1.1 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.2.1.1 - Skillbrains)
Macromedia Flash 5 (HKLM-x32\...\{4C93C363-414E-11D4-9756-00C04F8EEB39}) (Version: 5 - Macromedia)
Malwarebytes Anti-Malware version 1.70.0.1100 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.70.0.1100 - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Help Viewer 1.0 (HKLM\...\Microsoft Help Viewer 1.0) (Version: 1.0.30319 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\OneDriveSetup.exe) (Version: 17.0.4023.1211 - Microsoft Corporation)
Microsoft OneNote 2013 - en-us (HKLM\...\OneNoteFreeRetail - en-us) (Version: 15.0.4711.1003 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 (HKLM-x32\...\{B7E38540-E355-3503-AFD7-635B2F2F76E1}) (Version: 9.0.30729.4974 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Express - ENU (HKLM-x32\...\Microsoft Visual C++ 2010 Express - ENU) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Express Prerequisites x64 - ENU (HKLM\...\{BCA26999-EC22-3007-BB79-638913079C9A}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
MonkeyJam 3_050529 (HKLM-x32\...\MonkeyJam_is1) (Version:  - GiantScreamingRobotMonkeys)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4711.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4711.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4711.1003 - Microsoft Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Oracle VM VirtualBox 4.3.18 (HKLM\...\{74B7E6F9-DCAC-4ADB-B2D0-EEFDD1B5AC25}) (Version: 4.3.18 - Oracle Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.1.3.2637 - Electronic Arts, Inc.)
Overwolf (HKLM-x32\...\Overwolf) (Version: 0.84.95.0 - Overwolf Ltd.)
Pantech PCSuite (HKLM-x32\...\{9BC95D0F-EE60-43FB-ACE8-7D91A2ED33F3}) (Version: 1.1 - Pantech)
Pantech PCSuite (x32 Version: 1.1 - Pantech) Hidden
Pantech Unified USB Driver Ver1 (HKLM\...\{19E88D03-44D4-46aa-9F3C-D6CFC035BFE6}) (Version: 4.14.2.0 - Pantech)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.0 - Frank Heindörfer, Philip Chinery)
PFConfig 1.0.296 (HKLM-x32\...\PFConfig) (Version: 1.0.296 - Portforward.com)
PhotoShowExpress (x32 Version: 2.0.063 - Sonic Solutions) Hidden
Picmeta PhotoTracker v1.5 (HKLM-x32\...\Picmeta PhotoTracker_is1) (Version:  - Picmeta Systems)
Pivot Animator version 4.1.5 (HKLM-x32\...\Pivot Animator_is1) (Version: 4.1.5 - Motus Software Ltd)
Play withSIX (HKLM-x32\...\{D7F3EEAD-183C-47DE-BDC5-593539573F97}) (Version: 1.30.0476 - SIX Networks)
Portforward Static IP Address 1.0.47 (HKLM-x32\...\Portforward Static IP Address) (Version: 1.0.47 - Portforward.com)
Powerbullet Presenter  1.44 (HKLM-x32\...\Powerbullet Presenter_is1) (Version: 1.44 - DDD Pty Ltd)
PowerISO (HKLM-x32\...\PowerISO) (Version: 5.5 - Power Software Ltd)
PremiumSctructure (HKLM-x32\...\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{74e9abac}) (Version:  - PremiumSctructure) <==== ATTENTION
Project Zomboid Demo (HKLM-x32\...\Steam App 264910) (Version:  - Indie Stone Studios)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.988 - Even Balance, Inc.)
PX3 Presets Manager (HKLM-x32\...\{83030E21-76C9-4EFB-8182-EBC9B851B631}) (Version: 1.00.0000 - Turtle Beach)
Pyware 3D Performer's Practice Tools (HKLM-x32\...\Pyware 3D Performer's Practice Tools) (Version: 1.0.0.0 - Pygraphics)
Quick SEO  PageRank Backlinks  Alexa Tool (HKLM-x32\...\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}) (Version:  - ) <==== ATTENTION
RBVirtualFolder64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.31.1025.2010 - Realtek)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30126 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden
Roadkil's Unstoppable Copier Version 5.2 (HKLM-x32\...\{A306FD29-7D3A-4287-91AC-9A0180931395}_is1) (Version:  - Roadkil.Net)
Roblox for isaiah (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version:  - ROBLOX Corporation)
Roxio Creator Starter (HKLM-x32\...\{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}) (Version: 12.1.77.0 - Roxio)
Roxio File Backup (Version: 1.3.2 - Roxio) Hidden
Savant Web Server (HKLM-x32\...\Savant Web Server) (Version:  - )
ShopDroP (HKLM-x32\...\{B6D700D3-3D0D-FEEB-D675-2CE78F9EC5D6}) (Version:  - "") <==== ATTENTION
Sibelius 6 Demo (HKLM-x32\...\{A67C4EF9-725D-4C83-A67A-BB7B7DE96CF4}) (Version: 6.0.0 - Sibelius Software)
SketchUp 2015 (HKLM-x32\...\{D0A0BE3D-8D66-4BE9-87C4-D30CA5AA93A3}) (Version: 15.3.330 - Trimble Navigation Limited)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 5.10 (HKLM-x32\...\{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}) (Version: 5.10.116 - Skype Technologies S.A.)
SlimDX Runtime .NET 2.0 (January 2012) (HKLM-x32\...\{014A2868-BE56-4888-A16C-693989B8F153}) (Version: 2.0.13.43 - SlimDX Group)
Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0 - Sonic Solutions) Hidden
Sothink SWF Decompiler (HKLM-x32\...\{BCDB856C-D247-4DEE-9132-89C02F4D6B8C}_is1) (Version: 7.3 - SourceTec Software Co., LTD)
Sound Forge Audio Studio 10.0 (HKLM-x32\...\{7A263871-BEEC-11E1-AC53-F04DA23A5C58}) (Version: 10.0.178 - Sony)
Source SDK (HKLM-x32\...\Steam App 211) (Version:  - Valve)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synfig Studio (HKLM-x32\...\synfigstudio) (Version: 0.63.05 - )
Synthesia (HKLM-x32\...\Synthesia) (Version: 8.5 - Synthesia LLC)
TeamSpeak 3 Client (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
The Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.42.130 - Electronic Arts)
TrustedID (HKLM-x32\...\{C16A92EF-017B-4839-9C75-FBADB5A1FA27}) (Version: 5.0 - TrustedID)
Ulead VideoStudio SE DVD (HKLM-x32\...\{8F8D9297-FDD2-405A-97E7-E52C7B2F97B3}) (Version: 10.0 - Ulead Systems)
Unisales (HKLM-x32\...\{4CEE92A3-9F0C-51AB-ADC0-34EC24AD7B7E}) (Version:  - ) <==== ATTENTION
Unity Web Player (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Unturned (HKLM-x32\...\Steam App 304930) (Version:  - Nelson Sexton)
USB2.0 Grabber (HKLM-x32\...\{45518B6D-9DDF-4144-83E4-A56762524F35}) (Version: 7.12.000.003 - Youyan)
USB2.0 Grabber (HKLM-x32\...\USB2.0 Grabber) (Version:  - )
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Vectorian Giotto 3.0.0 (HKLM-x32\...\Vectorian Giotto_is1) (Version:  - Vectorian Inc.)
Vegas Pro 11.0 (HKLM-x32\...\{B5B98340-0296-11E2-8B8E-F04DA23A5C58}) (Version: 11.0.700 - Sony)
Vizzed Retro Game Room (HKLM-x32\...\{6D9F35D2-1D6F-4E17-A79F-991A7BD24AAD}) (Version: 2.0.0 - Vizzed)
Watcom C/C++ 11.0c update (HKLM-x32\...\Watcom C/C++ 11.0c update) (Version:  - )
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
youtubeadblocker (HKLM-x32\...\{4820778D-AB0D-6D18-C316-52A6A0E1D507}) (Version:  - ) <==== ATTENTION

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\isaiah\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\isaiah\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\isaiah\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000_Classes\CLSID\{D45F043D-F17F-4e8a-8435-70971D9FA46D}\InprocServer32 -> C:\Program Files (x86)\Blender Foundation\Blender\BlendThumb64.dll ()
CustomCLSID: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\isaiah\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\isaiah\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\amd64\FileSyncApi64.dll (Microsoft Corporation)

==================== Restore Points  =========================

18-04-2015 21:22:55 Windows Update
24-04-2015 17:36:40 Windows Update
28-04-2015 19:49:07 Windows Update
28-04-2015 20:04:05 Windows Defender Checkpoint
02-05-2015 12:10:48 Windows Update
03-05-2015 22:02:15 Removed GeekBuddy.
03-05-2015 22:02:54 Removed GeekBuddy.
07-05-2015 20:34:14 Malwarebytes Anti-Rootkit Restore Point
07-05-2015 21:48:54 Malwarebytes Anti-Rootkit Restore Point
08-05-2015 20:41:02 Malwarebytes Anti-Rootkit Restore Point
09-05-2015 13:55:22 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 19:34 - 2009-06-10 14:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {009B39B9-D515-4222-9460-ED6785F4F071} - System32\Tasks\{2C364901-AA06-473D-A052-32F3F54F358F} => Chrome.exe
Task: {09B760B5-3E15-486B-803B-EBE7E5B8A0D3} - System32\Tasks\0 => Iexplore.exe  <==== ATTENTION
Task: {0CEA552C-DEAC-4671-B3DA-621912592E15} - System32\Tasks\ProPCCleaner_Start => C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe <==== ATTENTION
Task: {0E51396B-770C-49BF-B1FA-676C467BB053} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {1533A718-3DD0-4CFB-884A-70FF635052B2} - System32\Tasks\{BA9B55D6-7F65-49D3-8DCB-061312A7342A} => pcalua.exe -a C:\watcom\WiseUpdt.exe
Task: {16FFA2EA-4B1F-4705-9797-24D152B7851B} - System32\Tasks\PCDEventLauncher => C:\Program Files\Dell Support Center\sessionchecker.exe [2012-04-12] (PC-Doctor, Inc.)
Task: {17455F81-AA8B-4290-9AD3-4224EA489A1E} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-24] (Microsoft Corporation)
Task: {30BFFF48-6CB9-4A1E-A459-69A36ECDCAFF} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-16] (Adobe Systems Incorporated)
Task: {40116C0B-5DE3-4E6B-8AFF-9EA10912B79E} - System32\Tasks\{2EC56597-00C3-4963-BC6D-ADE8D82FDEBA} => Chrome.exe
Task: {402BF172-310F-4192-8621-30EE4F975021} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {49893E45-C793-41C8-A1E1-A0B3910F8FA1} - System32\Tasks\{6BAF6CF2-946F-4DA5-B798-6AB61E5D5E42} => pcalua.exe -a C:\Users\isaiah\Downloads\Video_AMD_W7W8_A01_Setup-HC6HJ_ZPE.exe -d C:\Users\isaiah\Downloads
Task: {652FECDA-01D6-4EA7-9041-71F8CBFF3250} - System32\Tasks\GoogleUpdateTaskMachineCore1cd914d439221f3 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-27] (Google Inc.)
Task: {66D27535-5824-48D3-BFB1-2C1EB6EC9E4C} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell Support Center\uaclauncher.exe [2012-04-12] (PC-Doctor, Inc.)
Task: {66F5E966-1F44-4B93-9815-E10CC8369415} - System32\Tasks\ProPCCleaner_Popup => C:\Program Files (x86)\Pro PC Cleaner\Splash.exe <==== ATTENTION
Task: {740F64E3-6804-4B65-BDEF-6B6079B6E1FA} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {85E5AA2C-0306-40C7-A15A-A74CFD01E346} - System32\Tasks\4804 => Wscript.exe C:\Users\isaiah\AppData\Local\Temp\launchie.vbs //B <==== ATTENTION
Task: {89F5D76B-44D0-4720-AA22-E4F0F748C937} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-04-22] (Microsoft Corporation)
Task: {9C0A281A-97FD-4069-9D3D-BDEE01F2A06D} - System32\Tasks\{2FCE4873-A2D4-4E7B-B47C-ADAE461EF62F} => pcalua.exe -a "C:\Dell\drivers\HC6HJ\9.003 WHQL W7 W8-PX4-121025a-155179C-Dell\Bin\ATISetup.exe" -d "C:\Dell\drivers\HC6HJ\9.003 WHQL W7 W8-PX4-121025a-155179C-Dell\Bin"
Task: {B61ED734-AEC9-42D8-9DB3-F23E666292A7} - System32\Tasks\{25DFC93A-00C6-4C5E-8A9A-BB58662B5618} => pcalua.exe -a "C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\BEsetup\Setup_BattlEyeARMA2OA.exe" -d "C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead" -c [email protected] -nosplash
Task: {BFC33A76-8AB6-4709-A53B-C8395B903833} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-04-22] (Microsoft Corporation)
Task: {C6EEAD65-894F-496C-A4F8-CA70AD8E32E4} - System32\Tasks\update-S-1-5-21-4152253128-2157246082-1293380562-1000 => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [2014-03-25] ()
Task: {CC20E6C7-257A-42EE-BA0E-998E308A1526} - System32\Tasks\update-sys => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [2014-03-25] ()
Task: {CEE40174-B983-473B-A23B-825539FBDD03} - System32\Tasks\{6D1CEE4C-F539-431C-A412-FC2054464041} => pcalua.exe -a "C:\Program Files (x86)\SelectRebates\SelectRebatesUninstall.exe"
Task: {D039104F-4509-4A6B-AC15-D5A07991011B} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2015-04-05] (Overwolf LTD)
Task: {D68C89CB-E545-46E2-8BA9-EA3087E1EAFF} - System32\Tasks\SystemToolsDailyTest => C:\Program Files\Dell Support Center\uaclauncher.exe [2012-04-12] (PC-Doctor, Inc.)
Task: {D6CB2D92-4982-47E2-9670-B905FC32D25D} - System32\Tasks\GoogleUpdateTaskMachineUA1cd914d43dfa6d6 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-27] (Google Inc.)
Task: {E561DE58-F951-47DC-9F53-04934CF99BD0} - System32\Tasks\{EADB7BAB-5FC3-4762-8ED3-C84EA699D41C} => pcalua.exe -a "C:\Program Files (x86)\Steam\steamapps\common\Arma 2\BEsetup\setup_BattlEyeARMA2.exe" -d "C:\Program Files (x86)\Steam\steamapps\common\Arma 2\BEsetup"
Task: {F17DD5FB-B78B-4831-A2C8-D843FB3CCEEA} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1cd914d439221f3.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA1cd914d43dfa6d6.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\PCDoctorBackgroundMonitorTask.job => C:\Program Files\Dell Support Center\uaclauncher.exeo-backgroundmon scripts\defaultscan.xml
Task: C:\windows\Tasks\SystemToolsDailyTest.job => C:\Program Files\Dell Support Center\uaclauncher.exe
Task: C:\windows\Tasks\update-S-1-5-21-4152253128-2157246082-1293380562-1000.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
Task: C:\windows\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe

==================== Loaded Modules (whitelisted) ==============

2015-05-03 21:53 - 2015-05-03 17:13 - 00398336 _____ () C:\windows\system32\Juanenodra64.dll
2010-12-17 11:53 - 2010-12-17 11:53 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2012-07-19 13:06 - 2005-03-12 00:07 - 00087040 _____ () C:\windows\System32\pdfcmnnt.dll
2014-10-09 21:15 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2015-05-08 20:37 - 2015-05-08 20:37 - 00117248 _____ () C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031\nsu9557.tmp
2014-11-20 19:03 - 2014-11-20 19:03 - 00075064 _____ () C:\windows\SysWOW64\PnkBstrA.exe
2015-05-03 21:53 - 2015-05-03 21:54 - 00224768 _____ () C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031\jnsm42CF.tmp
2015-03-13 19:50 - 2015-01-27 08:29 - 08898720 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2011-08-23 04:00 - 2011-04-10 11:40 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2010-12-17 11:53 - 2010-12-17 11:53 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2010-11-17 08:35 - 2010-11-17 08:35 - 00514544 _____ () C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
2013-04-21 21:44 - 2013-04-21 21:44 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2013-04-21 21:44 - 2013-04-21 21:44 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2010-11-24 20:44 - 2010-11-24 20:44 - 00375280 _____ () c:\program files (x86)\common files\roxio shared\dllshared\SQLite352.dll
2014-10-15 16:35 - 2014-10-15 16:35 - 00169472 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\93182e9779b8be0f688fd0784df6d7fb\IsdiInterop.ni.dll
2011-08-23 01:34 - 2010-11-05 21:50 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll
2012-08-17 21:38 - 2012-08-17 21:38 - 00479160 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\dblite.dll
2012-08-17 21:40 - 2012-08-17 21:40 - 00068024 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\QtWebKit\qmlwebkitplugin4.dll
2012-08-17 21:39 - 2012-08-17 21:39 - 01310136 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\kpcengine.2.2.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm
AlternateDataStreams: C:\Users\Public\DRM:احتضان

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Juanenodra => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, the associated entry will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\aeriagames.com -> hxxps://aeriagames.com
IE trusted site: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\aeriagames.com -> hxxp://aeriagames.com
IE trusted site: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\vizzed.com -> www.vizzed.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\isaiah\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.254

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: Dell Webcam Central => "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2

==================== FirewallRules (whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

