Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

PC Running Sluggishly, Consistently Freezing

Vista 32bit; FRST scan logs

  • This topic is locked This topic is locked

#1
crybaby

crybaby

    Member

  • Member
  • PipPipPip
  • 175 posts

Hi, 

I'm unsure if this is a malware issue, but I suspect that it is. PC running on Vista 32bit, secured with Webroot; constantly freezing, running extremely slow both on and off-line. Major stuttering while playing video or mp3 files; lagging while trying to open windows, tabs, or programs; and occasionally upon startup, desktop is nothing more than a blue screen, resulting in rebooting several times before desktop is restored. Any help or direction to the proper forum would be greatly appreciated. Thank you for your time regarding this matter. 

 

FRST Logs: 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-05-2015 01
Ran by Shayla Potter (administrator) on BNSS-LEASED on 24-05-2015 12:30:15
Running from C:\Users\Shayla Potter\Desktop
Loaded Profiles: Shayla Potter (Available Profiles: Mason & Shayla Potter & Kieran & Administrator & Guest)
Platform: Microsoft® Windows Vista™ Home Basic  Service Pack 2 (X86) OS Language: English (United States)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Webroot) C:\Program Files\Webroot\WRSA.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
( ) C:\Windows\System32\dlcxcoms.exe
(NETGEAR) C:\Program Files\NETGEAR Genie\bin\NETGEARGenieDaemon.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Sonic Solutions) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(Microsoft Corporation) C:\Windows\System32\iashost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
() C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
() C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
(Microsoft Corporation) C:\Windows\System32\wpcumi.exe
(Primax Electronics Ltd.) C:\Windows\System32\ico.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Nokia) C:\Users\Shayla Potter\Desktop\Kierans folder\Nokia PC Suite 7\PCSuite.exe
(NETGEAR Inc.) C:\Program Files\NETGEAR Genie\bin\NETGEARGenie.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Avanquest Software ) C:\Program Files\Digital Line Detect\DLG.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Dropbox, Inc.) C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft® Corporation) C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe
() C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Nokia) C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
() C:\Program Files\NETGEAR Genie\bin\genie2_tray.exe
(Apache Software Foundation) C:\Program Files\OpenOffice 4\program\soffice.exe
(Apache Software Foundation) C:\Program Files\OpenOffice 4\program\soffice.bin
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Webroot) C:\Program Files\Webroot\WRSA.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [11930696 2013-03-29] (Realtek Semiconductor)
HKLM\...\Run: [ISUSScheduler] => C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [81920 2006-10-03] (Macrovision Corporation)
HKLM\...\Run: [dscactivate] => c:\dell\dsca.exe [16384 2007-07-30] ( )
HKLM\...\Run: [Google Desktop Search] => C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-06-22] (Google)
HKLM\...\Run: [FaxCenterServer] => C:\Program Files\Dell PC Fax\fm3032.exe [312200 2006-11-03] ()
HKLM\...\Run: [dlcxmon.exe] => C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe [292336 2007-01-12] ()
HKLM\...\Run: [MemoryCardManager] => C:\Program Files\Dell Photo AIO Printer 926\memcard.exe [304008 2006-11-03] ()
HKLM\...\Run: [DLCXCATS] => rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16
HKLM\...\Run: [WPCUMI] => C:\Windows\system32\WpcUmi.exe [176128 2006-11-02] (Microsoft Corporation)
HKLM\...\Run: [Mouse Suite 98 Daemon] => C:\Windows\system32\ICO.EXE [56128 2007-02-15] (Primax Electronics Ltd.)
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [40368 2011-08-30] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-03-29] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-03] (Apple Inc.)
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2006-12-10] (Hewlett-Packard Co.)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-12-22] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-11-14] ()
HKLM\...\Run: [TomcatStartup 2.5] => C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe [741376 2007-05-19] (Hewlett-Packard)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-07-08] (Apple Inc.)
HKLM\...\Run: [WRSVC] => C:\Program Files\Webroot\WRSA.exe [817072 2015-05-16] (Webroot)
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Run: [iLivid] => "C:\Users\Shayla Potter\AppData\Local\iLivid\iLivid.exe" -autorun
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Run: [Itibiti.exe] => C:\Program Files\Itibiti Soft Phone\Itibiti.exe
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Run: [PC Suite Tray] => C:\Users\Shayla Potter\Desktop\Kierans folder\Nokia PC Suite 7\PCSuite.exe [1516632 2012-06-26] (Nokia)
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Run: [NETGEARGenie] => C:\Program Files\NETGEAR Genie\bin\NETGEARGenie.exe [602880 2014-12-14] (NETGEAR Inc.)
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\MountPoints2: E - E:\WRSetupCD.exe
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\MountPoints2: {f46aefae-e281-11e3-82dc-001aa06945f1} - G:\LGAutoRun.exe
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\MountPoints2: {f46af174-e281-11e3-82dc-001aa06945f1} - G:\LaunchU3.exe -a
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [294912 2008-01-19] (Microsoft Corporation)
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk [2007-11-21]
ShortcutTarget: Digital Line Detect.lnk -> C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2014-06-12]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\Kids\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk [2011-05-18]
ShortcutTarget: OpenOffice.org 3.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File)
Startup: C:\Users\Mason\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iWin Desktop Alerts.lnk [2008-08-01]
ShortcutTarget: iWin Desktop Alerts.lnk -> C:\ProgramData\iWin Games\DesktopAlerts\DesktopAlerts.exe (No File)
Startup: C:\Users\Mason\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk [2009-06-16]
ShortcutTarget: OpenOffice.org 3.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File)
Startup: C:\Users\Shayla Potter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-04-10]
ShortcutTarget: Dropbox.lnk -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Shayla Potter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WKCALREM.LNK [2010-02-19]
ShortcutTarget: WKCALREM.LNK -> C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe (Microsoft® Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
GroupPolicyUsers\S-1-5-21-1260561122-373576474-2963483527-1010\User: Group Policy Restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-1260561122-373576474-2963483527-1005\User: Group Policy Restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-1260561122-373576474-2963483527-1000\User: Group Policy Restriction detected <======= ATTENTION
CHR HKU\S-1-5-21-1260561122-373576474-2963483527-1005\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.c...q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.c...q={searchTerms}
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....?trackid=sp-006
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\Software\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.co...=us&ibd=1071121
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
URLSearchHook: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 - (No Name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} -  No File
SearchScopes: HKLM -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.c...q={searchTerms}
SearchScopes: HKLM -> bProtectorDefaultScope {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
SearchScopes: HKLM -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://www.goonsearc...q={searchTerms}
SearchScopes: HKLM -> {9bd172ba-3f40-4303-bca1-0484b5ba2a7b} URL = http://search.mywebs...r={searchTerms}
SearchScopes: HKLM -> {CC865B26-C31D-4D23-B17B-96548EEF03F6} URL = 
SearchScopes: HKLM -> {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = http://us.yhs.search...p={searchTerms}
SearchScopes: HKLM -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.c...q={searchTerms}
SearchScopes: HKLM -> {EFE522B3-7ABD-49CB-A5C3-A2AFBBA83B9D} URL = https://www.google.c...q={searchTerms}
SearchScopes: HKU\.DEFAULT -> {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = http://us.yhs.search...p={searchTerms}
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.c...q={searchTerms}
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com...rchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-se...13_246&tsp=4981
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://www.goonsearc...q={searchTerms}
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {54ACE04D-52D8-4E32-97D3-0E379B1128F0} URL = http://groovorio.com...r=885083894&ir=
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {9001ECE5-27F9-7260-292B-CF945347FC97} URL = http://www.bing.com/...eferrer:source}
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {9bd172ba-3f40-4303-bca1-0484b5ba2a7b} URL = http://search.mywebs...r={searchTerms}
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL = http://toolbar.inbox...id=80051&lng=en
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {CC865B26-C31D-4D23-B17B-96548EEF03F6} URL = http://search.yahoo....p={searchTerms}
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = http://us.yhs.search...p={searchTerms}
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.c...q={searchTerms}
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {EFE522B3-7ABD-49CB-A5C3-A2AFBBA83B9D} URL = https://www.google.c...q={searchTerms}
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} ->  No File
BHO: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2011-08-30] (Adobe Systems Incorporated)
BHO: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll No File
BHO: AccelerateTab -> {48A789BF-F6D6-4930-9C8B-77855A63EDE1} -> C:\Program Files\Secure Speed Dial\IE\SpeedDial.dll [2014-05-26] (Secure Speed Dial)
BHO: Yahoo! IE Services Button -> {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -> C:\Program Files\Yahoo!\Common\yiesrvc.dll [2006-10-31] (Yahoo! Inc.)
BHO: No Name -> {6C8DB2EC-499B-4897-A784-0E3186C97E9D} ->  No File
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-24] (Oracle Corporation)
BHO: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files\Webroot\WRData\PKG\Vistax86\wrflt.dll [2015-05-16] (Webroot)
BHO: No Name -> {CA6319C0-31B7-401E-A518-A07C3DB8F777} ->  No File
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-24] (Oracle Corporation)
BHO: Adblock -> {EF5F59BA-B2AB-48D8-9747-54DF806C73B8} -> C:\Program Files\Secure Speed Dial\IE\ADBlock\IE\Adblock.dll [2014-06-17] (Adblock)
Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  No File
Toolbar: HKLM - No Name - {8660E5B3-6C41-44DE-8503-98D99BBECD41} -  No File
Toolbar: HKU\.DEFAULT -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  No File
Toolbar: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} -  No File
DPF: {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} http://www.infospace...pointsSetup.exe
DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} 
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab
DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2006-06-05] (Microsoft Corporation)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Winsock: Catalog9 01 C:\Windows\system32\wpclsp.dll [72192 2008-06-12] (Microsoft Corporation)
Winsock: Catalog9 02 C:\Windows\system32\wpclsp.dll [72192 2008-06-12] (Microsoft Corporation)
Winsock: Catalog9 03 C:\Windows\system32\wpclsp.dll [72192 2008-06-12] (Microsoft Corporation)
Winsock: Catalog9 04 C:\Windows\system32\wpclsp.dll [72192 2008-06-12] (Microsoft Corporation)
Winsock: Catalog9 05 C:\Windows\system32\wpclsp.dll [72192 2008-06-12] (Microsoft Corporation)
Winsock: Catalog9 06 C:\Windows\system32\wpclsp.dll [72192 2008-06-12] (Microsoft Corporation)
Winsock: Catalog9 07 C:\Windows\system32\wpclsp.dll [72192 2008-06-12] (Microsoft Corporation)
Winsock: Catalog9 08 C:\Windows\system32\wpclsp.dll [72192 2008-06-12] (Microsoft Corporation)
Winsock: Catalog9 19 C:\Windows\system32\wpclsp.dll [72192 2008-06-12] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
 
FireFox:
========
FF ProfilePath: C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default
FF DefaultSearchEngine: Google (avast)
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1215155.dll [2014-12-10] (Adobe Systems, Inc.)
FF Plugin: @alternatiff.com/AlternaTIFF -> C:\Program Files\MIE\AlternaTIFF\npzzatif.dll [2013-02-05] (Medical Informatics Engineering, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-21] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2013-09-16] (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll [2013-12-27] (DivX, LLC)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-24] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-24] (Oracle Corporation)
FF Plugin: @meadco.com/neptune plugin,version=2.0.0.29 -> C:\Program Files\OSA Kit Pro Player v4.0\npmeadax.dll [2008-10-09] (MeadCo Corp.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @movenetworks.com/Quantum Media Player -> C:\Users\Shayla Potter\AppData\Roaming\Move Networks\plugins\npqmp071504000001.dll No File
FF Plugin: @pack.google.com/Google Updater;version=14 -> C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll [2011-09-06] (Google)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin: [email protected]/YahooActiveXPluginBridge;version=1.0.0.1 -> C:\Program Files\Yahoo!\Common\npyaxmpb.dll No File
FF Plugin HKU\S-1-5-21-1260561122-373576474-2963483527-1005: @nsroblox.roblox.com/launcher -> C:\Users\Shayla Potter\AppData\Local\Roblox\Versions\version-c04585a2d58a4f29\\NPRobloxProxy.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-1260561122-373576474-2963483527-1005: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Shayla Potter\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-04-05] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-1260561122-373576474-2963483527-1005: @yahoo.com/BrowserPlus,version=2.9.8 -> C:\Users\Shayla Potter\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll [2010-08-04] (Yahoo! Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nphssb.dll [2009-07-09] (Homestead Technologies, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npmeadax.dll [2008-10-09] (MeadCo Corp.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2011-08-30] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2013-08-08] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2013-08-08] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2013-08-08] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2013-08-08] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2013-08-08] (Apple Inc.)
FF SearchPlugin: C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\searchplugins\bing-zugo.xml [2011-11-07]
FF SearchPlugin: C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\searchplugins\google-avast.xml [2014-12-22]
FF SearchPlugin: C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\searchplugins\Groovorio.xml [2015-04-25]
FF SearchPlugin: C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\searchplugins\SearchTheWeb.xml [2012-01-08]
FF SearchPlugin: C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\searchplugins\trovi-search.xml [2014-12-08]
FF SearchPlugin: C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\searchplugins\web-search.xml [2012-03-20]
FF SearchPlugin: C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\searchplugins\yahoo_ff.xml [2013-10-30]
FF Extension: AppGraffiti - C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\Extensions\AppGraffiti@AppGraffiti(93).com [2012-03-18]
FF Extension: AD Block - C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\Extensions\[email protected] [2014-06-27]
FF Extension: AccelerateTab - C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\Extensions\[email protected] [2014-10-08]
FF Extension: Ancestry.com Advanced Image Viewer - C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\Extensions\[email protected] [2010-05-16]
FF Extension: BitTorrentBar Community Toolbar - C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\Extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}(38) [2011-08-19]
FF Extension: Old Default Image Style - C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\Extensions\[email protected] [2012-03-23]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-06-29]
FF HKLM\...\Firefox\Extensions: [{1C43BAF1-00C2-40A8-A09E-F84CFD79546D}] - C:\Program Files\Coupons.com CouponBar\firefox\{1C43BAF1-00C2-40A8-A09E-F84CFD79546D}\Coupons.com.xpi
FF HKLM\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-11-23]
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer
FF Extension: Webroot Filtering Extension - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer [2015-05-16]
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2014-07-02]
 
Chrome: 
=======
CHR Profile: C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Zwinky) - C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehjkfdmkpocpileolmldepapdjbfegei [2014-08-08]
CHR Extension: (Bookmark Manager) - C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-15]
CHR Extension: (RealDownloader) - C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2013-11-23]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12]
CHR Extension: (Google Wallet) - C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21]
CHR HKLM\...\Chrome\Extension: [aaaaaiabcopkplhgaedhbloeejhhankf] - https://clients2.goo...ice/update2/crx
CHR HKLM\...\Chrome\Extension: [aaaaaigjndjblmpeckabiffcpogflfgl] - C:\Users\Shayla Potter\AppData\Local\ilividbandoomoviestoolbar\GC\toolbar.crx [2014-07-03]
CHR HKLM\...\Chrome\Extension: [blmchfpimpbbdmgpcieclabeafkljbhm] - https://clients2.goo...ice/update2/crx
CHR HKLM\...\Chrome\Extension: [cnpkmcjgpcihgfnkcjapiaabbbplkcmf] - C:\Program Files\Coupons.com CouponBar\chrome\Coupons.com.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Shayla Potter\AppData\Roaming\BabSolution\CR\Delta.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
CHR HKLM\...\Chrome\Extension: [kjeghcllfecehndceplomkocgfbklffd] - C:\ProgramData\WRData\PKG\CHROME\CHROME_1.1.0.57.crx [2015-05-16]
CHR HKU\S-1-5-21-1260561122-373576474-2963483527-1005\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [blmchfpimpbbdmgpcieclabeafkljbhm] - https://clients2.goo...ice/update2/crx
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 dlcx_device; C:\Windows\system32\dlcxcoms.exe [532480 2006-10-11] ( )
S3 DSBrokerService; C:\Program Files\DellSupport\brkrsvc.exe [70656 2007-03-19] () []
S3 GoogleDesktopManager-051210-111108; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-06-22] (Google)
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [225280 2007-01-02] (Hewlett-Packard Co.) []
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [131072 2006-12-10] (Hewlett-Packard Co.) []
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) []
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) []
R2 NETGEARGenieDaemon; C:\Program Files\NETGEAR Genie\bin\NETGEARGenieDaemon.exe [195840 2014-12-14] (NETGEAR)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) []
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
S3 RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [880640 2006-11-05] (Sonic Solutions) []
R2 RoxWatch9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [159744 2006-11-05] (Sonic Solutions) []
S2 SecureUpdateSvc; C:\Program Files\Secure Speed Dial\IE\SecureUpdate.exe [2580304 2014-05-28] () <==== ATTENTION
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-19] (Microsoft Corporation)
R2 WRSVC; C:\Program Files\Webroot\WRSA.exe [817072 2015-05-16] (Webroot)
S3 stllssvr; "C:\Program Files\Common Files\SureThing Shared\stllssvr.exe" [X]
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 Dot4Scan; C:\Windows\System32\DRIVERS\Dot4Scan.sys [10752 2008-01-19] (Microsoft Corporation)
S3 DSproct; C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys [4736 2006-10-05] (Gteko Ltd.) []
S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [61704 2014-01-08] (FTDI Ltd.)
R3 HPPLSBULK; C:\Windows\System32\drivers\hpplsbulk.sys [9344 2005-02-02] (Hewlett Packard) []
R3 MarvinBus; C:\Windows\System32\DRIVERS\MarvinBus.sys [171008 2005-06-02] (Pinnacle Systems GmbH) []
R2 NPF; C:\Windows\system32\drivers\npf.sys [35088 2015-05-13] (CACE Technologies, Inc.)
R1 PCLEPCI; C:\Windows\system32\drivers\pclepci.sys [14165 2005-02-09] (Pinnacle Systems GmbH) []
S3 pelmouse; C:\Windows\System32\DRIVERS\pelmouse.sys [23360 2007-02-15] (Primax Electronics Ltd.)
S3 pelusblf; C:\Windows\System32\DRIVERS\pelusblf.sys [19264 2007-02-15] (Primax Electronics Ltd.)
R0 PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [36624 2006-10-18] (Sonic Solutions) []
S3 usbanyka; C:\Windows\System32\DRIVERS\UsbAnyka.sys [17536 2007-10-22] (Anyka (Guangzhou) Software Technology Co., Ltd.) []
S3 vncmirror; C:\Windows\System32\DRIVERS\vncmirror.sys [3072 2007-10-17] (RealVNC Ltd.)
S2 W55U01; C:\Windows\System32\Drivers\W55U01.sys [15232 2005-08-12] (Windows ® 2000 DDK provider) []
R0 WRkrn; C:\Windows\System32\drivers\WRkrn.sys [117784 2015-05-16] (Webroot)
S3 wrUrlFlt; C:\Windows\system32\DRIVERS\wrUrlFlt.sys [37432 2015-05-16] (Webroot)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 easytether; system32\DRIVERS\easytthr.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S1 vieieerh; \??\C:\Windows\system32\drivers\vieieerh.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-05-24 12:30 - 2015-05-24 12:33 - 00036299 _____ () C:\Users\Shayla Potter\Desktop\FRST.txt
2015-05-24 12:28 - 2015-05-24 12:28 - 01146880 _____ (Farbar) C:\Users\Shayla Potter\Desktop\FRST.exe
2015-05-24 12:27 - 2015-05-24 12:30 - 00000000 ___DC () C:\FRST
2015-05-24 12:25 - 2015-05-24 12:27 - 01146880 _____ (Farbar) C:\Users\Shayla Potter\Downloads\FRST.exe
2015-05-23 12:17 - 2015-05-23 12:17 - 00002195 _____ () C:\Users\Shayla Potter\Desktop\T+C.txt
2015-05-18 16:17 - 2015-05-18 16:17 - 00018840 _____ () C:\Users\Shayla Potter\Desktop\KAEDYN ROCKS!.txt
2015-05-17 09:28 - 2015-05-17 09:28 - 00858768 _____ () C:\Users\Shayla Potter\Desktop\scanlog.log
2015-05-16 19:23 - 2015-05-16 19:23 - 00037432 ____T (Webroot) C:\Windows\system32\Drivers\wrUrlFlt.sys
2015-05-16 19:22 - 2015-05-20 13:32 - 00000657 _____ () C:\Users\Public\Desktop\Webroot SecureAnywhere.lnk
2015-05-16 19:22 - 2015-05-16 19:23 - 00000000 ____D () C:\Program Files\Webroot
2015-05-16 19:22 - 2015-05-16 19:22 - 00166128 _____ (Webroot) C:\Windows\system32\WRusr.dll
2015-05-16 19:22 - 2015-05-16 19:22 - 00117784 _____ (Webroot) C:\Windows\system32\Drivers\WRkrn.sys
2015-05-16 19:22 - 2015-05-16 19:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webroot SecureAnywhere
2015-05-16 19:01 - 2015-05-24 12:28 - 00000000 ____D () C:\ProgramData\WRData
2015-05-14 16:54 - 2015-05-14 16:54 - 00000000 ____D () C:\Users\Shayla Potter\Desktop\Make a word cloud - WordItOut_files
2015-05-13 09:04 - 2015-05-21 01:32 - 00000000 ____D () C:\Users\Shayla Potter\AppData\Local\NETGEARGenie
2015-05-13 09:04 - 2015-05-13 09:04 - 00001805 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NETGEAR Genie.lnk
2015-05-13 09:04 - 2015-05-13 09:04 - 00001793 _____ () C:\Users\Public\Desktop\NETGEAR Genie.lnk
2015-05-13 09:01 - 2015-05-13 09:02 - 39316824 _____ (NETGEAR Inc.) C:\Users\Shayla Potter\Downloads\NETGEARGenie-install (1).exe
2015-05-13 03:57 - 2015-04-30 11:03 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-13 03:55 - 2015-04-19 16:24 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2015-05-13 03:55 - 2015-04-19 16:24 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2015-05-13 03:55 - 2015-04-19 16:24 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2015-05-13 03:55 - 2015-04-19 16:24 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2015-05-13 03:55 - 2015-04-19 15:19 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-05-13 03:55 - 2015-04-19 15:18 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2015-05-13 03:55 - 2015-04-19 15:13 - 00682496 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2015-05-13 03:55 - 2015-04-19 15:12 - 01072640 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-13 03:55 - 2015-04-19 15:12 - 00801792 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-13 03:55 - 2015-04-18 23:59 - 02065408 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-13 03:52 - 2015-04-30 08:14 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 03:10 - 2015-04-10 18:22 - 00279552 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-12 17:38 - 2015-04-10 10:19 - 00421888 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-12 17:38 - 2015-04-10 10:18 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-05-12 17:38 - 2015-04-10 10:18 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-05-12 17:37 - 2015-04-10 10:30 - 12379136 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-12 17:37 - 2015-04-10 10:25 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-12 17:37 - 2015-04-10 10:25 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-12 17:37 - 2015-04-10 10:24 - 09750528 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-12 17:37 - 2015-04-10 10:21 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-12 17:37 - 2015-04-10 10:20 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-12 17:37 - 2015-04-10 10:20 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-12 17:37 - 2015-04-10 10:19 - 01804288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-12 17:37 - 2015-04-10 10:19 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-12 17:37 - 2015-04-10 10:19 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-12 17:37 - 2015-04-10 10:19 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-05-12 17:37 - 2015-04-10 10:19 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-05-12 17:37 - 2015-04-10 10:19 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-05-12 17:37 - 2015-04-10 10:19 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-05-12 17:37 - 2015-04-10 10:18 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-05-12 17:37 - 2015-04-10 10:18 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-12 17:37 - 2015-04-10 10:18 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-12 17:37 - 2015-04-10 10:18 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-12 17:37 - 2015-04-10 10:18 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-05-02 22:25 - 2015-05-02 22:25 - 00153448 _____ () C:\Windows\Minidump\Mini050215-01.dmp
2015-05-02 22:20 - 2014-01-09 19:59 - 526695157 _____ () C:\Users\Shayla Potter\Desktop\YUNC0001.mp4
2015-04-28 08:41 - 2015-04-28 08:43 - 00000000 ____D () C:\Users\Shayla Potter\Desktop\Jeremy
2015-04-24 19:16 - 2015-04-24 18:58 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-04-24 19:00 - 2015-04-24 19:00 - 00000000 ____D () C:\Program Files\Common Files\Java
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-05-24 12:31 - 2009-08-27 22:17 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-24 12:06 - 2012-03-31 06:52 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-24 11:35 - 2006-11-02 07:45 - 00003568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-24 11:35 - 2006-11-02 07:45 - 00003568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-24 11:24 - 2010-04-25 15:13 - 00000868 _____ () C:\Windows\Tasks\Google Software Updater.job
2015-05-24 07:13 - 2006-11-02 06:18 - 00000000 ____D () C:\Windows\tracing
2015-05-24 06:55 - 2007-11-21 10:54 - 01652633 _____ () C:\Windows\WindowsUpdate.log
2015-05-24 00:31 - 2009-08-27 22:17 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-20 14:10 - 2014-05-02 21:05 - 00000000 ___RD () C:\Users\Shayla Potter\Dropbox
2015-05-20 14:10 - 2014-05-02 21:02 - 00000000 ____D () C:\Users\Shayla Potter\AppData\Roaming\Dropbox
2015-05-20 14:06 - 2009-07-13 21:43 - 00000000 ____D () C:\Users\Shayla Potter
2015-05-20 13:32 - 2013-11-23 15:30 - 01069156 _____ () C:\Windows\PFRO.log
2015-05-20 13:32 - 2008-08-28 11:35 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2015-05-20 13:32 - 2006-11-02 07:58 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-20 13:28 - 2006-11-02 07:58 - 00032642 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-05-16 21:55 - 2014-04-02 19:10 - 00000000 ____D () C:\Users\Shayla Potter\AppData\Local\Softonic
2015-05-16 15:34 - 2009-07-13 21:44 - 00001356 _____ () C:\Users\Shayla Potter\AppData\Local\d3d9caps.dat
2015-05-15 08:32 - 2011-01-22 10:13 - 00120216 _____ () C:\Users\Shayla Potter\Desktop\Budget year look.ods
2015-05-13 09:03 - 2012-07-31 19:26 - 00281104 _____ (CACE Technologies, Inc.) C:\Windows\system32\wpcap.dll
2015-05-13 09:03 - 2012-07-31 19:26 - 00096784 _____ (CACE Technologies, Inc.) C:\Windows\system32\packet.dll
2015-05-13 09:03 - 2012-07-31 19:26 - 00035088 _____ (CACE Technologies, Inc.) C:\Windows\system32\Drivers\npf.sys
2015-05-13 04:33 - 2006-11-02 06:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-05-13 04:20 - 2006-11-02 07:44 - 00540864 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-13 04:17 - 2008-07-12 19:11 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-05-13 04:15 - 2006-11-02 07:35 - 00000000 ____D () C:\Windows\system32\XPSViewer
2015-05-13 03:50 - 2013-08-01 03:02 - 00000000 ____D () C:\Windows\system32\MRT
2015-05-13 03:14 - 2006-11-02 05:24 - 137310008 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-05-13 03:07 - 2010-06-03 21:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-05-12 18:12 - 2014-05-02 21:03 - 00000000 ____D () C:\Users\Shayla Potter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-05-11 03:13 - 2006-11-02 05:33 - 00784272 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-10 11:14 - 2014-06-12 19:56 - 00127388 _____ () C:\Windows\hppins01.dat
2015-05-10 11:14 - 2010-01-18 23:47 - 00042706 _____ () C:\ProgramData\hpzinstall.log
2015-05-10 07:42 - 2006-11-02 05:23 - 00000179 _____ () C:\Windows\win.ini
2015-05-10 07:38 - 2007-12-07 14:08 - 00000000 ____D () C:\Program Files\Dl_cats
2015-05-09 08:19 - 2013-11-23 14:40 - 00063057 _____ () C:\Windows\setupact.log
2015-05-02 22:25 - 2013-11-23 15:24 - 233041665 _____ () C:\Windows\MEMORY.DMP
2015-05-02 22:25 - 2008-01-04 16:11 - 00000000 ____D () C:\Windows\Minidump
2015-05-02 22:17 - 2010-03-31 07:49 - 00000000 ____C () C:\DebugTraceNormal.log
2015-05-02 22:17 - 2010-03-31 07:42 - 00000000 ____D () C:\ProgramData\VideoViewer
2015-05-02 22:16 - 2008-07-22 16:00 - 00000000 ____D () C:\MDT
2015-05-01 23:36 - 2006-11-02 06:18 - 00000000 ____D () C:\Windows\system32\LogFiles
2015-04-28 08:45 - 2015-03-22 11:47 - 00000000 ____D () C:\Users\Shayla Potter\Desktop\Eagle Aspen SSM-22 Single Signal Meter (SSM-22) from Solid Signal_files
2015-04-28 08:44 - 2014-03-06 17:58 - 00000000 ____D () C:\Users\Shayla Potter\Desktop\Shayla's Phone
2015-04-28 08:44 - 2013-06-18 07:56 - 00000000 ____D () C:\Users\Shayla Potter\Desktop\KAEDYN'S Stuff
2015-04-25 06:25 - 2014-01-13 22:34 - 00000000 ____D () C:\ProgramData\Oracle
2015-04-24 19:17 - 2007-11-21 11:02 - 00000000 ____D () C:\Program Files\Java
 
==================== Files in the root of some directories =======
 
2011-11-07 20:54 - 2011-09-16 15:50 - 0161712 _____ () C:\Program Files\u4res.dll
2014-08-24 19:49 - 2014-08-24 19:49 - 0000046 _____ () C:\Users\Shayla Potter\AppData\Roaming\Camdata.ini
2014-08-24 19:49 - 2014-08-24 19:49 - 0000408 _____ () C:\Users\Shayla Potter\AppData\Roaming\CamLayout.ini
2014-08-24 19:49 - 2014-08-24 19:49 - 0000408 _____ () C:\Users\Shayla Potter\AppData\Roaming\CamShapes.ini
2014-08-24 19:49 - 2014-08-24 19:49 - 0004535 _____ () C:\Users\Shayla Potter\AppData\Roaming\CamStudio.cfg
2014-10-22 21:17 - 2014-10-24 07:17 - 0000098 _____ () C:\Users\Shayla Potter\AppData\Roaming\WB.CFG
2009-08-18 12:53 - 2015-02-20 07:23 - 0003088 _____ () C:\Users\Shayla Potter\AppData\Roaming\wklnhst.dat
2009-07-13 21:44 - 2015-05-16 15:34 - 0001356 _____ () C:\Users\Shayla Potter\AppData\Local\d3d9caps.dat
2009-09-22 16:49 - 2015-03-12 10:25 - 0073216 _____ () C:\Users\Shayla Potter\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-01-08 15:27 - 2012-01-08 15:27 - 0000101 _____ () C:\Users\Shayla Potter\AppData\Local\fusioncache.dat
2010-01-18 23:47 - 2015-05-10 11:14 - 0042706 _____ () C:\ProgramData\hpzinstall.log
2008-01-26 18:43 - 2008-01-26 18:43 - 0164144 _____ () C:\ProgramData\SPL7338.tmp
 
Files to move or delete:
====================
C:\Users\Kids\jagex_runescape_preferences.dat
C:\Users\Kids\jagex_runescape_preferences2.dat
C:\Users\Kieran\jagex_runescape_preferences.dat
C:\Users\Kieran\jagex_runescape_preferences2.dat
C:\Users\Shayla Potter\jagex_runescape_preferences.dat
C:\Users\Shayla Potter\jagex_runescape_preferences2.dat
 
 
Some files in TEMP:
====================
C:\Users\Mason\AppData\Local\Temp\uninstall.exe
C:\Users\Shayla Potter\AppData\Local\Temp\APNSetup.exe
C:\Users\Shayla Potter\AppData\Local\Temp\banner.exe
C:\Users\Shayla Potter\AppData\Local\Temp\CloudBackup3926.exe
C:\Users\Shayla Potter\AppData\Local\Temp\dlLogic.exe
C:\Users\Shayla Potter\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmptpwcn5.dll
C:\Users\Shayla Potter\AppData\Local\Temp\exthelper.exe
C:\Users\Shayla Potter\AppData\Local\Temp\GCVerifier.dll
C:\Users\Shayla Potter\AppData\Local\Temp\InstallIMVU_507.0.exe
C:\Users\Shayla Potter\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Shayla Potter\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
C:\Users\Shayla Potter\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Shayla Potter\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
C:\Users\Shayla Potter\AppData\Local\Temp\jre-8u40-windows-au.exe
C:\Users\Shayla Potter\AppData\Local\Temp\jre-8u45-windows-au.exe
C:\Users\Shayla Potter\AppData\Local\Temp\lowproc.exe
C:\Users\Shayla Potter\AppData\Local\Temp\nsfD008.exe
C:\Users\Shayla Potter\AppData\Local\Temp\Softonic_EN_1-5-9_EN-Production_10_CleanRelease.exe
C:\Users\Shayla Potter\AppData\Local\Temp\spstub.exe
C:\Users\Shayla Potter\AppData\Local\Temp\stubhelper.dll
C:\Users\Shayla Potter\AppData\Local\Temp\vcredist_x86.exe
C:\Users\Shayla Potter\AppData\Local\Temp\verifier.exe
C:\Users\Shayla Potter\AppData\Local\Temp\_Installation Guide.exe
 
 
Some zero byte size files/folders:
==========================
C:\Windows\System32\DIFxAPI.dll
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
==================== End of log ============================
 
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 24-05-2015 01
Ran by Shayla Potter at 2015-05-24 12:36:38
Running from C:\Users\Shayla Potter\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1260561122-373576474-2963483527-500 - Administrator - Disabled) => C:\Users\Administrator
Guest (S-1-5-21-1260561122-373576474-2963483527-501 - Limited - Disabled) => C:\Users\Guest
Kieran (S-1-5-21-1260561122-373576474-2963483527-1010 - Limited - Enabled) => C:\Users\Kieran
Mason (S-1-5-21-1260561122-373576474-2963483527-1000 - Administrator - Enabled) => C:\Users\Mason
Shayla Potter (S-1-5-21-1260561122-373576474-2963483527-1005 - Administrator - Enabled) => C:\Users\Shayla Potter
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Webroot SecureAnywhere (Enabled - Up to date) {66A6FE14-08CB-F415-3742-517201416109}
AS: Webroot SecureAnywhere (Enabled - Up to date) {DDC71FF0-2EF1-FB9B-0DF2-6A007AC62BB4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden
ABBYY FineReader 6.0 Sprint (HKLM\...\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.1784.41616 - ABBYY Software House)
AccelerateTab (HKLM\...\AccelerateTab_is1) (Version: 2.6 - AccelerateTab)
Adobe Flash Player 17 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Reader 8.3.1 (HKLM\...\{AC76BA86-7AD7-1033-7B44-A83000000003}) (Version: 8.3.1 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM\...\Adobe Shockwave Player) (Version: 12.1.5.155 - Adobe Systems, Inc.)
Apple Application Support (HKLM\...\{21ECABC3-40B2-42DF-8E21-ACF3A4D0D95A}) (Version: 3.0.5 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{941B4CE7-3F5D-443E-A8B7-56A420D2EAFD}) (Version: 7.1.2.6 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Architectural Library for progeCAD SMART! ENG (HKLM\...\Architectural Library for progeCAD SMART! ENG) (Version:  - )
Arduino (HKLM\...\Arduino) (Version: 1.0.5-r2 - Arduino LLC)
AviSynth 2.5 (HKLM\...\AviSynth) (Version:  - )
Blender (HKLM\...\Blender) (Version: 2.68a - Blender Foundation)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Browser Address Error Redirector (HKLM\...\{62230596-37E5-4618-A329-0D21F529A86F}) (Version: 1.00.0000 - Dell)
BufferChm (Version: 82.0.173.000 - Hewlett-Packard) Hidden
CamStudio 2.7.2 (HKLM\...\{04B83666-3A62-452B-85D3-70F8117F2329}_is1) (Version: 2.7.2 - CamStudio Open Source)
Celtx (2.9.1) (HKLM\...\Celtx (2.9.1)) (Version: 2.9.1 (en-US) - Greyfirst)
Conexant D850 PCI V.92 Modem (HKLM\...\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1) (Version:  - )
CustomerResearchQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Dell DataSafe Online (HKLM\...\{2C6C74C2-042F-4D36-B7B0-0C538FCF01AB}) (Version: 1.0.15 - Dell, Inc.)
Dell Driver Download Manager (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\f031ef6ac137efc5) (Version: 2.1.0.0 - Dell Inc.)
Dell Getting Started Guide (HKLM\...\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell PC Fax (HKLM\...\Dell PC Fax) (Version:  - )
Dell Photo AIO Printer 926 (HKLM\...\Dell Photo AIO Printer 926) (Version:  - Dell, Inc.)
Dell Support Center (HKLM\...\{B8C54AB1-7E1A-40E8-B794-EDB6E8921F3A}) (Version: 1.0.07192 - Dell)
DellSupport (HKLM\...\{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}) (Version: 6.0.3075 - Dell)
DesignPro 5.4 Limited Edition (HKLM\...\InstallShield_{71F6DF7D-B639-4FAD-BA93-E6DF267AA44D}) (Version: 5.2.1201 - Avery Dennison)
DesignPro 5.4 Limited Edition (Version: 5.2.1201 - Avery Dennison) Hidden
Destinations (Version: 82.0.173.000 - Hewlett-Packard) Hidden
DeviceManagementQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Digital Line Detect (HKLM\...\{E646DCF0-5A68-11D5-B229-002078017FBF}) (Version: 1.21 - BVRP Software, Inc)
DivX Setup (HKLM\...\DivX Setup) (Version: 2.6.1.90 - DivX, LLC)
DocProc (Version: 8.1.0.0 - Hewlett-Packard) Hidden
DocProcQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Dropbox (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Dropbox) (Version: 3.4.6 - Dropbox, Inc.)
DVD Decrypter (Remove Only) (HKLM\...\DVD Decrypter) (Version:  - )
ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version:  - )
eSupportQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
FaxTools (HKLM\...\{F45298E5-0083-426F-A668-1A2C5F04B8A0}) (Version: 5.10 - BVRP Software)
File Shredder 2.5 (HKLM\...\File Shredder_is1) (Version:  - Pow Tools)
Google Chrome (HKLM\...\Google Chrome) (Version: 43.0.2357.65 - Google Inc.)
Google Desktop (HKLM\...\Google Desktop) (Version: 5.9.1005.12335 - Google)
Google Earth (HKLM\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google SketchUp 8 (HKLM\...\{B700113B-24A8-4D4C-8484-0CC944F764C8}) (Version: 3.0.3117 - Google, Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.27.5 - Google Inc.) Hidden
Google Updater (HKLM\...\Google Updater) (Version: 2.4.2432.1652 - Google Inc.)
HP Color LaserJet 2820/2830/2840 3.1 (HKLM\...\HP Color LaserJet 2820/2830/2840) (Version: 3.1 - HP)
HP Customer Participation Program 8.0 (HKLM\...\HPExtendedCapabilities) (Version: 8.0 - HP)
HP Imaging Device Functions 8.0 (HKLM\...\HP Imaging Device Functions) (Version: 8.0 - HP)
HP Managed Printing Admin (HKLM\...\{7CA4F780-7AD0-417A-82A1-46EB825CFD53}) (Version: 2.5.8 - Hewlett-Packard)
HP OCR Software 8.0 (HKLM\...\HPOCR) (Version: 8.0 - HP)
HP Solution Center 8.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 8.0 - HP)
HP Update (HKLM\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HP Wireless Rechargeable Optical Mouse (HKLM\...\MouseSuite98) (Version:  - )
hppCLJ2800 (Version: 003.000.00273 - Hewlett-Packard) Hidden
hppDustDevil (Version: 003.000.00106 - Hewlett-Packard) Hidden
hppFaxDrv (Version: 003.000.00136 - Hewlett-Packard) Hidden
hppFonts (Version: 001.001.00056 - Hewlett-Packard) Hidden
hppIOFiles (Version: 002.000.00030 - Hewlett-Packard) Hidden
hppManuals2800 (Version: 003.000.00284 - Hewlett-Packard) Hidden
HPProductAssistant (Version: 82.0.173.000 - Hewlett-Packard) Hidden
hppscan2800 (Version: 003.000.00274 - Hewlett-Packard) Hidden
hppScanTo (Version: 003.000.00261 - Hewlett-Packard) Hidden
hppSendFax (Version: 003.000.00136 - Hewlett-Packard) Hidden
hppTLBX2840 (Version: 001.000.00002 - Hewlett-Packard) Hidden
hppTLBX2840Help (Version: 001.000.00001 - Hewlett-Packard) Hidden
hppTooCool (Version: 1.00.0000 - Hewlett-Packard) Hidden
Itibiti RTC (Version: 0.0.1 - Itibiti Inc) Hidden
iTunes (HKLM\...\{0A37EE62-9A58-420D-90CC-4E52153112EE}) (Version: 11.3.0.54 - Apple Inc.)
Java 8 Update 45 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
Juniper Networks Cache Cleaner 6.1.0 (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Juniper_Networks_Cache_Cleaner 6.1.0) (Version: 6.1.0.13281 - Juniper Networks)
Juniper Networks Host Checker (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Neoteris_Host_Checker) (Version: 7.1.0.18193 - Juniper Networks)
Juniper Networks Setup Client Activex Control (HKLM\...\Juniper_Setup_Client Activex Control) (Version: 2.1.1.1 - Juniper Networks)
Juniper Networks, Inc. Setup Client (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Juniper_Setup_Client) (Version: 7.1.2.10059 - Juniper Networks, Inc.)
Logicator for PIC micros (HKLM\...\{273DE5D6-81A6-4EF5-B21C-E4095E21F174}) (Version: 3.06.05 - Revolution Education Limited)
MarketResearch (Version: 82.0.174.000 - Hewlett-Packard) Hidden
Mechanics Library for progeCAD SMART! ENG (HKLM\...\Mechanics Library for progeCAD SMART! ENG) (Version:  - )
Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version:  - )
Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version:  - )
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Automated Troubleshooting Services Shim (HKLM\...\{c9920352-04e6-469d-bab8-e2b9c7c75415}.sdb) (Version:  - )
Microsoft Fix it Center (HKLM\...\{B7588D45-AFDC-4C93-9E2E-A100F3554B64}) (Version: 1.0.0100 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Works (HKLM\...\{6D52C408-B09A-4520-9B18-475B81D393F1}) (Version: 08.05.0818 - Microsoft Corporation)
MiShell*Budget (remove only) (HKLM\...\MiShell_Budget) (Version:  - )
Modem Diagnostic Tool (HKLM\...\{F63A3748-B93D-4360-9AD4-B064481A5C7B}) (Version: 1.0.17.8 - Dell)
Mozilla Firefox 30.0 (x86 en-US) (HKLM\...\Mozilla Firefox 30.0 (x86 en-US)) (Version: 30.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla)
MSVC90_x86 (Version: 1.0.1.2 - Nokia) Hidden
MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
msxml4 (HKLM\...\{5AE3D9F1-9E9E-4015-8787-E22705AA32C5}) (Version: 1.0.0 - Default Company Name)
Music, Photos & Videos Launcher (HKLM\...\{D7769185-9A7C-48D4-8874-5388743A1DE2}) (Version: 1.00.0000 - Dell Inc.)
NaturalReaderFree (HKLM\...\{C5E7BF75-007E-44AD-8962-627ED44CB63B}) (Version: 11.8 - NaturalSoft)
NCH Toolbox (HKLM\...\ToolBox) (Version:  - NCH Software)
Netflix Movie Viewer (HKLM\...\{BCE72AED-3332-4863-9567-C5DCB9052CA2}) (Version: 1.2.211 - Netflix)
NETGEAR Genie (HKLM\...\NETGEAR Genie) (Version: 2.3.1.57 - NETGEAR Inc.)
NETGEAR Live Parental Controls Management Utility 2.1.5 (HKLM\...\NETGEAR Live Parental Controls Management Utility) (Version: 2.1.5 - )
NETGEAR Live Parental Controls User Utility 1.0b40 (HKLM\...\NETGEAR Live Parental Controls User Utility) (Version: 1.0b40 - )
Nokia Connectivity Cable Driver (HKLM\...\{A57025CC-5F2E-4D01-B387-06DB10500D43}) (Version: 7.1.78.0 - Nokia)
Nokia PC Suite (HKLM\...\Nokia PC Suite) (Version: 7.1.180.94 - Nokia)
Nokia PC Suite (Version: 7.1.180.94 - Nokia) Hidden
NVIDIA Graphics Driver 285.62 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 285.62 - NVIDIA Corporation)
NVIDIANetworkDiagnostic (HKLM\...\InstallShield_{EFAD4066-CAF3-4B27-9669-12EED352C376}) (Version: 1.00.0000 - NVIDIA Corporation)
Onverse (HKLM\...\{B3B30A68-B9A5-4d42-86E6-2BD1AFCE9DD4}) (Version:  - )
Onverse (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\{B3B30A68-B9A5-4d42-86E6-2BD1AFCE9DD4}) (Version:  - )
OpenAL (HKLM\...\OpenAL) (Version:  - )
OpenOffice 4.0.0 (HKLM\...\{55E61709-D7D4-43C0-B45D-BFAF5C09A02D}) (Version: 4.00.9702 - Apache Software Foundation)
OSA Kit Pro Player v4.0 1.0 (HKLM\...\OSA Kit Pro Player) (Version: 1.0 - Maher F. Farag)
PC Connectivity Solution (HKLM\...\{644F4910-E812-49AD-93EC-86828CB81A0D}) (Version: 12.0.27.0 - Nokia)
Pdf995 (HKLM\...\Pdf995) (Version:  - )
Pinnacle Instant DVD Recorder (HKLM\...\{EF781A5C-58F5-4BFD-87F9-E4F14D382F25}) (Version:  - )
Pinnacle Studio MediaSuite (HKLM\...\{77B8ECB2-1ACF-4587-8FB1-FCF856DB8149}) (Version:  - )
PowerDVD (HKLM\...\{281ECE39-F043-492B-8337-F2E546B5604A}) (Version: 7.0 - Dell)
Product Documentation Launcher (HKLM\...\{89CEAE14-DD0F-448E-9554-15781EC9DB24}) (Version: 1.00.0000 - Dell Inc.)
QuickTime 7 (HKLM\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
RealDownloader (Version: 1.3.3 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6873 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
ROBLOX Player for Shayla Potter (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version:  - ROBLOX Corporation)
ROBLOX Studio 2013 for Shayla Potter (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\{2922D6F1-2865-4EFA-97A9-94EEAB3AFA14}) (Version:  - ROBLOX Corporation)
Roxio Creator Audio (HKLM\...\{83FFCFC7-88C6-41c6-8752-958A45325C82}) (Version: 3.3.0 - Roxio)
Roxio Creator BDAV Plugin (HKLM\...\{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}) (Version: 3.3.0 - Roxio)
Roxio Creator Copy (HKLM\...\{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}) (Version: 3.3.0 - Roxio)
Roxio Creator Data (HKLM\...\{0D397393-9B50-4c52-84D5-77E344289F87}) (Version: 3.3.0 - Roxio)
Roxio Creator DE (HKLM\...\{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}) (Version: 3.3.0 - Roxio)
Roxio Creator Tools (HKLM\...\{0394CDC8-FABD-4ed8-B104-03393876DFDF}) (Version: 3.3.0 - Roxio)
Roxio MyDVD DE (HKLM\...\{D639085F-4B6E-4105-9F37-A0DBB023E2FB}) (Version: 9.0.116 - Roxio, Inc.)
Roxio Update Manager (HKLM\...\{30465B6C-B53F-49A1-9EBA-A3F187AD502E}) (Version: 3.0.0 - Roxio)
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.3.2300.0 - SAMSUNG Electronics Co., Ltd.)
Scan (Version: 8.1.0.0 - Hewlett-Packard) Hidden
Softonic for Windows (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Softonic for Windows) (Version: 1.5.11 - Softonic International S.L.) <==== ATTENTION
SolutionCenter (Version: 82.0.188.000 - Hewlett-Packard) Hidden
Sonic Activation Module (Version: 1.0 - Sonic Solutions) Hidden
Stepvoice Recorder 1.8.0.206 (HKLM\...\Stepvoice Recorder_is1) (Version:  - )
SupportSoft Assisted Service (HKLM\...\{5A3F6A80-7913-475E-8B96-477A952CFA43}) (Version: 15 - SupportSoft)
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
System Requirements Lab (HKLM\...\SystemRequirementsLab) (Version:  - )
teenSMART UAC (HKLM\...\{443e579d-41ad-4f89-8680-2dd410815800}.sdb) (Version:  - )
teenSMART v3 (HKLM\...\teenSMART v3 2012.03.06.i_v3) (Version: 2012.03.06.i_v3 - ADEPT)
TrayApp (Version: 82.0.188.000 - Hewlett-Packard) Hidden
Unity Web Player (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Updater Service (HKLM\...\Updater Service) (Version: 14,1,1,3 - ) <==== ATTENTION
User's Guides (HKLM\...\{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}) (Version:  - )
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden
Video Viewer (HKLM\...\Video Viewer) (Version: 0.1.5.0 - )
VideoPad Video Editor (HKLM\...\VideoPad) (Version: 3.29 - NCH Software)
VoiceSupport 1.2.01 (HKLM\...\TC-Helicon VoiceSupport_is1) (Version: 1.2.01 build 38 - TC-Helicon Vocal Technologies Inc.)
WebReg (Version: 82.0.173.000 - Hewlett-Packard) Hidden
Webroot SecureAnywhere (HKLM\...\WRUNINST) (Version: 8.0.8.88 - Webroot)
Windows Driver Package - Nokia Modem  (02/25/2011 4.7) (HKLM\...\E0AC723A3DE3A04256288CADBBB011B112AED454) (Version: 02/25/2011 4.7 - Nokia)
Windows Driver Package - Nokia Modem  (02/25/2011 7.01.0.9) (HKLM\...\72A50F48CC5601190B9C4E74D81161693133E7F7) (Version: 02/25/2011 7.01.0.9 - Nokia)
Windows Driver Package - Nokia pccsmcfd “LegacyDriver”  (05/31/2012 7.1.2.0) (HKLM\...\17D063A0A9F5D5A225B76B1D9BCB5ADBE85C8382) (Version: 05/31/2012 7.1.2.0 - Nokia)
Windows Media Player Firefox Plugin (HKLM\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
WinX DVD Ripper 5.5.12 (HKLM\...\WinX DVD Ripper_is1) (Version:  - Digiarty Software, Inc.)
Yahoo! Browser Services (HKLM\...\Yahoo! Extras) (Version:  - )
Yahoo! BrowserPlus 2.9.8 (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Yahoo! BrowserPlus) (Version:  - Yahoo! Inc.)
Yahoo! Internet Mail (HKLM\...\Yahoo! Mail) (Version:  - )
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{05EC5C13-D255-4592-9CCB-98615172F0D6}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{0ADF9C35-0D5E-4B75-88DD-B64868907E17}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{123FAF7F-3FB1-4B8F-AD18-0047401D436A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{37A2FC00-1795-4679-94A3-A153F1A8BB54}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{37A2FC02-1795-4679-94A3-A153F1A8BB54}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{4052D303-74C5-49EA-BC6B-66099C8D4007}\InprocServer32 -> C:\Program Files\Google\Google Desktop Search\GoogleDesktopAPI2.dll (Google)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\Shayla Potter\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{4716D3CE-55DB-4D2A-818C-87D912895890}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{4844F3F7-2161-4AC4-B219-B3B4311782AA}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{4A56F19E-9F50-4F43-93C8-050E44AA83A9}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{4E5E74B5-8EB5-4859-A335-837EED412620}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{5428A9ED-6CD8-11D6-9C8A-0001023DCAA2}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{547C8F00-5567-4AE3-8BB0-CC3CE2AB9070}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{57D590F1-91EB-44CE-8088-AE4AE19D30A1}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{596801D8-2C9D-4627-9C67-195CB81B655A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{5B7331FA-8910-4748-A8A4-60B445041F28}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{5ED8AC89-B2DE-476D-8EEA-E170B2FCB058}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{6CE4B8A6-4DB5-4F63-8013-1197503692EF}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\YBPAddon_2.9.8.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{738CD606-129D-45db-86D6-6C9739C750CA}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2009\qbw32.exe No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{7694F1CD-A55B-4B7C-8820-A90892EB4E9E}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{76D50904-6780-4c8b-8986-1A7EE0B1716D}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Local\Roblox\Versions\version-c04585a2d58a4f29\RobloxProxy.dll (ROBLOX Corporation)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{7DBF8260-30AD-4D1B-876A-8032B87B809F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{828E5386-74CF-4019-B356-C857CD028A7D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{82CC31B3-53B4-4161-A4E9-6B4F1290A6C8}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{8572570D-12D9-4F2C-8BB8-EB8848178B94}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{885BB46A-3F1E-44C3-A01B-A7D9260CC98B}\InprocServer32 -> C:\Windows\Downloaded Program Files\dwusplay.exe (InstallShield Software Corporation)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{885BB46A-3F1E-44C3-A01B-A7D9260CC98B}\localserver32 -> C:\Windows\Downloaded Program Files\dwusplay.exe (InstallShield Software Corporation)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{8E590317-1329-11D1-B70B-00805F29CD16}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2009\qbw32.exe No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{8FEDE364-AB37-4551-80C9-6D468E222AB2}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F2-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F3-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F4-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F5-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F6-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F7-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{A63E42D0-9C63-47B5-ABF2-0C839EC20778}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{A63E42D2-9C63-47B5-ABF2-0C839EC20778}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{AF5E0A13-CEAB-47CE-991D-77E82CD1BF3F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{B10BFAC3-EFF1-40D9-ADA0-BEBE037C24CA}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{B66F2BF1-91EB-44CE-8088-AE4AE19D30A1}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D14FD6B3-6A9F-4537-9460-07B836707127}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D4A12AAF-E15E-470B-A6B6-63032186F91F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9B9C060-0954-11D3-9E07-00104BD2BE34}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\ViewSource.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6F81-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\cominifile.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6F84-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\cominifile.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6F87-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\cominifile.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6FA1-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\GraphSeriesCol.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6FA6-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\GraphSeriesCol.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6FB2-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\StorageClasses.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{DCB2B478-EFF6-48F6-B718-13E98876854E}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{DFD0AF10-B86C-4AF3-B609-1348D513E565}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{E1A173E1-D957-4C3E-A098-43756A3DB454}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{E1A173E3-D957-4C3E-A098-43756A3DB454}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{EADA914E-5B08-4E85-8440-5A087504DF87}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{EAEF733D-5B08-4E85-8440-5A087504DF87}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{F2C593CC-74B2-4F71-8556-DD4D426D0409}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FAC93D42-FFC2-11d1-9DEB-0008C7A08EBA}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2009\qbw32.exe No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FB17915F-06D1-4214-A902-CC5EE05186E9}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FFF2D28F-E4EE-44D9-8104-8E71556757F6}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe (Macrovision Corporation)
 
==================== Restore Points =========================
 
17-05-2015 03:00:15 Windows Update
18-05-2015 03:00:15 Windows Update
19-05-2015 03:00:15 Windows Update
20-05-2015 03:00:17 Windows Update
20-05-2015 08:24:55 avast! antivirus system restore point
21-05-2015 03:00:13 Windows Update
22-05-2015 03:00:14 Windows Update
23-05-2015 03:00:18 Windows Update
24-05-2015 03:00:16 Windows Update
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2006-11-02 05:23 - 2011-06-27 07:39 - 00000098 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1       localhost
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {03355EE0-16B5-4F55-83C0-8246D6182C05} - System32\Tasks\{21ABCF18-A105-4A65-AD41-D5AD2C4BD073} => pcalua.exe -a "C:\Users\Shayla Potter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RKG1HMTY\Oil-hydraulics and Pneumatics.exe" -d "C:\Users\Shayla Potter\Desktop"
Task: {062C4F4C-8FB5-425A-9408-296D3EBAA594} - System32\Tasks\avastBCLRestartS-1-5-21-1260561122-373576474-2963483527-1005 => Chrome.exe 
Task: {0C6DF14F-9D21-4096-A449-D6E3964A0948} - System32\Tasks\{45671976-48C0-4B2E-BF6B-316085BF803E} => pcalua.exe -a E:\Setup.EXE -d E:\
Task: {165CB006-52E8-41D7-A24B-E9A308C76F61} - System32\Tasks\Microsoft\Support\Microsoft Fix it Center\MatSvc\DataUpload => Rundll32.exe "C:\Program Files\Microsoft Fix it Center\MatsApi.dll",RetryDataUpload
Task: {3C817959-645A-44D8-AFBE-FCF3A93A0A53} - System32\Tasks\ProPCCleaner_Start => C:\Program Files\Pro PC Cleaner\ProPCCleaner.exe <==== ATTENTION
Task: {456EE45A-4B28-41D4-8D6C-AD888CDA4656} - System32\Tasks\{9034CA5D-3868-440B-86CC-25C69343364C} => pcalua.exe -a "C:\Users\Shayla Potter\Desktop\OOo_3.3.0_Win_x86_install-wJRE_en-US.exe" -d "C:\Program Files\OpenOffice.org 3\program"
Task: {46FFC801-6837-49F6-8C1D-B04A4BAD8186} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-17] (Google Inc.)
Task: {49375187-C007-489A-96FD-A4331B62CAA7} - System32\Tasks\{C8563973-8E65-4A6A-BD02-D5B9A3C53F34} => pcalua.exe -a "C:\Users\Shayla Potter\Downloads\DesignPro5_4_Limited.exe" -d "C:\Program Files\Mozilla Firefox"
Task: {51B45166-C42C-4D32-BEEE-57D03E6E90B2} - System32\Tasks\{A4F70E4C-DCD9-4BD1-9A74-05EC7CAE49FC} => pcalua.exe -a C:\Windows\UninstallWSST.exe -c C:\Windows\UninstallLog0.log
Task: {54C60829-63CA-4F9F-9EC5-6D8404816914} - System32\Tasks\{EAFD04C2-A123-4CFF-B1F3-9CB4BE8C264A} => pcalua.exe -a "C:\Users\Shayla Potter\AppData\Roaming\Juniper Networks\Setup Client\JuniperSetupClientOCX.exe" -d "C:\Users\Shayla Potter\AppData\Roaming\Juniper Networks\Setup Client"
Task: {54CABFE2-787C-42EF-B335-0C6CDC2F147B} - System32\Tasks\{3C8083DF-4F53-4A31-A3EB-F969F7824170} => pcalua.exe -a "C:\Users\Shayla Potter\AppData\Local\Temp\Temp1_SolveigMM_AVI_Trimmer_1_6.zip\SolveigMM AVI Trimmer 1.6.1004.1.exe"
Task: {54F403D9-FC9A-4DAB-B396-3AD998C41E44} - System32\Tasks\{50958F2E-F646-4D8D-8E98-15E6B196B038} => pcalua.exe -a "E:\Setup\SmartSound\SmartSound Pinnacle Music.exe" -d E:\Setup\SmartSound
Task: {741DFBC8-7F9B-4971-9F65-67D1F1913E6B} - System32\Tasks\{FDA6F372-7FB8-441A-8819-BE9BD048413C} => pcalua.exe -a C:\Users\Mason\Downloads\tremulous-gpp1-installer.exe -d "C:\Program Files\Mozilla Firefox"
Task: {752E18DC-EE40-4A9E-8BF8-0D303F149432} - System32\Tasks\ProPCCleaner_Popup => C:\Program Files\Pro PC Cleaner\Splash.exe <==== ATTENTION
Task: {75BF9F2D-C582-441B-B90E-5C38A5A3A42A} - System32\Tasks\{ED4D5BE0-EA6C-4C9B-B997-5EC5FD4D0293} => pcalua.exe -a C:\Windows\system32\spool\drivers\w32x86\3\LXBKUN5C.EXE -c -dLexmark X1100 Series
Task: {7C0B4593-099D-4250-B068-34E23B7E8F2C} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - John => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation)
Task: {7E4A1DF3-9143-466F-9E36-4CCCD05EA138} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1260561122-373576474-2963483527-1005 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {8F1CAA9C-3433-4988-A755-A090D6A4A0CA} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15] (Adobe Systems Incorporated)
Task: {9E2E6518-A90A-4A86-8EB9-A9102BEB6485} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1260561122-373576474-2963483527-1005 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {A2426F58-A4A4-4B9B-8C0F-4EDC3D08DD4A} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {A48BE931-597A-4DAB-A4E1-09FA0A3E562C} - System32\Tasks\{C02B8D0C-1162-40AF-BE6C-63EC2AC5F650} => pcalua.exe -a "C:\Users\Shayla Potter\AppData\Local\Temp\Temp1_NokiaFREE_v310_Nokia_unlock_codes_calculator.zip\NokiaFREE_v310_Setup.exe"
Task: {A5FDC1D4-062A-4D85-9118-1BAA915FC980} - System32\Tasks\{41C22683-681B-47FF-9397-8FD2479D50AA} => pcalua.exe -a "C:\Remote Programs\Cradle of Rome\GPlrLanc.exe" -c -LOpCode 2 /RemoveContent cid=554750;name=Cradle of Rome;dir=C:\Remote Programs\Cradle of Rome\;prvid=143;cmdid=1;prvdir=Default
Task: {AA406F1B-464D-453A-92EA-EE7034CBE763} - System32\Tasks\Microsoft\Support\Microsoft Fix it Center\ConfigExec => Rundll32.exe "C:\Program Files\Microsoft Fix it Center\MatsApi.dll",RunCollectConfigurationInfo
Task: {B21A0D53-D398-4DC4-9FD5-9D4D3982566C} - System32\Tasks\ASC6_PerformanceMonitor => C:\Program Files\IObit\Advanced SystemCare 6\Monitor.exe
Task: {B8FECB13-473F-421C-AB70-E4CA7AB02702} - System32\Tasks\Google Software Updater => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-09-06] (Google)
Task: {C4D40DC6-1BE5-4C0F-93DF-D826422DBBE3} - System32\Tasks\ASC6_AutoClean => C:\Program Files\IObit\Advanced SystemCare 6\AutoSweep.exe
Task: {CED9A2C2-17F5-4000-9EC0-FE7C55E932A5} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Shayla Potter => C:\Program Files\Windows Calendar\wincal.exe [2009-04-11] (Microsoft Corporation)
Task: {D15D7662-D7F0-4EC1-BAA9-43730788AB69} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-17] (Google Inc.)
Task: {D18E439B-CB86-4ABF-A540-D57FA4C67AE6} - System32\Tasks\Microsoft\Support\Microsoft Fix it Center\OSUpgrade => Rundll32.exe "C:\Program Files\Microsoft Fix it Center\MatsApi.dll",RunHandleOSUpgrade
Task: {DBA60EE5-FD45-4F8D-915B-63B7914576AB} - System32\Tasks\{D676CE09-B41A-4987-A399-30C5FD39FBD5} => pcalua.exe -a "E:\Setup\SmartSound\Quicktracks Installer.exe" -d E:\Setup\SmartSound
Task: {DC8A53C9-9AC3-4B83-9A73-2C60B51686DC} - System32\Tasks\{CC778C55-1B0F-45F6-8EDB-B61CF4D59627} => pcalua.exe -a C:\DELL\E-Center\UninstallTB.exe -d C:\Windows\system32
Task: {EDC61C3C-3C8E-43E5-98BF-E3D87E739FA4} - System32\Tasks\LaunchSignup => C:\Program Files\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: {F3E8BD86-FB5F-48D0-97E0-3735989215EB} - System32\Tasks\{2204B856-631C-4373-A2EF-97C58CFBDAB7} => pcalua.exe -a "C:\Live! Cam\WCVista_1_11_01\VfwUpd.EXE" -d "C:\Live! Cam\WCVista_1_11_01"
Task: {FD573624-6E72-4FEF-9B56-71DF8A4F476F} - System32\Tasks\{77747B11-1225-42CF-B24A-54846703B0D7} => pcalua.exe -a C:\Windows\system32\javacpl.cpl -c Java
Task: {FE177C28-BD05-45B6-BA0D-BAF8FBDFCF07} - System32\Tasks\{086D66E6-23E3-4FA5-8CE0-046817135B3D} => pcalua.exe -a C:\Users\Mason\Desktop\dotnetfx3setup.exe -d C:\Users\Mason\Desktop
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Google Software Updater.job => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2007-12-07 13:59 - 2006-10-06 07:06 - 00045056 _____ () C:\Windows\System32\DLPRMON.DLL
2007-12-07 13:59 - 2006-10-06 07:24 - 00016384 _____ () C:\Program Files\Dell PC Fax\DlCtrStr.dll
2007-12-07 13:59 - 2006-10-06 07:04 - 00032768 _____ () C:\Program Files\Dell PC Fax\ipcmt.dll
2009-06-29 10:22 - 2009-06-29 10:23 - 00051716 _____ () C:\Windows\System32\pdf995mon.dll
2007-12-07 14:04 - 2006-10-20 00:33 - 00117760 _____ () C:\Windows\system32\spool\PRTPROCS\W32X86\dlcxdrpp.dll
2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-08-14 16:19 - 2013-08-14 16:19 - 00039056 _____ () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
2006-11-05 10:28 - 2006-11-05 10:28 - 04587520 ____R () C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\ROXIPP41.dll
2013-01-21 19:09 - 2012-11-09 06:02 - 01752576 _____ () C:\Program Files\File Shredder\fsshell.dll
2007-11-21 11:21 - 2010-06-22 16:47 - 00034816 _____ () C:\Program Files\Google\Google Desktop Search\gzlib.dll
2007-12-07 14:00 - 2007-01-12 11:57 - 00292336 _____ () C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
2007-12-07 14:00 - 2006-08-08 14:54 - 00278528 _____ () C:\Program Files\Dell Photo AIO Printer 926\dlcxscw.dll
2007-12-07 14:00 - 2006-09-06 05:13 - 00073728 _____ () C:\Program Files\Dell Photo AIO Printer 926\dlcxcfg.dll
2007-12-07 14:00 - 2006-11-03 17:04 - 00304008 _____ () C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
2013-11-14 19:48 - 2013-11-14 19:48 - 01861968 _____ () C:\Program Files\DivX\DivX Update\DivXUpdate.exe
2013-11-14 19:49 - 2013-11-14 19:49 - 00100688 _____ () C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
2012-06-26 14:11 - 2012-06-26 14:11 - 02302040 _____ () C:\Users\Shayla Potter\Desktop\Kierans folder\Nokia PC Suite 7\QtCore4.dll
2012-06-26 14:11 - 2012-06-26 14:11 - 08197208 _____ () C:\Users\Shayla Potter\Desktop\Kierans folder\Nokia PC Suite 7\QtGui4.dll
2012-06-26 14:11 - 2012-06-26 14:11 - 00345688 _____ () C:\Users\Shayla Potter\Desktop\Kierans folder\Nokia PC Suite 7\QtXml4.dll
2013-07-10 18:57 - 2009-10-07 15:42 - 00061440 ____N () C:\Windows\system32\wintab32.dll
2012-06-26 14:10 - 2012-06-26 14:10 - 00202328 _____ () C:\Users\Shayla Potter\Desktop\Kierans folder\Nokia PC Suite 7\imageformats\qjpeg4.dll
2012-06-26 14:10 - 2012-06-26 14:10 - 00027736 _____ () C:\Users\Shayla Potter\Desktop\Kierans folder\Nokia PC Suite 7\imageformats\qsvg4.dll
2012-06-26 14:11 - 2012-06-26 14:11 - 00282200 _____ () C:\Users\Shayla Potter\Desktop\Kierans folder\Nokia PC Suite 7\QtSvg4.dll
2013-09-28 20:14 - 2013-09-28 20:14 - 03369922 _____ () C:\Program Files\NETGEAR Genie\bin\icuin51.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00544817 _____ () C:\Program Files\NETGEAR Genie\bin\libgcc_s_dw2-1.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00989805 _____ () C:\Program Files\NETGEAR Genie\bin\libstdc++-6.dll
2013-09-28 20:14 - 2013-09-28 20:14 - 01978690 _____ () C:\Program Files\NETGEAR Genie\bin\icuuc51.dll
2013-09-28 20:14 - 2013-09-28 20:14 - 22378434 _____ () C:\Program Files\NETGEAR Genie\bin\icudt51.dll
2013-09-28 20:14 - 2013-09-28 20:14 - 01233408 _____ () C:\Program Files\NETGEAR Genie\bin\platforms\qwindows.dll
2015-01-09 01:40 - 2015-01-09 01:40 - 00640000 _____ () C:\Program Files\NETGEAR Genie\bin\Genie.dll
2014-12-19 01:03 - 2014-12-19 01:03 - 01686016 _____ () C:\Program Files\NETGEAR Genie\bin\SvtNetworkTool.dll
2015-01-09 01:01 - 2015-01-09 01:01 - 00192512 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_Airprint.dll
2014-11-05 02:37 - 2014-11-05 02:37 - 00632832 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_Internet.dll
2015-01-09 01:03 - 2015-01-09 01:03 - 06477824 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_Map.dll
2014-06-29 20:55 - 2014-06-29 20:55 - 00068608 _____ () C:\Program Files\NETGEAR Genie\bin\QRCode.dll
2014-06-29 21:05 - 2014-06-29 21:05 - 01183232 _____ () C:\Program Files\NETGEAR Genie\bin\qwt.dll
2015-01-07 20:57 - 2015-01-07 20:57 - 02493952 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_MyMedia.dll
2012-10-15 15:27 - 2012-10-15 15:27 - 00111616 _____ () C:\Program Files\NETGEAR Genie\bin\libvlc.dll
2012-10-15 15:28 - 2012-10-15 15:28 - 02286592 _____ () C:\Program Files\NETGEAR Genie\bin\libvlccore.dll
2014-12-05 00:32 - 2014-12-05 00:32 - 01056768 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_NetworkProblem.dll
2014-09-11 03:39 - 2014-09-11 03:39 - 00144896 _____ () C:\Program Files\NETGEAR Genie\bin\DragonNetTool.dll
2015-01-09 01:03 - 2015-01-09 01:03 - 01195008 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_ParentalControl.dll
2015-01-14 00:45 - 2015-01-14 00:45 - 10388480 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_Resource.dll
2015-01-14 22:04 - 2015-01-14 22:04 - 02545664 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_RouterConfiguration.dll
2014-12-18 02:49 - 2014-12-18 02:49 - 00177152 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_Statistics.dll
2014-12-05 00:35 - 2014-12-05 00:35 - 00890368 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_Ui.dll
2014-11-05 03:00 - 2014-11-05 03:00 - 00435712 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_Wireless.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00051200 _____ () C:\Program Files\NETGEAR Genie\bin\imageformats\qgif.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00052224 _____ () C:\Program Files\NETGEAR Genie\bin\imageformats\qico.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00261120 _____ () C:\Program Files\NETGEAR Genie\bin\imageformats\qjpeg.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00046080 _____ () C:\Program Files\NETGEAR Genie\bin\imageformats\qsvg.dll
2014-06-29 20:55 - 2014-06-29 20:55 - 00081408 _____ () C:\Program Files\NETGEAR Genie\bin\DiagnosePlugin.dll
2014-11-03 03:23 - 2014-11-03 03:23 - 00143360 _____ () C:\Program Files\NETGEAR Genie\bin\DiagnoseDll.dll
2014-06-18 21:22 - 2014-06-18 21:22 - 02177405 _____ () C:\Program Files\NETGEAR Genie\bin\drivers\libntgr_api.dll
2014-09-04 01:00 - 2014-09-04 01:00 - 00072192 _____ () C:\Program Files\NETGEAR Genie\bin\SVTUtils.dll
2014-09-04 01:00 - 2014-09-04 01:00 - 00074240 _____ () C:\Program Files\NETGEAR Genie\bin\NetcardApi.dll
2014-09-04 01:00 - 2014-09-04 01:00 - 00136704 _____ () C:\Program Files\NETGEAR Genie\bin\airprintdll.dll
2012-10-15 15:28 - 2012-10-15 15:28 - 00219648 _____ () C:\Program Files\NETGEAR Genie\bin\plugins\access\libdshow_plugin.dll
2012-10-15 15:28 - 2012-10-15 15:28 - 00049664 _____ () C:\Program Files\NETGEAR Genie\bin\plugins\audio_output\libaout_directx_plugin.dll
2012-10-15 15:28 - 2012-10-15 15:28 - 00051200 _____ () C:\Program Files\NETGEAR Genie\bin\plugins\audio_output\libwaveout_plugin.dll
2012-10-15 15:28 - 2012-10-15 15:28 - 00070144 _____ () C:\Program Files\NETGEAR Genie\bin\plugins\video_output\libdirectx_plugin.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00040960 _____ () C:\Program Files\NETGEAR Genie\bin\printsupport\windowsprintersupport.dll
2010-01-18 23:58 - 2007-01-25 13:25 - 00117248 _____ () C:\Windows\system32\spool\DRIVERS\W32X86\3\hpzpi4wm.DLL
2014-11-05 02:59 - 2014-11-05 02:59 - 00642048 _____ () C:\Program Files\NETGEAR Genie\bin\InnerPlugin_Update.dll
2014-11-05 03:01 - 2014-11-05 03:01 - 00458752 _____ () C:\Program Files\NETGEAR Genie\bin\InnerPlugin_WirelessExport.dll
2014-06-29 21:33 - 2014-06-29 21:33 - 00046080 _____ () C:\Program Files\NETGEAR Genie\bin\WSetupApiPlugin.dll
2014-09-04 01:00 - 2014-09-04 01:00 - 00066560 _____ () C:\Program Files\NETGEAR Genie\bin\WSetupDll.dll
2015-05-20 14:08 - 2015-05-20 14:08 - 00043008 _____ () c:\Users\Shayla Potter\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmptpwcn5.dll
2015-03-04 16:45 - 2015-03-04 16:45 - 00750080 _____ () C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2015-03-04 16:45 - 2015-03-04 16:45 - 00047616 _____ () C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\libEGL.dll
2015-03-04 16:45 - 2015-03-04 16:45 - 00865280 _____ () C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
2015-03-04 16:45 - 2015-03-04 16:45 - 00200704 _____ () C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
2007-04-03 16:58 - 2007-04-03 16:58 - 00020572 _____ () C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
2007-04-03 16:58 - 2007-04-03 16:58 - 00802901 _____ () C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\hotspot\jvm.dll
2007-04-03 16:58 - 2007-04-03 16:58 - 00028776 _____ () C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\hpi.dll
2007-04-03 16:58 - 2007-04-03 16:58 - 00053342 _____ () C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\verify.dll
2007-04-03 16:58 - 2007-04-03 16:58 - 00094308 _____ () C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\java.dll
2007-04-03 16:58 - 2007-04-03 16:58 - 00053349 _____ () C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\zip.dll
2007-04-03 16:58 - 2007-04-03 16:58 - 00032864 _____ () C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\net.dll
2004-08-20 07:02 - 2004-08-20 07:02 - 00102400 _____ () C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\PMLJNI.dll
2005-02-03 11:31 - 2005-02-03 11:31 - 00032768 _____ () C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\compJNI.dll
2014-12-14 21:27 - 2014-12-14 21:27 - 00105216 _____ () C:\Program Files\NETGEAR Genie\bin\genie2_tray.exe
2013-07-11 13:33 - 2013-07-11 13:33 - 00988160 _____ () C:\Program Files\OpenOffice 4\program\libxml2.dll
2013-07-10 22:08 - 2013-07-10 22:08 - 00170496 _____ () C:\Program Files\OpenOffice 4\program\libxslt.dll
2013-07-10 22:08 - 2013-07-10 22:08 - 00136192 _____ () C:\Program Files\OpenOffice 4\program\libxmlsec-mscrypto.dll
2013-07-10 22:08 - 2013-07-10 22:08 - 00303616 _____ () C:\Program Files\OpenOffice 4\program\libxmlsec.dll
2015-05-20 19:37 - 2015-05-13 11:48 - 14982472 _____ () C:\Program Files\Google\Chrome\Application\43.0.2357.65\PepperFlash\pepflashplayer.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\TEMP:08AC8A76
AlternateDataStreams: C:\ProgramData\TEMP:376AEA88
AlternateDataStreams: C:\ProgramData\TEMP:69F4A9BE
AlternateDataStreams: C:\ProgramData\TEMP:819BEFD3
AlternateDataStreams: C:\ProgramData\TEMP:81A5201B
AlternateDataStreams: C:\ProgramData\TEMP:8EC55520
AlternateDataStreams: C:\ProgramData\TEMP:A52C3C4A
AlternateDataStreams: C:\ProgramData\TEMP:AA3339BE
AlternateDataStreams: C:\ProgramData\TEMP:AD6273E0
AlternateDataStreams: C:\ProgramData\TEMP:D1B5B4F1
AlternateDataStreams: C:\ProgramData\TEMP:E33EA293
AlternateDataStreams: C:\ProgramData\TEMP:EA031481
AlternateDataStreams: C:\ProgramData\TEMP:FE53E4F7
AlternateDataStreams: C:\Users\Shayla Potter\Downloads\Fireworks Soundtrack 2012(Final2).mp3:TOC.WMV
AlternateDataStreams: C:\Users\Shayla Potter\Downloads\The.Event.S01E09.HDTV.XviD-LOL.avi:TOC.WMV
AlternateDataStreams: C:\Users\Shayla Potter\Downloads\The.Event.S01E10.HDTV.XviD-LOL.avi:TOC.WMV
 
==================== Safe Mode (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NTRSupport => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\100sexlinks.com -> 100sexlinks.com
 
There are 4788 more restricted sites.
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\Control Panel\Desktop\\Wallpaper -> C:\Users\Shayla Potter\Pictures\pics fpr screen saver\6toes.jpg
DNS Servers: 192.168.1.1
 
==================== MSCONFIG/TASK MANAGER Error getting ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [{3A9BE981-441E-4189-BACF-E5819B128C8A}] => (Allow) LPort=5500
FirewallRules: [{58B87AC9-0464-412B-9CCB-AC4BA07A473A}] => (Allow) LPort=5800
FirewallRules: [{320054C4-DEB8-4917-8C4B-A1733FCF603B}] => (Allow) LPort=5900
FirewallRules: [TCP Query User{24D4599C-C072-4D0B-9FBD-0E458620D486}C:\program files\internet explorer\iexplore.exe] => (Allow) C:\program files\internet explorer\iexplore.exe
FirewallRules: [UDP Query User{3186032E-8748-4002-ACBF-8857533B79D8}C:\program files\internet explorer\iexplore.exe] => (Allow) C:\program files\internet explorer\iexplore.exe
FirewallRules: [{5D127D00-8459-4860-B615-586AD6CA3746}] => (Allow) C:\Program Files\Dell Photo AIO Printer 926\dlcxaiox.exe
FirewallRules: [{77E7AB39-D552-40FC-9E32-A45840AB6CEA}] => (Allow) C:\Program Files\Dell Photo AIO Printer 926\dlcxaiox.exe
FirewallRules: [{A87FD550-32E3-4F0F-BC1C-47B55B3B3B4B}] => (Allow) LPort=135
FirewallRules: [{0AD58039-680E-490D-BF66-34028BF77850}] => (Allow) LPort=5000
FirewallRules: [{C1B08FC5-7838-49CE-BB00-D0C0AB9DF7AD}] => (Allow) LPort=5001
FirewallRules: [{29CE1D4B-0B59-4C54-9653-DDAFFB740CB2}] => (Allow) LPort=5002
FirewallRules: [{706662D2-F4C6-47AB-AEFC-9736034DFA6F}] => (Allow) LPort=5003
FirewallRules: [{13A4D1AF-FFDD-42BC-8AE4-60E8AE0CF8A8}] => (Allow) LPort=5004
FirewallRules: [{4E2B0263-67A2-4470-A3B2-67ED7D8BF6CB}] => (Allow) LPort=5005
FirewallRules: [{B4D621D2-7AFB-4E79-8A76-B36A2D02A61B}] => (Allow) LPort=5006
FirewallRules: [{5CE508DF-71C7-4616-8441-3FBFA3AD1313}] => (Allow) LPort=5007
FirewallRules: [{3E2F141C-71B3-4AF5-91BE-7F72E308ECB7}] => (Allow) LPort=5008
FirewallRules: [{0D3DEC16-FC11-4A90-AED0-20DE7D0C036D}] => (Allow) LPort=5009
FirewallRules: [{25DF0357-1CFA-4BBE-8AD2-918D5F501D35}] => (Allow) LPort=5010
FirewallRules: [{A99E3085-ACB1-4DDB-A2D9-2685FF10540A}] => (Allow) LPort=5011
FirewallRules: [{53DEC965-B95E-426C-A0DE-4BE9EC11BB7F}] => (Allow) LPort=5012
FirewallRules: [{68BC4BB3-EDAF-4989-80FF-F506E718F13E}] => (Allow) LPort=5013
FirewallRules: [{BEE7137B-19A3-4AD1-B974-4E131413DC63}] => (Allow) LPort=5014
FirewallRules: [{3E356141-4DC0-416B-9510-017A0D9FB53C}] => (Allow) LPort=5015
FirewallRules: [{FA2BD1D6-96C4-46DA-9931-A52F4F0852DC}] => (Allow) LPort=5016
FirewallRules: [{BCDC9A8B-9D78-47B7-A756-2F26593BF6C5}] => (Allow) LPort=5017
FirewallRules: [{001762D0-4C4E-4A25-A61C-9AAD6D7C0AB0}] => (Allow) LPort=5018
FirewallRules: [{C5FFE75E-3AD0-4B0B-9AB2-0146F4F6E223}] => (Allow) LPort=5019
FirewallRules: [{9ED89B40-CA25-4E41-AFDD-3B23D7598C5E}] => (Allow) LPort=5020
FirewallRules: [TCP Query User{03377708-7AA7-4AFB-93E0-884D368DA5D4}C:\program files\internet explorer\iexplore.exe] => (Allow) C:\program files\internet explorer\iexplore.exe
FirewallRules: [UDP Query User{FCA6B8BB-D1B1-43BF-BA25-EC5E7F2FD8BF}C:\program files\internet explorer\iexplore.exe] => (Allow) C:\program files\internet explorer\iexplore.exe
FirewallRules: [{CF3F1C2E-12B5-47B5-8614-EEA33474929F}] => (Allow) C:\Program Files\AVG\AVG8\avgemc.exe
FirewallRules: [{C27A2989-753C-4545-96EC-06E5B89D85B9}] => (Allow) C:\Program Files\AVG\AVG8\avgupd.exe
FirewallRules: [{CDE64441-851E-4950-9086-D36CED50AF12}] => (Allow) C:\Program Files\AVG\AVG8\avgnsx.exe
FirewallRules: [TCP Query User{8D7C38D2-21C3-46D9-9661-A82E89AFBE70}C:\program files\hewlett-packard\toolbox\jre\bin\javaw.exe] => (Allow) C:\program files\hewlett-packard\toolbox\jre\bin\javaw.exe
FirewallRules: [UDP Query User{2A5BC021-2D22-4643-82FE-DCD281942E2F}C:\program files\hewlett-packard\toolbox\jre\bin\javaw.exe] => (Allow) C:\program files\hewlett-packard\toolbox\jre\bin\javaw.exe
FirewallRules: [TCP Query User{BC94B49A-88ED-4BBA-9A50-62021F9065E7}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{138757B8-CB9B-4030-8527-B3CD9959604F}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{B3126AE1-D2C2-4A1D-BE57-D46BB2E7AEE7}] => (Allow) C:\Program Files\RealVNC\VNC4\vncviewer.exe
FirewallRules: [{50B98344-50AC-4A0C-ADEE-1A4E26C88D3E}] => (Allow) C:\Program Files\RealVNC\VNC4\vncviewer.exe
FirewallRules: [TCP Query User{A367A5EE-4A01-431B-AD71-5E30E127811E}C:\program files\yahoo!\messenger\yahoomessenger.exe] => (Allow) C:\program files\yahoo!\messenger\yahoomessenger.exe
FirewallRules: [UDP Query User{2AA150C8-3FF6-41C0-8A4A-B50B6C9C8854}C:\program files\yahoo!\messenger\yahoomessenger.exe] => (Allow) C:\program files\yahoo!\messenger\yahoomessenger.exe
FirewallRules: [{1BE1B989-8549-489D-91EB-5DD7EDCC87ED}] => (Allow) C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe
FirewallRules: [{66411175-1426-41E1-93AA-64B83B25236E}] => (Allow) C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe
FirewallRules: [{900F444D-979D-477E-B4BE-DB59F94F95DA}] => (Allow) LPort=5225
FirewallRules: [{72376B2E-0624-439C-A013-EB2EBD676A54}] => (Allow) LPort=5225
FirewallRules: [TCP Query User{0953E3C5-8959-49AF-9DBE-BE59A3050DB6}C:\program files\hewlett-packard\toolbox\jre\bin\javaw.exe] => (Allow) C:\program files\hewlett-packard\toolbox\jre\bin\javaw.exe
FirewallRules: [UDP Query User{4B0FF1CB-1D13-4732-8A72-E80B0EF9AC57}C:\program files\hewlett-packard\toolbox\jre\bin\javaw.exe] => (Allow) C:\program files\hewlett-packard\toolbox\jre\bin\javaw.exe
FirewallRules: [TCP Query User{77666501-3BDC-45D9-B0CE-69F1FB5742BC}C:\program files\java\jre1.6.0\bin\java.exe] => (Block) C:\program files\java\jre1.6.0\bin\java.exe
FirewallRules: [UDP Query User{B17062E3-2543-4DB6-893F-C9512144B9E8}C:\program files\java\jre1.6.0\bin\java.exe] => (Block) C:\program files\java\jre1.6.0\bin\java.exe
FirewallRules: [{ECA43E07-17DD-4C05-B171-746120C337E0}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{FA47773A-8DF9-4057-A4DB-E6A15E6E1AFA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7895B3EC-DEE2-4A4F-B71F-68DD7B2A7980}] => (Allow) C:\Windows\System32\dlcxcoms.exe
FirewallRules: [{4BE5E731-F4D1-4982-A9E4-CDBBC1AE6ED6}] => (Allow) C:\Windows\System32\dlcxcoms.exe
FirewallRules: [{16620345-D660-4F83-A157-D6A550481CAA}] => (Allow) C:\Program Files\Yahoo!\Messenger\YServer.exe
FirewallRules: [{B7C507E3-79E6-4FB5-82D5-3D12B43976DF}] => (Allow) C:\Program Files\Yahoo!\Messenger\YServer.exe
FirewallRules: [{D47F953B-0260-463C-BCF2-2AC9803E3C10}] => (Allow) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{E2996B45-E2E6-46ED-BD32-20811C1E172A}] => (Allow) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{CD116ACA-3788-47AD-B827-3761FAED4DB8}] => (Allow) C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe
FirewallRules: [{B6810223-1757-4AAB-B794-3B92F7825FC9}] => (Allow) C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe
FirewallRules: [{5A019ABC-883E-47E4-BA41-3F3CE3A42EC3}] => (Allow) C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
FirewallRules: [{6116FC38-AD5D-4A39-9ED6-EF6606412FCD}] => (Allow) C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
FirewallRules: [TCP Query User{0CFA288E-2F72-49CB-ADB4-C77FD4ACA2E8}C:\windows\system32\notepad.exe] => (Allow) C:\windows\system32\notepad.exe
FirewallRules: [UDP Query User{A9CFD4DA-6A14-4EE3-8291-6FF544161FC3}C:\windows\system32\notepad.exe] => (Allow) C:\windows\system32\notepad.exe
FirewallRules: [TCP Query User{E4467E63-334B-4AE8-BF25-7BEE8235CA9A}C:\program files\google\google earth\plugin\geplugin.exe] => (Block) C:\program files\google\google earth\plugin\geplugin.exe
FirewallRules: [UDP Query User{DF4A6181-866D-43BF-9FC7-577CA8AF19D7}C:\program files\google\google earth\plugin\geplugin.exe] => (Block) C:\program files\google\google earth\plugin\geplugin.exe
FirewallRules: [{B0888647-0174-4BDE-8B14-7D7E62DF5344}] => (Allow) LPort=80
FirewallRules: [{288FEDC6-0B73-40CF-AB4B-B9A013F91CB8}] => (Allow) LPort=80
FirewallRules: [{3ADB8FE2-EC6A-4440-A2B7-DFFA09FD84DE}] => (Allow) LPort=80
FirewallRules: [TCP Query User{DD49B455-91A7-447A-A147-86754DB4AEBF}C:\program files\team17\worms armageddon\wa.exe] => (Allow) C:\program files\team17\worms armageddon\wa.exe
FirewallRules: [UDP Query User{C812A600-96BB-4D24-88CA-E1D63224E64B}C:\program files\team17\worms armageddon\wa.exe] => (Allow) C:\program files\team17\worms armageddon\wa.exe
FirewallRules: [{4C72611F-769D-483D-AD1B-DA52358E9DD7}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\RM.exe
FirewallRules: [{7FCBF118-5344-41FC-93D9-4FD35E1BC8F9}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\RM.exe
FirewallRules: [{AF036FE1-D9A2-42DA-92AE-4BF5D3CD2DAD}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe
FirewallRules: [{4B6D640A-2938-4EB4-8FCB-617C179F5E0E}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe
FirewallRules: [{A3065E18-DD4B-407B-9CF5-E1664CDACF22}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\RM.exe
FirewallRules: [{0AA081F3-B548-4787-BAC3-457C6E3340ED}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\RM.exe
FirewallRules: [{8E8CA268-7C0A-4B7F-9DE3-D9F14EF177CE}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe
FirewallRules: [{96DB8F73-6CAD-4F86-B9A0-1C5EDE61B83F}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe
FirewallRules: [{9D50495F-2108-4648-BCA0-03BB03ED3E21}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe
FirewallRules: [{6970A4D6-F35B-44FC-A15E-A094E203ABFF}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe
FirewallRules: [{EEA71786-1D86-4154-ACD7-7A41581CC210}] => (Allow) C:\Program Files\Pinnacle\Shared Files\Programs\MediaManager\PMSManager.exe
FirewallRules: [{B3C5C46C-9762-44B1-849B-C8B6DBEFF408}] => (Allow) C:\Program Files\Pinnacle\Shared Files\Programs\MediaManager\PMSManager.exe
FirewallRules: [{6E1B3C88-641E-4168-A2AF-93FC222BE9DB}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\umi.exe
FirewallRules: [{9A5210EB-2829-4809-A21B-2A9FF6027EAE}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\umi.exe
FirewallRules: [TCP Query User{92E11C77-8470-4748-BCCE-0E850A28E516}C:\program files\pinnacle\shared files\programs\mediamanager\pmsmanager.exe] => (Allow) C:\program files\pinnacle\shared files\programs\mediamanager\pmsmanager.exe
FirewallRules: [UDP Query User{FAFC9B9B-A91F-464E-B2BE-862D8C57A791}C:\program files\pinnacle\shared files\programs\mediamanager\pmsmanager.exe] => (Allow) C:\program files\pinnacle\shared files\programs\mediamanager\pmsmanager.exe
FirewallRules: [TCP Query User{CBB45A30-67A4-4BE3-8B2F-BEB07056CB2A}C:\program files\videoviewer\videoviewer.exe] => (Block) C:\program files\videoviewer\videoviewer.exe
FirewallRules: [UDP Query User{23F744A0-717C-405A-B48E-BC34D0170158}C:\program files\videoviewer\videoviewer.exe] => (Block) C:\program files\videoviewer\videoviewer.exe
FirewallRules: [{5746ED1C-3542-4082-9717-59520FE697DE}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\ibtmpe88488\component_52.decrpt
FirewallRules: [{7710437B-2E16-4F8E-B989-E674C02E97D7}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\ibtmpe88488\component_138.decrpt
FirewallRules: [{06C4CF6A-8D7D-4479-8288-72149D5EFB16}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\ibtmpe88488\component_71.decrpt
FirewallRules: [TCP Query User{C44B8311-88EE-43F3-8EAF-886F27BE8F91}C:\program files\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files\netgear genie\bin\netgeargenie.exe
FirewallRules: [UDP Query User{29C0C165-6753-43C3-AC94-6F458D587E9F}C:\program files\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files\netgear genie\bin\netgeargenie.exe
FirewallRules: [{04671719-1204-47B5-8CE0-3766BA80447B}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\dyq9vwst418qg7qvx408\component_1.decrpt
FirewallRules: [TCP Query User{300522B8-B9B1-4DBF-B1F8-55AA486C3244}C:\program files\netgear genie\bin\netgeargenie.exe] => (Block) C:\program files\netgear genie\bin\netgeargenie.exe
FirewallRules: [UDP Query User{5D00D852-6AFD-487E-82A7-1E83E1F18701}C:\program files\netgear genie\bin\netgeargenie.exe] => (Block) C:\program files\netgear genie\bin\netgeargenie.exe
FirewallRules: [TCP Query User{720FB80F-2E0D-4D90-A249-D7CF054DE729}C:\program files\google\chrome\application\chrome.exe] => (Block) C:\program files\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{7CB2C5FE-D42A-4A87-883C-11E9CEFF2C4D}C:\program files\google\chrome\application\chrome.exe] => (Block) C:\program files\google\chrome\application\chrome.exe
FirewallRules: [TCP Query User{CC3A7C5D-5267-43DE-8CE5-8A2567DEF4B5}C:\program files\mozilla firefox\plugin-container.exe] => (Allow) C:\program files\mozilla firefox\plugin-container.exe
FirewallRules: [UDP Query User{0743C5E9-351F-41CB-B430-7014DF0F5136}C:\program files\mozilla firefox\plugin-container.exe] => (Allow) C:\program files\mozilla firefox\plugin-container.exe
FirewallRules: [{A104D517-3E9B-4F61-BF2C-82AC188FB153}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{960A0CF4-CF46-4C96-A8E0-5B3B9AC97E26}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{44399A32-BA2F-4FC0-BC70-8A0E8FD0FBF7}] => (Allow) C:\Program Files\iWin Games\iWinGames.exe
FirewallRules: [{A489724F-5A4A-4FA7-8C44-D41D8032F469}] => (Allow) C:\Program Files\iWin Games\iWinGames.exe
FirewallRules: [{5CB2FD23-1816-4740-BBAB-D416D55EB5DE}] => (Allow) C:\Program Files\iWin Games\WebUpdater.exe
FirewallRules: [{ED69E852-B26F-479B-8E00-B98B5044B0FC}] => (Allow) C:\Program Files\iWin Games\WebUpdater.exe
FirewallRules: [{AA15602D-9D18-4CB5-9762-720B79C11F61}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe
FirewallRules: [{87026E34-24B2-459A-8669-393E8EBAFF45}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe
FirewallRules: [TCP Query User{B8DFEA0F-4D12-4138-AFB3-A2419BD5D474}C:\program files\tmnationsforever\tmforever.exe] => (Allow) C:\program files\tmnationsforever\tmforever.exe
FirewallRules: [UDP Query User{C9B631DF-944E-4873-91F6-B28CACD9C6C3}C:\program files\tmnationsforever\tmforever.exe] => (Allow) C:\program files\tmnationsforever\tmforever.exe
FirewallRules: [{170550A7-709A-47E0-BB98-DB67EDF19D8E}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\umi.exe
FirewallRules: [{6395D1B7-EC14-4ED0-8018-4F6FB8669AB6}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\umi.exe
FirewallRules: [{614328DD-1303-4FAE-919F-520C8B373F5E}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{3EE83CD5-60FC-4928-B36D-63FB3E017386}] => (Allow) C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{6F11EE63-D815-421B-9D6A-48764294CF02}] => (Allow) C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{1ED680D5-CD81-4090-B014-002305E1CE5C}] => (Allow) C:\Users\Shayla Potter\Downloads\VideoPerformerSetup.exe
FirewallRules: [{D978B5B8-F77F-4D65-82A7-2BEC012FB9A4}] => (Allow) C:\Users\Shayla Potter\Downloads\VideoPerformerSetup.exe
FirewallRules: [{E084AF18-FF72-4B40-AFD1-28CF6C9B3AD8}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\0qvruq1t\SearchProtectInstaller
FirewallRules: [{1CAADD01-D900-4F4B-81C4-3728AEC3A1FD}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\0qvruq1t\SpeedanAlysisSetup
FirewallRules: [{69F7B8D1-BC9C-468A-A406-3E9CA38FE1C2}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\0qvruq1t\CloudBackupSetup
FirewallRules: [{9A8265F4-AB80-4342-93D1-487B6E7F4E58}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\0qvruq1t\PCPerformerSetup
FirewallRules: [{6B94B505-5AC5-46B1-9DCF-ED83303DC1EB}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\0qvruq1t\ZulaGamesSetup
FirewallRules: [{0C7EC599-D3E8-4DCD-8D2B-F7C63628CC75}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\0qvruq1t\VideoPerformerSetup
FirewallRules: [{F0FD8D67-C74D-4018-8745-55FCD6F11674}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [TCP Query User{023FD972-61BE-42E2-989C-B7672CE6E1D0}G:\simplisafewizard.exe] => (Allow) G:\simplisafewizard.exe
FirewallRules: [UDP Query User{10E89B64-ADCD-4ADE-A595-15A1D55E9FEF}G:\simplisafewizard.exe] => (Allow) G:\simplisafewizard.exe
FirewallRules: [{0E46D030-C9ED-42E0-B41C-C4E264D44BF7}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (05/24/2015 09:25:23 AM) (Source: MatSvc) (EventID: 3) (User: )
Description: The MATS service encountered a web service failure. hr=0x80072EFE
 
Error: (05/24/2015 09:20:24 AM) (Source: MatSvc) (EventID: 3) (User: )
Description: The MATS service encountered a web service failure. hr=0x80072EFE
 
Error: (05/24/2015 09:20:21 AM) (Source: MatSvc) (EventID: 15) (User: )
Description: The scheduled MATS task encountered a failure when collecting configuration data. hr=0xC004F00E
.
 
Error: (05/24/2015 09:20:19 AM) (Source: MatSvc) (EventID: 3) (User: )
Description: The MATS service encountered a web service failure. hr=0x80072EFE
 
Error: (05/24/2015 06:51:52 AM) (Source: MatSvc) (EventID: 3) (User: )
Description: The MATS service encountered a web service failure. hr=0x80072EFE
 
Error: (05/24/2015 06:46:55 AM) (Source: MatSvc) (EventID: 3) (User: )
Description: The MATS service encountered a web service failure. hr=0x80072EFE
 
Error: (05/24/2015 02:02:51 AM) (Source: MatSvc) (EventID: 3) (User: )
Description: The MATS service encountered a web service failure. hr=0x80072EFE
 
Error: (05/24/2015 01:57:52 AM) (Source: MatSvc) (EventID: 3) (User: )
Description: The MATS service encountered a web service failure. hr=0x80072EFE
 
Error: (05/23/2015 09:44:50 PM) (Source: MatSvc) (EventID: 3) (User: )
Description: The MATS service encountered a web service failure. hr=0x80072EFE
 
Error: (05/23/2015 09:39:52 PM) (Source: MatSvc) (EventID: 3) (User: )
Description: The MATS service encountered a web service failure. hr=0x80072EFE
 
 
System errors:
=============
Error: (05/24/2015 03:03:09 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: 0x80070103nVidia - Display - NVIDIA GeForce 6150SE nForce 430{1D38688E-F7C7-4448-8ED3-CF4D30DC746B}101
 
Error: (05/23/2015 03:04:25 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: 0x80070103nVidia - Display - NVIDIA GeForce 6150SE nForce 430{1D38688E-F7C7-4448-8ED3-CF4D30DC746B}101
 
Error: (05/22/2015 03:05:58 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: 0x80070103nVidia - Display - NVIDIA GeForce 6150SE nForce 430{1D38688E-F7C7-4448-8ED3-CF4D30DC746B}101
 
Error: (05/21/2015 03:05:25 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: 0x80070103nVidia - Display - NVIDIA GeForce 6150SE nForce 430{1D38688E-F7C7-4448-8ED3-CF4D30DC746B}101
 
Error: (05/21/2015 01:32:31 AM) (Source: Dhcp) (EventID: 1002) (User: )
Description: The IP address lease 192.168.1.10 for the Network Card with network address 001AA06945F1 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
 
Error: (05/20/2015 02:06:12 PM) (Source: Microsoft-Windows-GroupPolicy) (EventID: 1096) (User: BNSS-LEASED)
Description: The processing of Group Policy failed. Windows could not apply the registry-based policy settings for the Group Policy object LocalGPO. Group Policy settings will not be resolved until this event is resolved. View the event details for more information on the file name and path that caused the failure.
 
Error: (05/20/2015 01:33:35 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058
 
Error: (05/20/2015 01:33:35 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: WINBOND W55U01 USB%%1058
 
Error: (05/20/2015 01:32:56 PM) (Source: LSM) (EventID: 1048) (User: )
Description: Terminal Service start failed. The relevant status code was The configuration data for this product is corrupt. Contact your support personnel.
.
 
Error: (05/20/2015 01:27:18 PM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: WRSVC
 
 
Microsoft Office:
=========================
Error: (05/24/2015 09:25:23 AM) (Source: MatSvc) (EventID: 3) (User: )
Description: hr=0x80072EFEIDataUploadService::UploadResult
 
Error: (05/24/2015 09:20:24 AM) (Source: MatSvc) (EventID: 3) (User: )
Description: hr=0x80072EFEIDataUploadService::UploadResult
 
Error: (05/24/2015 09:20:21 AM) (Source: MatSvc) (EventID: 15) (User: )
Description: hr=0xC004F00E
 
Error: (05/24/2015 09:20:19 AM) (Source: MatSvc) (EventID: 3) (User: )
Description: hr=0x80072EFEISapCatalogService::GetFullSapCatalog
 
Error: (05/24/2015 06:51:52 AM) (Source: MatSvc) (EventID: 3) (User: )
Description: hr=0x80072EFEIDataUploadService::UploadResult
 
Error: (05/24/2015 06:46:55 AM) (Source: MatSvc) (EventID: 3) (User: )
Description: hr=0x80072EFEIDataUploadService::UploadResult
 
Error: (05/24/2015 02:02:51 AM) (Source: MatSvc) (EventID: 3) (User: )
Description: hr=0x80072EFEIDataUploadService::UploadResult
 
Error: (05/24/2015 01:57:52 AM) (Source: MatSvc) (EventID: 3) (User: )
Description: hr=0x80072EFEIDataUploadService::UploadResult
 
Error: (05/23/2015 09:44:50 PM) (Source: MatSvc) (EventID: 3) (User: )
Description: hr=0x80072EFEIDataUploadService::UploadResult
 
Error: (05/23/2015 09:39:52 PM) (Source: MatSvc) (EventID: 3) (User: )
Description: hr=0x80072EFEIDataUploadService::UploadResult
 
 
CodeIntegrity Errors:
===================================
  Date: 2014-07-15 23:50:24.151
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-securestartup-core_31bf3856ad364e35_6.0.6000.16386_none_32a3e3ecf533e7fe\fveapi.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-07-15 23:50:23.129
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-securestartup-core_31bf3856ad364e35_6.0.6000.16386_none_32a3e3ecf533e7fe\fveapi.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-07-15 23:50:22.105
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-securestartup-core_31bf3856ad364e35_6.0.6000.16386_none_32a3e3ecf533e7fe\fveapi.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-07-15 23:50:21.065
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-securestartup-core_31bf3856ad364e35_6.0.6000.16386_none_32a3e3ecf533e7fe\fveapi.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-07-15 23:49:03.129
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\fveapi.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-07-15 23:49:02.037
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\fveapi.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-07-15 23:49:00.931
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\fveapi.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-07-15 23:48:59.846
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\fveapi.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-02-28 22:23:21.033
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\Spigot\Search Settings\wth178.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-02-28 22:23:19.937
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\Spigot\Search Settings\wth178.dll because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: AMD Athlon™ 64 X2 Dual Core Processor 4000+
Percentage of memory in use: 88%
Total physical RAM: 1981.76 MB
Available physical RAM: 228.77 MB
Total Pagefile: 5430.23 MB
Available Pagefile: 2685.16 MB
Total Virtual: 2047.88 MB
Available Virtual: 1913.73 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:222.78 GB) (Free:8.54 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (RECOVERY) (Fixed) (Total:10 GB) (Free:4.95 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 232.8 GB) (Disk ID: 08000000)
Partition 1: (Not Active) - (Size=47 MB) - (Type=DE)
Partition 2: (Not Active) - (Size=10 GB) - (Type=07 NTFS)
Partition 3: (Active) - (Size=222.8 GB) - (Type=07 NTFS)
 
==================== End of log ============================

 


  • 0

Advertisements


#2
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
Hi! My name is zep516 and Welcome to Geekstogo!
I'll do the best I can to resolve your computer issue
Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, don't continue Stop and ask! Never be afraid to ask questions! :)


First
Please remove these programs from your programs an features list, Start > Control panel > Programs an features. In the list find the program listed below and uninstall it.
  • Adobe Reader 8.3.1
  • Updater Service
If a program will not remove skip it and keep following instructions please.

A few items to fix

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Open notepad (Start =>All Programs => Accessories => Notepad).
Copy/Paste the contents of the code box below into Notepad.
 
start
CloseProcesses:
CreateRestorePoint:
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Run: [iLivid] => "C:\Users\Shayla Potter\AppData\Local\iLivid\iLivid.exe" -autorun
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Run: [Itibiti.exe] => C:\Program Files\Itibiti Soft Phone\Itibiti.exe
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
GroupPolicyUsers\S-1-5-21-1260561122-373576474-2963483527-1010\User: Group Policy Restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-1260561122-373576474-2963483527-1005\User: Group Policy Restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-1260561122-373576474-2963483527-1000\User: Group Policy Restriction detected <======= ATTENTION
CHR HKU\S-1-5-21-1260561122-373576474-2963483527-1005\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
URLSearchHook: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 - (No Name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} -  No File
SearchScopes: HKLM -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://www.goonsearc...q={searchTerms}
SearchScopes: HKLM -> {9bd172ba-3f40-4303-bca1-0484b5ba2a7b} URL = http://search.mywebs...r={searchTerms}
SearchScopes: HKLM -> {CC865B26-C31D-4D23-B17B-96548EEF03F6} URL = 
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com...rchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-se...13_246&tsp=4981
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://www.goonsearc...q={searchTerms}
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {54ACE04D-52D8-4E32-97D3-0E379B1128F0} URL = http://groovorio.com...r=885083894&ir=
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {9bd172ba-3f40-4303-bca1-0484b5ba2a7b} URL = http://search.mywebs...r={searchTerms}
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL = http://toolbar.inbox...id=80051&lng=en
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} ->  No File
BHO: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll No File
BHO: AccelerateTab -> {48A789BF-F6D6-4930-9C8B-77855A63EDE1} -> C:\Program Files\Secure Speed Dial\IE\SpeedDial.dll [2014-05-26] (Secure Speed Dial)
BHO: No Name -> {6C8DB2EC-499B-4897-A784-0E3186C97E9D} ->  No File
BHO: No Name -> {CA6319C0-31B7-401E-A518-A07C3DB8F777} ->  No File
Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  No File
Toolbar: HKLM - No Name - {8660E5B3-6C41-44DE-8503-98D99BBECD41} -  No File
Toolbar: HKU\.DEFAULT -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  No File
Toolbar: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} -  No File
FF Plugin: @movenetworks.com/Quantum Media Player -> C:\Users\Shayla Potter\AppData\Roaming\Move Networks\plugins\npqmp071504000001.dll No File
FF Plugin: [email protected]/YahooActiveXPluginBridge;version=1.0.0.1 -> C:\Program Files\Yahoo!\Common\npyaxmpb.dll No File
FF HKLM\...\Firefox\Extensions: [{1C43BAF1-00C2-40A8-A09E-F84CFD79546D}] - C:\Program Files\Coupons.com CouponBar\firefox\{1C43BAF1-00C2-40A8-A09E-F84CFD79546D}\Coupons.com.xpi
CHR HKLM\...\Chrome\Extension: [cnpkmcjgpcihgfnkcjapiaabbbplkcmf] - C:\Program Files\Coupons.com CouponBar\chrome\Coupons.com.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Shayla Potter\AppData\Roaming\BabSolution\CR\Delta.crx [Not Found]
S3 stllssvr; "C:\Program Files\Common Files\SureThing Shared\stllssvr.exe" [X]
S2 SecureUpdateSvc; C:\Program Files\Secure Speed Dial\IE\SecureUpdate.exe [2580304 2014-05-28] () <==== ATTENTION
C:\Program Files\Secure Speed Dial
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 easytether; system32\DRIVERS\easytthr.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S1 vieieerh; \??\C:\Windows\system32\drivers\vieieerh.sys [X]
C:\Users\Kids\jagex_runescape_preferences.dat
C:\Users\Kids\jagex_runescape_preferences2.dat
C:\Users\Kieran\jagex_runescape_preferences.dat
C:\Users\Kieran\jagex_runescape_preferences2.dat
C:\Users\Shayla Potter\jagex_runescape_preferences.dat
C:\Users\Shayla Potter\jagex_runescape_preferences2.dat
MarketResearch (Version: 82.0.174.000 - Hewlett-Packard) Hidden  
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{05EC5C13-D255-4592-9CCB-98615172F0D6}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{0ADF9C35-0D5E-4B75-88DD-B64868907E17}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{123FAF7F-3FB1-4B8F-AD18-0047401D436A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{37A2FC00-1795-4679-94A3-A153F1A8BB54}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{37A2FC02-1795-4679-94A3-A153F1A8BB54}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{4052D303-74C5-49EA-BC6B-66099C8D4007}\InprocServer32 -> C:\Program Files\Google\Google Desktop Search\GoogleDesktopAPI2.dll (Google)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\Shayla Potter\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{4716D3CE-55DB-4D2A-818C-87D912895890}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{4844F3F7-2161-4AC4-B219-B3B4311782AA}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{4A56F19E-9F50-4F43-93C8-050E44AA83A9}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{4E5E74B5-8EB5-4859-A335-837EED412620}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{5428A9ED-6CD8-11D6-9C8A-0001023DCAA2}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{547C8F00-5567-4AE3-8BB0-CC3CE2AB9070}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{57D590F1-91EB-44CE-8088-AE4AE19D30A1}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{596801D8-2C9D-4627-9C67-195CB81B655A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{5B7331FA-8910-4748-A8A4-60B445041F28}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{5ED8AC89-B2DE-476D-8EEA-E170B2FCB058}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{6CE4B8A6-4DB5-4F63-8013-1197503692EF}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\YBPAddon_2.9.8.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{738CD606-129D-45db-86D6-6C9739C750CA}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2009\qbw32.exe No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{7694F1CD-A55B-4B7C-8820-A90892EB4E9E}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{76D50904-6780-4c8b-8986-1A7EE0B1716D}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Local\Roblox\Versions\version-c04585a2d58a4f29\RobloxProxy.dll (ROBLOX Corporation)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{7DBF8260-30AD-4D1B-876A-8032B87B809F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{828E5386-74CF-4019-B356-C857CD028A7D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{82CC31B3-53B4-4161-A4E9-6B4F1290A6C8}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{8572570D-12D9-4F2C-8BB8-EB8848178B94}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{885BB46A-3F1E-44C3-A01B-A7D9260CC98B}\InprocServer32 -> C:\Windows\Downloaded Program Files\dwusplay.exe (InstallShield Software Corporation)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{885BB46A-3F1E-44C3-A01B-A7D9260CC98B}\localserver32 -> C:\Windows\Downloaded Program Files\dwusplay.exe (InstallShield Software Corporation)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{8E590317-1329-11D1-B70B-00805F29CD16}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2009\qbw32.exe No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{8FEDE364-AB37-4551-80C9-6D468E222AB2}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F2-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F3-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F4-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F5-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F6-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F7-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{A63E42D0-9C63-47B5-ABF2-0C839EC20778}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{A63E42D2-9C63-47B5-ABF2-0C839EC20778}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{AF5E0A13-CEAB-47CE-991D-77E82CD1BF3F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{B10BFAC3-EFF1-40D9-ADA0-BEBE037C24CA}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{B66F2BF1-91EB-44CE-8088-AE4AE19D30A1}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D14FD6B3-6A9F-4537-9460-07B836707127}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D4A12AAF-E15E-470B-A6B6-63032186F91F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9B9C060-0954-11D3-9E07-00104BD2BE34}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\ViewSource.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6F81-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\cominifile.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6F84-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\cominifile.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6F87-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\cominifile.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6FA1-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\GraphSeriesCol.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6FA6-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\GraphSeriesCol.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6FB2-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\StorageClasses.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{DCB2B478-EFF6-48F6-B718-13E98876854E}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{DFD0AF10-B86C-4AF3-B609-1348D513E565}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{E1A173E1-D957-4C3E-A098-43756A3DB454}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{E1A173E3-D957-4C3E-A098-43756A3DB454}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{EADA914E-5B08-4E85-8440-5A087504DF87}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{EAEF733D-5B08-4E85-8440-5A087504DF87}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{F2C593CC-74B2-4F71-8556-DD4D426D0409}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FAC93D42-FFC2-11d1-9DEB-0008C7A08EBA}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2009\qbw32.exe No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FB17915F-06D1-4214-A902-CC5EE05186E9}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
Task: {3C817959-645A-44D8-AFBE-FCF3A93A0A53} - System32\Tasks\ProPCCleaner_Start => C:\Program Files\Pro PC Cleaner\ProPCCleaner.exe <==== ATTENTION
C:\Program Files\Pro PC Cleaner
Task: {752E18DC-EE40-4A9E-8BF8-0D303F149432} - System32\Tasks\ProPCCleaner_Popup => C:\Program Files\Pro PC Cleaner\Splash.exe <==== ATTENTION
Task: {EDC61C3C-3C8E-43E5-98BF-E3D87E739FA4} - System32\Tasks\LaunchSignup => C:\Program Files\MyPC Backup\Signup Wizard.exe <==== ATTENTION
C:\Program Files\MyPC Backup
AlternateDataStreams: C:\ProgramData\TEMP:08AC8A76
AlternateDataStreams: C:\ProgramData\TEMP:376AEA88
AlternateDataStreams: C:\ProgramData\TEMP:69F4A9BE
AlternateDataStreams: C:\ProgramData\TEMP:819BEFD3
AlternateDataStreams: C:\ProgramData\TEMP:81A5201B
AlternateDataStreams: C:\ProgramData\TEMP:8EC55520
AlternateDataStreams: C:\ProgramData\TEMP:A52C3C4A
AlternateDataStreams: C:\ProgramData\TEMP:AA3339BE
AlternateDataStreams: C:\ProgramData\TEMP:AD6273E0
AlternateDataStreams: C:\ProgramData\TEMP:D1B5B4F1
AlternateDataStreams: C:\ProgramData\TEMP:E33EA293
AlternateDataStreams: C:\ProgramData\TEMP:EA031481
AlternateDataStreams: C:\ProgramData\TEMP:FE53E4F7
AlternateDataStreams: C:\Users\Shayla Potter\Downloads\Fireworks Soundtrack 2012(Final2).mp3:TOC.WMV
AlternateDataStreams: C:\Users\Shayla Potter\Downloads\The.Event.S01E09.HDTV.XviD-LOL.avi:TOC.WMV
AlternateDataStreams: C:\Users\Shayla Potter\Downloads\The.Event.S01E10.HDTV.XviD-LOL.avi:TOC.WMV
FirewallRules: [{CF3F1C2E-12B5-47B5-8614-EEA33474929F}] => (Allow) C:\Program Files\AVG\AVG8\avgemc.exe
FirewallRules: [{C27A2989-753C-4545-96EC-06E5B89D85B9}] => (Allow) C:\Program Files\AVG\AVG8\avgupd.exe
FirewallRules: [{CDE64441-851E-4950-9086-D36CED50AF12}] => (Allow) C:\Program Files\AVG\AVG8\avgnsx.exe
FirewallRules: [{5746ED1C-3542-4082-9717-59520FE697DE}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\ibtmpe88488\component_52.decrpt
FirewallRules: [{7710437B-2E16-4F8E-B989-E674C02E97D7}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\ibtmpe88488\component_138.decrpt
FirewallRules: [{06C4CF6A-8D7D-4479-8288-72149D5EFB16}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\ibtmpe88488\component_71.decrpt
FirewallRules: [{04671719-1204-47B5-8CE0-3766BA80447B}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\dyq9vwst418qg7qvx408\component_1.decrpt
FirewallRules: [{E084AF18-FF72-4B40-AFD1-28CF6C9B3AD8}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\0qvruq1t\SearchProtectInstaller
FirewallRules: [{1CAADD01-D900-4F4B-81C4-3728AEC3A1FD}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\0qvruq1t\SpeedanAlysisSetup
FirewallRules: [{69F7B8D1-BC9C-468A-A406-3E9CA38FE1C2}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\0qvruq1t\CloudBackupSetup
FirewallRules: [{9A8265F4-AB80-4342-93D1-487B6E7F4E58}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\0qvruq1t\PCPerformerSetup
FirewallRules: [{6B94B505-5AC5-46B1-9DCF-ED83303DC1EB}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\0qvruq1t\ZulaGamesSetup
FirewallRules: [{0C7EC599-D3E8-4DCD-8D2B-F7C63628CC75}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\0qvruq1t\VideoPerformerSetup
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset catalog
CMD: ipconfig /flushdns
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
hosts:
Emptytemp:
Click Format and ensure Wordwrap is unchecked.
Save as Fixlist.txt to your Desktop (Must be in this location)
Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.

Note: If the tool warns you about the version you're using being an outdated version please download and run the updated version.

Please post the Fixlog.txt in your next reply. That log will be located on the desktop after fix has run.
  • 0

#3
crybaby

crybaby

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 175 posts

Hi zep516,

Thank you for taking the time to review my issue. I have run into a few problems while following your instruction. First, the Adobe Reader 8.3.1 would not uninstall; Second, I saw nothing entitled Updater Service; third, the FRST fix began, but is now no longer responding. What should I do?


  • 0

#4
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
Reboot the computer and retry FRST fix again.
  • 0

#5
crybaby

crybaby

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 175 posts

OK. After my last post, the program resumed, and Adobe Reader 8.3.1 was successfully uninstalled, and the computer was rebooted. Here is the Fixlog.txt you requested. 

 

 

Fix result of Farbar Recovery Scan Tool (x86) Version: 24-05-2015 01
Ran by Shayla Potter at 2015-05-25 10:31:44 Run:1
Running from C:\Users\Shayla Potter\Desktop
Loaded Profiles: Shayla Potter (Available Profiles: Mason & Shayla Potter & Kieran & Administrator & Guest)
Boot Mode: Normal
 
==============================================
 
fixlist content:
*****************
start
CloseProcesses:
CreateRestorePoint:
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Run: [iLivid] => "C:\Users\Shayla Potter\AppData\Local\iLivid\iLivid.exe" -autorun
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Run: [Itibiti.exe] => C:\Program Files\Itibiti Soft Phone\Itibiti.exe
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
GroupPolicyUsers\S-1-5-21-1260561122-373576474-2963483527-1010\User: Group Policy Restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-1260561122-373576474-2963483527-1005\User: Group Policy Restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-1260561122-373576474-2963483527-1000\User: Group Policy Restriction detected <======= ATTENTION
CHR HKU\S-1-5-21-1260561122-373576474-2963483527-1005\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
URLSearchHook: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 - (No Name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} -  No File
SearchScopes: HKLM -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://www.goonsearc...q={searchTerms}
SearchScopes: HKLM -> {9bd172ba-3f40-4303-bca1-0484b5ba2a7b} URL = http://search.mywebs...r={searchTerms}
SearchScopes: HKLM -> {CC865B26-C31D-4D23-B17B-96548EEF03F6} URL = 
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://www.trovi.com...rchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www1.delta-se...13_246&tsp=4981
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://www.goonsearc...q={searchTerms}
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {54ACE04D-52D8-4E32-97D3-0E379B1128F0} URL = http://groovorio.com...r=885083894&ir=
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {9bd172ba-3f40-4303-bca1-0484b5ba2a7b} URL = http://search.mywebs...r={searchTerms}
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL = http://toolbar.inbox...id=80051&lng=en
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} ->  No File
BHO: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll No File
BHO: AccelerateTab -> {48A789BF-F6D6-4930-9C8B-77855A63EDE1} -> C:\Program Files\Secure Speed Dial\IE\SpeedDial.dll [2014-05-26] (Secure Speed Dial)
BHO: No Name -> {6C8DB2EC-499B-4897-A784-0E3186C97E9D} ->  No File
BHO: No Name -> {CA6319C0-31B7-401E-A518-A07C3DB8F777} ->  No File
Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  No File
Toolbar: HKLM - No Name - {8660E5B3-6C41-44DE-8503-98D99BBECD41} -  No File
Toolbar: HKU\.DEFAULT -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  No File
Toolbar: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} -  No File
FF Plugin: @movenetworks.com/Quantum Media Player -> C:\Users\Shayla Potter\AppData\Roaming\Move Networks\plugins\npqmp071504000001.dll No File
FF Plugin: [email protected]/YahooActiveXPluginBridge;version=1.0.0.1 -> C:\Program Files\Yahoo!\Common\npyaxmpb.dll No File
FF HKLM\...\Firefox\Extensions: [{1C43BAF1-00C2-40A8-A09E-F84CFD79546D}] - C:\Program Files\Coupons.com CouponBar\firefox\{1C43BAF1-00C2-40A8-A09E-F84CFD79546D}\Coupons.com.xpi
CHR HKLM\...\Chrome\Extension: [cnpkmcjgpcihgfnkcjapiaabbbplkcmf] - C:\Program Files\Coupons.com CouponBar\chrome\Coupons.com.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Shayla Potter\AppData\Roaming\BabSolution\CR\Delta.crx [Not Found]
S3 stllssvr; "C:\Program Files\Common Files\SureThing Shared\stllssvr.exe" [X]
S2 SecureUpdateSvc; C:\Program Files\Secure Speed Dial\IE\SecureUpdate.exe [2580304 2014-05-28] () <==== ATTENTION
C:\Program Files\Secure Speed Dial
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 easytether; system32\DRIVERS\easytthr.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S1 vieieerh; \??\C:\Windows\system32\drivers\vieieerh.sys [X]
C:\Users\Kids\jagex_runescape_preferences.dat
C:\Users\Kids\jagex_runescape_preferences2.dat
C:\Users\Kieran\jagex_runescape_preferences.dat
C:\Users\Kieran\jagex_runescape_preferences2.dat
C:\Users\Shayla Potter\jagex_runescape_preferences.dat
C:\Users\Shayla Potter\jagex_runescape_preferences2.dat
MarketResearch (Version: 82.0.174.000 - Hewlett-Packard) Hidden  
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{05EC5C13-D255-4592-9CCB-98615172F0D6}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{0ADF9C35-0D5E-4B75-88DD-B64868907E17}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{123FAF7F-3FB1-4B8F-AD18-0047401D436A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{37A2FC00-1795-4679-94A3-A153F1A8BB54}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{37A2FC02-1795-4679-94A3-A153F1A8BB54}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{4052D303-74C5-49EA-BC6B-66099C8D4007}\InprocServer32 -> C:\Program Files\Google\Google Desktop Search\GoogleDesktopAPI2.dll (Google)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\Shayla Potter\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{4716D3CE-55DB-4D2A-818C-87D912895890}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{4844F3F7-2161-4AC4-B219-B3B4311782AA}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{4A56F19E-9F50-4F43-93C8-050E44AA83A9}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{4E5E74B5-8EB5-4859-A335-837EED412620}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{5428A9ED-6CD8-11D6-9C8A-0001023DCAA2}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{547C8F00-5567-4AE3-8BB0-CC3CE2AB9070}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{57D590F1-91EB-44CE-8088-AE4AE19D30A1}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{596801D8-2C9D-4627-9C67-195CB81B655A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{5B7331FA-8910-4748-A8A4-60B445041F28}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{5ED8AC89-B2DE-476D-8EEA-E170B2FCB058}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{6CE4B8A6-4DB5-4F63-8013-1197503692EF}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\YBPAddon_2.9.8.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{738CD606-129D-45db-86D6-6C9739C750CA}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2009\qbw32.exe No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{7694F1CD-A55B-4B7C-8820-A90892EB4E9E}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{76D50904-6780-4c8b-8986-1A7EE0B1716D}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Local\Roblox\Versions\version-c04585a2d58a4f29\RobloxProxy.dll (ROBLOX Corporation)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{7DBF8260-30AD-4D1B-876A-8032B87B809F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{828E5386-74CF-4019-B356-C857CD028A7D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{82CC31B3-53B4-4161-A4E9-6B4F1290A6C8}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{8572570D-12D9-4F2C-8BB8-EB8848178B94}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{885BB46A-3F1E-44C3-A01B-A7D9260CC98B}\InprocServer32 -> C:\Windows\Downloaded Program Files\dwusplay.exe (InstallShield Software Corporation)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{885BB46A-3F1E-44C3-A01B-A7D9260CC98B}\localserver32 -> C:\Windows\Downloaded Program Files\dwusplay.exe (InstallShield Software Corporation)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{8E590317-1329-11D1-B70B-00805F29CD16}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2009\qbw32.exe No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{8FEDE364-AB37-4551-80C9-6D468E222AB2}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F2-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F3-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F4-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F5-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F6-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F7-9E2B-492A-81B3-AA5A1CCFBC3A}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{A63E42D0-9C63-47B5-ABF2-0C839EC20778}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{A63E42D2-9C63-47B5-ABF2-0C839EC20778}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{AF5E0A13-CEAB-47CE-991D-77E82CD1BF3F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{B10BFAC3-EFF1-40D9-ADA0-BEBE037C24CA}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{B66F2BF1-91EB-44CE-8088-AE4AE19D30A1}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D14FD6B3-6A9F-4537-9460-07B836707127}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D4A12AAF-E15E-470B-A6B6-63032186F91F}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9B9C060-0954-11D3-9E07-00104BD2BE34}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\ViewSource.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6F81-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\cominifile.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6F84-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\cominifile.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6F87-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\cominifile.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6FA1-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\GraphSeriesCol.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6FA6-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\GraphSeriesCol.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6FB2-A54B-11D4-A516-0050DA68678D}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\StorageClasses.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{DCB2B478-EFF6-48F6-B718-13E98876854E}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{DFD0AF10-B86C-4AF3-B609-1348D513E565}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{E1A173E1-D957-4C3E-A098-43756A3DB454}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{E1A173E3-D957-4C3E-A098-43756A3DB454}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{EADA914E-5B08-4E85-8440-5A087504DF87}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{EAEF733D-5B08-4E85-8440-5A087504DF87}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{F2C593CC-74B2-4F71-8556-DD4D426D0409}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FAC93D42-FFC2-11d1-9DEB-0008C7A08EBA}\localserver32 -> C:\Program Files\Intuit\QuickBooks 2009\qbw32.exe No File
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FB17915F-06D1-4214-A902-CC5EE05186E9}\InprocServer32 -> C:\Program Files\Common Files\Intuit\QuickBooks\QBObjProxy.dll No File
Task: {3C817959-645A-44D8-AFBE-FCF3A93A0A53} - System32\Tasks\ProPCCleaner_Start => C:\Program Files\Pro PC Cleaner\ProPCCleaner.exe <==== ATTENTION
C:\Program Files\Pro PC Cleaner
Task: {752E18DC-EE40-4A9E-8BF8-0D303F149432} - System32\Tasks\ProPCCleaner_Popup => C:\Program Files\Pro PC Cleaner\Splash.exe <==== ATTENTION
Task: {EDC61C3C-3C8E-43E5-98BF-E3D87E739FA4} - System32\Tasks\LaunchSignup => C:\Program Files\MyPC Backup\Signup Wizard.exe <==== ATTENTION
C:\Program Files\MyPC Backup
AlternateDataStreams: C:\ProgramData\TEMP:08AC8A76
AlternateDataStreams: C:\ProgramData\TEMP:376AEA88
AlternateDataStreams: C:\ProgramData\TEMP:69F4A9BE
AlternateDataStreams: C:\ProgramData\TEMP:819BEFD3
AlternateDataStreams: C:\ProgramData\TEMP:81A5201B
AlternateDataStreams: C:\ProgramData\TEMP:8EC55520
AlternateDataStreams: C:\ProgramData\TEMP:A52C3C4A
AlternateDataStreams: C:\ProgramData\TEMP:AA3339BE
AlternateDataStreams: C:\ProgramData\TEMP:AD6273E0
AlternateDataStreams: C:\ProgramData\TEMP:D1B5B4F1
AlternateDataStreams: C:\ProgramData\TEMP:E33EA293
AlternateDataStreams: C:\ProgramData\TEMP:EA031481
AlternateDataStreams: C:\ProgramData\TEMP:FE53E4F7
AlternateDataStreams: C:\Users\Shayla Potter\Downloads\Fireworks Soundtrack 2012(Final2).mp3:TOC.WMV
AlternateDataStreams: C:\Users\Shayla Potter\Downloads\The.Event.S01E09.HDTV.XviD-LOL.avi:TOC.WMV
AlternateDataStreams: C:\Users\Shayla Potter\Downloads\The.Event.S01E10.HDTV.XviD-LOL.avi:TOC.WMV
FirewallRules: [{CF3F1C2E-12B5-47B5-8614-EEA33474929F}] => (Allow) C:\Program Files\AVG\AVG8\avgemc.exe
FirewallRules: [{C27A2989-753C-4545-96EC-06E5B89D85B9}] => (Allow) C:\Program Files\AVG\AVG8\avgupd.exe
FirewallRules: [{CDE64441-851E-4950-9086-D36CED50AF12}] => (Allow) C:\Program Files\AVG\AVG8\avgnsx.exe
FirewallRules: [{5746ED1C-3542-4082-9717-59520FE697DE}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\ibtmpe88488\component_52.decrpt
FirewallRules: [{7710437B-2E16-4F8E-B989-E674C02E97D7}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\ibtmpe88488\component_138.decrpt
FirewallRules: [{06C4CF6A-8D7D-4479-8288-72149D5EFB16}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\ibtmpe88488\component_71.decrpt
FirewallRules: [{04671719-1204-47B5-8CE0-3766BA80447B}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\dyq9vwst418qg7qvx408\component_1.decrpt
FirewallRules: [{E084AF18-FF72-4B40-AFD1-28CF6C9B3AD8}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\0qvruq1t\SearchProtectInstaller
FirewallRules: [{1CAADD01-D900-4F4B-81C4-3728AEC3A1FD}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\0qvruq1t\SpeedanAlysisSetup
FirewallRules: [{69F7B8D1-BC9C-468A-A406-3E9CA38FE1C2}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\0qvruq1t\CloudBackupSetup
FirewallRules: [{9A8265F4-AB80-4342-93D1-487B6E7F4E58}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\0qvruq1t\PCPerformerSetup
FirewallRules: [{6B94B505-5AC5-46B1-9DCF-ED83303DC1EB}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\0qvruq1t\ZulaGamesSetup
FirewallRules: [{0C7EC599-D3E8-4DCD-8D2B-F7C63628CC75}] => (Allow) C:\Users\SHAYLA~1\AppData\Local\Temp\0qvruq1t\VideoPerformerSetup
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset catalog
CMD: ipconfig /flushdns
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
hosts:
Emptytemp:
*****************
 
Processes closed successfully.
Restore point was successfully created.
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\Software\Microsoft\Windows\CurrentVersion\Run\\iLivid => value Removed successfully.
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\Software\Microsoft\Windows\CurrentVersion\Run\\Itibiti.exe => value Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bitguard.exe" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bprotect.exe" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bpsvc.exe" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserdefender.exe" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserprotect.exe" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browsersafeguard.exe" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\dprotectsvc.exe" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\jumpflip" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\protectedsearch.exe" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchinstaller.exe" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotection.exe" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotector.exe" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchsettings.exe" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchsettings64.exe" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\snapdo.exe" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst32.exe" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst64.exe" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\umbrella.exe" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\utiljumpflip.exe" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\volaro" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\vonteera" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\websteroids.exe" => key Removed successfully.
"HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\websteroidsservice.exe" => key Removed successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key Removed successfully.
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found. 
C:\Windows\system32\GroupPolicyUsers\S-1-5-21-1260561122-373576474-2963483527-1010\User => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
C:\Windows\system32\GroupPolicyUsers\S-1-5-21-1260561122-373576474-2963483527-1005\User => Moved successfully.
C:\Windows\system32\GroupPolicyUsers\S-1-5-21-1260561122-373576474-2963483527-1000\User => Moved successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005\SOFTWARE\Policies\Google" => key Removed successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\Software\Microsoft\Internet Explorer\URLSearchHooks\\{D3D233D5-9F6D-436C-B6C7-E63F77503B30} => value Removed successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}" => key Removed successfully.
HKCR\CLSID\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} => key not found. 
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9bd172ba-3f40-4303-bca1-0484b5ba2a7b}" => key Removed successfully.
HKCR\CLSID\{9bd172ba-3f40-4303-bca1-0484b5ba2a7b} => key not found. 
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CC865B26-C31D-4D23-B17B-96548EEF03F6}" => key Removed successfully.
HKCR\CLSID\{CC865B26-C31D-4D23-B17B-96548EEF03F6} => key not found. 
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" => key Removed successfully.
HKCR\CLSID\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} => key not found. 
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}" => key Removed successfully.
HKCR\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} => key not found. 
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}" => key Removed successfully.
HKCR\CLSID\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} => key not found. 
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{54ACE04D-52D8-4E32-97D3-0E379B1128F0}" => key Removed successfully.
HKCR\CLSID\{54ACE04D-52D8-4E32-97D3-0E379B1128F0} => key not found. 
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9bd172ba-3f40-4303-bca1-0484b5ba2a7b}" => key Removed successfully.
HKCR\CLSID\{9bd172ba-3f40-4303-bca1-0484b5ba2a7b} => key not found. 
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}" => key Removed successfully.
HKCR\CLSID\{C04B7D22-5AEC-4561-8F49-27F6269208F6} => key not found. 
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}" => key Removed successfully.
HKCR\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670} => key not found. 
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}" => key Removed successfully.
"HKCR\CLSID\{3049C3E9-B461-4BC5-8870-4C09146192CA}" => key Removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{48A789BF-F6D6-4930-9C8B-77855A63EDE1}" => key Removed successfully.
"HKCR\CLSID\{48A789BF-F6D6-4930-9C8B-77855A63EDE1}" => key Removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C8DB2EC-499B-4897-A784-0E3186C97E9D}" => key Removed successfully.
HKCR\CLSID\{6C8DB2EC-499B-4897-A784-0E3186C97E9D} => key not found. 
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}" => key Removed successfully.
HKCR\CLSID\{CA6319C0-31B7-401E-A518-A07C3DB8F777} => key not found. 
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => value Removed successfully.
HKCR\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => key not found. 
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{8660E5B3-6C41-44DE-8503-98D99BBECD41} => value Removed successfully.
HKCR\CLSID\{8660E5B3-6C41-44DE-8503-98D99BBECD41} => key not found. 
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value Removed successfully.
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found. 
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => value Removed successfully.
HKCR\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} => key not found. 
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value Removed successfully.
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found. 
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D7E97865-918F-41E4-9CD0-25AB1C574CE8} => value Removed successfully.
HKCR\CLSID\{D7E97865-918F-41E4-9CD0-25AB1C574CE8} => key not found. 
"HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player" => key Removed successfully.
"HKLM\Software\MozillaPlugins\[email protected]/YahooActiveXPluginBridge;version=1.0.0.1" => key Removed successfully.
HKLM\Software\Mozilla\Firefox\Extensions\\{1C43BAF1-00C2-40A8-A09E-F84CFD79546D} => value Removed successfully.
"HKLM\SOFTWARE\Google\Chrome\Extensions\cnpkmcjgpcihgfnkcjapiaabbbplkcmf" => key Removed successfully.
"HKLM\SOFTWARE\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde" => key Removed successfully.
stllssvr => Service Removed successfully.
SecureUpdateSvc => Service Removed successfully.
C:\Program Files\Secure Speed Dial => Moved successfully.
blbdrive => Service Removed successfully.
easytether => Service Removed successfully.
IpInIp => Service Removed successfully.
NwlnkFlt => Service Removed successfully.
NwlnkFwd => Service Removed successfully.
vieieerh => Service Removed successfully.
C:\Users\Kids\jagex_runescape_preferences.dat => Moved successfully.
C:\Users\Kids\jagex_runescape_preferences2.dat => Moved successfully.
C:\Users\Kieran\jagex_runescape_preferences.dat => Moved successfully.
C:\Users\Kieran\jagex_runescape_preferences2.dat => Moved successfully.
C:\Users\Shayla Potter\jagex_runescape_preferences.dat => Moved successfully.
C:\Users\Shayla Potter\jagex_runescape_preferences2.dat => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}\\SystemComponent => value Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{05EC5C13-D255-4592-9CCB-98615172F0D6}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{0ADF9C35-0D5E-4B75-88DD-B64868907E17}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{123FAF7F-3FB1-4B8F-AD18-0047401D436A}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{37A2FC00-1795-4679-94A3-A153F1A8BB54}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{37A2FC02-1795-4679-94A3-A153F1A8BB54}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{4052D303-74C5-49EA-BC6B-66099C8D4007}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{4716D3CE-55DB-4D2A-818C-87D912895890}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{4844F3F7-2161-4AC4-B219-B3B4311782AA}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{4A56F19E-9F50-4F43-93C8-050E44AA83A9}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{4E5E74B5-8EB5-4859-A335-837EED412620}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{5428A9ED-6CD8-11D6-9C8A-0001023DCAA2}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{547C8F00-5567-4AE3-8BB0-CC3CE2AB9070}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{57D590F1-91EB-44CE-8088-AE4AE19D30A1}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{596801D8-2C9D-4627-9C67-195CB81B655A}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{5B7331FA-8910-4748-A8A4-60B445041F28}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{5ED8AC89-B2DE-476D-8EEA-E170B2FCB058}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{6CE4B8A6-4DB5-4F63-8013-1197503692EF}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{738CD606-129D-45db-86D6-6C9739C750CA}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{7694F1CD-A55B-4B7C-8820-A90892EB4E9E}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{76D50904-6780-4c8b-8986-1A7EE0B1716D}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{7DBF8260-30AD-4D1B-876A-8032B87B809F}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{828E5386-74CF-4019-B356-C857CD028A7D}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{82CC31B3-53B4-4161-A4E9-6B4F1290A6C8}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{8572570D-12D9-4F2C-8BB8-EB8848178B94}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{885BB46A-3F1E-44C3-A01B-A7D9260CC98B}" => key Removed successfully.
HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{885BB46A-3F1E-44C3-A01B-A7D9260CC98B} => key not found. 
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{8E590317-1329-11D1-B70B-00805F29CD16}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{8FEDE364-AB37-4551-80C9-6D468E222AB2}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F2-9E2B-492A-81B3-AA5A1CCFBC3A}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F3-9E2B-492A-81B3-AA5A1CCFBC3A}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F4-9E2B-492A-81B3-AA5A1CCFBC3A}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F5-9E2B-492A-81B3-AA5A1CCFBC3A}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F6-9E2B-492A-81B3-AA5A1CCFBC3A}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{9D9B61F7-9E2B-492A-81B3-AA5A1CCFBC3A}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{A63E42D0-9C63-47B5-ABF2-0C839EC20778}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{A63E42D2-9C63-47B5-ABF2-0C839EC20778}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{AF5E0A13-CEAB-47CE-991D-77E82CD1BF3F}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{B10BFAC3-EFF1-40D9-ADA0-BEBE037C24CA}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{B66F2BF1-91EB-44CE-8088-AE4AE19D30A1}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D14FD6B3-6A9F-4537-9460-07B836707127}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D4A12AAF-E15E-470B-A6B6-63032186F91F}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9B9C060-0954-11D3-9E07-00104BD2BE34}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6F81-A54B-11D4-A516-0050DA68678D}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6F84-A54B-11D4-A516-0050DA68678D}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6F87-A54B-11D4-A516-0050DA68678D}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6FA1-A54B-11D4-A516-0050DA68678D}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6FA6-A54B-11D4-A516-0050DA68678D}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{D9BC6FB2-A54B-11D4-A516-0050DA68678D}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{DCB2B478-EFF6-48F6-B718-13E98876854E}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{DFD0AF10-B86C-4AF3-B609-1348D513E565}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{E1A173E1-D957-4C3E-A098-43756A3DB454}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{E1A173E3-D957-4C3E-A098-43756A3DB454}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{EADA914E-5B08-4E85-8440-5A087504DF87}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{EAEF733D-5B08-4E85-8440-5A087504DF87}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{F2C593CC-74B2-4F71-8556-DD4D426D0409}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FAC93D42-FFC2-11d1-9DEB-0008C7A08EBA}" => key Removed successfully.
"HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FB17915F-06D1-4214-A902-CC5EE05186E9}" => key Removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3C817959-645A-44D8-AFBE-FCF3A93A0A53}" => key Removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3C817959-645A-44D8-AFBE-FCF3A93A0A53}" => key Removed successfully.
C:\Windows\System32\Tasks\ProPCCleaner_Start => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ProPCCleaner_Start" => key Removed successfully.
"C:\Program Files\Pro PC Cleaner" => File/Folder not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{752E18DC-EE40-4A9E-8BF8-0D303F149432}" => key Removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{752E18DC-EE40-4A9E-8BF8-0D303F149432}" => key Removed successfully.
C:\Windows\System32\Tasks\ProPCCleaner_Popup => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ProPCCleaner_Popup" => key Removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EDC61C3C-3C8E-43E5-98BF-E3D87E739FA4}" => key Removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EDC61C3C-3C8E-43E5-98BF-E3D87E739FA4}" => key Removed successfully.
C:\Windows\System32\Tasks\LaunchSignup => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LaunchSignup" => key Removed successfully.
"C:\Program Files\MyPC Backup" => File/Folder not found.
C:\ProgramData\TEMP => ":08AC8A76" ADS Removed successfully..
C:\ProgramData\TEMP => ":376AEA88" ADS Removed successfully..
C:\ProgramData\TEMP => ":69F4A9BE" ADS Removed successfully..
C:\ProgramData\TEMP => ":819BEFD3" ADS Removed successfully..
C:\ProgramData\TEMP => ":81A5201B" ADS Removed successfully..
C:\ProgramData\TEMP => ":8EC55520" ADS Removed successfully..
C:\ProgramData\TEMP => ":A52C3C4A" ADS Removed successfully..
C:\ProgramData\TEMP => ":AA3339BE" ADS Removed successfully..
C:\ProgramData\TEMP => ":AD6273E0" ADS Removed successfully..
C:\ProgramData\TEMP => ":D1B5B4F1" ADS Removed successfully..
C:\ProgramData\TEMP => ":E33EA293" ADS Removed successfully..
C:\ProgramData\TEMP => ":EA031481" ADS Removed successfully..
C:\ProgramData\TEMP => ":FE53E4F7" ADS Removed successfully..
C:\Users\Shayla Potter\Downloads\Fireworks Soundtrack 2012(Final2).mp3 => ":TOC.WMV" ADS Removed successfully..
C:\Users\Shayla Potter\Downloads\The.Event.S01E09.HDTV.XviD-LOL.avi => ":TOC.WMV" ADS Removed successfully..
C:\Users\Shayla Potter\Downloads\The.Event.S01E10.HDTV.XviD-LOL.avi => ":TOC.WMV" ADS Removed successfully..
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{CF3F1C2E-12B5-47B5-8614-EEA33474929F} => value Removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C27A2989-753C-4545-96EC-06E5B89D85B9} => value Removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{CDE64441-851E-4950-9086-D36CED50AF12} => value Removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5746ED1C-3542-4082-9717-59520FE697DE} => value Removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7710437B-2E16-4F8E-B989-E674C02E97D7} => value Removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{06C4CF6A-8D7D-4479-8288-72149D5EFB16} => value Removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{04671719-1204-47B5-8CE0-3766BA80447B} => value Removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E084AF18-FF72-4B40-AFD1-28CF6C9B3AD8} => value Removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1CAADD01-D900-4F4B-81C4-3728AEC3A1FD} => value Removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{69F7B8D1-BC9C-468A-A406-3E9CA38FE1C2} => value Removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9A8265F4-AB80-4342-93D1-487B6E7F4E58} => value Removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6B94B505-5AC5-46B1-9DCF-ED83303DC1EB} => value Removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0C7EC599-D3E8-4DCD-8D2B-F7C63628CC75} => value Removed successfully.
 
=========  bitsadmin /reset /allusers =========
 
 
BITSADMIN version 3.0 [ 7.0.6001 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
 
0 out of 0 jobs canceled.
 
========= End of CMD: =========
 
 
=========  netsh winsock reset catalog =========
 
 
Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
 
 
========= End of CMD: =========
 
 
=========  ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
 
=========  netsh int ipv4 reset =========
 
Reseting Echo Request, OK!
Reseting Global, OK!
Reseting Interface, OK!
Reseting Unicast Address, OK!
Reseting Route, OK!
A reboot is required to complete this action.
 
 
========= End of CMD: =========
 
 
=========  netsh int ipv6 reset =========
 
Reseting Echo Request, OK!
A reboot is required to complete this action.
 
 
========= End of CMD: =========
 
"C:\Windows\System32\Drivers\etc\hosts" => Could not move.
Could not restore Hosts.
EmptyTemp: => Removed 6.6 GB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog 11:44:50 ====

  • 0

#6
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
Next

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the logfile button and the log will open in Notepad.
  • NOTE: If you get an error message, it means that nothing was found. Exit from AdwCleaner.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished and the PC has rebooted.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner
Next

thisisujrt.gif Please download Junkware Removal Tool to your Desktop.

Please close your security software to avoid potential conflicts. See Here how to disable you security protection (Anti Virus)
Run the tool by double-clicking it. If you are using Windows Vista or 7, right-mouse click it and select Run as administrator.
The tool will open and start scanning your system.
Please be patient as this can take a while to complete, depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
Please post the contents of JRT.txt into your reply.


In your next reply post;
  • The AdwCleaner [SO].txt Log
  • The JRT.txt Log
Thanks
Joe :)
  • 0

#7
crybaby

crybaby

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 175 posts

Had a few issues with the AdwCleaner, but finally got through it. Here are the logs. :)

 

 

# AdwCleaner v4.205 - Logfile created 26/05/2015 at 09:15:50
# Updated 21/05/2015 by Xplode
# Database : 2015-05-25.3 [Server]
# Operating system : Windows Vista ™ Home Basic Service Pack 2 (x86)
# Username : Shayla Potter - BNSS-LEASED
# Running from : C:\Users\Shayla Potter\Desktop\adwcleaner_4.205.exe
# Option : Cleaning
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\Users\Shayla Potter\AppData\LocalLow\Toolbar4
Folder Deleted : C:\Users\Shayla Potter\AppData\LocalLow\BitTorrentBar
Folder Deleted : C:\Users\Shayla Potter\AppData\LocalLow\ilividbandoomoviestoolbar
Folder Deleted : C:\Users\Shayla Potter\AppData\Roaming\BabSolution
Folder Deleted : C:\Users\Shayla Potter\AppData\Roaming\Babylon
Folder Deleted : C:\Users\Shayla Potter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Softonic
Folder Deleted : C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\Extensions\[email protected]
Folder Deleted : C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\Extensions\[email protected]
Folder Deleted : C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\Extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}(38)
Folder Deleted : C:\Users\KIDS.BNSS-LEASED\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaaigjndjblmpeckabiffcpogflfgl
Folder Deleted : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
Folder Deleted : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
[/!\] Not Deleted ( Junction ) : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda
Folder Deleted : C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehjkfdmkpocpileolmldepapdjbfegei
File Deleted : C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\glmfgahfleepmdfffonfckpmkondpdkg
File Deleted : C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hbcennhacfaagdopikcegfcobcadeocj
File Deleted : C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\icdlfehblmklkikfigmjhbmmpmkmpooj
File Deleted : C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mhkaekfpcppmmioggniknbnbdbcigpkk
File Deleted : C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pfndaklgolladniicklehhancnlgocpp
File Deleted : C:\Users\KIDS.BNSS-LEASED\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_aaaaaigjndjblmpeckabiffcpogflfgl_0.localstorage
File Deleted : C:\Users\KIDS.BNSS-LEASED\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_aaaaaigjndjblmpeckabiffcpogflfgl_0.localstorage-journal
File Deleted : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_icmlaeflemplmjndnaapfdbbnpncnbda_0.localstorage
File Deleted : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_icmlaeflemplmjndnaapfdbbnpncnbda_0.localstorage-journal
File Deleted : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_icmlaeflemplmjndnaapfdbbnpncnbda_0.localstorage
File Deleted : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_icmlaeflemplmjndnaapfdbbnpncnbda_0.localstorage-journal
File Deleted : C:\END
File Deleted : C:\Users\Kids\AppData\Roaming\Mozilla\Firefox\Profiles\p7sl9pri.default\bprotector_prefs.js
File Deleted : C:\Users\Kieran\AppData\Roaming\Mozilla\Firefox\Profiles\pmu0vc00.default\bprotector_prefs.js
File Deleted : C:\Users\Mason\AppData\Roaming\Mozilla\Firefox\Profiles\0ja701s1.default\bprotector_prefs.js
File Deleted : C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\invalidprefs.js
File Deleted : C:\Users\Kids\AppData\Roaming\Mozilla\Firefox\Profiles\p7sl9pri.default\searchplugins\Groovorio.xml
File Deleted : C:\Users\Kieran\AppData\Roaming\Mozilla\Firefox\Profiles\pmu0vc00.default\searchplugins\Groovorio.xml
File Deleted : C:\Users\Mason\AppData\Roaming\Mozilla\Firefox\Profiles\0ja701s1.default\searchplugins\Groovorio.xml
File Deleted : C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\searchplugins\Groovorio.xml
File Deleted : C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\searchplugins\SearchTheWeb.xml
File Deleted : C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\searchplugins\trovi-search.xml
File Deleted : C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\searchplugins\web-search.xml
File Deleted : C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\searchplugins\yahoo_ff.xml
File Deleted : C:\Users\Kids\AppData\Roaming\Mozilla\Firefox\Profiles\p7sl9pri.default\user.js
File Deleted : C:\Users\Kieran\AppData\Roaming\Mozilla\Firefox\Profiles\pmu0vc00.default\user.js
File Deleted : C:\Users\Mason\AppData\Roaming\Mozilla\Firefox\Profiles\0ja701s1.default\user.js
File Deleted : C:\Program Files\Mozilla Firefox\defaults\pref\itms.js
File Deleted : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\bprotector web data
File Deleted : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_answers.ask.com_0.localstorage
File Deleted : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_answers.ask.com_0.localstorage-journal
File Deleted : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage
File Deleted : C:\Users\Kids\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.ask.com_0.localstorage-journal
File Deleted : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences
File Deleted : C:\Users\Kieran\AppData\Local\Google\Chrome\User Data\Default\bprotector web data
File Deleted : C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\bprotector web data
 
***** [ Scheduled tasks ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
Key Deleted : HKCU\Software\Google\Chrome\Extensions\blmchfpimpbbdmgpcieclabeafkljbhm
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\blmchfpimpbbdmgpcieclabeafkljbhm
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaaiabcopkplhgaedhbloeejhhankf
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaaigjndjblmpeckabiffcpogflfgl
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\IMsiDe1egate.Application.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [bprotector start page]
Key Deleted : HKLM\SOFTWARE\Microsoft\WINDOWS\CURRENTVERSION\APP PATHS\PennyBee.exe
Key Deleted : HKCU\Software\808dd9e669ba17
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC99A798-FD3D-4AB4-969E-6071612524F9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{237FDFDB-3722-470E-8BA8-90196DABE967}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F126C9FC-9299-40F2-BD42-C59023AD1E7F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{48A789BF-F6D6-4930-9C8B-77855A63EDE1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC99A798-FD3D-4AB4-969E-6071612524F9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{48A789BF-F6D6-4930-9C8B-77855A63EDE1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C45EC9F0-8333-465D-9728-074BD41985C9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1D2AA885-2C50-4758-A262-17254662A5D5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C277597D-C02B-4C09-9778-671530D2700F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D22421A9-9464-4365-AE9B-D4AD70B99924}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FF777BF5-D424-4519-A61E-2B5BB204894D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C0CAA5FE-7C9C-4DCA-A265-63CF55379D1A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{49a32f81-0ba1-4b43-856c-9a61425e5bf1}
Key Deleted : HKCU\Software\APNDTX
Key Deleted : HKCU\Software\BABSOLUTION
Key Deleted : HKCU\Software\Compete
Key Deleted : HKCU\Software\Conduit
[#] Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\Delta
Key Deleted : HKCU\Software\filescout
Key Deleted : HKCU\Software\ilivid
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\Zugo
Key Deleted : HKCU\Software\Appscion
Key Deleted : HKCU\Software\AppDataLow\Software\AVG Security Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\Dealio
Key Deleted : HKCU\Software\AppDataLow\Software\FunWebProducts
Key Deleted : HKCU\Software\AppDataLow\Software\Search Settings
Key Deleted : HKLM\SOFTWARE\CompeteInc
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\DataMngr
Key Deleted : HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar
Key Deleted : HKLM\SOFTWARE\InstallIQ
Key Deleted : HKLM\SOFTWARE\PerformerSoft
Key Deleted : HKLM\SOFTWARE\Trymedia Systems
Key Deleted : HKU\.DEFAULT\Software\bProtector
Key Deleted : HKU\.DEFAULT\Software\IBUpdaterService
Key Deleted : HKU\.DEFAULT\Software\PennyBee
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Softonic for Windows
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Free Games 111
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Updater Service
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}_is1
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{C878CD69-85DB-426B-81A3-E71175AAEB91}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\file2linkib
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\PennyBee
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Softonic for Windows
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Updater Service
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\InstallBrain Updater Service
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{45F267AE-311F-43E2-BDAA-00D059B93BF9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{97BBECCF-B1FD-4010-8D4B-EFC9E3CCEECF}
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
 
***** [ Web browsers ] *****
 
-\\ Internet Explorer v9.0.8112.16644
 
 
-\\ Mozilla Firefox v30.0 (en-US)
 
[p7sl9pri.default\prefs.js] - Line Deleted : user_pref("extensions.wrc.searchrules.ask.com.style", ".wrcn {display:none} #yui-main .tsrc_vnru .title + .wrcn, #yui-main #teoma-results .title + .wrcn {display:inline !important; background: url(\"i[...]
[p7sl9pri.default\prefs.js] - Line Deleted : user_pref("extensions.wrc.searchrules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");
[p7sl9pri.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "Groovorio");
[p7sl9pri.default\prefs.js] - Line Deleted : user_pref("browser.startup.homepage", "hxxp://groovorio.com/?f=1&a=grv_keyd5_14_24&cd=2XzuyEtN2Y1L1QzutDtDtC0A0AtDyCzyyEyD0FtC0B0E0F0FtN0D0Tzu0StCtDtByCtN1L2XzutAtFyDtFtCtFtCtN1L1Czu1N1C2X1V1J1P2U1QyD[...]
[pmu0vc00.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "Groovorio");
[pmu0vc00.default\prefs.js] - Line Deleted : user_pref("browser.startup.homepage", "hxxp://groovorio.com/?f=1&a=grv_keyd5_14_24&cd=2XzuyEtN2Y1L1QzutDtDtC0A0AtDyCzyyEyD0FtC0B0E0F0FtN0D0Tzu0StCtDtByCtN1L2XzutAtFyDtFtCtFtCtN1L1Czu1N1C2X1V1J1P2U1QyD[...]
[0ja701s1.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "Groovorio");
[0ja701s1.default\prefs.js] - Line Deleted : user_pref("browser.startup.homepage", "hxxp://groovorio.com/?f=1&a=grv_keyd5_14_24&cd=2XzuyEtN2Y1L1QzutDtDtC0A0AtDyCzyyEyD0FtC0B0E0F0FtN0D0Tzu0StCtDtByCtN1L2XzutAtFyDtFtCtFtCtN1L1Czu1N1C2X1V1J1P2U1QyD[...]
[oyn0fdki.default\prefs.js] - Line Deleted : user_pref("communitytoolbar.alert.alertdialogsgetterlastchecktime", "sat may 14 2011 21:40:04 gmt-0500 (central daylight time)");
[oyn0fdki.default\prefs.js] - Line Deleted : user_pref("communitytoolbar.alert.alertinfointerval", 1440);
[oyn0fdki.default\prefs.js] - Line Deleted : user_pref("communitytoolbar.alert.alertinfolastchecktime", "thu jun 23 2011 12:41:35 gmt-0500 (central daylight time)");
[oyn0fdki.default\prefs.js] - Line Deleted : user_pref("communitytoolbar.alert.clientsserverurl", "hxxp://alert.client.conduit.com");
[oyn0fdki.default\prefs.js] - Line Deleted : user_pref("communitytoolbar.alert.locale", "en");
[oyn0fdki.default\prefs.js] - Line Deleted : user_pref("communitytoolbar.alert.loginintervalmin", 1440);
[oyn0fdki.default\prefs.js] - Line Deleted : user_pref("communitytoolbar.alert.loginlastchecktime", "fri jun 24 2011 12:41:27 gmt-0500 (central daylight time)");
[oyn0fdki.default\prefs.js] - Line Deleted : user_pref("communitytoolbar.alert.loginlastupdatetime", "1305622559");
[oyn0fdki.default\prefs.js] - Line Deleted : user_pref("communitytoolbar.alert.messageshowtimesec", 20);
[oyn0fdki.default\prefs.js] - Line Deleted : user_pref("communitytoolbar.alert.servicesserverurl", "hxxp://alert.services.conduit.com");
[oyn0fdki.default\prefs.js] - Line Deleted : user_pref("communitytoolbar.alert.showtrayicon", false);
[oyn0fdki.default\prefs.js] - Line Deleted : user_pref("communitytoolbar.alert.usercloseintervalmin", 300);
[oyn0fdki.default\prefs.js] - Line Deleted : user_pref("communitytoolbar.alert.userid", "58b95e33-3620-45bd-ba55-8367e689fab4");
[oyn0fdki.default\prefs.js] - Line Deleted : user_pref("communitytoolbar.enginehiddenbyuser", false);
[oyn0fdki.default\prefs.js] - Line Deleted : user_pref("communitytoolbar.engineowner", "ct2790392");
[oyn0fdki.default\prefs.js] - Line Deleted : user_pref("communitytoolbar.engineownerguid", "{88c7f2aa-f93f-432c-8f0e-b7d85967a527}");
[oyn0fdki.default\prefs.js] - Line Deleted : user_pref("communitytoolbar.engineownertoolbarid", "bittorrentbar");
 
-\\ Google Chrome v43.0.2357.81
 
[C:\Users\KIDS.BNSS-LEASED\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\KIDS.BNSS-LEASED\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\KIDS.BNSS-LEASED\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Extension] : aaaaaigjndjblmpeckabiffcpogflfgl
[C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.goonsearch.com/web.html?source=IBR-IB-PDP-INS-DBS&q={searchTerms}
[C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://movies.netflix.com/WiSearch?raw_query=holes&ac_category_type=none&ac_rel_posn=-1&ac_abs_posn=-1&v1={searchTerms}&search_submit=
[C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=C6C0001AA06945F1&affID=123485&tt=200813_246&tsp=4981
[C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}
[C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.tb.ask.com/search/GGmain.jhtml?st=kwd&ptb=82BCFDF9-0C2D-4554-ABC0-14414DE7070F&n=77fda4d4&ind=2013111508&p2=^ZJ^xpt298^S07612^us&searchfor={searchTerms}
[C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.search.ask.com/web?tpid=ORJ-V7C&o=APN11411&l=dis&pf=V7&p2=%5EBBJ%5EOSJ000%5EYY%5EUS&gct=&itbv=12.12.2.83&doi=2014-06-09&apn_uid=343602C1-B6E4-4C86-B912-F1D32B97CB1F&apn_ptnrs=BBJ&apn_dtid=%5EOSJ000%5EYY%5EUS&apn_dbr=cr_35.0.1916.114&psv=&pt=tb&trgb=CR&q={searchTerms}
[C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://groovorio.com/results.php?f=4&q={searchTerms}&a=grv_keyd5_14_24&cd=2XzuyEtN2Y1L1QzutDtDtC0A0AtDyCzyyEyD0FtC0B0E0F0FtN0D0Tzu0StCtDtByCtN1L2XzutAtFyDtFtCtFtCtN1L1Czu1N1C2X1V1J1P2U1QyD1VtCyE1VtByEtN1L1G1B1V1N2Y1L1Qzu2SyDtAtC0CyBtCyCtAtG0E0AyE0AtGtA0F0E0DtG0AzzzztBtGtCyB0EyEyEtCyBtCyD0B0E0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0EyCyE0DzzzytCyDtG0FtC0FyCtGyE0F0EtBtG0A0FyBzztGtA0C0EyCyCtDzztByD0B0E0B2Q&cr=885083894&ir=
[C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3320418&octid=EB_ORIGINAL_CTID&ISID=MFD0B5B6D-04C8-4F95-BACC-5AEE62B5F09C&SearchSource=58&CUI=&UM=6&UP=SPD2E4B3D3-3A39-4A43-8464-E48DA47A9EB5&q={searchTerms}&SSPV=
[C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
[C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Deleted [Homepage] : management","nativeMessaging","searchProvider","startupPages","storage","tabs","webRequest","webRequestBlocking"],"explicit_host":["hxxp://*/*","hxxps://*/*"],"manifest_permissions":[],"scriptable_host":["*://*.ask.com/
 
*************************
 
AdwCleaner[R0].txt - [41604 bytes] - [26/05/2015 08:56:58]
AdwCleaner[R1].txt - [41664 bytes] - [26/05/2015 09:01:58]
AdwCleaner[R2].txt - [39837 bytes] - [26/05/2015 09:14:03]
AdwCleaner[S0].txt - [2181 bytes] - [26/05/2015 09:04:48]
AdwCleaner[S1].txt - [26652 bytes] - [26/05/2015 09:15:50]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [26712  bytes] ##########
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.8.0 (05.25.2015:1)
OS: Windows Vista ™ Home Basic x86
Ran by Shayla Potter on 26/05/2015 at  9:30:02.79
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Tasks
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{4E7BD74F-2B8D-469E-C1EA-F165BB85A330}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{EF5F59BA-B2AB-48D8-9747-54DF806C73B8}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EF5F59BA-B2AB-48D8-9747-54DF806C73B8}
 
 
 
~~~ Files
 
Successfully deleted: [File] C:\Windows\System32\protector.dll
Successfully deleted: [File] C:\Windows\wininit.ini
 
 
 
~~~ Folders
 
Successfully deleted: [Folder] C:\ProgramData\datamngr
Successfully deleted: [Folder] C:\ProgramData\iwin games
Successfully deleted: [Folder] C:\Users\Shayla Potter\AppData\Roaming\red kawa
Successfully deleted: [Folder] C:\Users\Shayla Potter\documents\propccleaner
Successfully deleted: [Folder] C:\Users\Shayla Potter\local settings\application data\crashrpt
Successfully deleted: [Folder] C:\Users\Shayla Potter\local settings\application data\pro_pc_cleaner
 
 
 
~~~ FireFox
 
Successfully deleted: [File] C:\Users\Shayla Potter\AppData\Roaming\mozilla\firefox\profiles\oyn0fdki.default\searchplugins\bing-zugo.xml
Successfully deleted the following from C:\Users\Shayla Potter\AppData\Roaming\mozilla\firefox\profiles\oyn0fdki.default\prefs.js
 
user_pref(extensions.delta.admin, false);
user_pref(extensions.delta.aflt, babsst);
user_pref(extensions.delta.appId, {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3});
user_pref(extensions.delta.autoRvrt, false);
user_pref(extensions.delta.dfltLng, en);
user_pref(extensions.delta.excTlbr, false);
user_pref(extensions.delta.ffxUnstlRst, true);
user_pref(extensions.delta.id, c6c0beff000000000000001aa06945f1);
user_pref(extensions.delta.instlDay, 15938);
user_pref(extensions.delta.instlRef, sst);
user_pref(extensions.delta.newTab, false);
user_pref(extensions.delta.prdct, delta);
user_pref(extensions.delta.prtnrId, delta);
user_pref(extensions.delta.rvrt, false);
user_pref(extensions.delta.smplGrp, none);
user_pref(extensions.delta.tlbrId, base);
user_pref(extensions.delta.tlbrSrchUrl, );
user_pref(extensions.delta.vrsn, 1.8.24.6);
user_pref(extensions.delta.vrsnTs, 1.8.24.62:10:31);
user_pref(extensions.delta.vrsni, 1.8.24.6);
user_pref(extensions.delta_i.babExt, );
user_pref(extensions.delta_i.babTrack, affID=123485&tt=200813_246&tsp=4981);
user_pref(extensions.delta_i.srcExt, ss);
Emptied folder: C:\Users\Shayla Potter\AppData\Roaming\mozilla\firefox\profiles\oyn0fdki.default\minidumps [259 files]
 
 
 
~~~ Chrome
 
 
[C:\Users\Shayla Potter\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
 
[C:\Users\Shayla Potter\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
ehjkfdmkpocpileolmldepapdjbfegei
 
[C:\Users\Shayla Potter\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
 
[C:\Users\Shayla Potter\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
  aaaaafeopjhkcolncjbedbhofpocmdbn,
  blmchfpimpbbdmgpcieclabeafkljbhm,
  ehjkfdmkpocpileolmldepapdjbfegei,
  glmfgahfleepmdfffonfckpmkondpdkg,
  hbcennhacfaagdopikcegfcobcadeocj,
  icdlfehblmklkikfigmjhbmmpmkmpooj,
  mhkaekfpcppmmioggniknbnbdbcigpkk,
  pfndaklgolladniicklehhancnlgocpp
]
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 26/05/2015 at  9:33:33.12
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

  • 0

#8
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to the following:
  • Enable free trial of Malwarebytes Anti-Malware Premium
  • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete , make sure that that all Threats are selected, and click Remove Selected.
  • Reboot your computer if prompted.
Posting the Malwarebytes log.
  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the Scan Log which shows the Date and time of the scan just performed.
  • Click 'Export'.
  • Click 'Text file (*.txt)'
  • In the Save File dialog box which appears, click on Desktop.
  • In the File name: box type a name for your scan log.
  • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
  • Click Ok
  • post that saved log to your next reply.

  • 0

#9
crybaby

crybaby

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 175 posts

OK, Here is the MBAM Scan Log you requested. :)

 

 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 27/05/2015
Scan Time: 9:33:13 AM
Logfile: MBAMSCANLOG.txt
Administrator: Yes
 
Version: 2.01.6.1022
Malware Database: v2015.05.27.03
Rootkit Database: v2015.05.24.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
 
OS: Windows Vista Service Pack 2
CPU: x86
File System: NTFS
User: Shayla Potter
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 623108
Time Elapsed: 53 min, 18 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 82
PUP.Optional.Mindspark.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000_Classes\CLSID\{c3d3840c-12ea-4461-a61d-190555fecc82}, Quarantined, [7e21d8c0fa9086b08e04504abe45ef11], 
PUP.Optional.Mindspark.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1009_Classes\CLSID\{C3D3840C-12EA-4461-A61D-190555FECC82}, Quarantined, [7e21d8c0fa9086b08e04504abe45ef11], 
PUP.Optional.Mindspark.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010_Classes\CLSID\{C3D3840C-12EA-4461-A61D-190555FECC82}, Quarantined, [7e21d8c0fa9086b08e04504abe45ef11], 
PUP.Optional.Mindspark.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501_Classes\CLSID\{C3D3840C-12EA-4461-A61D-190555FECC82}, Quarantined, [7e21d8c0fa9086b08e04504abe45ef11], 
PUP.Optional.Babylon.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, Quarantined, [7f20d7c18901f244e1431f3f2cd744bc], 
PUP.Optional.Babylon.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}, Quarantined, [7f20d7c18901f244e1431f3f2cd744bc], 
PUP.Optional.Babylon.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}, Quarantined, [7f20d7c18901f244e1431f3f2cd744bc], 
PUP.Optional.Babylon.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}, Quarantined, [7f20d7c18901f244e1431f3f2cd744bc], 
PUP.Optional.Dealio.A, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}, Quarantined, [f1ae6c2c6426171fcec76beddf24dc24], 
PUP.Optional.Dealio.A, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}, Quarantined, [f1ae6c2c6426171fcec76beddf24dc24], 
PUP.Optional.Dealio.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}, Quarantined, [f1ae6c2c6426171fcec76beddf24dc24], 
PUP.Optional.AppGraffiti.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}, Quarantined, [6f304e4a2466b482c9bcf99dba49a45c], 
PUP.Optional.AppGraffiti.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}, Quarantined, [6f304e4a2466b482c9bcf99dba49a45c], 
PUP.Optional.AppGraffiti.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}, Quarantined, [6f304e4a2466b482c9bcf99dba49a45c], 
PUP.Optional.AppGraffiti.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}, Quarantined, [6f304e4a2466b482c9bcf99dba49a45c], 
PUP.Optional.Delta.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{82E1477C-B154-48D3-9891-33D83C26BCD3}, Quarantined, [4f506f29addd68cefe83f1a52bd8c23e], 
PUP.Optional.Delta.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{82E1477C-B154-48D3-9891-33D83C26BCD3}, Quarantined, [4f506f29addd68cefe83f1a52bd8c23e], 
PUP.Optional.Delta.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{82E1477C-B154-48D3-9891-33D83C26BCD3}, Quarantined, [4f506f29addd68cefe83f1a52bd8c23e], 
PUP.Optional.Delta.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{82E1477C-B154-48D3-9891-33D83C26BCD3}, Quarantined, [4f506f29addd68cefe83f1a52bd8c23e], 
PUP.Optional.CouponBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{8660E5B3-6C41-44DE-8503-98D99BBECD41}, Quarantined, [dfc0b0e8aae079bd44b26000ba49a060], 
PUP.Optional.CouponBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1009\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{8660E5B3-6C41-44DE-8503-98D99BBECD41}, Quarantined, [dfc0b0e8aae079bd44b26000ba49a060], 
PUP.Optional.CouponBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{8660E5B3-6C41-44DE-8503-98D99BBECD41}, Quarantined, [dfc0b0e8aae079bd44b26000ba49a060], 
PUP.Optional.CouponBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{8660E5B3-6C41-44DE-8503-98D99BBECD41}, Quarantined, [dfc0b0e8aae079bd44b26000ba49a060], 
PUP.Optional.CouponBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{8660E5B3-6C41-44DE-8503-98D99BBECD41}, Quarantined, [dfc0b0e8aae079bd44b26000ba49a060], 
PUP.Optional.CouponBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{8660E5B3-6C41-44DE-8503-98D99BBECD41}, Quarantined, [dfc0b0e8aae079bd44b26000ba49a060], 
PUP.Optional.CouponBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1009\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{8660E5B3-6C41-44DE-8503-98D99BBECD41}, Quarantined, [dfc0b0e8aae079bd44b26000ba49a060], 
PUP.Optional.CouponBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{8660E5B3-6C41-44DE-8503-98D99BBECD41}, Quarantined, [dfc0b0e8aae079bd44b26000ba49a060], 
PUP.Optional.CouponBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{8660E5B3-6C41-44DE-8503-98D99BBECD41}, Quarantined, [dfc0b0e8aae079bd44b26000ba49a060], 
PUP.Optional.CouponBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{8660E5B3-6C41-44DE-8503-98D99BBECD41}, Quarantined, [dfc0b0e8aae079bd44b26000ba49a060], 
PUP.Optional.SearchToolbar, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{9D425283-D487-4337-BAB6-AB8354A81457}, Quarantined, [465954447515ba7cb7bad6c1ec176c94], 
PUP.Optional.SearchToolbar, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{9D425283-D487-4337-BAB6-AB8354A81457}, Quarantined, [465954447515ba7cb7bad6c1ec176c94], 
PUP.Optional.BestToolbar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}, Quarantined, [712ec3d54c3eb3830849d28d32d1a759], 
PUP.Optional.BestToolbar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1009\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}, Quarantined, [712ec3d54c3eb3830849d28d32d1a759], 
PUP.Optional.BestToolbar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}, Quarantined, [712ec3d54c3eb3830849d28d32d1a759], 
PUP.Optional.BestToolbar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}, Quarantined, [712ec3d54c3eb3830849d28d32d1a759], 
PUP.Optional.BestToolbar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}, Quarantined, [712ec3d54c3eb3830849d28d32d1a759], 
PUP.Optional.BestToolbar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}, Quarantined, [712ec3d54c3eb3830849d28d32d1a759], 
PUP.Optional.BestToolbar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1009\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}, Quarantined, [712ec3d54c3eb3830849d28d32d1a759], 
PUP.Optional.BestToolbar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}, Quarantined, [712ec3d54c3eb3830849d28d32d1a759], 
PUP.Optional.BestToolbar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}, Quarantined, [712ec3d54c3eb3830849d28d32d1a759], 
PUP.Optional.BestToolbar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}, Quarantined, [712ec3d54c3eb3830849d28d32d1a759], 
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, Quarantined, [6d32039555354de9447fcf8fdb2838c8], 
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, Quarantined, [6d32039555354de9447fcf8fdb2838c8], 
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}, Quarantined, [f7a8782036540c2abf0271279271ec14], 
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}, Quarantined, [f7a8782036540c2abf0271279271ec14], 
PUP.Optional.SpeedDial.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{48A789BF-F6D6-4930-9C8B-77855A63EDE1}, Quarantined, [7926f4a43c4e6bcb46cb7ee1877c6e92], 
PUP.Optional.SpeedDial.A, HKLM\SOFTWARE\CLASSES\SpeedDial.TSpeedDial, Quarantined, [7926f4a43c4e6bcb46cb7ee1877c6e92], 
PUP.Optional.SpeedDial.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{48A789BF-F6D6-4930-9C8B-77855A63EDE1}, Quarantined, [7926f4a43c4e6bcb46cb7ee1877c6e92], 
PUP.Optional.SpeedDial.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1059\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{48A789BF-F6D6-4930-9C8B-77855A63EDE1}, Quarantined, [7926f4a43c4e6bcb46cb7ee1877c6e92], 
PUP.Optional.SpeedDial.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{48A789BF-F6D6-4930-9C8B-77855A63EDE1}, Quarantined, [7926f4a43c4e6bcb46cb7ee1877c6e92], 
PUP.Optional.SpeedDial.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{48A789BF-F6D6-4930-9C8B-77855A63EDE1}, Quarantined, [7926f4a43c4e6bcb46cb7ee1877c6e92], 
PUP.Optional.MyPoints.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A057A204-BACC-4D26-CEC4-75A487FD6484}, Quarantined, [b9e64d4b9eec082e52d6045a3cc77b85], 
PUP.Optional.Mindspark.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A916EEFE-6A17-4D7D-A131-2738B260BB55}, Quarantined, [b4ebff995139ec4a4a4a0694758eba46], 
PUP.Optional.Mindspark.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{D6A34ACB-76FA-4A14-88EA-5D54797A2028}, Quarantined, [d4cbdbbd61291b1bf0a6772344bfde22], 
PUP.Optional.Mindspark.A, HKLM\SOFTWARE\Guffins, Quarantined, [c1de6236a6e46cca85731945c73eb947], 
PUP.Optional.BitTorrentBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\APPDATALOW\SOFTWARE\BitTorrentBar, Quarantined, [c2dd613731592a0c6af21bd6ae553fc1], 
PUP.Optional.FunWebProducts.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\APPDATALOW\SOFTWARE\FunWebProducts, Quarantined, [bbe4e2b6c2c893a3ea1efc1b3ec618e8], 
PUP.Optional.Mindspark.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\APPDATALOW\SOFTWARE\Guffins, Quarantined, [e5ba1385cfbb96a08f484fc736cef30d], 
PUP.Optional.Spigot.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{54ACE04D-52D8-4E32-97D3-0E379B1128F0}, Quarantined, [a5fa9efaeb9fee484ed7c81a4cb72fd1], 
PUP.Optional.MyWebSearch.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BD172BA-3F40-4303-BCA1-0484B5BA2A7B}, Quarantined, [e6b962368dfde94d5d1d4138b3523ac6], 
PUP.Optional.MoviesToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1005\SOFTWARE\ilividbandoomoviestoolbar, Quarantined, [f6a9fb9d9af059ddb06e7bb4c1438e72], 
PUP.Optional.ProPCCleaner.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1005\SOFTWARE\ProPCCleanerLanguage, Quarantined, [d8c7e5b397f3251164076f08a26354ac], 
PUP.Optional.RapidMediaConverter.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1005\SOFTWARE\RapidMediaConverterApp, Quarantined, [1b846533a5e56ec812d604723ec7c739], 
PUP.Optional.Mindspark.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1005\SOFTWARE\APPDATALOW\SOFTWARE\Guffins, Quarantined, [118eeaae90fa88aebb1c1afc13f11ee2], 
PUP.Optional.Spigot.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1005\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CC865B26-C31D-4D23-B17B-96548EEF03F6}, Quarantined, [cad520783e4c59dda87d439f60a350b0], 
PUP.Optional.FunWebProducts.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1009\SOFTWARE\APPDATALOW\SOFTWARE\FunWebProducts, Quarantined, [48570d8b98f2063052b60215d33144bc], 
PUP.Optional.Mindspark.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1009\SOFTWARE\APPDATALOW\SOFTWARE\Guffins, Quarantined, [336c0a8e4347d46228afa076c53f38c8], 
PUP.Optional.MyWebSearch.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1009\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BD172BA-3F40-4303-BCA1-0484B5BA2A7B}, Quarantined, [b1ee5f390b7f7cbaec8e99e0986d7c84], 
PUP.Optional.FunWebProducts.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\APPDATALOW\SOFTWARE\FunWebProducts, Quarantined, [f4aba2f66c1ee25436d2888ffa0ace32], 
PUP.Optional.Mindspark.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\APPDATALOW\SOFTWARE\Guffins, Quarantined, [752a7d1bf9913105d8ffe333d92b1ae6], 
PUP.Optional.Spigot.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{54ACE04D-52D8-4E32-97D3-0E379B1128F0}, Quarantined, [2877b0e8840660d62ff65d8542c17987], 
PUP.Optional.MyWebSearch.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BD172BA-3F40-4303-BCA1-0484B5BA2A7B}, Quarantined, [99062f69aedc48ee57234633966f12ee], 
PUP.Optional.FunWebProducts.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\APPDATALOW\SOFTWARE\FunWebProducts, Quarantined, [4b5456420189ed4928e022f5947048b8], 
PUP.Optional.Mindspark.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\APPDATALOW\SOFTWARE\Guffins, Quarantined, [7629f3a546440432a73047cf35cf649c], 
PUP.Optional.BProtector, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\BPROTECTOR, Quarantined, [ccd3abeda1e90e287d42e02a08fd0ef2], 
PUP.Optional.Spigot.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{54ACE04D-52D8-4E32-97D3-0E379B1128F0}, Quarantined, [18875a3eff8b91a52ff6657dfe056f91], 
PUP.Optional.MyWebSearch.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BD172BA-3F40-4303-BCA1-0484B5BA2A7B}, Quarantined, [8f10ff998406f343324811682dd8d030], 
PUP.Optional.BitTorrentBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\APPDATALOW\SOFTWARE\BitTorrentBar, Quarantined, [8c131e7ac3c744f20d4fbb367d86639d], 
PUP.Optional.FunWebProducts.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\APPDATALOW\SOFTWARE\FunWebProducts, Quarantined, [9906692f414979bd9870cd4a7490926e], 
PUP.Optional.Mindspark.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\APPDATALOW\SOFTWARE\Guffins, Quarantined, [1c830890f793132351868c8a8e7604fc], 
PUP.Optional.Spigot.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{54ACE04D-52D8-4E32-97D3-0E379B1128F0}, Quarantined, [554acbcd6f1b49ed6abb439fe1227d83], 
PUP.Optional.MyWebSearch.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BD172BA-3F40-4303-BCA1-0484B5BA2A7B}, Quarantined, [e3bc3662ed9dd85e91e9d2a75ea7e917], 
 
Registry Values: 62
PUP.Optional.Mindspark.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{C3D3840C-12EA-4461-A61D-190555FECC82}, Quarantined, [7e21d8c0fa9086b08e04504abe45ef11], 
PUP.Optional.SearchToolbar, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{9D425283-D487-4337-BAB6-AB8354A81457}, Æ?RBÂâ?¡Ã?7Cº¶«Æ?T¨ W, Quarantined, [465954447515ba7cb7bad6c1ec176c94]
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, Quarantined, [6d32039555354de9447fcf8fdb2838c8], 
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1009\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, Quarantined, [6d32039555354de9447fcf8fdb2838c8], 
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, Quarantined, [6d32039555354de9447fcf8fdb2838c8], 
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, Quarantined, [6d32039555354de9447fcf8fdb2838c8], 
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, Quarantined, [6d32039555354de9447fcf8fdb2838c8], 
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{D7E97865-918F-41E4-9CD0-25AB1C574CE8}, exéÃ?Ââ??äAÅ?Ã%« WLè, Quarantined, [f7a8782036540c2abf0271279271ec14]
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1009\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{D7E97865-918F-41E4-9CD0-25AB1C574CE8}, exéÃ?Ââ??äAÅ?Ã%« WLè, Quarantined, [f7a8782036540c2abf0271279271ec14]
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{D7E97865-918F-41E4-9CD0-25AB1C574CE8}, exéÃ?Ââ??äAÅ?Ã%« WLè, Quarantined, [f7a8782036540c2abf0271279271ec14]
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{D7E97865-918F-41E4-9CD0-25AB1C574CE8}, exéÃ?Ââ??äAÅ?Ã%« WLè, Quarantined, [f7a8782036540c2abf0271279271ec14]
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{D7E97865-918F-41E4-9CD0-25AB1C574CE8}, exéÃ?Ââ??äAÅ?Ã%« WLè, Quarantined, [f7a8782036540c2abf0271279271ec14]
PUP.Optional.MyPoints.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{A057A204-BACC-4D26-CEC4-75A487FD6484},  Â¢W Ã?º&MÃ?Ã?u¤â?¡Ã½dâ??, Quarantined, [b9e64d4b9eec082e52d6045a3cc77b85]
PUP.Optional.MyPoints.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{A057A204-BACC-4D26-CEC4-75A487FD6484}, Quarantined, [8b1441576b1f191d83a58fcf57acf40c], 
PUP.Optional.SearchToolbar, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{9D425283-D487-4337-BAB6-AB8354A81457}, Quarantined, [1e8132662c5e1d1985ec97004fb4629e], 
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}, Quarantined, [9807f5a36327b97d0fb2692f1ce7fa06], 
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1009\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}, Quarantined, [f6a93464800a32046859ceca9073ea16], 
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}, Quarantined, [039cecacb8d20b2bdbe6bfd9fd06fb05], 
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}, Quarantined, [148b0791602a8da907ba1484ea19926e], 
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}, Quarantined, [97084f49ef9b67cf7a4791074fb41be5], 
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, Quarantined, [b3ec1d7bbad016200cb78ad4cc37e61a], 
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1009\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, Quarantined, [f4ab5a3ee5a56cca685bcc927093c33d], 
PUP.Optional.Mindspark.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{c3d3840c-12ea-4461-a61d-190555fecc82}, Quarantined, [9e01dbbd206ab482b2e0d7c36f94639d], 
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, Quarantined, [b3eccfc9345674c23093b1ad7291956b], 
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, Quarantined, [544bc3d505855fd7fcc79ec0b84b8977], 
PUP.Optional.InboxToolBar.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, Quarantined, [6738791f2a6084b2c9fac19d57ac748c], 
PUP.Optional.Groovorio.C, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files\Groovorio\\, Quarantined, [ced1336514761521590e1bc5bd467090]
PUP.Optional.BProtector, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|bProtectorDefaultScope, {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}, Quarantined, [a2fd8315ff8bc96d89384dbdd92c6898]
PUP.BProtector, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, http://www.goonsearc...R-IB-PDP-INS-HP, Quarantined, [1a8561373456a78f6993390a6d980ef2]
PUP.BProtector, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|bProtectorDefaultScope, {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}, Quarantined, [b1ee2a6e4248f046dc214201be4740c0]
PUP.Optional.Delta.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}|URL, http://www1.delta-se...3_246&tsp=4981,Quarantined, [c6d99404cebc8ea8189586eb9174e917]
PUP.Optional.Babylon.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}|FaviconURL, search.babylon.com/favicon.ico, Quarantined, [e3bc2a6eee9c70c6df04b826927128d8]
PUP.Optional.Spigot.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{54ACE04D-52D8-4E32-97D3-0E379B1128F0}|URL, http://search.yahoo....={searchTerms},Quarantined, [a5fa9efaeb9fee484ed7c81a4cb72fd1]
PUP.Optional.Spigot.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{54ACE04D-52D8-4E32-97D3-0E379B1128F0}|OSDFileURL, file:///C:/Program%20Files/Common%20Files/Spigot/Search%20Settings/yahoo_ie.xml, Quarantined, [4b544850c6c4d5612efe7009d233a858]
PUP.Optional.MyWebSearch.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9bd172ba-3f40-4303-bca1-0484b5ba2a7b}|URL, http://search.mywebs...={searchTerms},Quarantined, [e6b962368dfde94d5d1d4138b3523ac6]
PUP.Optional.Spigot.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1005\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CC865B26-C31D-4D23-B17B-96548EEF03F6}|URL, http://search.yahoo....={searchTerms},Quarantined, [cad520783e4c59dda87d439f60a350b0]
PUP.Optional.Spigot.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1005\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CC865B26-C31D-4D23-B17B-96548EEF03F6}|OSDFileURL, file:///C:/Program%20Files/Common%20Files/Spigot/Search%20Settings/yahoo_ie.xml, Quarantined, [aaf57a1eff8b83b32408730631d49c64]
PUP.BProtector, HKU\S-1-5-21-1260561122-373576474-2963483527-1009\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, http://www.goonsearc...R-IB-PDP-INS-HP, Quarantined, [c4db6b2d850583b34fad0e35aa5ba060]
PUP.BProtector, HKU\S-1-5-21-1260561122-373576474-2963483527-1009\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|bProtectorDefaultScope, {6A1806CD-94D4-4689-BA73-E35EA1EA9990}, Quarantined, [049bcfc95634b581fa0396ad20e59967]
PUP.Optional.MyWebSearch.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1009\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9bd172ba-3f40-4303-bca1-0484b5ba2a7b}|URL, http://search.mywebs...={searchTerms},Quarantined, [b1ee5f390b7f7cbaec8e99e0986d7c84]
PUP.BProtector, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, http://www.goonsearc...R-IB-PDP-INS-HP, Quarantined, [efb0eeaa8bffe84efa023b08768f926e]
PUP.BProtector, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|bProtectorDefaultScope, {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}, Quarantined, [633c5c3c6624e84e3ebfe65d887dce32]
PUP.Optional.Delta.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}|URL, http://www1.delta-se...3_246&tsp=4981,Quarantined, [67386632eaa0b4824469383909fc8c74]
PUP.Optional.Babylon.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}|FaviconURL, search.babylon.com/favicon.ico, Quarantined, [e9b6cccc1a701620cc17d20c12f1946c]
PUP.Optional.Spigot.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{54ACE04D-52D8-4E32-97D3-0E379B1128F0}|URL, http://search.yahoo....={searchTerms},Quarantined, [2877b0e8840660d62ff65d8542c17987]
PUP.Optional.Spigot.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{54ACE04D-52D8-4E32-97D3-0E379B1128F0}|OSDFileURL, file:///C:/Program%20Files/Common%20Files/Spigot/Search%20Settings/yahoo_ie.xml, Quarantined, [009f1b7d95f545f1f8346613c54034cc]
PUP.Optional.MyWebSearch.A, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9bd172ba-3f40-4303-bca1-0484b5ba2a7b}|URL, http://search.mywebs...={searchTerms},Quarantined, [99062f69aedc48ee57234633966f12ee]
PUP.Optional.BProtector, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\BPROTECTOR|iexplore homepages, http://go.microsoft....ww.yahoo.com/^^, Quarantined, [ccd3abeda1e90e287d42e02a08fd0ef2]
PUP.BProtector, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, http://www.goonsearc...R-IB-PDP-INS-HP, Quarantined, [d5ca6c2c2862f343eb1155ee44c10000]
PUP.BProtector, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|bProtectorDefaultScope, {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}, Quarantined, [2a755642e0aa89add726053e907556aa]
PUP.Optional.Delta.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}|URL, http://www1.delta-se...3_246&tsp=4981,Quarantined, [148b1385a9e15bdbddd04d242dd88080]
PUP.Optional.Babylon.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}|FaviconURL, search.babylon.com/favicon.ico, Quarantined, [d0cf3167f694cb6bfbe847979b68b749]
PUP.Optional.Spigot.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{54ACE04D-52D8-4E32-97D3-0E379B1128F0}|URL, http://search.yahoo....={searchTerms},Quarantined, [18875a3eff8b91a52ff6657dfe056f91]
PUP.Optional.Spigot.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{54ACE04D-52D8-4E32-97D3-0E379B1128F0}|OSDFileURL, file:///C:/Program%20Files/Common%20Files/Spigot/Search%20Settings/yahoo_ie.xml, Quarantined, [257a7f19e7a301351b11007961a4817f]
PUP.Optional.MyWebSearch.A, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9bd172ba-3f40-4303-bca1-0484b5ba2a7b}|URL, http://search.mywebs...={searchTerms},Quarantined, [8f10ff998406f343324811682dd8d030]
PUP.BProtector, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, http://www.goonsearc...R-IB-PDP-INS-HP, Quarantined, [fea1f5a3f49668ceb9436dd609fc817f]
PUP.BProtector, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|bProtectorDefaultScope, {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}, Quarantined, [f8a750489feb68cefffebc87a560eb15]
PUP.Optional.Delta.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}|URL, http://www1.delta-se...3_246&tsp=4981,Quarantined, [049b6731d7b33ff78e1fc0b1887d29d7]
PUP.Optional.Babylon.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}|FaviconURL, search.babylon.com/favicon.ico, Quarantined, [2f70e8b0b2d8e353776c4f8f18eb7a86]
PUP.Optional.Spigot.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{54ACE04D-52D8-4E32-97D3-0E379B1128F0}|URL, http://search.yahoo....={searchTerms},Quarantined, [554acbcd6f1b49ed6abb439fe1227d83]
PUP.Optional.Spigot.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{54ACE04D-52D8-4E32-97D3-0E379B1128F0}|OSDFileURL, file:///C:/Program%20Files/Common%20Files/Spigot/Search%20Settings/yahoo_ie.xml, Quarantined, [aaf5a8f0fb8f56e01a12e2971de81fe1]
PUP.Optional.MyWebSearch.A, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9bd172ba-3f40-4303-bca1-0484b5ba2a7b}|URL, http://search.mywebs...={searchTerms},Quarantined, [e3bc3662ed9dd85e91e9d2a75ea7e917]
 
Registry Data: 6
Hijack.StartPage, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, http://toolbar.inbox...tb_id&%language, Good: (www.google.com), Bad: (http://toolbar.inbox.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=%tb_id&%language),Replaced,[7c231781f99182b432ec54d758aec838]
Hijack.SearchBar, HKU\S-1-5-21-1260561122-373576474-2963483527-1010\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, http://toolbar.inbox...tb_id&%language, Good: (www.google.com/), Bad: (http://toolbar.inbox.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=%tb_id&%language),Replaced,[bfe0a8f0e1a97db95fc141ea09fd59a7]
Hijack.StartPage, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, http://toolbar.inbox...tb_id&%language, Good: (www.google.com), Bad: (http://toolbar.inbox.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=%tb_id&%language),Replaced,[3b644b4d9bef0333ce50111ab74f9070]
Hijack.SearchBar, HKU\S-1-5-21-1260561122-373576474-2963483527-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, http://toolbar.inbox...tb_id&%language, Good: (www.google.com/), Bad: (http://toolbar.inbox.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=%tb_id&%language),Replaced,[544bc1d797f3bc7a22fe5bd08e7817e9]
Hijack.StartPage, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, http://toolbar.inbox...tb_id&%language, Good: (www.google.com), Bad: (http://toolbar.inbox.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=%tb_id&%language),Replaced,[900fe3b505852610809e50db8a7cfc04]
Hijack.SearchBar, HKU\S-1-5-21-1260561122-373576474-2963483527-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, http://toolbar.inbox...tb_id&%language, Good: (www.google.com/), Bad: (http://toolbar.inbox.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=%tb_id&%language),Replaced,[2b74a2f6fd8df6406cb4ce5dbc4af30d]
 
Folders: 18
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\History, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Settings, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\Guffins, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\Guffins\Cache, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Shayla Potter\AppData\LocalLow\GuffinsEI, Quarantined, [d7c85246028872c4e1789b1f19ea6f91], 
PUP.Optional.Mindspark.A, C:\Users\Shayla Potter\AppData\LocalLow\GuffinsEI\Installr, Quarantined, [d7c85246028872c4e1789b1f19ea6f91], 
PUP.Optional.Mindspark.A, C:\Users\Shayla Potter\AppData\LocalLow\GuffinsEI\Installr\Cache, Quarantined, [d7c85246028872c4e1789b1f19ea6f91], 
PUP.Optional.Spigot.A, C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hbcennhacfaagdopikcegfcobcadeocj, Quarantined, [0996a0f83852b6803beefac219eae31d], 
PUP.Optional.Spigot.A, C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pfndaklgolladniicklehhancnlgocpp, Quarantined, [e7b8bedac2c84de99b8f615be023a55b], 
PUP.Optional.Groovorio.A, C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\nspdlgrvrio, Quarantined, [1c83197ff6947eb8b92eecd552b143bd], 
PUP.Optional.Groovorio.A, C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\nspdlgrvrio\fav_thumbs, Quarantined, [1c83197ff6947eb8b92eecd552b143bd], 
PUP.Optional.PennyBee.A, C:\Windows\System32\config\systemprofile\AppData\Local\ICSharpCode.net\PennyBeeW.exe_Url_agkh2q2wptz44nr1mbd43tyforr5s4zl, Quarantined, [e1be61378a00cc6ac7182e9a966daf51], 
PUP.Optional.PennyBee.A, C:\Windows\System32\config\systemprofile\AppData\Local\ICSharpCode.net\PennyBeeW.exe_Url_agkh2q2wptz44nr1mbd43tyforr5s4zl\1.0.2.0, Quarantined, [e1be61378a00cc6ac7182e9a966daf51], 
PUP.Optional.Spigot.A, C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mhkaekfpcppmmioggniknbnbdbcigpkk, Quarantined, [3d6234643a50ad890a76d201ba4919e7], 
PUP.Optional.Spigot.A, C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\icdlfehblmklkikfigmjhbmmpmkmpooj, Quarantined, [306f34644e3c89ad651d2ba8d92a02fe], 
 
Files: 71
PUP.Optional.Yappyz.A, C:\Users\Shayla Potter\AppData\Roaming\Angry_Birds\Angry_Birds.exe, Quarantined, [a0ff8a0e99f19c9a58bfcb3e9f63c43c], 
PUP.Optional.Mindspark.A, C:\Program Files\u4res.dll, Quarantined, [c3dc5246a2e876c0be07bea9ec1ae11f], 
PUP.Optional.Bunndle, C:\Program Files\CamStudio 2.7\BunndleOfferManager.exe, Quarantined, [811e287093f7f4425ee79ac513ed52ae], 
PUP.Optional.Babylon.A, C:\Program Files\OpenDownloaderManager\delta2.exe, Quarantined, [376893057e0c59dd9fb5ec4ffc050cf4], 
PUP.Optional.ArcadeFrontier.A, C:\Users\Shayla Potter\Downloads\ArcadeFrontierGames (1).exe, Quarantined, [6738bfd9becc7db931e895f9b44d34cc], 
PUP.Optional.ArcadeFrontier.A, C:\Users\Shayla Potter\Downloads\ArcadeFrontierGames.exe, Quarantined, [910eefa9256589ade33606888a77f30d], 
PUP.Optional.ArcadeSafari.A, C:\Users\Shayla Potter\Downloads\ArcadeSafariGames.exe, Quarantined, [d9c6aceccfbb93a38752faf6d13006fa], 
PUP.Optional.InstallIQ.A, C:\Users\Shayla Potter\Downloads\mplayer_tuguu_d1021510.exe, Quarantined, [920d9ff90b7f8caa6f2a95b69d64ef11], 
PUP.Optional.Inbox, C:\Users\Shayla Potter\Downloads\MusicSetup.exe, Quarantined, [07980791d6b42c0a96d4b9854db48080], 
PUP.Optional.Mindspark.A, C:\Users\Shayla Potter\Downloads\ZwinkyCrxSetup.82BCFDF9-0C2D-4554-ABC0-14414DE7070F.exe, Quarantined, [9d02dbbdbbcff64035903532a85eff01], 
PUP.Optional.OutBrowse, C:\Users\Shayla Potter\Downloads\Setup.rar, Quarantined, [6837c8d0543686b0b174f4f2d52c718f], 
PUP.Optional.OpenCandy, C:\Users\Shayla Potter\Downloads\videora-ipod-600-setup.exe, Quarantined, [455a0e8aabdf181efba5d18129dda45c], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\0121FEED.bmp, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\026D0578.bmp, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\0121A6BF, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\0121AEF9, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\0121B31E.bmp, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\0121B58E.bmp, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\0121B8C9.bmp, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\0121BA01.bmp, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\0121BB48.bmp, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\0121BCBF.bmp, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\0121BD8A.bmp, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\0121BE64.bmp, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\0121C132.bmp, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\0121C3FF.bmp, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\0121C6FC.bmp, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\0121C9BA.bmp, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\0121CB30.bmp, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\0121CD90.jhtml, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\0121EB2E, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\0174C181.bmp, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\01ABDADC, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\0494B458.bmp, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Cache\files.ini, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\History\search3, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Settings\prevcfg2.htm, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Settings\setting3.htm, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Settings\setting3.htm.bak, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Settings\s_w1.dat, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Settings\s_w1.dat.bak, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Settings\s_w2.dat, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\bar\Settings\s_w2.dat.bak, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\Guffins\Cache\PopupProperties100021150.html, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\Guffins\Cache\PopupProperties100021803.html, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\Guffins\Cache\PopupProperties100021805.html, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\Guffins\Cache\PopupProperties100021807.html, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\Guffins\Cache\PopupProperties100021809.html, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\Guffins\Cache\PopupProperties100021812.html, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\Guffins\Cache\PopupProperties100021814.html, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\Guffins\Cache\PopupProperties100035271.html, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\Guffins\Cache\PopupProperties100035273.html, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Kieran\AppData\LocalLow\Guffins\Guffins\Cache\PopupProperties100065024.html, Quarantined, [940b18800585fb3ba7b26b4fe81bd62a], 
PUP.Optional.Mindspark.A, C:\Users\Shayla Potter\AppData\LocalLow\GuffinsEI\Installr\Cache\01E6B083.exe, Quarantined, [d7c85246028872c4e1789b1f19ea6f91], 
PUP.Optional.Mindspark.A, C:\Users\Shayla Potter\AppData\LocalLow\GuffinsEI\Installr\Cache\files.ini, Quarantined, [d7c85246028872c4e1789b1f19ea6f91], 
PUP.Optional.Groovorio.A, C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\nspdlgrvrio\fav-groups, Quarantined, [1c83197ff6947eb8b92eecd552b143bd], 
PUP.Optional.Groovorio.A, C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\nspdlgrvrio\favs##942006f8edc57d8c49494bfc968642bf, Quarantined, [1c83197ff6947eb8b92eecd552b143bd], 
PUP.Optional.Groovorio.A, C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\nspdlgrvrio\favs##a9f7c77fc2446f61341aae55441bbfb1, Quarantined, [1c83197ff6947eb8b92eecd552b143bd], 
PUP.Optional.Groovorio.A, C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\nspdlgrvrio\fav_thumbs\142bfe64629a488669e3b5120b5e7daf, Quarantined, [1c83197ff6947eb8b92eecd552b143bd], 
PUP.Optional.Groovorio.A, C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\nspdlgrvrio\fav_thumbs\2961a5aa5f4b9d12caa77c56e39771ee, Quarantined, [1c83197ff6947eb8b92eecd552b143bd], 
PUP.Optional.Groovorio.A, C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\nspdlgrvrio\fav_thumbs\7a2538cdef3cda8a93c207db8faad8fe, Quarantined, [1c83197ff6947eb8b92eecd552b143bd], 
PUP.Optional.Groovorio.A, C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\nspdlgrvrio\fav_thumbs\80cf5105902805af514c7eb58a16536f, Quarantined, [1c83197ff6947eb8b92eecd552b143bd], 
PUP.Optional.Groovorio.A, C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\nspdlgrvrio\fav_thumbs\844798da64540b59fff5bd216dfcef06, Quarantined, [1c83197ff6947eb8b92eecd552b143bd], 
PUP.Optional.Groovorio.A, C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\nspdlgrvrio\fav_thumbs\a40505dc2a94cf49c951a934c7bb06ab, Quarantined, [1c83197ff6947eb8b92eecd552b143bd], 
PUP.Optional.Groovorio.A, C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\nspdlgrvrio\fav_thumbs\a8934e88ee482bcdb090c6bb541cef9d, Quarantined, [1c83197ff6947eb8b92eecd552b143bd], 
PUP.Optional.Groovorio.A, C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\nspdlgrvrio\fav_thumbs\d0ec4a944b1712cfbcf20953541280e7, Quarantined, [1c83197ff6947eb8b92eecd552b143bd], 
PUP.Optional.Groovorio.A, C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\nspdlgrvrio\fav_thumbs\eedcef8ef902e676d7f43de4d82a73e0, Quarantined, [1c83197ff6947eb8b92eecd552b143bd], 
PUP.Optional.Groovorio.A, C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\nspdlgrvrio\fav_thumbs\f654d0abf6c11dfdc5be993b1e56d9d2, Quarantined, [1c83197ff6947eb8b92eecd552b143bd], 
PUP.Optional.Groovorio.A, C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\nspdlgrvrio\fav_thumbs\ff5cdcdf065d10ffc2b8a92ffaae8a41, Quarantined, [1c83197ff6947eb8b92eecd552b143bd], 
PUP.Optional.PennyBee.A, C:\Windows\System32\config\systemprofile\AppData\Local\ICSharpCode.net\PennyBeeW.exe_Url_agkh2q2wptz44nr1mbd43tyforr5s4zl\1.0.2.0\user.config, Quarantined, [e1be61378a00cc6ac7182e9a966daf51], 
PUP.Optional.ASK.A, C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences, Good: (), Bad: ({"browser":{"show_home_button":true},"extensions":{"settings":{"aaaaaiabcopkplhgaedhbloeejhhankf":{"ack_prompt_count":3,"active_permissions":{"api":["homepage","management","nativeMessaging","searchProvider","startupPages","storage","tabs","webRequest","webRequestBlocking"],"explicit_host":["http://*/*","https://*/*"],"manifest_permissions":[],"scriptable_host":["*://*.ask.com/","*://*.bagsbuy.com/*","*://*.childrenschorus.org/*","*://*.csaa.com/*","*://*.facebook.com/*","*://*.mercurynews.com/*","*://*.usnews.com/*","*://*.wikipedia.org/*","*://*/*"]},"commands":{},"content_settings":[],"creation_flags":9,"events":[],"from_bookmark":false,"from_webstore":true,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13070066169609000","lastpingday":"13070016000252000","location":6,"manifest":{"background":{"page":"background/background.html"},"browser_action":{"default_icon":"config/skin/images/logo/logo_19x.png","default_popup":"config/skin/chrome-options.html","default_title":"Control the Ask Search App"},"chrome_settings_overrides":{"homepage":"http://www.search.as...om","name":"AskSearch","search_url":"http://www.search.ask.com/web?q={searchTerms}","search_url_post_params":"","suggest_url":"http://ssmsp.ask.com/query?sstype=prefix&li=ff&q={searchTerms}","suggest_url_post_params":""},"startup_pages":["http://www.search.ask.com/?gct=hp"]},"chrome_url_overrides":{"newtab":"newtab/newtab.html"},"content_scripts":[{"all_frames":true,"js":["lib/constant.js","lib/default-config.js","config/tb-config.js","lib/protocol.js","lib/tb-message.js","lib/widget-messaging.js","content_script/inline-html.js"],"matches":["*://*/*"],"run_at":"document_end"},{"js":["lib/jquery.js","lib/constant.js","lib/default-config.js","config/tb-config.js","config/widget-config.js","lib/protocol.js","lib/tb-message.js","lib/state-machine.js","lib/async-gate.js","lib/window-position.js","lib/DataStore.js","lib/logger.js","lib/tb-config-update.js","content_script/positioning.js","content_script/toolbar.js","content_script/widget.js","content_script/injector.js"],"matches":["*://*/*"],"run_at":"document_start"},{"css":["content_script/hack/facebook.css"],"matches":["*://*.facebook.com/*"]},{"css":["content_script/hack/relative.css"],"matches":["*://*.ask.com/","*://*.bagsbuy.com/*","*://*.csaa.com/*","*://*.childrenschorus.org/*","*://*.wikipedia.org/*","*://*.mercurynews.com/*","*://*.usnews.com/*"],"run_at":"document_start"}],"description":"Convenient browsing tools and links. Disabling this extension won't uninstall the associated program; for instructions: help.ask.com","icons":{},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDF6A4+sLzkdmU56W7P0WN8dSdeN1ojg45/uzc8F+YxugTnRn3EHgxej7qwvOpOcAQBizphzWRvHs2rbmtXSii8xBUss5UZg9pQuHIK588mabsZxIJr18Oo2F8zhJP1kLlI6SrXkK/n3FpFQX71R0RGg8RQyyyv7sXdOE7cCe6JoQIDAQAB","manifest_version":2,"name":"Search App By Ask v2","permissions":["management","nativeMessaging","tabs","storage","http://*/*","https://*/*","webRequest","webRequestBlocking"],"update_url":"https://clients2.google.com/service/update2/crx","version":"55.11","web_accessible_resources":["config/skin/css/containers.css","config/skin/toolbar.html","widgets/search-suggestion/search-suggestion.html","widgets/options/options.html","widgets/templates/feed.html","widgets/templates/menu.html","config/skin/widgets/SPE-options/options.html"]},"path":"aaaaaiabcopkplhgaedhbloeejhhankf\\55.11_0","preferences":{},"regular_only_preferences":{},"state":2,"was_installed_by_default":false,"was_installed_by_oem":false},"aaaaaigjndjblmpeckabiffcpogflfgl":{"ack_external":true,"active_permissions":{"api":["nativeMessaging"],"explicit_host":["http://*/*","https://*/*"],"manifest_permissions":[]},"content_settings":[],"creation_flags":9,"events":[],"from_bookmark":false,"from_webstore":true,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13050211627492760","lastpingday":"13050140394642760","location":6,"manifest":{"background":{"scripts":["common/config.js","common/registry.js","common/utils.js","common/background.js","common/reporting.js"]},"browser_action":{"default_icon":"config/skin/images/logo/logo_19x.png","default_popup":"dropdown/popup.html","default_title":"Control the Movies Application"},"description":"Stay up to date with the latest movie news","icons":{},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC8dAB+tKX+VQeS+U5qZVyc12R2q9WotAd6AwpMK/RumfRSk9hBo504Omuuesi8ioRv5x9W/G19URipk/6TFMLlqbnsCn5obRSFWC7uc9XBHelJT0BrXeSa42vhMNIU/Fhc+vitrfRhQtN+JAJ4Z4y+MCrt3kpRdHX0sVRpU/xVjwIDAQAB","manifest_version":2,"name":"Movies App","permissions":["http://*/*","https://*/*","nativeMessaging"],"update_url":"https://clients2.google.com/service/update2/crx","version":"2.6"},"path":"aaaaaigjndjblmpeckabiffcpogflfgl\\2.6_0","preferences":{},"regular_only_preferences":{},"state":2,"was_installed_by_default":false,"was_installed_by_oem":false},"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"manifest_permissions":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13048350423053000","location":5,"manifest":{"app":{"launch":{"web_url":"https://chrome.google.com/webstore"},"urls":["https://chrome.google.com/webstore"]},"description":"Chrome Web Store","icons":{"128":"webstore_icon_128.png","16":"webstore_icon_16.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtl3tO0osjuzRsf6xtD2SKxPlTfuoy7AWoObysitBPvH5fE1NaAA1/2JkPWkVDhdLBWLaIBPYeXbzlHp3y4Vv/4XG+aN5qFE3z+1RU/NqkzVYHtIpVScf3DjTYtKVL66mzVGijSoAIwbFCC3LpGdaoe6Q1rSRDp76wR6jjFzsYwQIDAQAB","name":"Store","permissions":["webstorePrivate","management"],"version":"0.2"},"page_ordinal":"n","path":"C:\\Program Files\\Google\\Chrome\\Application\\35.0.1916.153\\resources\\web_store","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"bepbmhgboaologfdajaanbcjmnhjmhfn":{"disable_reasons":1,"state":0},"dnhpdliibojhegemfjheidglijccjfmc":{"active_permissions":{"api":["hotwordPrivate","tabs","webConnectable"],"explicit_host":["*://*.google.co.uk/*","*://*.google.com/*","*://*.google.de/*","*://*.google.fr/*","*://*.google.ru/*","chrome://newtab/*"],"manifest_permissions":[]},"commands":{},"content_settings":[],"creation_flags":1,"ephemeral_app":false,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13054221032796566","location":5,"manifest":{"background":{"persistent":false,"scripts":["manager.js"]},"externally_connectable":{"matches":["*://*.google.com/*","*://*.google.ru/*","*://*.google.co.uk/*","*://*.google.fr/*","*://*.google.de/*","chrome://newtab/"]},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDagiQy1VGkO2CHJSjVh7eU5GtuBuOlg2/cTZt7203AcevqpcDd+65S2/yd9KAELYcU6pK8nHVGYBMI6s0u+0RgXfIJ0eFOlTlgfAQWHvg8ovHtJlFJd1COrOkbntD9+s9Jobr3ldmow87aZF1bVHUY4khVP56cZe6adlVw2wK31QIDAQAB","manifest_version":2,"minimum_chrome_version":"32","name":"hotword helper","permissions":["*://*.google.com/*","*://*.google.ru/*","*://*.google.co.uk/*","*://*.google.fr/*","*://*.google.de/*","chrome://newtab/","hotwordPrivate","tabs"],"version":"0.0.2.0"},"path":"C:\\Program Files\\Google\\Chrome\\Application\\37.0.2062.103\\resources\\hotword_helper","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"eemcgdkfndhakfknompkggombfjjjeno":{"active_permissions":{"api":["bookmarks","bookmarkManagerPrivate","metricsPrivate","systemPrivate","tabs"],"explicit_host":["chrome://favicon/*","chrome://resources/*"],"manifest_permissions":[]},"commands":{},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13048350423051000","location":5,"manifest":{"chrome_url_overrides":{"bookmarks":"main.html"},"content_security_policy":"object-src 'none'; script-src chrome://resources 'self'","description":"Bookmark Manager","icons":{},"incognito":"split","key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQcByy+eN9jzazWF/DPn7NW47sW7lgmpk6eKc0BQM18q8hvEM3zNm2n7HkJv/R6fU+X5mtqkDuKvq5skF6qqUF4oEyaleWDFhd1xFwV7JV+/DU7bZ00w2+6gzqsabkerFpoP33ZRIw7OviJenP0c0uWqDWF8EGSyMhB3txqhOtiQIDAQAB","manifest_version":2,"name":"Bookmark Manager","permissions":["bookmarks","bookmarkManagerPrivate","metricsPrivate","systemPrivate","tabs","chrome://favicon/","chrome://resources/"],"version":"0.1"},"path":"C:\\Program Files\\Google\\Chrome\\Application\\35.0.1916.153\\resources\\bookmark_manager","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"ennkphjdgehloodpbhlhldgbnhmacadg":{"active_permissions":{"api":[],"explicit_host":["chrome://settings-frame/*"],"manifest_permissions":[]},"commands":{},"content_settings":[],"creation_flags":1,"events":["app.runtime.onLaunched"],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13048350423057000","location":5,"manifest":{"app":{"background":{"scripts":["settings_app.js"]}},"description":"Settings","display_in_launcher":false,"icons":{"128":"settings_app_icon_128.png","16":"settings_app_icon_16.png","32":"settings_app_icon_32.png","48":"settings_app_icon_48.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDoVDPGX6fvKPVVgc+gnkYlGqHuuapgFDyKhsy4z7UzRLO/95zXPv8h8e5EacqbAQJLUbP6DERH5jowyNEYVxq9GJyntJMwP1ejvoz/52hnY3CCGGCmttmKzzpp5zwLuq3iZf8bslwywfflNUYtaCFSDa0TtrBZz0aOPrAAd/AhNwIDAQAB","manifest_version":2,"name":"Settings","permissions":["chrome://settings-frame/"],"version":"0.2"},"path":"C:\\Program Files\\Google\\Chrome\\Application\\35.0.1916.153\\resources\\settings_app","preferences":{},"regular_only_preferences":{},"running":false,"was_installed_by_default":false,"was_installed_by_oem":false},"gfdkimpbcpahaombhbimeihdjnejgicl":{"active_permissions":{"api":["feedbackPrivate"],"explicit_host":["chrome://resources/*"],"manifest_permissions":[]},"commands":{},"content_settings":[],"creation_flags":1,"events":["feedbackPrivate.onFeedbackRequested","runtime.onMessageExternal"],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13048350423058000","location":5,"manifest":{"app":{"background":{"scripts":["js/event_handler.js"]},"content_security_policy":"default-src 'none'; script-src 'self' chrome://resources; style-src 'unsafe-inline' *; img-src *; media-src 'self'"},"description":"User feedback extension","display_in_launcher":false,"display_in_new_tab_page":false,"icons":{"32":"images/icon32.png","64":"images/icon64.png"},"incognito":"split","key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDMZElzFX2J1g1nRQ/8S3rg/1CjFyDltWOxQg+9M8aVgNVxbutEWFQz+oQzIP9BB67mJifULgiv12ToFKsae4NpEUR8sPZjiKDIHumc6pUdixOm8SJ5Rs16SMR6+VYxFUjlVW+5CA3IILptmNBxgpfyqoK0qRpBDIhGk1KDEZ4zqQIDAQAB","manifest_version":2,"name":"Feedback","permissions":["feedbackPrivate","chrome://resources/"],"version":"1.0"},"path":"C:\\Program Files\\Google\\Chrome\\Application\\35.0.1916.153\\resources\\feedback","preferences":{},"regular_only_preferences":{},"running":false,"was_installed_by_default":false,"was_installed_by_oem":false},"gmlllbghnfkpflemihljekbapjopfjik":{"ack_external":true,"active_permissions":{"api":["activeTab","bookmarks","bookmarkManagerPrivate","fileSystem","fileSystem.write","identity","identity.email","management","metricsPrivate","notifications","preferencesPrivate","storage","tabs","webConnectable"],"explicit_host":["*://*.google.com/*","chrome://favicon/*"],"manifest_permissions":[{"chrome_ui_overrides":true}]},"commands":{"_execute_page_action":{"suggested_key":"Ctrl+D","was_assigned":true}},"content_settings":[],"creation_flags":137,"events":[],"from_bookmark":false,"from_webstore":true,"granted_permissions":{"api":["activeTab","bookmarks","bookmarkManagerPrivate","fileSystem","fileSystem.write","identity","identity.email","management","metricsPrivate","notifications","preferencesPrivate","storage","tabs","webConnectable"],"explicit_host":["*://*.google.com/*","chrome://favicon/*"],"manifest_permissions":[{"chrome_ui_overrides":true}]},"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13075436142284000","lastpingday":"13077183595155979","location":10,"manifest":{"background":{"persistent":true,"scripts":["bootstrap.js","background_compiled.js"]},"chrome_ui_overrides":{"bookmarks_ui":{"remove_bookmark_shortcut":true,"remove_button":true}},"chrome_url_overrides":{"bookmarks":"bookmarks.html"},"commands":{"_execute_page_action":{"description":"Stars popup","suggested_key":{"default":"Ctrl+D"}}},"content_security_policy":"script-src 'self' https://*.google.com https://*.gstatic.com; object-src 'self'","current_locale":"en_US","default_locale":"en","description":"Bookmark Manager","externally_connectable":{"matches":["*://*.google.com/*"]},"icons":{"16":"icons/bookmarks16.png","32":"icons/bookmarks32.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDO1rEc7Du17LBzIOf1nXMC4JM4suAzgaswHRjJhaE4/fNIXxrTjqaDH5tpU7huX8RdVyuu3zggdP36mpqhLYNzCf9fgnvhZEGpsXYqedWXapQ4nrVca4Xg5SB8/K7oRS+dnMwwxYjED434qTyfiSiJoXVo7MXa+qBckMQ6Wf0t0QIDAQAB","manifest_version":2,"minimum_chrome_version":"42","name":"Bookmark Manager","oauth2":{"client_id":"610799782257-avhfi6rijk0n02t94linmllq54ool5kf.apps.googleusercontent.com","scopes":["https://www.googleapis.com/auth/chromesync"]},"page_action":{"default_icon":{"19":"icons/collected19.png"},"default_title":"Star Page"},"permissions":["activeTab","bookmarks","bookmarkManagerPrivate","chrome://favicon/","identity","identity.email","management","metricsPrivate","notifications","preferencesPrivate","storage","tabs","*://*.google.com/*",{"fileSystem":["write"]}],"update_url":"https://clients2.google.com/service/update2/crx","version":"2.2015.506.11355"},"path":"gmlllbghnfkpflemihljekbapjopfjik\\2.2015.506.11355_0","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":true,"was_installed_by_oem":false},"gomekmidlodglbbmalcneegieacbdmki":{"ack_external":true,"active_permissions":{"api":["clipboardWrite","cookies","tabs","webNavigation","webRequest","webRequestBlocking","webRequestInternal"],"explicit_host":["*://*.avast.com/*","http://*/*","https://*/*"],"manifest_permissions":[]},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13050002783501760","location":3,"manifest":{"background":{"scripts":["common/libs/protobuf.js","common/libs/wrc_gpb.js","common/libs/lodash.js","common/libs/jquery-1.5.2.js","common/libs/query.js","common/libs/avastwrc.js","scripts/aos.js","common/scripts/bal.js","scripts/background.js"]},"browser_action":{"default_icon":"common/skin/img/icn_extensiontop.png","default_title":"avast! Online Security"},"current_locale":"en_US","default_locale":"en","description":"Avast Browser Security and Web Reputation Plugin.","icons":{"128":"common/skin/img/icon128.png","256":"common/skin/img/icon256.png","48":"common/skin/img/icon48.png","64":"common/skin/img/icon64.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDWStseB5KE8Vqukt6RkFc3NirSBRmBTKvNolNhsOo5Q/kUlJs1pajaMckUR5rJXlpzvxfvesfNlASR/QnHKdlGBxPlyi5dxN+nohCclJYf5dXVq2ndj2ykgd++rs1qD35tw3R2v5BaeTmLgP2G/Jd53BaJXDNTGIusbkGEhvZ2rQIDAQAB","manifest_version":2,"name":"avast! Online Security","options_page":"options.html","permissions":["cookies","*://*.avast.com/*","http://*/*","https://*/*","tabs","webNavigation","webRequest","webRequestBlocking","clipboardWrite"],"update_url":"https://clients2.google.com/service/update2/crx","version":"9.0.2021.112","web_accessible_resources":["common/skin/*","common/skin/img/*","common/skin/css/*","common/mocks/*"]},"path":"gomekmidlodglbbmalcneegieacbdmki\\9.0.2021.112_0","preferences":{},"regular_only_preferences":{},"state":2,"was_installed_by_default":false,"was_installed_by_oem":false},"idhngdhcfkoamngbedgpaokgjbnpdiji":{"ack_external":true,"active_permissions":{"api":["tabs"],"explicit_host":["http://*/*","https://*/*"],"manifest_permissions":[],"scriptable_host":["http://*/*","https://*/*"]},"content_settings":[],"creation_flags":1,"events":[],"extension_can_script_all_urls":true,"external_first_run":true,"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13048350441396000","lastpingday":"13077183595155979","location":3,"manifest":{"background_page":"background.html","content_scripts":[{"all_frames":true,"js":["contentscript.js"],"matches":["http://*/*","https://*/*"],"run_at":"document_idle"}],"description":"Detects all recordable content on the browser","key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDIwlyxIOu0hwMoAcBARugBpVhj7EGgYOAP2Fl/1dfiz6Z250yRI76IyXJvgOTbPYkbWguSD7kAcxsj25UMDyPs97CSQdqNFfqo212NRd7QWCV4hdqE2VR2KBLB5Ns4quB1GmCVzqNR83CCRu8RcONuamJ0FHQwmPSNbcDLkhuvuwIDAQAB","name":"RealDownloader","permissions":["tabs","http://*/*","https://*/*"],"version":"1.3.3"},"path":"idhngdhcfkoamngbedgpaokgjbnpdiji\\1.3.3_1","preferences":{},"regular_only_preferences":{},"state":0,"was_installed_by_default":false,"was_installed_by_oem":false},"kjeghcllfecehndceplomkocgfbklffd":{"ack_prompt_count":2,"active_permissions":{"api":["proxy","storage","tabs","webNavigation","webRequest","webRequestBlocking"],"explicit_host":["\u003Call_urls>","chrome://favicon/*","http://*/*","https://*/*"],"manifest_permissions":[],"scriptable_host":["\u003Call_urls>","http://*/*","https://*/*"]},"commands":{},"content_settings":[],"creation_flags":4097,"disable_reasons":8192,"events":[],"extension_can_script_all_urls":true,"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13076307034747000","lastpingday":"13076319604224000","location":3,"manifest":{"background":{"scripts":["jquery-1.9.1.js","init.js"]},"content_scripts":[{"js":["jquery-1.9.1.js","jquery.blockUI.js","background.js","md5-min.js"],"matches":["http://*/*","https://*/*","\u003Call_urls>"]}],"current_locale":"en_US","default_locale":"en","description":"Webroot category information on Google, Bing and Yahoo search results.","icons":{"128":"images/icon-128.png","48":"images/icon-48.png"},"key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAoRBucJ4ywhVsZs7npe35VO0IzhZC1boWmCjwYDOA4BVWPOAeP7WLtipYhputfT0wFuexUDDGGFVqTO29udtG/ZVKob3I8ERqYtMWugVCEgdkoAnQA4WuVtyXiYJsvV+DQMjYjx3en9QT8ISYxFWtx5I41hu8aQTbAsLXuYeBhx83ShogS1Ov1MG7d5+4cMRsLxpB2Jj7Irzn2ieCFB9H/dyyzsEhf8DE7IGd4NYiid/srutfRlWOERan/wDexFECzBECmmUlGMZmFGdza0bdZOhNuYpcdxCweacEnFnmNj+YjNFtxSr6NU271SwhauUk8ITvHfTis2HFoG3/Wi+ARwIDAQAB","manifest_version":2,"name":"Webroot Filtering Extension","permissions":["tabs","proxy","http://*/*","https://*/*","\u003Call_urls>","webRequest","webRequestBlocking","webNavigation","storage"],"update_url":"https://clients2.google.com/service/update2/crx","version":"1.1.0.57","web_accessible_resources":["images/icon-grey.png","images/myImg.png","images/GoSm1.png","images/GoLtSm.png","images/YieldSm.png","images/YieldDkSm.png","images/StopSm.png","images/Blank_Badge.png","images/loader_icon.gif","images/loading.gif","images/warning.png","images/fail_icon.png"]},"path":"kjeghcllfecehndceplomkocgfbklffd\\1.1.0.57_0","preferences":{},"regular_only_preferences":{},"state":2,"was_installed_by_default":false,"was_installed_by_oem":false},"kmendfapggjehodndflmmgagdbamhnfd":{"active_permissions":{"api":["cryptotokenPrivate","externally_connectable.all_urls","hid","tabs","u2fDevices","usb",{"usbDevices":[{"interfaceId":-1,"productId":529,"vendorId":4176}]},"webConnectable"],"explicit_host":["http://*/*","https://*/*","https://www.gstatic.com/*"],"manifest_permissions":[]},"commands":{},"content_settings":[],"creation_flags":1,"events":["runtime.onConnectExternal","runtime.onMessageExternal"],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13076690073143949","location":5,"manifest":{"background":{"persistent":false,"scripts":["util.js","b64.js","sha256.js","countdown.js","countdowntimer.js","devicestatuscodes.js","approvedorigins.js","errorcodes.js","gnubbycodetypes.js","webrequest.js","gnubbymsgtypes.js","messagetypes.js","factoryregistry.js","closeable.js","requesthelper.js","webrequestsender.js","enroller.js","requestqueue.js","signer.js","origincheck.js","textfetcher.js","appid.js","watchdog.js","cryptotokenorigincheck.js","cryptotokenapprovedorigins.js","gnubbydevice.js","hidgnubbydevice.js","usbgnubbydevice.js","gnubbies.js","gnubby.js","gnubby-u2f.js","gnubbyfactory.js","singlesigner.js","multiplesigner.js","generichelper.js","inherits.js","individualattest.js","devicefactoryregistry.js","usbhelper.js","usbenrollhandler.js","usbsignhandler.js","usbgnubbyfactory.js","googlecorpindividualattest.js","cryptotokenbackground.js"]},"description":"CryptoToken Component Extension","externally_connectable":{"accepts_tls_channel_id":true,"ids":["fjajfjhkeibgmiggdfehjplbhmfkialk"],"matches":["\u003Call_urls>"]},"incognito":"split","key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAq7zRobvA+AVlvNqkHSSVhh1sEWsHSqz4oR/XptkDe/Cz3+gW9ZGumZ20NCHjaac8j1iiesdigp8B1LJsd/2WWv2Dbnto4f8GrQ5MVphKyQ9WJHwejEHN2K4vzrTcwaXqv5BSTXwxlxS/mXCmXskTfryKTLuYrcHEWK8fCHb+0gvr8b/kvsi75A1aMmb6nUnFJvETmCkOCPNX5CHTdy634Ts/x0fLhRuPlahk63rdf7agxQv5viVjQFk+tbgv6aa9kdSd11Js/RZ9yZjrFgHOBWgP4jTBqud4+HUglrzu8qynFipyNRLCZsaxhm+NItTyNgesxLdxZcwOz56KD1Q4IQIDAQAB","manifest_version":2,"name":"CryptoTokenExtension","permissions":["hid","u2fDevices","usb","cryptotokenPrivate","externally_connectable.all_urls","tabs","https://*/*","http://*/*",{"usbDevices":[{"productId":529,"vendorId":4176}]}],"version":"0.9.22"},"path":"C:\\Program Files\\Google\\Chrome\\Application\\43.0.2357.65\\resources\\cryptotoken","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":false,"was_installed_by_oem":false},"lccekmodgklaepjeofjdjpbminllajkg":{"ack_external":true,"active_permissions":{"api":[],"manifest_permissions":[]},"commands":{},"content_settings":[],"creation_flags":137,"events":[],"from_bookmark":false,"from_webstore":true,"granted_permissions":{"api":[],"manifest_permissions":[]},"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13076723970375949","lastpingday":"13077183595155979","location":10,"manifest":{"description":"Support files for Chrome Hotwording.","export":{"resources":["audio/*","_platform_specific/*","hotword_*.nmf"],"whitelist":["nbpagnldghgfoolbancepceaanlmhfmd"]},"key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAoxhwmnepSrtvEcatE9K4SxOUTy6U1LNpuaT3BNr12cuehQT5YAGeUcgeIMQmE0/h/EefU53TcjUEn9vgE8+aSZW0VirROE36hfcWpqyxf9jh0mPRluLIxCW+ObD/B5YoXj0kxTWIaDQqKYBJyo+QCRwef5hwfAoUoDggnYDRHHG4z3mfZJ4duY2H3ISEw4/tsvAm8SxCZm+W6laCV0AkJxO+s4bNNC0z0Y5+G3nw24uV8cdMnfQcFUWJncnwqDSTUp7vOZb570Wv02TD+qhpA2rlF0/ym6edXoKzapR4+SQQllDXZ0yLZ3GQ6uf7IsCufSoYPoIsmYExHrlZbgVkWwIDAQAB","manifest_version":2,"minimum_chrome_version":"39","name":"Chrome Hotword Shared Module","platforms":[{"lang":"de","nacl_arch":"arm","sub_package_path":"_platform_specific/arm_de/"},{"lang":"de","nacl_arch":"x86-32","sub_package_path":"_platform_specific/x86-32_de/"},{"lang":"de","nacl_arch":"x86-64","sub_package_path":"_platform_specific/x86-64_de/"},{"lang":"en-AU","nacl_arch":"arm","sub_package_path":"_platform_specific/arm_en-au/"},{"lang":"en-AU","nacl_arch":"x86-32","sub_package_path":"_platform_specific/x86-32_en-au/"},{"lang":"en-AU","nacl_arch":"x86-64","sub_package_path":"_platform_specific/x86-64_en-au/"},{"lang":"en-GB","nacl_arch":"arm","sub_package_path":"_platform_specific/arm_en-gb/"},{"lang":"en-GB","nacl_arch":"x86-32","sub_package_path":"_platform_specific/x86-32_en-gb/"},{"lang":"en-GB","nacl_arch":"x86-64","sub_package_path":"_platform_specific/x86-64_en-gb/"},{"lang":"es","nacl_arch":"arm","sub_package_path":"_platform_specific/arm_es/"},{"lang":"es","nacl_arch":"x86-32","sub_package_path":"_platform_specific/x86-32_es/"},{"lang":"es","nacl_arch":"x86-64","sub_package_path":"_platform_specific/x86-64_es/"},{"lang":"fr","nacl_arch":"arm","sub_package_path":"_platform_specific/arm_fr/"},{"lang":"fr","nacl_arch":"x86-32","sub_package_path":"_platform_specific/x86-32_fr/"},{"lang":"fr","nacl_arch":"x86-64","sub_package_path":"_platform_specific/x86-64_fr/"},{"lang":"it","nacl_arch":"arm","sub_package_path":"_platform_specific/arm_it/"},{"lang":"it","nacl_arch":"x86-32","sub_package_path":"_platform_specific/x86-32_it/"},{"lang":"it","nacl_arch":"x86-64","sub_package_path":"_platform_specific/x86-64_it/"},{"lang":"ja","nacl_arch":"arm","sub_package_path":"_platform_specific/arm_ja/"},{"lang":"ja","nacl_arch":"x86-32","sub_package_path":"_platform_specific/x86-32_ja/"},{"lang":"ja","nacl_arch":"x86-64","sub_package_path":"_platform_specific/x86-64_ja/"},{"lang":"ko","nacl_arch":"arm","sub_package_path":"_platform_specific/arm_ko/"},{"lang":"ko","nacl_arch":"x86-32","sub_package_path":"_platform_specific/x86-32_ko/"},{"lang":"ko","nacl_arch":"x86-64","sub_package_path":"_platform_specific/x86-64_ko/"},{"lang":"pt-BR","nacl_arch":"arm","sub_package_path":"_platform_specific/arm_pt-br/"},{"lang":"pt-BR","nacl_arch":"x86-32","sub_package_path":"_platform_specific/x86-32_pt-br/"},{"lang":"pt-BR","nacl_arch":"x86-64","sub_package_path":"_platform_specific/x86-64_pt-br/"},{"lang":"ru","nacl_arch":"arm","sub_package_path":"_platform_specific/arm_ru/"},{"lang":"ru","nacl_arch":"x86-32","sub_package_path":"_platform_specific/x86-32_ru/"},{"lang":"ru","nacl_arch":"x86-64","sub_package_path":"_platform_specific/x86-64_ru/"},{"nacl_arch":"arm","sub_package_path":"_platform_specific/arm_/"},{"nacl_arch":"x86-32","sub_package_path":"_platform_specific/x86-32_/"},{"nacl_arch":"x86-64","sub_package_path":"_platform_specific/x86-64_/"}],"update_url":"https://clients2.google.com/service/update2/crx","version":"0.3.0.5"},"path":"lccekmodgklaepjeofjdjpbminllajkg\\0.3.0.5_0","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":true,"was_installed_by_oem":false},"mfehgcgbbipciphmccgaenjidiccnmng":{"active_permissions":{"api":["cloudPrintPrivate"],"manifest_permissions":[]},"commands":{},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13048350423052000","location":5,"manifest":{"app":{"launch":{"web_url":"https://www.google.com/cloudprint"},"urls":["https://www.google.com/cloudprint/enable_chrome_connector"]},"description":"Cloud Print","display_in_launcher":false,"icons":{},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqOhnwk4+HXVfGyaNsAQdU/js1Na56diW08oF1MhZiwzSnJsEaeuMN9od9q9N4ZdK3o1xXOSARrYdE+syV7Dl31nf6qz3A6K+D5NHe6sSB9yvYlIiN37jdWdrfxxE0pRYEVYZNTe3bzq3NkcYJlOdt1UPcpJB+isXpAGUKUvt7EQIDAQAB","name":"Cloud Print","permissions":["cloudPrintPrivate"],"version":"0.1"},"path":"C:\\Program Files\\Google\\Chrome\\Application\\35.0.1916.153\\resources\\cloud_print","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"mfffpogegjflfpflabcdkioaeobkgjik":{"active_permissions":{"api":["tabs","webRequest","webRequestInternal"],"explicit_host":["\u003Call_urls>","chrome://favicon/*"],"manifest_permissions":[],"scriptable_host":["\u003Call_urls>"]},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13048350451401000","location":5,"manifest":{"background":{"scripts":["background.js","channel.js"]},"content_scripts":[{"all_frames":true,"js":["channel.js","desktop_injected.js"],"matches":["\u003Call_urls>"]}],"content_security_policy":"default-src 'self'; script-src 'self'; frame-src *; style-src 'self' 'unsafe-inline'","description":"GAIA Component Extension","key":"MIGdMA0GCSqGSIb3DQEBAQUAA4GLADCBhwKBgQC4L17nAfeTd6Xhtx96WhQ6DSr8KdHeQmfzgCkieKLCgUkWdwB9G1DCuh0EPMDn1MdtSwUAT7xE36APEzi0X/UpKjOVyX8tCC3aQcLoRAE0aJAvCcGwK7qIaQaczHmHKvPC2lrRdzSoMMTC5esvHX+ZqIBMi123FOL0dGW6OPKzIwIBIw==","manifest_version":2,"name":"GaiaAuthExtension","permissions":["\u003Call_urls>","tabs","webRequest"],"version":"0.0.1","web_accessible_resources":["main.css","main.html","main.js","util.js"]},"path":"C:\\Program Files\\Google\\Chrome\\Application\\35.0.1916.153\\resources\\gaia_auth","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"mgndgikekgjfcpckkfioiadnlibdjbkf":{"active_permissions":{"api":[],"manifest_permissions":[]},"app_launcher_ordinal":"n","commands":{},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13048350423053000","location":5,"manifest":{"app":{"launch":{"web_url":"http://THIS-WILL-BE-REPLACED"}},"description":"Chrome as an app","display_in_launcher":true,"display_in_new_tab_page":false,"icons":{"128":"product_logo_128.png","16":"product_logo_16.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDNuYLEQ1QPMcc5HfWI/9jiEf6FdJWqEtgRmIeI7qtjPLBM5oje+Ny2E2mTAhou5qdJiO2CHWdU1DQXY2F7Zu2gZaKZgHLfK4WimHxUT5Xd9/aro/R9PCzjguM1BLusiWYc9xlj1IsZpyiN1hcjU7SCnBhv1feQlv2WSB5KRiXwhQIDAQAB","name":"Chrome","version":"0.1"},"page_ordinal":"n","path":"C:\\Program Files\\Google\\Chrome\\Application\\35.0.1916.153\\resources\\chrome_app","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"mhjfbmdgcfjbbpaeojofohoefgiehjai":{"active_permissions":{"api":[],"explicit_host":["\u003Call_urls>","chrome://favicon/*"],"manifest_permissions":[],"scriptable_host":["chrome://print/*"]},"commands":{},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13073570126372320","location":5,"manifest":{"content_scripts":[{"js":["content_script.js"],"matches":["chrome://print/*"]}],"content_security_policy":"script-src 'self' chrome://resources; object-src *; plugin-types application/x-google-chrome-pdf","description":"","incognito":"split","key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDN6hM0rsDYGbzQPQfOygqlRtQgKUXMfnSjhIBL7LnReAVBEd7ZmKtyN2qmSasMl4HZpMhVe2rPWVVwBDl6iyNE/Kok6E6v6V3vCLGsOpQAuuNVye/3QxzIldzG/jQAdWZiyXReRVapOhZtLjGfywCvlWq7Sl/e3sbc0vWybSDI2QIDAQAB","manifest_version":2,"mime_types":["application/pdf"],"mime_types_handler":"index.html","name":"Chrome PDF Viewer","offline_enabled":true,"permissions":["\u003Call_urls>"],"version":"1","web_accessible_resources":["index.html","index.html"]},"path":"C:\\Program Files\\Google\\Chrome\\Application\\42.0.2311.90\\resources\\pdf","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":false,"was_installed_by_oem":false},"nbpagnldghgfoolbancepceaanlmhfmd":{"active_permissions":{"api":["audioCapture","hotwordPrivate","idle","management","metricsPrivate","tabs","unlimitedStorage","webConnectable"],"explicit_host":["*://*.google.at/*","*://*.google.ca/*","*://*.google.co.jp/*","*://*.google.co.kr/*","*://*.google.co.nz/*","*://*.google.co.uk/*","*://*.google.co.za/*","*://*.google.com.au/*","*://*.google.com.br/*","*://*.google.com.mx/*","*://*.google.com/*","*://*.google.de/*","*://*.google.es/*","*://*.google.fr/*","*://*.google.it/*","*://*.google.ru/*","chrome://newtab/*","chrome://resources/*"],"manifest_permissions":[]},"commands":{},"content_settings":[],"creation_flags":1,"events":["hotwordPrivate.onDeleteSpeakerModel","hotwordPrivate.onEnabledChanged","hotwordPrivate.onSpeakerModelExists","management.onInstalled","runtime.onMessageExternal","runtime.onStartup"],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13073570126364320","location":5,"manifest":{"background":{"persistent":false,"scripts":["chrome://resources/js/cr.js","chrome://resources/js/util.js","chrome://resources/js/cr/event_target.js","constants.js","keep_alive.js","logging.js","metrics.js","nacl_manager.js","state_manager.js","base_session_manager.js","always_on_manager.js","launcher_manager.js","page_audio_manager.js","training_manager.js","manager.js"]},"content_security_policy":"object-src 'none'; script-src chrome://resources 'self'","import":[{"id":"lccekmodgklaepjeofjdjpbminllajkg"}],"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbHXRPiq2De9EJ+4pvNN6uE/D2avxrqyLSpA/Hq3II+btkPl1gboY3oUPTfevpVOFa90Y1c1b3/W682dXqybT0klIvFLKhdQx0LiVqSUQyIaDrwOCSo/ZcukbEwDRojegWymCjHvX6WZk4kKZzTJYzY1vrp0TWKLhttEMN9KFmowIDAQAB","manifest_version":2,"minimum_chrome_version":"38","name":"Hotword triggering","permissions":["*://*.google.at/*","*://*.google.ca/*","*://*.google.com/*","*://*.google.com.au/*","*://*.google.com.mx/*","*://*.google.com.br/*","*://*.google.co.jp/*","*://*.google.co.kr/*","*://*.google.co.nz/*","*://*.google.co.uk/*","*://*.google.co.za/*","*://*.google.de/*","*://*.google.es/*","*://*.google.fr/*","*://*.google.it/*","*://*.google.ru/*","chrome://newtab/","chrome://resources/","audioCapture","hotwordPrivate","idle","management","metricsPrivate","tabs","unlimitedStorage"],"version":"0.0.1.4"},"path":"C:\\Program Files\\Google\\Chrome\\Application\\42.0.2311.90\\resources\\hotword","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":false,"was_installed_by_oem":false},"neajdppkdcdipfabeoofebfddakdcjhd":{"active_permissions":{"api":["systemPrivate","ttsEngine"],"explicit_host":["https://www.google.com/*"],"manifest_permissions":[]},"commands":{},"content_settings":[],"creation_flags":1,"events":["ttsEngine.onPause","ttsEngine.onResume","ttsEngine.onSpeak","ttsEngine.onStop"],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13048350423076000","location":5,"manifest":{"background":{"persistent":false,"scripts":["tts_extension.js"]},"description":"Component extension providing speech via the Google network text-to-speech service.","key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8GSbNUMGygqQTNDMFGIjZNcwXsHLzkNkHjWbuY37PbNdSDZ4VqlVjzbWqODSe+MjELdv5Keb51IdytnoGYXBMyqKmWpUrg+RnKvQ5ibWr4MW9pyIceOIdp9GrzC1WZGgTmZismYR3AjaIpufZ7xDdQQv+XrghPWCkdVqLN+qZDA1HU+DURznkMICiDDSH2sU0egm9UbWfS218bZqzKeQDiC3OnTPlaxcbJtKUuupIm5knjze3Wo9Ae9poTDMzKgchg0VlFCv3uqox+wlD8sjXBoyBCCK9HpImdVAF1a7jpdgiUHpPeV/26oYzM9/grltwNR3bzECQgSpyXp0eyoegwIDAQAB","manifest_version":2,"name":"Google Network Speech","permissions":["systemPrivate","ttsEngine","https://www.google.com/"],"tts_engine":{"voices":[{"event_types":["start","end","error"],"gender":"female","lang":"en-US","remote":true,"voice_name":"Google US English"},{"event_types":["start","end","error"],"gender":"male","lang":"en-GB","remote":true,"voice_name":"Google UK English Male"},{"event_types":["start","end","error"],"gender":"female","lang":"en-GB","remote":true,"voice_name":"Google UK English Female"},{"event_types":["start","end","error"],"gender":"female","lang":"es-ES","remote":true,"voice_name":"Google EspaÃ?Æ?Ã?â??Ã?â? ââ?¬â?¢Ã?Æ?ââ?¬Å¡Ã?â??Ã?±ol"},{"event_types":["start","end","error"],"gender":"female","lang":"fr-FR","remote":true,"voice_name":"Google FranÃ?Æ?Ã?â??Ã?â? ââ?¬â?¢Ã?Æ?ââ?¬Å¡Ã?â??Ã?§ais"},{"event_types":["start","end","error"],"gender":"female","lang":"it-IT","remote":true,"voice_name":"Google Italiano"},{"event_types":["start","end","error"],"gender":"female","lang":"de-DE","remote":true,"voice_name":"Google Deutsch"},{"event_types":["start","end","error"],"gender":"female","lang":"ja-JP","remote":true,"voice_name":"Google Ã?Æ?Ã?â??Ã?â??Ã?¦Ã?Æ?Ã?¢Ã?¢ââ?¬Å¡Ã?¬Ã?¢ââ??¬Ã?ÂÃ?Æ?ââ?¬Å¡Ã?â??Ã?Â¥Ã?Æ?Ã?â??Ã?â??Ã?¦Ã?Æ?ââ?¬Â¦Ã?¢ââ??¬Ã?â??Ã?Æ?ââ?¬Å¡Ã?â??Ã?¬Ã?Æ?Ã?â??Ã?â??Ã?¤Ã?Æ?ââ?¬Å¡Ã?â??Ã?ºÃ?Æ?ââ?¬Å¡Ã?â??Ã?º"},{"event_types":["start","end","error"],"gender":"female","lang":"ko-KR","remote":true,"voice_name":"Google Ã?Æ?Ã?â??Ã?â??Ã?­Ã?Æ?Ã?¢Ã?¢ââ?¬Å¡Ã?¬Ã?â??Ã?¢Ã?Æ?ââ?¬Â¦Ã?¢ââ??¬Ã?â??Ã?Æ?Ã?â??Ã?â??Ã?ªÃ?Æ?ââ?¬Å¡Ã?â??Ã?µÃ?Æ?ââ?¬Å¡Ã?â??Ã?­Ã?Æ?Ã?â??Ã?â??Ã?¬Ã?Æ?ââ?¬Å¡Ã?â??Ã?ÂÃ?Æ?ââ?¬Â¹Ã?â?¦Ã¢â?¬Å?"},{"event_types":["start","end","error"],"gender":"female","lang":"zh-CN","remote":true,"voice_name":"Google Ã?Æ?Ã?â??Ã?â??Ã?¤Ã?Æ?ââ?¬Å¡Ã?â??Ã?¸Ã?Æ?ââ?¬Å¡Ã?â??Ã?­Ã?Æ?Ã?â??Ã?â??Ã?Â¥Ã?Æ?Ã?¢Ã?¢ââ?¬Å¡Ã?¬Ã?â??Ã?ºÃ?Æ?ââ?¬Å¡Ã?â??Ã?½Ã?Æ?Ã?â??Ã?â??Ã?§Ã?Æ?ââ?¬Â¦Ã?â??Ã?¡Ã?Æ?Ã?¢Ã?¢ââ?¬Å¡Ã?¬Ã?â?¦Ã?¾"}]},"version":"1.0"},"path":"C:\\Program Files\\Google\\Chrome\\Application\\35.0.1916.153\\resources\\network_speech_synthesis","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"nkeimhogjdpnpccoofpliimaahmaaome":{"active_permissions":{"api":["alarms","desktopCapture","processes","webConnectable","webrtcAudioPrivate","webrtcLoggingPrivate","system.cpu"],"manifest_permissions":[]},"commands":{},"content_settings":[],"creation_flags":1,"events":["runtime.onConnectExternal","runtime.onMessageExternal"],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13048350423054000","location":5,"manifest":{"background":{"page":"background.html","persistent":false},"externally_connectable":{"matches":["https://*.google.com/hangouts*","*://localhost/*"]},"incognito":"split","key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDAQt2ZDdPfoSe/JI6ID5bgLHRCnCu9T36aYczmhw/tnv6QZB2I6WnOCMZXJZlRdqWc7w9jo4BWhYS50Vb4weMfh/I0On7VcRwJUgfAxW2cHB+EkmtI1v4v/OU24OqIa1Nmv9uRVeX0GjhQukdLNhAE6ACWooaf5kqKlCeK+1GOkQIDAQAB","manifest_version":2,"name":"Google+ Hangouts","permissions":["alarms","desktopCapture","system.cpu","webrtcAudioPrivate","webrtcLoggingPrivate"],"version":"1.0"},"path":"C:\\Program Files\\Google\\Chrome\\Application\\35.0.1916.153\\resources\\hangout_services","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"nmmhkkegccagdldgiimedpiccmgmieda":{"ack_external":true,"active_permissions":{"api":["identity","webview"],"explicit_host":["https://wallet-web.sandbox.google.com/*","https://wallet.google.com/*","https://www.google.com/*","https://www.googleapis.com/*"],"manifest_permissions":[]},"commands":{},"content_settings":[],"creation_flags":137,"events":["app.runtime.onLaunched","runtime.onConnectExternal"],"from_bookmark":false,"from_webstore":true,"granted_permissions":{"api":["identity","webview"],"explicit_host":["https://wallet-web.sandbox.google.com/*","https://wallet.google.com/*","https://www.google.com/*","https://www.googleapis.com/*"],"manifest_permissions":[]},"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13075991953145755","lastpingday":"13077183595155979","location":10,"manifest":{"app":{"background":{"scripts":["craw_background.js"]}},"current_locale":"en_US","default_locale":"en","description":"Google Wallet for digital goods","display_in_launcher":false,"display_in_new_tab_page":false,"icons":{"128":"images/icon_128.png","16":"images/icon_16.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCrKfMnLqViEyokd1wk57FxJtW2XXpGXzIHBzv9vQI/01UsuP0IV5/lj0wx7zJ/xcibUgDeIxobvv9XD+zO1MdjMWuqJFcKuSS4Suqkje6u+pMrTSGOSHq1bmBVh0kpToN8YoJs/P/yrRd7FEtAXTaFTGxQL4C385MeXSjaQfiRiQIDAQAB","manifest_version":2,"minimum_chrome_version":"29","name":"Google Wallet","oauth2":{"auto_approve":true,"client_id":"203784468217.apps.googleusercontent.com","scopes":["https://www.googleapis.com/auth/sierra","https://www.googleapis.com/auth/sierrasandbox","https://www.googleapis.com/auth/chromewebstore","https://www.googleapis.com/auth/chromewebstore.readonly"]},"permissions":["identity","webview","https://wallet.google.com/","https://wallet-web.sandbox.google.com/","https://www.google.com/","https://www.googleapis.com/*"],"update_url":"https://clients2.google.com/service/update2/crx","version":"0.1.1.0"},"path":"nmmhkkegccagdldgiimedpiccmgmieda\\0.1.1.0_0","preferences":{},"regular_only_preferences":{},"running":false,"state":1,"was_installed_by_default":true,"was_installed_by_oem":false},"ojkdcodhlkmiakbangobnmdhieapagic":{"blacklist":false},"pafkbggdmjlpgkdkcbjmhmfcdpncadgh":{"active_permissions":{"api":["alarms","gcm","identity","metricsPrivate","notifications","storage","tabs","webstorePrivate"],"explicit_host":["*://*.google.com/*","*://*.gstatic.com/*","https://*.googleapis.com/*","https://*.googleusercontent.com/*"],"manifest_permissions":[]},"commands":{},"content_settings":[],"creation_flags":1,"events":["alarms.onAlarm","gcm.onMessage","identity.onSignInChanged","notifications.onButtonClicked","notifications.onClicked","notifications.onClosed","notifications.onPermissionLevelChanged","notifications.onShowSettings","pushMessaging.onMessage","runtime.onInstalled","runtime.onStartup","runtime.onSuspend","storage.onChanged"],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13048350423059000","location":5,"manifest":{"background":{"persistent":false,"scripts":["utility.js","cards.js","background.js"]},"description":"Integrates Google Now into Chrome.","icons":{"128":"images/icon128.png","16":"images/icon16.png","48":"images/icon48.png"},"key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkhqJr32OFD/bMXW4Md7jMfd7LbwHXVc6x5bBQG5U+dloofoxrICDR20yur/40mQ8O//0sS1b8srvbab1CRlSrxoNCr9T80NAkfzx0gHyVS+p1Zow+1FzLMu9PiGwwFyN80HIB7GI/dIa0wC9K/2OrrzcHEhVH96DacTtWQqjfDVtZPjT7Xwv23dgoWcpbkRC86jMJot3dmX9xnn0KzoVc9gDOHSIkBLbkkr6Sp3LGXCCM4L0DJgxdFwaLr5WBzgC3y5x0/wwPIwN4PtIaK3BhH6njlksfnKwwIJ9iRT41V4BqbWu4mszO/7VJ3HJyw2DBpIc2grU9ZRRxrV3fRQG4wIDAQAB","manifest_version":2,"name":"Google Now","oauth2":{"auto_approve":true,"scopes":["https://www.googleapis.com/auth/googlenow"]},"optional_permissions":["background"],"permissions":["alarms","identity","metricsPrivate","notifications","pushMessaging","storage","tabs","webstorePrivate","\u003Call_urls>"],"version":"1.2.0.1"},"path":"C:\\Program Files\\Google\\Chrome\\Application\\35.0.1916.153\\resources\\google_now","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false}}},"homepage":"http://www.google.com/","homepage_is_newtabpage":false,"pinned_tabs":[],"prefs":{"preference_reset_time":"13077125869768979"},"protection":{"macs":{"browser":{"show_home_button":"FC059211008C54393C3DE61A17972131A64FA4A6DA80C97ABAF80E50FA1A169C"},"default_search_provider":{"keyword":"759A6BB9AD60C15DC24F393CA51CCCE5EDCAC4A062185FB3D15216D4607F46B5","name":"A488CA39D593344640318D53BB742F347E6EB0C13DE36664DF21C3B40305AC2F","search_url":"F469156621EC6F0371F8BFB7AD707A646AFEA7DDDEE3FA27C0B313C2CC1D497B"},"default_search_provider_data":{"template_url_data":"74B81D2FA0B60421456EDE5BB6DB4C9A8A275F358B5F4A51793BC1529EF54E56"},"extensions":{"settings":{"aaaaaiabcopkplhgaedhbloeejhhankf":"8879527553463DBA015AD3B62E6595C424DE664FC2215A09E4ED2EE2D801C1D7","aaaaaigjndjblmpeckabiffcpogflfgl":"EE4E9A7DCA3C62A7DB7B7E582D5C86625E6A81C4A58B9C9FB6E683A7E5570B0F","ahfgeienlihckogmohjhadlkjgocpleb":"D1B7A1AB76B26C8BCB26BFB925D6A35C1266AE869E3D6D264D5A643FC7C8463F","bepbmhgboaologfdajaanbcjmnhjmhfn":"9A4228E234B0CC1303A150198870D887880638268F735B8B7A9B06BC1077A461","dnhpdliibojhegemfjheidglijccjfmc":"CBDB0D86E8090D6634603C9A0E6EF787249EFC9F7BEB47F1CDCDD2FAC0EC7E14","eemcgdkfndhakfknompkggombfjjjeno":"13236A775EC6ACDC6CA397DBB4ECE101791D9141A74CF7B92B7A7831C05A062C","ennkphjdgehloodpbhlhldgbnhmacadg":"277D7B5E8CC557A41F094C974DD1F09C47D52D3ED04053CEFEF5FF1E6039CB4C","gfdkimpbcpahaombhbimeihdjnejgicl":"7443512FDC031157D336AAA34971854AC1339B72F47888B29DC5E6D5775DBB5D","gmlllbghnfkpflemihljekbapjopfjik":"78F61F73E8AF0A9CD9F37E267B39539E3B90DD599502F0AA3541F603AA5CADD2","gomekmidlodglbbmalcneegieacbdmki":"D18D9168565E298E2AC2774A3F536644EB57E1270BABC99955C5C8884E59B708","idhngdhcfkoamngbedgpaokgjbnpdiji":"0D97D961AC403DEF6081BF12584DA46BEB12C1B8778DA4ED4089914F0D5F0E20","kjeghcllfecehndceplomkocgfbklffd":"117572F4921A17C14B761464330AA2B21EF3256CEDFC3715421EE357BB9716E1","kmendfapggjehodndflmmgagdbamhnfd":"63C5E2345DEAAB933958A2865DED48DD5325517CC697FFB29FAFE234D2F422E3","lccekmodgklaepjeofjdjpbminllajkg":"6BD5B81F852E30AE6176274D3C19329E3F25B0EDEE96AB0C278F7D177D3B2B0F","mfehgcgbbipciphmccgaenjidiccnmng":"A3A8A15B3B82612A1743CE8B00B9AC84DB46FEA75A64B4237EAD279E1E1E8252","mfffpogegjflfpflabcdkioaeobkgjik":"AA79763AF68E281DBA854A220D0B92BDDE9051C4E18F9E849EADF2893F6F924A","mgndgikekgjfcpckkfioiadnlibdjbkf":"F7982C29E41C3E848D8EEF0EC233FBCD61F0CAFF64C9B859E5C8BB539BD47ED9","mhjfbmdgcfjbbpaeojofohoefgiehjai":"4261A242B403BEA589AA19624EFDBA0F80538858F6F35D2A0120E487A089C2C5","nbpagnldghgfoolbancepceaanlmhfmd":"2662D3C54C18704B4DA265AF584F7C5366DE7A417EBCB9BF8B5F9E8B4BD9C56B","neajdppkdcdipfabeoofebfddakdcjhd":"40A100A35342E0EB08A8116858274E319C21287B48D75D44089E7F0EF3CCB536","nkeimhogjdpnpccoofpliimaahmaaome":"9638F007955445DEE221161D515ED66FCC51B256BB490A95D3EA6D7F46E2B582","nmmhkkegccagdldgiimedpiccmgmieda":"6FB10838787F2BA5C9CC1286BC40EC0FB04F5BC2784EE9F1030E31635A139C28","ojkdcodhlkmiakbangobnmdhieapagic":"15AA0226A72CD80C74C0B7082D9FE28CA4C1E91B8FAF6D2FBC75463E61B19B51","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"67CB463BD73D719330DE8149B0FBBC39357E417AC3E94AD068122D0885D102EB"}},"google":{"services":{"last_username":"F9BBA32DCA9748618185976881191E504C6F4C67A239EC9076387A665F378BF5","username":"B92F7CC837A18614FABA2A5C3768B06CE585188A5165CD17D783B06680AD758A"}},"homepage":"D28696F02B195B5046EA5DCCE3740CD6D9E99762759BC73F32AAA7D65D981305","homepage_is_newtabpage":"DC8D3A03929B35F8327A2448D5AADA686D57E9A3C73B59DC3A543A9ED7D3C6B9","pinned_tabs":"756C433BC10535F438486FC95E1A2E11C94F468947604007229AA2FD6300708A","prefs":{"preference_reset_time":"808E7937BCC12781050F9E467898C4C8DA3AC753076621A3BF23736368927322"},"profile":{"reset_prompt_memento":"61F72C9A671BBD08D0A298D1692E8FC4646002F55B74F1D7AE49F1DE4E124F70"},"safebrowsing":{"incidents_sent":"F06838438DD4F91630CB070303204C517D5A57C18AC288B6A9742CF507E2DD13"},"search_provider_overrides":"B3DC4F4FA6EA3792A659D4C95245AF3684D2481B1D29DF808D5AB21DA05C23E6","session":{"restore_on_startup":"F40CB67672D7C3795B1899FCA53E8E39467C80DBBB7BF399D045845D6F35F77D","startup_urls":"684C141F70AE35DEE6B5D7500E52D6E9B93DBB11B51D89E3315B6BAFD2B950D1"},"software_reporter":{"prompt_reason":"A8F4FC8E877121C55A90B431E141FA3C72FAB36F6C198CAC212E99F0F42AA18B","prompt_seed":"776CB7907B418F3290D7FAAD9701BF9D98668E390984B7542CF96379209624F4","prompt_version":"C037DF52FC1DD6FF29240085A501C73D71EEAF7AF05681E16B0D06C2A46E3C65"},"sync":{"remaining_rollback_tries":"BF48F9E8AE0B423B289F52A7394B8262A5C1441612473416CE03889FBF684982"}},"super_mac":"1D22ACDD952CA8080ADF04AA13D49287FE602FC40375602F49B362BBDAF7646A"},"session":{"restore_on_startup":4,"startup_urls":["https://www.google.com/?gws_rd=ssl"]},"sync":{"remaining_rollback_tries":0}}), Replaced,[e6b964342169fa3c5a43d09dd6308f71]
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)

  • 0

#10
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
Hello, Lots of adware on this machine so stick with till I say we are done :)

Please run ESET scan, this scan could take a while, then rerun FRST. Instructions to follow:

ESET Online Scanner

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.
  • Please go >>HERE<< then click on: ESET1st.jpg

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on the ESETexe.jpg icon to install.

    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
  • Select the option YES, I accept the Terms of Use then click on: ESETsave.jpg
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: EOLS3.gif
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed make sure you first copy the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic.
  • Now click on: EOLS4.gif
    (Selecting Uninstall application on close if you so wish)
Next
Re-run Farbar Recovery Scan Tool (FRST/FRST64) you ran at the very beginning of this topic.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Make sure you checkmark Addition.txt box.
  • Press Scan button.
  • Scan will create two logs, FRST.txt and Addition.txt in the same directory the tool is run. Please copy and paste them to your reply.
Post the following logs in next reply,

ESET scan results.
FRST.txt
Additions.txt

Thanks
Joe
  • 0

Advertisements


#11
crybaby

crybaby

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 175 posts

WOW! That scan took a very long time.  :blink:

Here are the logs you asked for. Thanks so much for walking me through this!

 

ESET:

 

 

C:\AdwCleaner\Quarantine\C\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe.vir a variant of Win32/Toolbar.Zugo potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Shayla Potter\AppData\Local\ilividbandoomoviestoolbar\GC\IACNativeMsgHost.exe.vir a variant of Win32/Bundled.Toolbar.Ask.K potentially unsafe application
C:\AdwCleaner\Quarantine\C\Users\Shayla Potter\AppData\Roaming\BabSolution\Shared\BabMaint.exe.vir Win32/Toolbar.Babylon.I potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Shayla Potter\AppData\Roaming\BabSolution\Shared\BUSolution.dll.vir a variant of Win32/Toolbar.Babylon.AE potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\Extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}(38)\chrome\bittorrentbar.jar.vir Win32/Toolbar.Conduit potentially unwanted application
C:\Program Files\NCH Software\VideoPad\videopad.exe a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application
C:\Program Files\NCH Software\VideoPad\videopadsetup_v3.29.exe a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application
C:\Program Files\OpenDownloaderManager\spnocrc.exe Win32/Conduit.SearchProtect.N potentially unwanted application
C:\ProgramData\IObit\ASCDownloader\ASCSetup.exe a variant of Win32/Toolbar.Widgi.B potentially unwanted application
C:\Users\All Users\IObit\ASCDownloader\ASCSetup.exe a variant of Win32/Toolbar.Widgi.B potentially unwanted application
C:\Users\Mason\Downloads\prismpsetup.exe a variant of Win32/Toolbar.Conduit.K potentially unwanted application
C:\Users\Mason\Downloads\SoftonicDownloader_for_windows-media-player.exe Win32/SoftonicDownloader.A potentially unwanted application
C:\Users\Shayla Potter\Downloads\cbsidlm-cbsi188-Budget_Calendar-SEO-10360090.exe a variant of Win32/CNETInstaller.B potentially unwanted application
C:\Users\Shayla Potter\Downloads\CouponPrinter.exe a variant of Win32/Adware.Softomate.AD application
C:\Users\Shayla Potter\Downloads\GraboidVideoSetup-3.11.exe Win32/Graboid potentially unsafe application
C:\Users\Shayla Potter\Downloads\vppsetup.exe a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Application Updater\temp\~wtA147.tmp a variant of Win32/Toolbar.Widgi.B potentially unwanted application
 
 
 
FRST:
 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-05-2015 01
Ran by Shayla Potter (administrator) on BNSS-LEASED on 28-05-2015 03:20:39
Running from C:\Users\Shayla Potter\Desktop
Loaded Profiles: Shayla Potter (Available Profiles: Mason & Shayla Potter & Kieran & Administrator & Guest)
Platform: Microsoft® Windows Vista™ Home Basic  Service Pack 2 (X86) OS Language: English (United States)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
( ) C:\Windows\System32\dlcxcoms.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(NETGEAR) C:\Program Files\NETGEAR Genie\bin\NETGEARGenieDaemon.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Sonic Solutions) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(Microsoft Corporation) C:\Windows\System32\iashost.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
() C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
() C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
(Microsoft Corporation) C:\Windows\System32\wpcumi.exe
(Primax Electronics Ltd.) C:\Windows\System32\ico.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Nokia) C:\Users\Shayla Potter\Desktop\Kierans folder\Nokia PC Suite 7\PCSuite.exe
(NETGEAR Inc.) C:\Program Files\NETGEAR Genie\bin\NETGEARGenie.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Avanquest Software ) C:\Program Files\Digital Line Detect\DLG.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Dropbox, Inc.) C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft® Corporation) C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe
() C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Nokia) C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
(Nokia) C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
() C:\Program Files\NETGEAR Genie\bin\genie2_tray.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [11930696 2013-03-29] (Realtek Semiconductor)
HKLM\...\Run: [ISUSScheduler] => C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [81920 2006-10-03] (Macrovision Corporation)
HKLM\...\Run: [dscactivate] => c:\dell\dsca.exe [16384 2007-07-30] ( )
HKLM\...\Run: [Google Desktop Search] => C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-06-22] (Google)
HKLM\...\Run: [FaxCenterServer] => C:\Program Files\Dell PC Fax\fm3032.exe [312200 2006-11-03] ()
HKLM\...\Run: [dlcxmon.exe] => C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe [292336 2007-01-12] ()
HKLM\...\Run: [MemoryCardManager] => C:\Program Files\Dell Photo AIO Printer 926\memcard.exe [304008 2006-11-03] ()
HKLM\...\Run: [DLCXCATS] => rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16
HKLM\...\Run: [WPCUMI] => C:\Windows\system32\WpcUmi.exe [176128 2006-11-02] (Microsoft Corporation)
HKLM\...\Run: [Mouse Suite 98 Daemon] => C:\Windows\system32\ICO.EXE [56128 2007-02-15] (Primax Electronics Ltd.)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-03] (Apple Inc.)
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2006-12-10] (Hewlett-Packard Co.)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-12-22] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-11-14] ()
HKLM\...\Run: [TomcatStartup 2.5] => C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe [741376 2007-05-19] (Hewlett-Packard)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-07-08] (Apple Inc.)
HKLM\...\Run: [WRSVC] => C:\Program Files\Webroot\WRSA.exe [817072 2015-05-16] (Webroot)
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Run: [PC Suite Tray] => C:\Users\Shayla Potter\Desktop\Kierans folder\Nokia PC Suite 7\PCSuite.exe [1516632 2012-06-26] (Nokia)
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Run: [NETGEARGenie] => C:\Program Files\NETGEAR Genie\bin\NETGEARGenie.exe [602880 2014-12-14] (NETGEAR Inc.)
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\MountPoints2: E - E:\WRSetupCD.exe
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\MountPoints2: {f46aefae-e281-11e3-82dc-001aa06945f1} - G:\LGAutoRun.exe
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\MountPoints2: {f46af174-e281-11e3-82dc-001aa06945f1} - G:\LaunchU3.exe -a
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [294912 2008-01-19] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk [2007-11-21]
ShortcutTarget: Digital Line Detect.lnk -> C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2014-06-12]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\Kids\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk [2011-05-18]
ShortcutTarget: OpenOffice.org 3.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File)
Startup: C:\Users\Mason\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iWin Desktop Alerts.lnk [2008-08-01]
ShortcutTarget: iWin Desktop Alerts.lnk -> C:\ProgramData\iWin Games\DesktopAlerts\DesktopAlerts.exe (No File)
Startup: C:\Users\Mason\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk [2009-06-16]
ShortcutTarget: OpenOffice.org 3.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe (No File)
Startup: C:\Users\Shayla Potter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-04-10]
ShortcutTarget: Dropbox.lnk -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Shayla Potter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\WKCALREM.LNK [2010-02-19]
ShortcutTarget: WKCALREM.LNK -> C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe (Microsoft® Corporation)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.c...q={searchTerms}
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.c...q={searchTerms}
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....?trackid=sp-006
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\Software\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.co...=us&ibd=1071121
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
SearchScopes: HKLM -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.c...q={searchTerms}
SearchScopes: HKLM -> {EFE522B3-7ABD-49CB-A5C3-A2AFBBA83B9D} URL = https://www.google.c...q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\.DEFAULT -> {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = http://us.yhs.search...p={searchTerms}
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.c...q={searchTerms}
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {9001ECE5-27F9-7260-292B-CF945347FC97} URL = http://www.bing.com/...eferrer:source}
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.c...q={searchTerms}
SearchScopes: HKU\S-1-5-21-1260561122-373576474-2963483527-1005 -> {EFE522B3-7ABD-49CB-A5C3-A2AFBBA83B9D} URL = https://www.google.c...q={searchTerms}
BHO: Yahoo! IE Services Button -> {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -> C:\Program Files\Yahoo!\Common\yiesrvc.dll [2006-10-31] (Yahoo! Inc.)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-04-24] (Oracle Corporation)
BHO: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files\Webroot\WRData\PKG\Vistax86\wrflt.dll [2015-05-16] (Webroot)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-24] (Oracle Corporation)
DPF: {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} http://www.infospace...pointsSetup.exe
DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} 
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab
DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2006-06-05] (Microsoft Corporation)
Winsock: Catalog5 000000000007 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
 
FireFox:
========
FF ProfilePath: C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default
FF DefaultSearchEngine: Google (avast)
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1215155.dll [2014-12-10] (Adobe Systems, Inc.)
FF Plugin: @alternatiff.com/AlternaTIFF -> C:\Program Files\MIE\AlternaTIFF\npzzatif.dll [2013-02-05] (Medical Informatics Engineering, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-21] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2013-09-16] (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll [2013-12-27] (DivX, LLC)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-24] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-24] (Oracle Corporation)
FF Plugin: @meadco.com/neptune plugin,version=2.0.0.29 -> C:\Program Files\OSA Kit Pro Player v4.0\npmeadax.dll [2008-10-09] (MeadCo Corp.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=14 -> C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll [2011-09-06] (Google)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin HKU\S-1-5-21-1260561122-373576474-2963483527-1005: @nsroblox.roblox.com/launcher -> C:\Users\Shayla Potter\AppData\Local\Roblox\Versions\version-c04585a2d58a4f29\\NPRobloxProxy.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-1260561122-373576474-2963483527-1005: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Shayla Potter\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-04-05] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-1260561122-373576474-2963483527-1005: @yahoo.com/BrowserPlus,version=2.9.8 -> C:\Users\Shayla Potter\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll [2010-08-04] (Yahoo! Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nphssb.dll [2009-07-09] (Homestead Technologies, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npmeadax.dll [2008-10-09] (MeadCo Corp.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2013-08-08] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2013-08-08] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2013-08-08] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2013-08-08] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2013-08-08] (Apple Inc.)
FF SearchPlugin: C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\searchplugins\google-avast.xml [2014-12-22]
FF Extension: AppGraffiti - C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\Extensions\AppGraffiti@AppGraffiti(93).com [2012-03-18]
FF Extension: Ancestry.com Advanced Image Viewer - C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\Extensions\[email protected] [2010-05-16]
FF Extension: Old Default Image Style - C:\Users\Shayla Potter\AppData\Roaming\Mozilla\Firefox\Profiles\oyn0fdki.default\Extensions\[email protected] [2012-03-23]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-06-29]
FF HKLM\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-11-23]
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer
FF Extension: Webroot Filtering Extension - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer [2015-05-16]
 
Chrome: 
=======
CHR Profile: C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Bookmark Manager) - C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-15]
CHR Extension: (Webroot Filtering Extension) - C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Extensions\kjeghcllfecehndceplomkocgfbklffd [2015-05-27]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12]
CHR Extension: (Google Wallet) - C:\Users\Shayla Potter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21]
CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]
CHR HKLM\...\Chrome\Extension: [kjeghcllfecehndceplomkocgfbklffd] - C:\ProgramData\WRData\PKG\CHROME\CHROME_1.1.0.57.crx [2015-05-16]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 dlcx_device; C:\Windows\system32\dlcxcoms.exe [532480 2006-10-11] ( )
S3 DSBrokerService; C:\Program Files\DellSupport\brkrsvc.exe [70656 2007-03-19] () [File not signed]
S3 GoogleDesktopManager-051210-111108; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [30192 2010-06-22] (Google)
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [225280 2007-01-02] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [131072 2006-12-10] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R2 NETGEARGenieDaemon; C:\Program Files\NETGEAR Genie\bin\NETGEARGenieDaemon.exe [195840 2014-12-14] (NETGEAR)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
S3 RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [880640 2006-11-05] (Sonic Solutions) [File not signed]
R2 RoxWatch9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [159744 2006-11-05] (Sonic Solutions) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-19] (Microsoft Corporation)
S2 WRSVC; C:\Program Files\Webroot\WRSA.exe [817072 2015-05-16] (Webroot)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 Dot4Scan; C:\Windows\System32\DRIVERS\Dot4Scan.sys [10752 2008-01-19] (Microsoft Corporation)
S3 DSproct; C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys [4736 2006-10-05] (Gteko Ltd.) [File not signed]
S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [61704 2014-01-08] (FTDI Ltd.)
R3 HPPLSBULK; C:\Windows\System32\drivers\hpplsbulk.sys [9344 2005-02-02] (Hewlett Packard) [File not signed]
R3 MarvinBus; C:\Windows\System32\DRIVERS\MarvinBus.sys [171008 2005-06-02] (Pinnacle Systems GmbH) [File not signed]
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2015-05-28] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
R2 NPF; C:\Windows\system32\drivers\npf.sys [35088 2015-05-13] (CACE Technologies, Inc.)
R1 PCLEPCI; C:\Windows\system32\drivers\pclepci.sys [14165 2005-02-09] (Pinnacle Systems GmbH) [File not signed]
S3 pelmouse; C:\Windows\System32\DRIVERS\pelmouse.sys [23360 2007-02-15] (Primax Electronics Ltd.)
S3 pelusblf; C:\Windows\System32\DRIVERS\pelusblf.sys [19264 2007-02-15] (Primax Electronics Ltd.)
R0 PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [36624 2006-10-18] (Sonic Solutions) [File not signed]
S3 usbanyka; C:\Windows\System32\DRIVERS\UsbAnyka.sys [17536 2007-10-22] (Anyka (Guangzhou) Software Technology Co., Ltd.) [File not signed]
S3 vncmirror; C:\Windows\System32\DRIVERS\vncmirror.sys [3072 2007-10-17] (RealVNC Ltd.)
S2 W55U01; C:\Windows\System32\Drivers\W55U01.sys [15232 2005-08-12] (Windows ® 2000 DDK provider) [File not signed]
R0 WRkrn; C:\Windows\System32\drivers\WRkrn.sys [117784 2015-05-16] (Webroot)
S3 wrUrlFlt; C:\Windows\system32\DRIVERS\wrUrlFlt.sys [37432 2015-05-16] (Webroot)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-05-28 03:20 - 2015-05-28 03:23 - 00025546 _____ () C:\Users\Shayla Potter\Desktop\FRST.txt
2015-05-28 03:18 - 2015-05-28 03:18 - 00000000 ____D () C:\Users\Shayla Potter\Desktop\FRST-OlderVersion
2015-05-27 15:32 - 2015-05-27 15:32 - 02347384 _____ (ESET) C:\Users\Shayla Potter\Downloads\esetsmartinstaller_enu(1).exe
2015-05-27 15:31 - 2015-05-27 15:31 - 02347384 _____ (ESET) C:\Users\Shayla Potter\Downloads\esetsmartinstaller_enu.exe
2015-05-27 10:51 - 2015-05-27 10:51 - 00001081 _____ () C:\Users\Shayla Potter\Desktop\MBAMscan results.txt
2015-05-27 09:32 - 2015-05-28 02:21 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-27 09:31 - 2015-05-27 09:31 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Shayla Potter\Desktop\mbam-setup-2.1.6.1022 (2).exe
2015-05-27 09:31 - 2015-05-27 09:31 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Shayla Potter\Desktop\mbam-setup-2.1.6.1022 (1).exe
2015-05-27 09:31 - 2015-05-27 09:31 - 00000861 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-27 09:31 - 2015-05-27 09:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-27 09:31 - 2015-05-27 09:31 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-05-27 09:31 - 2015-04-14 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-05-27 09:31 - 2015-04-14 09:37 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-05-27 09:31 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-05-27 09:27 - 2015-05-27 09:27 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Shayla Potter\Desktop\mbam-setup-2.1.6.1022.exe
2015-05-26 09:33 - 2015-05-26 09:33 - 00004217 _____ () C:\Users\Shayla Potter\Desktop\JRT.txt
2015-05-26 09:30 - 2015-05-26 09:30 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-BNSS-LEASED-Windows-Vista-™-Home-Basic-(32-bit).dat
2015-05-26 09:30 - 2015-05-26 09:30 - 00000000 ___DC () C:\RegBackup
2015-05-26 09:28 - 2015-05-26 09:28 - 02946703 _____ (Thisisu) C:\Users\Shayla Potter\Desktop\JRT.exe
2015-05-26 08:56 - 2015-05-26 09:19 - 00000000 ___DC () C:\AdwCleaner
2015-05-26 08:56 - 2015-05-26 08:56 - 00000013 _____ () C:\Users\Shayla Potter\Desktop\next step.txt
2015-05-26 06:48 - 2015-05-26 06:48 - 02223104 _____ () C:\Users\Shayla Potter\Desktop\adwcleaner_4.205.exe
2015-05-24 12:28 - 2015-05-28 03:18 - 01147392 ____C (Farbar) C:\Users\Shayla Potter\Desktop\FRST.exe
2015-05-24 12:27 - 2015-05-28 03:21 - 00000000 ___DC () C:\FRST
2015-05-24 12:25 - 2015-05-24 12:27 - 01146880 _____ (Farbar) C:\Users\Shayla Potter\Downloads\FRST.exe
2015-05-23 12:17 - 2015-05-23 12:17 - 00002195 _____ () C:\Users\Shayla Potter\Desktop\T+C.txt
2015-05-18 16:17 - 2015-05-18 16:17 - 00018840 _____ () C:\Users\Shayla Potter\Desktop\KAEDYN ROCKS!.txt
2015-05-17 09:28 - 2015-05-17 09:28 - 00858768 _____ () C:\Users\Shayla Potter\Desktop\scanlog.log
2015-05-16 19:23 - 2015-05-16 19:23 - 00037432 ____T (Webroot) C:\Windows\system32\Drivers\wrUrlFlt.sys
2015-05-16 19:22 - 2015-05-27 12:31 - 00000657 _____ () C:\Users\Public\Desktop\Webroot SecureAnywhere.lnk
2015-05-16 19:22 - 2015-05-16 19:23 - 00000000 ____D () C:\Program Files\Webroot
2015-05-16 19:22 - 2015-05-16 19:22 - 00166128 _____ (Webroot) C:\Windows\system32\WRusr.dll
2015-05-16 19:22 - 2015-05-16 19:22 - 00117784 _____ (Webroot) C:\Windows\system32\Drivers\WRkrn.sys
2015-05-16 19:22 - 2015-05-16 19:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webroot SecureAnywhere
2015-05-16 19:01 - 2015-05-26 18:03 - 00000000 ____D () C:\ProgramData\WRData
2015-05-14 16:54 - 2015-05-14 16:54 - 00000000 ____D () C:\Users\Shayla Potter\Desktop\Make a word cloud - WordItOut_files
2015-05-13 09:04 - 2015-05-26 09:24 - 00000000 ____D () C:\Users\Shayla Potter\AppData\Local\NETGEARGenie
2015-05-13 09:04 - 2015-05-13 09:04 - 00001805 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NETGEAR Genie.lnk
2015-05-13 09:04 - 2015-05-13 09:04 - 00001793 _____ () C:\Users\Public\Desktop\NETGEAR Genie.lnk
2015-05-13 09:01 - 2015-05-13 09:02 - 39316824 _____ (NETGEAR Inc.) C:\Users\Shayla Potter\Downloads\NETGEARGenie-install (1).exe
2015-05-13 03:57 - 2015-04-30 11:03 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-13 03:55 - 2015-04-19 16:24 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2015-05-13 03:55 - 2015-04-19 16:24 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2015-05-13 03:55 - 2015-04-19 16:24 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2015-05-13 03:55 - 2015-04-19 16:24 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2015-05-13 03:55 - 2015-04-19 15:19 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-05-13 03:55 - 2015-04-19 15:18 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2015-05-13 03:55 - 2015-04-19 15:13 - 00682496 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2015-05-13 03:55 - 2015-04-19 15:12 - 01072640 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-13 03:55 - 2015-04-19 15:12 - 00801792 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-13 03:55 - 2015-04-18 23:59 - 02065408 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-13 03:52 - 2015-04-30 08:14 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 03:10 - 2015-04-10 18:22 - 00279552 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-12 17:38 - 2015-04-10 10:19 - 00421888 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-12 17:38 - 2015-04-10 10:18 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-05-12 17:38 - 2015-04-10 10:18 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-05-12 17:37 - 2015-04-10 10:30 - 12379136 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-12 17:37 - 2015-04-10 10:25 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-12 17:37 - 2015-04-10 10:25 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-12 17:37 - 2015-04-10 10:24 - 09750528 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-12 17:37 - 2015-04-10 10:21 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-12 17:37 - 2015-04-10 10:20 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-12 17:37 - 2015-04-10 10:20 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-12 17:37 - 2015-04-10 10:19 - 01804288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-12 17:37 - 2015-04-10 10:19 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-12 17:37 - 2015-04-10 10:19 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-12 17:37 - 2015-04-10 10:19 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-05-12 17:37 - 2015-04-10 10:19 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-05-12 17:37 - 2015-04-10 10:19 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-05-12 17:37 - 2015-04-10 10:19 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-05-12 17:37 - 2015-04-10 10:18 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-05-12 17:37 - 2015-04-10 10:18 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-12 17:37 - 2015-04-10 10:18 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-12 17:37 - 2015-04-10 10:18 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-12 17:37 - 2015-04-10 10:18 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-05-02 22:25 - 2015-05-02 22:25 - 00153448 _____ () C:\Windows\Minidump\Mini050215-01.dmp
2015-05-02 22:20 - 2014-01-09 19:59 - 526695157 _____ () C:\Users\Shayla Potter\Desktop\YUNC0001.mp4
2015-04-28 08:41 - 2015-04-28 08:43 - 00000000 ____D () C:\Users\Shayla Potter\Desktop\Jeremy
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-05-28 03:06 - 2012-03-31 06:52 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-28 03:06 - 2007-11-21 10:54 - 01794847 _____ () C:\Windows\WindowsUpdate.log
2015-05-28 02:33 - 2006-11-02 07:45 - 00003568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-28 02:33 - 2006-11-02 07:45 - 00003568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-28 02:32 - 2009-08-27 22:17 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-28 00:31 - 2009-08-27 22:17 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-27 13:51 - 2014-05-02 21:05 - 00000000 ___RD () C:\Users\Shayla Potter\Dropbox
2015-05-27 13:51 - 2014-05-02 21:02 - 00000000 ____D () C:\Users\Shayla Potter\AppData\Roaming\Dropbox
2015-05-27 12:31 - 2013-11-23 15:30 - 01097474 _____ () C:\Windows\PFRO.log
2015-05-27 12:31 - 2008-08-28 11:35 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2015-05-27 12:31 - 2006-11-02 07:58 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-27 12:30 - 2006-11-02 06:18 - 00000000 ____D () C:\Windows\security
2015-05-27 12:29 - 2006-11-02 07:58 - 00032642 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-05-27 11:24 - 2010-04-25 15:13 - 00000868 _____ () C:\Windows\Tasks\Google Software Updater.job
2015-05-27 10:57 - 2014-12-07 11:49 - 00000000 ____D () C:\Users\Shayla Potter\AppData\Roaming\Angry_Birds
2015-05-27 10:57 - 2014-08-24 17:18 - 00000000 ____D () C:\Program Files\CamStudio 2.7
2015-05-27 10:57 - 2013-08-21 02:08 - 00000000 ____D () C:\Program Files\OpenDownloaderManager
2015-05-27 09:28 - 2008-04-14 12:12 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-05-25 12:21 - 2013-08-14 17:33 - 00000296 __RSH () C:\Users\Shayla Potter\ntuser.pol
2015-05-25 12:21 - 2009-07-13 21:43 - 00000000 ____D () C:\Users\Shayla Potter
2015-05-25 12:21 - 2006-11-02 06:18 - 00000000 ____D () C:\Windows\tracing
2015-05-25 11:16 - 2011-06-21 17:12 - 00000000 ____D () C:\Program Files\Adobe
2015-05-25 11:16 - 2009-08-17 07:57 - 00000000 ____D () C:\Users\Shayla Potter\AppData\Local\Adobe
2015-05-25 11:16 - 2007-11-21 11:21 - 00000000 ____D () C:\ProgramData\Adobe
2015-05-25 10:41 - 2011-08-20 20:58 - 00000000 ____D () C:\Users\Kieran
2015-05-25 10:41 - 2011-03-14 13:24 - 00000000 ____D () C:\Users\Kids
2015-05-25 10:40 - 2006-11-02 06:18 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2015-05-16 15:34 - 2009-07-13 21:44 - 00001356 _____ () C:\Users\Shayla Potter\AppData\Local\d3d9caps.dat
2015-05-15 08:32 - 2011-01-22 10:13 - 00120216 _____ () C:\Users\Shayla Potter\Desktop\Budget year look.ods
2015-05-13 09:03 - 2012-07-31 19:26 - 00281104 _____ (CACE Technologies, Inc.) C:\Windows\system32\wpcap.dll
2015-05-13 09:03 - 2012-07-31 19:26 - 00096784 _____ (CACE Technologies, Inc.) C:\Windows\system32\packet.dll
2015-05-13 09:03 - 2012-07-31 19:26 - 00035088 _____ (CACE Technologies, Inc.) C:\Windows\system32\Drivers\npf.sys
2015-05-13 04:33 - 2006-11-02 06:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-05-13 04:20 - 2006-11-02 07:44 - 00540864 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-13 04:17 - 2008-07-12 19:11 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-05-13 04:15 - 2006-11-02 07:35 - 00000000 ____D () C:\Windows\system32\XPSViewer
2015-05-13 03:50 - 2013-08-01 03:02 - 00000000 ____D () C:\Windows\system32\MRT
2015-05-13 03:14 - 2006-11-02 05:24 - 137310008 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-05-13 03:07 - 2010-06-03 21:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-05-12 18:12 - 2014-05-02 21:03 - 00000000 ____D () C:\Users\Shayla Potter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-05-11 03:13 - 2006-11-02 05:33 - 00784272 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-10 11:14 - 2014-06-12 19:56 - 00127388 _____ () C:\Windows\hppins01.dat
2015-05-10 11:14 - 2010-01-18 23:47 - 00042706 _____ () C:\ProgramData\hpzinstall.log
2015-05-10 07:42 - 2006-11-02 05:23 - 00000179 _____ () C:\Windows\win.ini
2015-05-10 07:38 - 2007-12-07 14:08 - 00000000 ____D () C:\Program Files\Dl_cats
2015-05-09 08:19 - 2013-11-23 14:40 - 00063057 _____ () C:\Windows\setupact.log
2015-05-02 22:25 - 2013-11-23 15:24 - 233041665 _____ () C:\Windows\MEMORY.DMP
2015-05-02 22:25 - 2008-01-04 16:11 - 00000000 ____D () C:\Windows\Minidump
2015-05-02 22:17 - 2010-03-31 07:49 - 00000000 ____C () C:\DebugTraceNormal.log
2015-05-02 22:16 - 2008-07-22 16:00 - 00000000 ____D () C:\MDT
2015-05-01 23:36 - 2006-11-02 06:18 - 00000000 ____D () C:\Windows\system32\LogFiles
2015-04-28 08:45 - 2015-03-22 11:47 - 00000000 ____D () C:\Users\Shayla Potter\Desktop\Eagle Aspen SSM-22 Single Signal Meter (SSM-22) from Solid Signal_files
2015-04-28 08:44 - 2014-03-06 17:58 - 00000000 ____D () C:\Users\Shayla Potter\Desktop\Shayla's Phone
2015-04-28 08:44 - 2013-06-18 07:56 - 00000000 ____D () C:\Users\Shayla Potter\Desktop\KAEDYN'S Stuff
 
==================== Files in the root of some directories =======
 
2014-08-24 19:49 - 2014-08-24 19:49 - 0000046 _____ () C:\Users\Shayla Potter\AppData\Roaming\Camdata.ini
2014-08-24 19:49 - 2014-08-24 19:49 - 0000408 _____ () C:\Users\Shayla Potter\AppData\Roaming\CamLayout.ini
2014-08-24 19:49 - 2014-08-24 19:49 - 0000408 _____ () C:\Users\Shayla Potter\AppData\Roaming\CamShapes.ini
2014-08-24 19:49 - 2014-08-24 19:49 - 0004535 _____ () C:\Users\Shayla Potter\AppData\Roaming\CamStudio.cfg
2014-10-22 21:17 - 2014-10-24 07:17 - 0000098 _____ () C:\Users\Shayla Potter\AppData\Roaming\WB.CFG
2009-08-18 12:53 - 2015-02-20 07:23 - 0003088 _____ () C:\Users\Shayla Potter\AppData\Roaming\wklnhst.dat
2009-07-13 21:44 - 2015-05-16 15:34 - 0001356 _____ () C:\Users\Shayla Potter\AppData\Local\d3d9caps.dat
2009-09-22 16:49 - 2015-03-12 10:25 - 0073216 _____ () C:\Users\Shayla Potter\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-01-08 15:27 - 2012-01-08 15:27 - 0000101 _____ () C:\Users\Shayla Potter\AppData\Local\fusioncache.dat
2010-01-18 23:47 - 2015-05-10 11:14 - 0042706 _____ () C:\ProgramData\hpzinstall.log
2008-01-26 18:43 - 2008-01-26 18:43 - 0164144 _____ () C:\ProgramData\SPL7338.tmp
 
Some files in TEMP:
====================
C:\Users\Shayla Potter\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp5tsd_j.dll
C:\Users\Shayla Potter\AppData\Local\Temp\Quarantine.exe
C:\Users\Shayla Potter\AppData\Local\Temp\sqlite3.dll
 
 
Some zero byte size files/folders:
==========================
C:\Windows\System32\DIFxAPI.dll
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
==================== End of log ============================
 
 
Additions.txt:
 
 
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 27-05-2015 01
Ran by Shayla Potter at 2015-05-28 03:24:44
Running from C:\Users\Shayla Potter\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1260561122-373576474-2963483527-500 - Administrator - Disabled) => C:\Users\Administrator
Guest (S-1-5-21-1260561122-373576474-2963483527-501 - Limited - Disabled) => C:\Users\Guest
Kieran (S-1-5-21-1260561122-373576474-2963483527-1010 - Limited - Enabled) => C:\Users\Kieran
Mason (S-1-5-21-1260561122-373576474-2963483527-1000 - Administrator - Enabled) => C:\Users\Mason
Shayla Potter (S-1-5-21-1260561122-373576474-2963483527-1005 - Administrator - Enabled) => C:\Users\Shayla Potter
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Webroot SecureAnywhere (Disabled - Up to date) {66A6FE14-08CB-F415-3742-517201416109}
AS: Webroot SecureAnywhere (Disabled - Up to date) {DDC71FF0-2EF1-FB9B-0DF2-6A007AC62BB4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden
ABBYY FineReader 6.0 Sprint (HKLM\...\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.1784.41616 - ABBYY Software House)
AccelerateTab (HKLM\...\AccelerateTab_is1) (Version: 2.6 - AccelerateTab)
Adobe Flash Player 17 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM\...\Adobe Shockwave Player) (Version: 12.1.5.155 - Adobe Systems, Inc.)
Apple Application Support (HKLM\...\{21ECABC3-40B2-42DF-8E21-ACF3A4D0D95A}) (Version: 3.0.5 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{941B4CE7-3F5D-443E-A8B7-56A420D2EAFD}) (Version: 7.1.2.6 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Architectural Library for progeCAD SMART! ENG (HKLM\...\Architectural Library for progeCAD SMART! ENG) (Version:  - )
Arduino (HKLM\...\Arduino) (Version: 1.0.5-r2 - Arduino LLC)
AviSynth 2.5 (HKLM\...\AviSynth) (Version:  - )
Blender (HKLM\...\Blender) (Version: 2.68a - Blender Foundation)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Browser Address Error Redirector (HKLM\...\{62230596-37E5-4618-A329-0D21F529A86F}) (Version: 1.00.0000 - Dell)
BufferChm (Version: 82.0.173.000 - Hewlett-Packard) Hidden
CamStudio 2.7.2 (HKLM\...\{04B83666-3A62-452B-85D3-70F8117F2329}_is1) (Version: 2.7.2 - CamStudio Open Source)
Celtx (2.9.1) (HKLM\...\Celtx (2.9.1)) (Version: 2.9.1 (en-US) - Greyfirst)
Conexant D850 PCI V.92 Modem (HKLM\...\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1) (Version:  - )
CustomerResearchQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Dell DataSafe Online (HKLM\...\{2C6C74C2-042F-4D36-B7B0-0C538FCF01AB}) (Version: 1.0.15 - Dell, Inc.)
Dell Driver Download Manager (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\f031ef6ac137efc5) (Version: 2.1.0.0 - Dell Inc.)
Dell Getting Started Guide (HKLM\...\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell PC Fax (HKLM\...\Dell PC Fax) (Version:  - )
Dell Photo AIO Printer 926 (HKLM\...\Dell Photo AIO Printer 926) (Version:  - Dell, Inc.)
Dell Support Center (HKLM\...\{B8C54AB1-7E1A-40E8-B794-EDB6E8921F3A}) (Version: 1.0.07192 - Dell)
DellSupport (HKLM\...\{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}) (Version: 6.0.3075 - Dell)
DesignPro 5.4 Limited Edition (HKLM\...\InstallShield_{71F6DF7D-B639-4FAD-BA93-E6DF267AA44D}) (Version: 5.2.1201 - Avery Dennison)
DesignPro 5.4 Limited Edition (Version: 5.2.1201 - Avery Dennison) Hidden
Destinations (Version: 82.0.173.000 - Hewlett-Packard) Hidden
DeviceManagementQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Digital Line Detect (HKLM\...\{E646DCF0-5A68-11D5-B229-002078017FBF}) (Version: 1.21 - BVRP Software, Inc)
DivX Setup (HKLM\...\DivX Setup) (Version: 2.6.1.90 - DivX, LLC)
DocProc (Version: 8.1.0.0 - Hewlett-Packard) Hidden
DocProcQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Dropbox (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Dropbox) (Version: 3.4.6 - Dropbox, Inc.)
DVD Decrypter (Remove Only) (HKLM\...\DVD Decrypter) (Version:  - )
ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version:  - )
eSupportQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
FaxTools (HKLM\...\{F45298E5-0083-426F-A668-1A2C5F04B8A0}) (Version: 5.10 - BVRP Software)
File Shredder 2.5 (HKLM\...\File Shredder_is1) (Version:  - Pow Tools)
Google Chrome (HKLM\...\Google Chrome) (Version: 43.0.2357.81 - Google Inc.)
Google Desktop (HKLM\...\Google Desktop) (Version: 5.9.1005.12335 - Google)
Google Earth (HKLM\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google SketchUp 8 (HKLM\...\{B700113B-24A8-4D4C-8484-0CC944F764C8}) (Version: 3.0.3117 - Google, Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.27.5 - Google Inc.) Hidden
Google Updater (HKLM\...\Google Updater) (Version: 2.4.2432.1652 - Google Inc.)
HP Color LaserJet 2820/2830/2840 3.1 (HKLM\...\HP Color LaserJet 2820/2830/2840) (Version: 3.1 - HP)
HP Customer Participation Program 8.0 (HKLM\...\HPExtendedCapabilities) (Version: 8.0 - HP)
HP Imaging Device Functions 8.0 (HKLM\...\HP Imaging Device Functions) (Version: 8.0 - HP)
HP Managed Printing Admin (HKLM\...\{7CA4F780-7AD0-417A-82A1-46EB825CFD53}) (Version: 2.5.8 - Hewlett-Packard)
HP OCR Software 8.0 (HKLM\...\HPOCR) (Version: 8.0 - HP)
HP Solution Center 8.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 8.0 - HP)
HP Update (HKLM\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HP Wireless Rechargeable Optical Mouse (HKLM\...\MouseSuite98) (Version:  - )
hppCLJ2800 (Version: 003.000.00273 - Hewlett-Packard) Hidden
hppDustDevil (Version: 003.000.00106 - Hewlett-Packard) Hidden
hppFaxDrv (Version: 003.000.00136 - Hewlett-Packard) Hidden
hppFonts (Version: 001.001.00056 - Hewlett-Packard) Hidden
hppIOFiles (Version: 002.000.00030 - Hewlett-Packard) Hidden
hppManuals2800 (Version: 003.000.00284 - Hewlett-Packard) Hidden
HPProductAssistant (Version: 82.0.173.000 - Hewlett-Packard) Hidden
hppscan2800 (Version: 003.000.00274 - Hewlett-Packard) Hidden
hppScanTo (Version: 003.000.00261 - Hewlett-Packard) Hidden
hppSendFax (Version: 003.000.00136 - Hewlett-Packard) Hidden
hppTLBX2840 (Version: 001.000.00002 - Hewlett-Packard) Hidden
hppTLBX2840Help (Version: 001.000.00001 - Hewlett-Packard) Hidden
hppTooCool (Version: 1.00.0000 - Hewlett-Packard) Hidden
Itibiti RTC (Version: 0.0.1 - Itibiti Inc) Hidden
iTunes (HKLM\...\{0A37EE62-9A58-420D-90CC-4E52153112EE}) (Version: 11.3.0.54 - Apple Inc.)
Java 8 Update 45 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
Juniper Networks Cache Cleaner 6.1.0 (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Juniper_Networks_Cache_Cleaner 6.1.0) (Version: 6.1.0.13281 - Juniper Networks)
Juniper Networks Host Checker (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Neoteris_Host_Checker) (Version: 7.1.0.18193 - Juniper Networks)
Juniper Networks Setup Client Activex Control (HKLM\...\Juniper_Setup_Client Activex Control) (Version: 2.1.1.1 - Juniper Networks)
Juniper Networks, Inc. Setup Client (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Juniper_Setup_Client) (Version: 7.1.2.10059 - Juniper Networks, Inc.)
Logicator for PIC micros (HKLM\...\{273DE5D6-81A6-4EF5-B21C-E4095E21F174}) (Version: 3.06.05 - Revolution Education Limited)
Malwarebytes Anti-Malware version 2.1.6.1022 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
MarketResearch (HKLM\...\{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}) (Version: 82.0.174.000 - Hewlett-Packard)
Mechanics Library for progeCAD SMART! ENG (HKLM\...\Mechanics Library for progeCAD SMART! ENG) (Version:  - )
Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version:  - )
Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version:  - )
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Automated Troubleshooting Services Shim (HKLM\...\{c9920352-04e6-469d-bab8-e2b9c7c75415}.sdb) (Version:  - )
Microsoft Fix it Center (HKLM\...\{B7588D45-AFDC-4C93-9E2E-A100F3554B64}) (Version: 1.0.0100 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Works (HKLM\...\{6D52C408-B09A-4520-9B18-475B81D393F1}) (Version: 08.05.0818 - Microsoft Corporation)
MiShell*Budget (remove only) (HKLM\...\MiShell_Budget) (Version:  - )
Modem Diagnostic Tool (HKLM\...\{F63A3748-B93D-4360-9AD4-B064481A5C7B}) (Version: 1.0.17.8 - Dell)
Mozilla Firefox 30.0 (x86 en-US) (HKLM\...\Mozilla Firefox 30.0 (x86 en-US)) (Version: 30.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla)
MSVC90_x86 (Version: 1.0.1.2 - Nokia) Hidden
MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB941833) (HKLM\...\{C523D256-313D-4866-B36A-F3DE528246EF}) (Version: 4.20.9849.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
msxml4 (HKLM\...\{5AE3D9F1-9E9E-4015-8787-E22705AA32C5}) (Version: 1.0.0 - Default Company Name)
Music, Photos & Videos Launcher (HKLM\...\{D7769185-9A7C-48D4-8874-5388743A1DE2}) (Version: 1.00.0000 - Dell Inc.)
NaturalReaderFree (HKLM\...\{C5E7BF75-007E-44AD-8962-627ED44CB63B}) (Version: 11.8 - NaturalSoft)
NCH Toolbox (HKLM\...\ToolBox) (Version:  - NCH Software)
Netflix Movie Viewer (HKLM\...\{BCE72AED-3332-4863-9567-C5DCB9052CA2}) (Version: 1.2.211 - Netflix)
NETGEAR Genie (HKLM\...\NETGEAR Genie) (Version: 2.3.1.57 - NETGEAR Inc.)
NETGEAR Live Parental Controls Management Utility 2.1.5 (HKLM\...\NETGEAR Live Parental Controls Management Utility) (Version: 2.1.5 - )
NETGEAR Live Parental Controls User Utility 1.0b40 (HKLM\...\NETGEAR Live Parental Controls User Utility) (Version: 1.0b40 - )
Nokia Connectivity Cable Driver (HKLM\...\{A57025CC-5F2E-4D01-B387-06DB10500D43}) (Version: 7.1.78.0 - Nokia)
Nokia PC Suite (HKLM\...\Nokia PC Suite) (Version: 7.1.180.94 - Nokia)
Nokia PC Suite (Version: 7.1.180.94 - Nokia) Hidden
NVIDIA Graphics Driver 285.62 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 285.62 - NVIDIA Corporation)
NVIDIANetworkDiagnostic (HKLM\...\InstallShield_{EFAD4066-CAF3-4B27-9669-12EED352C376}) (Version: 1.00.0000 - NVIDIA Corporation)
Onverse (HKLM\...\{B3B30A68-B9A5-4d42-86E6-2BD1AFCE9DD4}) (Version:  - )
Onverse (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\{B3B30A68-B9A5-4d42-86E6-2BD1AFCE9DD4}) (Version:  - )
OpenAL (HKLM\...\OpenAL) (Version:  - )
OpenOffice 4.0.0 (HKLM\...\{55E61709-D7D4-43C0-B45D-BFAF5C09A02D}) (Version: 4.00.9702 - Apache Software Foundation)
OSA Kit Pro Player v4.0 1.0 (HKLM\...\OSA Kit Pro Player) (Version: 1.0 - Maher F. Farag)
PC Connectivity Solution (HKLM\...\{644F4910-E812-49AD-93EC-86828CB81A0D}) (Version: 12.0.27.0 - Nokia)
Pdf995 (HKLM\...\Pdf995) (Version:  - )
Pinnacle Instant DVD Recorder (HKLM\...\{EF781A5C-58F5-4BFD-87F9-E4F14D382F25}) (Version:  - )
Pinnacle Studio MediaSuite (HKLM\...\{77B8ECB2-1ACF-4587-8FB1-FCF856DB8149}) (Version:  - )
PowerDVD (HKLM\...\{281ECE39-F043-492B-8337-F2E546B5604A}) (Version: 7.0 - Dell)
Product Documentation Launcher (HKLM\...\{89CEAE14-DD0F-448E-9554-15781EC9DB24}) (Version: 1.00.0000 - Dell Inc.)
QuickTime 7 (HKLM\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
RealDownloader (Version: 1.3.3 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6873 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
ROBLOX Player for Shayla Potter (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version:  - ROBLOX Corporation)
ROBLOX Studio 2013 for Shayla Potter (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\{2922D6F1-2865-4EFA-97A9-94EEAB3AFA14}) (Version:  - ROBLOX Corporation)
Roxio Creator Audio (HKLM\...\{83FFCFC7-88C6-41c6-8752-958A45325C82}) (Version: 3.3.0 - Roxio)
Roxio Creator BDAV Plugin (HKLM\...\{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}) (Version: 3.3.0 - Roxio)
Roxio Creator Copy (HKLM\...\{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}) (Version: 3.3.0 - Roxio)
Roxio Creator Data (HKLM\...\{0D397393-9B50-4c52-84D5-77E344289F87}) (Version: 3.3.0 - Roxio)
Roxio Creator DE (HKLM\...\{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}) (Version: 3.3.0 - Roxio)
Roxio Creator Tools (HKLM\...\{0394CDC8-FABD-4ed8-B104-03393876DFDF}) (Version: 3.3.0 - Roxio)
Roxio MyDVD DE (HKLM\...\{D639085F-4B6E-4105-9F37-A0DBB023E2FB}) (Version: 9.0.116 - Roxio, Inc.)
Roxio Update Manager (HKLM\...\{30465B6C-B53F-49A1-9EBA-A3F187AD502E}) (Version: 3.0.0 - Roxio)
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.3.2300.0 - SAMSUNG Electronics Co., Ltd.)
Scan (Version: 8.1.0.0 - Hewlett-Packard) Hidden
SolutionCenter (Version: 82.0.188.000 - Hewlett-Packard) Hidden
Sonic Activation Module (Version: 1.0 - Sonic Solutions) Hidden
Stepvoice Recorder 1.8.0.206 (HKLM\...\Stepvoice Recorder_is1) (Version:  - )
SupportSoft Assisted Service (HKLM\...\{5A3F6A80-7913-475E-8B96-477A952CFA43}) (Version: 15 - SupportSoft)
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
System Requirements Lab (HKLM\...\SystemRequirementsLab) (Version:  - )
teenSMART UAC (HKLM\...\{443e579d-41ad-4f89-8680-2dd410815800}.sdb) (Version:  - )
teenSMART v3 (HKLM\...\teenSMART v3 2012.03.06.i_v3) (Version: 2012.03.06.i_v3 - ADEPT)
TrayApp (Version: 82.0.188.000 - Hewlett-Packard) Hidden
Unity Web Player (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
User's Guides (HKLM\...\{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}) (Version:  - )
VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden
Video Viewer (HKLM\...\Video Viewer) (Version: 0.1.5.0 - )
VideoPad Video Editor (HKLM\...\VideoPad) (Version: 3.29 - NCH Software)
VoiceSupport 1.2.01 (HKLM\...\TC-Helicon VoiceSupport_is1) (Version: 1.2.01 build 38 - TC-Helicon Vocal Technologies Inc.)
WebReg (Version: 82.0.173.000 - Hewlett-Packard) Hidden
Webroot SecureAnywhere (HKLM\...\WRUNINST) (Version: 8.0.8.88 - Webroot)
Windows Driver Package - Nokia Modem  (02/25/2011 4.7) (HKLM\...\E0AC723A3DE3A04256288CADBBB011B112AED454) (Version: 02/25/2011 4.7 - Nokia)
Windows Driver Package - Nokia Modem  (02/25/2011 7.01.0.9) (HKLM\...\72A50F48CC5601190B9C4E74D81161693133E7F7) (Version: 02/25/2011 7.01.0.9 - Nokia)
Windows Driver Package - Nokia pccsmcfd “LegacyDriver”  (05/31/2012 7.1.2.0) (HKLM\...\17D063A0A9F5D5A225B76B1D9BCB5ADBE85C8382) (Version: 05/31/2012 7.1.2.0 - Nokia)
Windows Media Player Firefox Plugin (HKLM\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
WinX DVD Ripper 5.5.12 (HKLM\...\WinX DVD Ripper_is1) (Version:  - Digiarty Software, Inc.)
Yahoo! Browser Services (HKLM\...\Yahoo! Extras) (Version:  - )
Yahoo! BrowserPlus 2.9.8 (HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\Yahoo! BrowserPlus) (Version:  - Yahoo! Inc.)
Yahoo! Internet Mail (HKLM\...\Yahoo! Mail) (Version:  - )
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1260561122-373576474-2963483527-1005_Classes\CLSID\{FFF2D28F-E4EE-44D9-8104-8E71556757F6}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe (Macrovision Corporation)
 
==================== Restore Points =========================
 
27-05-2015 03:00:13 Windows Update
28-05-2015 03:00:16 Windows Update
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2006-11-02 05:23 - 2011-06-27 07:39 - 00000098 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1       localhost
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {03355EE0-16B5-4F55-83C0-8246D6182C05} - System32\Tasks\{21ABCF18-A105-4A65-AD41-D5AD2C4BD073} => pcalua.exe -a "C:\Users\Shayla Potter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RKG1HMTY\Oil-hydraulics and Pneumatics.exe" -d "C:\Users\Shayla Potter\Desktop"
Task: {062C4F4C-8FB5-425A-9408-296D3EBAA594} - System32\Tasks\avastBCLRestartS-1-5-21-1260561122-373576474-2963483527-1005 => Chrome.exe 
Task: {0C6DF14F-9D21-4096-A449-D6E3964A0948} - System32\Tasks\{45671976-48C0-4B2E-BF6B-316085BF803E} => pcalua.exe -a E:\Setup.EXE -d E:\
Task: {456EE45A-4B28-41D4-8D6C-AD888CDA4656} - System32\Tasks\{9034CA5D-3868-440B-86CC-25C69343364C} => pcalua.exe -a "C:\Users\Shayla Potter\Desktop\OOo_3.3.0_Win_x86_install-wJRE_en-US.exe" -d "C:\Program Files\OpenOffice.org 3\program"
Task: {46FFC801-6837-49F6-8C1D-B04A4BAD8186} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-17] (Google Inc.)
Task: {49375187-C007-489A-96FD-A4331B62CAA7} - System32\Tasks\{C8563973-8E65-4A6A-BD02-D5B9A3C53F34} => pcalua.exe -a "C:\Users\Shayla Potter\Downloads\DesignPro5_4_Limited.exe" -d "C:\Program Files\Mozilla Firefox"
Task: {51B45166-C42C-4D32-BEEE-57D03E6E90B2} - System32\Tasks\{A4F70E4C-DCD9-4BD1-9A74-05EC7CAE49FC} => pcalua.exe -a C:\Windows\UninstallWSST.exe -c C:\Windows\UninstallLog0.log
Task: {54C60829-63CA-4F9F-9EC5-6D8404816914} - System32\Tasks\{EAFD04C2-A123-4CFF-B1F3-9CB4BE8C264A} => pcalua.exe -a "C:\Users\Shayla Potter\AppData\Roaming\Juniper Networks\Setup Client\JuniperSetupClientOCX.exe" -d "C:\Users\Shayla Potter\AppData\Roaming\Juniper Networks\Setup Client"
Task: {54CABFE2-787C-42EF-B335-0C6CDC2F147B} - System32\Tasks\{3C8083DF-4F53-4A31-A3EB-F969F7824170} => pcalua.exe -a "C:\Users\Shayla Potter\AppData\Local\Temp\Temp1_SolveigMM_AVI_Trimmer_1_6.zip\SolveigMM AVI Trimmer 1.6.1004.1.exe"
Task: {54F403D9-FC9A-4DAB-B396-3AD998C41E44} - System32\Tasks\{50958F2E-F646-4D8D-8E98-15E6B196B038} => pcalua.exe -a "E:\Setup\SmartSound\SmartSound Pinnacle Music.exe" -d E:\Setup\SmartSound
Task: {6EB47A84-2857-47AD-B276-6018ABEBF134} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Shayla Potter => C:\Program Files\Windows Calendar\wincal.exe [2009-04-11] (Microsoft Corporation)
Task: {741DFBC8-7F9B-4971-9F65-67D1F1913E6B} - System32\Tasks\{FDA6F372-7FB8-441A-8819-BE9BD048413C} => pcalua.exe -a C:\Users\Mason\Downloads\tremulous-gpp1-installer.exe -d "C:\Program Files\Mozilla Firefox"
Task: {75BF9F2D-C582-441B-B90E-5C38A5A3A42A} - System32\Tasks\{ED4D5BE0-EA6C-4C9B-B997-5EC5FD4D0293} => pcalua.exe -a C:\Windows\system32\spool\drivers\w32x86\3\LXBKUN5C.EXE -c -dLexmark X1100 Series
Task: {7C0B4593-099D-4250-B068-34E23B7E8F2C} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - John => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation)
Task: {8F1CAA9C-3433-4988-A755-A090D6A4A0CA} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15] (Adobe Systems Incorporated)
Task: {A2426F58-A4A4-4B9B-8C0F-4EDC3D08DD4A} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {A48BE931-597A-4DAB-A4E1-09FA0A3E562C} - System32\Tasks\{C02B8D0C-1162-40AF-BE6C-63EC2AC5F650} => pcalua.exe -a "C:\Users\Shayla Potter\AppData\Local\Temp\Temp1_NokiaFREE_v310_Nokia_unlock_codes_calculator.zip\NokiaFREE_v310_Setup.exe"
Task: {A5FDC1D4-062A-4D85-9118-1BAA915FC980} - System32\Tasks\{41C22683-681B-47FF-9397-8FD2479D50AA} => pcalua.exe -a "C:\Remote Programs\Cradle of Rome\GPlrLanc.exe" -c -LOpCode 2 /RemoveContent cid=554750;name=Cradle of Rome;dir=C:\Remote Programs\Cradle of Rome\;prvid=143;cmdid=1;prvdir=Default
Task: {AA406F1B-464D-453A-92EA-EE7034CBE763} - System32\Tasks\Microsoft\Support\Microsoft Fix it Center\ConfigExec => Rundll32.exe "C:\Program Files\Microsoft Fix it Center\MatsApi.dll",RunCollectConfigurationInfo
Task: {B21A0D53-D398-4DC4-9FD5-9D4D3982566C} - System32\Tasks\ASC6_PerformanceMonitor => C:\Program Files\IObit\Advanced SystemCare 6\Monitor.exe
Task: {B8FECB13-473F-421C-AB70-E4CA7AB02702} - System32\Tasks\Google Software Updater => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-09-06] (Google)
Task: {C44F92AC-53E6-4D47-BCD6-1A24D8DD3F74} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1260561122-373576474-2963483527-1005 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {C4D40DC6-1BE5-4C0F-93DF-D826422DBBE3} - System32\Tasks\ASC6_AutoClean => C:\Program Files\IObit\Advanced SystemCare 6\AutoSweep.exe
Task: {CE0F358E-E5F4-4E85-A9BB-8FFF76342E62} - System32\Tasks\Microsoft\Support\Microsoft Fix it Center\MatSvc\DataUpload => Rundll32.exe "C:\Program Files\Microsoft Fix it Center\MatsApi.dll",RetryDataUpload
Task: {CE8D28C9-45E0-4C87-8CF0-3EBAA8282078} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1260561122-373576474-2963483527-1005 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.)
Task: {D15D7662-D7F0-4EC1-BAA9-43730788AB69} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-10-17] (Google Inc.)
Task: {D18E439B-CB86-4ABF-A540-D57FA4C67AE6} - System32\Tasks\Microsoft\Support\Microsoft Fix it Center\OSUpgrade => Rundll32.exe "C:\Program Files\Microsoft Fix it Center\MatsApi.dll",RunHandleOSUpgrade
Task: {DBA60EE5-FD45-4F8D-915B-63B7914576AB} - System32\Tasks\{D676CE09-B41A-4987-A399-30C5FD39FBD5} => pcalua.exe -a "E:\Setup\SmartSound\Quicktracks Installer.exe" -d E:\Setup\SmartSound
Task: {DC8A53C9-9AC3-4B83-9A73-2C60B51686DC} - System32\Tasks\{CC778C55-1B0F-45F6-8EDB-B61CF4D59627} => pcalua.exe -a C:\DELL\E-Center\UninstallTB.exe -d C:\Windows\system32
Task: {F3E8BD86-FB5F-48D0-97E0-3735989215EB} - System32\Tasks\{2204B856-631C-4373-A2EF-97C58CFBDAB7} => pcalua.exe -a "C:\Live! Cam\WCVista_1_11_01\VfwUpd.EXE" -d "C:\Live! Cam\WCVista_1_11_01"
Task: {FD573624-6E72-4FEF-9B56-71DF8A4F476F} - System32\Tasks\{77747B11-1225-42CF-B24A-54846703B0D7} => pcalua.exe -a C:\Windows\system32\javacpl.cpl -c Java
Task: {FE177C28-BD05-45B6-BA0D-BAF8FBDFCF07} - System32\Tasks\{086D66E6-23E3-4FA5-8CE0-046817135B3D} => pcalua.exe -a C:\Users\Mason\Desktop\dotnetfx3setup.exe -d C:\Users\Mason\Desktop
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Google Software Updater.job => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2007-12-07 13:59 - 2006-10-06 07:06 - 00045056 _____ () C:\Windows\System32\DLPRMON.DLL
2007-12-07 13:59 - 2006-10-06 07:24 - 00016384 _____ () C:\Program Files\Dell PC Fax\DlCtrStr.dll
2007-12-07 13:59 - 2006-10-06 07:04 - 00032768 _____ () C:\Program Files\Dell PC Fax\ipcmt.dll
2009-06-29 10:22 - 2009-06-29 10:23 - 00051716 _____ () C:\Windows\System32\pdf995mon.dll
2007-12-07 14:04 - 2006-10-20 00:33 - 00117760 _____ () C:\Windows\system32\spool\PRTPROCS\W32X86\dlcxdrpp.dll
2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-08-14 16:19 - 2013-08-14 16:19 - 00039056 _____ () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
2006-11-05 10:28 - 2006-11-05 10:28 - 04587520 ____R () C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\ROXIPP41.dll
2013-07-10 18:57 - 2009-10-07 15:42 - 00061440 ____N () C:\Windows\system32\wintab32.dll
2007-11-21 11:21 - 2010-06-22 16:47 - 00034816 _____ () C:\Program Files\Google\Google Desktop Search\gzlib.dll
2007-12-07 14:00 - 2007-01-12 11:57 - 00292336 _____ () C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
2007-12-07 14:00 - 2006-08-08 14:54 - 00278528 _____ () C:\Program Files\Dell Photo AIO Printer 926\dlcxscw.dll
2007-12-07 14:00 - 2006-09-06 05:13 - 00073728 _____ () C:\Program Files\Dell Photo AIO Printer 926\dlcxcfg.dll
2007-12-07 14:00 - 2006-11-03 17:04 - 00304008 _____ () C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
2013-11-14 19:48 - 2013-11-14 19:48 - 01861968 _____ () C:\Program Files\DivX\DivX Update\DivXUpdate.exe
2013-11-14 19:49 - 2013-11-14 19:49 - 00100688 _____ () C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
2012-06-26 14:11 - 2012-06-26 14:11 - 02302040 _____ () C:\Users\Shayla Potter\Desktop\Kierans folder\Nokia PC Suite 7\QtCore4.dll
2012-06-26 14:11 - 2012-06-26 14:11 - 08197208 _____ () C:\Users\Shayla Potter\Desktop\Kierans folder\Nokia PC Suite 7\QtGui4.dll
2012-06-26 14:11 - 2012-06-26 14:11 - 00345688 _____ () C:\Users\Shayla Potter\Desktop\Kierans folder\Nokia PC Suite 7\QtXml4.dll
2012-06-26 14:10 - 2012-06-26 14:10 - 00202328 _____ () C:\Users\Shayla Potter\Desktop\Kierans folder\Nokia PC Suite 7\imageformats\qjpeg4.dll
2012-06-26 14:10 - 2012-06-26 14:10 - 00027736 _____ () C:\Users\Shayla Potter\Desktop\Kierans folder\Nokia PC Suite 7\imageformats\qsvg4.dll
2012-06-26 14:11 - 2012-06-26 14:11 - 00282200 _____ () C:\Users\Shayla Potter\Desktop\Kierans folder\Nokia PC Suite 7\QtSvg4.dll
2013-09-28 20:14 - 2013-09-28 20:14 - 03369922 _____ () C:\Program Files\NETGEAR Genie\bin\icuin51.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00544817 _____ () C:\Program Files\NETGEAR Genie\bin\libgcc_s_dw2-1.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00989805 _____ () C:\Program Files\NETGEAR Genie\bin\libstdc++-6.dll
2013-09-28 20:14 - 2013-09-28 20:14 - 01978690 _____ () C:\Program Files\NETGEAR Genie\bin\icuuc51.dll
2013-09-28 20:14 - 2013-09-28 20:14 - 22378434 _____ () C:\Program Files\NETGEAR Genie\bin\icudt51.dll
2013-09-28 20:14 - 2013-09-28 20:14 - 01233408 _____ () C:\Program Files\NETGEAR Genie\bin\platforms\qwindows.dll
2015-01-09 01:40 - 2015-01-09 01:40 - 00640000 _____ () C:\Program Files\NETGEAR Genie\bin\Genie.dll
2014-12-19 01:03 - 2014-12-19 01:03 - 01686016 _____ () C:\Program Files\NETGEAR Genie\bin\SvtNetworkTool.dll
2015-01-09 01:01 - 2015-01-09 01:01 - 00192512 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_Airprint.dll
2014-11-05 02:37 - 2014-11-05 02:37 - 00632832 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_Internet.dll
2015-01-09 01:03 - 2015-01-09 01:03 - 06477824 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_Map.dll
2014-06-29 20:55 - 2014-06-29 20:55 - 00068608 _____ () C:\Program Files\NETGEAR Genie\bin\QRCode.dll
2014-06-29 21:05 - 2014-06-29 21:05 - 01183232 _____ () C:\Program Files\NETGEAR Genie\bin\qwt.dll
2015-01-07 20:57 - 2015-01-07 20:57 - 02493952 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_MyMedia.dll
2012-10-15 15:27 - 2012-10-15 15:27 - 00111616 _____ () C:\Program Files\NETGEAR Genie\bin\libvlc.dll
2012-10-15 15:28 - 2012-10-15 15:28 - 02286592 _____ () C:\Program Files\NETGEAR Genie\bin\libvlccore.dll
2014-12-05 00:32 - 2014-12-05 00:32 - 01056768 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_NetworkProblem.dll
2014-09-11 03:39 - 2014-09-11 03:39 - 00144896 _____ () C:\Program Files\NETGEAR Genie\bin\DragonNetTool.dll
2015-01-09 01:03 - 2015-01-09 01:03 - 01195008 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_ParentalControl.dll
2015-01-14 00:45 - 2015-01-14 00:45 - 10388480 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_Resource.dll
2015-01-14 22:04 - 2015-01-14 22:04 - 02545664 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_RouterConfiguration.dll
2014-12-18 02:49 - 2014-12-18 02:49 - 00177152 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_Statistics.dll
2014-12-05 00:35 - 2014-12-05 00:35 - 00890368 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_Ui.dll
2014-11-05 03:00 - 2014-11-05 03:00 - 00435712 _____ () C:\Program Files\NETGEAR Genie\bin\GeniePlugin_Wireless.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00051200 _____ () C:\Program Files\NETGEAR Genie\bin\imageformats\qgif.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00052224 _____ () C:\Program Files\NETGEAR Genie\bin\imageformats\qico.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00261120 _____ () C:\Program Files\NETGEAR Genie\bin\imageformats\qjpeg.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00046080 _____ () C:\Program Files\NETGEAR Genie\bin\imageformats\qsvg.dll
2014-06-29 20:55 - 2014-06-29 20:55 - 00081408 _____ () C:\Program Files\NETGEAR Genie\bin\DiagnosePlugin.dll
2014-11-03 03:23 - 2014-11-03 03:23 - 00143360 _____ () C:\Program Files\NETGEAR Genie\bin\DiagnoseDll.dll
2014-06-18 21:22 - 2014-06-18 21:22 - 02177405 _____ () C:\Program Files\NETGEAR Genie\bin\drivers\libntgr_api.dll
2014-09-04 01:00 - 2014-09-04 01:00 - 00072192 _____ () C:\Program Files\NETGEAR Genie\bin\SVTUtils.dll
2014-09-04 01:00 - 2014-09-04 01:00 - 00074240 _____ () C:\Program Files\NETGEAR Genie\bin\NetcardApi.dll
2014-09-04 01:00 - 2014-09-04 01:00 - 00136704 _____ () C:\Program Files\NETGEAR Genie\bin\airprintdll.dll
2012-10-15 15:28 - 2012-10-15 15:28 - 00219648 _____ () C:\Program Files\NETGEAR Genie\bin\plugins\access\libdshow_plugin.dll
2012-10-15 15:28 - 2012-10-15 15:28 - 00049664 _____ () C:\Program Files\NETGEAR Genie\bin\plugins\audio_output\libaout_directx_plugin.dll
2012-10-15 15:28 - 2012-10-15 15:28 - 00051200 _____ () C:\Program Files\NETGEAR Genie\bin\plugins\audio_output\libwaveout_plugin.dll
2012-10-15 15:28 - 2012-10-15 15:28 - 00070144 _____ () C:\Program Files\NETGEAR Genie\bin\plugins\video_output\libdirectx_plugin.dll
2013-09-28 20:13 - 2013-09-28 20:13 - 00040960 _____ () C:\Program Files\NETGEAR Genie\bin\printsupport\windowsprintersupport.dll
2010-01-18 23:58 - 2007-01-25 13:25 - 00117248 _____ () C:\Windows\system32\spool\DRIVERS\W32X86\3\hpzpi4wm.DLL
2014-11-05 02:59 - 2014-11-05 02:59 - 00642048 _____ () C:\Program Files\NETGEAR Genie\bin\InnerPlugin_Update.dll
2014-11-05 03:01 - 2014-11-05 03:01 - 00458752 _____ () C:\Program Files\NETGEAR Genie\bin\InnerPlugin_WirelessExport.dll
2014-06-29 21:33 - 2014-06-29 21:33 - 00046080 _____ () C:\Program Files\NETGEAR Genie\bin\WSetupApiPlugin.dll
2014-09-04 01:00 - 2014-09-04 01:00 - 00066560 _____ () C:\Program Files\NETGEAR Genie\bin\WSetupDll.dll
2015-05-27 13:50 - 2015-05-27 13:50 - 00043008 _____ () c:\Users\Shayla Potter\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp5tsd_j.dll
2015-03-04 16:45 - 2015-03-04 16:45 - 00750080 _____ () C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2015-03-04 16:45 - 2015-03-04 16:45 - 00047616 _____ () C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\libEGL.dll
2015-03-04 16:45 - 2015-03-04 16:45 - 00865280 _____ () C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
2015-03-04 16:45 - 2015-03-04 16:45 - 00200704 _____ () C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
2007-04-03 16:58 - 2007-04-03 16:58 - 00020572 _____ () C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
2007-04-03 16:58 - 2007-04-03 16:58 - 00802901 _____ () C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\hotspot\jvm.dll
2007-04-03 16:58 - 2007-04-03 16:58 - 00028776 _____ () C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\hpi.dll
2007-04-03 16:58 - 2007-04-03 16:58 - 00053342 _____ () C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\verify.dll
2007-04-03 16:58 - 2007-04-03 16:58 - 00094308 _____ () C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\java.dll
2007-04-03 16:58 - 2007-04-03 16:58 - 00053349 _____ () C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\zip.dll
2007-04-03 16:58 - 2007-04-03 16:58 - 00032864 _____ () C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\net.dll
2004-08-20 07:02 - 2004-08-20 07:02 - 00102400 _____ () C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\PMLJNI.dll
2005-02-03 11:31 - 2005-02-03 11:31 - 00032768 _____ () C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\compJNI.dll
2014-12-14 21:27 - 2014-12-14 21:27 - 00105216 _____ () C:\Program Files\NETGEAR Genie\bin\genie2_tray.exe
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NTRSupport => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-1260561122-373576474-2963483527-1005\...\100sexlinks.com -> 100sexlinks.com
 
There are 4788 more restricted sites.
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1260561122-373576474-2963483527-1005\Control Panel\Desktop\\Wallpaper -> C:\Users\Shayla Potter\Pictures\pics fpr screen saver\6toes.jpg
DNS Servers: 192.168.1.1
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe
FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe
FirewallRules: [{3A9BE981-441E-4189-BACF-E5819B128C8A}] => (Allow) LPort=5500
FirewallRules: [{58B87AC9-0464-412B-9CCB-AC4BA07A473A}] => (Allow) LPort=5800
FirewallRules: [{320054C4-DEB8-4917-8C4B-A1733FCF603B}] => (Allow) LPort=5900
FirewallRules: [TCP Query User{24D4599C-C072-4D0B-9FBD-0E458620D486}C:\program files\internet explorer\iexplore.exe] => (Allow) C:\program files\internet explorer\iexplore.exe
FirewallRules: [UDP Query User{3186032E-8748-4002-ACBF-8857533B79D8}C:\program files\internet explorer\iexplore.exe] => (Allow) C:\program files\internet explorer\iexplore.exe
FirewallRules: [{5D127D00-8459-4860-B615-586AD6CA3746}] => (Allow) C:\Program Files\Dell Photo AIO Printer 926\dlcxaiox.exe
FirewallRules: [{77E7AB39-D552-40FC-9E32-A45840AB6CEA}] => (Allow) C:\Program Files\Dell Photo AIO Printer 926\dlcxaiox.exe
FirewallRules: [{A87FD550-32E3-4F0F-BC1C-47B55B3B3B4B}] => (Allow) LPort=135
FirewallRules: [{0AD58039-680E-490D-BF66-34028BF77850}] => (Allow) LPort=5000
FirewallRules: [{C1B08FC5-7838-49CE-BB00-D0C0AB9DF7AD}] => (Allow) LPort=5001
FirewallRules: [{29CE1D4B-0B59-4C54-9653-DDAFFB740CB2}] => (Allow) LPort=5002
FirewallRules: [{706662D2-F4C6-47AB-AEFC-9736034DFA6F}] => (Allow) LPort=5003
FirewallRules: [{13A4D1AF-FFDD-42BC-8AE4-60E8AE0CF8A8}] => (Allow) LPort=5004
FirewallRules: [{4E2B0263-67A2-4470-A3B2-67ED7D8BF6CB}] => (Allow) LPort=5005
FirewallRules: [{B4D621D2-7AFB-4E79-8A76-B36A2D02A61B}] => (Allow) LPort=5006
FirewallRules: [{5CE508DF-71C7-4616-8441-3FBFA3AD1313}] => (Allow) LPort=5007
FirewallRules: [{3E2F141C-71B3-4AF5-91BE-7F72E308ECB7}] => (Allow) LPort=5008
FirewallRules: [{0D3DEC16-FC11-4A90-AED0-20DE7D0C036D}] => (Allow) LPort=5009
FirewallRules: [{25DF0357-1CFA-4BBE-8AD2-918D5F501D35}] => (Allow) LPort=5010
FirewallRules: [{A99E3085-ACB1-4DDB-A2D9-2685FF10540A}] => (Allow) LPort=5011
FirewallRules: [{53DEC965-B95E-426C-A0DE-4BE9EC11BB7F}] => (Allow) LPort=5012
FirewallRules: [{68BC4BB3-EDAF-4989-80FF-F506E718F13E}] => (Allow) LPort=5013
FirewallRules: [{BEE7137B-19A3-4AD1-B974-4E131413DC63}] => (Allow) LPort=5014
FirewallRules: [{3E356141-4DC0-416B-9510-017A0D9FB53C}] => (Allow) LPort=5015
FirewallRules: [{FA2BD1D6-96C4-46DA-9931-A52F4F0852DC}] => (Allow) LPort=5016
FirewallRules: [{BCDC9A8B-9D78-47B7-A756-2F26593BF6C5}] => (Allow) LPort=5017
FirewallRules: [{001762D0-4C4E-4A25-A61C-9AAD6D7C0AB0}] => (Allow) LPort=5018
FirewallRules: [{C5FFE75E-3AD0-4B0B-9AB2-0146F4F6E223}] => (Allow) LPort=5019
FirewallRules: [{9ED89B40-CA25-4E41-AFDD-3B23D7598C5E}] => (Allow) LPort=5020
FirewallRules: [TCP Query User{03377708-7AA7-4AFB-93E0-884D368DA5D4}C:\program files\internet explorer\iexplore.exe] => (Allow) C:\program files\internet explorer\iexplore.exe
FirewallRules: [UDP Query User{FCA6B8BB-D1B1-43BF-BA25-EC5E7F2FD8BF}C:\program files\internet explorer\iexplore.exe] => (Allow) C:\program files\internet explorer\iexplore.exe
FirewallRules: [TCP Query User{8D7C38D2-21C3-46D9-9661-A82E89AFBE70}C:\program files\hewlett-packard\toolbox\jre\bin\javaw.exe] => (Allow) C:\program files\hewlett-packard\toolbox\jre\bin\javaw.exe
FirewallRules: [UDP Query User{2A5BC021-2D22-4643-82FE-DCD281942E2F}C:\program files\hewlett-packard\toolbox\jre\bin\javaw.exe] => (Allow) C:\program files\hewlett-packard\toolbox\jre\bin\javaw.exe
FirewallRules: [TCP Query User{BC94B49A-88ED-4BBA-9A50-62021F9065E7}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{138757B8-CB9B-4030-8527-B3CD9959604F}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{B3126AE1-D2C2-4A1D-BE57-D46BB2E7AEE7}] => (Allow) C:\Program Files\RealVNC\VNC4\vncviewer.exe
FirewallRules: [{50B98344-50AC-4A0C-ADEE-1A4E26C88D3E}] => (Allow) C:\Program Files\RealVNC\VNC4\vncviewer.exe
FirewallRules: [TCP Query User{A367A5EE-4A01-431B-AD71-5E30E127811E}C:\program files\yahoo!\messenger\yahoomessenger.exe] => (Allow) C:\program files\yahoo!\messenger\yahoomessenger.exe
FirewallRules: [UDP Query User{2AA150C8-3FF6-41C0-8A4A-B50B6C9C8854}C:\program files\yahoo!\messenger\yahoomessenger.exe] => (Allow) C:\program files\yahoo!\messenger\yahoomessenger.exe
FirewallRules: [{1BE1B989-8549-489D-91EB-5DD7EDCC87ED}] => (Allow) C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe
FirewallRules: [{66411175-1426-41E1-93AA-64B83B25236E}] => (Allow) C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe
FirewallRules: [{900F444D-979D-477E-B4BE-DB59F94F95DA}] => (Allow) LPort=5225
FirewallRules: [{72376B2E-0624-439C-A013-EB2EBD676A54}] => (Allow) LPort=5225
FirewallRules: [TCP Query User{0953E3C5-8959-49AF-9DBE-BE59A3050DB6}C:\program files\hewlett-packard\toolbox\jre\bin\javaw.exe] => (Allow) C:\program files\hewlett-packard\toolbox\jre\bin\javaw.exe
FirewallRules: [UDP Query User{4B0FF1CB-1D13-4732-8A72-E80B0EF9AC57}C:\program files\hewlett-packard\toolbox\jre\bin\javaw.exe] => (Allow) C:\program files\hewlett-packard\toolbox\jre\bin\javaw.exe
FirewallRules: [TCP Query User{77666501-3BDC-45D9-B0CE-69F1FB5742BC}C:\program files\java\jre1.6.0\bin\java.exe] => (Block) C:\program files\java\jre1.6.0\bin\java.exe
FirewallRules: [UDP Query User{B17062E3-2543-4DB6-893F-C9512144B9E8}C:\program files\java\jre1.6.0\bin\java.exe] => (Block) C:\program files\java\jre1.6.0\bin\java.exe
FirewallRules: [{ECA43E07-17DD-4C05-B171-746120C337E0}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{FA47773A-8DF9-4057-A4DB-E6A15E6E1AFA}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7895B3EC-DEE2-4A4F-B71F-68DD7B2A7980}] => (Allow) C:\Windows\System32\dlcxcoms.exe
FirewallRules: [{4BE5E731-F4D1-4982-A9E4-CDBBC1AE6ED6}] => (Allow) C:\Windows\System32\dlcxcoms.exe
FirewallRules: [{16620345-D660-4F83-A157-D6A550481CAA}] => (Allow) C:\Program Files\Yahoo!\Messenger\YServer.exe
FirewallRules: [{B7C507E3-79E6-4FB5-82D5-3D12B43976DF}] => (Allow) C:\Program Files\Yahoo!\Messenger\YServer.exe
FirewallRules: [{D47F953B-0260-463C-BCF2-2AC9803E3C10}] => (Allow) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{E2996B45-E2E6-46ED-BD32-20811C1E172A}] => (Allow) C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{CD116ACA-3788-47AD-B827-3761FAED4DB8}] => (Allow) C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe
FirewallRules: [{B6810223-1757-4AAB-B794-3B92F7825FC9}] => (Allow) C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe
FirewallRules: [{5A019ABC-883E-47E4-BA41-3F3CE3A42EC3}] => (Allow) C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
FirewallRules: [{6116FC38-AD5D-4A39-9ED6-EF6606412FCD}] => (Allow) C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
FirewallRules: [TCP Query User{0CFA288E-2F72-49CB-ADB4-C77FD4ACA2E8}C:\windows\system32\notepad.exe] => (Allow) C:\windows\system32\notepad.exe
FirewallRules: [UDP Query User{A9CFD4DA-6A14-4EE3-8291-6FF544161FC3}C:\windows\system32\notepad.exe] => (Allow) C:\windows\system32\notepad.exe
FirewallRules: [TCP Query User{E4467E63-334B-4AE8-BF25-7BEE8235CA9A}C:\program files\google\google earth\plugin\geplugin.exe] => (Block) C:\program files\google\google earth\plugin\geplugin.exe
FirewallRules: [UDP Query User{DF4A6181-866D-43BF-9FC7-577CA8AF19D7}C:\program files\google\google earth\plugin\geplugin.exe] => (Block) C:\program files\google\google earth\plugin\geplugin.exe
FirewallRules: [{B0888647-0174-4BDE-8B14-7D7E62DF5344}] => (Allow) LPort=80
FirewallRules: [{288FEDC6-0B73-40CF-AB4B-B9A013F91CB8}] => (Allow) LPort=80
FirewallRules: [{3ADB8FE2-EC6A-4440-A2B7-DFFA09FD84DE}] => (Allow) LPort=80
FirewallRules: [TCP Query User{DD49B455-91A7-447A-A147-86754DB4AEBF}C:\program files\team17\worms armageddon\wa.exe] => (Allow) C:\program files\team17\worms armageddon\wa.exe
FirewallRules: [UDP Query User{C812A600-96BB-4D24-88CA-E1D63224E64B}C:\program files\team17\worms armageddon\wa.exe] => (Allow) C:\program files\team17\worms armageddon\wa.exe
FirewallRules: [{4C72611F-769D-483D-AD1B-DA52358E9DD7}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\RM.exe
FirewallRules: [{7FCBF118-5344-41FC-93D9-4FD35E1BC8F9}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\RM.exe
FirewallRules: [{AF036FE1-D9A2-42DA-92AE-4BF5D3CD2DAD}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe
FirewallRules: [{4B6D640A-2938-4EB4-8FCB-617C179F5E0E}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe
FirewallRules: [{A3065E18-DD4B-407B-9CF5-E1664CDACF22}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\RM.exe
FirewallRules: [{0AA081F3-B548-4787-BAC3-457C6E3340ED}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\RM.exe
FirewallRules: [{8E8CA268-7C0A-4B7F-9DE3-D9F14EF177CE}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe
FirewallRules: [{96DB8F73-6CAD-4F86-B9A0-1C5EDE61B83F}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe
FirewallRules: [{9D50495F-2108-4648-BCA0-03BB03ED3E21}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe
FirewallRules: [{6970A4D6-F35B-44FC-A15E-A094E203ABFF}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe
FirewallRules: [{EEA71786-1D86-4154-ACD7-7A41581CC210}] => (Allow) C:\Program Files\Pinnacle\Shared Files\Programs\MediaManager\PMSManager.exe
FirewallRules: [{B3C5C46C-9762-44B1-849B-C8B6DBEFF408}] => (Allow) C:\Program Files\Pinnacle\Shared Files\Programs\MediaManager\PMSManager.exe
FirewallRules: [{6E1B3C88-641E-4168-A2AF-93FC222BE9DB}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\umi.exe
FirewallRules: [{9A5210EB-2829-4809-A21B-2A9FF6027EAE}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\umi.exe
FirewallRules: [TCP Query User{92E11C77-8470-4748-BCCE-0E850A28E516}C:\program files\pinnacle\shared files\programs\mediamanager\pmsmanager.exe] => (Allow) C:\program files\pinnacle\shared files\programs\mediamanager\pmsmanager.exe
FirewallRules: [UDP Query User{FAFC9B9B-A91F-464E-B2BE-862D8C57A791}C:\program files\pinnacle\shared files\programs\mediamanager\pmsmanager.exe] => (Allow) C:\program files\pinnacle\shared files\programs\mediamanager\pmsmanager.exe
FirewallRules: [TCP Query User{CBB45A30-67A4-4BE3-8B2F-BEB07056CB2A}C:\program files\videoviewer\videoviewer.exe] => (Block) C:\program files\videoviewer\videoviewer.exe
FirewallRules: [UDP Query User{23F744A0-717C-405A-B48E-BC34D0170158}C:\program files\videoviewer\videoviewer.exe] => (Block) C:\program files\videoviewer\videoviewer.exe
FirewallRules: [TCP Query User{C44B8311-88EE-43F3-8EAF-886F27BE8F91}C:\program files\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files\netgear genie\bin\netgeargenie.exe
FirewallRules: [UDP Query User{29C0C165-6753-43C3-AC94-6F458D587E9F}C:\program files\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files\netgear genie\bin\netgeargenie.exe
FirewallRules: [TCP Query User{300522B8-B9B1-4DBF-B1F8-55AA486C3244}C:\program files\netgear genie\bin\netgeargenie.exe] => (Block) C:\program files\netgear genie\bin\netgeargenie.exe
FirewallRules: [UDP Query User{5D00D852-6AFD-487E-82A7-1E83E1F18701}C:\program files\netgear genie\bin\netgeargenie.exe] => (Block) C:\program files\netgear genie\bin\netgeargenie.exe
FirewallRules: [TCP Query User{720FB80F-2E0D-4D90-A249-D7CF054DE729}C:\program files\google\chrome\application\chrome.exe] => (Block) C:\program files\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{7CB2C5FE-D42A-4A87-883C-11E9CEFF2C4D}C:\program files\google\chrome\application\chrome.exe] => (Block) C:\program files\google\chrome\application\chrome.exe
FirewallRules: [TCP Query User{CC3A7C5D-5267-43DE-8CE5-8A2567DEF4B5}C:\program files\mozilla firefox\plugin-container.exe] => (Allow) C:\program files\mozilla firefox\plugin-container.exe
FirewallRules: [UDP Query User{0743C5E9-351F-41CB-B430-7014DF0F5136}C:\program files\mozilla firefox\plugin-container.exe] => (Allow) C:\program files\mozilla firefox\plugin-container.exe
FirewallRules: [{A104D517-3E9B-4F61-BF2C-82AC188FB153}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{960A0CF4-CF46-4C96-A8E0-5B3B9AC97E26}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{44399A32-BA2F-4FC0-BC70-8A0E8FD0FBF7}] => (Allow) C:\Program Files\iWin Games\iWinGames.exe
FirewallRules: [{A489724F-5A4A-4FA7-8C44-D41D8032F469}] => (Allow) C:\Program Files\iWin Games\iWinGames.exe
FirewallRules: [{5CB2FD23-1816-4740-BBAB-D416D55EB5DE}] => (Allow) C:\Program Files\iWin Games\WebUpdater.exe
FirewallRules: [{ED69E852-B26F-479B-8E00-B98B5044B0FC}] => (Allow) C:\Program Files\iWin Games\WebUpdater.exe
FirewallRules: [{AA15602D-9D18-4CB5-9762-720B79C11F61}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe
FirewallRules: [{87026E34-24B2-459A-8669-393E8EBAFF45}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe
FirewallRules: [TCP Query User{B8DFEA0F-4D12-4138-AFB3-A2419BD5D474}C:\program files\tmnationsforever\tmforever.exe] => (Allow) C:\program files\tmnationsforever\tmforever.exe
FirewallRules: [UDP Query User{C9B631DF-944E-4873-91F6-B28CACD9C6C3}C:\program files\tmnationsforever\tmforever.exe] => (Allow) C:\program files\tmnationsforever\tmforever.exe
FirewallRules: [{170550A7-709A-47E0-BB98-DB67EDF19D8E}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\umi.exe
FirewallRules: [{6395D1B7-EC14-4ED0-8018-4F6FB8669AB6}] => (Allow) C:\Program Files\Pinnacle\Studio 10\programs\umi.exe
FirewallRules: [{614328DD-1303-4FAE-919F-520C8B373F5E}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{3EE83CD5-60FC-4928-B36D-63FB3E017386}] => (Allow) C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{6F11EE63-D815-421B-9D6A-48764294CF02}] => (Allow) C:\Users\Shayla Potter\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{1ED680D5-CD81-4090-B014-002305E1CE5C}] => (Allow) C:\Users\Shayla Potter\Downloads\VideoPerformerSetup.exe
FirewallRules: [{D978B5B8-F77F-4D65-82A7-2BEC012FB9A4}] => (Allow) C:\Users\Shayla Potter\Downloads\VideoPerformerSetup.exe
FirewallRules: [{F0FD8D67-C74D-4018-8745-55FCD6F11674}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [TCP Query User{023FD972-61BE-42E2-989C-B7672CE6E1D0}G:\simplisafewizard.exe] => (Allow) G:\simplisafewizard.exe
FirewallRules: [UDP Query User{10E89B64-ADCD-4ADE-A595-15A1D55E9FEF}G:\simplisafewizard.exe] => (Allow) G:\simplisafewizard.exe
FirewallRules: [{7F1AE3F1-A8C4-47E9-8784-FEF4509A0F3D}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (05/28/2015 03:09:46 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (05/28/2015 03:08:48 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application Explorer.EXE, version 6.0.6002.18005, time stamp 0x49e01da5, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code 0xc0000005, fault offset 0x8d9bf998,
process id 0xdfc, application start time 0xExplorer.EXE0.
 
Error: (05/28/2015 00:33:27 AM) (Source: MatSvc) (EventID: 3) (User: )
Description: The MATS service encountered a web service failure. hr=0x80072EFE
 
Error: (05/28/2015 00:31:25 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   19 14.1.168.192.in-addr.arpa. PTR BNSS-Leased.local.
 
Error: (05/28/2015 00:31:23 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.1.14:5353   21 14.1.168.192.in-addr.arpa. PTR BNSS-Leased-2.local.
 
Error: (05/28/2015 00:28:31 AM) (Source: MatSvc) (EventID: 3) (User: )
Description: The MATS service encountered a web service failure. hr=0x80072EFE
 
Error: (05/27/2015 08:22:24 PM) (Source: MatSvc) (EventID: 3) (User: )
Description: The MATS service encountered a web service failure. hr=0x80072EFE
 
Error: (05/27/2015 08:17:31 PM) (Source: MatSvc) (EventID: 3) (User: )
Description: The MATS service encountered a web service failure. hr=0x80072EFE
 
Error: (05/27/2015 03:37:10 PM) (Source: MatSvc) (EventID: 3) (User: )
Description: The MATS service encountered a web service failure. hr=0x80072EFE
 
Error: (05/27/2015 03:32:12 PM) (Source: MatSvc) (EventID: 3) (User: )
Description: The MATS service encountered a web service failure. hr=0x80072EFE
 
 
System errors:
=============
Error: (05/28/2015 03:02:13 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: 0x80070103nVidia - Display - NVIDIA GeForce 6150SE nForce 430{1D38688E-F7C7-4448-8ED3-CF4D30DC746B}101
 
Error: (05/28/2015 00:31:14 AM) (Source: Dhcp) (EventID: 1002) (User: )
Description: The IP address lease 192.168.1.12 for the Network Card with network address 001AA06945F1 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
 
Error: (05/27/2015 00:33:11 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058
 
Error: (05/27/2015 00:33:11 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: WINBOND W55U01 USB%%1058
 
Error: (05/27/2015 00:31:38 PM) (Source: LSM) (EventID: 1048) (User: )
Description: Terminal Service start failed. The relevant status code was The configuration data for this product is corrupt. Contact your support personnel.
.
 
Error: (05/27/2015 03:03:55 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: 0x80070103nVidia - Display - NVIDIA GeForce 6150SE nForce 430{1D38688E-F7C7-4448-8ED3-CF4D30DC746B}101
 
Error: (05/26/2015 09:21:46 PM) (Source: Dhcp) (EventID: 1002) (User: )
Description: The IP address lease 192.168.1.14 for the Network Card with network address 001AA06945F1 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
 
Error: (05/26/2015 09:30:49 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: ServiceLayer1
 
Error: (05/26/2015 09:30:48 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: iPod Service1
 
Error: (05/26/2015 09:30:48 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Windows Media Player Network Sharing Service1300001Restart the service
 
 
Microsoft Office:
=========================
Error: (05/28/2015 03:09:46 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe
 
Error: (05/28/2015 03:08:48 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Explorer.EXE6.0.6002.1800549e01da5unknown0.0.0.000000000c00000058d9bf998dfc01d098adb17528b6
 
Error: (05/28/2015 00:33:27 AM) (Source: MatSvc) (EventID: 3) (User: )
Description: hr=0x80072EFEIDataUploadService::UploadResult
 
Error: (05/28/2015 00:31:25 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   19 14.1.168.192.in-addr.arpa. PTR BNSS-Leased.local.
 
Error: (05/28/2015 00:31:23 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.1.14:5353   21 14.1.168.192.in-addr.arpa. PTR BNSS-Leased-2.local.
 
Error: (05/28/2015 00:28:31 AM) (Source: MatSvc) (EventID: 3) (User: )
Description: hr=0x80072EFEIDataUploadService::UploadResult
 
Error: (05/27/2015 08:22:24 PM) (Source: MatSvc) (EventID: 3) (User: )
Description: hr=0x80072EFEIDataUploadService::UploadResult
 
Error: (05/27/2015 08:17:31 PM) (Source: MatSvc) (EventID: 3) (User: )
Description: hr=0x80072EFEIDataUploadService::UploadResult
 
Error: (05/27/2015 03:37:10 PM) (Source: MatSvc) (EventID: 3) (User: )
Description: hr=0x80072EFEIDataUploadService::UploadResult
 
Error: (05/27/2015 03:32:12 PM) (Source: MatSvc) (EventID: 3) (User: )
Description: hr=0x80072EFEIDataUploadService::UploadResult
 
 
CodeIntegrity Errors:
===================================
  Date: 2015-05-28 03:23:46.611
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-28 03:23:45.639
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-28 03:23:44.651
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-28 03:23:43.630
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-28 03:23:42.397
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-28 03:23:41.409
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-28 03:23:40.378
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-28 03:23:39.315
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-28 03:22:01.331
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-05-28 03:22:00.362
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\mwac.sys because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: AMD Athlon™ 64 X2 Dual Core Processor 4000+
Percentage of memory in use: 56%
Total physical RAM: 1981.76 MB
Available physical RAM: 854.08 MB
Total Pagefile: 5426.23 MB
Available Pagefile: 3474.97 MB
Total Virtual: 2047.88 MB
Available Virtual: 1912.68 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:222.78 GB) (Free:12.04 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (RECOVERY) (Fixed) (Total:10 GB) (Free:4.95 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 232.8 GB) (Disk ID: 08000000)
Partition 1: (Not Active) - (Size=47 MB) - (Type=DE)
Partition 2: (Not Active) - (Size=10 GB) - (Type=07 NTFS)
Partition 3: (Active) - (Size=222.8 GB) - (Type=07 NTFS)
 
==================== End of log ============================

  • 0

#12
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
You're welcome :)

A few items to fix, left overs.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Open notepad (Start =>All Programs => Accessories => Notepad).
Copy/Paste the contents of the code box below into Notepad.

start
CloseProcesses:
CreateRestorePoint:
C:\Users\Shayla Potter\Downloads\CouponPrinter.exe 
C:\Program Files\OpenDownloaspamnager\spnocrc.exe
C:\Users\Mason\Downloads\prismpsetup.exe 
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Application Updater\temp\~wtA147.tmp 
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
C:\Users\Shayla Potter\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp5tsd_j.dll
C:\Users\Shayla Potter\AppData\Local\Temp\Quarantine.exe
C:\Users\Shayla Potter\AppData\Local\Temp\sqlite3.dll
Emptytemp:
Click Format and ensure Wordwrap is unchecked.
Save as Fixlist.txt to your Desktop (Must be in this location)
Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.

Note: If the tool warns you about the version you're using being an outdated version please download and run the updated version.

Next

Download Security Check by screen317 from Here or Here
Save it to your Desktop.
Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
A Notepad document should open automatically called checkup.txt; please post the contents of that document.

NOTE: If SecurityCheck aborts and you get the following message: UNSUPPORTED OPERATING SYSTEM! ABORTED! try rebooting the system and then run SecurityCheck again.

Your next reply post to me
1- Fixlog.txt
2- Checkup.txt
  • 0

#13
crybaby

crybaby

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 175 posts

Hi. I have had a death in the family, and will not be able to continue with this process for a few days. May I ask that you please keep this thread open until I have a chance to resume? Thank you for your understanding. 


  • 0

#14
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,090 posts
This thread will remain open until your issue is resolved, and you feel your able to carry on.

I'm sorry for your loss.

Thanks
Joe :)
  • 0

#15
crybaby

crybaby

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 175 posts
Thank you. I appreciate that. I am continuing where we left off. I will post what you've requested soon.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP