Hi, having alot of problems with popups and the installation of crossbrowse, anyprotect, etc. Also, my Google Chrome disappeared. Appreciate any help. Here is my OTL log:
OTL logfile created on: 6/19/2015 11:48:02 PM - Run 5
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\jklm\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
7.80 Gb Total Physical Memory | 2.09 Gb Available Physical Memory | 26.80% Memory free
15.61 Gb Paging File | 7.65 Gb Available in Paging File | 49.02% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 1383.41 Gb Total Space | 1206.29 Gb Free Space | 87.20% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Drive Y: | 13.81 Gb Total Space | 5.55 Gb Free Space | 40.19% Space Free | Partition Type: NTFS
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - File not found --
PRC - [2015/06/19 23:37:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\jklm\Desktop\OTL.exe
PRC - [2015/06/19 23:01:41 | 000,157,696 | ---- | M] () -- C:\ProgramData\Msouflui\1.0.1.0\uawiemem.exe
PRC - [2015/06/19 23:01:08 | 000,147,456 | ---- | M] () -- C:\Users\jklm\AppData\Local\4C4C4544-1434754844-5610-8048-B7C04F445131\snsrA659.tmp
PRC - [2015/06/19 22:56:32 | 002,730,984 | ---- | M] (Time Lapse Solutions) -- C:\ProgramData\WBRYXRSt\xfrcCqRE.exe
PRC - [2015/06/19 22:56:31 | 000,817,965 | ---- | M] ( ) -- C:\Users\jklm\AppData\Roaming\4C4C4544-1434779849-5610-8048-B7C04F445131\vnspB0B4.tmp
PRC - [2015/06/19 22:55:58 | 000,603,648 | ---- | M] () -- C:\Program Files (x86)\version85IneedSpeed\b4IneedSpeedQ95.exe
PRC - [2015/06/19 22:54:56 | 001,383,504 | ---- | M] (Cinema_Plus-1.2V19.06) -- C:\Program Files (x86)\Cinema_Plus-1.2V19.06\ca281dfc-e383-4fa1-80fa-dc79c4d0c772-1-6.exe
PRC - [2015/06/19 22:53:46 | 001,570,896 | ---- | M] (Cinema_Plus-1.2V19.06) -- C:\Program Files (x86)\Cinema_Plus-1.2V19.06\ca281dfc-e383-4fa1-80fa-dc79c4d0c772-10.exe
PRC - [2015/06/19 09:55:46 | 003,319,976 | ---- | M] () -- C:\Users\jklm\AppData\Local\gmsd_us_005010007\upgmsd_us_005010007.exe
PRC - [2015/06/19 09:55:41 | 003,984,040 | ---- | M] () -- C:\Program Files (x86)\gmsd_us_005010007\gmsd_us_005010007.exe
PRC - [2015/06/18 21:06:42 | 002,422,784 | ---- | M] () -- C:\Program Files (x86)\Smwyyntm1ndi1zdz\nwjkm2z2y3mwbdd.exe
PRC - [2015/06/18 21:04:38 | 000,710,144 | ---- | M] () -- C:\Program Files (x86)\Umtayyznhndq1ntz\mwmyzjmzngu1mdy.exe
PRC - [2015/06/09 03:50:34 | 000,053,352 | ---- | M] (Games Bot Inc.) -- C:\Program Files (x86)\Games Bot\GamesBotSvc.exe
PRC - [2015/06/05 01:14:30 | 000,359,936 | ---- | M] () -- C:\Users\jklm\AppData\Local\4C4C4544-1434754703-5610-8048-B7C04F445131\bnsl9328.exe
PRC - [2015/05/28 10:06:16 | 001,240,096 | ---- | M] () -- C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe
PRC - [2015/04/22 05:00:56 | 000,311,912 | ---- | M] () -- C:\Program Files (x86)\Games Bot\GamesBot.exe
PRC - [2015/04/10 12:57:08 | 000,278,600 | ---- | M] (Infonaut) -- C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe
PRC - [2015/04/07 07:54:36 | 000,668,264 | ---- | M] (The Chromium Authors) -- C:\Users\jklm\AppData\Local\Games Bot\Explore\Explore.exe
PRC - [2015/02/25 08:32:16 | 001,200,656 | ---- | M] (Compete, Inc.) -- C:\Program Files (x86)\Consumer Input\InternetExplorer\dca-host.exe
PRC - [2015/02/17 04:00:10 | 000,270,368 | ---- | M] (SoftBrain Technologies Ltd.) -- C:\Users\jklm\AppData\Local\SmartWeb\SmartWebHelper.exe
PRC - [2015/02/17 04:00:06 | 000,557,088 | ---- | M] (SoftBrain Technologies Ltd.) -- C:\Users\jklm\AppData\Local\SmartWeb\SmartWebApp.exe
PRC - [2014/11/27 10:31:42 | 000,055,640 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe
PRC - [2014/11/27 09:04:42 | 000,997,728 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
PRC - [2014/11/27 09:04:18 | 000,407,904 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
PRC - [2014/11/27 04:34:18 | 001,513,752 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files (x86)\Citrix\Receiver\Receiver.exe
PRC - [2014/09/18 19:16:34 | 000,014,624 | ---- | M] (Intuit Inc.) -- C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
PRC - [2013/02/15 18:23:34 | 014,731,776 | ---- | M] (GARMIN Corp.) -- C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe
PRC - [2012/07/27 13:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/09/06 10:29:20 | 004,259,648 | ---- | M] (SoftThinks - Dell) -- C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
PRC - [2011/08/18 08:05:54 | 002,751,808 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
PRC - [2011/08/18 08:05:46 | 001,692,480 | ---- | M] (SoftThinks SAS) -- C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
PRC - [2011/08/01 10:56:48 | 000,460,096 | ---- | M] (SoftThinks - Dell) -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
PRC - [2010/11/17 08:35:40 | 001,440,240 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\Roxio Burn.exe
PRC - [2010/11/17 08:35:34 | 000,514,544 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
PRC - [2010/10/26 19:27:00 | 000,075,048 | ---- | M] (cyberlink) -- C:\Program Files (x86)\CyberLink\Shared files\brs.exe
PRC - [2010/10/01 14:55:28 | 000,087,336 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
PRC - [2010/01/27 14:01:56 | 000,237,568 | ---- | M] (Alcor Micro Corp.) -- C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe
========== Modules (No Company Name) ==========
MOD - [2015/06/19 23:01:41 | 000,157,696 | ---- | M] () -- C:\ProgramData\Msouflui\1.0.1.0\uawiemem.exe
MOD - [2015/06/19 22:57:39 | 000,117,248 | ---- | M] () -- C:\Users\jklm\AppData\Local\Temp\nspC290.tmp\IpConfig.dll
MOD - [2015/06/19 22:57:38 | 000,011,264 | ---- | M] () -- C:\Users\jklm\AppData\Local\Temp\nspC290.tmp\System.dll
MOD - [2015/06/19 22:55:58 | 000,603,648 | ---- | M] () -- C:\Program Files (x86)\version85IneedSpeed\b4IneedSpeedQ95.exe
MOD - [2015/06/19 22:55:46 | 000,494,592 | ---- | M] () -- C:\Program Files (x86)\version85IneedSpeed\192.dll
MOD - [2015/06/19 09:55:46 | 003,319,976 | ---- | M] () -- C:\Users\jklm\AppData\Local\gmsd_us_005010007\upgmsd_us_005010007.exe
MOD - [2015/06/19 09:55:41 | 003,984,040 | ---- | M] () -- C:\Program Files (x86)\gmsd_us_005010007\gmsd_us_005010007.exe
MOD - [2015/06/18 21:06:42 | 002,422,784 | ---- | M] () -- C:\Program Files (x86)\Smwyyntm1ndi1zdz\nwjkm2z2y3mwbdd.exe
MOD - [2015/06/09 03:52:08 | 000,056,424 | ---- | M] () -- C:\Program Files (x86)\Games Bot\Modules\wdm.dll
MOD - [2015/06/09 03:51:50 | 000,096,872 | ---- | M] () -- C:\Program Files (x86)\Games Bot\Modules\sipc.dll
MOD - [2015/06/09 03:51:38 | 000,041,576 | ---- | M] () -- C:\Program Files (x86)\Games Bot\Modules\inws.dll
MOD - [2015/06/09 03:51:30 | 000,090,728 | ---- | M] () -- C:\Program Files (x86)\Games Bot\Modules\cmd.dll
MOD - [2015/06/09 03:51:24 | 000,117,352 | ---- | M] () -- C:\Program Files (x86)\Games Bot\Modules\brs.dll
MOD - [2015/06/09 03:51:18 | 000,109,160 | ---- | M] () -- C:\Program Files (x86)\Games Bot\Modules\Base.dll
MOD - [2015/06/09 03:51:12 | 000,039,528 | ---- | M] () -- C:\Program Files (x86)\Games Bot\Modules\alzm.dll
MOD - [2015/06/05 01:14:30 | 000,359,936 | ---- | M] () -- C:\Users\jklm\AppData\Local\4C4C4544-1434754703-5610-8048-B7C04F445131\bnsl9328.exe
MOD - [2015/05/28 10:06:16 | 001,240,096 | ---- | M] () -- C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe
MOD - [2015/04/22 05:00:56 | 000,311,912 | ---- | M] () -- C:\Program Files (x86)\Games Bot\GamesBot.exe
MOD - [2015/04/22 01:24:54 | 000,904,704 | ---- | M] () -- C:\Program Files (x86)\Games Bot\System.Data.SQLite.dll
MOD - [2015/03/26 07:39:47 | 008,569,856 | ---- | M] () -- C:\Users\jklm\AppData\Local\Games Bot\Explore\pdf.dll
MOD - [2015/03/26 07:18:11 | 000,324,608 | ---- | M] () -- C:\Users\jklm\AppData\Local\Games Bot\Explore\ppGoogleNaClPluginChrome.dll
MOD - [2015/03/26 07:14:17 | 000,880,128 | ---- | M] () -- C:\Users\jklm\AppData\Local\Games Bot\Explore\ffmpegsumo.dll
MOD - [2015/02/25 08:32:08 | 001,938,944 | ---- | M] () -- C:\Program Files (x86)\Consumer Input\InternetExplorer\mozjs185-1.0.dll
MOD - [2014/09/22 21:07:04 | 014,891,848 | ---- | M] () -- C:\Users\jklm\AppData\Local\Games Bot\Explore\PepperFlash\pepflashplayer.dll
MOD - [2013/04/21 21:44:32 | 000,087,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2013/04/21 21:44:04 | 001,242,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/08/18 08:05:54 | 002,751,808 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
MOD - [2011/06/11 19:55:03 | 002,295,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\b1a619266964bede98b18ef83eb1c559\System.Core.ni.dll
MOD - [2011/04/07 15:11:06 | 005,246,976 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
MOD - [2011/04/07 12:31:09 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\598a9987f519acb9efe5372a2c556af6\PresentationFramework.Aero.ni.dll
MOD - [2011/04/07 12:31:06 | 014,318,592 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\eb5ff7b60b69cc300751f46c6af316ad\PresentationFramework.ni.dll
MOD - [2011/04/07 12:30:56 | 012,216,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\a937151be4e65fd89c55b4c603f7d902\PresentationCore.ni.dll
MOD - [2011/04/07 12:30:56 | 000,185,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\f050ef6d97c0102333ded4d8d58ffa4e\UIAutomationTypes.ni.dll
MOD - [2011/04/07 12:30:56 | 000,060,928 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\de2941860ca151f8f9dd719daa7f9650\UIAutomationProvider.ni.dll
MOD - [2011/04/07 12:30:49 | 003,313,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d80659eacd9554d9606881b0d35835cf\WindowsBase.ni.dll
MOD - [2011/04/07 12:30:40 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\b2e6d33df15f6ca262db09558982e0f2\Accessibility.ni.dll
MOD - [2011/04/07 12:30:39 | 012,430,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f92c882fd4e7005c005e208daa04c28d\System.Windows.Forms.ni.dll
MOD - [2011/04/07 12:30:27 | 000,628,224 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\7e94064464380c8a5d7315c8b5d312aa\System.EnterpriseServices.ni.dll
MOD - [2011/04/07 12:30:26 | 000,627,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\c744f0f95227e75796b8689801740d4b\System.Transactions.ni.dll
MOD - [2011/04/07 12:30:25 | 006,618,624 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\935ac020241e59cab3287d5eb38c592d\System.Data.ni.dll
MOD - [2011/04/07 12:30:17 | 001,586,688 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\fdeec42fa02f3d789c42be2e33b130eb\System.Drawing.ni.dll
MOD - [2011/04/07 12:30:11 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\3060dfcdecbeb8ee65077fb29b217c3d\System.Xml.ni.dll
MOD - [2011/04/07 12:30:09 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\4be2653d1c9804d2ff6e6b66d22764e1\System.Configuration.ni.dll
MOD - [2011/04/07 12:30:08 | 007,949,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\500ddd904b1099f95552a81b54223b7f\System.ni.dll
MOD - [2011/04/07 12:29:42 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\f58ab951b57c8526430486dcf7ee38fd\mscorlib.ni.dll
MOD - [2010/11/24 20:44:02 | 000,375,280 | ---- | M] () -- c:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\SQLite352.dll
MOD - [2010/11/17 08:35:40 | 001,440,240 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\Roxio Burn.exe
MOD - [2010/11/17 08:35:34 | 000,514,544 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
MOD - [2010/11/17 08:35:28 | 000,657,904 | ---- | M] () -- C:\Program Files (x86)\Roxio\OEM\Roxio Burn\BBEngineAS.dll
MOD - [2010/03/24 21:17:36 | 008,794,464 | ---- | M] () -- C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2010/01/30 02:41:12 | 004,254,560 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2009/06/10 14:23:20 | 002,048,000 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll
MOD - [2009/06/10 14:23:19 | 000,261,632 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
MOD - [2009/06/10 14:23:18 | 003,178,496 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
MOD - [2009/06/10 14:23:17 | 002,933,248 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2009/06/10 14:23:17 | 000,425,984 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll
========== Services (SafeList) ==========
SRV:64bit: - [2010/11/11 14:36:38 | 000,282,616 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2010/11/11 14:36:38 | 000,012,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2010/09/22 16:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2009/07/13 18:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2015/06/19 23:11:17 | 000,558,544 | ---- | M] () [Auto | Running] -- C:/Program Files (x86)/ORBTR/orbiter.dll -- (Orbiter)
SRV - [2015/06/19 23:01:08 | 000,147,456 | ---- | M] () [Auto | Running] -- C:\Users\jklm\AppData\Local\4C4C4544-1434754844-5610-8048-B7C04F445131\snsrA659.tmp -- (kysykiti)
SRV - [2015/06/19 22:58:46 | 000,105,944 | ---- | M] (ConsumerInput) [On_Demand | Stopped] -- C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe -- (consumerinput_updatem)
SRV - [2015/06/19 22:58:46 | 000,105,944 | ---- | M] (ConsumerInput) [Auto | Stopped] -- C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe -- (consumerinput_update)
SRV - [2015/06/19 22:56:32 | 002,730,984 | ---- | M] (Time Lapse Solutions) [Auto | Running] -- C:\ProgramData\WBRYXRSt\xfrcCqRE.exe -- (xfrcCqRE)
SRV - [2015/06/19 22:53:52 | 000,068,608 | ---- | M] (globalUpdate) [On_Demand | Stopped] -- C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe -- (globalUpdatem)
SRV - [2015/06/19 22:53:52 | 000,068,608 | ---- | M] (globalUpdate) [Auto | Stopped] -- C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe -- (globalUpdate)
SRV - [2015/06/18 21:04:38 | 000,710,144 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Umtayyznhndq1ntz\mwmyzjmzngu1mdy.exe -- (UniversalUpdater)
SRV - [2015/06/10 04:57:08 | 000,268,464 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2015/06/09 03:50:34 | 000,053,352 | ---- | M] (Games Bot Inc.) [Auto | Running] -- C:\Program Files (x86)\Games Bot\GamesBotSvc.exe -- (GamesBotService)
SRV - [2015/06/03 02:35:02 | 003,285,776 | ---- | M] (Client Connect LTD) [Auto | Running] -- C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe -- (CltMngSvc)
SRV - [2015/04/10 12:57:08 | 000,278,600 | ---- | M] (Infonaut) [Auto | Running] -- C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe -- (insvc_1.10.0.14)
SRV - [2014/09/18 19:16:34 | 000,014,624 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe -- (IntuitUpdateServiceV4)
SRV - [2012/07/27 13:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/08/18 08:05:46 | 001,692,480 | ---- | M] (SoftThinks SAS) [Auto | Running] -- C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe -- (SftService)
SRV - [2011/04/07 12:31:12 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
SRV - [2010/11/25 03:34:18 | 000,219,632 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe -- (RoxWatch12)
SRV - [2010/11/25 03:33:18 | 001,116,656 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe -- (RoxMediaDB12OEM)
SRV - [2010/10/26 16:26:58 | 000,236,016 | ---- | M] (CyberLink) [Auto | Stopped] -- C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe -- (CLKMSVC10_9EC60124)
SRV - [2010/10/12 10:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 14:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2015/06/19 22:55:57 | 000,050,216 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\webTinstMKTN84.sys -- (webTinstMKTN84)
DRV:64bit: - [2015/06/18 21:08:12 | 000,050,520 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\nwjkm2z2y3mwbdd.sys -- (nwjkm2z2y3mwbdd)
DRV:64bit: - [2015/04/10 12:56:56 | 000,058,224 | ---- | M] (Infonaut) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\innfd_1_10_0_14.sys -- (innfd_1_10_0_14)
DRV:64bit: - [2014/10/29 17:26:46 | 000,131,256 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ctxusbm.sys -- (ctxusbm)
DRV:64bit: - [2013/02/21 07:05:44 | 000,011,296 | ---- | M] (Safend Ltd.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\SpfdBus.sys -- (SpfdBus)
DRV:64bit: - [2012/12/13 13:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2010/10/24 21:25:38 | 000,072,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2010/07/30 16:36:38 | 000,025,072 | ---- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Running] -- c:\Program Files\Dell Support Center\pcdsrvc_x64.pkms -- (PCDSRVC{1E208CE0-FB7451FF-06020101}_0)
DRV:64bit: - [2010/04/01 07:47:10 | 010,322,848 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2010/03/19 01:00:00 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2010/02/27 08:32:14 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2010/02/03 22:38:32 | 000,271,872 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2009/10/16 04:32:24 | 000,321,064 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a)
DRV:64bit: - [2009/09/17 13:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV:64bit: - [2009/07/13 18:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/07/13 18:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/13 18:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 18:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 18:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 18:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009/07/13 18:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/07 10:53:04 | 000,032,256 | ---- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\libusb0.sys -- (libusb0)
DRV:64bit: - [2009/06/10 13:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 13:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 13:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 13:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2006/11/01 10:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV - [2009/07/13 18:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.trovi.com...C&D=062015=
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B8 48 D0 59 05 06 CF 01 [binary data]
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {008E7F3B-B9BB-4F68-9EE6-985CDA3090CC}
IE - HKCU\..\SearchScopes\{008E7F3B-B9BB-4F68-9EE6-985CDA3090CC}: "URL" = http://www.google.co...{outputEncoding?}
IE - HKCU\..\SearchScopes\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9}: "URL" = http://www.trovi.com...archTerms}=
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_188.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Citrix.com/npican: C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll (Citrix Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll (globalUpdate)
FF - HKLM\Software\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll (globalUpdate)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{78DADB4B-7468-4c1c-8612-00FBF356A9FF}: C:\Program Files (x86)\Kotato\YouTube Downloader\YTD_FF.xpi [2013/07/30 17:09:48 | 000,012,301 | ---- | M] ()
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{B64D9B05-48E1-4CEB-BF58-E0643994E900}: C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ [2014/04/23 19:12:47 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{C6476A68-B06E-82C0-8E2F-D79F1A73C235}: C:\Program Files (x86)\version85IneedSpeed\192.xpi [2015/06/19 22:56:16 | 000,010,631 | ---- | M] ()
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\ConsumerInput@Compete: C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12099.xpi [2015/01/21 05:15:46 | 000,511,969 | ---- | M] ()
[2013/07/18 23:29:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
========== Chrome ==========
CHR - Extension: No name found = C:\Users\jklm\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
CHR - Extension: No name found = C:\Users\jklm\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Users\jklm\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.4_0\
CHR - Extension: No name found = C:\Users\jklm\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.7_0\
CHR - Extension: No name found = C:\Users\jklm\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.30_0\
CHR - Extension: No name found = C:\Users\jklm\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebjipgnedcljapmafeafekmlebefcafp\1.1.0_0\
CHR - Extension: No name found = C:\Users\jklm\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
CHR - Extension: No name found = C:\Users\jklm\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg\0.3.0.5_0\
CHR - Extension: No name found = C:\Users\jklm\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjdhhjbhbfhkmmcjojicgkoplildbkbk\1.192.0.0_0\
CHR - Extension: No name found = C:\Users\jklm\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.1.0_0\
CHR - Extension: No name found = C:\Users\jklm\AppData\Local\Google\Chrome\User Data\Default\Extensions\papbadoldddalgcjcicnikcfenodpghp\1.26.85_0\
CHR - Extension: No name found = C:\Users\jklm\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
O1 HOSTS File: ([2009/06/10 14:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (IneedSpeed) - {9480B134-F446-56C2-81C2-8E7E24D11E5F} - C:\Program Files (x86)\version85IneedSpeed\192_x64.dll ()
O2:64bit: - BHO: (Consumer Input DCA BHO) - {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} - C:\Program Files (x86)\Consumer Input\InternetExplorer\x64\dca-bho.dll (Compete, Inc.)
O2:64bit: - BHO: (DVDVideoSoft IE Extension) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
O2 - BHO: (IneedSpeed) - {9480B134-F446-56C2-81C2-8E7E24D11E5F} - C:\Program Files (x86)\version85IneedSpeed\192.dll ()
O2 - BHO: (Consumer Input DCA BHO) - {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} - C:\Program Files (x86)\Consumer Input\InternetExplorer\dca-bho.dll (Compete, Inc.)
O2 - BHO: (DVDVideoSoft IE Extension) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [AccessSecureData] C:\Users\jklm\AppData\Local\Temp\{8565EB50-E289-4892-A596-DA6331E51B86}\AccessSecureData.exe File not found
O4:64bit: - HKLM..\Run: [DellStage] C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BDRegion] C:\Program Files (x86)\CyberLink\Shared files\brs.exe (cyberlink)
O4 - HKLM..\Run: [CitrixReceiver] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix\Receiver Updater.lnk" File not found
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [gmsd_us_005010007] C:\Program Files (x86)\gmsd_us_005010007\gmsd_us_005010007.exe ()
O4 - HKLM..\Run: [mwyyntm1ndi1zdz] C:\Program Files (x86)\Smwyyntm1ndi1zdz\nwjkm2z2y3mwbdd.exe ()
O4 - HKLM..\Run: [PDVD9LanguageShortcut] C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Redirector] C:\Program Files (x86)\Citrix\ICA Client\redirector.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [RemoteControl9] C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKLM..\Run: [ShwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe (Alcor Micro Corp.)
O4 - HKLM..\Run: [SmartWeb] C:\Users\jklm\AppData\Local\SmartWeb\SmartWebHelper.exe (SoftBrain Technologies Ltd.)
O4 - HKLM..\Run: [WinCheck] C:\Users\jklm\AppData\Local\4C4C4544-1434754703-5610-8048-B7C04F445131\bnsl9328.exe ()
O4 - HKCU..\Run: [ANT Agent] C:\Program Files (x86)\Garmin\ANT Agent\ANT Agent.exe (GARMIN Corp.)
O4 - HKCU..\Run: [GamesBot] C:\Program Files (x86)\Games Bot\GamesBot.exe ()
O4 - HKCU..\Run: [GoogleChromeAutoLaunch_D1B0517A1A5838A6E831285B01BA7F9A] C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe (Crossbrowse)
O4 - HKCU..\Run: [PCKeeper2] "C:\Program Files\Kromtech\PCKeeper\PCKeeper.exe" /autorun File not found
O4 - HKLM..\RunOnce: [upgmsd_us_005010007.exe] C:\Users\jklm\AppData\Local\gmsd_us_005010007\upgmsd_us_005010007.exe ()
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_17_0_0_188_ActiveX.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Users\jklm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\crossbrowse.lnk = C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe (Crossbrowse)
O4 - Startup: C:\Users\jklm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk = C:\Users\jklm\AppData\Local\SmartWeb\SmartWebHelper.exe (SoftBrain Technologies Ltd.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Download video on this page - C:\Program Files (x86)\Kotato\YouTube Downloader\YTD_IE.dll (Kotato)
O8:64bit: - Extra context menu item: Download video this links to - C:\Program Files (x86)\Kotato\YouTube Downloader\YTD_IE.dll (Kotato)
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm ()
O8 - Extra context menu item: Download video on this page - C:\Program Files (x86)\Kotato\YouTube Downloader\YTD_IE.dll (Kotato)
O8 - Extra context menu item: Download video this links to - C:\Program Files (x86)\Kotato\YouTube Downloader\YTD_IE.dll (Kotato)
O8 - Extra context menu item: Free YouTube Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm ()
O9:64bit: - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
O9:64bit: - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
O9 - Extra Button: Download Video - {731DC20B-51DE-4681-BBB9-69593E9F99A2} - C:\Program Files (x86)\Kotato\YouTube Downloader\YTD_IE.dll (Kotato)
O9 - Extra 'Tools' menuitem : Download video on this page - {731DC20B-51DE-4681-BBB9-69593E9F99A2} - C:\Program Files (x86)\Kotato\YouTube Downloader\YTD_IE.dll (Kotato)
O9 - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O9 - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{532EA892-0F4F-476E-8CAC-78C4C48327DB}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\application/x-ica - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=euc-jp - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=ISO-8859-1 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS936 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS949 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS950 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=UTF8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=UTF-8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=euc-jp - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=ISO-8859-1 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS936 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS949 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS950 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=UTF8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=UTF-8 - No CLSID value found
O18:64bit: - Protocol\Filter\ica - No CLSID value found
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll) - C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll (Client Connect LTD)
O20:64bit: - AppInit_DLLs: (C:\ProgramData\FlashBeat\FlashBeat64.dll) - C:\ProgramData\FlashBeat\FlashBeat64.dll (FlashBeat)
O20 - AppInit_DLLs: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll) - C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll (Client Connect LTD)
O20 - AppInit_DLLs: (C:\ProgramData\FlashBeat\FlashBeat32.dll) - C:\ProgramData\FlashBeat\FlashBeat32.dll (FlashBeat)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/04/30 15:01:00 | 000,000,053 | -HS- | M] () - Y:\AUTORUN.INF -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2015/06/19 23:37:45 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\jklm\Desktop\OTL.exe
[2015/06/19 23:27:45 | 000,000,000 | ---D | C] -- C:\Users\jklm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup
[2015/06/19 23:21:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AnyProtectEx
[2015/06/19 23:21:10 | 000,000,000 | -HSD | C] -- C:\Users\jklm\AppData\Roaming\AnyProtectEx
[2015/06/19 23:20:33 | 000,000,000 | ---D | C] -- C:\Users\jklm\AppData\Roaming\Compete
[2015/06/19 23:17:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP
[2015/06/19 23:17:37 | 000,000,000 | ---D | C] -- C:\Users\jklm\AppData\Local\Crossbrowse
[2015/06/19 23:17:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crossbrowse
[2015/06/19 23:17:29 | 000,000,000 | ---D | C] -- C:\Users\jklm\AppData\Local\gmsd_us_005010007
[2015/06/19 23:17:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\gmsd_us_005010007
[2015/06/19 23:17:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Crossbrowse
[2015/06/19 23:14:12 | 000,000,000 | ---D | C] -- C:\Users\jklm\AppData\Local\avabvbavad
[2015/06/19 23:14:06 | 000,000,000 | ---D | C] -- C:\Users\jklm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games Bot
[2015/06/19 23:14:05 | 000,000,000 | ---D | C] -- C:\Users\jklm\AppData\Local\Games Bot
[2015/06/19 23:14:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Games Bot
[2015/06/19 23:13:55 | 000,000,000 | ---D | C] -- C:\Users\jklm\AppData\Local\SearchProtect
[2015/06/19 23:13:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SearchProtect
[2015/06/19 23:12:12 | 000,000,000 | ---D | C] -- C:\Users\jklm\AppData\Local\SmartWeb
[2015/06/19 23:11:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ORBTR
[2015/06/19 23:10:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Infonaut_1.10.0.14
[2015/06/19 23:02:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Setup Support for Consumer Input
[2015/06/19 23:01:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Msouflui
[2015/06/19 23:00:44 | 000,000,000 | ---D | C] -- C:\Users\jklm\AppData\Local\4C4C4544-1434754844-5610-8048-B7C04F445131
[2015/06/19 22:58:49 | 000,000,000 | ---D | C] -- C:\Users\jklm\AppData\Local\Consumer Input
[2015/06/19 22:58:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Consumer Input
[2015/06/19 22:58:23 | 000,000,000 | ---D | C] -- C:\Users\jklm\AppData\Local\4C4C4544-1434754703-5610-8048-B7C04F445131
[2015/06/19 22:58:18 | 000,000,000 | ---D | C] -- C:\Users\jklm\AppData\Local\Kromtech
[2015/06/19 22:58:15 | 000,000,000 | ---D | C] -- C:\Users\jklm\AppData\Local\Zeoinsight
[2015/06/19 22:58:14 | 000,000,000 | ---D | C] -- C:\Users\jklm\AppData\Local\ZBAnalyticsCore
[2015/06/19 22:57:34 | 000,000,000 | ---D | C] -- C:\Users\jklm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASPackage
[2015/06/19 22:57:29 | 000,000,000 | ---D | C] -- C:\Users\jklm\AppData\Roaming\ASPackage
[2015/06/19 22:57:29 | 000,000,000 | ---D | C] -- C:\Users\jklm\AppData\Roaming\4C4C4544-1434779849-5610-8048-B7C04F445131
[2015/06/19 22:57:15 | 000,000,000 | ---D | C] -- C:\Users\jklm\AppData\Local\ZombieNews
[2015/06/19 22:56:30 | 000,000,000 | ---D | C] -- C:\ProgramData\WBRYXRSt
[2015/06/19 22:56:16 | 000,000,000 | ---D | C] -- C:\ProgramData\ZombieNews
[2015/06/19 22:56:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\version85IneedSpeed
[2015/06/19 22:54:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Umtayyznhndq1ntz
[2015/06/19 22:54:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hades
[2015/06/19 22:54:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Smwyyntm1ndi1zdz
[2015/06/19 22:54:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\22c5dbb2-38e8-401e-a36d-e396d9be6748
[2015/06/19 22:53:53 | 000,000,000 | ---D | C] -- C:\Users\jklm\AppData\Local\globalUpdate
[2015/06/19 22:53:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\globalUpdate
[2015/06/19 22:53:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cinema_Plus-1.2V19.06
[2015/06/19 22:52:29 | 000,000,000 | ---D | C] -- C:\ProgramData\5aae4531dc23473f8da7a5bac9f3a51f
[2015/06/19 22:52:27 | 000,000,000 | ---D | C] -- C:\ProgramData\28341ff220e0446c9fff27c4493d622e
[2015/06/19 22:52:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Kromtech
[2015/06/19 22:52:22 | 000,000,000 | ---D | C] -- C:\ProgramData\FlashBeat
[2015/06/19 22:51:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LuckyTab
[2015/06/19 22:36:42 | 000,000,000 | ---D | C] -- C:\Users\jklm\Desktop\Atlas Genius - When It Was Now
[2015/06/18 21:08:12 | 000,050,520 | ---- | C] (Windows ® Win 7 DDK provider) -- C:\Windows\SysNative\drivers\nwjkm2z2y3mwbdd.sys
[2015/06/17 22:39:48 | 000,000,000 | ---D | C] -- C:\Users\jklm\Desktop\Imagine Dragons - Smoke + Mirrors
[2015/06/17 22:35:46 | 000,000,000 | ---D | C] -- C:\Users\jklm\Desktop\Sutter 2015 Slideshow
[2015/05/29 08:02:40 | 000,000,000 | ---D | C] -- C:\Users\jklm\Desktop\md new mp3
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\jklm\AppData\Local\*.tmp files -> C:\Users\jklm\AppData\Local\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2015/06/19 23:50:00 | 000,000,358 | ---- | M] () -- C:\Windows\tasks\CIMT_S-1-5-21-2695581885-3589152984-3162700467-1001.job
[2015/06/19 23:47:30 | 000,000,378 | ---- | M] () -- C:\Windows\tasks\APSnotifierPP1.job
[2015/06/19 23:39:35 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015/06/19 23:37:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\jklm\Desktop\OTL.exe
[2015/06/19 23:27:48 | 000,000,376 | ---- | M] () -- C:\Windows\tasks\APSnotifierPP3.job
[2015/06/19 23:27:47 | 000,000,376 | ---- | M] () -- C:\Windows\tasks\APSnotifierPP2.job
[2015/06/19 23:27:45 | 000,001,011 | ---- | M] () -- C:\Users\jklm\Desktop\AnyProtect.lnk
[2015/06/19 23:17:58 | 000,002,384 | ---- | M] () -- C:\Users\jklm\Application Data\Microsoft\Internet Explorer\Quick Launch\Crossbrowse.lnk
[2015/06/19 23:17:37 | 000,001,054 | ---- | M] () -- C:\Windows\tasks\Crossbrowse.job
[2015/06/19 23:17:35 | 000,002,215 | ---- | M] () -- C:\Users\Public\Desktop\Search.lnk
[2015/06/19 23:17:30 | 000,002,360 | ---- | M] () -- C:\Users\Public\Desktop\Crossbrowse.lnk
[2015/06/19 23:17:30 | 000,002,360 | ---- | M] () -- C:\Users\jklm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\crossbrowse.lnk
[2015/06/19 23:12:14 | 000,001,100 | ---- | M] () -- C:\Users\jklm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk
[2015/06/19 23:04:16 | 000,000,966 | ---- | M] () -- C:\Windows\tasks\ConsumerInputUpdateTaskMachineUA.job
[2015/06/19 23:03:00 | 000,000,962 | ---- | M] () -- C:\Windows\tasks\ConsumerInputUpdateTaskMachineCore.job
[2015/06/19 23:02:15 | 000,000,392 | ---- | M] () -- C:\Windows\tasks\CIMT_daily_S-1-5-21-2695581885-3589152984-3162700467-1001.job
[2015/06/19 22:59:10 | 000,000,996 | ---- | M] () -- C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job
[2015/06/19 22:59:00 | 000,000,992 | ---- | M] () -- C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job
[2015/06/19 22:56:27 | 000,000,430 | ---- | M] () -- C:\Windows\tasks\IneedSpeed Update.job
[2015/06/19 22:56:25 | 000,001,822 | ---- | M] () -- C:\Windows\patsearch.bin
[2015/06/19 22:56:23 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_webTinstMKTN84_01009.Wdf
[2015/06/19 22:56:17 | 000,000,258 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2015/06/19 22:56:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015/06/19 22:55:57 | 000,050,216 | ---- | M] () -- C:\Windows\SysNative\drivers\webTinstMKTN84.sys
[2015/06/19 22:55:16 | 000,001,010 | ---- | M] () -- C:\Windows\tasks\g5EHHvd7KBE2FYc8jv1Ik.job
[2015/06/19 22:55:11 | 000,002,444 | ---- | M] () -- C:\Windows\tasks\ca281dfc-e383-4fa1-80fa-dc79c4d0c772-5_user.job
[2015/06/19 22:55:08 | 000,002,444 | ---- | M] () -- C:\Windows\tasks\ca281dfc-e383-4fa1-80fa-dc79c4d0c772-5.job
[2015/06/19 22:54:49 | 000,003,136 | ---- | M] () -- C:\Windows\tasks\ca281dfc-e383-4fa1-80fa-dc79c4d0c772-1-6.job
[2015/06/19 22:54:45 | 000,003,136 | ---- | M] () -- C:\Windows\tasks\ca281dfc-e383-4fa1-80fa-dc79c4d0c772-1-7.job
[2015/06/19 22:54:23 | 000,005,516 | ---- | M] () -- C:\Windows\tasks\ca281dfc-e383-4fa1-80fa-dc79c4d0c772-6.job
[2015/06/19 22:54:14 | 000,005,180 | ---- | M] () -- C:\Windows\tasks\ca281dfc-e383-4fa1-80fa-dc79c4d0c772-7.job
[2015/06/19 22:54:00 | 000,004,156 | ---- | M] () -- C:\Windows\tasks\ca281dfc-e383-4fa1-80fa-dc79c4d0c772-3.job
[2015/06/19 22:53:49 | 000,000,004 | ---- | M] () -- C:\Windows\SysWow64\029B560A371F4E00AB32838EBC01B9E7
[2015/06/19 22:53:46 | 000,002,110 | ---- | M] () -- C:\Windows\tasks\ca281dfc-e383-4fa1-80fa-dc79c4d0c772-10_user.job
[2015/06/19 22:53:00 | 000,000,328 | ---- | M] () -- C:\Windows\tasks\MTCYOKLOLS1.job
[2015/06/19 22:30:24 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015/06/19 18:21:22 | 000,000,422 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2015/06/18 21:08:12 | 000,050,520 | ---- | M] (Windows ® Win 7 DDK provider) -- C:\Windows\SysNative\drivers\nwjkm2z2y3mwbdd.sys
[2015/06/10 22:44:22 | 000,763,853 | ---- | M] () -- C:\Users\jklm\Desktop\IMG_1326.JPG
[2015/06/10 05:39:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015/06/08 11:00:03 | 000,000,564 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2015/06/02 21:55:48 | 000,729,688 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2015/06/02 21:55:48 | 000,626,040 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2015/06/02 21:55:48 | 000,107,316 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2015/05/22 09:52:23 | 000,199,930 | ---- | M] () -- C:\Users\jklm\Desktop\hswpvtrnemp.pdf
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\jklm\AppData\Local\*.tmp files -> C:\Users\jklm\AppData\Local\*.tmp -> ]
========== Files Created - No Company Name ==========
[2015/06/19 23:27:48 | 000,000,376 | ---- | C] () -- C:\Windows\tasks\APSnotifierPP3.job
[2015/06/19 23:27:47 | 000,000,376 | ---- | C] () -- C:\Windows\tasks\APSnotifierPP2.job
[2015/06/19 23:27:45 | 000,001,011 | ---- | C] () -- C:\Users\jklm\Desktop\AnyProtect.lnk
[2015/06/19 23:27:45 | 000,000,378 | ---- | C] () -- C:\Windows\tasks\APSnotifierPP1.job
[2015/06/19 23:17:40 | 000,002,360 | ---- | C] () -- C:\Users\jklm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\crossbrowse.lnk
[2015/06/19 23:17:36 | 000,001,054 | ---- | C] () -- C:\Windows\tasks\Crossbrowse.job
[2015/06/19 23:17:35 | 000,002,215 | ---- | C] () -- C:\Users\Public\Desktop\Search.lnk
[2015/06/19 23:17:30 | 000,002,384 | ---- | C] () -- C:\Users\jklm\Application Data\Microsoft\Internet Explorer\Quick Launch\Crossbrowse.lnk
[2015/06/19 23:17:30 | 000,002,360 | ---- | C] () -- C:\Users\Public\Desktop\Crossbrowse.lnk
[2015/06/19 23:12:14 | 000,001,100 | ---- | C] () -- C:\Users\jklm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk
[2015/06/19 23:02:14 | 000,000,392 | ---- | C] () -- C:\Windows\tasks\CIMT_daily_S-1-5-21-2695581885-3589152984-3162700467-1001.job
[2015/06/19 23:02:13 | 000,000,358 | ---- | C] () -- C:\Windows\tasks\CIMT_S-1-5-21-2695581885-3589152984-3162700467-1001.job
[2015/06/19 22:59:01 | 000,000,966 | ---- | C] () -- C:\Windows\tasks\ConsumerInputUpdateTaskMachineUA.job
[2015/06/19 22:58:59 | 000,000,962 | ---- | C] () -- C:\Windows\tasks\ConsumerInputUpdateTaskMachineCore.job
[2015/06/19 22:56:27 | 000,000,430 | ---- | C] () -- C:\Windows\tasks\IneedSpeed Update.job
[2015/06/19 22:56:25 | 000,001,822 | ---- | C] () -- C:\Windows\patsearch.bin
[2015/06/19 22:56:23 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_webTinstMKTN84_01009.Wdf
[2015/06/19 22:56:18 | 000,050,216 | ---- | C] () -- C:\Windows\SysNative\drivers\webTinstMKTN84.sys
[2015/06/19 22:56:16 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2015/06/19 22:55:14 | 000,001,010 | ---- | C] () -- C:\Windows\tasks\g5EHHvd7KBE2FYc8jv1Ik.job
[2015/06/19 22:55:09 | 000,002,444 | ---- | C] () -- C:\Windows\tasks\ca281dfc-e383-4fa1-80fa-dc79c4d0c772-5_user.job
[2015/06/19 22:55:07 | 000,002,444 | ---- | C] () -- C:\Windows\tasks\ca281dfc-e383-4fa1-80fa-dc79c4d0c772-5.job
[2015/06/19 22:54:46 | 000,003,136 | ---- | C] () -- C:\Windows\tasks\ca281dfc-e383-4fa1-80fa-dc79c4d0c772-1-6.job
[2015/06/19 22:54:44 | 000,003,136 | ---- | C] () -- C:\Windows\tasks\ca281dfc-e383-4fa1-80fa-dc79c4d0c772-1-7.job
[2015/06/19 22:54:15 | 000,005,516 | ---- | C] () -- C:\Windows\tasks\ca281dfc-e383-4fa1-80fa-dc79c4d0c772-6.job
[2015/06/19 22:54:03 | 000,005,180 | ---- | C] () -- C:\Windows\tasks\ca281dfc-e383-4fa1-80fa-dc79c4d0c772-7.job
[2015/06/19 22:54:02 | 000,000,996 | ---- | C] () -- C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job
[2015/06/19 22:54:00 | 000,000,992 | ---- | C] () -- C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job
[2015/06/19 22:53:54 | 000,004,156 | ---- | C] () -- C:\Windows\tasks\ca281dfc-e383-4fa1-80fa-dc79c4d0c772-3.job
[2015/06/19 22:53:49 | 000,000,004 | ---- | C] () -- C:\Windows\SysWow64\029B560A371F4E00AB32838EBC01B9E7
[2015/06/19 22:53:45 | 000,002,110 | ---- | C] () -- C:\Windows\tasks\ca281dfc-e383-4fa1-80fa-dc79c4d0c772-10_user.job
[2015/06/19 22:52:31 | 000,000,328 | ---- | C] () -- C:\Windows\tasks\MTCYOKLOLS1.job
[2015/06/17 23:02:34 | 000,763,853 | ---- | C] () -- C:\Users\jklm\Desktop\IMG_1326.JPG
[2015/05/22 09:52:22 | 000,199,930 | ---- | C] () -- C:\Users\jklm\Desktop\hswpvtrnemp.pdf
[2015/04/20 07:05:14 | 001,579,520 | ---- | C] () -- C:\Users\jklm\AppData\Roaming\g5EHHvd7KBE2FYc8jv1Ik.exe
[2015/04/19 05:20:16 | 000,005,872 | ---- | C] () -- C:\Users\jklm\AppData\Roaming\g5EHHvd7KBE2FYc8jv1Ik
[2014/03/29 20:31:00 | 000,000,614 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2013/11/17 19:03:48 | 000,004,096 | -H-- | C] () -- C:\Users\jklm\AppData\Local\keyfile3.drm
[2013/11/01 21:22:12 | 000,001,075 | ---- | C] () -- C:\Users\jklm\Documents - Shortcut.lnk
[2013/07/24 17:18:40 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013/07/24 17:18:40 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013/07/24 17:18:40 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013/07/24 17:18:40 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013/07/24 17:18:40 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
========== ZeroAccess Check ==========
[2009/07/13 21:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2011/04/07 15:11:07 | 014,162,944 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2011/04/07 15:11:07 | 012,867,584 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 18:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/07/13 18:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 18:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2015/06/19 23:20:29 | 000,000,000 | ---D | M] -- C:\Users\jklm\AppData\Roaming\4C4C4544-1434779849-5610-8048-B7C04F445131
[2015/06/19 23:21:10 | 000,000,000 | -HSD | M] -- C:\Users\jklm\AppData\Roaming\AnyProtectEx
[2015/06/19 22:57:32 | 000,000,000 | ---D | M] -- C:\Users\jklm\AppData\Roaming\ASPackage
[2015/06/19 23:20:33 | 000,000,000 | ---D | M] -- C:\Users\jklm\AppData\Roaming\Compete
[2014/04/28 07:22:38 | 000,000,000 | ---D | M] -- C:\Users\jklm\AppData\Roaming\DVDVideoSoft
[2013/07/02 04:46:23 | 000,000,000 | ---D | M] -- C:\Users\jklm\AppData\Roaming\Garmin
[2014/05/09 05:31:42 | 000,000,000 | ---D | M] -- C:\Users\jklm\AppData\Roaming\HandBrake
[2015/03/24 17:01:14 | 000,000,000 | ---D | M] -- C:\Users\jklm\AppData\Roaming\ICAClient
[2014/05/05 19:38:18 | 000,000,000 | ---D | M] -- C:\Users\jklm\AppData\Roaming\Kotato
[2015/06/19 23:11:29 | 000,000,000 | ---D | M] -- C:\Users\jklm\AppData\Roaming\MediaMonkey
[2011/06/12 14:00:24 | 000,000,000 | ---D | M] -- C:\Users\jklm\AppData\Roaming\PCDr
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2013/08/02 23:50:06 | 000,000,068 | ---- | M] ()(C:\Users\jklm\Desktop\? Rowbury wins 3000m with leading time - Universal Sports - YouTube.url) -- C:\Users\jklm\Desktop\▶ Rowbury wins 3000m with leading time - Universal Sports - YouTube.url
[2013/08/02 23:50:06 | 000,000,068 | ---- | C] ()(C:\Users\jklm\Desktop\? Rowbury wins 3000m with leading time - Universal Sports - YouTube.url) -- C:\Users\jklm\Desktop\▶ Rowbury wins 3000m with leading time - Universal Sports - YouTube.url
========== Alternate Data Streams ==========
@Alternate Data Stream - 1228 bytes -> C:\Users\jklm\Desktop\noname.eml:OECustomProperty
< End of report >