FirewallRules: [{FB6C794F-7922-48D8-A3F1-A44404E84F12}] => (Allow) C:\Program Files (x86)\Dell\VideoStage\VideoStage.exe
FirewallRules: [{63854801-A57A-4ABB-81E7-5C4DC3157658}] => (Allow) C:\Program Files (x86)\Intel Corporation\Intel WiDi\WiDiApp.exe
FirewallRules: [{12585EEA-68D6-408D-8517-280CAA92E4A0}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{DD57CD94-27D6-4122-86EA-DB88430B1CB0}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{752E3E89-AF7E-4B59-8866-C7970C224C3C}] => (Allow) LPort=2869
FirewallRules: [{7A902977-647A-468E-8931-396ED9E71E84}] => (Allow) LPort=1900
FirewallRules: [{0F7E30EE-C410-4D29-B1F4-54FBE548FE97}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{CAE8A2FC-722C-48F6-A455-2FA259AE53A0}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{E9E30087-2443-4798-955C-EF1AA1491643}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{012CD4EF-672F-46AC-B9D0-F281B2AC810D}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{197528BE-073B-4AE2-8528-CD2CDD7362B3}] => (Allow) C:\Program Files\dell stage\dell stage\accuweather\accuweather.exe
FirewallRules: [{B5FC9064-61FB-4239-9AFE-850C68495823}] => (Allow) C:\Program Files\dell stage\musicstage\musicstageengine.exe
FirewallRules: [{A2D300F2-21DA-4A32-8699-FB1A6A12DDF4}] => (Allow) C:\Program Files\dell stage\dell stage\stage_primary.exe
FirewallRules: [{10ECBC56-DF4C-4E71-816C-83BA8FD49A89}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
FirewallRules: [{9CE7BF3D-062D-42AD-8664-A39A0C907B42}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
FirewallRules: [{C357C8ED-9A97-413B-89D6-CE4152DF55BB}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
FirewallRules: [{43AC5FE2-DDC5-43FA-9EB8-D615DA093668}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
FirewallRules: [{FAAB9E6F-CF0D-4E7F-BD82-71B6CB74C25E}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{E3A7C8B5-04AC-4D19-A2B2-95A2D17A9353}] => (Allow) C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\TroubleShooter.exe
FirewallRules: [{D60727C2-8C03-4F89-A2EB-5A3E44A14B91}] => (Allow) C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\TroubleShooter.exe
FirewallRules: [{C6A23999-B8F6-4CE2-97F6-00788ADE5CB8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{9317D26B-2F68-4672-8074-259E8E7D1338}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [TCP Query User{BB94525D-EC67-47B0-BE58-7BC5F9292A9C}C:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe] => (Allow) C:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe
FirewallRules: [UDP Query User{D2207485-A32A-4059-94F8-DFCA229F2841}C:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe] => (Allow) C:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe
FirewallRules: [TCP Query User{F6DFB93A-8C9A-45C9-A455-6A1072FC97E5}C:\users\isaiah\documents\arma 2\expansion\beta\arma2oa.exe] => (Allow) C:\users\isaiah\documents\arma 2\expansion\beta\arma2oa.exe
FirewallRules: [UDP Query User{941B0E54-6AA8-4A41-B666-1026F440C875}C:\users\isaiah\documents\arma 2\expansion\beta\arma2oa.exe] => (Allow) C:\users\isaiah\documents\arma 2\expansion\beta\arma2oa.exe
FirewallRules: [{96D96BA7-F17E-46E6-B4BF-F12C56B103FA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2\arma2.exe
FirewallRules: [{314B7D78-94A0-4349-BBC9-33624EC89331}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2\arma2.exe
FirewallRules: [{15895A70-9802-4D97-8898-400EC4C2D843}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\ArmA2OA.exe
FirewallRules: [{9EB13300-A4B1-4112-8910-036629D5D11A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\ArmA2OA.exe
FirewallRules: [{4836FCF4-9BB3-4902-8884-611EC0D21A28}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\BEsetup\Setup_BattlEyeARMA2OA.exe
FirewallRules: [{2E918AC1-DDFB-427D-BECB-1960AFC989D6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\BEsetup\Setup_BattlEyeARMA2OA.exe
FirewallRules: [TelnetServer-TlntSvr-TCP-In] => (Allow) %systemroot%\system32\tlntsvr.exe
FirewallRules: [TelnetServer-Tlntadmn-RPC-In] => (Allow) %systemroot%\system32\tlntsvr.exe
FirewallRules: [{B67463BB-F4A5-40AB-A436-C1D1D0880FBE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\Expansion\beta\Arma2OA.exe
FirewallRules: [{02540B9A-E497-451A-AFB6-CA886A07A548}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\Expansion\beta\Arma2OA.exe
FirewallRules: [{B5D857F8-0CEE-49B0-997E-7C48AD3E6325}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{A2F3C668-51FA-44F7-83AE-76F995FAA1D7}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{97D65CF0-84F6-4897-8A54-0C4420274BD8}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{03F4D284-2275-4B42-A6DC-986ADED7B968}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{86C04536-A007-4518-8A61-954D896FF24C}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{E6C8584E-37F7-4BB4-BB32-0414FDC000CC}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{45854D96-0B6E-4D00-95BA-8177382EF602}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{A8653AE9-C6A9-421C-8515-944A08409C68}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{3C3BCFAB-27C4-4293-B3DE-7B0E94B72CDD}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{E665FFC5-64AB-402F-BB02-C3F0CE12410B}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{B8512867-3199-4121-A49A-F5D5F7E1AF25}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{5F9F44AD-07FF-4299-A484-114C3CAEB1C4}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{2F3A8874-4A67-4D9A-BCCA-964FD36F3B5B}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{CDB939EB-A340-4729-BE7D-44E8A9584B54}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{FEF78855-BA7B-4BA2-AAB9-515515030BD0}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{C7BEAC9A-0718-4C6B-B0C9-648861548349}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{7B59DED9-4C84-4007-927D-DB2EEEE88ED6}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{D039FF42-7318-47AD-B987-1EBE71796652}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{EBEBD8A7-6048-4AA0-AED5-827C8783B484}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{1A1B1F5E-005A-486B-A9BC-D023C75C52A4}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{CED5EF5E-F614-4000-9F8A-C01E287FA528}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{64825B42-1996-49FF-A530-520AE090353D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{FF107C82-1939-4E90-9FC2-42224DF53860}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{28A958BD-7A82-431B-A2E2-9ED38A202C02}] => (Allow) C:\Users\isaiah\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{66C60478-1894-49A8-A443-F93E1368FF4C}] => (Allow) C:\Users\isaiah\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{C1A54FC1-C9B0-4491-B1E1-F8F36CE7FC3A}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{CCF76574-D646-45D1-82D3-2F1DCC3D34C0}] => (Allow) C:\Program Files (x86)\Sibelius Software\Sibelius 6 Demo\RegTool.exe
FirewallRules: [{BF8FC548-2863-4DD2-A9F4-AD96930853E2}] => (Allow) C:\Program Files (x86)\Sibelius Software\Sibelius 6 Demo\RegTool.exe
FirewallRules: [{A3715BD5-99B3-4818-B574-83BB0AE01B69}] => (Allow) C:\Program Files (x86)\Sibelius Software\Sibelius 6 Demo\Sibelius.exe
FirewallRules: [{9AADF8FE-3BB8-47BD-ADCA-377D0D6B6395}] => (Allow) C:\Program Files (x86)\Sibelius Software\Sibelius 6 Demo\Sibelius.exe
FirewallRules: [{E71C00F4-3C19-4CB6-9E9F-32C75850A280}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{E59972B6-F43D-45ED-A604-632CE54F8DEF}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{AD135AE5-93C1-4D3A-8B2C-959381FD9587}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{E69A4F65-9A83-4F50-9A77-3D01E82F25FC}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{9DBAD9EF-6D2A-45E5-9538-D9DCDB39A92A}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{54FE5C8B-7914-4EA7-9C12-5C47A6831CA6}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{5D6F0DD1-0361-476F-BBF9-CEF5AB0435EF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{1CD9158C-F9B2-477D-9964-5CBE968D8994}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{D147D394-73CD-4BB4-AFAF-D779C7868421}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{96435E38-7774-4E5D-954B-3A64449F753A}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{CE675344-42FD-40D9-BCF5-A56473C60EDD}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{DE895E9C-8FA0-4E94-864B-54A00980054A}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{50ECF78E-F2E1-44DC-9516-7C62377A07B7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dystopia\hl2.exe
FirewallRules: [{806EA9CC-A6BB-493E-AB32-90F1DDB0E631}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dystopia\hl2.exe
FirewallRules: [{397B6D36-497C-4868-A41A-40E03E1D9679}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{908AF1B7-82D9-4BB0-B47F-43AB55B88D88}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{FCE00889-A54B-47DA-93BB-AF20C9CD332C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{8B4B2CE7-3120-472D-8F7F-0DA54C027108}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{2A2E1B5C-545E-4013-B8BD-E6CF18A27DB6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{D268BEE6-1B40-4FDD-B133-0B13295A08E8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{A66DFEA2-A32F-4E6D-8672-687C606C27B1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{F3C0C2E5-100F-4083-AFCC-06C138B9EDD1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{2DB11E19-D773-4A30-A496-62D9F084FCAC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{46652C7F-B004-46A3-AF01-3B59029AE1FB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{7783C636-6DAA-4EE7-8B19-AA31FFCF1624}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{D49951CB-4AEC-40E6-9C0E-F63428F5F43B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{EF7C9F41-2702-4BBE-95B9-259E7FBA2200}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SourceSDK\bin\SDKLauncher.exe
FirewallRules: [{A24A339E-327E-4C4F-9F83-47F8A8964802}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SourceSDK\bin\SDKLauncher.exe
FirewallRules: [{D399BE08-1177-4881-9E93-1D73B67D225D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{178133F8-17F7-46D0-8FDF-B2FD7FC56135}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{C20197EE-C991-4084-B38A-2E8EFBE0C71E}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{7DCE9768-2811-4544-9195-FFF15C99CF1A}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{61DC4E84-48CA-41CC-81EC-8EE92BD69293}C:\users\isaiah\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\isaiah\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{FE3A2764-CDAD-45F4-A927-7696FF33B0C4}C:\users\isaiah\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\isaiah\appdata\local\akamai\netsession_win.exe
FirewallRules: [TCP Query User{15A3C15A-BA7C-4E64-9198-CF90BCAF2E60}C:\users\isaiah\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\isaiah\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{1EF7FB12-39FE-41EE-A725-9A9488E3439F}C:\users\isaiah\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\isaiah\appdata\local\akamai\netsession_win.exe
FirewallRules: [{4FDA637A-3EDA-4493-8BFA-B1BC41469C68}] => (Allow) C:\Users\isaiah\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{C3970759-44FA-45BE-A160-2C4E60B09FED}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Battlefield Bad Company 2\BFBC2Game.exe
FirewallRules: [{FD45BFEC-D668-4B4B-ABE1-F11199BA8940}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Battlefield Bad Company 2\BFBC2Game.exe
FirewallRules: [{7F4B2C0C-090E-4FEA-A11A-6FAC869CEA39}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{2521313E-7A6A-43F9-9AC7-8A936ECD0E41}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{024290EF-CCC1-4CAB-9744-75B05D31E44C}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{8DE86DB8-B999-49F5-A4F1-BBC16EFA8D39}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [TCP Query User{F8E7BA2B-C07C-45EA-A75E-F94337AA896F}C:\program files (x86)\starcraft\starcraft.exe] => (Block) C:\program files (x86)\starcraft\starcraft.exe
FirewallRules: [UDP Query User{4E49E8C7-0AC8-4AC0-A1C0-C29713D2F3B9}C:\program files (x86)\starcraft\starcraft.exe] => (Block) C:\program files (x86)\starcraft\starcraft.exe
FirewallRules: [{8A124A1B-6883-4FCB-AD6D-81040F867678}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ_BE.exe
FirewallRules: [{9D6830DA-BD7C-45D1-BABA-770F7957788A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ_BE.exe
FirewallRules: [TCP Query User{C3684451-AA8F-40BB-A78E-BF0E27D29CFE}C:\program files\java\jre7\bin\javaw.exe] => (Block) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{A5DE10FA-3FE8-423F-AFA6-7C9B743E710D}C:\program files\java\jre7\bin\javaw.exe] => (Block) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{12F07043-9EC9-43F2-B5B8-4110A638B150}C:\program files\andy\andy.exe] => (Allow) C:\program files\andy\andy.exe
FirewallRules: [UDP Query User{C6CAF11B-BDFD-407D-9536-9477D2431CA5}C:\program files\andy\andy.exe] => (Allow) C:\program files\andy\andy.exe
FirewallRules: [{204DD4E8-C91E-4992-A36D-F405E3E5235C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Project Zomboid Demo\ProjectZomboid64.exe
FirewallRules: [{1C10656A-C6E8-474F-ACD6-8882831063DB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Project Zomboid Demo\ProjectZomboid64.exe
FirewallRules: [TCP Query User{C8631496-3840-4660-8622-93DD79861543}C:\program files (x86)\the elder scrolls v skyrim\creationkit.exe] => (Allow) C:\program files (x86)\the elder scrolls v skyrim\creationkit.exe
FirewallRules: [UDP Query User{5C40F815-7D04-4652-9CA8-6565450F2384}C:\program files (x86)\the elder scrolls v skyrim\creationkit.exe] => (Allow) C:\program files (x86)\the elder scrolls v skyrim\creationkit.exe
FirewallRules: [TCP Query User{0FBA8A7A-C340-49AF-9637-A245740934D9}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{A78E5463-1B90-4D63-AD09-B4BCFA8553C4}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{08EA1A3E-B831-4F5D-999C-CB26DEEC2406}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{6CCF437F-603D-4C73-B9E6-73F8376AA5E0}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{DFE02089-F143-4BAE-A36E-510BB05E09C6}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{A5C7614C-3DD0-4BC7-9E50-D378C090B17C}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [{4FC4C42C-7832-4953-A273-799E62AE3633}] => (Allow) C:\Users\isaiah\AppData\Local\Temp\nsbE299.tmp\CnetInstaller-10257337.exe
FirewallRules: [{1E0CBCB6-D74A-430A-B754-A6D68B7FB243}] => (Allow) C:\Users\isaiah\AppData\Local\Temp\nsbE299.tmp\CnetInstaller-10257337.exe
FirewallRules: [TCP Query User{D27C5782-3133-4774-805A-A95F829BFAA9}C:\savant\savant.exe] => (Allow) C:\savant\savant.exe
FirewallRules: [UDP Query User{E364D1FE-4A01-476A-A0A8-B7B0882A7E2A}C:\savant\savant.exe] => (Allow) C:\savant\savant.exe
FirewallRules: [TCP Query User{4837C4D3-D04B-47AA-9145-C5B6ED44DD08}C:\savant\savant.exe] => (Block) C:\savant\savant.exe
FirewallRules: [UDP Query User{2EEC6FEB-3185-479B-B5DF-4E51F567E380}C:\savant\savant.exe] => (Block) C:\savant\savant.exe
FirewallRules: [{45C3E57E-1FF9-4BF7-8F48-25B0218C5D21}] => (Allow) C:\ProgramData\boostwebapp\1.1.0.31\gefaucu.EXE
FirewallRules: [{73B92472-2AFC-40AF-93B2-2B13839636C5}] => (Allow) C:\ProgramData\boostwebapp\1.1.0.31\gefaucu.EXE
FirewallRules: [{6EFFD7E9-B50D-450A-90D3-2AD488622840}] => (Allow) C:\ProgramData\boostwebapp\1.1.0.31\gefaucu.EXE
FirewallRules: [{7C55DD14-179F-4F6E-B947-3E8B8B51E8F3}] => (Allow) C:\ProgramData\boostwebapp\1.1.0.31\gefaucu.EXE
FirewallRules: [{906C62C6-360B-4E6B-B3BC-BE85F4D0EE64}] => (Allow) C:\ProgramData\boostwebapp\1.1.0.31\gefaucu.EXE
FirewallRules: [{EAB59816-4E3C-47B8-B5DF-5F10D9F6264A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============

Name: VirtualBox Host-Only Ethernet Adapter
Description: VirtualBox Host-Only Ethernet Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Oracle Corporation
Service: VBoxNetAdp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

==================== Event log errors: =========================

Application errors:
==================
Error: (05/09/2015 02:24:14 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/09/2015 01:55:33 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddWin32ServiceFiles: Unable to back up image of service QumbaFyvu since QueryServiceConfig API failed

System Error:
Access is denied.
.

Error: (05/09/2015 01:55:33 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddWin32ServiceFiles: Unable to back up image of service jylvirmid since QueryServiceConfig API failed

System Error:
Access is denied.
.

Error: (05/09/2015 01:55:33 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddWin32ServiceFiles: Unable to back up image of service imhmypneta since QueryServiceConfig API failed

System Error:
Access is denied.
.

Error: (05/09/2015 01:55:33 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary tammgR119 service.

System Error:
Access is denied.
.

Error: (05/09/2015 01:55:33 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary tammgF119 service.

System Error:
Access is denied.
.

Error: (05/09/2015 01:49:10 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/08/2015 08:45:47 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/08/2015 08:41:07 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddWin32ServiceFiles: Unable to back up image of service QumbaFyvu since QueryServiceConfig API failed

System Error:
Access is denied.
.

Error: (05/08/2015 08:41:07 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddWin32ServiceFiles: Unable to back up image of service jylvirmid since QueryServiceConfig API failed

System Error:
Access is denied.
.

System errors:
=============
Error: (05/09/2015 02:26:33 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Dell Digital Delivery Service service failed to start due to the following error:
%%2

Error: (05/09/2015 02:25:39 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (05/09/2015 02:23:29 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \SystemRoot\SysWow64\drivers\pfc.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

Error: (05/09/2015 02:23:26 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \SystemRoot\SysWow64\drivers\pfc.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

Error: (05/09/2015 01:51:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Dell Digital Delivery Service service failed to start due to the following error:
%%2

Error: (05/09/2015 01:48:20 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Skype Click to Call Updater service failed to start due to the following error:
%%1053

Error: (05/09/2015 01:48:18 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Skype Click to Call Updater service to connect.

Error: (05/09/2015 01:47:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Bluetooth Device Monitor service failed to start due to the following error:
%%1053

Error: (05/09/2015 01:47:06 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Bluetooth Device Monitor service to connect.

Error: (05/09/2015 01:46:53 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Microsoft Office Sessions:
=========================
Error: (05/09/2015 02:24:14 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/09/2015 01:55:33 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service QumbaFyvu since QueryServiceConfig API failed

System Error:
Access is denied.

Error: (05/09/2015 01:55:33 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service jylvirmid since QueryServiceConfig API failed

System Error:
Access is denied.

Error: (05/09/2015 01:55:33 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service imhmypneta since QueryServiceConfig API failed

System Error:
Access is denied.

Error: (05/09/2015 01:55:33 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddLegacyDriverFiles: Unable to back up image of binary tammgR119 service.

System Error:
Access is denied.

Error: (05/09/2015 01:55:33 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddLegacyDriverFiles: Unable to back up image of binary tammgF119 service.

System Error:
Access is denied.

Error: (05/09/2015 01:49:10 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/08/2015 08:45:47 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/08/2015 08:41:07 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service QumbaFyvu since QueryServiceConfig API failed

System Error:
Access is denied.

Error: (05/08/2015 08:41:07 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service jylvirmid since QueryServiceConfig API failed

System Error:
Access is denied.

CodeIntegrity Errors:
===================================
  Date: 2014-10-12 17:49:34.587
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-12 17:49:34.577
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-12 17:49:34.577
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-12 17:49:34.567
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-12 17:49:34.557
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-12 17:49:34.557
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-08 19:31:35.104
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-08 19:31:35.104
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-08 19:31:35.094
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-08 19:31:35.014
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

==================== Memory info ===========================

Processor: Intel® Core™ i5-2410M CPU @ 2.30GHz
Percentage of memory in use: 32%
Total physical RAM: 6051.17 MB
Available physical RAM: 4058.27 MB
Total Pagefile: 12100.54 MB
Available Pagefile: 9766.6 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:581.42 GB) (Free:257.16 GB) NTFS
Drive e: (SKYRIM_EN) (CDROM) (Total:5.12 GB) (Free:0 GB) UDF

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596.2 GB) (Disk ID: D9D722B7)
Partition 1: (Not Active) - (Size=100 MB) - (Type=DE)
Partition 2: (Active) - (Size=14.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=581.4 GB) - (Type=07 NTFS)

==================== End Of Log ============================


  • 0

#8
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts
It appears that this one is able to regenerate itself. We need to take another approach.



FRST.gif Scan with Farbar Recovery Scan Tool from the Recovery Environment

On a clean machine lease download Farbar Recovery Scan Tool and save it to your flash drive.
There will be two versions to download: 32-bit and 64-bit. Please download the one that is designed for your system. If you don't know which one should it be, download both of them and try each other out. Only one will run - this will be the right one.
Plug the flash drive into the infected PC.

WindowsKey.png Enter the System Recovery Options

Enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select English as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.
On the System Recovery Options menu you will get the following options:
  • Startup Repair
  • System Restore
  • Windows Complete PC Restore
  • Windows Memory Diagnostic Tool
  • Command Prompt
Select Command Prompt.

notepad.png Access the notepad and identify your USB drive

In the Command Prompt please type in notepad.exe and press Enter.
  • When the notepad opens, go to File menu.
  • Select Open.
  • Go to Computer and search there for your USB drive letter.
Note down the letter and close the notepad.

FRST.gif Scan with Farbar Recovery Scan Tool

Once back in the command prompt window, please do the following:
  • Type in e:\frst.exe and press Enter.
    You need to replace e with the letter of your USB drive taken from notepad!
    Please mind also that for 64-bit systems you need to type in FRST64.exe!
  • FRST will start to run. Give him a minute or so to load itself.
  • Click Yes to Disclaimer.
  • In the main console, please click Scan and wait.
When finished it will produce a logfile named FRST.txt in the root of your pendrive and display it. Close that logfile.

Please include the content of that logfile in your next reply.
  • 0

#9
crazyfrank39

crazyfrank39

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-05-2015
Ran by SYSTEM on MININT-9MKKALF on 10-05-2015 22:38:25
Running from F:\
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Recovery

The current controlset is ControlSet001
[b]ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.[/b]

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-25] (IDT, Inc.)
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [609144 2011-04-12] (Alps Electric Co., Ltd.)
HKLM\...\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1933584 2010-12-17] (Intel(R) Corporation)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [DellStage] => C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe [2195824 2012-02-01] ()
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-05] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [RoxWatchTray] => c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\...\Run: [Desktop Disc Tool] => c:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe [514544 2010-11-17] ()
HKLM-x32\...\Run: [Dell Registration] => C:\Program Files (x86)\System Registration\prodreg.exe [3926528 2010-08-23] (Dell, Inc.)
HKLM-x32\...\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation)
HKLM-x32\...\Run: [UVS10 Preload] => C:\Program Files (x86)\Ulead Systems\Ulead VideoStudio SE DVD\uvPL.exe [36864 2006-08-09] (Ulead Systems, Inc.)
HKLM-x32\...\Run: [AccuWeatherWidget] => C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe [968048 2012-02-01] ()
HKLM-x32\...\Run: [Aeria Ignite] => C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-06] (Aeria Games & Entertainment)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226560 2014-11-18] ()
HKLM-x32\...\Run: [Andy] => C:\Program Files\Andy\HandyAndy.exe [896904 2014-10-22] ()
HKLM-x32\...\Run: [AVP] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [218880 2012-08-17] (Kaspersky Lab ZAO)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\isaiah\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [17418928 2012-07-13] (Skype Technologies S.A.)
HKU\isaiah\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3492504 2012-12-24] (Electronic Arts)
HKU\isaiah\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2889408 2015-04-13] (Valve Corporation)
HKU\isaiah\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3674320 2013-01-08] (DT Soft Ltd)
HKU\isaiah\...\Run: [Akamai NetSession Interface] => C:\Users\isaiah\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-30] (Akamai Technologies, Inc.)
HKU\isaiah\...\Run: [uTorrent] => C:\Users\isaiah\AppData\Roaming\uTorrent\uTorrent.exe [1378640 2014-12-18] (BitTorrent Inc.)
Startup: C:\Users\isaiah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk [2014-02-22]
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 ADExchange; C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [44736 2013-10-24] (ArcSoft, Inc.)
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-02-22] (Adobe Systems)
S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [218880 2012-08-17] (Kaspersky Lab ZAO)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [967040 2015-04-02] ()
S2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
S2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
S2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2719928 2015-04-22] (Microsoft Corporation)
S2 FTSvc; C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Updater\FantapperUpdater.exe [16896 2013-01-23] (Brand Affinity Technologies)
S2 imhmypneta; C:\ProgramData\boostwebapp\1.1.0.31\gefwucu.exe [202736 2015-05-03] ()
S3 Juanenodra; C:\ProgramData\boostwebapp\1.1.0.31\Juanenodra.exe [2771968 2015-05-03] ()
S2 jylvirmid; C:\ProgramData\boostwebapp\1.1.0.31\gefaucu.exe [499696 2015-05-03] ()
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [398184 2012-12-14] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [682344 2012-12-14] (Malwarebytes Corporation)
S2 mikikycu; C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031\nsu9557.tmp [117248 2015-05-08] ()
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-12-17] ()
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [998640 2015-04-05] (Overwolf LTD)
S2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [75064 2014-11-20] ()
S2 QumbaFyvu; C:\ProgramData\boostwebapp\1.1.0.31\XebbaEwyn.exe [266736 2015-05-03] ()
S3 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-13] (Microsoft Corporation)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
S2 wyzicyjy; C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031\jnsm42CF.tmp [224768 2015-05-03] ()
S2 DellDigitalDelivery; "C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-02-27] (DT Soft Ltd)
S0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458584 2012-06-19] (Kaspersky Lab ZAO)
S5 klflt; C:\Windows\System32\Drivers\klflt.sys [89432 2012-08-13] (Kaspersky Lab)
S1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [611160 2012-10-25] (Kaspersky Lab)
S1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [28504 2012-08-02] (Kaspersky Lab ZAO)
S3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29016 2012-10-25] (Kaspersky Lab)
S3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29528 2012-10-25] (Kaspersky Lab)
S1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54104 2012-06-08] (Kaspersky Lab)
S1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178008 2012-08-13] (Kaspersky Lab)
S3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [24176 2012-12-14] (Malwarebytes Corporation)
S3 pfc; C:\Windows\SysWOW64\drivers\pfc.sys [10368 2003-09-19] (Padus, Inc.)
S3 PSMNBUS; C:\Windows\System32\DRIVERS\PSMNBUS.sys [107272 2013-11-21] (DEVGURU Co., LTD.)
S3 PSMNMDM; C:\Windows\System32\DRIVERS\PSMNMDM.sys [187144 2013-11-21] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 PSMNVSP; C:\Windows\System32\DRIVERS\PSMNVSP.sys [187144 2013-11-21] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 StkCMini; C:\Windows\System32\Drivers\StkCMini.sys [1917576 2010-06-07] (Syntek)
S1 tammgF119; C:\windows\system32\Drivers\tammgF119.sys [34952 2015-05-03] ()
S1 tammgR119; C:\windows\system32\Drivers\tammgR119.sys [37000 2015-05-03] ()
S3 VBoxDrv; \??\c:\Program Files\Oracle\VirtualBox\VBoxDrv.sys [X]
S3 X6va017; \??\C:\windows\SysWOW64\Drivers\X6va017 [X]
S3 xhunter1; \??\C:\windows\xhunter1.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-09 14:34 - 2015-05-09 14:34 - 00000000 ____D () C:\Users\isaiah\Desktop\FRST-OlderVersion
2015-05-09 14:29 - 2015-05-09 14:28 - 00001148 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security 2013.lnk
2015-05-09 14:29 - 2015-05-09 14:28 - 00001148 _____ () C:\ProgramData\Desktop\Kaspersky Internet Security 2013.lnk
2015-05-09 14:28 - 2012-07-11 17:09 - 00064856 _____ (Kaspersky Lab) C:\Windows\System32\klfphc.dll
2015-05-09 14:27 - 2015-05-09 14:27 - 00000000 ____D () C:\Windows\ELAMBKUP
2015-05-09 14:27 - 2015-05-09 14:27 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab
2015-05-09 14:27 - 2012-10-25 17:23 - 00611160 _____ (Kaspersky Lab) C:\Windows\System32\Drivers\klif.sys
2015-05-09 14:27 - 2012-08-13 18:24 - 00089432 _____ (Kaspersky Lab) C:\Windows\System32\Drivers\klflt.sys
2015-05-09 14:22 - 2015-05-09 14:22 - 00000000 ____D () C:\Program Files\Trend Micro
2015-05-08 21:58 - 2015-05-08 21:58 - 00725281 _____ (Malwarebytes Corp.) C:\Users\isaiah\Downloads\mbar-1.09.1.1004 (1).exe.sqk8lhs.partial
2015-05-08 20:46 - 2015-05-03 21:53 - 00037000 _____ () C:\Windows\System32\Drivers\tammgR119.sys
2015-05-08 20:45 - 2015-05-03 21:53 - 00034952 _____ () C:\Windows\System32\Drivers\tammgF119.sys
2015-05-08 20:44 - 2015-05-08 20:44 - 00000000 _____ () C:\Windows\DCEBOOT.LOG
2015-05-08 19:56 - 2015-05-08 19:56 - 00000010 _____ () C:\Users\isaiah\AppData\Local\sponge.last.runtime.cache
2015-05-08 19:15 - 2015-05-09 14:17 - 00236080 _____ (Trend Micro Inc.) C:\Windows\RegBootClean64.exe
2015-05-08 19:15 - 2015-05-08 19:16 - 00025136 _____ (Trend Micro Inc.) C:\Windows\DCEBoot64.exe
2015-05-08 18:43 - 2015-05-09 14:21 - 00000000 ____D () C:\ProgramData\Trend Micro
2015-05-08 18:39 - 2015-05-08 18:39 - 00000036 _____ () C:\Users\isaiah\AppData\Local\housecall.guid.cache
2015-05-08 18:28 - 2015-05-08 18:28 - 06630552 _____ (Trend Micro Inc.) C:\Users\isaiah\Downloads\TrendMicro_TAV_8.0_US-en_Downloader.exe
2015-05-07 19:43 - 2015-05-09 13:45 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-05-07 19:37 - 2015-05-08 20:41 - 00000000 ____D () C:\Users\isaiah\Desktop\mbar
2015-05-07 19:37 - 2015-05-08 19:48 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamchameleon.sys
2015-05-07 19:31 - 2015-05-07 19:37 - 16502728 _____ (Malwarebytes Corp.) C:\Users\isaiah\Downloads\mbar-1.09.1.1004.exe
2015-05-06 08:14 - 2015-05-09 14:36 - 00068112 _____ () C:\Users\isaiah\Desktop\Addition.txt
2015-05-06 08:13 - 2015-05-09 14:36 - 00072933 _____ () C:\Users\isaiah\Desktop\FRST.txt
2015-05-06 08:12 - 2015-05-10 22:38 - 00000000 ____D () C:\FRST
2015-05-06 08:11 - 2015-05-09 14:34 - 02102784 _____ (Farbar) C:\Users\isaiah\Desktop\FRST64.exe
2015-05-05 16:37 - 2015-05-05 16:37 - 02960802 _____ () C:\Windows\shost.bin
2015-05-04 21:39 - 2015-05-04 21:39 - 00797232 _____ (Generic ) C:\Users\isaiah\Downloads\java_runtime_enviroment_setup.exe
2015-05-04 21:27 - 2015-05-04 21:27 - 00002261 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-05-04 21:27 - 2015-05-04 21:27 - 00002261 _____ () C:\ProgramData\Desktop\Google Chrome.lnk
2015-05-03 22:10 - 2015-05-03 22:10 - 00000000 ____D () C:\Users\isaiah\AppData\Roaming\dlg
2015-05-03 22:08 - 2015-05-03 22:08 - 00000000 _____ () C:\END
2015-05-03 22:07 - 2015-05-03 22:07 - 00000000 ____D () C:\Users\isaiah\AppData\Local\SearchProtect
2015-05-03 22:00 - 2015-05-03 22:00 - 00003464 _____ () C:\Windows\System32\Tasks\ProPCCleaner_Popup
2015-05-03 22:00 - 2015-05-03 22:00 - 00003200 _____ () C:\Windows\System32\Tasks\ProPCCleaner_Start
2015-05-03 21:59 - 2015-05-03 22:05 - 00000000 ____D () C:\Users\isaiah\AppData\Local\4C4C4544-1430690388-5A10-8058-C8C04F4C5031
2015-05-03 21:59 - 2015-05-03 21:59 - 00000000 ____D () C:\Users\isaiah\AppData\Local\Pro_PC_Cleaner
2015-05-03 21:53 - 2015-05-10 20:51 - 00004816 _____ () C:\Windows\SysWOW64\Juanenodra.ini
2015-05-03 21:53 - 2015-05-10 20:51 - 00002720 _____ () C:\Windows\SysWOW64\JuanenodraOff.ini
2015-05-03 21:53 - 2015-05-10 20:51 - 00002720 _____ () C:\Windows\System32\JuanenodraOff.ini
2015-05-03 21:53 - 2015-05-08 20:37 - 00000000 ____D () C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031
2015-05-03 21:53 - 2015-05-03 21:53 - 00000000 ____D () C:\ProgramData\boostwebapp
2015-05-03 21:53 - 2015-05-03 17:13 - 00398336 _____ () C:\Windows\System32\Juanenodra64.dll
2015-05-03 21:53 - 2015-05-03 17:12 - 00329216 _____ () C:\Windows\SysWOW64\Juanenodra.dll
2015-04-29 20:04 - 2015-04-29 20:41 - 00000000 ____D () C:\Users\isaiah\Desktop\Music Sheets
2015-04-29 20:02 - 2015-04-29 20:02 - 00014281 _____ () C:\Users\isaiah\Downloads\Kirby Super Star - The Halberd.mid
2015-04-29 20:02 - 2015-04-29 20:02 - 00012331 _____ () C:\Users\isaiah\Downloads\Kirby Super Star - Cavios.mid
2015-04-20 20:06 - 2015-04-20 20:06 - 00000000 ____D () C:\Savant
2015-04-20 20:01 - 2015-04-20 20:03 - 01269567 _____ (Michael Lamont ) C:\Users\isaiah\Downloads\Savant31.exe
2015-04-19 20:52 - 2015-04-19 20:54 - 34404626 _____ () C:\Users\isaiah\Downloads\torbrowser-install-4.0.8_en-US.exe
2015-04-15 03:40 - 2015-04-15 03:41 - 01059952 _____ () C:\Windows\Minidump\041515-109512-01.dmp
2015-04-14 18:49 - 2015-03-24 20:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\WinSetupUI.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\System32\wups2.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\System32\wups.dll
2015-04-14 18:49 - 2015-03-24 20:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2015-04-14 18:49 - 2015-03-24 20:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2015-04-14 18:49 - 2015-03-24 20:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\System32\wu.upgrade.ps.dll
2015-04-14 18:49 - 2015-03-24 20:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-04-14 18:49 - 2015-03-24 20:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-04-14 18:49 - 2015-03-24 20:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-04-14 18:49 - 2015-03-24 20:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-04-14 18:49 - 2015-03-24 20:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-04-14 18:49 - 2015-03-22 20:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\System32\invagent.dll
2015-04-14 18:49 - 2015-03-22 20:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\System32\generaltel.dll
2015-04-14 18:49 - 2015-03-22 20:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\System32\appraiser.dll
2015-04-14 18:49 - 2015-03-22 20:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\System32\devinv.dll
2015-04-14 18:49 - 2015-03-22 20:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\System32\aepdu.dll
2015-04-14 18:49 - 2015-03-22 20:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\System32\aepic.dll
2015-04-14 18:49 - 2015-03-22 20:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\System32\acmigration.dll
2015-04-14 18:49 - 2015-03-22 20:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\System32\aeinv.dll
2015-04-14 18:49 - 2015-03-16 22:22 - 05557696 _____ (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2015-04-14 18:49 - 2015-03-16 22:22 - 00155576 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2015-04-14 18:49 - 2015-03-16 22:22 - 00095672 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2015-04-14 18:49 - 2015-03-16 22:19 - 01727904 _____ (Microsoft Corporation) C:\Windows\System32\ntdll.dll
2015-04-14 18:49 - 2015-03-16 22:17 - 00362496 _____ (Microsoft Corporation) C:\Windows\System32\wow64win.dll
2015-04-14 18:49 - 2015-03-16 22:17 - 00243712 _____ (Microsoft Corporation) C:\Windows\System32\wow64.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 01461760 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 01163264 _____ (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00728064 _____ (Microsoft Corporation) C:\Windows\System32\kerberos.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00503808 _____ (Microsoft Corporation) C:\Windows\System32\srcore.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00424448 _____ (Microsoft Corporation) C:\Windows\System32\KernelBase.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00341504 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00314880 _____ (Microsoft Corporation) C:\Windows\System32\msv1_0.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00309760 _____ (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00296960 _____ (Microsoft Corporation) C:\Windows\System32\rstrui.exe
2015-04-14 18:49 - 2015-03-16 22:16 - 00215040 _____ (Microsoft Corporation) C:\Windows\System32\winsrv.dll
2015-04-14 18:49 - 2015-03-16 22:16 - 00210944 _____ (Microsoft Corporation) C:\Windows\System32\wdigest.dll
2015-04-14 18:49 - 2015-03-16 22:15 - 00338432 _____ (Microsoft Corporation) C:\Windows\System32\conhost.exe
2015-04-14 18:49 - 2015-03-16 22:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-04-14 18:49 - 2015-03-16 22:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-04-14 18:49 - 2015-03-16 21:59 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-04-14 18:49 - 2015-03-16 21:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-04-14 18:49 - 2015-03-16 21:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-04-14 18:49 - 2015-03-16 21:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-04-14 18:49 - 2015-03-16 21:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-04-14 18:49 - 2015-03-16 21:56 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-04-14 18:49 - 2015-03-09 20:25 - 01882624 _____ (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2015-04-14 18:49 - 2015-03-09 20:21 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2015-04-14 18:49 - 2015-03-09 20:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-04-14 18:49 - 2015-03-09 20:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-04-14 18:49 - 2015-03-04 22:12 - 00404480 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll
2015-04-14 18:49 - 2015-03-04 21:05 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-04-14 18:48 - 2015-04-01 17:17 - 00389808 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2015-04-14 18:48 - 2015-04-01 16:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-04-14 18:48 - 2015-03-16 22:17 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00136192 _____ (Microsoft Corporation) C:\Windows\System32\sspicli.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00112640 _____ (Microsoft Corporation) C:\Windows\System32\smss.exe
2015-04-14 18:48 - 2015-03-16 22:16 - 00086528 _____ (Microsoft Corporation) C:\Windows\System32\TSpkg.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00050176 _____ (Microsoft Corporation) C:\Windows\System32\srclient.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00043520 _____ (Microsoft Corporation) C:\Windows\System32\csrsrv.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00029184 _____ (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00028160 _____ (Microsoft Corporation) C:\Windows\System32\secur32.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00022016 _____ (Microsoft Corporation) C:\Windows\System32\credssp.dll
2015-04-14 18:48 - 2015-03-16 22:16 - 00016384 _____ (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll
2015-04-14 18:48 - 2015-03-16 22:15 - 00064000 _____ (Microsoft Corporation) C:\Windows\System32\auditpol.exe
2015-04-14 18:48 - 2015-03-16 22:15 - 00031232 _____ (Microsoft Corporation) C:\Windows\System32\lsass.exe
2015-04-14 18:48 - 2015-03-16 22:13 - 00146432 _____ (Microsoft Corporation) C:\Windows\System32\msaudite.dll
2015-04-14 18:48 - 2015-03-16 22:13 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\msobjs.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\System32\adtschema.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\System32\apisetschema.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 22:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-04-14 18:48 - 2015-03-16 21:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-04-14 18:48 - 2015-03-16 21:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-04-14 18:48 - 2015-03-16 21:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-04-14 18:48 - 2015-03-16 21:57 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-04-14 18:48 - 2015-03-16 21:56 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-04-14 18:48 - 2015-03-16 21:56 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-04-14 18:48 - 2015-03-16 21:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-04-14 18:48 - 2015-03-16 21:56 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-04-14 18:48 - 2015-03-16 21:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-04-14 18:48 - 2015-03-16 21:56 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-04-14 18:48 - 2015-03-16 21:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-04-14 18:48 - 2015-03-16 21:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 21:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 20:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-04-14 18:48 - 2015-03-16 20:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-04-14 18:48 - 2015-03-16 20:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 20:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 20:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-04-14 18:48 - 2015-03-16 20:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-04-14 18:48 - 2015-03-12 21:32 - 24980480 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2015-04-14 18:48 - 2015-03-12 21:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2015-04-14 18:48 - 2015-03-12 21:25 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
2015-04-14 18:48 - 2015-03-12 21:09 - 00066560 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2015-04-14 18:48 - 2015-03-12 21:08 - 00584192 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2015-04-14 18:48 - 2015-03-12 21:08 - 00417280 _____ (Microsoft Corporation) C:\Windows\System32\html.iec
2015-04-14 18:48 - 2015-03-12 21:08 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
2015-04-14 18:48 - 2015-03-12 21:07 - 02886144 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2015-04-14 18:48 - 2015-03-12 21:06 - 00088064 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
2015-04-14 18:48 - 2015-03-12 21:00 - 00054784 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2015-04-14 18:48 - 2015-03-12 20:59 - 00034304 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2015-04-14 18:48 - 2015-03-12 20:55 - 00633856 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2015-04-14 18:48 - 2015-03-12 20:54 - 00144384 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2015-04-14 18:48 - 2015-03-12 20:54 - 00114688 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
2015-04-14 18:48 - 2015-03-12 20:53 - 00814080 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
2015-04-14 18:48 - 2015-03-12 20:50 - 06025216 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2015-04-14 18:48 - 2015-03-12 20:44 - 00968704 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2015-04-14 18:48 - 2015-03-12 20:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-04-14 18:48 - 2015-03-12 20:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-04-14 18:48 - 2015-03-12 20:40 - 00490496 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2015-04-14 18:48 - 2015-03-12 20:32 - 00077824 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll
2015-04-14 18:48 - 2015-03-12 20:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-04-14 18:48 - 2015-03-12 20:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-04-14 18:48 - 2015-03-12 20:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-04-14 18:48 - 2015-03-12 20:27 - 00199680 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
2015-04-14 18:48 - 2015-03-12 20:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-04-14 18:48 - 2015-03-12 20:26 - 00092160 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2015-04-14 18:48 - 2015-03-12 20:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-04-14 18:48 - 2015-03-12 20:23 - 00316928 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2015-04-14 18:48 - 2015-03-12 20:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-04-14 18:48 - 2015-03-12 20:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-04-14 18:48 - 2015-03-12 20:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-04-14 18:48 - 2015-03-12 20:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-04-14 18:48 - 2015-03-12 20:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-04-14 18:48 - 2015-03-12 20:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-04-14 18:48 - 2015-03-12 20:08 - 00720384 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2015-04-14 18:48 - 2015-03-12 20:07 - 00801280 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2015-04-14 18:48 - 2015-03-12 20:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-04-14 18:48 - 2015-03-12 20:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2015-04-14 18:48 - 2015-03-12 20:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2015-04-14 18:48 - 2015-03-12 20:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-04-14 18:48 - 2015-03-12 20:00 - 14397440 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2015-04-14 18:48 - 2015-03-12 19:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-04-14 18:48 - 2015-03-12 19:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-04-14 18:48 - 2015-03-12 19:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-04-14 18:48 - 2015-03-12 19:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-04-14 18:48 - 2015-03-12 19:45 - 02358784 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2015-04-14 18:48 - 2015-03-12 19:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-04-14 18:48 - 2015-03-12 19:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-04-14 18:48 - 2015-03-12 19:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-04-14 18:48 - 2015-03-12 19:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-04-14 18:48 - 2015-03-12 19:33 - 01548288 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2015-04-14 18:48 - 2015-03-12 19:22 - 00800768 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2015-04-14 18:48 - 2015-03-12 19:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-04-14 18:48 - 2015-03-12 19:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-04-14 18:48 - 2015-03-12 19:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-04-14 18:48 - 2015-02-24 20:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\http.sys
2015-04-14 18:45 - 2015-03-03 21:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\System32\clfs.sys
2015-04-14 18:45 - 2015-03-03 21:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\System32\clfsw32.dll
2015-04-14 18:45 - 2015-03-03 21:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll
2015-04-11 20:00 - 2015-04-11 20:05 - 01035272 _____ () C:\Windows\Minidump\041115-35537-01.dmp

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-10 21:28 - 2012-12-22 11:38 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-05-10 21:28 - 2011-08-23 01:23 - 02051267 _____ () C:\Windows\WindowsUpdate.log
2015-05-10 21:19 - 2012-09-12 18:15 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cd914d43dfa6d6.job
2015-05-10 21:15 - 2012-08-20 18:02 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-10 21:08 - 2014-01-25 14:48 - 00000390 _____ () C:\Windows\Tasks\update-sys.job
2015-05-10 21:05 - 2012-12-24 13:12 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2015-05-10 21:01 - 2009-07-13 21:45 - 00028576 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-10 21:01 - 2009-07-13 21:45 - 00028576 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-10 20:52 - 2013-02-25 20:47 - 00000000 ____D () C:\Users\isaiah\AppData\Roaming\uTorrent
2015-05-10 20:52 - 2012-12-06 19:32 - 00000000 ____D () C:\Program Files (x86)\Origin
2015-05-10 20:52 - 2011-12-29 18:20 - 00000000 ____D () C:\Users\isaiah\AppData\Roaming\Skype
2015-05-10 20:50 - 2012-12-24 11:46 - 00041183 _____ () C:\Windows\setupact.log
2015-05-10 20:50 - 2012-09-12 18:15 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cd914d439221f3.job
2015-05-10 20:50 - 2009-07-13 22:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-09 14:23 - 2010-11-20 20:47 - 01630352 _____ () C:\Windows\PFRO.log
2015-05-08 20:44 - 2015-02-08 21:42 - 00000000 ____D () C:\Program Files (x86)\SoftwareHelp
2015-05-08 20:11 - 2014-01-25 14:48 - 00000390 _____ () C:\Windows\Tasks\update-S-1-5-21-4152253128-2157246082-1293380562-1000.job
2015-05-07 20:46 - 2012-12-24 10:39 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2015-05-07 19:42 - 2015-02-08 21:41 - 00000000 ____D () C:\ProgramData\5551195122105854317
2015-05-05 16:49 - 2014-10-09 21:15 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2015-05-04 21:27 - 2011-12-31 10:52 - 00000000 ____D () C:\Users\isaiah\AppData\Local\Google
2015-05-04 21:27 - 2011-12-31 10:52 - 00000000 ____D () C:\Program Files (x86)\Google
2015-05-04 21:16 - 2009-07-13 22:13 - 00823564 _____ () C:\Windows\System32\PerfStringBackup.INI
2015-05-04 18:18 - 2012-04-17 18:25 - 00000506 _____ () C:\Windows\Tasks\SystemToolsDailyTest.job
2015-05-03 21:01 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\System32\NDF
2015-04-28 20:04 - 2015-02-08 21:40 - 00000000 ____D () C:\ProgramData\{8613789a-ab6e-b73f-8613-3789aab6e26a}
2015-04-23 16:51 - 2011-12-24 22:45 - 00000000 ____D () C:\Users\isaiah\AppData\Roaming\Adobe
2015-04-22 20:06 - 2014-01-25 14:48 - 00003266 _____ () C:\Windows\System32\Tasks\update-S-1-5-21-4152253128-2157246082-1293380562-1000
2015-04-22 20:06 - 2014-01-25 14:48 - 00000424 _____ () C:\Users\isaiah\AppData\Local\UserProducts.xml
2015-04-19 20:54 - 2013-12-21 22:08 - 00000000 ____D () C:\Users\isaiah\Desktop\Tor Browser
2015-04-16 18:15 - 2012-08-20 18:02 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-04-16 18:15 - 2012-08-20 18:02 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-16 18:15 - 2012-08-20 18:02 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-04-15 05:33 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\rescache
2015-04-15 05:25 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\AppCompat
2015-04-15 03:40 - 2013-03-28 10:11 - 603850817 _____ () C:\Windows\MEMORY.DMP
2015-04-15 03:40 - 2013-03-28 10:11 - 00000000 ____D () C:\Windows\Minidump
2015-04-15 03:27 - 2014-12-10 22:00 - 00000000 ____D () C:\Windows\System32\appraiser
2015-04-15 03:27 - 2014-04-29 22:07 - 00000000 ___SD () C:\Windows\System32\CompatTel
2015-04-15 03:27 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-04-15 03:10 - 2011-08-23 01:36 - 00816178 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-04-15 03:08 - 2013-08-08 03:01 - 00000000 ____D () C:\Windows\System32\MRT
2015-04-15 03:03 - 2012-01-23 20:22 - 128913832 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2015-04-11 12:10 - 2015-01-06 16:02 - 00000000 ____D () C:\Program Files (x86)\Overwolf

Some content of TEMP:
====================
C:\Users\isaiah\AppData\Local\Temp\2100.exe
C:\Users\isaiah\AppData\Local\Temp\226380_199177.exe
C:\Users\isaiah\AppData\Local\Temp\3faig5ns.dll
C:\Users\isaiah\AppData\Local\Temp\4c2459bebc146bfd821d90e28a2411ab.dll
C:\Users\isaiah\AppData\Local\Temp\6_Offer_12.exe
C:\Users\isaiah\AppData\Local\Temp\81c992b.exe
C:\Users\isaiah\AppData\Local\Temp\83929-92631-microsoft-office-2010.exe
C:\Users\isaiah\AppData\Local\Temp\a15154fd9009bc6f9bea0d0659312534.dll
C:\Users\isaiah\AppData\Local\Temp\bitool.dll
C:\Users\isaiah\AppData\Local\Temp\bpygdfsv.dll
C:\Users\isaiah\AppData\Local\Temp\CheatEngine62Clean.exe
C:\Users\isaiah\AppData\Local\Temp\conduitinstaller.exe
C:\Users\isaiah\AppData\Local\Temp\couponamazing.exe
C:\Users\isaiah\AppData\Local\Temp\cvtres.exe
C:\Users\isaiah\AppData\Local\Temp\DM1394570410.exe
C:\Users\isaiah\AppData\Local\Temp\fbyho1hu.dll
C:\Users\isaiah\AppData\Local\Temp\i4jdel0.exe
C:\Users\isaiah\AppData\Local\Temp\ICReinstall_donkey-kong.exe
C:\Users\isaiah\AppData\Local\Temp\IminentSetup.exe
C:\Users\isaiah\AppData\Local\Temp\instloffer.exe
C:\Users\isaiah\AppData\Local\Temp\InternetTurboSetup__1814_i1675065_il1537.exe
C:\Users\isaiah\AppData\Local\Temp\lnd15xiv.dll
C:\Users\isaiah\AppData\Local\Temp\nsb4CAB.tmp.exe
C:\Users\isaiah\AppData\Local\Temp\oi_{74E8797E-56B6-42A9-8C89-469757A0DC67}.exe
C:\Users\isaiah\AppData\Local\Temp\PCFixSpeedSetup.exe
C:\Users\isaiah\AppData\Local\Temp\photostage_1.0.0.50_1.5.0.130_update_all.exe
C:\Users\isaiah\AppData\Local\Temp\safeguard.exe
C:\Users\isaiah\AppData\Local\Temp\somoto_HD CODEC_1.0.exe
C:\Users\isaiah\AppData\Local\Temp\SpOrder.dll
C:\Users\isaiah\AppData\Local\Temp\supoptsetup.exe
C:\Users\isaiah\AppData\Local\Temp\tbcpa0.dll
C:\Users\isaiah\AppData\Local\Temp\UNINSTALL.EXE
C:\Users\isaiah\AppData\Local\Temp\Updater.exe
C:\Users\isaiah\AppData\Local\Temp\utt88CD.tmp.exe
C:\Users\isaiah\AppData\Local\Temp\winziprosetup-WZRO6_20130221.exe


==================== Known DLLs (Whitelisted) ================


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Restore Points  =========================

Restore point made on: 2015-04-18 21:23:22
Restore point made on: 2015-04-24 17:37:01
Restore point made on: 2015-04-28 19:49:40
Restore point made on: 2015-04-28 20:04:17
Restore point made on: 2015-05-02 12:11:11
Restore point made on: 2015-05-03 22:02:32
Restore point made on: 2015-05-03 22:03:18
Restore point made on: 2015-05-05 23:03:40
Restore point made on: 2015-05-07 20:34:39
Restore point made on: 2015-05-07 21:49:18
Restore point made on: 2015-05-08 20:41:21
Restore point made on: 2015-05-09 13:55:50

==================== Memory info =========================== 

Percentage of memory in use: 15%
Total physical RAM: 6051.17 MB
Available physical RAM: 5127.22 MB
Total Pagefile: 6049.37 MB
Available Pagefile: 5126.04 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:581.42 GB) (Free:256.97 GB) NTFS
Drive e: (Recovery) (Fixed) (Total:14.65 GB) (Free:7 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive f: (USB Disk) (Removable) (Total:14.9 GB) (Free:1.27 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596.2 GB) (Disk ID: D9D722B7)
Partition 1: (Not Active) - (Size=100 MB) - (Type=DE)
Partition 2: (Active) - (Size=14.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=581.4 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 14.9 GB) (Disk ID: C3072E18)
Partition 1: (Not Active) - (Size=14.9 GB) - (Type=0C)


LastRegBack: 2015-05-05 17:17

==================== End Of Log ============================

  • 0

#10
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts
Download the attached file and save it to the root of your pendrive. Both FRST and fixlist file have to be in the same location.

Re-run FRST from the external environment, just like before - but this time please press FIX. It will generate a fixlog file in the root of the pendrive. Please post it. Aside of that reboot your machine and tell me if the boostwebapp issues continue.

NOTE: This is not the end!

Attached Files


  • 0

Advertisements


#11
crazyfrank39

crazyfrank39

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

I never thought I would go online again... But wow... I Thank you for everything you did Naathim :D  :laughing: !

I never thought this virus would disappear... Thank You for helping me fight this battle that lasted a good 9 days :popcorn: . Thank you for aiding me and helping me see

that there was no need to buy anything expensive or fancy, this was just perfect. Well, I did have trouble with the internet connecting, but I just reseted the wifisock (I think that's what its called) and everything went back to normal! I love this forum now! I really am glad that I built up the courage for help, if not then I would of been done for.

Though there are a few questions I was wondering throughout... :pepsi:

  • I heard its a new type of virus, is there any more information on this new virus? Any name in particular? I just called it the boostwebapp folder problem.
  • Is there any other thread that explains in detail on the process you just gave me? Like how to check logs and edit them and fix them in a txt. file?
  • I consider myself having a healthy knowledge of computers, but I want to learn about these and how to fix it. vvv This question explains it...
  • Is there any way I can contribute to the forum? I am new and I want to expand and learn on how to do these things to help others, where do I start?

Sorry for the huge list of questions, I am just so excited I can go on my browser again! Thanks Naathim once again, you were the biggest help, thanks for helping me fight the boostwebapp virus for these 9 days of distress! :geek:

 

Oh and if I didn't go on this forum in the first place I probably would of done this :killcomp:  :smashcomp:


Edited by crazyfrank39, 12 May 2015 - 09:35 PM.

  • 0

#12
crazyfrank39

crazyfrank39

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

Oh yeah and last but not least, the log.

 

 

 

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-05-2015
Ran by isaiah at 2015-05-12 18:31:04 Run:1
Running from F:\
Loaded Profiles: isaiah (Available profiles: isaiah)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
C:\ProgramData\boostwebapp
S2 imhmypneta; C:\ProgramData\boostwebapp\1.1.0.31\gefwucu.exe [202736 2015-05-03] ()
S3 Juanenodra; C:\ProgramData\boostwebapp\1.1.0.31\Juanenodra.exe [2771968 2015-05-03] ()
S2 jylvirmid; C:\ProgramData\boostwebapp\1.1.0.31\gefaucu.exe [499696 2015-05-03] ()
S2 mikikycu; C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031\nsu9557.tmp [117248 2015-05-08] ()
C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031
S2 QumbaFyvu; C:\ProgramData\boostwebapp\1.1.0.31\XebbaEwyn.exe [266736 2015-05-03] ()
S2 wyzicyjy; C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031\jnsm42CF.tmp [224768 2015-05-03] ()
S1 tammgF119; C:\windows\system32\Drivers\tammgF119.sys [34952 2015-05-03] ()
C:\windows\system32\Drivers\tammgF119.sys
S1 tammgR119; C:\windows\system32\Drivers\tammgR119.sys [37000 2015-05-03] ()
C:\windows\system32\Drivers\tammgR119.sys
2015-05-08 20:46 - 2015-05-03 21:53 - 00037000 _____ () C:\Windows\System32\Drivers\tammgR119.sys
2015-05-08 20:45 - 2015-05-03 21:53 - 00034952 _____ () C:\Windows\System32\Drivers\tammgF119.sys
2015-05-03 22:07 - 2015-05-03 22:07 - 00000000 ____D () C:\Users\isaiah\AppData\Local\SearchProtect
2015-05-03 22:00 - 2015-05-03 22:00 - 00003464 _____ () C:\Windows\System32\Tasks\ProPCCleaner_Popup
2015-05-03 22:00 - 2015-05-03 22:00 - 00003200 _____ () C:\Windows\System32\Tasks\ProPCCleaner_Start
2015-05-03 21:59 - 2015-05-03 22:05 - 00000000 ____D () C:\Users\isaiah\AppData\Local\4C4C4544-1430690388-5A10-8058-C8C04F4C5031
2015-05-03 21:59 - 2015-05-03 21:59 - 00000000 ____D () C:\Users\isaiah\AppData\Local\Pro_PC_Cleaner
2015-05-03 21:53 - 2015-05-10 20:51 - 00004816 _____ () C:\Windows\SysWOW64\Juanenodra.ini
2015-05-03 21:53 - 2015-05-10 20:51 - 00002720 _____ () C:\Windows\SysWOW64\JuanenodraOff.ini
2015-05-03 21:53 - 2015-05-10 20:51 - 00002720 _____ () C:\Windows\System32\JuanenodraOff.ini
2015-05-03 21:53 - 2015-05-08 20:37 - 00000000 ____D () C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031
2015-05-03 21:53 - 2015-05-03 21:53 - 00000000 ____D () C:\ProgramData\boostwebapp
2015-05-03 21:53 - 2015-05-03 17:13 - 00398336 _____ () C:\Windows\System32\Juanenodra64.dll
2015-05-03 21:53 - 2015-05-03 17:12 - 00329216 _____ () C:\Windows\SysWOW64\Juanenodra.dll
C:\Users\isaiah\AppData\Local\Temp\2100.exe
C:\Users\isaiah\AppData\Local\Temp\226380_199177.exe
C:\Users\isaiah\AppData\Local\Temp\3faig5ns.dll
C:\Users\isaiah\AppData\Local\Temp\4c2459bebc146bfd821d90e28a2411ab.dll
C:\Users\isaiah\AppData\Local\Temp\6_Offer_12.exe
C:\Users\isaiah\AppData\Local\Temp\81c992b.exe
C:\Users\isaiah\AppData\Local\Temp\83929-92631-microsoft-office-2010.exe
C:\Users\isaiah\AppData\Local\Temp\a15154fd9009bc6f9bea0d0659312534.dll
C:\Users\isaiah\AppData\Local\Temp\bitool.dll
C:\Users\isaiah\AppData\Local\Temp\bpygdfsv.dll
C:\Users\isaiah\AppData\Local\Temp\CheatEngine62Clean.exe
C:\Users\isaiah\AppData\Local\Temp\conduitinstaller.exe
C:\Users\isaiah\AppData\Local\Temp\couponamazing.exe
C:\Users\isaiah\AppData\Local\Temp\cvtres.exe
C:\Users\isaiah\AppData\Local\Temp\DM1394570410.exe
C:\Users\isaiah\AppData\Local\Temp\fbyho1hu.dll
C:\Users\isaiah\AppData\Local\Temp\i4jdel0.exe
C:\Users\isaiah\AppData\Local\Temp\ICReinstall_donkey-kong.exe
C:\Users\isaiah\AppData\Local\Temp\IminentSetup.exe
C:\Users\isaiah\AppData\Local\Temp\instloffer.exe
C:\Users\isaiah\AppData\Local\Temp\InternetTurboSetup__1814_i1675065_il1537.exe
C:\Users\isaiah\AppData\Local\Temp\lnd15xiv.dll
C:\Users\isaiah\AppData\Local\Temp\nsb4CAB.tmp.exe
C:\Users\isaiah\AppData\Local\Temp\oi_{74E8797E-56B6-42A9-8C89-469757A0DC67}.exe
C:\Users\isaiah\AppData\Local\Temp\PCFixSpeedSetup.exe
C:\Users\isaiah\AppData\Local\Temp\photostage_1.0.0.50_1.5.0.130_update_all.exe
C:\Users\isaiah\AppData\Local\Temp\safeguard.exe
C:\Users\isaiah\AppData\Local\Temp\somoto_HD CODEC_1.0.exe
C:\Users\isaiah\AppData\Local\Temp\SpOrder.dll
C:\Users\isaiah\AppData\Local\Temp\supoptsetup.exe
C:\Users\isaiah\AppData\Local\Temp\tbcpa0.dll
C:\Users\isaiah\AppData\Local\Temp\UNINSTALL.EXE
C:\Users\isaiah\AppData\Local\Temp\Updater.exe
C:\Users\isaiah\AppData\Local\Temp\utt88CD.tmp.exe
C:\Users\isaiah\AppData\Local\Temp\winziprosetup-WZRO6_20130221.exe

*****************

C:\windows\system32\GroupPolicy\Machine => Moved successfully.
C:\windows\system32\GroupPolicy\GPT.ini => Moved successfully.
C:\windows\SysWOW64\GroupPolicy\GPT.ini => Moved successfully.

"C:\ProgramData\boostwebapp" directory move:

Could not move "C:\ProgramData\boostwebapp" directory. => Scheduled to move on reboot.

imhmypneta => Unable to stop service
imhmypneta => Error deleting Service
Juanenodra => Service stopped successfully.
Juanenodra => Service deleted successfully.
jylvirmid => Unable to stop service
jylvirmid => Error deleting Service
mikikycu => Service stopped successfully.
mikikycu => Service deleted successfully.
C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031 => Moved successfully.
QumbaFyvu => Unable to stop service
QumbaFyvu => Error deleting Service
wyzicyjy => Service stopped successfully.
wyzicyjy => Service deleted successfully.
tammgF119 => Unable to stop service
tammgF119 => Error deleting Service
Could not move "C:\windows\system32\Drivers\tammgF119.sys" => Scheduled to move on reboot.
tammgR119 => Unable to stop service
tammgR119 => Error deleting Service
Could not move "C:\windows\system32\Drivers\tammgR119.sys" => Scheduled to move on reboot.
Could not move "C:\Windows\System32\Drivers\tammgR119.sys" => Scheduled to move on reboot.
Could not move "C:\Windows\System32\Drivers\tammgF119.sys" => Scheduled to move on reboot.
C:\Users\isaiah\AppData\Local\SearchProtect => Moved successfully.
C:\Windows\System32\Tasks\ProPCCleaner_Popup => Moved successfully.
C:\Windows\System32\Tasks\ProPCCleaner_Start => Moved successfully.
C:\Users\isaiah\AppData\Local\4C4C4544-1430690388-5A10-8058-C8C04F4C5031 => Moved successfully.
C:\Users\isaiah\AppData\Local\Pro_PC_Cleaner => Moved successfully.
C:\Windows\SysWOW64\Juanenodra.ini => Moved successfully.
C:\Windows\SysWOW64\JuanenodraOff.ini => Moved successfully.
C:\Windows\System32\JuanenodraOff.ini => Moved successfully.
"C:\Users\isaiah\AppData\Roaming\4C4C4544-1430715185-5A10-8058-C8C04F4C5031" => File/Directory not found.

"C:\ProgramData\boostwebapp" directory move:

Could not move "C:\ProgramData\boostwebapp" directory. => Scheduled to move on reboot.

C:\Windows\System32\Juanenodra64.dll => Moved successfully.
C:\Windows\SysWOW64\Juanenodra.dll => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\2100.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\226380_199177.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\3faig5ns.dll => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\4c2459bebc146bfd821d90e28a2411ab.dll => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\6_Offer_12.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\81c992b.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\83929-92631-microsoft-office-2010.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\a15154fd9009bc6f9bea0d0659312534.dll => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\bitool.dll => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\bpygdfsv.dll => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\CheatEngine62Clean.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\conduitinstaller.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\couponamazing.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\cvtres.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\DM1394570410.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\fbyho1hu.dll => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\i4jdel0.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\ICReinstall_donkey-kong.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\IminentSetup.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\instloffer.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\InternetTurboSetup__1814_i1675065_il1537.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\lnd15xiv.dll => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\nsb4CAB.tmp.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\oi_{74E8797E-56B6-42A9-8C89-469757A0DC67}.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\PCFixSpeedSetup.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\photostage_1.0.0.50_1.5.0.130_update_all.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\safeguard.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\somoto_HD CODEC_1.0.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\SpOrder.dll => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\supoptsetup.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\tbcpa0.dll => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\UNINSTALL.EXE => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\Updater.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\utt88CD.tmp.exe => Moved successfully.
C:\Users\isaiah\AppData\Local\Temp\winziprosetup-WZRO6_20130221.exe => Moved successfully.

=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-05-12 18:35:00)<=

C:\ProgramData\boostwebapp => Is moved successfully.
C:\windows\system32\Drivers\tammgF119.sys => Is moved successfully.
C:\windows\system32\Drivers\tammgR119.sys => Is moved successfully.
C:\Windows\System32\Drivers\tammgR119.sys => Is moved successfully.
C:\Windows\System32\Drivers\tammgF119.sys => Is moved successfully.
C:\ProgramData\boostwebapp => Is moved successfully.

==== End of Fixlog 18:35:05 ====


  • 0

#13
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts
Hi :)

I am very glad to hear that but - as told prior - this is not the end! We still need to double check some things.

Though there are a few questions I was wondering throughout... :pepsi:

Sure, let's try to address them :)

I heard its a new type of virus, is there any more information on this new virus? Any name in particular? I just called it the boostwebapp folder problem.


It's not a virus, it's an adware with what we technically call a rootkit driver to protect some things from being deleted. It uses low level techniques to defend itself.

Is there any other thread that explains in detail on the process you just gave me? Like how to check logs and edit them and fix them in a txt. file?


There is FRST tutorial publicly available how to construct the scripts, but having only this tutorial without the other knowledge (how the system is structured itself) it's not wise to try to do that on your own. You need to know more than how to prepare FRST script. FRST Tutorial - How to use Farbar Recovery Scan Tool.
Moreover, trying to apply procedures from FRST tutorial without knowing what is presented in the logfiles (and how those things relate to each other) may be dangerous.

I consider myself having a healthy knowledge of computers, but I want to learn about these and how to fix it. vvv This question explains it...
Is there any way I can contribute to the forum? I am new and I want to expand and learn on how to do these things to help others, where do I start?


We have a training program available. It is meant to teach people how to deal with malware - it's not only about the FRST and other tools we are using. It gives you much more. If you really want to try, take a look here: Would you like to learn to fight malware?


Now let's go back to our ongoing topic. I need a fresh set of logfiles.



FRST.gif Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool.
  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    > XP users click run after receipt of Windows Security Warning - Open File.
    > 8 users will be prompted about Windows SmartScreen protection - click More information and Run.
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please include their content in your next reply.
  • 0

#14
crazyfrank39

crazyfrank39

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-05-2015
Ran by isaiah (administrator) on ISAIAH-PC on 13-05-2015 08:46:23
Running from C:\Users\isaiah\Desktop
Loaded Profiles: isaiah (Available profiles: isaiah)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ArcSoft, Inc.) C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Brand Affinity Technologies) C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Updater\FantapperUpdater.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Ulead Systems, Inc.) C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(Intel® Corporation) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Red Bend Ltd.) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Akamai Technologies, Inc.) C:\Users\isaiah\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\isaiah\AppData\Local\Akamai\netsession_win.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
() C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
() C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.2.1.1\Lightshot.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-25] (IDT, Inc.)
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [609144 2011-04-12] (Alps Electric Co., Ltd.)
HKLM\...\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1933584 2010-12-17] (Intel® Corporation)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [DellStage] => C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe [2195824 2012-02-01] ()
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-05] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [RoxWatchTray] => c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\...\Run: [Desktop Disc Tool] => c:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe [514544 2010-11-17] ()
HKLM-x32\...\Run: [Dell Registration] => C:\Program Files (x86)\System Registration\prodreg.exe [3926528 2010-08-23] (Dell, Inc.)
HKLM-x32\...\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation)
HKLM-x32\...\Run: [UVS10 Preload] => C:\Program Files (x86)\Ulead Systems\Ulead VideoStudio SE DVD\uvPL.exe [36864 2006-08-09] (Ulead Systems, Inc.)
HKLM-x32\...\Run: [AccuWeatherWidget] => C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe [968048 2012-02-01] ()
HKLM-x32\...\Run: [Aeria Ignite] => C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-06] (Aeria Games & Entertainment)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226560 2014-11-18] ()
HKLM-x32\...\Run: [Andy] => C:\Program Files\Andy\HandyAndy.exe [896904 2014-10-22] ()
HKLM-x32\...\Run: [AVP] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2015-05-10] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [17418928 2012-07-13] (Skype Technologies S.A.)
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3492504 2012-12-24] (Electronic Arts)
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2889408 2015-04-13] (Valve Corporation)
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3674320 2013-01-08] (DT Soft Ltd)
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Run: [Akamai NetSession Interface] => C:\Users\isaiah\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-30] (Akamai Technologies, Inc.)
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Run: [uTorrent] => C:\Users\isaiah\AppData\Roaming\uTorrent\uTorrent.exe [1694560 2015-05-12] (BitTorrent Inc.)
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\MountPoints2: F - F:\INSTALL.EXE
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\MountPoints2: {3a94db90-8157-11e2-b692-ac7289429fb8} - E:\INSTALL.EXE
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Savant Web Server.lnk [2015-04-20]
ShortcutTarget: Savant Web Server.lnk -> C:\Savant\Savant.exe (Developed by Michael Lamont)
Startup: C:\Users\isaiah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk [2014-02-22]
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://google.com/
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.funmood...tC&cr=304164244
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.funmood...tC&cr=304164244
SearchScopes: HKLM -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL = http://www.bing.com/...rc=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
SearchScopes: HKLM-x32 -> Backup.Old.DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
SearchScopes: HKLM-x32 -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL = http://www.bing.com/...rc=IE-SearchBox
SearchScopes: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000 -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL =
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-03-10] (Microsoft Corporation)
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2015-05-10] (Kaspersky Lab ZAO)
BHO: ExstrraSavoinigS -> {59060e68-247a-431b-a61b-78837e4e796c} -> C:\Program Files (x86)\ExstrraSavoinigS\FH2hvZY9buOuAQ.x64.dll No File
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2015-05-10] (Kaspersky Lab ZAO)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll [2015-05-10] (Kaspersky Lab ZAO)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-03-10] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-03-10] (Microsoft Corporation)
BHO: NeWuSAveer -> {de3fbf61-62a0-4957-9460-bd3f936940ab} -> C:\Program Files (x86)\NeWuSAveer\LlL8WKoPVDgDEV.x64.dll No File
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll [2015-05-10] (Kaspersky Lab ZAO)
BHO: ShopDroP -> {ef35e7f1-d0a0-4199-95c0-269459afa4a7} -> C:\Program Files (x86)\ShopDroP\fnlIDiD1Lp2qbr.x64.dll No File
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2015-05-10] (Kaspersky Lab ZAO)
BHO-x32: ExstrraSavoinigS -> {59060e68-247a-431b-a61b-78837e4e796c} -> C:\Program Files (x86)\ExstrraSavoinigS\FH2hvZY9buOuAQ.dll No File
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2015-05-10] (Kaspersky Lab ZAO)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll [2015-05-10] (Kaspersky Lab ZAO)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-03-10] (Microsoft Corporation)
BHO-x32: NeWuSAveer -> {de3fbf61-62a0-4957-9460-bd3f936940ab} -> C:\Program Files (x86)\NeWuSAveer\LlL8WKoPVDgDEV.dll No File
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll [2015-05-10] (Kaspersky Lab ZAO)
BHO-x32: ShopDroP -> {ef35e7f1-d0a0-4199-95c0-269459afa4a7} -> C:\Program Files (x86)\ShopDroP\fnlIDiD1Lp2qbr.dll No File
Toolbar: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000 -> No Name - {687578B9-7132-4A7A-80E4-30EE31099E03} -  No File
Toolbar: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000 -> No Name - {9CF43840-9957-4411-9CCB-D996CD24A45A} -  No File
DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2011-11-03] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
Handler: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2013-12-15] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-12-15] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2013-04-08] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2013-12-30] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2013-12-30] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll [2010-03-31] ( Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpWinExt,version=5.0 -> C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll [2010-08-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-10-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin-x32: @vizzed.com/VizzedRGR -> C:\Program Files (x86)\Vizzed\Vizzed Retro Game Room\NpVizzedRgr.dll [2013-01-11] (Vizzed.com)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4152253128-2157246082-1293380562-1000: @nsroblox.roblox.com/launcher -> C:\Users\isaiah\AppData\Local\Roblox\Versions\version-221a4807685c44e7\\NPRobloxProxy.dll [2012-05-24] ( Roblox Corporation)
FF Plugin HKU\S-1-5-21-4152253128-2157246082-1293380562-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\isaiah\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-03-24] (Unity Technologies ApS)
FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\Web Assistant\Firefox
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox
FF Extension: Bing Bar - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2011-08-23]
FF HKLM-x32\...\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension
FF Extension: Search Helper Extension - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension [2011-08-23]
FF HKLM-x32\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension
FF Extension: Default Manager - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2011-08-23]
FF HKLM-x32\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\Web Assistant\Firefox
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\[email protected]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\BetterSurf\ff
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Better-Surf\ff
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha646\ff
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2015-05-09]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2015-05-09]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2015-05-09]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2015-05-09]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2015-05-09]
FF HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Firefox\Extensions: [[email protected]] - C:\Users\isaiah\AppData\Roaming\Mozilla\Firefox\Profiles\profile\extensions\[email protected]
FF Extension: SpecialSavings - C:\Users\isaiah\AppData\Roaming\Mozilla\Firefox\Profiles\profile\extensions\[email protected] [2012-09-01]
FF Extension: No Name - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha646\ff [Not Found]

Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR StartupUrls: Default -> "https://www.google.com/"
CHR Profile: C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-05-04]
CHR Extension: (Google Docs) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-04]
CHR Extension: (Google Drive) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-04]
CHR Extension: (YouTube) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-04]
CHR Extension: (Google Search) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-04]
CHR Extension: (Google Sheets) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-05-04]
CHR Extension: (Clear Cache Shortcut) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnajhcakejgchhbjlchkfmdidgjefleg [2015-05-07]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-04]
CHR Extension: (Google Wallet) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-05-04]
CHR Extension: (Gmail) - C:\Users\isaiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-04]
CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx [Not Found]
CHR HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pacgpkgadgmibnhpdidcnfafllnmeomc] - C:\Users\isaiah\AppData\Local\CRE\pacgpkgadgmibnhpdidcnfafllnmeomc.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [lmgdincpppijbgecdpafkaonihahdaof] - C:\ProgramData\wxDfast\lmgdincpppijbgecdpafkaonihahdaof.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [lpoimibckejjdjcfbdnajaicnklhfplh] - https://chrome.googl...dnajaicnklhfplh
CHR HKLM-x32\...\Chrome\Extension: [ohgcjecomkebbohfjgmncelbhogbbokf] - C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Player\\Fantapper.crx [2012-05-12]
CHR HKLM-x32\...\Chrome\Extension: [pacgpkgadgmibnhpdidcnfafllnmeomc] - C:\Users\isaiah\AppData\Local\CRE\pacgpkgadgmibnhpdidcnfafllnmeomc.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx [2012-10-25]
CHR HKLM-x32\...\Chrome\Extension: [poheodfamflhhhdcmjfeggbgigeefaco] - C:\Program Files (x86)\Better-Surf\ch\Chrome.crx [Not Found]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ADExchange; C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [44736 2013-10-24] (ArcSoft, Inc.)
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-02-22] (Adobe Systems) [File not signed]
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2015-05-10] (Kaspersky Lab ZAO)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [967040 2015-04-02] ()
R2 Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [897088 2010-11-03] (Intel Corporation) [File not signed]
R3 Bluetooth Media Service; C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [1298496 2010-11-03] (Intel Corporation) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2719928 2015-04-22] (Microsoft Corporation)
R2 DiagTrack; C:\Windows\system32\diagtrack.dll [1254400 2015-04-27] (Microsoft Corporation)
R2 DMAgent; C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [498688 2011-06-14] (Red Bend Ltd.) [File not signed]
R2 FTSvc; C:\Program Files (x86)\Brand Affinity Technologies\Fantapper Updater\FantapperUpdater.exe [16896 2013-01-23] (Brand Affinity Technologies) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [398184 2012-12-14] (Malwarebytes Corporation) [File not signed]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [682344 2012-12-14] (Malwarebytes Corporation) [File not signed]
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-12-17] ()
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [999152 2015-05-04] (Overwolf LTD)
R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [75064 2014-11-20] ()
S3 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-13] (Microsoft Corporation)
R2 UleadBurningHelper; C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-09-28] (Ulead Systems, Inc.) [File not signed]
R2 WiMAXAppSrv; C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [986112 2011-06-14] (Intel® Corporation) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
S2 DellDigitalDelivery; "C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe" [X]
S2 imhmypneta; "C:\ProgramData\boostwebapp\1.1.0.31\gefwucu.exe" -cms [X]
S2 jylvirmid; "C:\ProgramData\boostwebapp\1.1.0.31\gefaucu.exe" /ts2=1 [X]
S2 QumbaFyvu; "C:\ProgramData\boostwebapp\1.1.0.31\XebbaEwyn.exe" -cmd [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-02-27] (DT Soft Ltd)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2015-05-12] (Kaspersky Lab ZAO)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [91008 2015-05-12] (Kaspersky Lab ZAO) [File not signed]
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [628320 2015-05-12] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2015-05-12] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2015-05-12] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2015-05-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54368 2015-05-12] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [177864 2015-05-12] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [24176 2012-12-14] (Malwarebytes Corporation) [File not signed]
S3 pfc; C:\Windows\SysWOW64\drivers\pfc.sys [10368 2003-09-19] (Padus, Inc.) [File not signed]
S3 PSMNBUS; C:\Windows\System32\DRIVERS\PSMNBUS.sys [107272 2013-11-21] (DEVGURU Co., LTD.)
S3 PSMNMDM; C:\Windows\System32\DRIVERS\PSMNMDM.sys [187144 2013-11-21] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 PSMNVSP; C:\Windows\System32\DRIVERS\PSMNVSP.sys [187144 2013-11-21] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 StkCMini; C:\Windows\System32\Drivers\StkCMini.sys [1917576 2010-06-07] (Syntek)
S1 tammgF119; \??\C:\windows\system32\Drivers\tammgF119.sys [X]
S1 tammgR119; \??\C:\windows\system32\Drivers\tammgR119.sys [X]
S3 VBoxDrv; \??\c:\Program Files\Oracle\VirtualBox\VBoxDrv.sys [X]
S3 X6va017; \??\C:\windows\SysWOW64\Drivers\X6va017 [X]
S3 xhunter1; \??\C:\windows\xhunter1.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)

==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-13 08:36 - 2015-05-13 08:36 - 00002346 _____ () C:\Users\isaiah\Desktop\Safe Money.lnk
2015-05-13 00:01 - 2015-05-01 06:17 - 00124112 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 00:01 - 2015-05-01 06:16 - 00102608 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-12 20:51 - 2015-05-04 18:29 - 00342016 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2015-05-12 20:51 - 2015-05-04 18:12 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2015-05-12 20:51 - 2015-04-17 20:10 - 00460800 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2015-05-12 20:51 - 2015-04-17 19:56 - 00342016 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2015-05-12 20:51 - 2015-03-03 21:41 - 00342016 _____ (Microsoft Corporation) C:\windows\system32\apphelp.dll
2015-05-12 20:51 - 2015-03-03 21:41 - 00072192 _____ (Microsoft Corporation) C:\windows\system32\aelupsvc.dll
2015-05-12 20:51 - 2015-03-03 21:41 - 00023552 _____ (Microsoft Corporation) C:\windows\system32\sdbinst.exe
2015-05-12 20:51 - 2015-03-03 21:41 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\shimeng.dll
2015-05-12 20:51 - 2015-03-03 21:11 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\shimeng.dll
2015-05-12 20:51 - 2015-03-03 21:10 - 00295936 _____ (Microsoft Corporation) C:\windows\SysWOW64\apphelp.dll
2015-05-12 20:51 - 2015-03-03 21:10 - 00020992 _____ (Microsoft Corporation) C:\windows\SysWOW64\sdbinst.exe
2015-05-12 20:50 - 2015-04-27 12:28 - 05569984 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-05-12 20:50 - 2015-04-27 12:28 - 00155584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-05-12 20:50 - 2015-04-27 12:28 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2015-05-12 20:50 - 2015-04-27 12:26 - 01728960 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 01461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 01254400 _____ (Microsoft Corporation) C:\windows\system32\diagtrack.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 01162752 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00879104 _____ (Microsoft Corporation) C:\windows\system32\tdh.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00879104 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00113664 _____ (Microsoft Corporation) C:\windows\system32\sechost.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2015-05-12 20:50 - 2015-04-27 12:23 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2015-05-12 20:50 - 2015-04-27 12:22 - 00404992 _____ (Microsoft Corporation) C:\windows\system32\tracerpt.exe
2015-05-12 20:50 - 2015-04-27 12:22 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2015-05-12 20:50 - 2015-04-27 12:22 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2015-05-12 20:50 - 2015-04-27 12:22 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2015-05-12 20:50 - 2015-04-27 12:22 - 00104448 _____ (Microsoft Corporation) C:\windows\system32\logman.exe
2015-05-12 20:50 - 2015-04-27 12:22 - 00047104 _____ (Microsoft Corporation) C:\windows\system32\typeperf.exe
2015-05-12 20:50 - 2015-04-27 12:22 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\relog.exe
2015-05-12 20:50 - 2015-04-27 12:22 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2015-05-12 20:50 - 2015-04-27 12:22 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\diskperf.exe
2015-05-12 20:50 - 2015-04-27 12:21 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2015-05-12 20:50 - 2015-04-27 12:16 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:16 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 12:11 - 03989440 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2015-05-12 20:50 - 2015-04-27 12:11 - 03934144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2015-05-12 20:50 - 2015-04-27 12:08 - 01310744 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2015-05-12 20:50 - 2015-04-27 12:05 - 00635392 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdh.dll
2015-05-12 20:50 - 2015-04-27 12:05 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-05-12 20:50 - 2015-04-27 12:05 - 00221184 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2015-05-12 20:50 - 2015-04-27 12:05 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2015-05-12 20:50 - 2015-04-27 12:05 - 00092160 _____ (Microsoft Corporation) C:\windows\SysWOW64\sechost.dll
2015-05-12 20:50 - 2015-04-27 12:05 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2015-05-12 20:50 - 2015-04-27 12:05 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2015-05-12 20:50 - 2015-04-27 12:05 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2015-05-12 20:50 - 2015-04-27 12:05 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2015-05-12 20:50 - 2015-04-27 12:04 - 00641536 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2015-05-12 20:50 - 2015-04-27 12:04 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-05-12 20:50 - 2015-04-27 12:04 - 00364544 _____ (Microsoft Corporation) C:\windows\SysWOW64\tracerpt.exe
2015-05-12 20:50 - 2015-04-27 12:04 - 00082944 _____ (Microsoft Corporation) C:\windows\SysWOW64\logman.exe
2015-05-12 20:50 - 2015-04-27 12:04 - 00040448 _____ (Microsoft Corporation) C:\windows\SysWOW64\typeperf.exe
2015-05-12 20:50 - 2015-04-27 12:04 - 00037888 _____ (Microsoft Corporation) C:\windows\SysWOW64\relog.exe
2015-05-12 20:50 - 2015-04-27 12:04 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2015-05-12 20:50 - 2015-04-27 12:04 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2015-05-12 20:50 - 2015-04-27 12:03 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2015-05-12 20:50 - 2015-04-27 12:03 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2015-05-12 20:50 - 2015-04-27 12:03 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2015-05-12 20:50 - 2015-04-27 12:03 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2015-05-12 20:50 - 2015-04-27 12:03 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\diskperf.exe
2015-05-12 20:50 - 2015-04-27 12:03 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2015-05-12 20:50 - 2015-04-27 11:59 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 11:59 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 11:59 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 11:59 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 11:59 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 11:59 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 11:59 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 11:59 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 11:59 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 11:59 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 11:59 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 11:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 11:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 11:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 11:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 11:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 11:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-05-12 20:50 - 2015-04-27 11:06 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\UtcResources.dll
2015-05-12 20:50 - 2015-04-21 19:28 - 00389840 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2015-05-12 20:50 - 2015-04-21 18:48 - 00342736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-05-12 20:50 - 2015-04-21 10:14 - 24971776 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-05-12 20:50 - 2015-04-21 10:08 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2015-05-12 20:50 - 2015-04-21 10:07 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2015-05-12 20:50 - 2015-04-21 09:51 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2015-05-12 20:50 - 2015-04-21 09:50 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-05-12 20:50 - 2015-04-21 09:50 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-05-12 20:50 - 2015-04-21 09:50 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2015-05-12 20:50 - 2015-04-21 09:49 - 02885120 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-05-12 20:50 - 2015-04-21 09:48 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-05-12 20:50 - 2015-04-21 09:41 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2015-05-12 20:50 - 2015-04-21 09:40 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2015-05-12 20:50 - 2015-04-21 09:37 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-05-12 20:50 - 2015-04-21 09:35 - 00816640 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-05-12 20:50 - 2015-04-21 09:35 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2015-05-12 20:50 - 2015-04-21 09:35 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2015-05-12 20:50 - 2015-04-21 09:34 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2015-05-12 20:50 - 2015-04-21 09:31 - 06025728 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-05-12 20:50 - 2015-04-21 09:26 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2015-05-12 20:50 - 2015-04-21 09:25 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2015-05-12 20:50 - 2015-04-21 09:24 - 19691008 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-05-12 20:50 - 2015-04-21 09:22 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2015-05-12 20:50 - 2015-04-21 09:14 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2015-05-12 20:50 - 2015-04-21 09:11 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-05-12 20:50 - 2015-04-21 09:11 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2015-05-12 20:50 - 2015-04-21 09:10 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2015-05-12 20:50 - 2015-04-21 09:09 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-05-12 20:50 - 2015-04-21 09:09 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-05-12 20:50 - 2015-04-21 09:08 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-05-12 20:50 - 2015-04-21 09:08 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-05-12 20:50 - 2015-04-21 09:05 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-05-12 20:50 - 2015-04-21 09:04 - 02278400 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-05-12 20:50 - 2015-04-21 09:03 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2015-05-12 20:50 - 2015-04-21 09:02 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2015-05-12 20:50 - 2015-04-21 09:00 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-05-12 20:50 - 2015-04-21 08:58 - 00664576 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-05-12 20:50 - 2015-04-21 08:58 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2015-05-12 20:50 - 2015-04-21 08:57 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2015-05-12 20:50 - 2015-04-21 08:49 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-05-12 20:50 - 2015-04-21 08:49 - 00720384 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2015-05-12 20:50 - 2015-04-21 08:48 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2015-05-12 20:50 - 2015-04-21 08:47 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2015-05-12 20:50 - 2015-04-21 08:46 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-05-12 20:50 - 2015-04-21 08:43 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-05-12 20:50 - 2015-04-21 08:40 - 14401536 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-05-12 20:50 - 2015-04-21 08:39 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-05-12 20:50 - 2015-04-21 08:38 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-05-12 20:50 - 2015-04-21 08:36 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-05-12 20:50 - 2015-04-21 08:31 - 04305920 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-05-12 20:50 - 2015-04-21 08:27 - 02352128 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-05-12 20:50 - 2015-04-21 08:26 - 00688640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-05-12 20:50 - 2015-04-21 08:25 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-05-12 20:50 - 2015-04-21 08:24 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2015-05-12 20:50 - 2015-04-21 08:17 - 12828672 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-05-12 20:50 - 2015-04-21 08:15 - 01547264 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-05-12 20:50 - 2015-04-21 08:03 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-05-12 20:50 - 2015-04-21 08:02 - 01882112 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-05-12 20:50 - 2015-04-21 07:58 - 01310208 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-05-12 20:50 - 2015-04-21 07:56 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-05-12 20:50 - 2015-04-12 20:28 - 00328704 _____ (Microsoft Corporation) C:\windows\system32\services.exe
2015-05-12 20:49 - 2015-04-27 12:18 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2015-05-12 20:49 - 2015-04-27 12:18 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2015-05-12 20:49 - 2015-04-27 12:16 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2015-05-12 20:49 - 2015-04-27 12:16 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2015-05-12 20:49 - 2015-04-27 12:16 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-05-12 20:49 - 2015-04-27 12:16 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-12 20:49 - 2015-04-27 12:16 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-05-12 20:49 - 2015-04-27 12:16 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-05-12 20:49 - 2015-04-27 12:16 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-05-12 20:49 - 2015-04-27 12:16 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-05-12 20:49 - 2015-04-27 12:01 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2015-05-12 20:49 - 2015-04-27 12:01 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2015-05-12 20:49 - 2015-04-27 11:59 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2015-05-12 20:49 - 2015-04-27 11:59 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2015-05-12 20:49 - 2015-04-27 11:59 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-05-12 20:49 - 2015-04-27 11:59 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-05-12 20:49 - 2015-04-27 11:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-05-12 20:49 - 2015-04-27 11:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-05-12 20:49 - 2015-04-27 11:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-05-12 20:49 - 2015-04-27 11:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-05-12 20:49 - 2015-04-27 11:59 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-05-12 20:49 - 2015-04-27 10:57 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2015-05-12 20:49 - 2015-04-27 10:57 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2015-05-12 20:49 - 2015-04-27 10:55 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-05-12 20:49 - 2015-04-27 10:55 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-05-12 20:49 - 2015-04-27 10:55 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-05-12 20:49 - 2015-04-27 10:55 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-05-12 20:49 - 2015-04-19 20:17 - 01647104 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2015-05-12 20:49 - 2015-04-19 20:17 - 01179136 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2015-05-12 20:49 - 2015-04-19 19:56 - 01250816 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll
2015-05-12 20:49 - 2015-04-19 19:11 - 03204608 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-05-12 20:49 - 2015-04-07 20:29 - 00275456 _____ (Microsoft Corporation) C:\windows\system32\InkEd.dll
2015-05-12 20:49 - 2015-04-07 20:29 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\jnwmon.dll
2015-05-12 20:49 - 2015-04-07 20:14 - 00216064 _____ (Microsoft Corporation) C:\windows\SysWOW64\InkEd.dll
2015-05-12 20:49 - 2015-02-18 00:06 - 00123904 _____ (Microsoft Corporation) C:\windows\SysWOW64\poqexec.exe
2015-05-12 20:49 - 2015-02-18 00:04 - 00142336 _____ (Microsoft Corporation) C:\windows\system32\poqexec.exe
2015-05-12 20:49 - 2015-01-28 20:19 - 02543104 _____ (Microsoft Corporation) C:\windows\system32\wpdshext.dll
2015-05-12 20:49 - 2015-01-28 20:02 - 02311168 _____ (Microsoft Corporation) C:\windows\SysWOW64\wpdshext.dll
2015-05-12 19:57 - 2015-05-12 19:57 - 00008236 _____ () C:\WirelessDiagLog.csv
2015-05-09 14:34 - 2015-05-09 14:34 - 00000000 ____D () C:\Users\isaiah\Desktop\FRST-OlderVersion
2015-05-09 14:29 - 2015-05-09 14:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2013
2015-05-09 14:29 - 2015-05-09 14:28 - 00001148 _____ () C:\Users\Public\Desktop\Kaspersky Internet Security 2013.lnk
2015-05-09 14:28 - 2012-07-11 17:09 - 00064856 _____ (Kaspersky Lab) C:\windows\system32\klfphc.dll
2015-05-09 14:27 - 2015-05-12 20:57 - 00628320 _____ (Kaspersky Lab ZAO) C:\windows\system32\Drivers\klif.sys
2015-05-09 14:27 - 2015-05-12 20:57 - 00091008 _____ (Kaspersky Lab ZAO) C:\windows\system32\Drivers\klflt.sys
2015-05-09 14:27 - 2015-05-09 14:27 - 00000000 ____D () C:\windows\ELAMBKUP
2015-05-09 14:27 - 2015-05-09 14:27 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab
2015-05-09 14:22 - 2015-05-09 14:22 - 00000000 ____D () C:\Program Files\Trend Micro
2015-05-08 21:58 - 2015-05-08 21:58 - 00725281 _____ (Malwarebytes Corp.) C:\Users\isaiah\Downloads\mbar-1.09.1.1004 (1).exe.sqk8lhs.partial
2015-05-08 20:44 - 2015-05-08 20:44 - 00000000 _____ () C:\windows\DCEBOOT.LOG
2015-05-08 19:56 - 2015-05-08 19:56 - 00000010 _____ () C:\Users\isaiah\AppData\Local\sponge.last.runtime.cache
2015-05-08 19:15 - 2015-05-09 14:17 - 00236080 _____ (Trend Micro Inc.) C:\windows\RegBootClean64.exe
2015-05-08 19:15 - 2015-05-08 19:16 - 00025136 _____ (Trend Micro Inc.) C:\windows\DCEBoot64.exe
2015-05-08 18:43 - 2015-05-09 14:21 - 00000000 ____D () C:\ProgramData\Trend Micro
2015-05-08 18:39 - 2015-05-08 18:39 - 00000036 _____ () C:\Users\isaiah\AppData\Local\housecall.guid.cache
2015-05-08 18:28 - 2015-05-08 18:28 - 06630552 _____ (Trend Micro Inc.) C:\Users\isaiah\Downloads\TrendMicro_TAV_8.0_US-en_Downloader.exe
2015-05-07 19:43 - 2015-05-09 13:45 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-05-07 19:37 - 2015-05-08 20:41 - 00000000 ____D () C:\Users\isaiah\Desktop\mbar
2015-05-07 19:37 - 2015-05-08 19:48 - 00107736 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-05-07 19:31 - 2015-05-07 19:37 - 16502728 _____ (Malwarebytes Corp.) C:\Users\isaiah\Downloads\mbar-1.09.1.1004.exe
2015-05-06 08:14 - 2015-05-09 14:36 - 00068112 _____ () C:\Users\isaiah\Desktop\Addition.txt
2015-05-06 08:13 - 2015-05-13 08:46 - 00032448 _____ () C:\Users\isaiah\Desktop\FRST.txt
2015-05-06 08:12 - 2015-05-13 08:46 - 00000000 ____D () C:\FRST
2015-05-06 08:11 - 2015-05-09 14:34 - 02102784 _____ (Farbar) C:\Users\isaiah\Desktop\FRST64.exe
2015-05-05 16:37 - 2015-05-05 16:37 - 02960802 _____ () C:\windows\shost.bin
2015-05-04 21:39 - 2015-05-04 21:39 - 00797232 _____ (Generic ) C:\Users\isaiah\Downloads\java_runtime_enviroment_setup.exe
2015-05-04 21:27 - 2015-05-04 21:27 - 00002261 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-05-04 21:27 - 2015-05-04 21:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-05-03 22:10 - 2015-05-03 22:10 - 00000000 ____D () C:\Users\isaiah\AppData\Roaming\dlg
2015-05-03 22:08 - 2015-05-03 22:08 - 00000000 _____ () C:\END
2015-05-03 22:07 - 2015-05-03 22:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD CODEC
2015-04-29 20:04 - 2015-04-29 20:41 - 00000000 ____D () C:\Users\isaiah\Desktop\Music Sheets
2015-04-29 20:02 - 2015-04-29 20:02 - 00014281 _____ () C:\Users\isaiah\Downloads\Kirby Super Star - The Halberd.mid
2015-04-29 20:02 - 2015-04-29 20:02 - 00012331 _____ () C:\Users\isaiah\Downloads\Kirby Super Star - Cavios.mid
2015-04-22 20:06 - 2015-04-22 20:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot
2015-04-20 20:06 - 2015-04-20 20:06 - 00000000 ____D () C:\Savant
2015-04-20 20:06 - 2015-04-20 20:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Savant Web Server
2015-04-20 20:01 - 2015-04-20 20:03 - 01269567 _____ (Michael Lamont ) C:\Users\isaiah\Downloads\Savant31.exe
2015-04-19 20:52 - 2015-04-19 20:54 - 34404626 _____ () C:\Users\isaiah\Downloads\torbrowser-install-4.0.8_en-US.exe
2015-04-15 03:40 - 2015-04-15 03:41 - 01059952 _____ () C:\windows\Minidump\041515-109512-01.dmp
2015-04-14 18:49 - 2015-03-24 20:24 - 03298816 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 02553856 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00696320 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00191488 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00098304 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-04-14 18:49 - 2015-03-24 20:24 - 00035328 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-04-14 18:49 - 2015-03-24 20:23 - 00135168 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-04-14 18:49 - 2015-03-24 20:23 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-04-14 18:49 - 2015-03-24 20:23 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
2015-04-14 18:49 - 2015-03-24 20:00 - 00566784 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-04-14 18:49 - 2015-03-24 20:00 - 00173056 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-04-14 18:49 - 2015-03-24 20:00 - 00092672 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-04-14 18:49 - 2015-03-24 20:00 - 00033792 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-04-14 18:49 - 2015-03-24 20:00 - 00029696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-04-14 18:49 - 2015-03-22 20:25 - 00769536 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-04-14 18:49 - 2015-03-22 20:25 - 00726528 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-04-14 18:49 - 2015-03-22 20:24 - 00957952 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-04-14 18:49 - 2015-03-22 20:24 - 00419840 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-04-14 18:49 - 2015-03-22 20:24 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-04-14 18:49 - 2015-03-22 20:24 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2015-04-14 18:49 - 2015-03-22 20:24 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-04-14 18:49 - 2015-03-22 20:17 - 01111552 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-04-14 18:49 - 2015-03-09 20:25 - 01882624 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2015-04-14 18:49 - 2015-03-09 20:21 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2015-04-14 18:49 - 2015-03-09 20:08 - 01237504 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2015-04-14 18:49 - 2015-03-09 20:05 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2015-04-14 18:49 - 2015-03-04 22:12 - 00404480 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2015-04-14 18:49 - 2015-03-04 21:05 - 00311808 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2015-04-14 18:48 - 2015-02-24 20:18 - 00754688 _____ (Microsoft Corporation) C:\windows\system32\Drivers\http.sys
2015-04-14 18:45 - 2015-03-03 21:55 - 00367552 _____ (Microsoft Corporation) C:\windows\system32\clfs.sys
2015-04-14 18:45 - 2015-03-03 21:41 - 00079360 _____ (Microsoft Corporation) C:\windows\system32\clfsw32.dll
2015-04-14 18:45 - 2015-03-03 21:10 - 00058880 _____ (Microsoft Corporation) C:\windows\SysWOW64\clfsw32.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-13 08:45 - 2009-07-13 21:45 - 00028576 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-13 08:45 - 2009-07-13 21:45 - 00028576 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-13 08:44 - 2011-08-23 01:23 - 01652556 _____ () C:\windows\WindowsUpdate.log
2015-05-13 08:39 - 2009-07-13 22:13 - 00823564 _____ () C:\windows\system32\PerfStringBackup.INI
2015-05-13 08:37 - 2013-02-25 20:47 - 00000000 ____D () C:\Users\isaiah\AppData\Roaming\uTorrent
2015-05-13 08:37 - 2012-12-06 19:32 - 00000000 ____D () C:\Program Files (x86)\Origin
2015-05-13 08:37 - 2011-12-29 18:20 - 00000000 ____D () C:\Users\isaiah\AppData\Roaming\Skype
2015-05-13 08:35 - 2012-12-24 13:12 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2015-05-13 08:35 - 2012-12-22 11:38 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-05-13 08:34 - 2012-09-12 18:15 - 00000894 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore1cd914d439221f3.job
2015-05-13 08:31 - 2012-12-24 11:46 - 00041687 _____ () C:\windows\setupact.log
2015-05-13 08:31 - 2009-07-13 22:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-05-13 08:31 - 2009-07-13 21:45 - 00428016 _____ () C:\windows\system32\FNTCACHE.DAT
2015-05-13 08:28 - 2011-08-23 04:15 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-13 08:28 - 2009-07-13 20:20 - 00000000 ____D () C:\windows\system32\AdvancedInstallers
2015-05-13 08:27 - 2012-08-20 18:02 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-05-13 00:11 - 2014-01-25 14:48 - 00000390 _____ () C:\windows\Tasks\update-S-1-5-21-4152253128-2157246082-1293380562-1000.job
2015-05-13 00:10 - 2013-08-08 03:01 - 00000000 ____D () C:\windows\system32\MRT
2015-05-13 00:04 - 2012-01-23 20:22 - 140425016 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-05-12 23:18 - 2012-09-12 18:15 - 00000898 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA1cd914d43dfa6d6.job
2015-05-12 22:31 - 2015-01-06 16:02 - 00000000 ____D () C:\Program Files (x86)\Overwolf
2015-05-12 21:08 - 2014-01-25 14:48 - 00000390 _____ () C:\windows\Tasks\update-sys.job
2015-05-12 20:57 - 2012-10-25 17:23 - 00029280 _____ (Kaspersky Lab ZAO) C:\windows\system32\Drivers\klmouflt.sys
2015-05-12 20:57 - 2012-10-25 17:23 - 00029280 _____ (Kaspersky Lab ZAO) C:\windows\system32\Drivers\klkbdflt.sys
2015-05-12 20:57 - 2012-08-13 16:49 - 00177864 _____ (Kaspersky Lab ZAO) C:\windows\system32\Drivers\kneps.sys
2015-05-12 20:57 - 2012-08-02 15:09 - 00029792 _____ (Kaspersky Lab ZAO) C:\windows\system32\Drivers\klim6.sys
2015-05-12 20:57 - 2012-06-19 17:28 - 00458336 _____ (Kaspersky Lab ZAO) C:\windows\system32\Drivers\kl1.sys
2015-05-12 20:57 - 2012-06-08 11:38 - 00054368 _____ (Kaspersky Lab ZAO) C:\windows\system32\Drivers\kltdi.sys
2015-05-12 20:52 - 2013-04-04 21:42 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-05-12 20:05 - 2009-07-13 20:20 - 00000000 ____D () C:\windows\system32\NDF
2015-05-12 19:42 - 2009-07-13 22:08 - 00032610 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2015-05-12 18:34 - 2014-01-29 17:00 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2015-05-12 18:34 - 2013-08-13 19:27 - 00000008 __RSH () C:\Users\isaiah\ntuser.pol
2015-05-12 18:34 - 2011-12-24 22:41 - 00000000 ____D () C:\Users\isaiah
2015-05-12 18:32 - 2010-11-20 20:47 - 01631366 _____ () C:\windows\PFRO.log
2015-05-12 18:31 - 2009-07-13 20:20 - 00000000 ___HD () C:\windows\system32\GroupPolicy
2015-05-12 18:31 - 2009-07-13 20:20 - 00000000 ____D () C:\windows\SysWOW64\GroupPolicy
2015-05-08 20:44 - 2015-02-08 21:42 - 00000000 ____D () C:\Program Files (x86)\SoftwareHelp
2015-05-07 20:46 - 2012-12-24 10:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
2015-05-07 20:46 - 2012-12-24 10:39 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2015-05-07 19:42 - 2015-02-08 21:41 - 00000000 ____D () C:\ProgramData\5551195122105854317
2015-05-05 16:49 - 2014-10-09 21:15 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2015-05-04 21:27 - 2011-12-31 10:52 - 00000000 ____D () C:\Users\isaiah\AppData\Local\Google
2015-05-04 21:27 - 2011-12-31 10:52 - 00000000 ____D () C:\Program Files (x86)\Google
2015-05-04 18:18 - 2012-04-17 18:25 - 00000506 _____ () C:\windows\Tasks\SystemToolsDailyTest.job
2015-04-28 20:04 - 2015-02-08 21:40 - 00000000 ____D () C:\ProgramData\{8613789a-ab6e-b73f-8613-3789aab6e26a}
2015-04-23 16:51 - 2011-12-24 22:45 - 00000000 ____D () C:\Users\isaiah\AppData\Roaming\Adobe
2015-04-22 20:06 - 2014-01-25 14:48 - 00003266 _____ () C:\windows\System32\Tasks\update-S-1-5-21-4152253128-2157246082-1293380562-1000
2015-04-22 20:06 - 2014-01-25 14:48 - 00000424 _____ () C:\Users\isaiah\AppData\Local\UserProducts.xml
2015-04-19 20:54 - 2013-12-21 22:08 - 00000000 ____D () C:\Users\isaiah\Desktop\Tor Browser
2015-04-16 18:15 - 2012-08-20 18:02 - 00778416 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-04-16 18:15 - 2012-08-20 18:02 - 00142512 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-16 18:15 - 2012-08-20 18:02 - 00003768 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-04-15 05:33 - 2009-07-13 20:20 - 00000000 ____D () C:\windows\rescache
2015-04-15 05:25 - 2009-07-13 20:20 - 00000000 ____D () C:\windows\AppCompat
2015-04-15 03:40 - 2013-03-28 10:11 - 603850817 _____ () C:\windows\MEMORY.DMP
2015-04-15 03:40 - 2013-03-28 10:11 - 00000000 ____D () C:\windows\Minidump
2015-04-15 03:27 - 2014-12-10 22:00 - 00000000 ____D () C:\windows\system32\appraiser
2015-04-15 03:27 - 2014-04-29 22:07 - 00000000 ___SD () C:\windows\system32\CompatTel
2015-04-15 03:27 - 2009-07-13 20:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2015-04-15 03:10 - 2011-08-23 01:36 - 00816178 _____ () C:\windows\SysWOW64\PerfStringBackup.INI

==================== Files in the root of some directories =======

2005-05-30 08:19 - 2012-12-23 03:14 - 0004115 ____H () C:\Users\isaiah\AppData\Roaming\isaiahlog.dat
2011-12-31 19:44 - 2014-11-30 01:31 - 0016896 _____ () C:\Users\isaiah\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-05-08 18:39 - 2015-05-08 18:39 - 0000036 _____ () C:\Users\isaiah\AppData\Local\housecall.guid.cache
2015-01-05 23:36 - 2015-01-10 02:01 - 0007606 _____ () C:\Users\isaiah\AppData\Local\Resmon.ResmonCfg
2015-05-08 19:56 - 2015-05-08 19:56 - 0000010 _____ () C:\Users\isaiah\AppData\Local\sponge.last.runtime.cache
2014-01-25 14:48 - 2014-01-25 14:48 - 0000003 _____ () C:\Users\isaiah\AppData\Local\updater.log
2014-01-25 14:48 - 2015-04-22 20:06 - 0000424 _____ () C:\Users\isaiah\AppData\Local\UserProducts.xml
2012-12-24 13:15 - 2012-12-24 13:15 - 0017408 _____ () C:\Users\isaiah\AppData\Local\WebpageIcons.db

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2015-05-05 17:17

==================== End Of Log ============================

 

 

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-05-2015
Ran by isaiah at 2015-05-13 08:47:10
Running from C:\Users\isaiah\Desktop
Boot Mode: Normal
==========================================================

==================== Accounts: =============================

Administrator (S-1-5-21-4152253128-2157246082-1293380562-500 - Administrator - Disabled)
Guest (S-1-5-21-4152253128-2157246082-1293380562-501 - Limited - Disabled)
isaiah (S-1-5-21-4152253128-2157246082-1293380562-1000 - Administrator - Enabled) => C:\Users\isaiah

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Kaspersky Internet Security (Enabled - Up to date) {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
AS: Kaspersky Internet Security (Enabled - Up to date) {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\uTorrent) (Version: 3.4.3.40298 - BitTorrent Inc.)
AdBlocker Manger (HKLM-x32\...\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version:  - AdBlocker Manger) <==== ATTENTION
Adobe Acrobat 5.0 (HKLM-x32\...\Adobe Acrobat 5.0) (Version: 5.0 - Adobe Systems, Inc.)
Adobe Flash Player 10 Plugin (HKLM-x32\...\{4ED0DB47-769D-4B71-8724-E7A5BFEA1D51}) (Version: 10.3.181.22 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Photoshop CS2 (HKLM-x32\...\Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}) (Version: 9.0 - Adobe Systems, Inc.)
Adobe Reader XI (11.0.11) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.11 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.3.633 - Adobe Systems, Inc.)
Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
Aeria Ignite (HKLM-x32\...\Aeria Ignite 1.13.3296) (Version: 1.13.3296 - Aeria Games & Entertainment)
Aeria Ignite (HKLM-x32\...\Aeria Ignite) (Version: 1.13.3296 - Aeria Games & Entertainment)
Aeria Ignite (x32 Version: 1.13.3296 - Aeria Games & Entertainment) Hidden
Akamai NetSession Interface (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\Akamai) (Version:  - Akamai Technologies, Inc)
Alliance of Valiant Arms (HKLM-x32\...\Alliance of Valiant Arms) (Version:  - )
AMD Catalyst Install Manager (HKLM\...\{7071F235-9C2C-ACDE-36CC-E18034946DD7}) (Version: 8.0.891.0 - Advanced Micro Devices, Inc.)
Andy OS (HKLM-x32\...\Andy OS) (Version: 0.41 - Andy OS, Inc)
Anime Studio Debut 6.1 (HKLM-x32\...\Anime Studio Debut_is1) (Version:  - Smith Micro Software, Inc.)
AnyTrans 3.6.6 (HKLM-x32\...\{E580ED1F-AAF8-4F7E-B174-54BFA2B94E0B}}_is1) (Version: 3.6.6 - iMobie Inc.)
Apple Application Support (HKLM-x32\...\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2F72F540-1F60-4266-9506-952B21D6640D}) (Version: 6.1.0.13 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcSoft MediaConverter 8 (HKLM-x32\...\{2CAD3C16-ACD0-43E5-81DA-7E56C3E5336C}) (Version: 8.0.0.21 - ArcSoft)
ARMA 2 (HKLM-x32\...\Steam App 33900) (Version:  - Bohemia Interactive)
Ask Toolbar Updater (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.2.0.20007 - Ask.com) <==== ATTENTION
AssaultCube v1.1.0.4 (HKLM-x32\...\AssaultCube_v1.1.0.4) (Version: v1.1.0.4 - )
Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team)
AVS Video Converter 8.5 (HKLM-x32\...\AVS4YOU Video Converter 7_is1) (Version: 8.5.1.551 - Online Media Technologies Ltd.)
Battlefield: Bad Company 2 (HKLM-x32\...\Steam App 24960) (Version:  - DICE)
BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version:  - )
BattlEye Uninstall (HKLM-x32\...\BattlEye for A2) (Version:  - )
Bing Bar (HKLM-x32\...\{08234a0d-cf39-4dca-99f0-0c5cb496da81}) (Version: 6.0.2282.0 - Microsoft Corporation)
Bing Bar Platform (x32 Version: 6.0.2282.0 - Microsoft Corporation) Hidden
Bing Rewards Client Installer (x32 Version: 16.0.345.0 - Microsoft Corporation) Hidden
Blender (HKLM\...\Blender) (Version: 2.65a-release - Blender Foundation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
boostwebapp (HKLM-x32\...\{0E376CD8-8982-4BE6-b505-91881F3B3343}) (Version: 1.1.0.31 - boostwebapp) <==== ATTENTION
CamStudio version 2.6b (HKLM-x32\...\{2793F5A3-509A-4CB6-B014-1E0E0794351A}_is1) (Version: 2.6b - Download Freely, LLC)
Canon MP495 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP495_series) (Version:  - )
Cheat Engine 6.2 (HKLM-x32\...\Cheat Engine 6.2_is1) (Version:  - Dark Byte)
Clear Cache Shortcut (HKLM-x32\...\{AF992111-52BE-832B-5882-8477E4A3C99A}) (Version:  - "") <==== ATTENTION
Club Penguin Money Maker (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\a87d8e93174496f4) (Version: 1.2.0.0 - ClubPenguinCP)
Cool AVI To WAV Converter 1.0 (HKLM-x32\...\Cool AVI To WAV Converter_is1) (Version:  - A Software Plus)
Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version:  - Valve)
CreaToon 3.0 (HKLM-x32\...\CreaToon 3.0) (Version:  - )
Cross Fire En (HKLM-x32\...\Cross Fire_is1) (Version:  - Z8Games.com)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.46.1.0328 - DT Soft Ltd)
DayZ (HKLM-x32\...\Steam App 221100) (Version:  - Bohemia Interactive)
DayZ Commander (HKLM-x32\...\{0B74EC0B-2A85-4542-A167-3DE2132E7DAA}) (Version: 0.92.85 - Dotjosh Studios)
DealNoDeal (HKLM-x32\...\{37476589-E48E-439E-A706-56189E2ED4C4}) (Version:  - DealNoDeal) <==== ATTENTION
Dell Digital Delivery (HKLM-x32\...\{31045ECE-019D-4DDF-A5C8-5C51A3FE50EE}) (Version: 1.7.4501.0 - Dell Products, LP)
Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Dell Getting Started Guide (HKLM-x32\...\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell MusicStage (HKLM-x32\...\{91AF2672-F5BC-42CF-8037-A9D2F92BBCC0}) (Version: 1.5.201.0 - Fingertapps)
Dell Perks Webslice IE8 (HKLM-x32\...\{CF67ED0C-F85D-4791-AED3-3FE882EDB45D}) (Version: 8.0 - Nextjump Inc)
Dell PhotoStage (HKLM-x32\...\{E4335E82-17B3-460F-9E70-39D9BC269DB3}) (Version: 1.5.0.65 - ArcSoft)
Dell Product Registration (HKLM-x32\...\{2A0F2CC5-3065-492C-8380-B03AA7106B1A}) (Version: 1.0.3 - Dell Inc.)
Dell Stage (HKLM-x32\...\{FE182796-F6BA-486A-8590-89B7E8D1D60F}) (Version: 1.7.209.0 - Fingertapps)
Dell Support Center (HKLM\...\Dell Support Center) (Version: 3.1.5907.23 - Dell Inc.)
Dell Support Center (Version: 3.1.5907.23 - PC-Doctor, Inc.) Hidden
Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.1209.101.204 - ALPS ELECTRIC CO., LTD.)
Dell VideoStage  (HKLM-x32\...\InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}) (Version: 1.2.0.1712 - CyberLink Corp.)
Dell VideoStage  (x32 Version: 1.2.0.1712 - CyberLink Corp.) Hidden
Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 2.00.44 - Creative Technology Ltd)
Dev-C++ (HKLM-x32\...\Dev-C++) (Version: 5.4.2 - )
DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden
DiscJuggler (HKLM-x32\...\{C3C538E5-524C-4253-AA74-0EEEF34990EA}) (Version: 4.10 - Padus, Inc.)
Doom Builder 2.1 (HKLM-x32\...\Doom Builder 2_is1) (Version:  - CodeImp)
Dystopia (HKLM-x32\...\Steam App 17580) (Version:  - Dystopia Team)
EnjooyCooupOn (HKLM-x32\...\{2DF3E224-05CD-4113-AA7A-86F2F6607B46}) (Version:  - "") <==== ATTENTION
Explorer Suite IV (HKLM\...\Explorer Suite_is1) (Version:  - )
ExstrraSavoinigS (HKLM-x32\...\{C637A71C-A4B2-4B47-1B2A-1042A8D525A3}) (Version:  - "") <==== ATTENTION
Fallout Mod Manager 0.12.6 (HKLM-x32\...\Fallout Mod Manager_is1) (Version:  - Timeslip, Q)
Fallout Mod Manager 0.13.21 (HKLM-x32\...\Generic Mod Manager_is1) (Version:  - Q, Timeslip)
Fantapper Player (HKLM-x32\...\{CDACD4C9-F984-409A-9D26-DF77E003FD89}) (Version: 2.0.3 - Brand Affinity Technologies)
Fantapper Updater (HKLM-x32\...\{57570C54-7615-4925-8219-895F01EBB16B}) (Version: 2.0.2 - Brand Affinity Technologies)
FileViewPro (HKLM\...\FileViewPro_is1) (Version: 4.0 - Solvusoft Corporation)
Finale NotePad 2007 (HKLM-x32\...\Finale NotePad 2007) (Version: 12.0.13 - MakeMusic)
Fraps (HKLM-x32\...\Fraps) (Version:  - )
Free AVI To MP3 Converter (HKLM-x32\...\{2A0E555E-1533-468E-B49E-4A39050FB562}) (Version: 1.0.0 - Convert Audio Free)
FreeOTFE Explorer (HKLM-x32\...\FreeOTFE Explorer) (Version:  - Sarah Dean)
GameMaker-Studio 1.1 (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\GameMaker-Studio11) (Version:  - YoYo Games Ltd.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 42.0.2311.135 - Google Inc.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
GTA San Andreas (HKLM-x32\...\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6324.0 - IDT)
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Display Audio Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3097 - Intel Corporation)
Intel® Driver Update Utility 2.0 (x32 Version: 2.0.0.29 - Intel) Hidden
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation)
Intel® PROSet/Wireless Software for Bluetooth® Technology (HKLM\...\{7CE8BE79-ABC3-4B2C-9543-28ED2B0A9EA8}) (Version: 1.0.0.0454 - Intel Corporation)
Intel® PROSet/Wireless WiFi Software (HKLM\...\{290D4DB2-F1B4-4B8E-918D-D71EF29A001B}) (Version: 14.00.1000 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation)
Intel® Turbo Boost Technology Monitor 2.0 (HKLM\...\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.1.23.0 - Intel)
Intel® WiDi (HKLM-x32\...\{25680C01-6753-4FE9-A891-7857F26457C1}) (Version: 2.1.35.0 - Intel Corporation)
Intel® Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
Intel® Driver Update Utility (HKLM-x32\...\{8409c4f7-2340-4933-a304-5d37db4fb48b}) (Version: 2.0.0.29 - Intel)
Intel® PROSet/Wireless WiMAX Software (HKLM\...\{5C1DA3D9-F590-4317-A4FB-274F658E504B}) (Version: 6.05.0000 - Intel Corporation)
Internet Explorer (x32 Version: 8 - Microsoft Corporation) Hidden
iPhoneBrowser (HKLM-x32\...\{C1FCDCA1-2759-4E5E-84EE-3A665BB2F513}) (Version: 1.9.3 - Cranium Consulting and Custom Software)
iTunes (HKLM\...\{427174C0-096E-40D9-9684-9C109BEE2CBF}) (Version: 11.0.5.5 - Apple Inc.)
Java 7 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417045FF}) (Version: 7.0.450 - Oracle)
Java 7 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.450 - Oracle)
Java SE Development Kit 7 Update 45 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170450}) (Version: 1.7.0.450 - Oracle)
Java™ 6 Update 24 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416024FF}) (Version: 6.0.240 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Kaspersky Internet Security 2013 (HKLM-x32\...\InstallWIX_{560985FB-4B76-4121-9189-7A2CDC7886D6}) (Version: 13.0.1.4190 - Kaspersky Lab)
Kaspersky Internet Security 2013 (x32 Version: 13.0.1.4190 - Kaspersky Lab) Hidden
Lightshot-5.2.1.1 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.2.1.1 - Skillbrains)
Macromedia Flash 5 (HKLM-x32\...\{4C93C363-414E-11D4-9756-00C04F8EEB39}) (Version: 5 - Macromedia)
Malwarebytes Anti-Malware version 1.70.0.1100 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.70.0.1100 - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Help Viewer 1.0 (HKLM\...\Microsoft Help Viewer 1.0) (Version: 1.0.30319 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\OneDriveSetup.exe) (Version: 17.0.4023.1211 - Microsoft Corporation)
Microsoft OneNote 2013 - en-us (HKLM\...\OneNoteFreeRetail - en-us) (Version: 15.0.4711.1003 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 (HKLM-x32\...\{B7E38540-E355-3503-AFD7-635B2F2F76E1}) (Version: 9.0.30729.4974 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Express - ENU (HKLM-x32\...\Microsoft Visual C++ 2010 Express - ENU) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Express Prerequisites x64 - ENU (HKLM\...\{BCA26999-EC22-3007-BB79-638913079C9A}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
MonkeyJam 3_050529 (HKLM-x32\...\MonkeyJam_is1) (Version:  - GiantScreamingRobotMonkeys)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4711.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4711.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4711.1003 - Microsoft Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Oracle VM VirtualBox 4.3.18 (HKLM\...\{74B7E6F9-DCAC-4ADB-B2D0-EEFDD1B5AC25}) (Version: 4.3.18 - Oracle Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.1.3.2637 - Electronic Arts, Inc.)
Overwolf (HKLM-x32\...\Overwolf) (Version: 0.85.190.0 - Overwolf Ltd.)
Pantech PCSuite (HKLM-x32\...\{9BC95D0F-EE60-43FB-ACE8-7D91A2ED33F3}) (Version: 1.1 - Pantech)
Pantech PCSuite (x32 Version: 1.1 - Pantech) Hidden
Pantech Unified USB Driver Ver1 (HKLM\...\{19E88D03-44D4-46aa-9F3C-D6CFC035BFE6}) (Version: 4.14.2.0 - Pantech)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.2.0 - Frank Heindörfer, Philip Chinery)
PFConfig 1.0.296 (HKLM-x32\...\PFConfig) (Version: 1.0.296 - Portforward.com)
PhotoShowExpress (x32 Version: 2.0.063 - Sonic Solutions) Hidden
Picmeta PhotoTracker v1.5 (HKLM-x32\...\Picmeta PhotoTracker_is1) (Version:  - Picmeta Systems)
Pivot Animator version 4.1.5 (HKLM-x32\...\Pivot Animator_is1) (Version: 4.1.5 - Motus Software Ltd)
Play withSIX (HKLM-x32\...\{D7F3EEAD-183C-47DE-BDC5-593539573F97}) (Version: 1.30.0476 - SIX Networks)
Portforward Static IP Address 1.0.47 (HKLM-x32\...\Portforward Static IP Address) (Version: 1.0.47 - Portforward.com)
Powerbullet Presenter  1.44 (HKLM-x32\...\Powerbullet Presenter_is1) (Version: 1.44 - DDD Pty Ltd)
PowerISO (HKLM-x32\...\PowerISO) (Version: 5.5 - Power Software Ltd)
PremiumSctructure (HKLM-x32\...\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{74e9abac}) (Version:  - PremiumSctructure) <==== ATTENTION
Project Zomboid Demo (HKLM-x32\...\Steam App 264910) (Version:  - Indie Stone Studios)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.988 - Even Balance, Inc.)
PX3 Presets Manager (HKLM-x32\...\{83030E21-76C9-4EFB-8182-EBC9B851B631}) (Version: 1.00.0000 - Turtle Beach)
Pyware 3D Performer's Practice Tools (HKLM-x32\...\Pyware 3D Performer's Practice Tools) (Version: 1.0.0.0 - Pygraphics)
Quick SEO  PageRank Backlinks  Alexa Tool (HKLM-x32\...\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}) (Version:  - ) <==== ATTENTION
RBVirtualFolder64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.31.1025.2010 - Realtek)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30126 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden
Roadkil's Unstoppable Copier Version 5.2 (HKLM-x32\...\{A306FD29-7D3A-4287-91AC-9A0180931395}_is1) (Version:  - Roadkil.Net)
Roblox for isaiah (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version:  - ROBLOX Corporation)
Roxio Creator Starter (HKLM-x32\...\{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}) (Version: 12.1.77.0 - Roxio)
Roxio File Backup (Version: 1.3.2 - Roxio) Hidden
Savant Web Server (HKLM-x32\...\Savant Web Server) (Version:  - )
ShopDroP (HKLM-x32\...\{B6D700D3-3D0D-FEEB-D675-2CE78F9EC5D6}) (Version:  - "") <==== ATTENTION
Sibelius 6 Demo (HKLM-x32\...\{A67C4EF9-725D-4C83-A67A-BB7B7DE96CF4}) (Version: 6.0.0 - Sibelius Software)
SketchUp 2015 (HKLM-x32\...\{D0A0BE3D-8D66-4BE9-87C4-D30CA5AA93A3}) (Version: 15.3.330 - Trimble Navigation Limited)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 5.10 (HKLM-x32\...\{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}) (Version: 5.10.116 - Skype Technologies S.A.)
SlimDX Runtime .NET 2.0 (January 2012) (HKLM-x32\...\{014A2868-BE56-4888-A16C-693989B8F153}) (Version: 2.0.13.43 - SlimDX Group)
Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0 - Sonic Solutions) Hidden
Sothink SWF Decompiler (HKLM-x32\...\{BCDB856C-D247-4DEE-9132-89C02F4D6B8C}_is1) (Version: 7.3 - SourceTec Software Co., LTD)
Sound Forge Audio Studio 10.0 (HKLM-x32\...\{7A263871-BEEC-11E1-AC53-F04DA23A5C58}) (Version: 10.0.178 - Sony)
Source SDK (HKLM-x32\...\Steam App 211) (Version:  - Valve)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synfig Studio (HKLM-x32\...\synfigstudio) (Version: 0.63.05 - )
Synthesia (HKLM-x32\...\Synthesia) (Version: 8.5 - Synthesia LLC)
TeamSpeak 3 Client (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
The Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.42.130 - Electronic Arts)
TrustedID (HKLM-x32\...\{C16A92EF-017B-4839-9C75-FBADB5A1FA27}) (Version: 5.0 - TrustedID)
Ulead VideoStudio SE DVD (HKLM-x32\...\{8F8D9297-FDD2-405A-97E7-E52C7B2F97B3}) (Version: 10.0 - Ulead Systems)
Unisales (HKLM-x32\...\{4CEE92A3-9F0C-51AB-ADC0-34EC24AD7B7E}) (Version:  - ) <==== ATTENTION
Unity Web Player (HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Unturned (HKLM-x32\...\Steam App 304930) (Version:  - Nelson Sexton)
USB2.0 Grabber (HKLM-x32\...\{45518B6D-9DDF-4144-83E4-A56762524F35}) (Version: 7.12.000.003 - Youyan)
USB2.0 Grabber (HKLM-x32\...\USB2.0 Grabber) (Version:  - )
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Vectorian Giotto 3.0.0 (HKLM-x32\...\Vectorian Giotto_is1) (Version:  - Vectorian Inc.)
Vegas Pro 11.0 (HKLM-x32\...\{B5B98340-0296-11E2-8B8E-F04DA23A5C58}) (Version: 11.0.700 - Sony)
Vizzed Retro Game Room (HKLM-x32\...\{6D9F35D2-1D6F-4E17-A79F-991A7BD24AAD}) (Version: 2.0.0 - Vizzed)
Watcom C/C++ 11.0c update (HKLM-x32\...\Watcom C/C++ 11.0c update) (Version:  - )
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
youtubeadblocker (HKLM-x32\...\{4820778D-AB0D-6D18-C316-52A6A0E1D507}) (Version:  - ) <==== ATTENTION

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\isaiah\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\isaiah\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\isaiah\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000_Classes\CLSID\{D45F043D-F17F-4e8a-8435-70971D9FA46D}\InprocServer32 -> C:\Program Files (x86)\Blender Foundation\Blender\BlendThumb64.dll ()
CustomCLSID: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\isaiah\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\isaiah\AppData\Local\Microsoft\SkyDrive\17.0.4023.1211\amd64\FileSyncApi64.dll (Microsoft Corporation)

==================== Restore Points  =========================

28-04-2015 19:49:07 Windows Update
28-04-2015 20:04:05 Windows Defender Checkpoint
02-05-2015 12:10:48 Windows Update
03-05-2015 22:02:15 Removed GeekBuddy.
03-05-2015 22:02:54 Removed GeekBuddy.
07-05-2015 20:34:14 Malwarebytes Anti-Rootkit Restore Point
07-05-2015 21:48:54 Malwarebytes Anti-Rootkit Restore Point
08-05-2015 20:41:02 Malwarebytes Anti-Rootkit Restore Point
09-05-2015 13:55:22 Windows Update
12-05-2015 20:36:29 Windows Update
13-05-2015 00:00:09 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 19:34 - 2009-06-10 14:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {009B39B9-D515-4222-9460-ED6785F4F071} - System32\Tasks\{2C364901-AA06-473D-A052-32F3F54F358F} => Chrome.exe
Task: {09B760B5-3E15-486B-803B-EBE7E5B8A0D3} - System32\Tasks\0 => Iexplore.exe  <==== ATTENTION
Task: {0CEA552C-DEAC-4671-B3DA-621912592E15} - \ProPCCleaner_Start No Task File <==== ATTENTION
Task: {0E51396B-770C-49BF-B1FA-676C467BB053} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {1533A718-3DD0-4CFB-884A-70FF635052B2} - System32\Tasks\{BA9B55D6-7F65-49D3-8DCB-061312A7342A} => pcalua.exe -a C:\watcom\WiseUpdt.exe
Task: {16FFA2EA-4B1F-4705-9797-24D152B7851B} - System32\Tasks\PCDEventLauncher => C:\Program Files\Dell Support Center\sessionchecker.exe [2012-04-12] (PC-Doctor, Inc.)
Task: {17455F81-AA8B-4290-9AD3-4224EA489A1E} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-24] (Microsoft Corporation)
Task: {30BFFF48-6CB9-4A1E-A459-69A36ECDCAFF} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-16] (Adobe Systems Incorporated)
Task: {40116C0B-5DE3-4E6B-8AFF-9EA10912B79E} - System32\Tasks\{2EC56597-00C3-4963-BC6D-ADE8D82FDEBA} => Chrome.exe
Task: {402BF172-310F-4192-8621-30EE4F975021} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {49893E45-C793-41C8-A1E1-A0B3910F8FA1} - System32\Tasks\{6BAF6CF2-946F-4DA5-B798-6AB61E5D5E42} => pcalua.exe -a C:\Users\isaiah\Downloads\Video_AMD_W7W8_A01_Setup-HC6HJ_ZPE.exe -d C:\Users\isaiah\Downloads
Task: {652FECDA-01D6-4EA7-9041-71F8CBFF3250} - System32\Tasks\GoogleUpdateTaskMachineCore1cd914d439221f3 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-27] (Google Inc.)
Task: {66D27535-5824-48D3-BFB1-2C1EB6EC9E4C} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell Support Center\uaclauncher.exe [2012-04-12] (PC-Doctor, Inc.)
Task: {66F5E966-1F44-4B93-9815-E10CC8369415} - \ProPCCleaner_Popup No Task File <==== ATTENTION
Task: {740F64E3-6804-4B65-BDEF-6B6079B6E1FA} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {85E5AA2C-0306-40C7-A15A-A74CFD01E346} - System32\Tasks\4804 => Wscript.exe C:\Users\isaiah\AppData\Local\Temp\launchie.vbs //B <==== ATTENTION
Task: {89F5D76B-44D0-4720-AA22-E4F0F748C937} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-04-22] (Microsoft Corporation)
Task: {9C0A281A-97FD-4069-9D3D-BDEE01F2A06D} - System32\Tasks\{2FCE4873-A2D4-4E7B-B47C-ADAE461EF62F} => pcalua.exe -a "C:\Dell\drivers\HC6HJ\9.003 WHQL W7 W8-PX4-121025a-155179C-Dell\Bin\ATISetup.exe" -d "C:\Dell\drivers\HC6HJ\9.003 WHQL W7 W8-PX4-121025a-155179C-Dell\Bin"
Task: {B61ED734-AEC9-42D8-9DB3-F23E666292A7} - System32\Tasks\{25DFC93A-00C6-4C5E-8A9A-BB58662B5618} => pcalua.exe -a "C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\BEsetup\Setup_BattlEyeARMA2OA.exe" -d "C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead" -c [email protected] -nosplash
Task: {BFC33A76-8AB6-4709-A53B-C8395B903833} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-04-22] (Microsoft Corporation)
Task: {C6EEAD65-894F-496C-A4F8-CA70AD8E32E4} - System32\Tasks\update-S-1-5-21-4152253128-2157246082-1293380562-1000 => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [2014-03-25] ()
Task: {CC20E6C7-257A-42EE-BA0E-998E308A1526} - System32\Tasks\update-sys => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [2014-03-25] ()
Task: {CEE40174-B983-473B-A23B-825539FBDD03} - System32\Tasks\{6D1CEE4C-F539-431C-A412-FC2054464041} => pcalua.exe -a "C:\Program Files (x86)\SelectRebates\SelectRebatesUninstall.exe"
Task: {D039104F-4509-4A6B-AC15-D5A07991011B} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2015-05-04] (Overwolf LTD)
Task: {D68C89CB-E545-46E2-8BA9-EA3087E1EAFF} - System32\Tasks\SystemToolsDailyTest => C:\Program Files\Dell Support Center\uaclauncher.exe [2012-04-12] (PC-Doctor, Inc.)
Task: {D6CB2D92-4982-47E2-9670-B905FC32D25D} - System32\Tasks\GoogleUpdateTaskMachineUA1cd914d43dfa6d6 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-27] (Google Inc.)
Task: {E561DE58-F951-47DC-9F53-04934CF99BD0} - System32\Tasks\{EADB7BAB-5FC3-4762-8ED3-C84EA699D41C} => pcalua.exe -a "C:\Program Files (x86)\Steam\steamapps\common\Arma 2\BEsetup\setup_BattlEyeARMA2.exe" -d "C:\Program Files (x86)\Steam\steamapps\common\Arma 2\BEsetup"
Task: {F17DD5FB-B78B-4831-A2C8-D843FB3CCEEA} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1cd914d439221f3.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA1cd914d43dfa6d6.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\PCDoctorBackgroundMonitorTask.job => C:\Program Files\Dell Support Center\uaclauncher.exeo-backgroundmon scripts\defaultscan.xml
Task: C:\windows\Tasks\SystemToolsDailyTest.job => C:\Program Files\Dell Support Center\uaclauncher.exe
Task: C:\windows\Tasks\update-S-1-5-21-4152253128-2157246082-1293380562-1000.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
Task: C:\windows\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe

==================== Loaded Modules (whitelisted) ==============

2010-12-17 11:53 - 2010-12-17 11:53 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2012-07-19 13:06 - 2005-03-12 00:07 - 00087040 _____ () C:\windows\System32\pdfcmnnt.dll
2014-10-09 21:15 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2014-11-20 19:03 - 2014-11-20 19:03 - 00075064 _____ () C:\windows\SysWOW64\PnkBstrA.exe
2015-03-13 19:50 - 2015-01-27 08:29 - 08898720 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2011-08-23 04:00 - 2011-04-10 11:40 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2010-12-17 11:53 - 2010-12-17 11:53 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2010-11-17 08:35 - 2010-11-17 08:35 - 00514544 _____ () C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
2012-02-01 11:50 - 2012-02-01 11:50 - 00968048 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
2013-04-21 21:44 - 2013-04-21 21:44 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2013-04-21 21:44 - 2013-04-21 21:44 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2012-08-17 21:39 - 2015-05-09 14:46 - 01310136 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\kpcengine.2.2.dll
2013-03-12 17:10 - 2015-03-09 23:37 - 00775680 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2015-01-19 19:03 - 2014-12-01 17:29 - 05002752 _____ () C:\Program Files (x86)\Steam\v8.dll
2015-01-19 19:03 - 2014-12-01 17:29 - 01612800 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2015-01-19 19:03 - 2014-12-01 17:29 - 01210368 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2014-05-21 16:39 - 2015-04-13 16:44 - 02371776 _____ () C:\Program Files (x86)\Steam\video.dll
2014-08-29 16:44 - 2014-12-01 14:31 - 02396672 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2014-08-29 16:44 - 2014-12-01 14:31 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2014-08-29 16:44 - 2014-12-01 14:31 - 00479744 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2014-08-29 16:44 - 2014-12-01 14:31 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2014-08-29 16:44 - 2014-12-01 14:31 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2013-08-01 14:49 - 2015-04-13 16:44 - 00702656 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2014-10-15 16:35 - 2014-10-15 16:35 - 00169472 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\93182e9779b8be0f688fd0784df6d7fb\IsdiInterop.ni.dll
2011-08-23 01:34 - 2010-11-05 21:50 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll
2010-11-24 20:44 - 2010-11-24 20:44 - 00375280 _____ () c:\program files (x86)\common files\roxio shared\dllshared\SQLite352.dll
2012-02-01 11:44 - 2012-02-01 11:44 - 08151040 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtGui4.dll
2012-02-01 11:44 - 2012-02-01 11:44 - 02278400 _____ () C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtCore4.dll
2012-08-17 21:38 - 2012-08-17 21:38 - 00479160 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\dblite.dll
2012-08-17 21:40 - 2012-08-17 21:40 - 00068024 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\QtWebKit\qmlwebkitplugin4.dll
2013-08-01 14:49 - 2015-02-24 18:58 - 34641288 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm
AlternateDataStreams: C:\Users\Public\DRM:احتضان

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tammgF119.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tammgR119.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Juanenodra => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tammgF119.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tammgR119.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, the associated entry will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\aeriagames.com -> hxxps://aeriagames.com
IE trusted site: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\aeriagames.com -> hxxp://aeriagames.com
IE trusted site: HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\...\vizzed.com -> www.vizzed.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-4152253128-2157246082-1293380562-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\isaiah\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.254

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: Dell Webcam Central => "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2

==================== FirewallRules (whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

FirewallRules: [{FB6C794F-7922-48D8-A3F1-A44404E84F12}] => (Allow) C:\Program Files (x86)\Dell\VideoStage\VideoStage.exe
FirewallRules: [{63854801-A57A-4ABB-81E7-5C4DC3157658}] => (Allow) C:\Program Files (x86)\Intel Corporation\Intel WiDi\WiDiApp.exe
FirewallRules: [{12585EEA-68D6-408D-8517-280CAA92E4A0}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{DD57CD94-27D6-4122-86EA-DB88430B1CB0}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{752E3E89-AF7E-4B59-8866-C7970C224C3C}] => (Allow) LPort=2869
FirewallRules: [{7A902977-647A-468E-8931-396ED9E71E84}] => (Allow) LPort=1900
FirewallRules: [{0F7E30EE-C410-4D29-B1F4-54FBE548FE97}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{CAE8A2FC-722C-48F6-A455-2FA259AE53A0}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{E9E30087-2443-4798-955C-EF1AA1491643}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{012CD4EF-672F-46AC-B9D0-F281B2AC810D}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{197528BE-073B-4AE2-8528-CD2CDD7362B3}] => (Allow) C:\Program Files\dell stage\dell stage\accuweather\accuweather.exe
FirewallRules: [{B5FC9064-61FB-4239-9AFE-850C68495823}] => (Allow) C:\Program Files\dell stage\musicstage\musicstageengine.exe
FirewallRules: [{A2D300F2-21DA-4A32-8699-FB1A6A12DDF4}] => (Allow) C:\Program Files\dell stage\dell stage\stage_primary.exe
FirewallRules: [{10ECBC56-DF4C-4E71-816C-83BA8FD49A89}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
FirewallRules: [{9CE7BF3D-062D-42AD-8664-A39A0C907B42}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
FirewallRules: [{C357C8ED-9A97-413B-89D6-CE4152DF55BB}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
FirewallRules: [{43AC5FE2-DDC5-43FA-9EB8-D615DA093668}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
FirewallRules: [{E3A7C8B5-04AC-4D19-A2B2-95A2D17A9353}] => (Allow) C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\TroubleShooter.exe
FirewallRules: [{D60727C2-8C03-4F89-A2EB-5A3E44A14B91}] => (Allow) C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\TroubleShooter.exe
FirewallRules: [{C6A23999-B8F6-4CE2-97F6-00788ADE5CB8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{9317D26B-2F68-4672-8074-259E8E7D1338}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [TCP Query User{BB94525D-EC67-47B0-BE58-7BC5F9292A9C}C:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe] => (Allow) C:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe
FirewallRules: [UDP Query User{D2207485-A32A-4059-94F8-DFCA229F2841}C:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe] => (Allow) C:\program files (x86)\six networks\play withsix\tools\bin\rsync.exe
FirewallRules: [TCP Query User{F6DFB93A-8C9A-45C9-A455-6A1072FC97E5}C:\users\isaiah\documents\arma 2\expansion\beta\arma2oa.exe] => (Allow) C:\users\isaiah\documents\arma 2\expansion\beta\arma2oa.exe
FirewallRules: [UDP Query User{941B0E54-6AA8-4A41-B666-1026F440C875}C:\users\isaiah\documents\arma 2\expansion\beta\arma2oa.exe] => (Allow) C:\users\isaiah\documents\arma 2\expansion\beta\arma2oa.exe
FirewallRules: [{96D96BA7-F17E-46E6-B4BF-F12C56B103FA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2\arma2.exe
FirewallRules: [{314B7D78-94A0-4349-BBC9-33624EC89331}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2\arma2.exe
FirewallRules: [{15895A70-9802-4D97-8898-400EC4C2D843}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\ArmA2OA.exe
FirewallRules: [{9EB13300-A4B1-4112-8910-036629D5D11A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\ArmA2OA.exe
FirewallRules: [{4836FCF4-9BB3-4902-8884-611EC0D21A28}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\BEsetup\Setup_BattlEyeARMA2OA.exe
FirewallRules: [{2E918AC1-DDFB-427D-BECB-1960AFC989D6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\BEsetup\Setup_BattlEyeARMA2OA.exe
FirewallRules: [TelnetServer-TlntSvr-TCP-In] => (Allow) %systemroot%\system32\tlntsvr.exe
FirewallRules: [TelnetServer-Tlntadmn-RPC-In] => (Allow) %systemroot%\system32\tlntsvr.exe
FirewallRules: [{B67463BB-F4A5-40AB-A436-C1D1D0880FBE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\Expansion\beta\Arma2OA.exe
FirewallRules: [{02540B9A-E497-451A-AFB6-CA886A07A548}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\Expansion\beta\Arma2OA.exe
FirewallRules: [{B5D857F8-0CEE-49B0-997E-7C48AD3E6325}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{A2F3C668-51FA-44F7-83AE-76F995FAA1D7}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{97D65CF0-84F6-4897-8A54-0C4420274BD8}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{03F4D284-2275-4B42-A6DC-986ADED7B968}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{86C04536-A007-4518-8A61-954D896FF24C}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{E6C8584E-37F7-4BB4-BB32-0414FDC000CC}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{45854D96-0B6E-4D00-95BA-8177382EF602}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{A8653AE9-C6A9-421C-8515-944A08409C68}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{3C3BCFAB-27C4-4293-B3DE-7B0E94B72CDD}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{E665FFC5-64AB-402F-BB02-C3F0CE12410B}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{B8512867-3199-4121-A49A-F5D5F7E1AF25}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{5F9F44AD-07FF-4299-A484-114C3CAEB1C4}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{2F3A8874-4A67-4D9A-BCCA-964FD36F3B5B}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{CDB939EB-A340-4729-BE7D-44E8A9584B54}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{FEF78855-BA7B-4BA2-AAB9-515515030BD0}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{C7BEAC9A-0718-4C6B-B0C9-648861548349}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{7B59DED9-4C84-4007-927D-DB2EEEE88ED6}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{D039FF42-7318-47AD-B987-1EBE71796652}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{EBEBD8A7-6048-4AA0-AED5-827C8783B484}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{1A1B1F5E-005A-486B-A9BC-D023C75C52A4}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{CED5EF5E-F614-4000-9F8A-C01E287FA528}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{64825B42-1996-49FF-A530-520AE090353D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{FF107C82-1939-4E90-9FC2-42224DF53860}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{28A958BD-7A82-431B-A2E2-9ED38A202C02}] => (Allow) C:\Users\isaiah\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{66C60478-1894-49A8-A443-F93E1368FF4C}] => (Allow) C:\Users\isaiah\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{C1A54FC1-C9B0-4491-B1E1-F8F36CE7FC3A}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{CCF76574-D646-45D1-82D3-2F1DCC3D34C0}] => (Allow) C:\Program Files (x86)\Sibelius Software\Sibelius 6 Demo\RegTool.exe
FirewallRules: [{BF8FC548-2863-4DD2-A9F4-AD96930853E2}] => (Allow) C:\Program Files (x86)\Sibelius Software\Sibelius 6 Demo\RegTool.exe
FirewallRules: [{A3715BD5-99B3-4818-B574-83BB0AE01B69}] => (Allow) C:\Program Files (x86)\Sibelius Software\Sibelius 6 Demo\Sibelius.exe
FirewallRules: [{9AADF8FE-3BB8-47BD-ADCA-377D0D6B6395}] => (Allow) C:\Program Files (x86)\Sibelius Software\Sibelius 6 Demo\Sibelius.exe
FirewallRules: [{E71C00F4-3C19-4CB6-9E9F-32C75850A280}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{E59972B6-F43D-45ED-A604-632CE54F8DEF}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{AD135AE5-93C1-4D3A-8B2C-959381FD9587}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{E69A4F65-9A83-4F50-9A77-3D01E82F25FC}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{9DBAD9EF-6D2A-45E5-9538-D9DCDB39A92A}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{54FE5C8B-7914-4EA7-9C12-5C47A6831CA6}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{5D6F0DD1-0361-476F-BBF9-CEF5AB0435EF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{1CD9158C-F9B2-477D-9964-5CBE968D8994}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{D147D394-73CD-4BB4-AFAF-D779C7868421}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{96435E38-7774-4E5D-954B-3A64449F753A}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{CE675344-42FD-40D9-BCF5-A56473C60EDD}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{DE895E9C-8FA0-4E94-864B-54A00980054A}] => (Allow) C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe
FirewallRules: [{50ECF78E-F2E1-44DC-9516-7C62377A07B7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dystopia\hl2.exe
FirewallRules: [{806EA9CC-A6BB-493E-AB32-90F1DDB0E631}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Dystopia\hl2.exe
FirewallRules: [{397B6D36-497C-4868-A41A-40E03E1D9679}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{908AF1B7-82D9-4BB0-B47F-43AB55B88D88}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{FCE00889-A54B-47DA-93BB-AF20C9CD332C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{8B4B2CE7-3120-472D-8F7F-0DA54C027108}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{2A2E1B5C-545E-4013-B8BD-E6CF18A27DB6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{D268BEE6-1B40-4FDD-B133-0B13295A08E8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{A66DFEA2-A32F-4E6D-8672-687C606C27B1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{F3C0C2E5-100F-4083-AFCC-06C138B9EDD1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{2DB11E19-D773-4A30-A496-62D9F084FCAC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{46652C7F-B004-46A3-AF01-3B59029AE1FB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ.exe
FirewallRules: [{7783C636-6DAA-4EE7-8B19-AA31FFCF1624}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{D49951CB-4AEC-40E6-9C0E-F63428F5F43B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{EF7C9F41-2702-4BBE-95B9-259E7FBA2200}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SourceSDK\bin\SDKLauncher.exe
FirewallRules: [{A24A339E-327E-4C4F-9F83-47F8A8964802}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SourceSDK\bin\SDKLauncher.exe
FirewallRules: [{D399BE08-1177-4881-9E93-1D73B67D225D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{178133F8-17F7-46D0-8FDF-B2FD7FC56135}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{C20197EE-C991-4084-B38A-2E8EFBE0C71E}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{7DCE9768-2811-4544-9195-FFF15C99CF1A}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{61DC4E84-48CA-41CC-81EC-8EE92BD69293}C:\users\isaiah\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\isaiah\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{FE3A2764-CDAD-45F4-A927-7696FF33B0C4}C:\users\isaiah\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\isaiah\appdata\local\akamai\netsession_win.exe
FirewallRules: [TCP Query User{15A3C15A-BA7C-4E64-9198-CF90BCAF2E60}C:\users\isaiah\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\isaiah\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{1EF7FB12-39FE-41EE-A725-9A9488E3439F}C:\users\isaiah\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\isaiah\appdata\local\akamai\netsession_win.exe
FirewallRules: [{4FDA637A-3EDA-4493-8BFA-B1BC41469C68}] => (Allow) C:\Users\isaiah\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{C3970759-44FA-45BE-A160-2C4E60B09FED}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Battlefield Bad Company 2\BFBC2Game.exe
FirewallRules: [{FD45BFEC-D668-4B4B-ABE1-F11199BA8940}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Battlefield Bad Company 2\BFBC2Game.exe
FirewallRules: [{7F4B2C0C-090E-4FEA-A11A-6FAC869CEA39}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{2521313E-7A6A-43F9-9AC7-8A936ECD0E41}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{024290EF-CCC1-4CAB-9744-75B05D31E44C}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{8DE86DB8-B999-49F5-A4F1-BBC16EFA8D39}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [TCP Query User{F8E7BA2B-C07C-45EA-A75E-F94337AA896F}C:\program files (x86)\starcraft\starcraft.exe] => (Block) C:\program files (x86)\starcraft\starcraft.exe
FirewallRules: [UDP Query User{4E49E8C7-0AC8-4AC0-A1C0-C29713D2F3B9}C:\program files (x86)\starcraft\starcraft.exe] => (Block) C:\program files (x86)\starcraft\starcraft.exe
FirewallRules: [{8A124A1B-6883-4FCB-AD6D-81040F867678}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ_BE.exe
FirewallRules: [{9D6830DA-BD7C-45D1-BABA-770F7957788A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\DayZ\DayZ_BE.exe
FirewallRules: [TCP Query User{C3684451-AA8F-40BB-A78E-BF0E27D29CFE}C:\program files\java\jre7\bin\javaw.exe] => (Block) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{A5DE10FA-3FE8-423F-AFA6-7C9B743E710D}C:\program files\java\jre7\bin\javaw.exe] => (Block) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{12F07043-9EC9-43F2-B5B8-4110A638B150}C:\program files\andy\andy.exe] => (Allow) C:\program files\andy\andy.exe
FirewallRules: [UDP Query User{C6CAF11B-BDFD-407D-9536-9477D2431CA5}C:\program files\andy\andy.exe] => (Allow) C:\program files\andy\andy.exe
FirewallRules: [{204DD4E8-C91E-4992-A36D-F405E3E5235C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Project Zomboid Demo\ProjectZomboid64.exe
FirewallRules: [{1C10656A-C6E8-474F-ACD6-8882831063DB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Project Zomboid Demo\ProjectZomboid64.exe
FirewallRules: [TCP Query User{C8631496-3840-4660-8622-93DD79861543}C:\program files (x86)\the elder scrolls v skyrim\creationkit.exe] => (Allow) C:\program files (x86)\the elder scrolls v skyrim\creationkit.exe
FirewallRules: [UDP Query User{5C40F815-7D04-4652-9CA8-6565450F2384}C:\program files (x86)\the elder scrolls v skyrim\creationkit.exe] => (Allow) C:\program files (x86)\the elder scrolls v skyrim\creationkit.exe
FirewallRules: [TCP Query User{0FBA8A7A-C340-49AF-9637-A245740934D9}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{A78E5463-1B90-4D63-AD09-B4BCFA8553C4}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{08EA1A3E-B831-4F5D-999C-CB26DEEC2406}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{6CCF437F-603D-4C73-B9E6-73F8376AA5E0}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{DFE02089-F143-4BAE-A36E-510BB05E09C6}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{A5C7614C-3DD0-4BC7-9E50-D378C090B17C}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [{4FC4C42C-7832-4953-A273-799E62AE3633}] => (Allow) C:\Users\isaiah\AppData\Local\Temp\nsbE299.tmp\CnetInstaller-10257337.exe
FirewallRules: [{1E0CBCB6-D74A-430A-B754-A6D68B7FB243}] => (Allow) C:\Users\isaiah\AppData\Local\Temp\nsbE299.tmp\CnetInstaller-10257337.exe
FirewallRules: [TCP Query User{D27C5782-3133-4774-805A-A95F829BFAA9}C:\savant\savant.exe] => (Allow) C:\savant\savant.exe
FirewallRules: [UDP Query User{E364D1FE-4A01-476A-A0A8-B7B0882A7E2A}C:\savant\savant.exe] => (Allow) C:\savant\savant.exe
FirewallRules: [TCP Query User{4837C4D3-D04B-47AA-9145-C5B6ED44DD08}C:\savant\savant.exe] => (Block) C:\savant\savant.exe
FirewallRules: [UDP Query User{2EEC6FEB-3185-479B-B5DF-4E51F567E380}C:\savant\savant.exe] => (Block) C:\savant\savant.exe
FirewallRules: [{45C3E57E-1FF9-4BF7-8F48-25B0218C5D21}] => (Allow) C:\ProgramData\boostwebapp\1.1.0.31\gefaucu.EXE
FirewallRules: [{73B92472-2AFC-40AF-93B2-2B13839636C5}] => (Allow) C:\ProgramData\boostwebapp\1.1.0.31\gefaucu.EXE
FirewallRules: [{6EFFD7E9-B50D-450A-90D3-2AD488622840}] => (Allow) C:\ProgramData\boostwebapp\1.1.0.31\gefaucu.EXE
FirewallRules: [{7C55DD14-179F-4F6E-B947-3E8B8B51E8F3}] => (Allow) C:\ProgramData\boostwebapp\1.1.0.31\gefaucu.EXE
FirewallRules: [{906C62C6-360B-4E6B-B3BC-BE85F4D0EE64}] => (Allow) C:\ProgramData\boostwebapp\1.1.0.31\gefaucu.EXE
FirewallRules: [{EAB59816-4E3C-47B8-B5DF-5F10D9F6264A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{1F385774-6778-4522-B28D-74209F081886}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe

==================== Faulty Device Manager Devices =============

Name: VirtualBox Host-Only Ethernet Adapter
Description: VirtualBox Host-Only Ethernet Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Oracle Corporation
Service: VBoxNetAdp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: tammgR119 service
Description: tammgR119 service
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: tammgR119
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

==================== Event log errors: =========================

Application errors:
==================
Error: (05/13/2015 08:32:12 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/13/2015 08:27:51 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/12/2015 08:51:46 PM) (Source: MsiInstaller) (EventID: 1024) (User: isaiah-PC)
Description: Product: Adobe Reader XI (11.0.10) - Update '{AC76BA86-7AD7-0000-2550-7A8C40011011}' could not be installed. Error code 1625. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft....k/?LinkId=23127

Error: (05/12/2015 08:32:51 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/12/2015 08:17:48 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/12/2015 07:45:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: aeriaignite.exe, version: 1.13.3296.0, time stamp: 0x51b10621
Faulting module name: KERNELBASE.dll, version: 6.1.7601.18798, time stamp: 0x5507b485
Exception code: 0xe0434352
Fault offset: 0x0000c42d
Faulting process id: 0x1098
Faulting application start time: 0xaeriaignite.exe0
Faulting application path: aeriaignite.exe1
Faulting module path: aeriaignite.exe2
Report Id: aeriaignite.exe3

Error: (05/12/2015 07:44:59 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: aeriaignite.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.Net.Sockets.SocketException
Stack:
   at System.Net.SafeCloseSocketAndEvent.CreateWSASocketWithEvent(System.Net.Sockets.AddressFamily, System.Net.Sockets.SocketType, System.Net.Sockets.ProtocolType, Boolean, Boolean)
   at System.Net.NetworkInformation.NetworkChange+AddressChangeListener.StartHelper(System.Net.NetworkInformation.NetworkAddressChangedEventHandler, Boolean, System.Net.NetworkInformation.StartIPOptions)
   at System.Net.NetworkInformation.NetworkChange+AvailabilityChangeListener.Start(System.Net.NetworkInformation.NetworkAvailabilityChangedEventHandler)
   at AI.AppController.detectNetwork()
   at AI.AppController..ctor()
   at AI.AppController.get_Default()
   at AI.Service.AnalyticRequestManager.Track(System.String, System.Collections.Generic.Dictionary`2<System.String,System.String>, AI.Service.AIAnalyticCompletedEventHandler)
   at AI.Service.AnalyticRequestManager.TrackError(System.String, System.String, System.Exception)
   at AI.App.handleException(System.Exception, System.String, Boolean)
   at AI.App.catchUnhandledUIExceptions(System.Object, System.Windows.Threading.DispatcherUnhandledExceptionEventArgs)
   at System.Windows.Threading.Dispatcher.CatchException(System.Exception)
   at System.Windows.Threading.Dispatcher.CatchExceptionStatic(System.Object, System.Exception)
   at System.Windows.Threading.ExceptionWrapper.CatchException(System.Object, System.Exception, System.Delegate)
   at MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
   at System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
   at MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
   at MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef)
   at System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
   at System.Windows.Threading.Dispatcher.PushFrame(System.Windows.Threading.DispatcherFrame)
   at System.Windows.Threading.Dispatcher.Run()
   at System.Windows.Application.RunDispatcher(System.Object)
   at System.Windows.Application.RunInternal(System.Windows.Window)
   at System.Windows.Application.Run(System.Windows.Window)
   at AI.Program.StartApp(System.String[])
   at AI.Program.Main(System.String[])

Error: (05/12/2015 07:42:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/12/2015 07:42:03 PM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out

Error: (05/12/2015 06:40:04 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: aeriaignite.exe, version: 1.13.3296.0, time stamp: 0x51b10621
Faulting module name: KERNELBASE.dll, version: 6.1.7601.18798, time stamp: 0x5507b485
Exception code: 0xe0434352
Fault offset: 0x0000c42d
Faulting process id: 0x99c
Faulting application start time: 0xaeriaignite.exe0
Faulting application path: aeriaignite.exe1
Faulting module path: aeriaignite.exe2
Report Id: aeriaignite.exe3

System errors:
=============
Error: (05/13/2015 08:34:49 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Dell Digital Delivery Service service failed to start due to the following error:
%%2

Error: (05/13/2015 08:34:41 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (05/13/2015 08:33:20 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Windows Modules Installer service terminated with the following error:
%%16405

Error: (05/13/2015 08:32:28 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
tammgF119
tammgR119

Error: (05/13/2015 08:32:01 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The QumbaFyvu service failed to start due to the following error:
%%2

Error: (05/13/2015 08:31:54 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The jylvirmid service failed to start due to the following error:
%%2

Error: (05/13/2015 08:31:54 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The imhmypneta service failed to start due to the following error:
%%2

Error: (05/13/2015 08:31:00 AM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \SystemRoot\SysWow64\drivers\pfc.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

Error: (05/13/2015 08:30:59 AM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \SystemRoot\SysWow64\drivers\pfc.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

Error: (05/13/2015 08:31:25 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 8:29:09 AM on ‎5/‎13/‎2015 was unexpected.

Microsoft Office Sessions:
=========================
Error: (05/13/2015 08:32:12 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/13/2015 08:27:51 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/12/2015 08:51:46 PM) (Source: MsiInstaller) (EventID: 1024) (User: isaiah-PC)
Description: Adobe Reader XI (11.0.10){AC76BA86-7AD7-0000-2550-7A8C40011011}1625(NULL)(NULL)(NULL)

Error: (05/12/2015 08:32:51 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/12/2015 08:17:48 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/12/2015 07:45:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: aeriaignite.exe1.13.3296.051b10621KERNELBASE.dll6.1.7601.187985507b485e04343520000c42d109801d08d26ac894b94C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exeC:\windows\syswow64\KERNELBASE.dll0d545ac7-f91a-11e4-9992-ac7289429fb8

Error: (05/12/2015 07:44:59 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: aeriaignite.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.Net.Sockets.SocketException
Stack:
   at System.Net.SafeCloseSocketAndEvent.CreateWSASocketWithEvent(System.Net.Sockets.AddressFamily, System.Net.Sockets.SocketType, System.Net.Sockets.ProtocolType, Boolean, Boolean)
   at System.Net.NetworkInformation.NetworkChange+AddressChangeListener.StartHelper(System.Net.NetworkInformation.NetworkAddressChangedEventHandler, Boolean, System.Net.NetworkInformation.StartIPOptions)
   at System.Net.NetworkInformation.NetworkChange+AvailabilityChangeListener.Start(System.Net.NetworkInformation.NetworkAvailabilityChangedEventHandler)
   at AI.AppController.detectNetwork()
   at AI.AppController..ctor()
   at AI.AppController.get_Default()
   at AI.Service.AnalyticRequestManager.Track(System.String, System.Collections.Generic.Dictionary`2<System.String,System.String>, AI.Service.AIAnalyticCompletedEventHandler)
   at AI.Service.AnalyticRequestManager.TrackError(System.String, System.String, System.Exception)
   at AI.App.handleException(System.Exception, System.String, Boolean)
   at AI.App.catchUnhandledUIExceptions(System.Object, System.Windows.Threading.DispatcherUnhandledExceptionEventArgs)
   at System.Windows.Threading.Dispatcher.CatchException(System.Exception)
   at System.Windows.Threading.Dispatcher.CatchExceptionStatic(System.Object, System.Exception)
   at System.Windows.Threading.ExceptionWrapper.CatchException(System.Object, System.Exception, System.Delegate)
   at MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
   at System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
   at MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)
   at MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef)
   at System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame)
   at System.Windows.Threading.Dispatcher.PushFrame(System.Windows.Threading.DispatcherFrame)
   at System.Windows.Threading.Dispatcher.Run()
   at System.Windows.Application.RunDispatcher(System.Object)
   at System.Windows.Application.RunInternal(System.Windows.Window)
   at System.Windows.Application.Run(System.Windows.Window)
   at AI.Program.StartApp(System.String[])
   at AI.Program.Main(System.String[])

Error: (05/12/2015 07:42:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (05/12/2015 07:42:03 PM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out

Error: (05/12/2015 06:40:04 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: aeriaignite.exe1.13.3296.051b10621KERNELBASE.dll6.1.7601.187985507b485e04343520000c42d99c01d08d1d1e1fd70cC:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exeC:\windows\syswow64\KERNELBASE.dllf9c15cf6-f910-11e4-abf4-ac7289429fb8

CodeIntegrity Errors:
===================================
  Date: 2014-10-12 17:49:34.587
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-12 17:49:34.577
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-12 17:49:34.577
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-12 17:49:34.567
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-12 17:49:34.557
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-12 17:49:34.557
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-08 19:31:35.104
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-08 19:31:35.104
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-08 19:31:35.094
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-10-08 19:31:35.014
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.

==================== Memory info ===========================

Processor: Intel® Core™ i5-2410M CPU @ 2.30GHz
Percentage of memory in use: 45%
Total physical RAM: 6051.17 MB
Available physical RAM: 3324.61 MB
Total Pagefile: 12100.55 MB
Available Pagefile: 9403.97 MB
Total Virtual: 8192 MB
Available Virtual: 8191.86 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:581.42 GB) (Free:255.72 GB) NTFS
Drive e: (SKYRIM_EN) (CDROM) (Total:5.12 GB) (Free:0 GB) UDF

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596.2 GB) (Disk ID: D9D722B7)
Partition 1: (Not Active) - (Size=100 MB) - (Type=DE)
Partition 2: (Active) - (Size=14.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=581.4 GB) - (Type=07 NTFS)

==================== End Of Log ============================


  • 0

#15
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts
Still lots of work to be done here...



JRTbythisisu.png Fix with Junkware Removal Tool

Please download JRT by Thisisu and save the file to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.
  • Right-click on JRTbythisisu.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Follow the prompts and let this process run uninterrupted.
  • This scan can take a while, depending on your System specs.
  • Upon completion, a log (JRT.txt) will open on your desktop.
Please include the contents of that file in your reply.
Do not forget to re-enable your previously switched off protection software!
Please also manually reboot your machine after this procedure.



adwcleaner_new.png Fix with AdwCleaner

Please download AdwCleaner by Xplode and save the file to your desktop.
  • Right-click on adwcleaner_new.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • The program will begin to update the database (if internet connection is operational). Please wait a little bit.
  • Follow the prompts and click Scan.
  • When finished, please click Clean.
  • Upon completion, click Report. A log (AdwCleaner[S*].txt) will open.
Please include the contents of that file in your reply.
  • 0






Similar Topics


Also tagged with one or more of these keywords: malware, virus, help, cmd, boostwebapp

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP