Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Malware Invasion


  • This topic is locked This topic is locked

#16
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,811 posts
OK,

Can you do this for me, I want to see what I can see in a fresh set of logs.

Re-run Farbar Recovery Scan Tool (FRST/FRST64) you ran at the very beginning of this topic.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Make sure you checkmark Addition.txt box.
  • Press Scan button.
  • Scan will create two logs, FRST.txt and Addition.txt in the same directory the tool is run. Please copy and paste them to your reply.

  • 0

Advertisements


#17
TriciaDP72

TriciaDP72

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts

ok, can't run the program now because it is checking for updates with no internet connection...


  • 0

#18
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,811 posts
Try a system restore,

1. Open the Control Panel by clicking Start, and then clicking Control Panel.
2. Click System and Security, and then click System.
3. Under the Control Panel Home menu, click System protection.
4. Click System Restore.
5. Recommended Restore is the default choice. This restore is the most recent restore point and the best place to start.
6. To choose a different restore point, click Choose a different restore point, click Next and then click a restore point.
7. Click Next, and then click Finish to confirm your restore point.
8, To start the restore process, click Yes.
Once the system restore is complete, your computer will restart.
  • 0

#19
TriciaDP72

TriciaDP72

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts

ok, so the only system restore points are during the mass invasion, nothing pre-invasion so I am going to go back to the earliest restore point? and then start from the beginning? just checking to see if this is the best course of action before i click the button. this.is.crazy.

 

Tricia


  • 0

#20
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,811 posts

this.is.crazy.


The machine is badly infected, removing malware can be risky at times and things can go wrong. Find a restore point that works and at least gets connected and we will start from there.

Post a new set of logs from frst if we get connected.

Back later today at around 4pm.

Thanks
Joe :)
  • 0

#21
TriciaDP72

TriciaDP72

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts

Hi Joe (thank you SO much for all this help btw), here are the frst log and addition log, i did a restore the furthest point back i could go and was able to establish an internet connection:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:12-08-2015
Ran by Owner (administrator) on OWNER-PC (13-08-2015 07:24:11)
Running from C:\Users\Owner\Desktop
Loaded Profiles: Owner (Available Profiles: Owner)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser path: "C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe" -- "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Webroot) C:\Program Files (x86)\Webroot\WRSA.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Webroot) C:\Program Files (x86)\Webroot\WRSA.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(LeapFrog Enterprises, Inc.) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
() C:\Program Files\ASUS\ASUS Secure Delete\ADDEL.exe
(ASUS) C:\Program Files\P4G\BatteryLife.exe
() C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
() C:\Program Files (x86)\adlevel\TunePro360Updater.exe
(eLink Industry, Inc.) C:\Users\Owner\AppData\Roaming\TWV\MediaService.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Sierra Wireless, Inc.) C:\Program Files (x86)\Sierra Wireless Inc\Common\SwiCardDetect64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Intel® Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
(ASUS) C:\Windows\AsScrPro.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
() C:\Program Files (x86)\Coupon Time\updateCouponTime.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel® Corporation) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Red Bend Ltd.) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
(Windows ® Win 7 DDK provider) C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.149\SSScheduler.exe
(LeapFrog Enterprises, Inc.) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PCM4Everio\EverioService.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
(Sierra Wireless, Inc.) C:\Program Files (x86)\Sierra Wireless Inc\WebUpdater\TRUUpdater.exe
(Sierra Wireless Inc.) C:\Program Files (x86)\Sierra Wireless Inc\3G Watcher\WaHelper.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\WimaxConsole.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
() C:\Program Files (x86)\DrSpeedyPC\secure\secureupdater.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.149\McUICnt.exe
() C:\Program Files (x86)\DNS Unlocker\dnswabeno.exe
() C:\Program Files (x86)\Coupon Time\bin\utilCouponTime.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.149\McCHSvc.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(OVP development) C:\Users\Owner\AppData\Roaming\TWV\upd.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2226280 2011-06-02] (Realtek Semiconductor)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [324096 2010-05-02] (Alcor Micro Corp.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2785064 2011-05-05] (Synaptics Incorporated)
HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel® Corporation)
HKLM\...\Run: [SynAsusAcpi] => C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [97064 2011-05-05] (Synaptics Incorporated)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [Setwallpaper] => c:\programdata\SetWallpaper.cmd
HKLM\...\Run: [MRT] => C:\Windows\system32\MRT.exe [132483416 2015-08-13] (Microsoft Corporation)
HKLM\...\Run: [SpaceSoundPro] => "C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe"
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3331312 2011-09-23] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-09] (Virage Logic Corporation / Sonic Focus)
HKLM-x32\...\Run: [FLxHCIm] => C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe [43008 2011-04-08] (Windows ® Win 7 DDK provider)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-23] ()
HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [WRSVC] => C:\Program Files (x86)\Webroot\WRSA.exe [822728 2015-07-27] (Webroot)
HKLM-x32\...\Run: [Monitor] => C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe [106496 2013-10-31] (LeapFrog Enterprises, Inc.)
HKLM-x32\...\Run: [EverioService] => C:\Program Files (x86)\CyberLink\PCM4Everio\EverioService.exe [151552 2007-11-01] (CyberLink Corp.)
HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [300472 2010-05-12] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [976320 2009-12-03] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [TRUUpdater] => C:\Program Files (x86)\Sierra Wireless Inc\WebUpdater\TRUUpdater.exe [570736 2010-07-13] (Sierra Wireless, Inc.)
HKLM-x32\...\Run: [WatcherHelper] => C:\Program Files (x86)\Sierra Wireless Inc\3G Watcher\WaHelper.exe [103792 2010-06-23] (Sierra Wireless Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
HKLM-x32\...\Run: [BrowserPlugInHelper] => C:\Program Files (x86)\iSkysoft\Video Converter Ultimate\BrowserPlugInHelper.exe [400896 2013-01-19] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2020704 2014-07-09] (Wondershare)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-04-18] (Apple Inc.)
HKLM-x32\...\Run: [gmsd_us_005010055] => [X]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3206371679-4115178929-761777742-1000\...\Run: [EPSON NX420 Series] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGCA.EXE [224768 2009-09-14] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3206371679-4115178929-761777742-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-3206371679-4115178929-761777742-1000\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-3206371679-4115178929-761777742-1000\...\Run: [com.apple.dav.bookmarks.daemon] => C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
HKU\S-1-5-21-3206371679-4115178929-761777742-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53661824 2015-07-28] (Skype Technologies S.A.)
HKU\S-1-5-21-3206371679-4115178929-761777742-1000\...\Run: [GoogleChromeAutoLaunch_9C0C11CE362BB547A69B6E9BF20A1C96] => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe [770048 2015-05-11] (Crossbrowse)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk [2011-09-23]
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk [2011-11-15]
ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install Webroot FF RunOnce.lnk [2012-11-15]
ShortcutTarget: Install Webroot FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\wruninstall.exe (Webroot Software, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install Webroot IE RunOnce.lnk [2012-11-15]
ShortcutTarget: Install Webroot IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\wruninstall.exe (Webroot Software, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2012-07-02]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.149\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk [2011-09-23]
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk [2011-09-23]
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\crossbrowse.lnk [2015-08-08]
ShortcutTarget: crossbrowse.lnk -> C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe (Crossbrowse)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3206371679-4115178929-761777742-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.trovi.com/?gd=&ctid=CT3333887&octid=EB_ORIGINAL_CTID&ISID=M3C8A0B2F-1FE5-42B5-927C-787973A1EAEE&SearchSource=55&CUI=&UM=8&UP=SP1F6B56EB-6ADD-474D-AB94-E47A608388C1&D=080815&SSPV=
HKU\S-1-5-21-3206371679-4115178929-761777742-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3206371679-4115178929-761777742-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3206371679-4115178929-761777742-1000 -> {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3333887&octid=EB_ORIGINAL_CTID&ISID=M3C8A0B2F-1FE5-42B5-927C-787973A1EAEE&SearchSource=58&CUI=&UM=8&UP=SP1F6B56EB-6ADD-474D-AB94-E47A608388C1&D=080815&q={searchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-3206371679-4115178929-761777742-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar64.dll [2012-11-15] ()
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06] (Adobe Systems Incorporated)
BHO-x32: Babylon toolbar helper -> {2EECD738-5844-4a99-B4B6-146BF802613B} -> C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll [2011-08-14] (Babylon BHO)
BHO-x32: TunePro360 -> {5E04457F-D6D4-4A7E-8277-5EF1CA591CC7} -> C:\Program Files (x86)\adlevel\TunePRO360.dll No File
BHO-x32: SpecialSavings -> {74F475FA-6C75-43BD-AAB9-ECDA6184F600} -> C:\Program Files (x86)\SpecialSavings\SpecialSavingsSinged.dll [2011-12-18] (SpecialSavings)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-09-02] (Oracle Corporation)
BHO-x32: drspeedypc -> {768919B3-C6AD-47D4-94E9-A4A2FBA8A83D} -> C:\Program Files (x86)\DrSpeedyPC\secure\drspeedypc.dll [2015-05-26] (drspeedypc)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: iSkysoft Video Converter Ultimate -> {C7C3BC26-4F2B-4997-A3CB-163337FE975B} -> C:\Program Files (x86)\iSkysoft\Video Converter Ultimate\SVRIEPlugin.dll [2013-01-19] (iSkysoft Software Co., Ltd.)
BHO-x32: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar.dll [2012-11-15] ()
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-03-01] (Microsoft Corporation.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-09-02] (Oracle Corporation)
Toolbar: HKLM - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar64.dll [2012-11-15] ()
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-03-01] (Microsoft Corporation.)
Toolbar: HKLM-x32 - Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll [2011-08-14] (Babylon Ltd.)
Toolbar: HKLM-x32 - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar.dll [2012-11-15] ()
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2010-05-12] (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2010-05-12] (Citrix Systems, Inc.)
Winsock: Catalog9 01 C:\Windows\SysWOW64\Peakoar.dll [283488 2015-08-08] ()
Winsock: Catalog9 02 C:\Windows\SysWOW64\Peakoar.dll [283488 2015-08-08] ()
Winsock: Catalog9 03 C:\Windows\SysWOW64\Peakoar.dll [283488 2015-08-08] ()
Winsock: Catalog9 04 C:\Windows\SysWOW64\Peakoar.dll [283488 2015-08-08] ()
Winsock: Catalog9 16 C:\Windows\SysWOW64\Peakoar.dll [283488 2015-08-08] ()
Winsock: Catalog9-x64 01 C:\Windows\system32\Peakoar64.dll [353632 2015-08-08] ()
Winsock: Catalog9-x64 02 C:\Windows\system32\Peakoar64.dll [353632 2015-08-08] ()
Winsock: Catalog9-x64 03 C:\Windows\system32\Peakoar64.dll [353632 2015-08-08] ()
Winsock: Catalog9-x64 04 C:\Windows\system32\Peakoar64.dll [353632 2015-08-08] ()
Winsock: Catalog9-x64 16 C:\Windows\system32\Peakoar64.dll [353632 2015-08-08] ()
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 205.171.2.25
Tcpip\..\Interfaces\{086893CE-DFF2-436F-A597-AF439872C8A2}: [NameServer] 82.163.143.152,82.163.142.154
Tcpip\..\Interfaces\{086893CE-DFF2-436F-A597-AF439872C8A2}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{45142FFD-8A27-4A5D-AB0C-21C3D33841BA}: [NameServer] 82.163.143.152,82.163.142.154
Tcpip\..\Interfaces\{B6E6BE54-A718-4AF6-95D1-75DB49F73055}: [NameServer] 82.163.143.152,82.163.142.154
Tcpip\..\Interfaces\{B6E6BE54-A718-4AF6-95D1-75DB49F73055}: [DhcpNameServer] 192.168.0.1 205.171.2.25

FireFox:
========
FF ProfilePath: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default
FF SelectedSearchEngine: Trovi
FF NewTab: about:newtab
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-08-07] ()
FF Plugin: @bestbuy.com/npBestBuyPcAppDetector,version=1.0 -> C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll [2011-06-30] (Best Buy)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-08-07] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin-x32: @bestbuy.com/npBestBuyPcAppDetector,version=1.0 -> C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll [2011-06-30] (Best Buy)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-09-02] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-09-02] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-08-08] (globalUpdate)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [2015-08-08] (globalUpdate)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-27] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-27] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2011-06-06] (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\user.js [2015-08-08]
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\CCMSDK.dll [2010-05-12] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\cgpcfg.dll [2010-05-12] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\CgpCore.dll [2010-05-12] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\confmgr.dll [2010-05-12] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxlogging.dll [2010-05-12] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxmui.dll [2010-05-12] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icafile.dll [2010-05-12] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icalogon.dll [2010-05-12] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npicaN.dll [2010-05-12] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2015-05-10] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2015-05-10] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2015-05-10] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2015-05-10] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2015-05-10] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll [2015-05-10] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll [2015-05-10] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\sslsdk_b.dll [2010-04-14] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\TcpPServ.dll [2010-05-12] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Owner\AppData\Roaming\mozilla\plugins\npatgpc.dll [2012-03-03] (Cisco WebEx LLC)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\findit.xml [2015-08-08]
FF Extension: No Name - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\Extensions\[email protected] [2012-03-18]
FF Extension: Webroot - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\Extensions\{8ac62a8b-8b3f-43ba-9b1a-90c299b9dfda} [2012-11-15]
FF Extension: FireFTP - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\Extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f} [2015-06-15]
FF Extension: Ghostery - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\Extensions\[email protected] [2013-08-21]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\temp [2015-08-08]
FF Extension: DrSpeedyPc - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\{88d83554-2fdc-4bb9-8dcd-f2d46d175f88} [2015-08-13]
FF HKLM\...\Firefox\Extensions: [{0a0e29f6-0ab0-44e1-a98e-bd050ee692ec}] - C:\Program Files\shopperz04082015\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{845257EF-A892-484e-8EB0-47F563D75939}] - C:\Program Files (x86)\iSkysoft\Video Converter Ultimate\SVRFirefoxExt
FF Extension: No Name - C:\Program Files (x86)\iSkysoft\Video Converter Ultimate\SVRFirefoxExt [2013-03-24]
FF HKLM-x32\...\Firefox\Extensions: [{0a0e29f6-0ab0-44e1-a98e-bd050ee692ec}] - C:\Program Files\shopperz04082015\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{969a43f0-fd3b-4026-aa4b-af70ac7c9d9c}] - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\{969a43f0-fd3b-4026-aa4b-af70ac7c9d9c}
FF HKLM-x32\...\Firefox\Extensions: [{88d83554-2fdc-4bb9-8dcd-f2d46d175f88}] - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\{88d83554-2fdc-4bb9-8dcd-f2d46d175f88}
FF HKU\S-1-5-21-3206371679-4115178929-761777742-1000\...\Firefox\Extensions: [[email protected]] - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles/lghuf863.default\extensions\[email protected]
FF Extension: No Name - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles/lghuf863.default\extensions\[email protected] [2012-03-18]
FF HKU\S-1-5-21-3206371679-4115178929-761777742-1000\...\Firefox\Extensions: [{845257EF-A892-484e-8EB0-47F563D75939}] - C:\Program Files (x86)\iSkysoft\Video Converter Ultimate\SVRFirefoxExt

Chrome:
=======
CHR Profile: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (iSkysoft Video Converter Ultimate) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlfeafapmnniobpffacckpddijdjgpmj [2013-08-01]
CHR Extension: (No Name) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-04-21]
CHR Extension: (Webroot) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\okfhiodnpcnnnpgbjbhfebjnbagmfhab [2013-08-01]
CHR HKLM-x32\...\Chrome\Extension: [hlfeafapmnniobpffacckpddijdjgpmj] - C:\Program Files (x86)\iSkysoft\Video Converter Ultimate\SVRChromePlugin.crx [2013-03-24]
CHR HKLM-x32\...\Chrome\Extension: [okfhiodnpcnnnpgbjbhfebjnbagmfhab] - C:\ProgramData\WRData\pkg\lpchrome.crx [2012-11-15]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 DMAgent; C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [498688 2011-06-14] (Red Bend Ltd.) [File not signed]
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-08-08] (globalUpdate) [File not signed] <==== ATTENTION
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-08-08] (globalUpdate) [File not signed] <==== ATTENTION
R2 LeapFrog Connect Device Service; C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe [7393280 2013-10-31] (LeapFrog Enterprises, Inc.) [File not signed]
R3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.149\McCHSvc.exe [289256 2015-06-26] (McAfee, Inc.)
R2 MediaService; C:\Users\Owner\AppData\Roaming\TWV\MediaService.exe [115712 2015-05-21] (eLink Industry, Inc.) [File not signed]
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
R3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [272024 2006-12-19] ()
R2 SwiCardDetectSvc; C:\Program Files (x86)\Sierra Wireless Inc\Common\SwiCardDetect64.exe [284016 2010-07-13] (Sierra Wireless, Inc.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5448976 2015-04-17] (TeamViewer GmbH)
R2 Update Coupon Time; C:\Program Files (x86)\Coupon Time\updateCouponTime.exe [654576 2015-08-08] ()
R2 Util Coupon Time; C:\Program Files (x86)\Coupon Time\bin\utilCouponTime.exe [473840 2015-08-13] ()
R2 WiMAXAppSrv; C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [986112 2011-06-14] (Intel® Corporation) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
R2 WRSVC; C:\Program Files (x86)\Webroot\WRSA.exe [822728 2015-07-27] (Webroot)
S2 comyninu; C:\Program Files (x86)\07599E80-1439095677-81E1-3676-5404A63C37F3\hnsfB1D2.tmp [X]
S2 dezyloje; C:\Program Files (x86)\07599E80-1439095677-81E1-3676-5404A63C37F3\knsfD0EE.tmpfs [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 assd; C:\Windows\System32\Drivers\assd.sys [27264 2010-04-28] (ASUS Corporation)
R3 FLxHCIh; C:\Windows\System32\DRIVERS\FLxHCIh.sys [56320 2011-04-08] (Fresco Logic)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
S3 swmsflt; C:\Windows\System32\DRIVERS\swmsflt.sys [48856 2010-04-15] ()
S3 SWNC8UA3; C:\Windows\System32\DRIVERS\swnc8ua3.sys [240640 2010-06-21] (Sierra Wireless Inc.)
S3 SWUMXA3; C:\Windows\System32\DRIVERS\swumxa3.sys [210944 2010-06-21] (Sierra Wireless Inc.)
R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13832 2010-04-16] ()
R0 WRkrn; C:\Windows\System32\drivers\WRkrn.sys [116224 2015-07-27] (Webroot)
R1 {949ba8b6-a9ea-4b6b-a97d-688a70f2ea0b}Gw64; C:\Windows\System32\drivers\{949ba8b6-a9ea-4b6b-a97d-688a70f2ea0b}Gw64.sys [48784 2015-08-08] (StdLib)
S1 cherimoya; system32\drivers\cherimoya.sys [X]
S1 snqjhjan; \??\C:\Windows\system32\drivers\snqjhjan.sys [X]
S3 SWUMX20; system32\DRIVERS\swumx20.sys [X]
S1 wsafd_1_10_0_19; system32\drivers\wsafd_1_10_0_19.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-13 07:26 - 2015-08-13 05:29 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{6ec09908-795a-4141-bffa-5fa914d42b7e}Gw64.sys
2015-08-13 07:23 - 2015-08-12 17:25 - 02173952 _____ (Farbar) C:\Users\Owner\Desktop\FRST64.exe
2015-08-13 07:12 - 2015-08-13 07:12 - 00003072 _____ C:\Windows\System32\Tasks\DrspeedyPc Secure
2015-08-13 07:11 - 2015-08-13 07:12 - 00000000 ____D C:\Program Files (x86)\DrSpeedyPC
2015-08-12 15:26 - 2015-08-12 15:26 - 00016445 _____ C:\tricia.txt
2015-08-12 14:52 - 2015-08-13 07:07 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-08-12 14:52 - 2015-08-12 14:52 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-08-12 13:02 - 2015-08-12 13:03 - 00005737 _____ C:\Users\Owner\Desktop\JRT.txt
2015-08-12 12:22 - 2015-08-12 12:32 - 00000000 ____D C:\AdwCleaner
2015-08-11 22:29 - 2015-08-11 22:29 - 00025653 _____ C:\Users\Owner\Downloads\fixlist.txt
2015-08-09 21:31 - 2015-08-09 21:31 - 00000000 ____D C:\Users\Owner\AppData\Roaming\System Cleaner Pro
2015-08-09 21:30 - 2015-08-13 07:07 - 00000000 ____D C:\Program Files (x86)\System Cleaner Pro
2015-08-09 13:45 - 2015-08-09 13:45 - 00000000 _____ C:\CEC7.tmp
2015-08-09 10:15 - 2015-08-12 15:13 - 00000000 ____D C:\Users\Owner\AppData\Local\bvxvyxvec
2015-08-09 10:05 - 2015-08-09 10:06 - 00050226 _____ C:\Users\Owner\Desktop\Addition.txt
2015-08-09 10:04 - 2015-08-13 07:26 - 00033080 _____ C:\Users\Owner\Desktop\FRST.txt
2015-08-09 10:04 - 2015-08-13 07:24 - 00000000 ____D C:\FRST
2015-08-08 23:35 - 2015-08-08 23:35 - 00000000 _____ C:\Windows\SysWOW64\Number of results
2015-08-08 22:51 - 2015-08-13 07:08 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GUPlayer
2015-08-08 22:51 - 2015-08-13 07:08 - 00000000 ____D C:\Program Files (x86)\GUPlayer
2015-08-08 22:51 - 2015-08-13 07:08 - 00000000 ____D C:\Program Files (x86)\DNS Unlocker
2015-08-08 22:51 - 2015-08-08 22:51 - 00026348 _____ C:\Windows\System32\Tasks\DNSWABENO
2015-08-08 22:51 - 2015-08-08 22:51 - 00002065 _____ C:\Users\Owner\Desktop\Continue SpaceSoundPro Uninstaller.lnk
2015-08-08 22:51 - 2015-08-08 22:51 - 00001009 _____ C:\Users\Owner\Desktop\GUPlayer.lnk
2015-08-08 22:30 - 2015-08-13 07:09 - 00000378 _____ C:\Windows\Tasks\APSnotifierPP1.job
2015-08-08 22:30 - 2015-08-13 07:09 - 00000376 _____ C:\Windows\Tasks\APSnotifierPP3.job
2015-08-08 22:30 - 2015-08-13 07:09 - 00000376 _____ C:\Windows\Tasks\APSnotifierPP2.job
2015-08-08 22:30 - 2015-08-08 22:32 - 00002828 _____ C:\Windows\System32\Tasks\APSnotifierPP1
2015-08-08 22:30 - 2015-08-08 22:32 - 00002826 _____ C:\Windows\System32\Tasks\APSnotifierPP3
2015-08-08 22:30 - 2015-08-08 22:32 - 00002826 _____ C:\Windows\System32\Tasks\APSnotifierPP2
2015-08-08 22:29 - 2015-08-13 07:09 - 00000340 _____ C:\Windows\Tasks\Superclean.job
2015-08-08 22:29 - 2015-08-13 07:08 - 00000000 ____D C:\ProgramData\{4d917b50-ca18-1849-4d91-17b50ca1ed43}
2015-08-08 22:29 - 2015-08-08 22:29 - 00003252 _____ C:\Windows\System32\Tasks\Superclean
2015-08-08 22:29 - 2015-08-08 22:29 - 00000000 ____D C:\Windows\SysWOW64\Flash
2015-08-08 22:26 - 2015-08-13 07:10 - 00001018 _____ C:\Windows\Tasks\YeUBBA7OfsskP753cAqWAW4.job
2015-08-08 22:26 - 2015-08-13 07:10 - 00001016 _____ C:\Windows\Tasks\YeUBBA7OfsskP753cAqWAW.job
2015-08-08 22:26 - 2015-08-08 22:26 - 00004044 _____ C:\Windows\System32\Tasks\YeUBBA7OfsskP753cAqWAW4
2015-08-08 22:26 - 2015-08-08 22:26 - 00004042 _____ C:\Windows\System32\Tasks\YeUBBA7OfsskP753cAqWAW
2015-08-08 22:25 - 2015-08-13 07:10 - 00000970 _____ C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-08-08 22:25 - 2015-08-13 07:10 - 00000000 ____D C:\Program Files (x86)\globalUpdate
2015-08-08 22:25 - 2015-08-08 22:30 - 00000974 _____ C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2015-08-08 22:25 - 2015-08-08 22:25 - 00003972 _____ C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
2015-08-08 22:25 - 2015-08-08 22:25 - 00003718 _____ C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
2015-08-08 22:25 - 2015-08-08 22:25 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-08-08 22:24 - 2015-08-13 07:10 - 00000000 ____D C:\Program Files (x86)\adlevel
2015-08-08 22:24 - 2015-08-13 07:08 - 00000000 ____D C:\Program Files (x86)\TechVedic
2015-08-08 22:24 - 2015-08-08 22:24 - 00154826 _____ C:\Program Files (x86)\uninstaller.exe
2015-08-08 22:24 - 2015-08-08 22:24 - 00003060 _____ C:\Windows\System32\Tasks\TunePro360 Updater
2015-08-08 22:24 - 2015-08-08 22:24 - 00002528 _____ C:\Windows\system32\PeakoarOff.ini
2015-08-08 22:23 - 2015-08-13 07:10 - 00001056 _____ C:\Windows\Tasks\Crossbrowse.job
2015-08-08 22:23 - 2015-08-13 07:08 - 00000000 ____D C:\Windows\system32\aby
2015-08-08 22:23 - 2015-08-13 07:08 - 00000000 ____D C:\Users\Owner\AppData\Local\Crossbrowse
2015-08-08 22:23 - 2015-08-13 07:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crossbrowse
2015-08-08 22:23 - 2015-08-13 07:08 - 00000000 ____D C:\Program Files\shopperz04082015
2015-08-08 22:23 - 2015-08-13 07:08 - 00000000 ____D C:\Program Files (x86)\Crossbrowse
2015-08-08 22:23 - 2015-08-08 22:24 - 00004808 _____ C:\Windows\SysWOW64\Peakoar.ini
2015-08-08 22:23 - 2015-08-08 22:24 - 00002528 _____ C:\Windows\SysWOW64\PeakoarOff.ini
2015-08-08 22:23 - 2015-08-08 22:23 - 00004082 _____ C:\Windows\System32\Tasks\Crossbrowse
2015-08-08 22:23 - 2015-08-08 22:23 - 00002396 _____ C:\Users\Public\Desktop\Crossbrowse.lnk
2015-08-08 22:23 - 2015-08-02 07:50 - 00353632 _____ C:\Windows\system32\Peakoar64.dll
2015-08-08 22:23 - 2015-08-02 07:50 - 00283488 _____ C:\Windows\SysWOW64\Peakoar.dll
2015-08-08 21:54 - 2015-08-13 07:08 - 00000000 ____D C:\Program Files\SpaceSoundPro
2015-08-08 21:53 - 2015-08-13 07:10 - 00000342 ____H C:\Windows\Tasks\SFNPKXCMWVMXYUKG.job
2015-08-08 21:53 - 2015-08-13 07:10 - 00000330 _____ C:\Windows\Tasks\OMYQNNDMU1.job
2015-08-08 21:53 - 2015-08-13 07:08 - 00000000 ____D C:\Users\Owner\AppData\Local\SmartWeb
2015-08-08 21:53 - 2015-08-13 07:08 - 00000000 ____D C:\ProgramData\Service1291
2015-08-08 21:53 - 2015-08-13 07:08 - 00000000 ____D C:\ProgramData\FlashBeat
2015-08-08 21:53 - 2015-08-08 21:53 - 00004034 _____ C:\Windows\System32\Tasks\SmartWeb Upgrade Trigger Task
2015-08-08 21:53 - 2015-08-08 21:53 - 00003376 _____ C:\Windows\System32\Tasks\SFNPKXCMWVMXYUKG
2015-08-08 21:53 - 2015-08-08 21:53 - 00002852 _____ C:\Windows\System32\Tasks\OMYQNNDMU1
2015-08-08 21:50 - 2015-08-08 18:39 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{949ba8b6-a9ea-4b6b-a97d-688a70f2ea0b}Gw64.sys
2015-08-08 21:49 - 2009-06-10 14:00 - 00000824 _____ C:\Windows\system32\Drivers\etc\hp.bak
2015-08-08 21:48 - 2015-08-13 07:08 - 00000000 ____D C:\Users\Owner\AppData\Local\07599E80-1439070532-81E1-3676-5404A63C37F3
2015-08-08 21:48 - 2015-08-08 21:48 - 00003542 _____ C:\Windows\System32\Tasks\Inst_Rep
2015-08-08 21:47 - 2015-08-13 07:25 - 00000000 ____D C:\Program Files (x86)\Coupon Time
2015-08-08 21:47 - 2015-08-13 07:08 - 00000000 ____D C:\Program Files (x86)\Coupoon
2015-08-08 21:47 - 2015-08-13 07:07 - 00000000 ____D C:\Program Files (x86)\07599E80-1439095677-81E1-3676-5404A63C37F3
2015-08-08 21:46 - 2015-08-13 07:08 - 00000000 ____D C:\Users\Owner\AppData\Local\StormAlerts
2015-08-08 21:45 - 2015-08-13 07:08 - 00000000 ____D C:\Users\Owner\AppData\Roaming\TWV
2015-08-08 21:45 - 2015-08-08 21:45 - 00750096 _____ () C:\Users\Owner\Downloads\7 Wonders_ Treasures of Seven__3422_il1095080.exe
2015-08-08 21:45 - 2015-08-08 21:45 - 00003984 _____ C:\Windows\System32\Tasks\LaunchPreSignup
2015-08-08 21:45 - 2015-08-08 21:45 - 00001199 _____ C:\Users\Owner\Desktop\Continue installation .lnk
2015-08-07 23:21 - 2015-08-13 07:06 - 00000000 ____D C:\ProgramData\PopCap Games
2015-08-07 23:21 - 2015-08-07 23:21 - 00001315 _____ C:\Users\Public\Desktop\Plants vs. Zombies.lnk
2015-08-07 23:21 - 2015-08-07 23:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PopCap Games
2015-08-07 23:21 - 2015-08-07 23:21 - 00000000 ____D C:\Program Files (x86)\PopCap Games
2015-08-07 23:18 - 2015-08-07 23:19 - 42708728 _____ C:\Users\Owner\Downloads\PlantsVsZombies_20110922_EN_3_1.exe
2015-08-07 21:14 - 2015-07-25 11:07 - 00017856 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-08-07 21:14 - 2015-07-25 11:04 - 00765440 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-08-07 21:14 - 2015-07-25 11:04 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-08-07 21:14 - 2015-07-25 11:03 - 01085440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-08-07 21:14 - 2015-07-25 11:03 - 00433664 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-08-07 21:14 - 2015-07-25 11:03 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-08-07 21:14 - 2015-07-25 11:03 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-08-07 21:14 - 2015-07-25 10:55 - 01145856 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-08-07 21:13 - 2015-07-14 20:19 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-08-07 21:13 - 2015-07-14 20:19 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-08-07 21:13 - 2015-07-14 20:19 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-08-07 21:13 - 2015-07-14 20:19 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-08-07 21:13 - 2015-07-14 19:55 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-08-07 21:13 - 2015-07-14 19:55 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-08-07 21:13 - 2015-07-14 19:55 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-08-07 21:13 - 2015-07-14 19:54 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-08-07 21:13 - 2015-07-14 18:59 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-08-07 21:13 - 2015-07-14 18:52 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-08-07 21:13 - 2015-07-09 10:58 - 03154944 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-08-07 21:13 - 2015-07-09 10:58 - 02603008 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-08-07 21:13 - 2015-07-09 10:58 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-08-07 21:13 - 2015-07-09 10:58 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-08-07 21:13 - 2015-07-09 10:58 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-08-07 21:13 - 2015-07-09 10:58 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-08-07 21:13 - 2015-07-09 10:58 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-08-07 21:13 - 2015-07-09 10:58 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-08-07 21:13 - 2015-07-09 10:58 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-08-07 21:13 - 2015-07-09 10:58 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-08-07 21:13 - 2015-07-09 10:58 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-08-07 21:13 - 2015-07-09 10:43 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-08-07 21:13 - 2015-07-09 10:43 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-08-07 21:13 - 2015-07-09 10:43 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-08-07 21:13 - 2015-07-09 10:43 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-08-07 21:13 - 2015-07-09 10:42 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-08-07 21:13 - 2015-06-25 01:57 - 03207168 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-08-07 21:13 - 2015-06-01 17:07 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll
2015-08-07 21:13 - 2015-06-01 16:47 - 00210432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cewmdm.dll
2015-08-07 21:12 - 2015-07-02 14:21 - 19877376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-08-07 21:12 - 2015-07-02 14:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-08-07 21:12 - 2015-07-02 13:50 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-08-07 21:12 - 2015-07-02 13:49 - 25193984 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-08-07 21:12 - 2015-07-02 13:46 - 00479232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-08-07 21:12 - 2015-07-02 13:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-08-07 21:12 - 2015-07-02 13:23 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-08-07 21:12 - 2015-07-02 13:19 - 12855296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-08-07 21:12 - 2015-07-02 13:12 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-08-07 21:12 - 2015-07-02 12:55 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-08-07 21:12 - 2015-07-02 12:20 - 14453248 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-08-07 21:12 - 2015-07-02 11:59 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-08-07 21:12 - 2015-06-26 19:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-08-07 21:12 - 2015-06-26 19:43 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-08-07 21:12 - 2015-06-26 18:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-08-07 21:12 - 2015-06-26 18:39 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-08-07 21:12 - 2015-06-25 11:09 - 00389832 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-08-07 21:12 - 2015-06-25 10:43 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-08-07 21:12 - 2015-06-20 13:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-08-07 21:12 - 2015-06-20 12:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-08-07 21:12 - 2015-06-20 12:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-08-07 21:12 - 2015-06-20 12:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-08-07 21:12 - 2015-06-20 12:40 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-08-07 21:12 - 2015-06-20 12:39 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-08-07 21:12 - 2015-06-20 12:34 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-08-07 21:12 - 2015-06-20 12:34 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-08-07 21:12 - 2015-06-20 12:34 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-08-07 21:12 - 2015-06-20 12:25 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-07 21:12 - 2015-06-20 12:21 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-08-07 21:12 - 2015-06-20 12:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-07 21:12 - 2015-06-20 12:07 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-08-07 21:12 - 2015-06-20 12:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-08-07 21:12 - 2015-06-20 11:48 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-08-07 21:12 - 2015-06-20 11:48 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-08-07 21:12 - 2015-06-20 11:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-08-07 21:12 - 2015-06-20 11:46 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-08-07 21:12 - 2015-06-20 11:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-08-07 21:12 - 2015-06-19 11:25 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-08-07 21:12 - 2015-06-19 11:25 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-08-07 21:12 - 2015-06-19 11:24 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-08-07 21:12 - 2015-06-19 11:24 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-08-07 21:12 - 2015-06-19 11:23 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-08-07 21:12 - 2015-06-19 11:17 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-08-07 21:12 - 2015-06-19 11:16 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-08-07 21:12 - 2015-06-19 11:13 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-08-07 21:12 - 2015-06-19 11:13 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-08-07 21:12 - 2015-06-19 11:03 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-08-07 21:12 - 2015-06-19 10:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-08-07 21:12 - 2015-06-19 10:53 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-08-07 21:12 - 2015-06-19 10:52 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-08-07 21:12 - 2015-06-19 10:51 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-08-07 21:12 - 2015-06-19 10:40 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-08-07 21:12 - 2015-06-19 10:40 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-08-07 21:12 - 2015-06-19 10:39 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-08-07 21:12 - 2015-06-19 10:15 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-08-07 21:12 - 2015-06-19 10:11 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-08-07 21:12 - 2015-06-17 10:47 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-08-07 21:12 - 2015-06-17 10:37 - 00312320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-08-07 21:11 - 2015-07-04 11:07 - 02087424 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2015-08-07 21:11 - 2015-07-04 10:48 - 01414656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2015-08-07 21:11 - 2015-06-20 12:49 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-08-07 21:11 - 2015-06-20 12:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-08-07 21:11 - 2015-06-20 12:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-08-07 21:11 - 2015-06-20 11:26 - 02427392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-08-07 21:10 - 2015-07-01 13:56 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-08-07 21:10 - 2015-07-01 13:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-08-07 21:10 - 2015-07-01 13:49 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-08-07 21:10 - 2015-07-01 13:49 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-08-07 21:10 - 2015-07-01 13:49 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-08-07 21:10 - 2015-07-01 13:49 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-08-07 21:10 - 2015-07-01 13:49 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-08-07 21:10 - 2015-07-01 13:49 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-08-07 21:10 - 2015-07-01 13:49 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-08-07 21:10 - 2015-07-01 13:49 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-08-07 21:10 - 2015-07-01 13:49 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-08-07 21:10 - 2015-07-01 13:49 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-08-07 21:10 - 2015-07-01 13:49 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-08-07 21:10 - 2015-07-01 13:48 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-08-07 21:10 - 2015-07-01 13:48 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-08-07 21:10 - 2015-07-01 13:47 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-08-07 21:10 - 2015-07-01 13:47 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-08-07 21:10 - 2015-07-01 13:43 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-08-07 21:10 - 2015-07-01 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-08-07 21:10 - 2015-07-01 13:39 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-08-07 21:10 - 2015-07-01 13:30 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-08-07 21:10 - 2015-07-01 13:30 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-08-07 21:10 - 2015-07-01 13:30 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-08-07 21:10 - 2015-07-01 13:30 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-08-07 21:10 - 2015-07-01 13:30 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-08-07 21:10 - 2015-07-01 13:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-08-07 21:10 - 2015-07-01 13:30 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-08-07 21:10 - 2015-07-01 13:30 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-08-07 21:10 - 2015-07-01 13:30 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-08-07 21:10 - 2015-07-01 13:29 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-08-07 21:10 - 2015-07-01 13:29 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-08-07 21:10 - 2015-07-01 13:29 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-08-07 21:10 - 2015-07-01 13:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-08-07 21:10 - 2015-07-01 13:26 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-08-07 21:10 - 2015-07-01 13:24 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-08-07 21:10 - 2015-07-01 12:27 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-08-07 21:10 - 2015-07-01 12:26 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-08-07 21:10 - 2015-07-01 12:26 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-08-07 21:10 - 2015-06-15 14:50 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-08-07 21:10 - 2015-06-15 14:45 - 03242496 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-08-07 21:10 - 2015-06-15 14:45 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-08-07 21:10 - 2015-06-15 14:45 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2015-08-07 21:10 - 2015-06-15 14:45 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-08-07 21:10 - 2015-06-15 14:44 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2015-08-07 21:10 - 2015-06-15 14:43 - 02364416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2015-08-07 21:10 - 2015-06-15 14:43 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-08-07 21:10 - 2015-06-15 14:43 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2015-08-07 21:10 - 2015-06-15 14:42 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2015-08-07 21:10 - 2015-06-15 14:42 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2015-08-07 21:10 - 2015-06-15 14:37 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2015-08-07 21:10 - 2015-04-27 12:23 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-08-07 21:10 - 2015-04-27 12:23 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-08-07 21:10 - 2015-04-27 12:23 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-08-07 21:10 - 2015-04-27 12:23 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-08-07 21:10 - 2015-04-27 12:05 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2015-08-07 21:10 - 2015-04-27 12:04 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2015-08-07 21:10 - 2015-04-27 12:04 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2015-08-07 21:10 - 2015-04-27 12:04 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2015-07-27 08:53 - 2015-08-13 07:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2015-07-27 08:52 - 2015-08-13 07:08 - 00000000 ____D C:\Program Files\McAfee Security Scan

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-13 07:26 - 2012-03-03 17:26 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-13 07:26 - 2012-01-18 15:02 - 00000000 ____D C:\ProgramData\WRData
2015-08-13 07:26 - 2011-11-15 00:00 - 01468527 _____ C:\Windows\WindowsUpdate.log
2015-08-13 07:25 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\system32\GroupPolicy
2015-08-13 07:25 - 2009-07-13 19:34 - 00000505 _____ C:\Windows\win.ini
2015-08-13 07:23 - 2009-07-13 22:13 - 00797850 _____ C:\Windows\system32\PerfStringBackup.INI
2015-08-13 07:23 - 2009-07-13 21:51 - 00094237 _____ C:\Windows\setupact.log
2015-08-13 07:22 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\system32\NDF
2015-08-13 07:21 - 2013-08-15 08:00 - 00000000 ____D C:\Windows\system32\MRT
2015-08-13 07:19 - 2012-07-02 16:03 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Skype
2015-08-13 07:19 - 2009-07-13 21:45 - 00018736 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-13 07:19 - 2009-07-13 21:45 - 00018736 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-13 07:16 - 2012-01-18 11:33 - 132483416 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-08-13 07:10 - 2013-08-01 13:46 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-13 07:10 - 2012-01-17 21:46 - 00001415 _____ C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-13 07:10 - 2011-11-15 00:15 - 00002558 _____ C:\Windows\system32\AutoRunFilter.ini
2015-08-13 07:10 - 2011-11-15 00:15 - 00001519 _____ C:\Windows\system32\ServiceFilter.ini
2015-08-13 07:09 - 2014-05-18 15:26 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-08-13 07:09 - 2012-01-17 21:44 - 00000000 ____D C:\Users\Owner
2015-08-13 07:09 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-13 07:08 - 2015-04-06 07:55 - 00000000 ___SD C:\Windows\system32\GWX
2015-08-13 07:08 - 2014-12-14 21:45 - 00000000 ____D C:\Windows\system32\appraiser
2015-08-13 07:08 - 2014-09-02 16:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-08-13 07:08 - 2013-08-01 13:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-13 07:08 - 2012-11-15 07:32 - 00000000 ____D C:\Users\Owner\AppData\Local\lptmp660068200
2015-08-13 07:08 - 2012-07-02 00:28 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2015-08-13 07:08 - 2012-03-18 18:45 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VideoConverter
2015-08-13 07:08 - 2012-03-18 18:45 - 00000000 ____D C:\Program Files (x86)\VideoConverter
2015-08-13 07:08 - 2012-03-18 18:44 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpecialSavings
2015-08-13 07:08 - 2012-03-18 18:44 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AudioConverter
2015-08-13 07:08 - 2012-03-18 18:44 - 00000000 ____D C:\Users\Owner\AppData\Local\Babylon
2015-08-13 07:08 - 2012-03-18 18:44 - 00000000 ____D C:\ProgramData\IBUpdaterService
2015-08-13 07:08 - 2012-03-18 18:44 - 00000000 ____D C:\Program Files (x86)\SpecialSavings
2015-08-13 07:08 - 2012-01-18 15:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webroot SecureAnywhere
2015-08-13 07:08 - 2012-01-18 15:01 - 00000000 ____D C:\Program Files (x86)\Webroot
2015-08-13 07:08 - 2012-01-17 21:44 - 00000000 ___RD C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-13 07:08 - 2012-01-17 21:44 - 00000000 ___RD C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-13 07:08 - 2011-11-15 00:14 - 00000000 ____D C:\ProgramData\P4G
2015-08-13 07:08 - 2011-11-15 00:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Best Buy Connect
2015-08-13 07:08 - 2011-11-15 00:13 - 00000000 ____D C:\Program Files (x86)\Best Buy Connect
2015-08-13 07:08 - 2011-09-23 05:52 - 00000000 ____D C:\ProgramData\Best Buy pc app
2015-08-13 07:08 - 2009-07-13 20:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-13 07:08 - 2009-07-13 20:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-13 07:08 - 2009-07-13 20:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-13 07:08 - 2009-07-13 20:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-13 07:08 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-08-13 07:07 - 2012-03-18 18:44 - 00000000 ____D C:\Program Files (x86)\BabylonToolbar
2015-08-13 07:07 - 2012-03-18 18:44 - 00000000 ____D C:\Program Files (x86)\AudioConverter
2015-08-13 07:07 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\registration
2015-08-13 07:06 - 2014-09-02 16:21 - 00000000 ____D C:\Program Files (x86)\Java
2015-08-09 10:04 - 2012-01-17 21:45 - 00000000 ____D C:\Users\Owner\AppData\Local\VirtualStore
2015-08-09 09:21 - 2015-07-10 06:39 - 00000000 ___HD C:\$Windows.~BT
2015-08-09 09:03 - 2009-07-28 23:03 - 00000000 ____D C:\Windows\Panther
2015-08-08 22:59 - 2012-01-17 21:46 - 00000000 ____D C:\Users\Owner\AppData\Local\Deployment
2015-08-08 22:37 - 2013-10-12 10:34 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-08-08 22:24 - 2015-06-15 08:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-08 22:24 - 2011-09-23 05:27 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2015-08-08 22:24 - 2011-09-23 05:27 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2015-08-08 22:00 - 2013-08-01 13:46 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-08 21:51 - 2012-01-17 21:45 - 00045056 _____ C:\Windows\system32\acovcnt.exe
2015-08-08 21:35 - 2012-07-02 16:03 - 00000000 ____D C:\ProgramData\Skype
2015-08-07 23:37 - 2013-10-12 10:34 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-08-07 23:37 - 2012-07-02 00:28 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-08-07 23:37 - 2012-07-02 00:28 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-08-07 23:21 - 2009-07-13 22:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-08-07 23:14 - 2009-07-13 21:45 - 00347432 _____ C:\Windows\system32\FNTCACHE.DAT
2015-08-07 23:12 - 2015-04-06 07:55 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-08-07 21:18 - 2013-08-01 13:46 - 00002185 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-02 19:48 - 2012-10-07 19:02 - 00000000 ____D C:\Users\Owner\Desktop\delti pics
2015-07-27 08:55 - 2013-08-01 13:46 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-07-27 08:55 - 2013-08-01 13:46 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-07-27 08:55 - 2012-01-18 15:02 - 00166128 _____ (Webroot) C:\Windows\SysWOW64\WRusr.dll
2015-07-27 08:55 - 2012-01-18 15:02 - 00116224 _____ (Webroot) C:\Windows\system32\Drivers\WRkrn.sys
2015-07-27 08:55 - 2012-01-18 15:02 - 00103816 _____ (Webroot) C:\Windows\system32\WRusr.dll
2015-07-27 08:53 - 2012-07-02 00:28 - 00001936 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2015-07-27 08:52 - 2015-04-15 11:19 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-07-27 08:49 - 2012-05-05 18:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-07-27 08:49 - 2011-09-23 05:39 - 00376934 _____ C:\Windows\PFRO.log

==================== Files in the root of some directories =======

2015-05-12 16:22 - 2015-05-12 16:22 - 0099678 _____ () C:\Program Files (x86)\tunepro138x138.ico
2015-08-08 22:24 - 2015-08-08 22:24 - 0154826 _____ () C:\Program Files (x86)\uninstaller.exe
2012-11-15 07:32 - 2012-11-15 07:32 - 9842040 _____ (Webroot Software, Inc.) C:\Program Files (x86)\Common Files\wruninstall.exe
2015-04-14 09:28 - 2015-04-14 09:28 - 0004387 _____ () C:\Users\Owner\AppData\Roaming\DK8is89dyPzmla2uemyT3
2015-04-19 05:20 - 2015-04-19 05:20 - 0005872 _____ () C:\Users\Owner\AppData\Roaming\dum3wyST49Ex
2014-09-24 21:56 - 2014-09-24 21:56 - 0000000 _____ () C:\Users\Owner\AppData\Roaming\MLib.tmp
2014-09-24 21:56 - 2014-09-24 21:56 - 0000000 _____ () C:\Users\Owner\AppData\Roaming\SBLib.tmp
2015-04-20 07:05 - 2015-04-20 07:05 - 1246720 _____ () C:\Users\Owner\AppData\Roaming\YeUBBA7OfsskP753cAqWAW.exe
2015-04-20 07:05 - 2015-04-20 07:05 - 1579520 _____ () C:\Users\Owner\AppData\Roaming\YeUBBA7OfsskP753cAqWAW4.exe
2011-11-15 00:19 - 2011-11-15 00:19 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2011-11-15 00:18 - 2011-11-15 00:19 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log

Some files in TEMP:
====================
C:\Users\Owner\AppData\Local\Temp\011md0gh.dll
C:\Users\Owner\AppData\Local\Temp\1349.exe
C:\Users\Owner\AppData\Local\Temp\2218.exe
C:\Users\Owner\AppData\Local\Temp\2958.exe
C:\Users\Owner\AppData\Local\Temp\3019.exe
C:\Users\Owner\AppData\Local\Temp\3355.exe
C:\Users\Owner\AppData\Local\Temp\7 Wonders_ Treasures of Seven__3422_il1095080.exe
C:\Users\Owner\AppData\Local\Temp\fsd1B8B.exe
C:\Users\Owner\AppData\Local\Temp\fsd9BE1.exe
C:\Users\Owner\AppData\Local\Temp\fuf21D2.exe
C:\Users\Owner\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Owner\AppData\Local\Temp\mVOA4B7.exe
C:\Users\Owner\AppData\Local\Temp\oprun10083.exe
C:\Users\Owner\AppData\Local\Temp\oprun32466.exe
C:\Users\Owner\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Owner\AppData\Local\Temp\SpOrder.dll
C:\Users\Owner\AppData\Local\Temp\supoptsetup.exe
C:\Users\Owner\AppData\Local\Temp\Uninstall.exe
C:\Users\Owner\AppData\Local\Temp\UninstallModule.exe
C:\Users\Owner\AppData\Local\Temp\vcredist_x86.exe
C:\Users\Owner\AppData\Local\Temp\WRupdate325230.exe
C:\Users\Owner\AppData\Local\Temp\WRupdate327258.exe
C:\Users\Owner\AppData\Local\Temp\WRupdate336306.exe
C:\Users\Owner\AppData\Local\Temp\WRupdate372265.exe
C:\Users\Owner\AppData\Local\Temp\_is8A63.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll
[2011-09-23 05:27] - [2015-08-08 22:24] - 0357888 ____A (Microsoft Corporation) 67529135895CE87AD5B2C33F4CBFE4F1

C:\Windows\SysWOW64\dnsapi.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-06-09 23:01

==================== End of log ============================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:12-08-2015
Ran by Owner (2015-08-13 07:27:04)
Running from C:\Users\Owner\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3206371679-4115178929-761777742-500 - Administrator - Disabled)
Guest (S-1-5-21-3206371679-4115178929-761777742-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3206371679-4115178929-761777742-1002 - Limited - Enabled)
Owner (S-1-5-21-3206371679-4115178929-761777742-1000 - Administrator - Enabled) => C:\Users\Owner

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Webroot SecureAnywhere (Enabled - Up to date) {66A6FE14-08CB-F415-3742-517201416109}
AS: Webroot SecureAnywhere (Enabled - Up to date) {DDC71FF0-2EF1-FB9B-0DF2-6A007AC62BB4}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.0.32.18 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
Adobe Reader X (10.1.0) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.0 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM-x32\...\InstallShield_{1F7424F8-F992-48BC-90EF-7C4DB0405E3F}) (Version: 1.7.17.25416 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.7.17.25416 - Alcor Micro Corp.) Hidden
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ASUS AI Recovery (HKLM-x32\...\{38253529-D97D-4901-AE53-5CC9736D3A2E}) (Version: 1.0.13 - ASUS)
ASUS FancyStart (HKLM-x32\...\{2B81872B-A054-48DA-BE3B-FA5C164C303A}) (Version: 1.0.8 - ASUSTeK Computer Inc.)
ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.21 - ASUS)
ASUS Live Update (HKLM-x32\...\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}) (Version: 2.5.9 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.1.43 - ASUS)
ASUS Secure Delete (HKLM\...\{761C6783-D3BC-48AB-8E7C-61CE918A8436}) (Version: 1.00.0006 - ASUS)
ASUS SmartLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0011 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0031 - ASUS)
ASUS U Series ScreenSaver (HKLM-x32\...\ASUS U Series ScreenSaver) (Version: 1.0.0002 - ASUS)
ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.21 - asus)
AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.6.125 - ASUSTEK)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0008 - ASUS)
AudioConverter (HKLM-x32\...\AudioConverter) (Version:  - PerformerSoft LLC) <==== ATTENTION
Babylon toolbar on IE (HKLM-x32\...\BabylonToolbar) (Version:  - ) <==== ATTENTION
Best Buy Connect (HKLM-x32\...\{B435FD87-CA14-45E3-9D0B-A30F1F9F3866}) (Version: 3.00.68 - Best Buy)
Best Buy pc app (HKU\S-1-5-21-3206371679-4115178929-761777742-1000\...\e55b814e55744b76) (Version: 3.2.545.3 - Best Buy)
Best Buy pc app (Version: 3.2.2.0 - Best Buy) Hidden
Best Buy pc app (x32 Version: 3.2.2.0 - Best Buy) Hidden
Bing Bar (HKLM-x32\...\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}) (Version: 7.0.610.0 - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Citrix online plug-in (Web) (HKLM-x32\...\{B124E6D3-91B4-4E3C-AD03-BA959B223537}) (Version: 12.0.3.6 - Citrix Systems, Inc.)
Crossbrowse (HKLM-x32\...\Crossbrowse) (Version: 39.6.2171.95 - The Crossbrowse Authors) <==== ATTENTION
CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1908 - CyberLink Corp.)
CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3602c - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Digital Photo Navigator 1.5 (HKLM-x32\...\{CF9CD37C-E29A-11D5-AE3D-005004B8E30C}) (Version:  - )
DNS Unlocker version 1.3 (HKLM-x32\...\{E1527582-8509-4011-B922-29E3FB548882}_is1) (Version: 1.3 - www.vidcreek.tv) <==== ATTENTION
DrSpeedyPC (HKLM-x32\...\DrSpeedyPC) (Version:  - )
Epson Event Manager (HKLM-x32\...\{03B8AA32-F23C-4178-B8E6-09ECD07EAA47}) (Version: 2.40.0001 - SEIKO EPSON CORPORATION)
EPSON NX420 Series Printer Uninstall (HKLM\...\EPSON NX420 Series) (Version:  - SEIKO EPSON Corporation)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.10 - ASUS)
Free M4a to MP3 Converter 7.2 (HKLM-x32\...\Free M4a to MP3 Converter_is1) (Version:  - ManiacTools.com)
Fresco Logic USB3.0 Host Controller (HKLM\...\{B1E301A1-C2B4-4B0B-AF31-C71F8A53DCDA}) (Version: 3.0.119.1 - Fresco Logic Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 44.0.2403.130 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
GUPlayer (remove only) (HKU\S-1-5-21-3206371679-4115178929-761777742-1000\...\GUPlayer) (Version:  - ) <==== ATTENTION
iCloud (HKLM\...\{2AAF09D5-4B3F-4975-B6A9-ECE2631FC942}) (Version: 4.0.5.20 - Apple Inc.)
iExplorer 3.7.4.0 (HKLM-x32\...\{7FD8B0C1-CDDA-4B4D-A577-B2E3570EA3A3}_is1) (Version:  - Macroplant LLC)
Intel PROSet Wireless (x32 Version:  - ) Hidden
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2291 - Intel Corporation)
Intel® PROSet/Wireless WiFi Software (HKLM\...\{3C41721F-AF0F-4086-AA1C-4C7F29076228}) (Version: 14.01.1000 - Intel Corporation)
Intel® Turbo Boost Technology Monitor (HKLM\...\{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}) (Version: 1.0.400.4 - Intel)
Intel® WiDi (HKLM-x32\...\{25680C01-6753-4FE9-A891-7857F26457C1}) (Version: 2.1.35.0 - Intel Corporation)
Intel® Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
Intel® PROSet/Wireless WiMAX Software (HKLM\...\{5C1DA3D9-F590-4317-A4FB-274F658E504B}) (Version: 6.05.0000 - Intel Corporation)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.32 - Irfan Skiljan)
iSkysoft Video Converter Ultimate(Build 4.0.1.0) (HKLM-x32\...\iSkysoft Video Converter Ultimate_is1) (Version: 4.0.1.0 - iSkysoft Software)
iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LeapFrog Connect (HKLM-x32\...\UPCShell) (Version: 5.1.26.18340 - LeapFrog)
LeapFrog Connect (x32 Version: 5.1.26.18340 - LeapFrog) Hidden
LeapFrog LeapPad Explorer Plugin (x32 Version: 5.1.26.18340 - LeapFrog) Hidden
LeapFrog MyOwnLeaptop Plugin (x32 Version: 5.1.26.18340 - LeapFrog) Hidden
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.149.2 - McAfee, Inc.)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 38.0.5 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 38.0.5 (x86 en-US)) (Version: 38.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla)
Mozilla Thunderbird 15.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Thunderbird 15.0.1 (x86 en-US)) (Version: 15.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Plants vs. Zombies (HKLM-x32\...\Plants vs. Zombies) (Version:  - PopCap Games)
PowerCinema NE for Everio (HKLM-x32\...\{39CEE1F2-12B6-4C50-9131-04BFCA110578}) (Version:  - )
PowerDirector Express (HKLM-x32\...\{EDE721EC-870A-11D8-9D75-000129760D75}) (Version:  - )
PowerProducer (HKLM-x32\...\{B7A0CE06-068E-11D6-97FD-0050BACBF861}) (Version: 074511a(3.7)_Vista_JVC - CyberLink Corp.)
QuickTime (HKLM-x32\...\{0E64B098-8018-4256-BA23-C316A43AD9B0}) (Version: 7.72.80.56 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6392 - Realtek Semiconductor Corp.)
SceneSwitch (HKLM-x32\...\{5172E572-C175-4F80-A6D5-5CB45826AD61}) (Version: 1.0.6 - ASUS)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Sierra Wireless AirCard Watcher (HKLM-x32\...\{7AC21DE8-2904-4667-99C7-732A02B1324E}) (Version: 6.0.2699.6301 - Sierra Wireless Inc.)
Skype™ 7.7 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.7.103 - Skype Technologies S.A.)
Sonic Focus (HKLM-x32\...\{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}) (Version: 1.0.0.4 - Synopsys )
SpecialSavings (HKLM-x32\...\SpecialSavings) (Version:  - ) <==== ATTENTION
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.6.0 - Synaptics Incorporated)
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.41459 - TeamViewer)
Updater Service (HKLM-x32\...\Updater Service) (Version: 11,6,20,2 - ) <==== ATTENTION
Use the entry named LeapFrog Connect to uninstall (LeapFrog LeapPad Explorer Plugin) (HKLM-x32\...\LeapPadExplorerPlugin) (Version:  - LeapFrog)
Use the entry named LeapFrog Connect to uninstall (LeapFrog MyOwnLeaptop Plugin) (HKLM-x32\...\LeaptopPlugin) (Version:  - LeapFrog)
VideoConverter (HKLM-x32\...\VideoConverter) (Version:  - PerformerSoft LLC) <==== ATTENTION
Webroot SecureAnywhere (HKLM-x32\...\WRUNINST) (Version: 9.0.1.35 - Webroot)
Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net  (09/10/2009 02.03.05.012) (HKLM\...\8F14F2ECEDE68D26EA515B48DC25B39103C4FE8D) (Version: 09/10/2009 02.03.05.012 - Leapfrog)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.31.1 - ASUS)
Wireless Console 3 (HKLM-x32\...\{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}) (Version: 3.0.19 - ASUS)
Wondershare Video Editor(Build 4.6.0) (HKLM-x32\...\Wondershare Video Editor_is1) (Version:  - Wondershare Software)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================

09-08-2015 00:16:17 Windows Update
11-08-2015 22:22:39 Removed Java 7 Update 67
11-08-2015 22:33:12 Restore Point Created by FRST
12-08-2015 12:45:45 JRT Pre-Junkware Removal
13-08-2015 07:03:30 Restore Operation
13-08-2015 07:15:17 Windows Update

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 19:34 - 2009-06-10 14:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {008CF8DA-6DE9-4DC6-A075-0FAB8521E08F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-01] (Google Inc.)
Task: {1290AA52-EC88-4431-8DB1-A12AFAB33ACC} - System32\Tasks\OMYQNNDMU1 => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: {184AC837-F3CE-4D07-A0B9-E34D8CCE8B7A} - System32\Tasks\SmartWeb Upgrade Trigger Task => C:\Users\Owner\AppData\Local\SmartWeb\SmartWebHelper.exe <==== ATTENTION
Task: {209793CF-2F7A-46BB-94E7-5839D7F1D0EC} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-08-08] (globalUpdate) <==== ATTENTION
Task: {23DBCB30-02B3-4C4A-9BDB-E6F772CB7BED} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2010-11-15] (ASUS)
Task: {2A6EA2D8-85D7-4D91-B0F4-FEF81D8DC820} - System32\Tasks\Crossbrowse => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe [2015-08-08] () <==== ATTENTION
Task: {570A1AD0-975E-4E8B-8C79-A55973A92FE2} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {5A83F9D6-EB46-425F-B12F-89B5768FF848} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS)
Task: {66BF42E4-3DEC-46B5-9173-08F913E4966C} - System32\Tasks\DNSWABENO => C:\Program Files (x86)\DNS Unlocker\dnswabeno.exe [2015-07-15] ()
Task: {6A2D9BBF-9585-4DB7-871A-2C50751E5942} - \AdobeFlashPlayerUpdate 2 -> No File <==== ATTENTION
Task: {7258C0C7-1D18-4A99-9C7D-7D094BA06E37} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2010-08-02] (ASUS)
Task: {73BF7A7B-53F0-4B43-9B19-5F45809C414D} - System32\Tasks\bProtector => Sc.exe start bProtector
Task: {7BE0C2FB-9FED-4218-9C95-2F75C6CD836F} - System32\Tasks\LaunchPreSignup => C:\Program Files (x86)\OLBPre\OLBPre.exe <==== ATTENTION
Task: {8AA9E63F-BF5B-4896-9C74-09383AAA3A30} - System32\Tasks\YeUBBA7OfsskP753cAqWAW4 => C:\Users\Owner\AppData\Roaming\YeUBBA7OfsskP753cAqWAW4.exe [2015-04-20] () <==== ATTENTION
Task: {92FEAD3D-5CA4-414D-8242-01D83E308F78} - System32\Tasks\YeUBBA7OfsskP753cAqWAW => C:\Users\Owner\AppData\Roaming\YeUBBA7OfsskP753cAqWAW.exe [2015-04-20] () <==== ATTENTION
Task: {9F9CBAFE-4063-4658-AAC8-5A7E770711BB} - System32\Tasks\Superclean => c:\programdata\{4d917b50-ca18-1849-4d91-17b50ca1ed43}\hqghumeaylnlf.exe [2014-08-08] (Super PC Tools Ltd) <==== ATTENTION
Task: {A0B36402-EBDA-4D05-B40A-5151EC10AD82} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-08-08] (globalUpdate) <==== ATTENTION
Task: {A0DCA9D5-BBBE-427D-90C1-1F3E9877CE95} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-07] (Adobe Systems Incorporated)
Task: {A1C5E39C-8392-481E-9CA2-4F070AEA782B} - System32\Tasks\TunePro360 Updater => C:\Program Files (x86)\adlevel\TunePro360Updater.exe [2015-08-08] ()
Task: {AD3C4602-C0E1-4CA4-9E72-AA85A1480A45} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {B01A05AD-48EF-48F7-98F8-9452D0B1F72F} - System32\Tasks\ASUS Patch 10430001 => C:\Windows\AsPatch10430001.exe [2010-07-29] ()
Task: {CA586909-A8D8-4F2F-8AED-F473EB14C968} - \AdobeFlashPlayerUpdate -> No File <==== ATTENTION
Task: {CC694E9E-259C-48EB-89AC-4BB0B713F4F5} - System32\Tasks\ASUS Secure Delete => C:\Program Files\ASUS\ASUS Secure Delete\ADDEL.exe [2010-05-11] ()
Task: {CE285F28-DC0D-45B2-A41F-C5D768861CC4} - System32\Tasks\DrspeedyPc Secure => C:\Program Files (x86)\DrSpeedyPC\secure\secureupdater.exe [2015-05-26] () <==== ATTENTION
Task: {DE63DC20-24F5-4278-B4C8-20D688B15AF6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-01] (Google Inc.)
Task: {E57A1D11-C2B9-4423-904C-45352BA05DEC} - System32\Tasks\SFNPKXCMWVMXYUKG => C:\ProgramData\Service1291\Service1291.exe [2015-06-28] () <==== ATTENTION
Task: {EB31BCEC-BF3F-4549-A96F-225D0B175682} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-12-01] (ASUS)
Task: {F0BF0259-B9B1-43EF-AC92-D47976342F14} - System32\Tasks\Inst_Rep => C:\Users\Owner\AppData\Local\Installer\Install_24213\DCbrakieamo_amobl_setup.exe [2015-08-08] ()
Task: {F2EFC929-73AC-457B-AF5A-0C7E2E09177E} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {F9CF4761-D978-4B2F-9A08-1D88C88CDF51} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe [2007-11-30] ()

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\Crossbrowse.job => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\OMYQNNDMU1.job => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: C:\Windows\Tasks\SFNPKXCMWVMXYUKG.job => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: C:\Windows\Tasks\Superclean.job => c:\programdata\{4d917b50-ca18-1849-4d91-17b50ca1ed43}\hqghumeaylnlf.exe <==== ATTENTION
Task: C:\Windows\Tasks\YeUBBA7OfsskP753cAqWAW.job => C:\Users\Owner\AppData\Roaming\YeUBBA7OfsskP753cAqWAW.exe <==== ATTENTION
Task: C:\Windows\Tasks\YeUBBA7OfsskP753cAqWAW4.job => C:\Users\Owner\AppData\Roaming\YeUBBA7OfsskP753cAqWAW4.exe <==== ATTENTION

==================== Loaded Modules (Whitelisted) ==============

2015-08-08 22:23 - 2015-08-02 07:50 - 00353632 _____ () C:\Windows\system32\Peakoar64.dll
2011-05-02 14:41 - 2011-05-02 14:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2013-03-24 20:43 - 2013-01-08 10:32 - 00721917 _____ () C:\Windows\SysWOW64\ISCM64.dll
2010-04-02 20:21 - 2008-10-01 00:08 - 00011264 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2010-05-11 18:35 - 2010-05-11 18:35 - 00489392 _____ () C:\Program Files\ASUS\ASUS Secure Delete\ADDEL.exe
2010-07-14 17:11 - 2010-07-14 17:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll
2011-11-15 00:14 - 2007-11-30 12:20 - 00051768 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
2015-06-16 01:42 - 2015-08-08 22:24 - 01928704 _____ () C:\Program Files (x86)\adlevel\TunePro360Updater.exe
2015-08-08 22:37 - 2015-08-08 22:37 - 00654576 _____ () C:\Program Files (x86)\Coupon Time\updateCouponTime.exe
2012-01-21 23:41 - 2006-12-19 15:23 - 00272024 ____N () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2011-07-15 01:15 - 2011-05-05 05:30 - 00057640 _____ () C:\Program Files\Synaptics\SynTP\SynTPEnhPS.dll
2011-05-02 14:41 - 2011-05-02 14:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2011-07-15 01:14 - 2011-01-26 17:11 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2010-09-23 17:53 - 2010-09-23 17:53 - 01601536 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
2010-08-11 20:52 - 2010-08-11 20:52 - 00060928 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\WimaxConsole.exe
2015-05-26 22:01 - 2015-05-26 22:01 - 01878080 _____ () C:\Program Files (x86)\DrSpeedyPC\secure\secureupdater.exe
2015-08-08 22:51 - 2015-07-15 19:30 - 00537088 _____ () C:\Program Files (x86)\DNS Unlocker\dnswabeno.exe
2015-08-08 20:06 - 2015-08-13 07:14 - 00473840 _____ () C:\Program Files (x86)\Coupon Time\bin\utilCouponTime.exe
2014-02-12 21:58 - 2014-02-12 21:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 14:05 - 2014-10-11 14:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2009-11-02 15:20 - 2009-11-02 15:20 - 00619816 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2009-11-02 15:23 - 2009-11-02 15:23 - 00013096 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2012-01-21 23:38 - 2007-11-01 18:13 - 00012288 ____N () C:\Program Files (x86)\CyberLink\PCM4Everio\Kernel\common\CLEverioDetector.dll
2010-07-13 19:19 - 2010-07-13 19:19 - 00243056 _____ () C:\Program Files (x86)\Sierra Wireless Inc\WebUpdater\WebUpdtAPI.dll
2014-09-15 21:31 - 2014-07-09 12:01 - 01459712 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll
2014-09-15 21:31 - 2014-05-19 17:19 - 00137728 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll
2015-08-08 22:37 - 2015-08-13 05:27 - 00108272 _____ () C:\Program Files (x86)\Coupon Time\bin\CouponTime.BrowserAdapter.exe
2015-01-15 03:02 - 2015-01-15 03:02 - 40555520 _____ () C:\Users\Owner\AppData\Roaming\TWV\libcef.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Owner\Downloads\7 Wonders_ Treasures of Seven__3422_il1095080.exe:typelib

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3206371679-4115178929-761777742-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 82.163.143.152 - 82.163.142.154
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe
MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{971ECBD0-029F-40E0-9A58-8AC6FDEB5240}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{BD0BEA2A-8059-4F00-B27A-59CBF24842F9}] => (Allow) LPort=2869
FirewallRules: [{FF166191-502D-4474-AB35-56B29DF72699}] => (Allow) LPort=1900
FirewallRules: [{B87DEACC-75E4-42E4-B8AE-45D17B4094C9}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{94D57A9D-82D4-4819-801F-5C580C5F10E1}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{0CECF09F-7F53-4DE5-BAD1-70F17C800115}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{56D7E544-6B1D-4764-8AA1-BD06EB2D3FB0}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
FirewallRules: [{47DEB5A5-0E90-477C-8884-5A61AF5FB907}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
FirewallRules: [{21D28BA4-7579-4806-9251-73D99F27B866}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
FirewallRules: [{F92E7C54-A565-477C-87E4-FEFA4E88C401}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
FirewallRules: [{0EA81692-61A8-408C-B609-7B26679D76A0}] => (Allow) C:\Program Files (x86)\Intel Corporation\Intel WiDi\WiDiApp.exe
FirewallRules: [{D77A872E-8CF6-4F6C-998F-3F64E961E880}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector Express\PDX.EXE
FirewallRules: [{4E81B0FF-3BA0-4AF2-B90C-E0E0C6877671}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
FirewallRules: [{6F082AF8-BFDE-4FB9-B989-52479AC6FC3F}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
FirewallRules: [TCP Query User{0AF121D4-C84F-4A71-9F9B-1F4216CE9932}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe
FirewallRules: [UDP Query User{442D7FC3-D5D1-4C13-9D85-D82014621323}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe
FirewallRules: [{715A7F41-612C-49C8-993E-9A458172C0DD}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{14FA5589-EC60-403B-AAA9-77F725D0A349}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A0300A6D-5AA3-461B-9801-414C836C01B1}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{EF97939D-46D2-4135-9F45-A9D3734330E5}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{B23BEDE7-0F39-402C-9DC4-2FD1EEEC0230}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{56842EB6-8B4D-409B-90E1-ECD875E23024}] => (Allow) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\LeapfrogConnect.exe
FirewallRules: [TCP Query User{6EC1A75F-F416-49DB-8B5B-D583B1ED7374}C:\program files (x86)\iskysoft\video converter ultimate\urlreqservice.exe] => (Allow) C:\program files (x86)\iskysoft\video converter ultimate\urlreqservice.exe
FirewallRules: [UDP Query User{23BCFB8C-C5C4-4FE2-936E-2499F1AC110F}C:\program files (x86)\iskysoft\video converter ultimate\urlreqservice.exe] => (Allow) C:\program files (x86)\iskysoft\video converter ultimate\urlreqservice.exe
FirewallRules: [{2D419864-6670-441C-8AEE-AF796079CCE0}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{B1A0592A-0087-4214-8650-D596D3101743}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{E6027A77-1296-42D9-AB3A-2F2EE7F41D24}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{716D0095-327B-4509-AF9A-58150BF568F3}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{3847B58A-D1AE-4424-9450-6EBD7AA85BD3}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{C2275A14-EF6F-4CE2-9D52-502E06AED029}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{94F4A426-4DCA-4775-97C3-AD107747957B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{5B4FF5D8-5C69-4F81-9B06-8B4A183067B1}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{9B1B5C3D-CBF9-4495-B64F-AA7FE3C5B489}] => (Allow) C:\Users\Owner\AppData\Roaming\TWV\TWV.exe
FirewallRules: [{8D2B5048-9D0B-44F4-8FCF-EAFE9C0A31F5}] => (Allow) C:\Users\Owner\AppData\Roaming\TWV\upd.exe
FirewallRules: [{A31AA8E0-B0EB-4912-A9F1-B53421EE4B6F}] => (Allow) C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Sierra Wireless Inc\3G Watcher\TRUUpdater.exe] => C:\Program Files (x86)\Sierra Wireless Inc\WebUpdater\TRUUpdater.exe:*:Enabled:TRUUpdater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Sierra Wireless Inc\WebUpdater\SwiApiMuxX.exe] => Enabled:SwiApiMuxX
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Sierra Wireless Inc\3G Watcher\SwiApiMuxX.exe] => Enabled:SwiApiMuxX
StandardProfile\AuthorizedApplications: [C:\Windows\TEMP\x20su.exe] => Enabled:Policy

==================== Faulty Device Manager Devices =============

Name: cherimoya
Description: cherimoya
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: cherimoya
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: wsafd_1_10_0_19
Description: wsafd_1_10_0_19
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: wsafd_1_10_0_19
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (08/13/2015 07:27:59 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: winpl.exe, version: 1.0.0.1, time stamp: 0x555dc22c
Faulting module name: libcef.dll, version: 3.2171.1972.0, time stamp: 0x54b78ee6
Exception code: 0x80000003
Fault offset: 0x0013b7f0
Faulting process id: 0x10e0
Faulting application start time: 0xwinpl.exe0
Faulting application path: winpl.exe1
Faulting module path: winpl.exe2
Report Id: winpl.exe3

Error: (08/13/2015 07:27:49 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: winpl.exe, version: 1.0.0.1, time stamp: 0x555dc22c
Faulting module name: libcef.dll, version: 3.2171.1972.0, time stamp: 0x54b78ee6
Exception code: 0x80000003
Fault offset: 0x0013b7f0
Faulting process id: 0x1f90
Faulting application start time: 0xwinpl.exe0
Faulting application path: winpl.exe1
Faulting module path: winpl.exe2
Report Id: winpl.exe3

Error: (08/13/2015 07:27:39 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: winpl.exe, version: 1.0.0.1, time stamp: 0x555dc22c
Faulting module name: libcef.dll, version: 3.2171.1972.0, time stamp: 0x54b78ee6
Exception code: 0x80000003
Fault offset: 0x0013b7f0
Faulting process id: 0x1438
Faulting application start time: 0xwinpl.exe0
Faulting application path: winpl.exe1
Faulting module path: winpl.exe2
Report Id: winpl.exe3

Error: (08/13/2015 07:27:27 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: winpl.exe, version: 1.0.0.1, time stamp: 0x555dc22c
Faulting module name: libcef.dll, version: 3.2171.1972.0, time stamp: 0x54b78ee6
Exception code: 0x80000003
Fault offset: 0x0013b7f0
Faulting process id: 0x1e24
Faulting application start time: 0xwinpl.exe0
Faulting application path: winpl.exe1
Faulting module path: winpl.exe2
Report Id: winpl.exe3

Error: (08/13/2015 07:27:16 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: winpl.exe, version: 1.0.0.1, time stamp: 0x555dc22c
Faulting module name: libcef.dll, version: 3.2171.1972.0, time stamp: 0x54b78ee6
Exception code: 0x80000003
Fault offset: 0x0013b7f0
Faulting process id: 0x1cac
Faulting application start time: 0xwinpl.exe0
Faulting application path: winpl.exe1
Faulting module path: winpl.exe2
Report Id: winpl.exe3

Error: (08/13/2015 07:27:06 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: winpl.exe, version: 1.0.0.1, time stamp: 0x555dc22c
Faulting module name: libcef.dll, version: 3.2171.1972.0, time stamp: 0x54b78ee6
Exception code: 0x80000003
Fault offset: 0x0013b7f0
Faulting process id: 0x1dd4
Faulting application start time: 0xwinpl.exe0
Faulting application path: winpl.exe1
Faulting module path: winpl.exe2
Report Id: winpl.exe3

Error: (08/13/2015 07:26:54 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: winpl.exe, version: 1.0.0.1, time stamp: 0x555dc22c
Faulting module name: libcef.dll, version: 3.2171.1972.0, time stamp: 0x54b78ee6
Exception code: 0x80000003
Fault offset: 0x0013b7f0
Faulting process id: 0x888
Faulting application start time: 0xwinpl.exe0
Faulting application path: winpl.exe1
Faulting module path: winpl.exe2
Report Id: winpl.exe3

Error: (08/13/2015 07:26:43 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: winpl.exe, version: 1.0.0.1, time stamp: 0x555dc22c
Faulting module name: libcef.dll, version: 3.2171.1972.0, time stamp: 0x54b78ee6
Exception code: 0x80000003
Fault offset: 0x0013b7f0
Faulting process id: 0x154c
Faulting application start time: 0xwinpl.exe0
Faulting application path: winpl.exe1
Faulting module path: winpl.exe2
Report Id: winpl.exe3

Error: (08/13/2015 07:26:30 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: winpl.exe, version: 1.0.0.1, time stamp: 0x555dc22c
Faulting module name: libcef.dll, version: 3.2171.1972.0, time stamp: 0x54b78ee6
Exception code: 0x80000003
Fault offset: 0x0013b7f0
Faulting process id: 0xc3c
Faulting application start time: 0xwinpl.exe0
Faulting application path: winpl.exe1
Faulting module path: winpl.exe2
Report Id: winpl.exe3

Error: (08/13/2015 07:26:20 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: winpl.exe, version: 1.0.0.1, time stamp: 0x555dc22c
Faulting module name: libcef.dll, version: 3.2171.1972.0, time stamp: 0x54b78ee6
Exception code: 0x80000003
Fault offset: 0x0013b7f0
Faulting process id: 0x115c
Faulting application start time: 0xwinpl.exe0
Faulting application path: winpl.exe1
Faulting module path: winpl.exe2
Report Id: winpl.exe3


System errors:
=============
Error: (08/13/2015 07:22:14 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 for x64-based Systems (KB3079757).

Error: (08/13/2015 07:16:19 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Update for Windows 7 for x64-based Systems (KB3075851).

Error: (08/13/2015 07:15:54 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024200d: Update for Windows 7 for x64-based Systems (KB3064209).

Error: (08/13/2015 07:10:38 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
cherimoya
wsafd_1_10_0_19

Error: (08/13/2015 07:10:04 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Chip High-tech service failed to start due to the following error:
%%2

Error: (08/13/2015 07:10:04 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Wire Professional Version service failed to start due to the following error:
%%2

Error: (08/13/2015 07:04:30 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The Bonjour Service service terminated with service-specific error %%-1.

Error: (08/13/2015 07:02:14 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Windows Update service terminated with the following error:
%%-2147014792

Error: (08/13/2015 07:02:03 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error: (08/13/2015 07:01:44 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Windows Update service terminated with the following error:
%%-2147014792


Microsoft Office:
=========================
Error: (08/13/2015 07:27:59 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: winpl.exe1.0.0.1555dc22clibcef.dll3.2171.1972.054b78ee6800000030013b7f010e001d0d5d440f6d4d3C:\Users\Owner\AppData\Roaming\TWV\winpl.exeC:\Users\Owner\AppData\Roaming\TWV\libcef.dll7ea82274-41c7-11e5-9c97-5404a63c37f3

Error: (08/13/2015 07:27:49 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: winpl.exe1.0.0.1555dc22clibcef.dll3.2171.1972.054b78ee6800000030013b7f01f9001d0d5d43aeb9661C:\Users\Owner\AppData\Roaming\TWV\winpl.exeC:\Users\Owner\AppData\Roaming\TWV\libcef.dll78c098a6-41c7-11e5-9c97-5404a63c37f3

Error: (08/13/2015 07:27:39 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: winpl.exe1.0.0.1555dc22clibcef.dll3.2171.1972.054b78ee6800000030013b7f0143801d0d5d434e77c10C:\Users\Owner\AppData\Roaming\TWV\winpl.exeC:\Users\Owner\AppData\Roaming\TWV\libcef.dll729b2b11-41c7-11e5-9c97-5404a63c37f3

Error: (08/13/2015 07:27:27 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: winpl.exe1.0.0.1555dc22clibcef.dll3.2171.1972.054b78ee6800000030013b7f01e2401d0d5d42db0503bC:\Users\Owner\AppData\Roaming\TWV\winpl.exeC:\Users\Owner\AppData\Roaming\TWV\libcef.dll6b855280-41c7-11e5-9c97-5404a63c37f3

Error: (08/13/2015 07:27:16 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: winpl.exe1.0.0.1555dc22clibcef.dll3.2171.1972.054b78ee6800000030013b7f01cac01d0d5d427ae974aC:\Users\Owner\AppData\Roaming\TWV\winpl.exeC:\Users\Owner\AppData\Roaming\TWV\libcef.dll655fe4eb-41c7-11e5-9c97-5404a63c37f3

Error: (08/13/2015 07:27:06 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: winpl.exe1.0.0.1555dc22clibcef.dll3.2171.1972.054b78ee6800000030013b7f01dd401d0d5d421af3fbaC:\Users\Owner\AppData\Roaming\TWV\winpl.exeC:\Users\Owner\AppData\Roaming\TWV\libcef.dll5f608d5a-41c7-11e5-9c97-5404a63c37f3

Error: (08/13/2015 07:26:54 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: winpl.exe1.0.0.1555dc22clibcef.dll3.2171.1972.054b78ee6800000030013b7f088801d0d5d41a7cd6a6C:\Users\Owner\AppData\Roaming\TWV\winpl.exeC:\Users\Owner\AppData\Roaming\TWV\libcef.dll5832e707-41c7-11e5-9c97-5404a63c37f3

Error: (08/13/2015 07:26:43 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: winpl.exe1.0.0.1555dc22clibcef.dll3.2171.1972.054b78ee6800000030013b7f0154c01d0d5d41345aad1C:\Users\Owner\AppData\Roaming\TWV\winpl.exeC:\Users\Owner\AppData\Roaming\TWV\libcef.dll515fb4fe-41c7-11e5-9c97-5404a63c37f3

Error: (08/13/2015 07:26:30 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: winpl.exe1.0.0.1555dc22clibcef.dll3.2171.1972.054b78ee6800000030013b7f0c3c01d0d5d40c10e05dC:\Users\Owner\AppData\Roaming\TWV\winpl.exeC:\Users\Owner\AppData\Roaming\TWV\libcef.dll49c22dfd-41c7-11e5-9c97-5404a63c37f3

Error: (08/13/2015 07:26:20 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: winpl.exe1.0.0.1555dc22clibcef.dll3.2171.1972.054b78ee6800000030013b7f0115c01d0d5d4060f005bC:\Users\Owner\AppData\Roaming\TWV\winpl.exeC:\Users\Owner\AppData\Roaming\TWV\libcef.dll43cc34dd-41c7-11e5-9c97-5404a63c37f3


CodeIntegrity:
===================================
  Date: 2015-08-08 22:36:37.388
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-08 22:36:02.068
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-08 22:35:57.958
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-08 22:34:23.314
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-08 22:34:17.884
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-08 22:34:01.130
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-08 22:33:53.980
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-08 22:32:43.448
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-08 22:32:38.109
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-08 22:31:58.172
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: Intel® Core™ i7-2620M CPU @ 2.70GHz
Percentage of memory in use: 41%
Total physical RAM: 8102.76 MB
Available physical RAM: 4718.3 MB
Total Virtual: 16203.72 MB
Available Virtual: 13053.2 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:673.64 GB) (Free:440.93 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive d: () (Removable) (Total:0.47 GB) (Free:0.44 GB) FAT

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: 496B9619)
Partition 1: (Not Active) - (Size=25 GB) - (Type=1C)
Partition 2: (Active) - (Size=673.6 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 481.3 MB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=481 MB) - (Type=06)

==================== End of log ============================


  • 0

#22
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,811 posts
Thanks for the logs, got tied up at work today so I'm running behind. I'll be with as soon as possible. Good work by the way !

Thanks
Joe :)
  • 0

#23
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,811 posts
Remove programs.
Run a fix.
Post a log.
 
First
Please remove these programs from your programs an features list, Start > Control panel > Programs an features. In the list find the program listed below and uninstall it.
  • AudioConverter
  • Babylon toolbar on IE
  • Crossbrowse
  • DNS Unlocker version
  • GUPlayer (remove only)
  • SpecialSavings
  • Updater Service
  • VideoConverter (HKLM-x32\...\VideoConverter)
If a program will not remove skip it and keep following instructions please.
 
Next
Download the enclosed file-> Attached File  FIXLIST.txt   16.42KB   123 downloads Save it in the location FRST is (Your Desktop). Run FRST(Right click on FRST icon and "Run as administrator") and click on the Fix button. Wait until finished.
The tool will make a log in the location FRST64 is, (Fixlog.txt).
Please post Fixlog.txt in your next reply.

Thanks
Joe :)
  • 0

#24
TriciaDP72

TriciaDP72

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts

Hi - Here it is:

Fix result of Farbar Recovery Scan Tool (x64) Version:12-08-2015
Ran by Owner (2015-08-14 07:38:47) Run:3
Running from C:\Users\Owner\Desktop
Loaded Profiles: Owner (Available Profiles: Owner)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:
HKLM-x32\...\Run: [gmsd_us_005010055] => [X]
HKU\S-1-5-21-3206371679-4115178929-761777742-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.trovi.com/?gd=&ctid=CT3333887&octid=EB_ORIGINAL_CTID&ISID=M3C8A0B2F-1FE5-42B5-927C-787973A1EAEE&SearchSource=55&CUI=&UM=8&UP=SP1F6B56EB-6ADD-474D-AB94-E47A608388C1&D=080815&SSPV=
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3206371679-4115178929-761777742-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3206371679-4115178929-761777742-1000 -> {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3333887&octid=EB_ORIGINAL_CTID&ISID=M3C8A0B2F-1FE5-42B5-927C-787973A1EAEE&SearchSource=58&CUI=&UM=8&UP=SP1F6B56EB-6ADD-474D-AB94-E47A608388C1&D=080815&q={searchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-3206371679-4115178929-761777742-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: Babylon toolbar helper -> {2EECD738-5844-4a99-B4B6-146BF802613B} -> C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll [2011-08-14] (Babylon BHO)
BHO-x32: TunePro360 -> {5E04457F-D6D4-4A7E-8277-5EF1CA591CC7} -> C:\Program Files (x86)\adlevel\TunePRO360.dll No File
BHO-x32: SpecialSavings -> {74F475FA-6C75-43BD-AAB9-ECDA6184F600} -> C:\Program Files (x86)\SpecialSavings\SpecialSavingsSinged.dll [2011-12-18] (SpecialSavings)
BHO-x32: drspeedypc -> {768919B3-C6AD-47D4-94E9-A4A2FBA8A83D} -> C:\Program Files (x86)\DrSpeedyPC\secure\drspeedypc.dll [2015-05-26] (drspeedypc)
FF SelectedSearchEngine: Trovi
FF NewTab: about:newtab
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\temp [2015-08-08]
FF Extension: DrSpeedyPc - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\{88d83554-2fdc-4bb9-8dcd-f2d46d175f88} [2015-08-13]
FF HKLM\...\Firefox\Extensions: [{0a0e29f6-0ab0-44e1-a98e-bd050ee692ec}] - C:\Program Files\shopperz04082015\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{0a0e29f6-0ab0-44e1-a98e-bd050ee692ec}] - C:\Program Files\shopperz04082015\Firefox
FF HKU\S-1-5-21-3206371679-4115178929-761777742-1000\...\Firefox\Extensions: [[email protected]] - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles/lghuf863.default\extensions\[email protected]
FF Extension: No Name - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles/lghuf863.default\extensions\[email protected] [2012-03-18]
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-08-08] (globalUpdate) [File not signed] <==== ATTENTION
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [68608 2015-08-08] (globalUpdate) [File not signed] <==== ATTENTION
R2 Update Coupon Time; C:\Program Files (x86)\Coupon Time\updateCouponTime.exe [654576 2015-08-08] ()
R2 Util Coupon Time; C:\Program Files (x86)\Coupon Time\bin\utilCouponTime.exe [473840 2015-08-13] ()
C:\Program Files (x86)\Coupon Time
S1 cherimoya; system32\drivers\cherimoya.sys [X]
S1 snqjhjan; \??\C:\Windows\system32\drivers\snqjhjan.sys [X]
S3 SWUMX20; system32\DRIVERS\swumx20.sys [X]
S1 wsafd_1_10_0_19; system32\drivers\wsafd_1_10_0_19.sys [X]
C:\Program Files (x86)\DrSpeedyPC
2015-08-13 07:26 - 2015-08-13 05:29 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{6ec09908-795a-4141-bffa-5fa914d42b7e}Gw64.sys
2015-08-13 07:12 - 2015-08-13 07:12 - 00003072 _____ C:\Windows\System32\Tasks\DrspeedyPc Secure
2015-08-09 13:45 - 2015-08-09 13:45 - 00000000 _____ C:\CEC7.tmp
2015-08-09 10:15 - 2015-08-12 15:13 - 00000000 ____D C:\Users\Owner\AppData\Local\bvxvyxvec
015-08-08 22:51 - 2015-08-13 07:08 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GUPlayer
2015-08-08 22:51 - 2015-08-13 07:08 - 00000000 ____D C:\Program Files (x86)\GUPlayer
2015-08-08 22:51 - 2015-08-13 07:08 - 00000000 ____D C:\Program Files (x86)\DNS Unlocker
2015-08-08 22:51 - 2015-08-08 22:51 - 00026348 _____ C:\Windows\System32\Tasks\DNSWABENO
2015-08-08 22:51 - 2015-08-08 22:51 - 00002065 _____ C:\Users\Owner\Desktop\Continue SpaceSoundPro Uninstaller.lnk
2015-08-08 22:51 - 2015-08-08 22:51 - 00001009 _____ C:\Users\Owner\Desktop\GUPlayer.lnk
2015-08-08 22:30 - 2015-08-13 07:09 - 00000378 _____ C:\Windows\Tasks\APSnotifierPP1.job
2015-08-08 22:30 - 2015-08-13 07:09 - 00000376 _____ C:\Windows\Tasks\APSnotifierPP3.job
2015-08-08 22:30 - 2015-08-13 07:09 - 00000376 _____ C:\Windows\Tasks\APSnotifierPP2.job
2015-08-08 22:30 - 2015-08-08 22:32 - 00002828 _____ C:\Windows\System32\Tasks\APSnotifierPP1
2015-08-08 22:30 - 2015-08-08 22:32 - 00002826 _____ C:\Windows\System32\Tasks\APSnotifierPP3
2015-08-08 22:30 - 2015-08-08 22:32 - 00002826 _____ C:\Windows\System32\Tasks\APSnotifierPP2
2015-08-08 22:29 - 2015-08-13 07:09 - 00000340 _____ C:\Windows\Tasks\Superclean.job
2015-08-08 22:29 - 2015-08-13 07:08 - 00000000 ____D C:\ProgramData\{4d917b50-ca18-1849-4d91-17b50ca1ed43}
2015-08-08 22:29 - 2015-08-08 22:29 - 00003252 _____ C:\Windows\System32\Tasks\Superclean
015-08-08 22:26 - 2015-08-13 07:10 - 00001018 _____ C:\Windows\Tasks\YeUBBA7OfsskP753cAqWAW4.job
2015-08-08 22:26 - 2015-08-13 07:10 - 00001016 _____ C:\Windows\Tasks\YeUBBA7OfsskP753cAqWAW.job
2015-08-08 22:26 - 2015-08-08 22:26 - 00004044 _____ C:\Windows\System32\Tasks\YeUBBA7OfsskP753cAqWAW4
2015-08-08 22:26 - 2015-08-08 22:26 - 00004042 _____ C:\Windows\System32\Tasks\YeUBBA7OfsskP753cAqWAW
2015-08-08 22:25 - 2015-08-13 07:10 - 00000970 _____ C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-08-08 22:25 - 2015-08-13 07:10 - 00000000 ____D C:\Program Files (x86)\globalUpdate
2015-08-08 22:25 - 2015-08-08 22:30 - 00000974 _____ C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2015-08-08 22:25 - 2015-08-08 22:25 - 00003972 _____ C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
2015-08-08 22:25 - 2015-08-08 22:25 - 00003718 _____ C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
2015-08-08 22:25 - 2015-08-08 22:25 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-08-08 22:24 - 2015-08-13 07:10 - 00000000 ____D C:\Program Files (x86)\adlevel
2015-08-08 22:24 - 2015-08-13 07:08 - 00000000 ____D C:\Program Files (x86)\TechVedic
2015-08-08 22:24 - 2015-08-08 22:24 - 00154826 _____ C:\Program Files (x86)\uninstaller.exe
2015-08-08 22:24 - 2015-08-08 22:24 - 00003060 _____ C:\Windows\System32\Tasks\TunePro360 Updater
2015-08-08 22:24 - 2015-08-08 22:24 - 00002528 _____ C:\Windows\system32\PeakoarOff.ini
2015-08-08 22:23 - 2015-08-13 07:10 - 00001056 _____ C:\Windows\Tasks\Crossbrowse.job
2015-08-08 22:23 - 2015-08-13 07:08 - 00000000 ____D C:\Windows\system32\aby
2015-08-08 22:23 - 2015-08-13 07:08 - 00000000 ____D C:\Users\Owner\AppData\Local\Crossbrowse
2015-08-08 22:23 - 2015-08-13 07:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crossbrowse
2015-08-08 22:23 - 2015-08-13 07:08 - 00000000 ____D C:\Program Files\shopperz04082015
2015-08-08 22:23 - 2015-08-13 07:08 - 00000000 ____D C:\Program Files (x86)\Crossbrowse
2015-08-08 22:23 - 2015-08-08 22:24 - 00004808 _____ C:\Windows\SysWOW64\Peakoar.ini
2015-08-08 22:23 - 2015-08-08 22:24 - 00002528 _____ C:\Windows\SysWOW64\PeakoarOff.ini
2015-08-08 22:23 - 2015-08-08 22:23 - 00004082 _____ C:\Windows\System32\Tasks\Crossbrowse
2015-08-08 22:23 - 2015-08-08 22:23 - 00002396 _____ C:\Users\Public\Desktop\Crossbrowse.lnk
2015-08-08 22:23 - 2015-08-02 07:50 - 00353632 _____ C:\Windows\system32\Peakoar64.dll
2015-08-08 22:23 - 2015-08-02 07:50 - 00283488 _____ C:\Windows\SysWOW64\Peakoar.dll
2015-08-08 21:54 - 2015-08-13 07:08 - 00000000 ____D C:\Program Files\SpaceSoundPro
2015-08-08 21:53 - 2015-08-13 07:10 - 00000342 ____H C:\Windows\Tasks\SFNPKXCMWVMXYUKG.job
2015-08-08 21:53 - 2015-08-13 07:10 - 00000330 _____ C:\Windows\Tasks\OMYQNNDMU1.job
2015-08-08 21:53 - 2015-08-13 07:08 - 00000000 ____D C:\Users\Owner\AppData\Local\SmartWeb
2015-08-08 21:53 - 2015-08-13 07:08 - 00000000 ____D C:\ProgramData\Service1291
2015-08-08 21:53 - 2015-08-13 07:08 - 00000000 ____D C:\ProgramData\FlashBeat
2015-08-08 21:53 - 2015-08-08 21:53 - 00004034 _____ C:\Windows\System32\Tasks\SmartWeb Upgrade Trigger Task
2015-08-08 21:53 - 2015-08-08 21:53 - 00003376 _____ C:\Windows\System32\Tasks\SFNPKXCMWVMXYUKG
2015-08-08 21:53 - 2015-08-08 21:53 - 00002852 _____ C:\Windows\System32\Tasks\OMYQNNDMU1
2015-08-08 21:50 - 2015-08-08 18:39 - 00048784 _____ (StdLib) C:\Windows\system32\Drivers\{949ba8b6-a9ea-4b6b-a97d-688a70f2ea0b}Gw64.sys
2015-08-08 21:48 - 2015-08-08 21:48 - 00003542 _____ C:\Windows\System32\Tasks\Inst_Rep
2015-08-08 21:47 - 2015-08-13 07:25 - 00000000 ____D C:\Program Files (x86)\Coupon Time
2015-08-08 21:47 - 2015-08-13 07:08 - 00000000 ____D C:\Program Files (x86)\Coupoon
2015-08-08 21:47 - 2015-08-13 07:07 - 00000000 ____D C:\Program Files (x86)\07599E80-1439095677-81E1-3676-5404A63C37F3
2015-08-08 21:46 - 2015-08-13 07:08 - 00000000 ____D C:\Users\Owner\AppData\Local\StormAlerts
2015-08-08 21:45 - 2015-08-13 07:08 - 00000000 ____D C:\Users\Owner\AppData\Roaming\TWV
2015-08-08 21:45 - 2015-08-08 21:45 - 00003984 _____ C:\Windows\System32\Tasks\LaunchPreSignup
2015-08-08 21:45 - 2015-08-08 21:45 - 00001199 _____ C:\Users\Owner\Desktop\Continue installation .lnk
2015-08-13 07:08 - 2012-03-18 18:45 - 00000000 ____D C:\Program Files (x86)\VideoConverter
2015-08-13 07:08 - 2012-03-18 18:44 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpecialSavings
2015-08-13 07:08 - 2012-03-18 18:44 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AudioConverter
2015-08-13 07:08 - 2012-03-18 18:44 - 00000000 ____D C:\Users\Owner\AppData\Local\Babylon
2015-08-13 07:08 - 2012-03-18 18:44 - 00000000 ____D C:\ProgramData\IBUpdaterService
2015-08-13 07:08 - 2012-03-18 18:44 - 00000000 ____D C:\Program Files (x86)\SpecialSavings
2015-08-13 07:07 - 2012-03-18 18:44 - 00000000 ____D C:\Program Files (x86)\BabylonToolbar
2015-08-13 07:07 - 2012-03-18 18:44 - 00000000 ____D C:\Program Files (x86)\AudioConverter
2015-05-12 16:22 - 2015-05-12 16:22 - 0099678 _____ () C:\Program Files (x86)\tunepro138x138.ico
2015-08-08 22:24 - 2015-08-08 22:24 - 0154826 _____ () C:\Program Files (x86)\uninstaller.exe
2015-04-19 05:20 - 2015-04-19 05:20 - 0005872 _____ () C:\Users\Owner\AppData\Roaming\dum3wyST49Ex
2014-09-24 21:56 - 2014-09-24 21:56 - 0000000 _____ () C:\Users\Owner\AppData\Roaming\MLib.tmp
2014-09-24 21:56 - 2014-09-24 21:56 - 0000000 _____ () C:\Users\Owner\AppData\Roaming\SBLib.tmp
2015-04-20 07:05 - 2015-04-20 07:05 - 1246720 _____ () C:\Users\Owner\AppData\Roaming\YeUBBA7OfsskP753cAqWAW.exe
2015-04-20 07:05 - 2015-04-20 07:05 - 1579520 _____ () C:\Users\Owner\AppData\Roaming\YeUBBA7OfsskP753cAqWAW4.exe
Task: {1290AA52-EC88-4431-8DB1-A12AFAB33ACC} - System32\Tasks\OMYQNNDMU1 => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: {184AC837-F3CE-4D07-A0B9-E34D8CCE8B7A} - System32\Tasks\SmartWeb Upgrade Trigger Task => C:\Users\Owner\AppData\Local\SmartWeb\SmartWebHelper.exe <==== ATTENTION
Task: {209793CF-2F7A-46BB-94E7-5839D7F1D0EC} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-08-08] (globalUpdate) <==== ATTENTION
C:\ProgramData\FlashBeat
C:\Users\Owner\AppData\Local\SmartWeb
C:\Program Files (x86)\globalUpdate
Task: {2A6EA2D8-85D7-4D91-B0F4-FEF81D8DC820} - System32\Tasks\Crossbrowse => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe [2015-08-08] () <==== ATTENTION
Task: {570A1AD0-975E-4E8B-8C79-A55973A92FE2} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
C:\Program Files (x86)\Crossbrowse
C:\Program Files (x86)\AnyProtectEx
Task: {66BF42E4-3DEC-46B5-9173-08F913E4966C} - System32\Tasks\DNSWABENO => C:\Program Files (x86)\DNS Unlocker\dnswabeno.exe [2015-07-15] ()
Task: {6A2D9BBF-9585-4DB7-871A-2C50751E5942} - \AdobeFlashPlayerUpdate 2 -> No File <==== ATTENTION
C:\Program Files (x86)\DNS Unlocker
Task: {7BE0C2FB-9FED-4218-9C95-2F75C6CD836F} - System32\Tasks\LaunchPreSignup => C:\Program Files (x86)\OLBPre\OLBPre.exe <==== ATTENTION
Task: {8AA9E63F-BF5B-4896-9C74-09383AAA3A30} - System32\Tasks\YeUBBA7OfsskP753cAqWAW4 => C:\Users\Owner\AppData\Roaming\YeUBBA7OfsskP753cAqWAW4.exe [2015-04-20] () <==== ATTENTION
Task: {92FEAD3D-5CA4-414D-8242-01D83E308F78} - System32\Tasks\YeUBBA7OfsskP753cAqWAW => C:\Users\Owner\AppData\Roaming\YeUBBA7OfsskP753cAqWAW.exe [2015-04-20] () <==== ATTENTION
Task: {9F9CBAFE-4063-4658-AAC8-5A7E770711BB} - System32\Tasks\Superclean => c:\programdata\{4d917b50-ca18-1849-4d91-17b50ca1ed43}\hqghumeaylnlf.exe [2014-08-08] (Super PC Tools Ltd) <==== ATTENTION
Task: {A0B36402-EBDA-4D05-B40A-5151EC10AD82} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe [2015-08-08] (globalUpdate) <==== ATTENTION
C:\Program Files (x86)\OLBPre
C:\Users\Owner\AppData\Roaming\YeUBBA7OfsskP753cAqWAW4.exe
c:\programdata\{4d917b50-ca18-1849-4d91-17b50ca1ed43}
Task: {A1C5E39C-8392-481E-9CA2-4F070AEA782B} - System32\Tasks\TunePro360 Updater => C:\Program Files (x86)\adlevel\TunePro360Updater.exe [2015-08-08] ()
Task: {AD3C4602-C0E1-4CA4-9E72-AA85A1480A45} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {CA586909-A8D8-4F2F-8AED-F473EB14C968} - \AdobeFlashPlayerUpdate -> No File <==== ATTENTION
C:\Program Files (x86)\adlevel
C:\Program Files (x86)\AnyProtectEx
Task: {E57A1D11-C2B9-4423-904C-45352BA05DEC} - System32\Tasks\SFNPKXCMWVMXYUKG => C:\ProgramData\Service1291\Service1291.exe [2015-06-28] () <==== ATTENTION
C:\ProgramData\Service1291
Task: {F2EFC929-73AC-457B-AF5A-0C7E2E09177E} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: C:\Windows\Tasks\Crossbrowse.job => C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\utility.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\globalupdate.exe <==== ATTENTION
ask: C:\Windows\Tasks\OMYQNNDMU1.job => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION
Task: C:\Windows\Tasks\SFNPKXCMWVMXYUKG.job => C:\ProgramData\Service1291\Service1291.exe <==== ATTENTION
Task: C:\Windows\Tasks\Superclean.job => c:\programdata\{4d917b50-ca18-1849-4d91-17b50ca1ed43}\hqghumeaylnlf.exe <==== ATTENTION
Task: C:\Windows\Tasks\YeUBBA7OfsskP753cAqWAW.job => C:\Users\Owner\AppData\Roaming\YeUBBA7OfsskP753cAqWAW.exe <==== ATTENTION
Task: C:\Windows\Tasks\YeUBBA7OfsskP753cAqWAW4.job => C:\Users\Owner\AppData\Roaming\YeUBBA7OfsskP753cAqWAW4.exe <==== ATTENTION
AlternateDataStreams: C:\Users\Owner\Downloads\7 Wonders_ Treasures of Seven__3422_il1095080.exe:typelib
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"
FirewallRules: [{9B1B5C3D-CBF9-4495-B64F-AA7FE3C5B489}] => (Allow) C:\Users\Owner\AppData\Roaming\TWV\TWV.exe
FirewallRules: [{8D2B5048-9D0B-44F4-8FCF-EAFE9C0A31F5}] => (Allow) C:\Users\Owner\AppData\Roaming\TWV\upd.exe
FirewallRules: [{A31AA8E0-B0EB-4912-A9F1-B53421EE4B6F}] => (Allow) C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe
CMD: bitsadmin /reset /allusers
CMD: netsh winsock reset catalog
CMD: ipconfig /flushdns
RemoveProxy:
hosts:
Emptytemp:

*****************

Processes closed successfully.
Restore point was successfully created.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_us_005010055 => value not found.
HKU\S-1-5-21-3206371679-4115178929-761777742-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value not found.
HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} => key not found.
HKCR\CLSID\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} => key not found.
HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B} => key not found.
HKCR\Wow6432Node\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5E04457F-D6D4-4A7E-8277-5EF1CA591CC7} => key not found.
HKCR\Wow6432Node\CLSID\{5E04457F-D6D4-4A7E-8277-5EF1CA591CC7} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{74F475FA-6C75-43BD-AAB9-ECDA6184F600} => key not found.
HKCR\Wow6432Node\CLSID\{74F475FA-6C75-43BD-AAB9-ECDA6184F600} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{768919B3-C6AD-47D4-94E9-A4A2FBA8A83D} => key not found.
HKCR\Wow6432Node\CLSID\{768919B3-C6AD-47D4-94E9-A4A2FBA8A83D} => key not found.
Firefox SelectedSearchEngine removed successfully
Firefox "newtab" removed successfully
C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\temp not found.
C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\{88d83554-2fdc-4bb9-8dcd-f2d46d175f88} not found.
HKLM\Software\Mozilla\Firefox\Extensions\\{0a0e29f6-0ab0-44e1-a98e-bd050ee692ec} => value not found.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{0a0e29f6-0ab0-44e1-a98e-bd050ee692ec} => value not found.
HKU\S-1-5-21-3206371679-4115178929-761777742-1000\Software\Mozilla\Firefox\Extensions\\[email protected] => value not found.
C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles/lghuf863.default\extensions\[email protected] not found.
globalUpdate => service not found.
globalUpdatem => service not found.
Update Coupon Time => service not found.
Util Coupon Time => service not found.
C:\Program Files (x86)\Coupon Time => moved successfully.
cherimoya => service not found.
snqjhjan => service not found.
SWUMX20 => service not found.
wsafd_1_10_0_19 => service not found.
"C:\Program Files (x86)\DrSpeedyPC" => File/Folder not found.
"C:\Windows\system32\Drivers\{6ec09908-795a-4141-bffa-5fa914d42b7e}Gw64.sys" => File/Folder not found.
"C:\Windows\System32\Tasks\DrspeedyPc Secure" => File/Folder not found.
"C:\CEC7.tmp" => File/Folder not found.
"C:\Users\Owner\AppData\Local\bvxvyxvec" => File/Folder not found.
015-08-08 22:51 - 2015-08-13 07:08 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GUPlayer => Error: No automatic fix found for this entry.
"C:\Program Files (x86)\GUPlayer" => File/Folder not found.
"C:\Program Files (x86)\DNS Unlocker" => File/Folder not found.
"C:\Windows\System32\Tasks\DNSWABENO" => File/Folder not found.
"C:\Users\Owner\Desktop\Continue SpaceSoundPro Uninstaller.lnk" => File/Folder not found.
"C:\Users\Owner\Desktop\GUPlayer.lnk" => File/Folder not found.
"C:\Windows\Tasks\APSnotifierPP1.job" => File/Folder not found.
"C:\Windows\Tasks\APSnotifierPP3.job" => File/Folder not found.
"C:\Windows\Tasks\APSnotifierPP2.job" => File/Folder not found.
"C:\Windows\System32\Tasks\APSnotifierPP1" => File/Folder not found.
"C:\Windows\System32\Tasks\APSnotifierPP3" => File/Folder not found.
"C:\Windows\System32\Tasks\APSnotifierPP2" => File/Folder not found.
"C:\Windows\Tasks\Superclean.job" => File/Folder not found.
"C:\ProgramData\{4d917b50-ca18-1849-4d91-17b50ca1ed43}" => File/Folder not found.
"C:\Windows\System32\Tasks\Superclean" => File/Folder not found.
015-08-08 22:26 - 2015-08-13 07:10 - 00001018 _____ C:\Windows\Tasks\YeUBBA7OfsskP753cAqWAW4.job => Error: No automatic fix found for this entry.
"C:\Windows\Tasks\YeUBBA7OfsskP753cAqWAW.job" => File/Folder not found.
"C:\Windows\System32\Tasks\YeUBBA7OfsskP753cAqWAW4" => File/Folder not found.
"C:\Windows\System32\Tasks\YeUBBA7OfsskP753cAqWAW" => File/Folder not found.
"C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job" => File/Folder not found.
"C:\Program Files (x86)\globalUpdate" => File/Folder not found.
"C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job" => File/Folder not found.
"C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA" => File/Folder not found.
"C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore" => File/Folder not found.
"C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7" => File/Folder not found.
"C:\Program Files (x86)\adlevel" => File/Folder not found.
"C:\Program Files (x86)\TechVedic" => File/Folder not found.
"C:\Program Files (x86)\uninstaller.exe" => File/Folder not found.
"C:\Windows\System32\Tasks\TunePro360 Updater" => File/Folder not found.
"C:\Windows\system32\PeakoarOff.ini" => File/Folder not found.
"C:\Windows\Tasks\Crossbrowse.job" => File/Folder not found.
"C:\Windows\system32\aby" => File/Folder not found.
"C:\Users\Owner\AppData\Local\Crossbrowse" => File/Folder not found.
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crossbrowse" => File/Folder not found.
"C:\Program Files\shopperz04082015" => File/Folder not found.
"C:\Program Files (x86)\Crossbrowse" => File/Folder not found.
"C:\Windows\SysWOW64\Peakoar.ini" => File/Folder not found.
"C:\Windows\SysWOW64\PeakoarOff.ini" => File/Folder not found.
"C:\Windows\System32\Tasks\Crossbrowse" => File/Folder not found.
"C:\Users\Public\Desktop\Crossbrowse.lnk" => File/Folder not found.
"C:\Windows\system32\Peakoar64.dll" => File/Folder not found.
"C:\Windows\SysWOW64\Peakoar.dll" => File/Folder not found.
"C:\Program Files\SpaceSoundPro" => File/Folder not found.
"C:\Windows\Tasks\SFNPKXCMWVMXYUKG.job" => File/Folder not found.
"C:\Windows\Tasks\OMYQNNDMU1.job" => File/Folder not found.
"C:\Users\Owner\AppData\Local\SmartWeb" => File/Folder not found.
"C:\ProgramData\Service1291" => File/Folder not found.
"C:\ProgramData\FlashBeat" => File/Folder not found.
"C:\Windows\System32\Tasks\SmartWeb Upgrade Trigger Task" => File/Folder not found.
"C:\Windows\System32\Tasks\SFNPKXCMWVMXYUKG" => File/Folder not found.
"C:\Windows\System32\Tasks\OMYQNNDMU1" => File/Folder not found.
"C:\Windows\system32\Drivers\{949ba8b6-a9ea-4b6b-a97d-688a70f2ea0b}Gw64.sys" => File/Folder not found.
"C:\Windows\System32\Tasks\Inst_Rep" => File/Folder not found.
"C:\Program Files (x86)\Coupon Time" => File/Folder not found.
"C:\Program Files (x86)\Coupoon" => File/Folder not found.
"C:\Program Files (x86)\07599E80-1439095677-81E1-3676-5404A63C37F3" => File/Folder not found.
"C:\Users\Owner\AppData\Local\StormAlerts" => File/Folder not found.
"C:\Users\Owner\AppData\Roaming\TWV" => File/Folder not found.
"C:\Windows\System32\Tasks\LaunchPreSignup" => File/Folder not found.
"C:\Users\Owner\Desktop\Continue installation .lnk" => File/Folder not found.
"C:\Program Files (x86)\VideoConverter" => File/Folder not found.
"C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpecialSavings" => File/Folder not found.
"C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AudioConverter" => File/Folder not found.
"C:\Users\Owner\AppData\Local\Babylon" => File/Folder not found.
"C:\ProgramData\IBUpdaterService" => File/Folder not found.
"C:\Program Files (x86)\SpecialSavings" => File/Folder not found.
"C:\Program Files (x86)\BabylonToolbar" => File/Folder not found.
"C:\Program Files (x86)\AudioConverter" => File/Folder not found.
"C:\Program Files (x86)\tunepro138x138.ico" => File/Folder not found.
"C:\Program Files (x86)\uninstaller.exe" => File/Folder not found.
"C:\Users\Owner\AppData\Roaming\dum3wyST49Ex" => File/Folder not found.
"C:\Users\Owner\AppData\Roaming\MLib.tmp" => File/Folder not found.
"C:\Users\Owner\AppData\Roaming\SBLib.tmp" => File/Folder not found.
"C:\Users\Owner\AppData\Roaming\YeUBBA7OfsskP753cAqWAW.exe" => File/Folder not found.
"C:\Users\Owner\AppData\Roaming\YeUBBA7OfsskP753cAqWAW4.exe" => File/Folder not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1290AA52-EC88-4431-8DB1-A12AFAB33ACC} => key not found.
C:\Windows\System32\Tasks\OMYQNNDMU1 not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OMYQNNDMU1 => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{184AC837-F3CE-4D07-A0B9-E34D8CCE8B7A} => key not found.
C:\Windows\System32\Tasks\SmartWeb Upgrade Trigger Task not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SmartWeb Upgrade Trigger Task => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{209793CF-2F7A-46BB-94E7-5839D7F1D0EC} => key not found.
C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA => key not found.
"C:\ProgramData\FlashBeat" => File/Folder not found.
"C:\Users\Owner\AppData\Local\SmartWeb" => File/Folder not found.
"C:\Program Files (x86)\globalUpdate" => File/Folder not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A6EA2D8-85D7-4D91-B0F4-FEF81D8DC820} => key not found.
C:\Windows\System32\Tasks\Crossbrowse not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Crossbrowse => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{570A1AD0-975E-4E8B-8C79-A55973A92FE2} => key not found.
C:\Windows\System32\Tasks\APSnotifierPP3 not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP3 => key not found.
"C:\Program Files (x86)\Crossbrowse" => File/Folder not found.
"C:\Program Files (x86)\AnyProtectEx" => File/Folder not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{66BF42E4-3DEC-46B5-9173-08F913E4966C} => key not found.
C:\Windows\System32\Tasks\DNSWABENO not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DNSWABENO => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A2D9BBF-9585-4DB7-871A-2C50751E5942} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeFlashPlayerUpdate 2 => key not found.
"C:\Program Files (x86)\DNS Unlocker" => File/Folder not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7BE0C2FB-9FED-4218-9C95-2F75C6CD836F} => key not found.
C:\Windows\System32\Tasks\LaunchPreSignup not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LaunchPreSignup => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8AA9E63F-BF5B-4896-9C74-09383AAA3A30} => key not found.
C:\Windows\System32\Tasks\YeUBBA7OfsskP753cAqWAW4 not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YeUBBA7OfsskP753cAqWAW4 => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{92FEAD3D-5CA4-414D-8242-01D83E308F78} => key not found.
C:\Windows\System32\Tasks\YeUBBA7OfsskP753cAqWAW not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YeUBBA7OfsskP753cAqWAW => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9F9CBAFE-4063-4658-AAC8-5A7E770711BB} => key not found.
C:\Windows\System32\Tasks\Superclean not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Superclean => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A0B36402-EBDA-4D05-B40A-5151EC10AD82} => key not found.
C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore => key not found.
"C:\Program Files (x86)\OLBPre" => File/Folder not found.
"C:\Users\Owner\AppData\Roaming\YeUBBA7OfsskP753cAqWAW4.exe" => File/Folder not found.
"c:\programdata\{4d917b50-ca18-1849-4d91-17b50ca1ed43}" => File/Folder not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A1C5E39C-8392-481E-9CA2-4F070AEA782B} => key not found.
C:\Windows\System32\Tasks\TunePro360 Updater not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\TunePro360 Updater => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AD3C4602-C0E1-4CA4-9E72-AA85A1480A45} => key not found.
C:\Windows\System32\Tasks\APSnotifierPP1 not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP1 => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CA586909-A8D8-4F2F-8AED-F473EB14C968} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdobeFlashPlayerUpdate => key not found.
"C:\Program Files (x86)\adlevel" => File/Folder not found.
"C:\Program Files (x86)\AnyProtectEx" => File/Folder not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E57A1D11-C2B9-4423-904C-45352BA05DEC} => key not found.
C:\Windows\System32\Tasks\SFNPKXCMWVMXYUKG not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SFNPKXCMWVMXYUKG => key not found.
"C:\ProgramData\Service1291" => File/Folder not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F2EFC929-73AC-457B-AF5A-0C7E2E09177E} => key not found.
C:\Windows\System32\Tasks\APSnotifierPP2 not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP2 => key not found.
C:\Windows\Tasks\APSnotifierPP1.job not found.
C:\Windows\Tasks\APSnotifierPP2.job not found.
C:\Windows\Tasks\APSnotifierPP3.job not found.
C:\Windows\Tasks\Crossbrowse.job not found.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job not found.
C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job not found.
ask: C:\Windows\Tasks\OMYQNNDMU1.job => C:\ProgramData\FlashBeat\FlashBeat.exe <==== ATTENTION => Error: No automatic fix found for this entry.
C:\Windows\Tasks\SFNPKXCMWVMXYUKG.job not found.
C:\Windows\Tasks\Superclean.job not found.
C:\Windows\Tasks\YeUBBA7OfsskP753cAqWAW.job not found.
C:\Windows\Tasks\YeUBBA7OfsskP753cAqWAW4.job not found.
"C:\Users\Owner\Downloads\7 Wonders_ Treasures of Seven__3422_il1095080.exe" => ":typelib" ADS not found.
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\WRkrn => key not found.
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\WRSVC => key not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9B1B5C3D-CBF9-4495-B64F-AA7FE3C5B489} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8D2B5048-9D0B-44F4-8FCF-EAFE9C0A31F5} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A31AA8E0-B0EB-4912-A9F1-B53421EE4B6F} => value not found.

=========  bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

0 out of 0 jobs canceled.

========= End of CMD: =========


=========  netsh winsock reset catalog =========


Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.


========= End of CMD: =========


=========  ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========


========= RemoveProxy: =========

"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully


========= End of RemoveProxy: =========

"C:\Windows\System32\Drivers\etc\hosts" => Could not move.
Could not restore Hosts.
EmptyTemp: => 226.7 MB temporary data Removed.


The system needed a reboot..

==== End of Fixlog 07:39:55 ====


  • 0

#25
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,811 posts
Perhaps some of the adware was removed according to FRST nothing was found, in any event run a Malwarebytes scan again. You can skip the download part since we have it installed already..
  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete , make sure that that all Threats are selected, and click Remove Selected.
  • Reboot your computer if prompted.
Posting the Malwarebytes log.
  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the Scan Log which shows the Date and time of the scan just performed.
  • Click 'Export'.
  • Click 'Text file (*.txt)'
  • In the Save File dialog box which appears, click on Desktop.
  • In the File name: box type a name for your scan log.
  • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
  • Click Ok
  • post that saved log to your next reply.

  • 0

Advertisements


#26
TriciaDP72

TriciaDP72

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts

Hi - Here is the MBAM Log:

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 8/16/2015
Scan Time: 10:15 AM
Logfile: tricia2.txt
Administrator: Yes

Version: 2.1.8.1057
Malware Database: v2015.08.16.02
Rootkit Database: v2015.08.16.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Owner

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 394987
Time Elapsed: 17 min, 41 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 2
PUP.Optional.Compete, C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe, 5072, Delete-on-Reboot, [ff8368a128633501bd60691dcd38b64a]
PUP.Optional.WebBar.A, C:\Program Files\WebBar\2.0.5659.26749\wb.exe, 4520, Delete-on-Reboot, [4a38c148f992082e6d26bd6ae91aeb15]

Modules: 0
(No malicious items detected)

Registry Keys: 251
PUP.Optional.ConsumerInput.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\consumerinput_update, Quarantined, [42403acfe7a4082ec88760bce21f6c94],
PUP.Optional.ConsumerInput.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\consumerinput_updatem, Quarantined, [42403acfe7a4082ec88760bce21f6c94],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\CONSUMERINPUTUPDATE.EXE, Quarantined, [42403acfe7a4082ec88760bce21f6c94],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\CONSUMERINPUTUPDATE.EXE, Quarantined, [42403acfe7a4082ec88760bce21f6c94],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\CLSID\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\TYPELIB\{7BAB653D-88FB-4F60-AFC2-8E6FD59FAFF3}, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\INTERFACE\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{DD05B915-F77B-474A-9D42-9FEEAF5475C4}, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{7BAB653D-88FB-4F60-AFC2-8E6FD59FAFF3}, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{7BAB653D-88FB-4F60-AFC2-8E6FD59FAFF3}, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\dcabho.Dca.1, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\dcabho.Dca, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, HKLM\SOFTWARE\WOW6432NODE\CLASSES\dcabho.Dca, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\WOW6432NODE\dcabho.Dca, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, HKLM\SOFTWARE\WOW6432NODE\CLASSES\dcabho.Dca.1, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\WOW6432NODE\dcabho.Dca.1, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, HKLM\SOFTWARE\CLASSES\CLSID\{B49699FC-1665-4414-A1CB-C4A2A4A13EEC}\INPROCSERVER32, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\APPID\{D2A19E15-4D23-41F5-8035-E2D730DA691C}, Quarantined, [91f124e564270333c388345e07fbe020],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassSvc, Quarantined, [91f124e564270333c388345e07fbe020],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [91f124e564270333c388345e07fbe020],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassSvc, Quarantined, [91f124e564270333c388345e07fbe020],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [91f124e564270333c388345e07fbe020],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.OnDemandCOMClassSvc, Quarantined, [91f124e564270333c388345e07fbe020],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [91f124e564270333c388345e07fbe020],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{D2A19E15-4D23-41F5-8035-E2D730DA691C}, Quarantined, [91f124e564270333c388345e07fbe020],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{D2A19E15-4D23-41F5-8035-E2D730DA691C}, Quarantined, [91f124e564270333c388345e07fbe020],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D2A19E15-4D23-41F5-8035-E2D730DA691C}, Quarantined, [91f124e564270333c388345e07fbe020],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{D2A19E15-4D23-41F5-8035-E2D730DA691C}, Quarantined, [91f124e564270333c388345e07fbe020],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\APPID\{E3EBCC2D-D239-4CA9-BF77-8DC68381D6CA}, Quarantined, [c3bf7c8da2e97bbb92badcb607fb60a0],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3COMClassService, Quarantined, [c3bf7c8da2e97bbb92badcb607fb60a0],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3COMClassService.1.0, Quarantined, [c3bf7c8da2e97bbb92badcb607fb60a0],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3COMClassService, Quarantined, [c3bf7c8da2e97bbb92badcb607fb60a0],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3COMClassService.1.0, Quarantined, [c3bf7c8da2e97bbb92badcb607fb60a0],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3COMClassService, Quarantined, [c3bf7c8da2e97bbb92badcb607fb60a0],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3COMClassService.1.0, Quarantined, [c3bf7c8da2e97bbb92badcb607fb60a0],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{E3EBCC2D-D239-4CA9-BF77-8DC68381D6CA}, Quarantined, [c3bf7c8da2e97bbb92badcb607fb60a0],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{E3EBCC2D-D239-4CA9-BF77-8DC68381D6CA}, Quarantined, [c3bf7c8da2e97bbb92badcb607fb60a0],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E3EBCC2D-D239-4CA9-BF77-8DC68381D6CA}, Quarantined, [c3bf7c8da2e97bbb92badcb607fb60a0],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{E3EBCC2D-D239-4CA9-BF77-8DC68381D6CA}, Quarantined, [c3bf7c8da2e97bbb92badcb607fb60a0],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{0C6D49F4-6E41-4632-BE86-F210D5D894BA}, Quarantined, [a7dbf4158b002313a0a38f038b77e11f],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebMachineFallback.1.0, Quarantined, [a7dbf4158b002313a0a38f038b77e11f],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebMachineFallback, Quarantined, [a7dbf4158b002313a0a38f038b77e11f],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebMachineFallback, Quarantined, [a7dbf4158b002313a0a38f038b77e11f],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3WebMachineFallback, Quarantined, [a7dbf4158b002313a0a38f038b77e11f],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebMachineFallback.1.0, Quarantined, [a7dbf4158b002313a0a38f038b77e11f],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3WebMachineFallback.1.0, Quarantined, [a7dbf4158b002313a0a38f038b77e11f],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{0C6D49F4-6E41-4632-BE86-F210D5D894BA}, Quarantined, [a7dbf4158b002313a0a38f038b77e11f],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{1AB0B6A3-9BC5-419B-B86D-40FA2998A131}, Quarantined, [681a7e8b860573c3251f8a0858aa38c8],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoreClass.1, Quarantined, [681a7e8b860573c3251f8a0858aa38c8],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoreClass, Quarantined, [681a7e8b860573c3251f8a0858aa38c8],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoreClass, Quarantined, [681a7e8b860573c3251f8a0858aa38c8],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CoreClass, Quarantined, [681a7e8b860573c3251f8a0858aa38c8],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoreClass.1, Quarantined, [681a7e8b860573c3251f8a0858aa38c8],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CoreClass.1, Quarantined, [681a7e8b860573c3251f8a0858aa38c8],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{1AB0B6A3-9BC5-419B-B86D-40FA2998A131}, Quarantined, [681a7e8b860573c3251f8a0858aa38c8],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3A40DF53-EB22-49FE-9246-8084403424E7}, Quarantined, [740ec049f5965cdac2837c16e919768a],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CredentialDialogMachine.1.0, Quarantined, [740ec049f5965cdac2837c16e919768a],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CredentialDialogMachine, Quarantined, [740ec049f5965cdac2837c16e919768a],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CredentialDialogMachine, Quarantined, [740ec049f5965cdac2837c16e919768a],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CredentialDialogMachine, Quarantined, [740ec049f5965cdac2837c16e919768a],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CredentialDialogMachine.1.0, Quarantined, [740ec049f5965cdac2837c16e919768a],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CredentialDialogMachine.1.0, Quarantined, [740ec049f5965cdac2837c16e919768a],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3A40DF53-EB22-49FE-9246-8084403424E7}, Quarantined, [740ec049f5965cdac2837c16e919768a],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3DBBAB3C-4077-4EC4-BF2C-E89C7784846A}, Quarantined, [651d1aefd5b65bdb74d2f59d8c7614ec],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebSvc.1.0, Quarantined, [651d1aefd5b65bdb74d2f59d8c7614ec],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebSvc, Quarantined, [651d1aefd5b65bdb74d2f59d8c7614ec],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebSvc, Quarantined, [651d1aefd5b65bdb74d2f59d8c7614ec],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3WebSvc, Quarantined, [651d1aefd5b65bdb74d2f59d8c7614ec],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebSvc.1.0, Quarantined, [651d1aefd5b65bdb74d2f59d8c7614ec],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.Update3WebSvc.1.0, Quarantined, [651d1aefd5b65bdb74d2f59d8c7614ec],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3DBBAB3C-4077-4EC4-BF2C-E89C7784846A}, Quarantined, [651d1aefd5b65bdb74d2f59d8c7614ec],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5CF02202-6278-47EE-9947-C2D0A057EABD}, Quarantined, [3250f6136c1f0234b691494908fa4ab6],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.ProcessLauncher.1.0, Quarantined, [3250f6136c1f0234b691494908fa4ab6],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.ProcessLauncher, Quarantined, [3250f6136c1f0234b691494908fa4ab6],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.ProcessLauncher, Quarantined, [3250f6136c1f0234b691494908fa4ab6],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.ProcessLauncher, Quarantined, [3250f6136c1f0234b691494908fa4ab6],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.ProcessLauncher.1.0, Quarantined, [3250f6136c1f0234b691494908fa4ab6],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.ProcessLauncher.1.0, Quarantined, [3250f6136c1f0234b691494908fa4ab6],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{5CF02202-6278-47EE-9947-C2D0A057EABD}, Quarantined, [3250f6136c1f0234b691494908fa4ab6],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{65BF611F-85CD-4E7F-966C-853573462C14}, Quarantined, [463c35d4e6a580b6a0a8d5bda45e847c],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [463c35d4e6a580b6a0a8d5bda45e847c],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachineFallback, Quarantined, [463c35d4e6a580b6a0a8d5bda45e847c],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachineFallback, Quarantined, [463c35d4e6a580b6a0a8d5bda45e847c],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.OnDemandCOMClassMachineFallback, Quarantined, [463c35d4e6a580b6a0a8d5bda45e847c],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [463c35d4e6a580b6a0a8d5bda45e847c],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [463c35d4e6a580b6a0a8d5bda45e847c],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{65BF611F-85CD-4E7F-966C-853573462C14}, Quarantined, [463c35d4e6a580b6a0a8d5bda45e847c],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{87A125E5-B663-496F-954E-488A82FAC012}, Quarantined, [71115eab1b7089ad1732642efe041ee2],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoCreateAsync.1.0, Quarantined, [71115eab1b7089ad1732642efe041ee2],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoCreateAsync, Quarantined, [71115eab1b7089ad1732642efe041ee2],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoCreateAsync, Quarantined, [71115eab1b7089ad1732642efe041ee2],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CoCreateAsync, Quarantined, [71115eab1b7089ad1732642efe041ee2],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoCreateAsync.1.0, Quarantined, [71115eab1b7089ad1732642efe041ee2],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.CoCreateAsync.1.0, Quarantined, [71115eab1b7089ad1732642efe041ee2],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{87A125E5-B663-496F-954E-488A82FAC012}, Quarantined, [71115eab1b7089ad1732642efe041ee2],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{8AF9C44C-E497-4776-A7EF-F6455F982825}, Quarantined, [f191b9507813e254bb8fe8aa0ff320e0],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [f191b9507813e254bb8fe8aa0ff320e0],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachine, Quarantined, [f191b9507813e254bb8fe8aa0ff320e0],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachine, Quarantined, [f191b9507813e254bb8fe8aa0ff320e0],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.OnDemandCOMClassMachine, Quarantined, [f191b9507813e254bb8fe8aa0ff320e0],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [f191b9507813e254bb8fe8aa0ff320e0],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInputUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [f191b9507813e254bb8fe8aa0ff320e0],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{8AF9C44C-E497-4776-A7EF-F6455F982825}, Quarantined, [f191b9507813e254bb8fe8aa0ff320e0],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F90B8F59-792D-4F5A-97AD-06E83284F9AB}, Quarantined, [b1d111f819727cba1d301a7807fb59a7],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInput.OneClickProcessLauncherMachine.1.0, Quarantined, [b1d111f819727cba1d301a7807fb59a7],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\ConsumerInput.OneClickProcessLauncherMachine, Quarantined, [b1d111f819727cba1d301a7807fb59a7],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInput.OneClickProcessLauncherMachine, Quarantined, [b1d111f819727cba1d301a7807fb59a7],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInput.OneClickProcessLauncherMachine, Quarantined, [b1d111f819727cba1d301a7807fb59a7],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInput.OneClickProcessLauncherMachine.1.0, Quarantined, [b1d111f819727cba1d301a7807fb59a7],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\ConsumerInput.OneClickProcessLauncherMachine.1.0, Quarantined, [b1d111f819727cba1d301a7807fb59a7],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{F90B8F59-792D-4F5A-97AD-06E83284F9AB}, Quarantined, [b1d111f819727cba1d301a7807fb59a7],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F90B8F59-792D-4F5A-97AD-06E83284F9AB}, Quarantined, [b1d111f819727cba1d301a7807fb59a7],
PUP.Optional.Amonetize.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{B0660298-91AA-421F-BF0D-BFF6BB8BF3AE}, Quarantined, [f19114f58cff84b2dc07b91a9e643ac6],
PUP.Optional.Amonetize.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{EAC7DE5C-9520-435D-91AA-4A02E4773CEA}, Quarantined, [f19114f58cff84b2dc07b91a9e643ac6],
PUP.Optional.Amonetize.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{EAC7DE5C-9520-435D-91AA-4A02E4773CEA}, Quarantined, [f19114f58cff84b2dc07b91a9e643ac6],
PUP.Optional.Amonetize.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{EAC7DE5C-9520-435D-91AA-4A02E4773CEA}, Quarantined, [f19114f58cff84b2dc07b91a9e643ac6],
PUP.Optional.Amonetize.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{B0660298-91AA-421F-BF0D-BFF6BB8BF3AE}, Quarantined, [f19114f58cff84b2dc07b91a9e643ac6],
PUP.Optional.Amonetize.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{B0660298-91AA-421F-BF0D-BFF6BB8BF3AE}, Quarantined, [f19114f58cff84b2dc07b91a9e643ac6],
PUP.Optional.SharedBHO.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}, Quarantined, [2f5335d424674fe76e533a5fa55d57a9],
PUP.Optional.SharedBHO.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}, Quarantined, [2f5335d424674fe76e533a5fa55d57a9],
PUP.Optional.Compete, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Consumer Input Installer, Quarantined, [156dc3466a21e84e35e881057c898f71],
PUP.Optional.WebBar.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{0BCE8B0A-1E76-44E5-9909-3CF804D92E4D}_is1, Quarantined, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.WebBar.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\wbsvc, Quarantined, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{f3e41bda-246e-4159-bfab-605b34e2ce62}Gw64, Quarantined, [1969b1581675999d97740d392cd77888],
PUP.Optional.Coupoon.A, HKLM\SOFTWARE\coupoon, Quarantined, [dba79c6dc4c7270fc96e841ba460837d],
PUP.Optional.Flashbeat.A, HKLM\SOFTWARE\Flashbeat, Quarantined, [8bf77990a1ea979f7eaebd6d7e85867a],
PUP.Optional.HighDefAction.A, HKLM\SOFTWARE\HighDefAction, Quarantined, [c6bc94751774b77ffa9e7b2b12f2ea16],
PUP.Optional.YorkNewCin.A, HKLM\SOFTWARE\YorkNewCin, Quarantined, [d3af10f9a3e893a3bce7fcaa02028c74],
PUP.Optional.CinemaPlus.C, HKLM\SOFTWARE\ARENAHD, Quarantined, [186af811711a0b2bbbd85c465aaa21df],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoreMachineClass, Quarantined, [235fc4459fecbc7ab2830c59867dad53],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.CoreMachineClass.1, Quarantined, [1b671dec7c0fd0665ed7461f1ae98977],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebMachine, Quarantined, [10727198f7949d992510ef7660a3d52b],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\ConsumerInputUpdate.Update3WebMachine.1.0, Quarantined, [235f4dbc97f493a30a2b92d3a95a956b],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\APPID\ConsumerInputUpdate.exe, Quarantined, [9fe38683f8935dd981b5b46ee71cf20e],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\ConsumerInputUpdate.exe, Quarantined, [fb87bc4d92f99e980c2acf53699af40c],
PUP.Optional.WombatUpdater.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\SERVICE1291.EXE, Quarantined, [5c267f8a4d3ef640779c69ae0ef529d7],
PUP.Optional.AmiUpdater.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\amiupdaterExd, Quarantined, [50328b7e404ba88e65f59881748f14ec],
PUP.Optional.AmiUpdater.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\amiupdaterExi, Quarantined, [245eb35612792d090951d0490201ac54],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\CIMT_daily_S-1-5-21-3206371679-4115178929-761777742-1000, Quarantined, [cfb3c643f695d0664963b3665fa4649c],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\CIMT_S-1-5-21-3206371679-4115178929-761777742-1000, Quarantined, [ceb448c1cac1f4423677a772af54bf41],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\ConsumerInputUpdateTaskMachineCore, Quarantined, [a0e2cd3cc0cb290d5658f3266f9452ae],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\ConsumerInputUpdateTaskMachineUA, Quarantined, [8df57b8e583354e27e300217a55e3ac6],
PUP.Optional.DrSpeedyPc.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\DrspeedyPc Secure, Quarantined, [5230c346abe010263d0b25f2d42fae52],
PUP.Optional.Goobzo.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Inst_Rep, Quarantined, [2b579f6a4d3ea09685a8c456768dd030],
PUP.Optional.WebBar.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\WebBarLaunchTask, Quarantined, [a3df8782503b2e08d53d38e1ed160ef2],
PUP.Optional.WebBar.A, HKLM\SOFTWARE\WEBBAR, Quarantined, [5131ad5cb1da5ed82ddcaefa5ca8659b],
PUP.Optional.ConsumerInput, HKLM\SOFTWARE\WOW6432NODE\CompeteInc, Quarantined, [e0a25dac0a81ae884b5fa30bd72d8e72],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\ConsumerInput, Quarantined, [2b579c6d1b703501713d46d816ed07f9],
PUP.Optional.CouponTime.A, HKLM\SOFTWARE\WOW6432NODE\Coupon Time, Quarantined, [b8ca9277a1ea1b1b3da2b2ec986cef11],
PUP.Optional.Coupoon.A, HKLM\SOFTWARE\WOW6432NODE\coupoon, Quarantined, [bac8a564d1ba87af082fa6f926def60a],
PUP.Optional.Crossbrowse.A, HKLM\SOFTWARE\WOW6432NODE\Crossbrowse, Quarantined, [067c18f1147746f0e41b1808aa59ea16],
PUP.Optional.DataMangr.A, HKLM\SOFTWARE\WOW6432NODE\DataMngr, Quarantined, [f58dfe0b662567cf9836f15e34cff40c],
PUP.Optional.Flashbeat.A, HKLM\SOFTWARE\WOW6432NODE\Flashbeat, Quarantined, [5f2324e5f794f1452c00a88246bdd22e],
PUP.Optional.HighDefAction.A, HKLM\SOFTWARE\WOW6432NODE\HighDefAction, Quarantined, [d6ac75941f6c87afc4d4a4025ba91fe1],
PUP.Optional.SpaceSoundPro.A, HKLM\SOFTWARE\WOW6432NODE\SpaceSondPro, Quarantined, [87fbb4554b4052e46138d2db9173da26],
PUP.Optional.WordSurfer.A, HKLM\SOFTWARE\WOW6432NODE\WordSurfer_1.10.0.19, Quarantined, [037fe52426659c9a6f19149a5ca88f71],
PUP.Optional.YorkNewCin.A, HKLM\SOFTWARE\WOW6432NODE\YorkNewCin, Quarantined, [156d4bbee5a6c2749e05efb7c440ab55],
PUP.Optional.SuperOptimizer.C, HKLM\SOFTWARE\WOW6432NODE\{1146AC44-2F03-4431-B4FD-889BC837521F}, Quarantined, [91f13bce810a0a2cb69d26830cf851af],
PUP.Optional.SuperOptimizer.C, HKLM\SOFTWARE\WOW6432NODE\{6791A2F3-FC80-475C-A002-C014AF797E9C}, Quarantined, [bbc779905833cc6a1440595033d13ac6],
PUP.Optional.CrossRider.C, HKLM\SOFTWARE\WOW6432NODE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [077b8c7d5a31eb4b1e92eb33d03343bd],
PUP.Optional.CinemaPlus.C, HKLM\SOFTWARE\WOW6432NODE\ARENAHD, Quarantined, [ff83f316dbb085b15043a8fac2424fb1],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoreMachineClass, Quarantined, [f0928a7f84079a9c67ce70f5ef1460a0],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.CoreMachineClass.1, Quarantined, [8200f1187f0c8da9b77ec3a2b54e1ce4],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebMachine, Quarantined, [5d25be4b9eed7db993a2ce97d330ed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\ConsumerInputUpdate.Update3WebMachine.1.0, Quarantined, [9ae8a8613457c472b3829cc97c8753ad],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\ConsumerInputUpdate.exe, Quarantined, [473b8b7e6b204ee880b621017b88718f],
PUP.Optional.VoPackage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\VOPackage, Quarantined, [6f13b851c8c36cca6010b9e5d72d5ea2],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{1146AC44-2F03-4431-B4FD-889BC837521F}{cae99edb}, Quarantined, [196925e4f497310527f1f6b01de7d030],
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}, Quarantined, [a5dd66a3424939fdeac577a732d15da3],
PUP.Optional.Tuto4PC.A, HKLM\SOFTWARE\WOW6432NODE\TUTORIALS, Quarantined, [95ed64a55b30d0664a61446f7193ca36],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{6ec09908-795a-4141-bffa-5fa914d42b7e}Gw64, Quarantined, [711134d5ccbf191d72e187ab5ca7748c],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{949ba8b6-a9ea-4b6b-a97d-688a70f2ea0b}Gw64, Quarantined, [8101d0390e7df24472e1161cb84b629e],
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\COMYNINU, Quarantined, [631f31d8711aa49242b9ff9e05ff1ae6],
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\DEZYLOJE, Quarantined, [5e2482879fecb6803cbf9805917309f7],
PUP.Optional.MediaService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\MEDIASERVICE, Quarantined, [8101f316e3a842f460c5d2d6986c31cf],
PUP.Optional.SuperOptimizer.C, HKU\S-1-5-18\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, Quarantined, [562c20e9276480b6ba983376af557f81],
PUP.Optional.Coupoon.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\coupoon, Quarantined, [8df5a168cfbc68ce47eef0afaa5a6e92],
PUP.Optional.Crossrider.C, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\_CrossriderRegNamePlaceHolder_, Quarantined, [820050b9612a280ef6a0950d19eb9d63],
PUP.Optional.Shopperz.A, HKU\S-1-5-18\SOFTWARE\{599BDCE5-E3A1-4B2A-83A7-DDAFA1C42D9C}, Quarantined, [0c76ab5ebccfca6c5e17baf452b2ca36],
PUP.Optional.Shopperz.A, HKU\S-1-5-19\SOFTWARE\{599BDCE5-E3A1-4B2A-83A7-DDAFA1C42D9C}, Quarantined, [433f4cbdbfccb87ec8ad377731d3de22],
PUP.Optional.Shopperz.A, HKU\S-1-5-20\SOFTWARE\{599BDCE5-E3A1-4B2A-83A7-DDAFA1C42D9C}, Quarantined, [a2e039d0296243f38fe62a84b74dd22e],
PUP.Optional.CinemaPlus.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\CinemaPlus-3.2cV30.07-nv-ie, Quarantined, [2e54a663fb9002343b5b59db4eb5a759],
PUP.Optional.ConsumerInput, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\Compete, Quarantined, [e89a4dbc0883b3839a0f7e307e865ea2],
PUP.Optional.ConsumerInput.C, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\ConsumerInput, Quarantined, [96ecc2476b20122406de61bfe122ad53],
PUP.Optional.Crossbrowse.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\Crossbrowse, Quarantined, [71113fca91fa69cdc23c0e12a063d62a],
PUP.Optional.Crossbrowse.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\CrossBrowser, Quarantined, [b3cf7594b1da64d21de1120e91729769],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\DataMngr, Quarantined, [abd752b796f5f34391d4373f1de7fb05],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\DataMngr_Toolbar, Quarantined, [99e921e8d9b287afc89ce294e91bd32d],
PUP.Optional.HighDefAction.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\HighDefAction, Quarantined, [b6cc8980d8b336004d4af8ae2cd823dd],
PUP.Optional.MediaService.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\TWV OK, Quarantined, [f78b3ecb0d7e06300221e8c08d773fc1],
PUP.Optional.YorkNewCin.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\YorkNewCin, Quarantined, [5b27c0496526c96d2c76dec8d72df10f],
PUP.Optional.AnyProtect, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\ANYPROTECT, Quarantined, [7c06a267325941f5693eded0b84c38c8],
PUP.Optional.SuperOptimizer.C, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, Quarantined, [ccb68e7b79127eb872e04663fa0a04fc],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [e2a0fd0caae14de933ecf496a361916f],
PUP.Optional.ConsumerInput, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\APPDATALOW\SOFTWARE\COMPETE, Quarantined, [c7bb92775734c670e5c34e60c53fdb25],
PUP.Optional.CinemaPlus.C, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\ARENAHD, Quarantined, [7f0364a5a1ea9b9b266ce3bf38cc2cd4],
PUP.Optional.BProtector, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\BPROTECTOR, Quarantined, [f38f070275161422bfc051ece22219e7],
PUP.Optional.GlobalUpdate.C, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY, Quarantined, [e0a20dfc5b30ba7c9e2fc65a9c6716ea],
PUP.Optional.AudioPerformer.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\PERFORMERSOFT LLC\Audio Performer, Quarantined, [b7cb10f91477fe3836df97b4ab58b24e],
PUP.Optional.VideoPerformer.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\PERFORMERSOFT LLC\Video Performer, Quarantined, [b7cb31d88dfef54110695fe90ff47c84],
PUP.Optional.SuperOptimizer.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\SUPER OPTIMIZER, Quarantined, [760c45c4f893b77ffb06ccdcb4506a96],
PUP.Optional.MediaService.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\TWV, Quarantined, [800221e8f398b77fd45010986a9a2fd1],
PUP.Optional.Shopperz.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\{599BDCE5-E3A1-4B2A-83A7-DDAFA1C42D9C}, Quarantined, [f68ca762e6a546f0e88d931bd82cf50b],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{60260024-AA48-4A2F-84DA-2C2DCB24AAD0}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{15527BF5-9729-49DC-889C-9F956983154C}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C015D269-0F4E-4B52-A91F-721F6DAC9437}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{15527BF5-9729-49DC-889C-9F956983154C}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C015D269-0F4E-4B52-A91F-721F6DAC9437}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{15527BF5-9729-49DC-889C-9F956983154C}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{C015D269-0F4E-4B52-A91F-721F6DAC9437}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\CptUrlPassthru.HttpMonitor.1, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\CptUrlPassthru.HttpMonitor, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CptUrlPassthru.HttpMonitor, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CptUrlPassthru.HttpMonitor, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CptUrlPassthru.HttpMonitor.1, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CptUrlPassthru.HttpMonitor.1, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\CLSID\{60260024-AA48-4A2F-84DA-2C2DCB24AAD0}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\CLSID\{82025773-B1B0-497b-B942-0171A2E42C3C}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\CptUrlPassthru.HttpHeaders.1, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\CptUrlPassthru.HttpHeaders, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CptUrlPassthru.HttpHeaders, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CptUrlPassthru.HttpHeaders, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CptUrlPassthru.HttpHeaders.1, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CptUrlPassthru.HttpHeaders.1, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{82025773-B1B0-497B-B942-0171A2E42C3C}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{82025773-B1B0-497B-B942-0171A2E42C3C}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{60260024-AA48-4A2F-84DA-2C2DCB24AAD0}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{294BC5A4-7157-4131-AB81-1DEC393D0F0A}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{06306AA5-80A1-4260-A9A3-A8E10F6AA8B7}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E98F6ADA-0655-45F4-9141-9F7A18C5B46B}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{06306AA5-80A1-4260-A9A3-A8E10F6AA8B7}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E98F6ADA-0655-45F4-9141-9F7A18C5B46B}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{06306AA5-80A1-4260-A9A3-A8E10F6AA8B7}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{E98F6ADA-0655-45F4-9141-9F7A18C5B46B}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{294BC5A4-7157-4131-AB81-1DEC393D0F0A}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{294BC5A4-7157-4131-AB81-1DEC393D0F0A}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{0E02C3DE-FDA9-4381-99E6-7ED76A518504}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{0E02C3DE-FDA9-4381-99E6-7ED76A518504}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D8F06F2A-FDCE-4F12-8D2A-7A97A752CF1A}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{D8F06F2A-FDCE-4F12-8D2A-7A97A752CF1A}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Setup Support for Consumer Input, Quarantined, [176b31d8c2c940f67c3daa634cb7b64a],

Registry Values: 29
PUP.Optional.CinemaPlus.C, HKLM\SOFTWARE\ARENAHD|value, 1, Quarantined, [186af811711a0b2bbbd85c465aaa21df]
PUP.Optional.PCTuner.C, HKLM\SOFTWARE\HIGHDEFACTION|value, 1, Quarantined, [f0923ccdfb9060d67529237f33d1d828]
PUP.Optional.WombatUpdater.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\Service1291.exe|{a53dd3e5-0283-4ab3-b77c-7bd1bc7550c6}.sdb, 130835696307233272, Quarantined, [5c267f8a4d3ef640779c69ae0ef529d7]
PUP.Optional.SpaceSoundPro.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|SpaceSoundPro, "C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe", Quarantined, [94ee6c9d4e3da59134638c2140c4ab55]
PUP.Optional.WebBar.A, HKLM\SOFTWARE\WEBBAR|Wb, C:\Program Files\WebBar\2.0.5659.26749\wb.exe, Quarantined, [5131ad5cb1da5ed82ddcaefa5ca8659b]
PUP.Optional.CinemaPlus.C, HKLM\SOFTWARE\WOW6432NODE\ARENAHD|value, 1, Quarantined, [ff83f316dbb085b15043a8fac2424fb1]
PUP.Optional.PCTuner.C, HKLM\SOFTWARE\WOW6432NODE\HIGHDEFACTION|value, 1, Quarantined, [453d0ffaef9c7abc2e70604232d202fe]
PUP.Optional.ConsumerInput.C, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}|DisplayName, Consumer Input Update Helper, Quarantined, [a5dd66a3424939fdeac577a732d15da3]
PUP.Optional.TunePro360.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{969a43f0-fd3b-4026-aa4b-af70ac7c9d9c}, C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\{969a43f0-fd3b-4026-aa4b-af70ac7c9d9c}, Quarantined, [b9c97c8d8803bb7bafa2e92ee81be818]
PUP.Optional.DrSpeedyPc.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{88d83554-2fdc-4bb9-8dcd-f2d46d175f88}, C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\{88d83554-2fdc-4bb9-8dcd-f2d46d175f88}, Quarantined, [5131db2eb8d32e084900a770a95a01ff]
PUP.Optional.Tuto4PC.A, HKLM\SOFTWARE\WOW6432NODE\TUTORIALS|HostGUID, A4466493-9EAF-4F7F-8910-8F0C0B3A20C2, Quarantined, [95ed64a55b30d0664a61446f7193ca36]
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\comyninu|ImagePath, C:\Program Files (x86)\07599E80-1439095677-81E1-3676-5404A63C37F3\hnsfB1D2.tmp, Quarantined, [631f31d8711aa49242b9ff9e05ff1ae6]
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\dezyloje|ImagePath, C:\Program Files (x86)\07599E80-1439095677-81E1-3676-5404A63C37F3\knsfD0EE.tmpfs, Quarantined, [5e2482879fecb6803cbf9805917309f7]
PUP.Optional.MediaService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\MEDIASERVICE|ImagePath, C:\Users\Owner\AppData\Roaming\TWV\MediaService.exe, Quarantined, [8101f316e3a842f460c5d2d6986c31cf]
PUP.Optional.WebBar.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WBSVC|ImagePath, "C:\Program Files\WebBar\wbsvc.exe", Quarantined, [146e16f38803ec4a811452d5e61d9070]
PUP.Optional.Shopperz.A, HKU\S-1-5-18\SOFTWARE\{599bdce5-e3a1-4b2a-83a7-ddafa1c42d9c}|Name, C:\Program Files\shopperz04082015\Sfval.exe, Quarantined, [0c76ab5ebccfca6c5e17baf452b2ca36]
PUP.Optional.Shopperz.A, HKU\S-1-5-19\SOFTWARE\{599bdce5-e3a1-4b2a-83a7-ddafa1c42d9c}|Name, C:\Program Files\shopperz04082015\Sfval.exe, Quarantined, [433f4cbdbfccb87ec8ad377731d3de22]
PUP.Optional.Shopperz.A, HKU\S-1-5-20\SOFTWARE\{599bdce5-e3a1-4b2a-83a7-ddafa1c42d9c}|Name, C:\Program Files\shopperz04082015\Sfval.exe, Quarantined, [a2e039d0296243f38fe62a84b74dd22e]
PUP.Optional.AnyProtect, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\ANYPROTECT|ABTest, {"general":{"test_id":"B6","installer_pre_page":true,"scanner_pre_page":false},"1":{"email_check":true},"7":{"notification_20_mins":"3A"},"9":{"scan_page_id":2},"12":{"upclick_exit_show":false,"upclick_exit_countries":{"US":{"phone":"(855) 602-9762"},"CA":{"phone":"(855) 602-9762"},"UK":{"phone":"0800 031 4647"},"GB":{"phone":"0800 031 4647"},"AU":{"phone":"1800-762-367"}}},"14":{"upclick_scan_id_show":false,"upclick_scan_id":"000-000-000"},"15":{"upclick_bottom_offer_show":false,"upclick_bottom_offer_countries":{"US":{"phone":"(855) 602-9762"},"GB":{"phone":"0800 031 4647"},"UK":{"phone":"0800 031 4647"},"DE":{"phone":"800-182-0188"},"CA":{"phone":"(855) 602-9762"},"AU":{"phone":"1800-762-367"},"FR":{"phone":"9 75 18 72 00"}}},"18":{"movie":1}}, Quarantined, [7c06a267325941f5693eded0b84c38c8]
PUP.Optional.ConsumerInput, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\APPDATALOW\SOFTWARE\COMPETE|Install_Dir, C:\Program Files (x86)\Consumer Input\InternetExplorer, Quarantined, [c7bb92775734c670e5c34e60c53fdb25]
PUP.Optional.CinemaPlus.C, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\ARENAHD|value, 1, Quarantined, [7f0364a5a1ea9b9b266ce3bf38cc2cd4]
PUP.Optional.BProtector, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\BPROTECTOR|iexplore homepages, http://asus.msn.com^^, Quarantined, [f38f070275161422bfc051ece22219e7]
PUP.Optional.GlobalUpdate.C, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY|source, IE, Quarantined, [e0a20dfc5b30ba7c9e2fc65a9c6716ea]
PUP.Optional.PCTuner.C, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\HIGHDEFACTION|value, 1, Quarantined, [d0b29970aae1a294e5b7bce6da2a16ea]
PUP.Optional.ConsumerInput.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|[email protected], C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12191.xpi, Quarantined, [097938d1d9b257dfa32944f48f74f010]
PUP.Optional.SuperOptimizer.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\SUPER OPTIMIZER|SetupName, C:\Users\Owner\AppData\Local\Temp\f9626892-7a78-3199-abd2-97bbce96297b\adv_100.exe, Quarantined, [760c45c4f893b77ffb06ccdcb4506a96]
PUP.Optional.SuperOptimizer.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\SUPER OPTIMIZER|AdsBuyNowURL, http://supc33.superp...85-DC78174C77F8, Quarantined, [542ed138e0ab92a43d0ee2c38d77c23e]
PUP.Optional.MediaService.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\TWV|version, 1, Quarantined, [800221e8f398b77fd45010986a9a2fd1]
PUP.Optional.Shopperz.A, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\{599bdce5-e3a1-4b2a-83a7-ddafa1c42d9c}|Name, C:\Program Files\shopperz04082015\Sfval.exe, Quarantined, [f68ca762e6a546f0e88d931bd82cf50b]

Registry Data: 4
PUM.Hijack.StartMenu, HKU\S-1-5-21-3206371679-4115178929-761777742-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED|Start_ShowSearch, 0, Good: (1), Bad: (0),Replaced,[ed9533d6ccbf83b3ef9fb89610f5d62a]
Trojan.DNSChanger, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{086893CE-DFF2-436F-A597-AF439872C8A2}|NameServer, 82.163.143.152,82.163.142.154, Good: (), Bad: (82.163.143.152,82.163.142.154),Replaced,[1f631cedcebd9f97d7ca005458ade020]
Trojan.DNSChanger, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{45142FFD-8A27-4A5D-AB0C-21C3D33841BA}|NameServer, 82.163.143.152,82.163.142.154, Good: (), Bad: (82.163.143.152,82.163.142.154),Replaced,[d6ac8287701b50e6455c252f5aab0ef2]
Trojan.DNSChanger, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{B6E6BE54-A718-4AF6-95D1-75DB49F73055}|NameServer, 82.163.143.152,82.163.142.154, Good: (), Bad: (82.163.143.152,82.163.142.154),Replaced,[f2903acf73189f97b3ee83d14fb634cc]

Folders: 144
PUP.Optional.WebBar.A, C:\Users\Owner\AppData\Local\WebBar, Delete-on-Reboot, [b2d0b257335858de5f86879856adbb45],
PUP.Optional.WebBar.A, C:\Windows\System32\config\systemprofile\AppData\Local\WebBar, Quarantined, [b5cd43c6c3c8a195b13449d60df64cb4],
PUP.Optional.WebBar.A, C:\Program Files\WebBar, Delete-on-Reboot, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.WebBar.A, C:\Program Files\WebBar\2.0.5659.26749, Delete-on-Reboot, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.InstallSightSDK.A, C:\ProgramData\InstallSightSDK, Quarantined, [8ff358b1fb9059ddac7c0e9504009868],
PUP.Optional.ConvertAd.A, C:\Users\Owner\AppData\Local\07599E80-1439070532-81E1-3676-5404A63C37F3, Quarantined, [275b49c02269fc3a556ce6c46b99649c],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Consumer Input, Quarantined, [3a48b8510c7fcf67456deafb46bcef11],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Consumer Input\CrashReports, Quarantined, [3a48b8510c7fcf67456deafb46bcef11],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input, Delete-on-Reboot, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\CrashReports, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Firefox, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\InternetExplorer, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\InternetExplorer\x64, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Monitoring, Delete-on-Reboot, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\1.3.25.309, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\Download, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\Download\{1138A907-2253-45D6-99C1-843A0AC58730}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\Download\{1138A907-2253-45D6-99C1-843A0AC58730}\0.0.0.0, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\Download\{B3F80DB8-951F-4A2A-BE2F-ED6F4FF63B98}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\Download\{B3F80DB8-951F-4A2A-BE2F-ED6F4FF63B98}\0.0.0.0, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\Download\{C7B061F6-380E-4545-86E3-400E3156FD28}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\Download\{C7B061F6-380E-4545-86E3-400E3156FD28}\0.0.0.0, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\Install, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\Offline, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\Offline\{A91E0291-F173-4EED-9070-370FEBCF6AEC}, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\addon, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\content, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\cookies, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\homepage, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\incognito, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\info, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\logging, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\logging\appenders, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\popups, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\sender, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\storage, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\storage\file, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\storage\preferences, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\storage\registry, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\tabs, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\uninstall, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\utils, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\utils\compression, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\voicebox, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\web, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\windows, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\xhr, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\bus, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\config, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\dispatchers, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\dispatchers\killswitch, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\dispatchers\killswitch\triggers, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\downloaders, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\listeners, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\providers, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\reporter, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\retriever, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\storage, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\capture, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\ajax, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\ajax\config, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\clicksending, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\clicksending\config, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\clicksending\processors, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\component, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\cookies, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dcaservice, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dcaservice\config, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dispatchers, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dispatchers\deadmen, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\epochtime, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\epochtime\config, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\eventsending, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\piirules, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\piirules\config, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\reporters, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\utils, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\eventDiagnostic, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\pingModule, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\sendingStats, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\testclick, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\eula, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\event, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\exceptions, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\extensionManager, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\extensionManager\install, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\extensionManager\install\strategies, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\extensionManager\update, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\config, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\parser, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\providers, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\utils, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalReader, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\machine, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\notification, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\notification\actions, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\notification\config, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\partnerActivation, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\session, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\session\settings, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\settings, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\substitution, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\substitution\config, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\substitution\settings, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\compression, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\crypto, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\actions, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\validators, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\web, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\icons, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\addon, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\content, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\cookies, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\incognito, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\info, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\logging, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\logging\appenders, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\popups, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\sender, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\storage, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\storage\file, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\storage\preferences, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\storage\registry, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\tabs, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\utils, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\utils\compression, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\voicebox, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\web, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\windows, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\xhr, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\_metadata, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Setup Support for Consumer Input, Quarantined, [176b31d8c2c940f67c3daa634cb7b64a],

Files: 559
PUP.Optional.Compete, C:\Program Files (x86)\Consumer Input\Monitoring\dca-monitoring.exe, Delete-on-Reboot, [ff8368a128633501bd60691dcd38b64a],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\ConsumerInputUpdate.exe, Quarantined, [42403acfe7a4082ec88760bce21f6c94],
PUP.Optional.Compete, C:\Program Files (x86)\Consumer Input\InternetExplorer\x64\dca-bho.dll, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, C:\Program Files (x86)\Consumer Input\InternetExplorer\dca-bho.dll, Quarantined, [ceb47495cdbed95d2eefe4a2cd38629e],
PUP.Optional.Compete, C:\Program Files (x86)\Consumer Input\CIuninstall.exe, Quarantined, [156dc3466a21e84e35e881057c898f71],
PUP.Optional.Installcore, C:\Users\Owner\Downloads\7 Wonders_ Treasures of Seven__3422_il1095080.exe, Quarantined, [fd85c841385373c3b66d384f4fb6db25],
Trojan.Agent, C:\Users\Owner\AppData\Local\07599E80-1439070532-81E1-3676-5404A63C37F3\pnsaA0E5.exe, Quarantined, [3c461ced8308aa8c50be43fd1ce94cb4],
PUP.Optional.BrowserAir.C, C:\Users\Owner\AppData\Local\Installer\Install_23404\DCbrakieamo_amobl_setup.exe, Quarantined, [176bbb4eddae82b4282813740bfafb05],
PUP.Optional.BrowserAir.C, C:\Users\Owner\AppData\Local\Installer\Install_24213\DCbrakieamo_amobl_setup.exe, Quarantined, [1b6766a3acdf6ccaa7a9fb8c3acbfa06],
PUP.Optional.WombatUpdater.A, C:\Windows\AppPatch\Custom\{a53dd3e5-0283-4ab3-b77c-7bd1bc7550c6}.sdb, Quarantined, [b5cda861d2b943f330e2c7502cd7d42c],
PUP.Optional.WebBar.A, C:\Users\Owner\AppData\Local\WebBar\wb.log, Delete-on-Reboot, [b2d0b257335858de5f86879856adbb45],
PUP.Optional.WebBar.A, C:\Users\Owner\AppData\Local\WebBar\wb.app.settings, Quarantined, [b2d0b257335858de5f86879856adbb45],
PUP.Optional.WebBar.A, C:\Users\Owner\AppData\Local\WebBar\wb.user.history, Quarantined, [b2d0b257335858de5f86879856adbb45],
PUP.Optional.WebBar.A, C:\Users\Owner\AppData\Local\WebBar\wb.user.settings, Quarantined, [b2d0b257335858de5f86879856adbb45],
PUP.Optional.WebBar.A, C:\Windows\System32\config\systemprofile\AppData\Local\WebBar\wb.log, Quarantined, [b5cd43c6c3c8a195b13449d60df64cb4],
PUP.Optional.Crossbrowse.C, C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\crossbrowse.lnk, Quarantined, [d8aa848583080f276e681d03ec17d62a],
PUP.Optional.Crossbrowse.A, C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Crossbrowse.lnk, Quarantined, [750d05040883d561f311a57ce91a5ea2],
PUP.Optional.WebBar.A, C:\Windows\System32\Tasks\WebBarUpdateTask, Quarantined, [2e5424e54d3e41f510a60e14a85b37c9],
PUP.Optional.WebBar.A, C:\Program Files\WebBar\unins000.dat, Quarantined, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.WebBar.A, C:\Program Files\WebBar\InstallUtil.InstallLog, Quarantined, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.WebBar.A, C:\Program Files\WebBar\ISightSDK.dll, Quarantined, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.WebBar.A, C:\Program Files\WebBar\Microsoft.Win32.TaskScheduler.dll, Quarantined, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.WebBar.A, C:\Program Files\WebBar\unins000.exe, Quarantined, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.WebBar.A, C:\Program Files\WebBar\wbsvc.exe, Quarantined, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.WebBar.A, C:\Program Files\WebBar\wbsvc.exe.config, Quarantined, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.WebBar.A, C:\Program Files\WebBar\wbsvc.InstallLog, Quarantined, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.WebBar.A, C:\Program Files\WebBar\wbsvc.InstallState, Quarantined, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.WebBar.A, C:\Program Files\WebBar\2.0.5659.26749\Interop.SHDocVw.dll, Quarantined, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.WebBar.A, C:\Program Files\WebBar\2.0.5659.26749\ISightSDK.dll, Quarantined, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.WebBar.A, C:\Program Files\WebBar\2.0.5659.26749\ISightSDK_x64.dll, Delete-on-Reboot, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.WebBar.A, C:\Program Files\WebBar\2.0.5659.26749\log4net.dll, Delete-on-Reboot, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.WebBar.A, C:\Program Files\WebBar\2.0.5659.26749\Newtonsoft.Json.dll, Delete-on-Reboot, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.WebBar.A, C:\Program Files\WebBar\2.0.5659.26749\System.Threading.dll, Delete-on-Reboot, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.WebBar.A, C:\Program Files\WebBar\2.0.5659.26749\wb.exe, Delete-on-Reboot, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.WebBar.A, C:\Program Files\WebBar\2.0.5659.26749\wb.exe.config, Quarantined, [4a38c148f992082e6d26bd6ae91aeb15],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{f3e41bda-246e-4159-bfab-605b34e2ce62}Gw64.sys, Quarantined, [1969b1581675999d97740d392cd77888],
PUP.Optional.ConsumerInput.A, C:\Windows\System32\Tasks\ConsumerInputUpdateTaskMachineCore, Quarantined, [433ff019296205314b452f1ceb18bb45],
PUP.Optional.ConsumerInput.A, C:\Windows\System32\Tasks\ConsumerInputUpdateTaskMachineUA, Quarantined, [6a180aff6a213afceaa6af9c8d76936d],
PUP.Optional.ConsumerInput.A, C:\Windows\Tasks\ConsumerInputUpdateTaskMachineCore.job, Quarantined, [7111d237c7c4fc3a5978bcd0e4209f61],
PUP.Optional.ConsumerInput.A, C:\Windows\Tasks\ConsumerInputUpdateTaskMachineUA.job, Quarantined, [087afd0cc6c57eb8eee3ace07490a65a],
PUP.Optional.ConsumerInput.A, C:\Windows\Tasks\CIMT_daily_S-1-5-21-3206371679-4115178929-761777742-1000.job, Quarantined, [156de623385390a682eb44568a7adc24],
PUP.Optional.ConsumerInput.A, C:\Windows\System32\Tasks\CIMT_daily_S-1-5-21-3206371679-4115178929-761777742-1000, Quarantined, [810108019af1bf772c425d3d0bf9956b],
PUP.Optional.ConsumerInput.A, C:\Windows\Tasks\CIMT_S-1-5-21-3206371679-4115178929-761777742-1000.job, Quarantined, [6919df2ac5c6af87eb848218f212ec14],
PUP.Optional.ConsumerInput.A, C:\Windows\System32\Tasks\CIMT_S-1-5-21-3206371679-4115178929-761777742-1000, Quarantined, [1f63f712f49778be89e7bfdbc53f33cd],
PUP.Optional.WebBar.A, C:\Windows\System32\Tasks\WebBarLaunchTask, Quarantined, [6a18cd3c7b10a2940c899b019470c33d],
PUP.Optional.InstallSightSDK.A, C:\ProgramData\InstallSightSDK\3c99e24ae.dat, Quarantined, [8ff358b1fb9059ddac7c0e9504009868],
PUP.Optional.ConvertAd.A, C:\Users\Owner\AppData\Local\07599E80-1439070532-81E1-3676-5404A63C37F3\Uninstall.exe, Quarantined, [275b49c02269fc3a556ce6c46b99649c],
PUP.Optional.ConvertAd.A, C:\Users\Owner\AppData\Local\07599E80-1439070532-81E1-3676-5404A63C37F3\pnsaA0E5.exe, Quarantined, [275b49c02269fc3a556ce6c46b99649c],
PUP.Optional.ConvertAd.A, C:\Users\Owner\AppData\Local\07599E80-1439070532-81E1-3676-5404A63C37F3\rnsaA0E3.exe, Quarantined, [275b49c02269fc3a556ce6c46b99649c],
PUP.Optional.Linkury.ShrtCln, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\findit.xml, Quarantined, [97eb5baecdbe171f53d4991b0bf9a35d],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\CIuninstall.ico, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12191.xpi, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Firefox\uninstall.exe, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Firefox\uninstall.ico, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\InternetExplorer\cookie-retriever.exe, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\InternetExplorer\cpturlpassthru.dll, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\InternetExplorer\x64\cpturlpassthru.dll, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\InternetExplorer\dca-host.exe, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\InternetExplorer\dca.js, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\InternetExplorer\mozjs185-1.0.dll, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\InternetExplorer\uninstall.exe, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\InternetExplorer\uninstall.ico, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\InternetExplorer\uninstall.log, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\InternetExplorer\x64\cookie-retriever.exe, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Monitoring\cinm-host.exe, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Monitoring\cookie-retriever.exe, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Monitoring\manifest.json, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Monitoring\uninstall.exe, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Monitoring\uninstall.ico, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\1.3.25.309\ConsumerInputCrashHandler.exe, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\1.3.25.309\ConsumerInputUpdate.exe, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\1.3.25.309\ConsumerInputUpdateBroker.exe, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\1.3.25.309\ConsumerInputUpdateHelper.msi, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\1.3.25.309\ConsumerInputUpdateOnDemand.exe, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\1.3.25.309\goopdate.dll, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\1.3.25.309\goopdateres_de.dll, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\1.3.25.309\goopdateres_en.dll, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\1.3.25.309\goopdateres_es-419.dll, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\1.3.25.309\goopdateres_es.dll, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\1.3.25.309\goopdateres_fr.dll, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\1.3.25.309\goopdateres_ja.dll, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\1.3.25.309\goopdateres_zh-CN.dll, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\1.3.25.309\psmachine.dll, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\1.3.25.309\psuser.dll, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\Download\{1138A907-2253-45D6-99C1-843A0AC58730}\0.0.0.0\ciie-3.2.0-12405.exe, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\Download\{B3F80DB8-951F-4A2A-BE2F-ED6F4FF63B98}\0.0.0.0\cimt-3.2.1-1105.exe, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Consumer Input\Update\Download\{C7B061F6-380E-4545-86E3-400E3156FD28}\0.0.0.0\ciff-3.2.0-12191.exe, Quarantined, [562c9c6deba0c472ab08f8edd72bed13],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\background.html, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\manifest.json, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\SettingsInit.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\CICRSettings.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\Initializer.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\addon\MockAddonManager.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\content\CodeExecutor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\content\CodeExecutorFactory.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\content\ConnectionPort.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\content\ContentEventsObserver.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\content\ContentMessagesRetriever.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\content\contentScripts.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\content\WebRequestListenerMixin.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\cookies\CookieManager.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\cookies\CookieManagerFactory.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\homepage\HomepageTracker.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\incognito\Mode.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\info\Environment.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\logging\appenders\ConsoleAppender.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\popups\PopupsFactory.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\popups\PopupsTracker.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\sender\ExternalEventSender.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\sender\ExternalSenderFactory.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\storage\StorageFactory.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\storage\WebStorage.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\storage\file\FileStorage.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\storage\preferences\PreferenceObserver.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\storage\preferences\PreferenceStorageNotifier.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\storage\registry\RegistryStorage.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\tabs\Tab.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\tabs\TabController.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\tabs\TabVisibilityWatcher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\uninstall\UninstallExecutor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\utils\Generators.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\utils\compression\Adler32Calculator.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\utils\compression\CompressorFactory.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\utils\compression\DeflateCompressor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\utils\compression\RawDeflateCompressor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\voicebox\ImageVoicebox.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\voicebox\VoiceboxFactory.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\web\WebRequestCache.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\web\WebRequestObserver.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\windows\ChromeWindow.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\windows\WindowController.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\xhr\ErrorMessageProcessor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\xhr\NetworkErrorList.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\xhr\Request.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\chrome\xhr\RequestFactory.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\Core.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\CoreInitializer.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\CoreListenerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\CoreListenerPrototype.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\HeaderProcessor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\ModuleInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\ReportableSubject.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\bus\BusClientInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\bus\CommunicationBus.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\CachingService.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\CachingServiceBuilder.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\CachingServiceCommunicator.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\CachingServiceInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\CachingServiceStatus.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\config\CachingServiceConfig.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\config\ConfigParserInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\dispatchers\CachingDispatcherInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\dispatchers\CachingSourceDispatcher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\dispatchers\IntervalDispatcher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\dispatchers\PrefSwitcher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\dispatchers\SwitcherComposite.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\dispatchers\UpdateInterval.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\dispatchers\URLDispatcher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\dispatchers\killswitch\KillSwitchContext.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\dispatchers\killswitch\KillSwitchContextListenerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\dispatchers\killswitch\KillSwitchDispatcher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\dispatchers\killswitch\KillSwitchFactory.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\dispatchers\killswitch\triggers\CaptureTypeKillSwitchTrigger.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\dispatchers\killswitch\triggers\ClickDisableKillSwitchTrigger.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\dispatchers\killswitch\triggers\EulaVersionKillSwitchTrigger.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\dispatchers\killswitch\triggers\KillSwitchTriggerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\downloaders\DownloadController.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\downloaders\DownloadControllerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\downloaders\DownloaderInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\downloaders\UrlBasedDownloader.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\listeners\AbstractCachingServiceConfigListener.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\listeners\ListenersQueue.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\providers\AbstractServiceConfigProvider.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\providers\CachingServiceConfigProvider.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\providers\CachingServiceConfigProviderInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\providers\DCAProfileServiceConfigProvider.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\providers\StaticConfigProvider.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\reporter\ServiceFailureAdaptor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\reporter\ServiceStatusReporter.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\retriever\CachePreferencesController.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\retriever\ConfigRetriever.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\retriever\ConfigRetrieverInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\storage\CachingStorage.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\caching\storage\CachingStorageInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\capture\CaptureType.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\capture\CaptureTypeChangeNotifier.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\capture\CaptureTypeModule.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\capture\Type.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\AbstractDataProcessor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\AbstractEvent.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\AddonStateListener.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\DataProcessorInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\DCAContext.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\DCAContextListenerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\DCAServicesManager.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\PriorityEnum.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\ajax\AjaxClickProcessor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\ajax\WhitelistSettings.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\ajax\config\AjaxClickConfig.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\ajax\config\AjaxClickTrackingEntry.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\ajax\config\WhitelistConfigParser.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\clicksending\AbstractClickSender.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\clicksending\ClickBatchSender.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\clicksending\ClickDataSender.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\clicksending\ClickSendingComponentController.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\clicksending\ClickSendingFactory.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\clicksending\ClickSendingServiceSettings.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\clicksending\ClickSwitcher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\clicksending\DCAClick.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\clicksending\config\ClickSendingConfig.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\clicksending\config\ClickSendingConfigParser.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\clicksending\config\ClickSendingConfigProvider.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\clicksending\processors\BatchCompressionProcessor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\clicksending\processors\CaptureTypeProcessor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\clicksending\processors\ClickIDProcessor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\clicksending\processors\EventTypeFilteringProcessor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\clicksending\processors\PopupProcessor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\component\ComponentControllerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\component\ComponentRegistry.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\cookies\CookieManagerWrapper.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\cookies\CookieReader.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\cookies\DcaPrefsCookieChangeHandler.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\cookies\DcaPrefsCookieListener.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\cookies\DcaPrefsCookieParser.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\cookies\DcaPrefsCookieReader.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\cookies\DcaPrefsCookieUpdater.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dcaservice\ConfigVersionProvider.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dcaservice\CrashDumpProvider.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dcaservice\DCAConfigServiceSettings.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dcaservice\DCAServiceComponentController.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dcaservice\DCAServicesFactory.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dcaservice\ParserRegistrySetup.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dcaservice\ServiceConfigUrlProvider.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dcaservice\config\DCAConfigInvalidException.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dcaservice\config\DCAConfigValidator.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dcaservice\config\DCAServiceConfig.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dcaservice\config\DCAServiceConfigParser.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dcaservice\config\MetaProfile.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dcaservice\config\MetaProfileParser.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dcaservice\config\MetaProfileParserRegistry.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dcaservice\config\ServiceConfigParser.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dispatchers\ConfigAvailabilityDispatcher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dispatchers\IncognitoModeDispatcher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dispatchers\ServiceConfigDispatcher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dispatchers\deadmen\DeadManComponentsFactory.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dispatchers\deadmen\DeadMenContext.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dispatchers\deadmen\DeadMenProbationSettingsWatcher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dispatchers\deadmen\DeadMenProbationWatcher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dispatchers\deadmen\DeadMenSwitchDispatcher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dispatchers\deadmen\DeadMenThresholdSettingsWatcher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dispatchers\deadmen\DeadMenWatcher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dispatchers\deadmen\PrivacyRulesDeadMenSwitchDispatcher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\dispatchers\deadmen\PrivacyRulesFailuresWatcher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\epochtime\DCAServerTime.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\epochtime\EpochTimeCachingStorage.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\epochtime\EpochTimeComponentController.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\epochtime\EpochTimeServiceSettings.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\epochtime\EpochTimeWorker.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\epochtime\TimeStampProcessor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\epochtime\config\EpochTimeConfigParser.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\eventsending\CaptureTypeEventSwitcher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\eventsending\DCAEvent.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\eventsending\DCAEventComposer.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\eventsending\EventDataSender.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\eventsending\EventSendingServiceSettings.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\piirules\PrivacyRuleSetExecutor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\piirules\PrivacyRulesProcessor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\piirules\PrivacyRulesSettings.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\piirules\PrivacyRulesWorker.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\piirules\PrivacyURL.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\piirules\PrivacyURLParameter.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\piirules\UserAgentWorker.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\piirules\config\PrivacyRuleEntry.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\piirules\config\PrivacyRulesConfig.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\piirules\config\PrivacyRuleSet.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\piirules\config\PrivacyRulesParser.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\piirules\config\PrivacyRulesServiceConfig.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\piirules\config\PrivacyRulesServiceConfigParser.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\reporters\AbstractDataSenderImpl.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\reporters\DataBatch.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\reporters\DataBatchingIntervalScheduler.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\reporters\DataReporter.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\reporters\DataReporterListenerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\reporters\DataSenderInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\reporters\GenericDataSender.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\reporters\MultipleDataWorker.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\reporters\ProcessorsChain.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\reporters\ReportersFactory.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\reporters\ReporterStateListenerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\reporters\SchedulerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\reporters\SingleDataWorker.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\reporters\SingleThreadedIntervalScheduler.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\reporters\StartAutoControllableScheduler.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\reporters\SwitchableScheduler.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\utils\ConfigBasedIntervalScheduler.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\utils\ContentTypeFilter.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\utils\DCAPostDataParser.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\utils\SwitcherBasedStarter.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\dca\utils\UrlFormatter.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\AddOnStateListener.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\ClickProcessingTestCaseWriter.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\DiagnosticModule.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\eventDiagnostic\EventSendDateModule.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\eventDiagnostic\EventSendSettings.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\eventDiagnostic\StatsSaver.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\pingModule\PingModule.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\pingModule\PingServiceSettings.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\sendingStats\StatisticCollector.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\sendingStats\StatisticModel.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\sendingStats\StatisticModule.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\sendingStats\StatisticSettings.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\testclick\TCConfigListeners.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\testclick\TCDispatcherState.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\testclick\TCReporterListener.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\testclick\TestClickModule.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\diagnostic\testclick\TestDCAClick.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\eula\EulaVersion.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\eula\EulaVersionModule.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\event\EventReporter.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\event\EventReporterModule.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\exceptions\AbstractMethodException.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\exceptions\DOMInvalidException.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\exceptions\DOMNotWellFormedException.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\exceptions\ParserException.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\extensionManager\ExtensionProcedures.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\extensionManager\UninstallerProcedures.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\extensionManager\install\InstallDetails.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\extensionManager\install\InstallDetailsProvider.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\extensionManager\install\InstallProcedures.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\extensionManager\install\PostInstallPageCoordinator.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\extensionManager\install\strategies\AbstractInstallStrategy.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\extensionManager\install\strategies\InstallAPIStrategy.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\extensionManager\install\strategies\InstallEXTStrategy.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\extensionManager\install\strategies\InstallSDKStrategy.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\extensionManager\update\CorePostUpdateListener.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\extensionManager\update\UpdateProcedures.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\EJSCacheDispatcher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\EJSCompressionProcessor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\EJSConfigRetriever.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\EJSDataComposingProcessor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\EJSDataSender.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\EJSServiceFactory.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\EJSServiceListener.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\ExecutorController.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\ExternalJSCacheCleaner.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\ExternalJSController.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\ExternalJSSettings.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\ModuleController.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\ModulesApplier.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\ModulesApplierInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\config\ExternalJSModule.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\config\ExternalJSResult.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\config\ExternalJSScript.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\parser\ExternalJSModuleParser.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\parser\ExternalJSScriptParser.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\parser\ExternalJSServiceConfigParser.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\providers\EJSModuleServiceConfigProvider.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\utils\DelayedExecutor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalJS\utils\EJSResultScheduler.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\externalReader\RegistryExternalReader.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\machine\MachineID.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\machine\MachineIDModule.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\machine\MachineIDRetriever.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\notification\InstallTimeSaver.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\notification\NotificationActionFactory.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\notification\NotificationActivityWatcher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\notification\NotificationComponentController.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\notification\NotificationLauncher.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\notification\NotificationPrefAdapter.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\notification\NotificationQueue.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\notification\NotificationSettings.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\notification\NotificationTrigger.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\notification\NotificationValidator.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\notification\actions\ActionListener.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\notification\config\Notification.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\notification\config\NotificationConfig.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\notification\config\NotificationConfigParser.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\notification\config\NotificationParser.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\partnerActivation\ActivationListener.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\partnerActivation\ActivationManager.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\partnerActivation\ActivationSender.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\partnerActivation\ActivationSettings.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\partnerActivation\PostBackContext.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\partnerActivation\SyncStorageExecutor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\session\login.xul, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\session\SessionTrackerConfig.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\session\SessionTrackerConfigProvider.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\session\SessionTrackerParser.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\session\SessionTrackerView.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\session\SessionTrackerViewInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\session\STViewHttpListener.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\session\settings\SessionTrackerSettings.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\settings\dcaSettings.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\settings\OptionsChangeNotifier.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\settings\OptionsListenerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\substitution\ComponentController.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\substitution\ContentReplacer.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\substitution\ContentReplacerController.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\substitution\ReplacingScript.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\substitution\config\ReplacementEntry.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\substitution\config\SubstitutionConfigParser.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\substitution\config\SubstitutionModel.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\substitution\config\SubstitutionRule.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\substitution\settings\SubstitutionSettings.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\ArrayUtils.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\DateUtils.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\debugUtils.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\FolderRemover.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\MD5Calculator.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\ParsingUtils.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\RequestDataFormer.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\ServiceSettingsGenerator.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\StorageCleaner.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\UrlHelper.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\utils.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\compression\AbstractCompressionProcessor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\crypto\BigInteger.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\crypto\cryptoUtils.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\crypto\DES.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\crypto\EncryptionKeysInfo.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\crypto\EncryptionProcessor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\crypto\Encryptor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\utils\crypto\RSA.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\VBChangesNotifier.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\VBComponentsFactory.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\VBConfigController.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\VBController.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\VBRulesProvider.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\VBSynchronizedRule.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\VBWindowController.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\VBWindowListener.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\VoiceBoxAddonManagerListener.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\VoiceBoxNavigator.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\VoiceBoxParser.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\VoiceboxPostProcessingListener.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\VoiceBoxRule.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\VoiceBoxScheduler.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\VoiceBoxServiceSettings.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\VoiceBoxSettings.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\VoiceBoxUtils.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\actions\VBAbstractCloseAction.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\actions\VBActionInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\actions\VBActionsFactory.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\actions\VBBrokenAction.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\actions\VBClickedAction.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\actions\VBClosedAction.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\actions\VBDisplayedAction.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\actions\VBDownloadErrorAction.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\actions\VBImageErrorAction.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\actions\VBTimeoutAction.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\actions\VBTriggeredAction.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\validators\VBExpiredValidator.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\validators\VBLastDisplayValidator.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\validators\VBNumDisplaysValidator.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\voicebox\validators\VBStartTimeValidator.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\web\ClicksCollector.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\web\WebNavigationEvent.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\web\WebNavigationListenerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\web\WebNavigationObserver.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\web\WebNavigationsFactory.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\core\web\WebNavigationTypes.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\icons\logo128.png, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\icons\logo16.png, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\icons\logo48.png, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\Context.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\InitializerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\InitializerListenerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\addon\AbstractAddonManager.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\addon\AddOn.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\addon\AddOnManagerFactoryInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\addon\AddOnManagerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\addon\AddOnManagerListenerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\addon\CoreAddOnManager.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\addon\UninstallState.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\content\CodeExecutorFactoryInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\content\CodeExecutorInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\content\ContentEvent.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\content\ContentEventsObserverInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\cookies\CookieItem.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\cookies\CookieListenerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\cookies\CookieManagerFactoryInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\cookies\CookieManagerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\incognito\ModeInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\incognito\ModeListenerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\info\BrowserVersion.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\info\EnvironmentInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\info\URLOpenStrategy.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\logging\LoggerBuilder.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\logging\LoggerFactory.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\logging\LoggerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\logging\LoggerSettings.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\logging\appenders\FileAppender.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\logging\appenders\LoggerAppenderInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\popups\PopupsFactoryInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\popups\PopupsTrackerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\popups\PopupTrackerListener.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\sender\ExternalEventSenderInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\sender\ExternalSenderFactoryInterfaces.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\storage\GenericStorage.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\storage\ItemsFilter.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\storage\StorageFactoryInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\storage\StorageInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\storage\file\FilePermissionFlags.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\storage\file\FileStorageInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\storage\file\PermissionRetrieverMixin.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\storage\preferences\PreferenceController.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\storage\preferences\PreferenceControllerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\storage\preferences\PreferenceListenerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\storage\preferences\PreferenceObserverInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\storage\preferences\PreferenceStorageAdaptor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\storage\registry\RegistryStorageAdaptor.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\storage\registry\RegistryStorageInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\tabs\TabControllerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\tabs\TabInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\tabs\TabListenerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\utils\EcmaScript5.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\utils\GeneratorsInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\utils\ImageDataRetriever.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\utils\ImageDataRetrieverInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\utils\Inheritance.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\utils\InstanceCounter.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\utils\ListenersHandlerMixin.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\utils\NotImplementedException.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\utils\SelfClearedDataPoolMixin.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\utils\compression\CompressorFactoryInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\utils\compression\CompressorInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\voicebox\VoiceboxFactoryInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\voicebox\VoiceboxInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\voicebox\VoiceboxListenerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\web\WebRequest.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\web\WebRequestFactoryInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\web\WebRequestListenerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\web\WebRequestModification.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\web\WebRequestObserverInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\windows\WindowControllerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\windows\WindowInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\windows\WindowListenerInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\xhr\RequestInterface.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\xhr\Response.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\xhr\ResponseFactory.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\interfaces\xhr\ResponseStatus.js, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\_metadata\computed_hashes.json, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc\3.2.0.3219_0\_metadata\verified_contents.json, Quarantined, [6f13ed1c216acb6b612a1ced02019d63],
PUP.Optional.ConsumerInput.A, C:\Program Files (x86)\Setup Support for Consumer Input\uninst.exe, Quarantined, [176b31d8c2c940f67c3daa634cb7b64a],
PUP.Optional.Babylon.A, C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js, Good: (), Bad: (user_pref("extensions.BabylonToolbar_i.aflt", "babsst");), Replaced,[7d05fe0b088374c290ef5537bb4a7b85]
PUP.Optional.Babylon.A, C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js, Good: (), Bad: (nces

/* Do not edit this file.
 *
 * If you mak), Replaced,[51319e6b246786b09de2375582837e82]
PUP.Optional.Babylon.A, C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js, Good: (), Bad: (ferences

/* Do not edit this file.
 *
 * If you make changes ), Replaced,[523034d58803a591ccb395f70ef7d32d]
PUP.Optional.Babylon.A, C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js, Good: (), Bad: ( Do not edit this file.
 *
 * If you make changes to this file while the applicati), Replaced,[0c76f019850687afc7b8177511f49c64]
PUP.Optional.Babylon.A, C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js, Good: (), Bad: (file.
 *
 * If you make changes to this file while the application is running,), Replaced,[8bf733d63a511620017e67259c69e917]
PUP.Optional.Babylon.A, C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js, Good: (), Bad: (his file.
 *
 * If you make changes to this file while th), Replaced,[79098c7d1774e155106fbeceb352817f]
PUP.Optional.Babylon.A, C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js, Good: (), Bad: (s

/* Do not edit this file.
 *
 * If you make change), Replaced,[8af853b6a6e5db5bd9a62e5e14f1df21]
PUP.Optional.Babylon.A, C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js, Good: (), Bad: (ces

/* Do not edit this file.
 *
 * If you make changes to t), Replaced,[3d4515f4bfcc7cba5c2367258283936d]
PUP.Optional.Babylon.A, C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js, Good: (), Bad: (* Do not edit this file.
 *
 * If you make changes to this), Replaced,[087a0306553684b298e7593312f3d12f]
PUP.Optional.Babylon.A, C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js, Good: (), Bad: (

/* Do not edit this file.
 *
 * If you make changes), Replaced,[daa821e884070036413eb4d8d33228d8]
PUP.Optional.Babylon.A, C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js, Good: (), Bad: (ces

/* Do not edit this file.
 *
 * If you make c), Replaced,[bac89e6b6328f442c4bbe1ab5ea7936d]
PUP.Optional.Babylon.A, C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js, Good: (), Bad: (rences

/* Do not edit this file.
 *
 * If you make ), Replaced,[641e4dbca7e47abcb1ce2765f70ecd33]
PUP.Optional.Babylon.A, C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js, Good: (), Bad: (nces

/* Do not edit this file.
 *
 * If you make chan), Replaced,[a9d931d87d0e9b9b710ebdcfa95cd32d]
PUP.Optional.Babylon.A, C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js, Good: (), Bad: (es

/* Do not edit this file.
 *
 * If you make changes to this ), Replaced,[374b55b4e0ab013592ed1c7018ed0bf5]
PUP.Optional.Babylon.A, C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js, Good: (), Bad: (o not edit this file.
 *
 * If you make changes to this f), Replaced,[abd7be4b1f6c0531b4cb0d7fc54032ce]

Physical Sectors: 0
(No malicious items detected)


(end)


  • 0

#27
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,811 posts
Please do this next,

Next

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the logfile button and the log will open in Notepad.
  • NOTE: If you get an error message, it means that nothing was found. Exit from AdwCleaner.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished and the PC has rebooted.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner
Next

thisisujrt.gif Please download Junkware Removal Tool to your Desktop.

Please close your security software to avoid potential conflicts. See Here how to disable you security protection (Anti Virus)
Run the tool by double-clicking it. If you are using Windows Vista or 7, right-mouse click it and select Run as administrator.
The tool will open and start scanning your system.
Please be patient as this can take a while to complete, depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
Please post the contents of JRT.txt into your reply.


In your next reply post;
  • The AdwCleaner [SO].txt Log
  • The JRT.txt Log
Thanks
Joe :)
  • 0

#28
TriciaDP72

TriciaDP72

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts

AdWare Cleaner Log:

 

# AdwCleaner v5.000 - Logfile created 16/08/2015 at 14:22:20
# Updated 14/08/2015 by Xplode
# Database : 2015-08-16.2 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Owner - OWNER-PC
# Running from : C:\Users\Owner\Desktop\adwcleaner_5.000.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\Users\Owner\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}

***** [ Files ] *****

[-] File Deleted : C:\user.js
[-] File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\yahoo.xml
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_papbadoldddalgcjcicnikcfenodpghp_0
[-] File Deleted : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\papbadoldddalgcjcicnikcfenodpghp
[-] File Deleted : C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\user.js

***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

[-] Task Deleted : bProtector
[-] Task Deleted : WebBarUpdateTask

***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\CptUrlPassthru.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\dca-bho.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
[-] Key Deleted : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
[-] Key Deleted : HKLM\SOFTWARE\5da059a482fd494db3f252126fbc3d5b
[-] Key Deleted : HKLM\SOFTWARE\c15a9597-bfd8-b7d1-05bf-52838fc57072
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{DD7C44CC-0F60-4FD9-A38F-5CF30D698AC2}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{425F4ABF-B8E4-402D-9E49-06E494EB8DBF}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1663C10B-0D55-438D-8496-19A3DBAEC0E4}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A43DE495-3D00-47D4-9D2C-303115707939}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7D8DAE88-BC05-4578-8C29-E541FFBA5757}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9582D7B-F24A-441D-9D26-450D58F3CD17}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{14EF423E-3EE8-44AE-9337-07AC3F27B744}
[!] Key Not Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
[!] Key Not Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A9582D7B-F24A-441D-9D26-450D58F3CD17}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}
[-] Key Deleted : HKU\.DEFAULT\Software\bProtector
[-] Key Deleted : HKU\.DEFAULT\Software\IBUpdaterService
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\Compete
[-] Key Deleted : HKCU\Software\APN PIP
[-] Key Deleted : HKCU\Software\GlobalUpdate
[-] Key Deleted : HKCU\Software\performersoft llc
[-] Key Deleted : HKCU\Software\Online video player
[-] Key Deleted : HKCU\Software\{3BDFD1D7-7A9B-4D29-80B3-D00E66E62885}
[-] Key Deleted : HKCU\Software\DAILYPCCLEAN
[-] Key Deleted : HKLM\SOFTWARE\AppDataLow\SOFTWARE\_CrossriderRegNamePlaceHolder_
[-] Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
[-] Key Deleted : HKLM\SOFTWARE\Babylon
[-] Key Deleted : HKLM\SOFTWARE\GlobalUpdate
[-] Key Deleted : HKLM\SOFTWARE\PIP
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E1527582-8509-4011-B922-29E3FB548882}_is1
[!] Key Not Deleted : [x64] HKCU\Software\APN PIP
[!] Key Not Deleted : [x64] HKCU\Software\GlobalUpdate
[!] Key Not Deleted : [x64] HKCU\Software\performersoft llc
[!] Key Not Deleted : [x64] HKCU\Software\Online video player
[!] Key Not Deleted : [x64] HKCU\Software\{3BDFD1D7-7A9B-4D29-80B3-D00E66E62885}
[!] Key Not Deleted : [x64] HKCU\Software\DAILYPCCLEAN
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GLOBALUPDATE.EXE

***** [ Web browsers ] *****

[-] [C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js] [Preference] Deleted : user_pref("extensions.BabylonToolbar_i.babExt", "");
[-] [C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js] [Preference] Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=101587");
[-] [C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js] [Preference] Deleted : user_pref("extensions.BabylonToolbar_i.hardId", "dcc9ff5c00000000000064d4da65a93b");
[-] [C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js] [Preference] Deleted : user_pref("extensions.BabylonToolbar_i.id", "dcc9ff5c00000000000064d4da65a93b");
[-] [C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js] [Preference] Deleted : user_pref("extensions.BabylonToolbar_i.instlDay", "15418");
[-] [C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js] [Preference] Deleted : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
[-] [C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js] [Preference] Deleted : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
[-] [C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js] [Preference] Deleted : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
[-] [C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js] [Preference] Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
[-] [C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js] [Preference] Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
[-] [C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js] [Preference] Deleted : user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
[-] [C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js] [Preference] Deleted : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
[-] [C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js] [Preference] Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1718:44:27");
[-] [C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\prefs.js] [Preference] Deleted : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");

*************************

:: Proxy settings cleared
:: Winsock settings cleared

*************************

C:\AdwCleaner[C1].txt - [8409 octets] - [16/08/2015 14:22:20]
C:\AdwCleaner[S1].txt - [7970 octets] - [16/08/2015 14:18:13]

########## EOF - C:\AdwCleaner[C1].txt - [8535 octets] ##########
 

 

JRT Log:

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.6 (08.10.2015:1)
OS: Windows 7 Home Premium x64
Ran by Owner on Sun 08/16/2015 at 14:39:30.76
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\browserpluginhelper



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Update Coupon Time
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Util Coupon Time
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\wbsvc



~~~ Files

Failed to delete: [File] C:\Windows\SysWOW64\number of results



~~~ Folders

Successfully deleted: [Folder] C:\ProgramData\best buy pc app
Successfully deleted: [Folder] C:\Users\Owner\Appdata\Local\installer



~~~ Chrome


[C:\Users\Owner\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\Owner\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\Owner\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\Owner\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sun 08/16/2015 at 14:47:09.02
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 


  • 0

#29
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 6,811 posts
Very good.

Now I need to see another FARBER scan, post both logs.

Re-run Farbar Recovery Scan Tool (FRST/FRST64) you ran at the very beginning of this topic.
  • Right click on FRST. "Run as administrator" When the tool opens click Yes to disclaimer. Always run as administrator !
  • Make sure you checkmark Addition.txt box.
  • Press Scan button.
  • Scan will create two logs, FRST.txt and Addition.txt in the same directory the tool is run. Please copy and paste them to your reply.

  • 0

#30
TriciaDP72

TriciaDP72

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts

FRST.txt Log:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:16-08-2015
Ran by Owner (administrator) on OWNER-PC (16-08-2015 15:13:57)
Running from C:\Users\Owner\Desktop
Loaded Profiles: Owner (Available Profiles: Owner)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Webroot) C:\Program Files (x86)\Webroot\WRSA.exe
(Webroot) C:\Program Files (x86)\Webroot\WRSA.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel® Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel® Corporation) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
(Red Bend Ltd.) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2226280 2011-06-02] (Realtek Semiconductor)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [324096 2010-05-02] (Alcor Micro Corp.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2785064 2011-05-05] (Synaptics Incorporated)
HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel® Corporation)
HKLM\...\Run: [SynAsusAcpi] => C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [97064 2011-05-05] (Synaptics Incorporated)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [Setwallpaper] => c:\programdata\SetWallpaper.cmd
HKLM\...\Run: [MRT] => C:\Windows\system32\MRT.exe [132483416 2015-08-13] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3331312 2011-09-23] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-09] (Virage Logic Corporation / Sonic Focus)
HKLM-x32\...\Run: [FLxHCIm] => C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe [43008 2011-04-08] (Windows ® Win 7 DDK provider)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-23] ()
HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [WRSVC] => C:\Program Files (x86)\Webroot\WRSA.exe [822728 2015-07-27] (Webroot)
HKLM-x32\...\Run: [Monitor] => C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe [106496 2013-10-31] (LeapFrog Enterprises, Inc.)
HKLM-x32\...\Run: [EverioService] => C:\Program Files (x86)\CyberLink\PCM4Everio\EverioService.exe [151552 2007-11-01] (CyberLink Corp.)
HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [300472 2010-05-12] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [976320 2009-12-03] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [TRUUpdater] => C:\Program Files (x86)\Sierra Wireless Inc\WebUpdater\TRUUpdater.exe [570736 2010-07-13] (Sierra Wireless, Inc.)
HKLM-x32\...\Run: [WatcherHelper] => C:\Program Files (x86)\Sierra Wireless Inc\3G Watcher\WaHelper.exe [103792 2010-06-23] (Sierra Wireless Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2020704 2014-07-09] (Wondershare)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-04-18] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3206371679-4115178929-761777742-1000\...\Run: [EPSON NX420 Series] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGCA.EXE [224768 2009-09-14] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3206371679-4115178929-761777742-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-3206371679-4115178929-761777742-1000\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-3206371679-4115178929-761777742-1000\...\Run: [com.apple.dav.bookmarks.daemon] => C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk [2011-09-23]
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk [2011-11-15]
ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install Webroot FF RunOnce.lnk [2012-11-15]
ShortcutTarget: Install Webroot FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\wruninstall.exe (Webroot Software, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install Webroot IE RunOnce.lnk [2012-11-15]
ShortcutTarget: Install Webroot IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\wruninstall.exe (Webroot Software, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2012-07-02]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.149\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk [2011-09-23]
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (No File)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk [2011-09-23]
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (No File)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3206371679-4115178929-761777742-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar64.dll [2012-11-15] ()
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06] (Adobe Systems Incorporated)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-09-02] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: iSkysoft Video Converter Ultimate -> {C7C3BC26-4F2B-4997-A3CB-163337FE975B} -> C:\Program Files (x86)\iSkysoft\Video Converter Ultimate\SVRIEPlugin.dll [2013-01-19] (iSkysoft Software Co., Ltd.)
BHO-x32: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar.dll [2012-11-15] ()
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-03-01] (Microsoft Corporation.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-09-02] (Oracle Corporation)
Toolbar: HKLM - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar64.dll [2012-11-15] ()
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-03-01] (Microsoft Corporation.)
Toolbar: HKLM-x32 - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar.dll [2012-11-15] ()
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2010-05-12] (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2010-05-12] (Citrix Systems, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 205.171.2.25
Tcpip\..\Interfaces\{086893CE-DFF2-436F-A597-AF439872C8A2}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{B6E6BE54-A718-4AF6-95D1-75DB49F73055}: [DhcpNameServer] 192.168.0.1 205.171.2.25

FireFox:
========
FF ProfilePath: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-13] ()
FF Plugin: @bestbuy.com/npBestBuyPcAppDetector,version=1.0 -> C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll [No File]
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-13] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin-x32: @bestbuy.com/npBestBuyPcAppDetector,version=1.0 -> C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll [No File]
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-09-02] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-09-02] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-27] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-27] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2011-06-06] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\CCMSDK.dll [2010-05-12] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\cgpcfg.dll [2010-05-12] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\CgpCore.dll [2010-05-12] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\confmgr.dll [2010-05-12] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxlogging.dll [2010-05-12] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ctxmui.dll [2010-05-12] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icafile.dll [2010-05-12] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\icalogon.dll [2010-05-12] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npicaN.dll [2010-05-12] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2015-05-10] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2015-05-10] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2015-05-10] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2015-05-10] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2015-05-10] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll [2015-05-10] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll [2015-05-10] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\sslsdk_b.dll [2010-04-14] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\TcpPServ.dll [2010-05-12] (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Owner\AppData\Roaming\mozilla\plugins\npatgpc.dll [2012-03-03] (Cisco WebEx LLC)
FF Extension: Webroot - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\Extensions\{8ac62a8b-8b3f-43ba-9b1a-90c299b9dfda} [2012-11-15]
FF Extension: FireFTP - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\Extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f} [2015-06-15]
FF Extension: Ghostery - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\lghuf863.default\Extensions\[email protected] [2013-08-21]
FF HKLM-x32\...\Firefox\Extensions: [{845257EF-A892-484e-8EB0-47F563D75939}] - C:\Program Files (x86)\iSkysoft\Video Converter Ultimate\SVRFirefoxExt
FF Extension: No Name - C:\Program Files (x86)\iSkysoft\Video Converter Ultimate\SVRFirefoxExt [2013-03-24]
FF HKU\S-1-5-21-3206371679-4115178929-761777742-1000\...\Firefox\Extensions: [{845257EF-A892-484e-8EB0-47F563D75939}] - C:\Program Files (x86)\iSkysoft\Video Converter Ultimate\SVRFirefoxExt
FF Extension: No Name - C:\Program Files (x86)\Consumer Input\Firefox\ciff-3.2.0-12191.xpi [not found]

Chrome:
=======
CHR Profile: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (iSkysoft Video Converter Ultimate) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlfeafapmnniobpffacckpddijdjgpmj [2013-08-01]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-08-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-04-21]
CHR Extension: (Webroot) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\okfhiodnpcnnnpgbjbhfebjnbagmfhab [2013-08-01]
CHR HKLM-x32\...\Chrome\Extension: [hlfeafapmnniobpffacckpddijdjgpmj] - C:\Program Files (x86)\iSkysoft\Video Converter Ultimate\SVRChromePlugin.crx [2013-03-24]
CHR HKLM-x32\...\Chrome\Extension: [okfhiodnpcnnnpgbjbhfebjnbagmfhab] - C:\ProgramData\WRData\pkg\lpchrome.crx [2012-11-15]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 DMAgent; C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [498688 2011-06-14] (Red Bend Ltd.) [File not signed]
S2 LeapFrog Connect Device Service; C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe [7393280 2013-10-31] (LeapFrog Enterprises, Inc.) [File not signed]
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.149\McCHSvc.exe [289256 2015-06-26] (McAfee, Inc.)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
S3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [272024 2006-12-19] ()
S2 SwiCardDetectSvc; C:\Program Files (x86)\Sierra Wireless Inc\Common\SwiCardDetect64.exe [284016 2010-07-13] (Sierra Wireless, Inc.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5448976 2015-04-17] (TeamViewer GmbH)
R2 WiMAXAppSrv; C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [986112 2011-06-14] (Intel® Corporation) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
R2 WRSVC; C:\Program Files (x86)\Webroot\WRSA.exe [822728 2015-07-27] (Webroot)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 assd; C:\Windows\System32\Drivers\assd.sys [27264 2010-04-28] (ASUS Corporation)
R3 FLxHCIh; C:\Windows\System32\DRIVERS\FLxHCIh.sys [56320 2011-04-08] (Fresco Logic)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-08-16] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
S3 swmsflt; C:\Windows\System32\DRIVERS\swmsflt.sys [48856 2010-04-15] ()
S3 SWNC8UA3; C:\Windows\System32\DRIVERS\swnc8ua3.sys [240640 2010-06-21] (Sierra Wireless Inc.)
S3 SWUMXA3; C:\Windows\System32\DRIVERS\swumxa3.sys [210944 2010-06-21] (Sierra Wireless Inc.)
R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13832 2010-04-16] ()
R0 WRkrn; C:\Windows\System32\drivers\WRkrn.sys [116224 2015-07-27] (Webroot)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-16 15:13 - 2015-08-16 15:13 - 00000000 ____D C:\Users\Owner\Desktop\FRST-OlderVersion
2015-08-16 14:47 - 2015-08-16 14:47 - 00001883 _____ C:\Users\Owner\Desktop\JRT.txt
2015-08-16 14:38 - 2015-08-16 14:36 - 01791580 _____ (Malwarebytes Corporation) C:\Users\Owner\Desktop\JRT.exe
2015-08-16 14:22 - 2015-08-16 14:22 - 00008648 _____ C:\AdwCleaner[C1].txt
2015-08-16 14:18 - 2015-08-16 14:18 - 00007970 _____ C:\AdwCleaner[S1].txt
2015-08-16 14:17 - 2015-08-16 14:14 - 01563648 _____ C:\Users\Owner\Desktop\adwcleaner_5.000.exe
2015-08-16 10:41 - 2015-08-16 10:41 - 00203208 _____ C:\tricia2.txt
2015-08-16 10:07 - 2015-08-16 14:27 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-16 10:07 - 2015-08-16 10:07 - 00001104 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-08-16 10:07 - 2015-08-16 10:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-08-16 10:06 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-08-16 10:06 - 2015-06-18 08:41 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-08-16 10:06 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-08-16 10:05 - 2015-08-14 20:17 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Owner\Desktop\mbam-setup-2.1.8.1057.exe
2015-08-14 01:22 - 2015-07-10 10:51 - 03722752 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-08-14 01:22 - 2015-07-10 10:51 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2015-08-14 01:22 - 2015-07-10 10:51 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2015-08-14 01:22 - 2015-07-10 10:34 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-08-14 01:22 - 2015-07-10 10:34 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2015-08-14 01:22 - 2015-07-10 10:33 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2015-08-13 07:49 - 2015-07-20 17:39 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-08-13 07:49 - 2015-07-20 17:12 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-08-13 07:49 - 2015-07-16 14:14 - 25192448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-08-13 07:49 - 2015-07-16 13:54 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-08-13 07:49 - 2015-07-16 13:54 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-08-13 07:49 - 2015-07-16 13:37 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-08-13 07:49 - 2015-07-16 13:36 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-08-13 07:49 - 2015-07-16 13:36 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-08-13 07:49 - 2015-07-16 13:36 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-08-13 07:49 - 2015-07-16 13:35 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-08-13 07:49 - 2015-07-16 13:35 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-08-13 07:49 - 2015-07-16 13:27 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-08-13 07:49 - 2015-07-16 13:26 - 05923328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-08-13 07:49 - 2015-07-16 13:26 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-08-13 07:49 - 2015-07-16 13:23 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-08-13 07:49 - 2015-07-16 13:21 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-08-13 07:49 - 2015-07-16 13:21 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-08-13 07:49 - 2015-07-16 13:21 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-08-13 07:49 - 2015-07-16 13:21 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-08-13 07:49 - 2015-07-16 13:20 - 19870208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-08-13 07:49 - 2015-07-16 13:12 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-13 07:49 - 2015-07-16 13:08 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-08-13 07:49 - 2015-07-16 13:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-08-13 07:49 - 2015-07-16 13:00 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-13 07:49 - 2015-07-16 12:55 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-08-13 07:49 - 2015-07-16 12:54 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-08-13 07:49 - 2015-07-16 12:51 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-08-13 07:49 - 2015-07-16 12:51 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-08-13 07:49 - 2015-07-16 12:51 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-08-13 07:49 - 2015-07-16 12:50 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-08-13 07:49 - 2015-07-16 12:50 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-08-13 07:49 - 2015-07-16 12:49 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-08-13 07:49 - 2015-07-16 12:45 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-08-13 07:49 - 2015-07-16 12:43 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-08-13 07:49 - 2015-07-16 12:43 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-08-13 07:49 - 2015-07-16 12:41 - 00479232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-08-13 07:49 - 2015-07-16 12:39 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-08-13 07:49 - 2015-07-16 12:39 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-08-13 07:49 - 2015-07-16 12:38 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-08-13 07:49 - 2015-07-16 12:36 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-08-13 07:49 - 2015-07-16 12:35 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-08-13 07:49 - 2015-07-16 12:34 - 14451200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-08-13 07:49 - 2015-07-16 12:33 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-08-13 07:49 - 2015-07-16 12:32 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-08-13 07:49 - 2015-07-16 12:29 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-08-13 07:49 - 2015-07-16 12:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-08-13 07:49 - 2015-07-16 12:20 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-08-13 07:49 - 2015-07-16 12:19 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-08-13 07:49 - 2015-07-16 12:17 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-08-13 07:49 - 2015-07-16 12:12 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-08-13 07:49 - 2015-07-16 12:12 - 02427904 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-08-13 07:49 - 2015-07-16 12:10 - 12856832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-08-13 07:49 - 2015-07-16 12:06 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-08-13 07:49 - 2015-07-16 12:06 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-08-13 07:49 - 2015-07-16 12:05 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-08-13 07:49 - 2015-07-16 12:01 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-08-13 07:49 - 2015-07-16 11:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-08-13 07:49 - 2015-07-16 11:42 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-08-13 07:49 - 2015-07-16 11:38 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-08-13 07:49 - 2015-07-16 11:37 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-08-13 07:49 - 2015-07-15 11:15 - 05568960 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-08-13 07:49 - 2015-07-15 11:15 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-08-13 07:49 - 2015-07-15 11:15 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-08-13 07:49 - 2015-07-15 11:15 - 00094656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-08-13 07:49 - 2015-07-15 11:12 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-08-13 07:49 - 2015-07-15 11:11 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-08-13 07:49 - 2015-07-15 11:11 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-08-13 07:49 - 2015-07-15 11:11 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-08-13 07:49 - 2015-07-15 11:11 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-08-13 07:49 - 2015-07-15 11:11 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-08-13 07:49 - 2015-07-15 11:10 - 01743360 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2015-08-13 07:49 - 2015-07-15 11:10 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-08-13 07:49 - 2015-07-15 11:10 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-08-13 07:49 - 2015-07-15 11:10 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-08-13 07:49 - 2015-07-15 11:10 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-08-13 07:49 - 2015-07-15 11:10 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-08-13 07:49 - 2015-07-15 11:10 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-08-13 07:49 - 2015-07-15 11:10 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-08-13 07:49 - 2015-07-15 11:10 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-08-13 07:49 - 2015-07-15 11:10 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-08-13 07:49 - 2015-07-15 11:10 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-08-13 07:49 - 2015-07-15 11:10 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-08-13 07:49 - 2015-07-15 11:10 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-08-13 07:49 - 2015-07-15 11:10 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-08-13 07:49 - 2015-07-15 11:10 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-08-13 07:49 - 2015-07-15 11:10 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-08-13 07:49 - 2015-07-15 11:10 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-08-13 07:49 - 2015-07-15 11:10 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-08-13 07:49 - 2015-07-15 11:10 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-08-13 07:49 - 2015-07-15 11:10 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-08-13 07:49 - 2015-07-15 11:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-08-13 07:49 - 2015-07-15 11:10 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-08-13 07:49 - 2015-07-15 11:10 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-08-13 07:49 - 2015-07-15 11:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-08-13 07:49 - 2015-07-15 11:09 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-08-13 07:49 - 2015-07-15 11:05 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-08-13 07:49 - 2015-07-15 11:05 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 11:00 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:59 - 03989952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-08-13 07:49 - 2015-07-15 10:59 - 03934656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-08-13 07:49 - 2015-07-15 10:56 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-08-13 07:49 - 2015-07-15 10:55 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-08-13 07:49 - 2015-07-15 10:55 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-08-13 07:49 - 2015-07-15 10:55 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-08-13 07:49 - 2015-07-15 10:55 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-08-13 07:49 - 2015-07-15 10:55 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-08-13 07:49 - 2015-07-15 10:54 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-08-13 07:49 - 2015-07-15 10:54 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-08-13 07:49 - 2015-07-15 10:54 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-08-13 07:49 - 2015-07-15 10:54 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-08-13 07:49 - 2015-07-15 10:54 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-08-13 07:49 - 2015-07-15 10:54 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-08-13 07:49 - 2015-07-15 10:54 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-08-13 07:49 - 2015-07-15 10:53 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-08-13 07:49 - 2015-07-15 10:53 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-08-13 07:49 - 2015-07-15 10:53 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-08-13 07:49 - 2015-07-15 10:53 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-08-13 07:49 - 2015-07-15 10:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-08-13 07:49 - 2015-07-15 10:53 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-08-13 07:49 - 2015-07-15 10:49 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-08-13 07:49 - 2015-07-15 10:48 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 10:44 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 09:46 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-08-13 07:49 - 2015-07-15 09:46 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-08-13 07:49 - 2015-07-15 09:46 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-08-13 07:49 - 2015-07-15 09:37 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-08-13 07:49 - 2015-07-15 09:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-08-13 07:49 - 2015-07-15 09:34 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 09:34 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 09:34 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-08-13 07:49 - 2015-07-15 09:34 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-08-13 07:48 - 2015-07-28 13:09 - 00017344 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-08-13 07:48 - 2015-07-28 13:05 - 01116672 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-08-13 07:48 - 2015-07-28 13:05 - 00774656 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-08-13 07:48 - 2015-07-28 13:05 - 00743424 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-08-13 07:48 - 2015-07-28 13:05 - 00437760 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-08-13 07:48 - 2015-07-28 13:05 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-08-13 07:48 - 2015-07-28 13:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-08-13 07:48 - 2015-07-28 12:55 - 01148416 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-08-13 07:46 - 2015-07-14 20:19 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2015-08-13 07:44 - 2015-07-01 13:49 - 00260096 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2015-08-13 07:44 - 2015-07-01 13:48 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2015-08-13 07:44 - 2015-07-01 13:30 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2015-08-13 07:44 - 2015-07-01 13:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2015-08-13 07:38 - 2015-07-30 11:06 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-08-13 07:38 - 2015-07-30 11:06 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-08-13 07:38 - 2015-07-30 11:06 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-08-13 07:38 - 2015-07-30 11:06 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-08-13 07:38 - 2015-07-30 11:06 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-08-13 07:38 - 2015-07-30 11:06 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-08-13 07:38 - 2015-07-30 11:06 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-08-13 07:38 - 2015-07-30 10:57 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2015-08-13 07:38 - 2015-07-30 10:57 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-08-13 07:38 - 2015-07-30 10:57 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-08-13 07:38 - 2015-07-30 10:57 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-08-13 07:38 - 2015-07-30 10:57 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-08-13 07:38 - 2015-07-30 10:55 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-08-13 07:38 - 2015-07-30 09:56 - 03208192 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-08-13 07:38 - 2015-07-30 09:52 - 00372736 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-08-13 07:38 - 2015-07-30 09:49 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-08-13 07:38 - 2015-07-14 20:19 - 02004992 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-08-13 07:38 - 2015-07-14 20:19 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-08-13 07:38 - 2015-07-14 20:14 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2015-08-13 07:38 - 2015-07-14 20:13 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-08-13 07:38 - 2015-07-14 19:55 - 01390592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2015-08-13 07:38 - 2015-07-14 19:55 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-08-13 07:38 - 2015-07-14 19:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2015-08-13 07:38 - 2015-07-14 19:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-08-13 07:38 - 2015-07-10 10:51 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-08-13 07:38 - 2015-07-10 10:34 - 12875776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-08-13 07:38 - 2015-07-09 10:57 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe
2015-08-13 07:38 - 2015-07-09 10:57 - 00193536 _____ (Microsoft Corporation) C:\Windows\notepad.exe
2015-08-13 07:38 - 2015-07-09 10:42 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
2015-08-13 07:37 - 2015-08-13 07:37 - 09284296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2015-08-13 07:37 - 2015-07-20 11:12 - 03154944 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-08-13 07:37 - 2015-07-20 11:12 - 02606080 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-08-13 07:37 - 2015-07-20 11:12 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-08-13 07:37 - 2015-07-20 11:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-08-13 07:37 - 2015-07-20 11:12 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-08-13 07:37 - 2015-07-20 11:12 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-08-13 07:37 - 2015-07-20 11:12 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-08-13 07:37 - 2015-07-20 11:12 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-08-13 07:37 - 2015-07-20 11:12 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-08-13 07:37 - 2015-07-20 11:12 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-08-13 07:37 - 2015-07-20 11:12 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-08-13 07:37 - 2015-07-20 10:56 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-08-13 07:37 - 2015-07-20 10:56 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-08-13 07:37 - 2015-07-20 10:56 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-08-13 07:37 - 2015-07-20 10:56 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-08-13 07:37 - 2015-07-20 10:56 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-08-13 07:37 - 2015-05-09 11:26 - 00493504 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll
2015-08-13 07:30 - 2015-07-30 06:13 - 00124624 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 07:30 - 2015-07-30 06:13 - 00103120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 07:23 - 2015-08-16 15:13 - 02173440 _____ (Farbar) C:\Users\Owner\Desktop\FRST64.exe
2015-08-12 15:26 - 2015-08-12 15:26 - 00016445 _____ C:\tricia.txt
2015-08-12 14:52 - 2015-08-16 10:07 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-08-12 14:52 - 2015-08-12 14:52 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-08-12 12:22 - 2015-08-16 14:22 - 00000000 ____D C:\AdwCleaner
2015-08-11 22:29 - 2015-08-11 22:29 - 00025653 _____ C:\Users\Owner\Downloads\fixlist.txt
2015-08-09 21:31 - 2015-08-09 21:31 - 00000000 ____D C:\Users\Owner\AppData\Roaming\System Cleaner Pro
2015-08-09 21:30 - 2015-08-13 07:07 - 00000000 ____D C:\Program Files (x86)\System Cleaner Pro
2015-08-09 10:05 - 2015-08-13 07:28 - 00047370 _____ C:\Users\Owner\Desktop\Addition.txt
2015-08-09 10:04 - 2015-08-16 15:14 - 00021953 _____ C:\Users\Owner\Desktop\FRST.txt
2015-08-09 10:04 - 2015-08-16 15:14 - 00000000 ____D C:\FRST
2015-08-08 23:35 - 2015-08-08 23:35 - 00000000 _____ C:\Windows\SysWOW64\Number of results
2015-08-08 22:29 - 2015-08-08 22:29 - 00000000 ____D C:\Windows\SysWOW64\Flash
2015-08-08 21:49 - 2009-06-10 14:00 - 00000824 _____ C:\Windows\system32\Drivers\etc\hp.bak
2015-08-07 23:21 - 2015-08-13 07:06 - 00000000 ____D C:\ProgramData\PopCap Games
2015-08-07 23:21 - 2015-08-07 23:21 - 00001315 _____ C:\Users\Public\Desktop\Plants vs. Zombies.lnk
2015-08-07 23:21 - 2015-08-07 23:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PopCap Games
2015-08-07 23:21 - 2015-08-07 23:21 - 00000000 ____D C:\Program Files (x86)\PopCap Games
2015-08-07 23:18 - 2015-08-07 23:19 - 42708728 _____ C:\Users\Owner\Downloads\PlantsVsZombies_20110922_EN_3_1.exe
2015-08-07 21:13 - 2015-06-01 17:07 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll
2015-08-07 21:13 - 2015-06-01 16:47 - 00210432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cewmdm.dll
2015-08-07 21:12 - 2015-06-17 10:47 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-08-07 21:12 - 2015-06-17 10:37 - 00312320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-08-07 21:11 - 2015-07-04 11:07 - 02087424 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2015-08-07 21:11 - 2015-07-04 10:48 - 01414656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2015-08-07 21:10 - 2015-06-15 14:50 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-08-07 21:10 - 2015-06-15 14:45 - 03242496 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-08-07 21:10 - 2015-06-15 14:45 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-08-07 21:10 - 2015-06-15 14:45 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2015-08-07 21:10 - 2015-06-15 14:45 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-08-07 21:10 - 2015-06-15 14:44 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2015-08-07 21:10 - 2015-06-15 14:43 - 02364416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2015-08-07 21:10 - 2015-06-15 14:43 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-08-07 21:10 - 2015-06-15 14:43 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2015-08-07 21:10 - 2015-06-15 14:42 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2015-08-07 21:10 - 2015-06-15 14:42 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2015-08-07 21:10 - 2015-06-15 14:37 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2015-08-07 21:10 - 2015-04-27 12:23 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-08-07 21:10 - 2015-04-27 12:23 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-08-07 21:10 - 2015-04-27 12:23 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-08-07 21:10 - 2015-04-27 12:23 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-08-07 21:10 - 2015-04-27 12:05 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2015-08-07 21:10 - 2015-04-27 12:04 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2015-08-07 21:10 - 2015-04-27 12:04 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2015-08-07 21:10 - 2015-04-27 12:04 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2015-07-27 08:53 - 2015-08-13 07:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2015-07-27 08:52 - 2015-08-13 07:08 - 00000000 ____D C:\Program Files\McAfee Security Scan

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-16 15:14 - 2012-01-18 15:02 - 00000000 ____D C:\ProgramData\WRData
2015-08-16 15:00 - 2013-08-01 13:46 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-16 14:44 - 2011-11-15 00:00 - 01438939 _____ C:\Windows\WindowsUpdate.log
2015-08-16 14:38 - 2009-07-13 21:45 - 00018736 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-16 14:38 - 2009-07-13 21:45 - 00018736 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-16 14:37 - 2013-10-12 10:34 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-08-16 14:23 - 2013-08-01 13:46 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-16 14:23 - 2012-01-17 21:45 - 00045056 _____ C:\Windows\system32\acovcnt.exe
2015-08-16 14:23 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-16 14:23 - 2009-07-13 21:51 - 00094573 _____ C:\Windows\setupact.log
2015-08-16 14:15 - 2011-09-23 05:39 - 00665764 _____ C:\Windows\PFRO.log
2015-08-16 10:39 - 2011-11-15 00:15 - 00001594 _____ C:\Windows\system32\ServiceFilter.ini
2015-08-16 10:35 - 2013-08-01 13:46 - 00002185 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-14 07:49 - 2012-01-17 21:46 - 00001415 _____ C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-13 21:24 - 2009-07-13 22:13 - 00797850 _____ C:\Windows\system32\PerfStringBackup.INI
2015-08-13 21:07 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\rescache
2015-08-13 20:34 - 2009-07-13 19:34 - 00000505 _____ C:\Windows\win.ini
2015-08-13 20:30 - 2009-07-13 21:45 - 00347432 _____ C:\Windows\system32\FNTCACHE.DAT
2015-08-13 20:28 - 2014-12-14 21:45 - 00000000 ____D C:\Windows\system32\appraiser
2015-08-13 20:28 - 2014-05-18 15:26 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-08-13 08:00 - 2012-07-02 16:03 - 00000000 ____D C:\Users\Owner\AppData\Roaming\Skype
2015-08-13 07:37 - 2013-10-12 10:34 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-08-13 07:37 - 2012-07-02 00:28 - 00778440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-08-13 07:37 - 2012-07-02 00:28 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-08-13 07:29 - 2013-03-14 19:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-08-13 07:28 - 2013-03-14 19:33 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-08-13 07:28 - 2013-03-14 19:33 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-08-13 07:27 - 2012-03-03 17:26 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-13 07:25 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\system32\GroupPolicy
2015-08-13 07:22 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\system32\NDF
2015-08-13 07:21 - 2013-08-15 08:00 - 00000000 ____D C:\Windows\system32\MRT
2015-08-13 07:16 - 2012-01-18 11:33 - 132483416 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-08-13 07:10 - 2011-11-15 00:15 - 00002558 _____ C:\Windows\system32\AutoRunFilter.ini
2015-08-13 07:09 - 2012-01-17 21:44 - 00000000 ____D C:\Users\Owner
2015-08-13 07:08 - 2015-04-06 07:55 - 00000000 ___SD C:\Windows\system32\GWX
2015-08-13 07:08 - 2014-09-02 16:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-08-13 07:08 - 2013-08-01 13:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-13 07:08 - 2012-11-15 07:32 - 00000000 ____D C:\Users\Owner\AppData\Local\lptmp660068200
2015-08-13 07:08 - 2012-07-02 00:28 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2015-08-13 07:08 - 2012-01-18 15:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webroot SecureAnywhere
2015-08-13 07:08 - 2012-01-18 15:01 - 00000000 ____D C:\Program Files (x86)\Webroot
2015-08-13 07:08 - 2012-01-17 21:44 - 00000000 ___RD C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-13 07:08 - 2012-01-17 21:44 - 00000000 ___RD C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-13 07:08 - 2011-11-15 00:14 - 00000000 ____D C:\ProgramData\P4G
2015-08-13 07:08 - 2011-11-15 00:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Best Buy Connect
2015-08-13 07:08 - 2011-11-15 00:13 - 00000000 ____D C:\Program Files (x86)\Best Buy Connect
2015-08-13 07:08 - 2009-07-13 20:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-13 07:08 - 2009-07-13 20:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-13 07:08 - 2009-07-13 20:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-13 07:08 - 2009-07-13 20:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-13 07:08 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-08-13 07:07 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\registration
2015-08-13 07:06 - 2014-09-02 16:21 - 00000000 ____D C:\Program Files (x86)\Java
2015-08-09 10:04 - 2012-01-17 21:45 - 00000000 ____D C:\Users\Owner\AppData\Local\VirtualStore
2015-08-09 09:21 - 2015-07-10 06:39 - 00000000 ___HD C:\$Windows.~BT
2015-08-09 09:03 - 2009-07-28 23:03 - 00000000 ____D C:\Windows\Panther
2015-08-08 22:59 - 2012-01-17 21:46 - 00000000 ____D C:\Users\Owner\AppData\Local\Deployment
2015-08-08 22:24 - 2015-06-15 08:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-08 22:24 - 2011-09-23 05:27 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2015-08-08 22:24 - 2011-09-23 05:27 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2015-08-08 21:35 - 2012-07-02 16:03 - 00000000 ____D C:\ProgramData\Skype
2015-08-07 23:21 - 2009-07-13 22:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-08-07 23:12 - 2015-04-06 07:55 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-08-02 19:48 - 2012-10-07 19:02 - 00000000 ____D C:\Users\Owner\Desktop\delti pics
2015-07-27 08:55 - 2013-08-01 13:46 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-07-27 08:55 - 2013-08-01 13:46 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-07-27 08:55 - 2012-01-18 15:02 - 00166128 _____ (Webroot) C:\Windows\SysWOW64\WRusr.dll
2015-07-27 08:55 - 2012-01-18 15:02 - 00116224 _____ (Webroot) C:\Windows\system32\Drivers\WRkrn.sys
2015-07-27 08:55 - 2012-01-18 15:02 - 00103816 _____ (Webroot) C:\Windows\system32\WRusr.dll
2015-07-27 08:53 - 2012-07-02 00:28 - 00001936 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2015-07-27 08:52 - 2015-04-15 11:19 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-07-27 08:49 - 2012-05-05 18:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service

==================== Files in the root of some directories =======

2012-11-15 07:32 - 2012-11-15 07:32 - 9842040 _____ (Webroot Software, Inc.) C:\Program Files (x86)\Common Files\wruninstall.exe
2015-04-14 09:28 - 2015-04-14 09:28 - 0004387 _____ () C:\Users\Owner\AppData\Roaming\DK8is89dyPzmla2uemyT3
2011-11-15 00:19 - 2011-11-15 00:19 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2011-11-15 00:18 - 2011-11-15 00:19 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log

Some files in TEMP:
====================
C:\Users\Owner\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll
[2011-09-23 05:27] - [2015-08-08 22:24] - 0357888 ____A (Microsoft Corporation) 67529135895CE87AD5B2C33F4CBFE4F1

C:\Windows\SysWOW64\dnsapi.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-08-13 08:18

==================== End of log ============================

 

addition.txt log:

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:16-08-2015
Ran by Owner (2015-08-16 15:14:44)
Running from C:\Users\Owner\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3206371679-4115178929-761777742-500 - Administrator - Disabled)
Guest (S-1-5-21-3206371679-4115178929-761777742-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3206371679-4115178929-761777742-1002 - Limited - Enabled)
Owner (S-1-5-21-3206371679-4115178929-761777742-1000 - Administrator - Enabled) => C:\Users\Owner

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Webroot SecureAnywhere (Enabled - Up to date) {66A6FE14-08CB-F415-3742-517201416109}
AS: Webroot SecureAnywhere (Enabled - Up to date) {DDC71FF0-2EF1-FB9B-0DF2-6A007AC62BB4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.0.32.18 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Reader X (10.1.0) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.0 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM-x32\...\InstallShield_{1F7424F8-F992-48BC-90EF-7C4DB0405E3F}) (Version: 1.7.17.25416 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.7.17.25416 - Alcor Micro Corp.) Hidden
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ASUS AI Recovery (HKLM-x32\...\{38253529-D97D-4901-AE53-5CC9736D3A2E}) (Version: 1.0.13 - ASUS)
ASUS FancyStart (HKLM-x32\...\{2B81872B-A054-48DA-BE3B-FA5C164C303A}) (Version: 1.0.8 - ASUSTeK Computer Inc.)
ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.21 - ASUS)
ASUS Live Update (HKLM-x32\...\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}) (Version: 2.5.9 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.1.43 - ASUS)
ASUS Secure Delete (HKLM\...\{761C6783-D3BC-48AB-8E7C-61CE918A8436}) (Version: 1.00.0006 - ASUS)
ASUS SmartLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0011 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0031 - ASUS)
ASUS U Series ScreenSaver (HKLM-x32\...\ASUS U Series ScreenSaver) (Version: 1.0.0002 - ASUS)
ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.21 - asus)
AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.6.125 - ASUSTEK)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0008 - ASUS)
Best Buy Connect (HKLM-x32\...\{B435FD87-CA14-45E3-9D0B-A30F1F9F3866}) (Version: 3.00.68 - Best Buy)
Best Buy pc app (HKU\S-1-5-21-3206371679-4115178929-761777742-1000\...\e55b814e55744b76) (Version: 3.2.545.3 - Best Buy)
Best Buy pc app (Version: 3.2.2.0 - Best Buy) Hidden
Best Buy pc app (x32 Version: 3.2.2.0 - Best Buy) Hidden
Bing Bar (HKLM-x32\...\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}) (Version: 7.0.610.0 - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Citrix online plug-in (Web) (HKLM-x32\...\{B124E6D3-91B4-4E3C-AD03-BA959B223537}) (Version: 12.0.3.6 - Citrix Systems, Inc.)
CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1908 - CyberLink Corp.)
CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3602c - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Digital Photo Navigator 1.5 (HKLM-x32\...\{CF9CD37C-E29A-11D5-AE3D-005004B8E30C}) (Version:  - )
DrSpeedyPC (HKLM-x32\...\DrSpeedyPC) (Version:  - )
Epson Event Manager (HKLM-x32\...\{03B8AA32-F23C-4178-B8E6-09ECD07EAA47}) (Version: 2.40.0001 - SEIKO EPSON CORPORATION)
EPSON NX420 Series Printer Uninstall (HKLM\...\EPSON NX420 Series) (Version:  - SEIKO EPSON Corporation)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - Seiko Epson Corporation)
Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.10 - ASUS)
Free M4a to MP3 Converter 7.2 (HKLM-x32\...\Free M4a to MP3 Converter_is1) (Version:  - ManiacTools.com)
Fresco Logic USB3.0 Host Controller (HKLM\...\{B1E301A1-C2B4-4B0B-AF31-C71F8A53DCDA}) (Version: 3.0.119.1 - Fresco Logic Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 44.0.2403.155 - Google Inc.)
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
iCloud (HKLM\...\{2AAF09D5-4B3F-4975-B6A9-ECE2631FC942}) (Version: 4.0.5.20 - Apple Inc.)
iExplorer 3.7.4.0 (HKLM-x32\...\{7FD8B0C1-CDDA-4B4D-A577-B2E3570EA3A3}_is1) (Version:  - Macroplant LLC)
Intel PROSet Wireless (x32 Version:  - ) Hidden
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2291 - Intel Corporation)
Intel® PROSet/Wireless WiFi Software (HKLM\...\{3C41721F-AF0F-4086-AA1C-4C7F29076228}) (Version: 14.01.1000 - Intel Corporation)
Intel® Turbo Boost Technology Monitor (HKLM\...\{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}) (Version: 1.0.400.4 - Intel)
Intel® WiDi (HKLM-x32\...\{25680C01-6753-4FE9-A891-7857F26457C1}) (Version: 2.1.35.0 - Intel Corporation)
Intel® Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
Intel® PROSet/Wireless WiMAX Software (HKLM\...\{5C1DA3D9-F590-4317-A4FB-274F658E504B}) (Version: 6.05.0000 - Intel Corporation)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.32 - Irfan Skiljan)
iSkysoft Video Converter Ultimate(Build 4.0.1.0) (HKLM-x32\...\iSkysoft Video Converter Ultimate_is1) (Version: 4.0.1.0 - iSkysoft Software)
iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LeapFrog Connect (HKLM-x32\...\UPCShell) (Version: 5.1.26.18340 - LeapFrog)
LeapFrog Connect (x32 Version: 5.1.26.18340 - LeapFrog) Hidden
LeapFrog LeapPad Explorer Plugin (x32 Version: 5.1.26.18340 - LeapFrog) Hidden
LeapFrog MyOwnLeaptop Plugin (x32 Version: 5.1.26.18340 - LeapFrog) Hidden
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.149.2 - McAfee, Inc.)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 38.0.5 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 38.0.5 (x86 en-US)) (Version: 38.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla)
Mozilla Thunderbird 15.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Thunderbird 15.0.1 (x86 en-US)) (Version: 15.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Plants vs. Zombies (HKLM-x32\...\Plants vs. Zombies) (Version:  - PopCap Games)
PowerCinema NE for Everio (HKLM-x32\...\{39CEE1F2-12B6-4C50-9131-04BFCA110578}) (Version:  - )
PowerDirector Express (HKLM-x32\...\{EDE721EC-870A-11D8-9D75-000129760D75}) (Version:  - )
PowerProducer (HKLM-x32\...\{B7A0CE06-068E-11D6-97FD-0050BACBF861}) (Version: 074511a(3.7)_Vista_JVC - CyberLink Corp.)
QuickTime (HKLM-x32\...\{0E64B098-8018-4256-BA23-C316A43AD9B0}) (Version: 7.72.80.56 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6392 - Realtek Semiconductor Corp.)
SceneSwitch (HKLM-x32\...\{5172E572-C175-4F80-A6D5-5CB45826AD61}) (Version: 1.0.6 - ASUS)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Sierra Wireless AirCard Watcher (HKLM-x32\...\{7AC21DE8-2904-4667-99C7-732A02B1324E}) (Version: 6.0.2699.6301 - Sierra Wireless Inc.)
Skype™ 7.7 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.7.103 - Skype Technologies S.A.)
Sonic Focus (HKLM-x32\...\{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}) (Version: 1.0.0.4 - Synopsys )
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.6.0 - Synaptics Incorporated)
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.41459 - TeamViewer)
Use the entry named LeapFrog Connect to uninstall (LeapFrog LeapPad Explorer Plugin) (HKLM-x32\...\LeapPadExplorerPlugin) (Version:  - LeapFrog)
Use the entry named LeapFrog Connect to uninstall (LeapFrog MyOwnLeaptop Plugin) (HKLM-x32\...\LeaptopPlugin) (Version:  - LeapFrog)
Webroot SecureAnywhere (HKLM-x32\...\WRUNINST) (Version: 9.0.1.35 - Webroot)
Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net  (09/10/2009 02.03.05.012) (HKLM\...\8F14F2ECEDE68D26EA515B48DC25B39103C4FE8D) (Version: 09/10/2009 02.03.05.012 - Leapfrog)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.31.1 - ASUS)
Wireless Console 3 (HKLM-x32\...\{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}) (Version: 3.0.19 - ASUS)
Wondershare Video Editor(Build 4.6.0) (HKLM-x32\...\Wondershare Video Editor_is1) (Version:  - Wondershare Software)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================

13-08-2015 12:01:56 Windows Update
13-08-2015 21:23:36 Restore Point Created by FRST
14-08-2015 03:00:10 Windows Update
14-08-2015 07:38:47 Restore Point Created by FRST
16-08-2015 14:39:34 JRT Pre-Junkware Removal

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 19:34 - 2009-06-10 14:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {008CF8DA-6DE9-4DC6-A075-0FAB8521E08F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-01] (Google Inc.)
Task: {104CEB10-3E29-4685-9280-FFB59132F0E6} - \ConsumerInputUpdateTaskMachineUA -> No File <==== ATTENTION
Task: {23DBCB30-02B3-4C4A-9BDB-E6F772CB7BED} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2010-11-15] (ASUS)
Task: {472A4209-B80C-4BB8-97DA-A8499DC01B82} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {5A83F9D6-EB46-425F-B12F-89B5768FF848} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS)
Task: {5ABF7B85-4D0C-4A52-BD34-96AD4AD7301A} - \CIMT_S-1-5-21-3206371679-4115178929-761777742-1000 -> No File <==== ATTENTION
Task: {707DF837-F854-4D6E-A6BD-C10027F85872} - \ConsumerInputUpdateTaskMachineCore -> No File <==== ATTENTION
Task: {7258C0C7-1D18-4A99-9C7D-7D094BA06E37} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2010-08-02] (ASUS)
Task: {A0DCA9D5-BBBE-427D-90C1-1F3E9877CE95} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-13] (Adobe Systems Incorporated)
Task: {B01A05AD-48EF-48F7-98F8-9452D0B1F72F} - System32\Tasks\ASUS Patch 10430001 => C:\Windows\AsPatch10430001.exe [2010-07-29] ()
Task: {BD85C3C8-AC0C-486B-9B36-B437CA41BBE7} - \WebBarLaunchTask -> No File <==== ATTENTION
Task: {CC694E9E-259C-48EB-89AC-4BB0B713F4F5} - System32\Tasks\ASUS Secure Delete => C:\Program Files\ASUS\ASUS Secure Delete\ADDEL.exe [2010-05-11] ()
Task: {CE285F28-DC0D-45B2-A41F-C5D768861CC4} - \DrspeedyPc Secure -> No File <==== ATTENTION
Task: {DE63DC20-24F5-4278-B4C8-20D688B15AF6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-01] (Google Inc.)
Task: {EB31BCEC-BF3F-4549-A96F-225D0B175682} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-12-01] (ASUS)
Task: {F0BF0259-B9B1-43EF-AC92-D47976342F14} - \Inst_Rep -> No File <==== ATTENTION
Task: {F6610C81-8F26-4295-89F2-B2B37BCEAECE} - \CIMT_daily_S-1-5-21-3206371679-4115178929-761777742-1000 -> No File <==== ATTENTION
Task: {F9CF4761-D978-4B2F-9A08-1D88C88CDF51} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe [2007-11-30] ()

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2013-03-24 20:43 - 2013-01-08 10:32 - 00721917 _____ () C:\Windows\SysWOW64\ISCM64.dll
2014-02-12 21:58 - 2014-02-12 21:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 14:05 - 2014-10-11 14:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3206371679-4115178929-761777742-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1 - 205.171.2.25
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe
MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{971ECBD0-029F-40E0-9A58-8AC6FDEB5240}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{BD0BEA2A-8059-4F00-B27A-59CBF24842F9}] => (Allow) LPort=2869
FirewallRules: [{FF166191-502D-4474-AB35-56B29DF72699}] => (Allow) LPort=1900
FirewallRules: [{B87DEACC-75E4-42E4-B8AE-45D17B4094C9}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{94D57A9D-82D4-4819-801F-5C580C5F10E1}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{0CECF09F-7F53-4DE5-BAD1-70F17C800115}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{56D7E544-6B1D-4764-8AA1-BD06EB2D3FB0}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
FirewallRules: [{47DEB5A5-0E90-477C-8884-5A61AF5FB907}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
FirewallRules: [{21D28BA4-7579-4806-9251-73D99F27B866}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
FirewallRules: [{F92E7C54-A565-477C-87E4-FEFA4E88C401}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
FirewallRules: [{0EA81692-61A8-408C-B609-7B26679D76A0}] => (Allow) C:\Program Files (x86)\Intel Corporation\Intel WiDi\WiDiApp.exe
FirewallRules: [{D77A872E-8CF6-4F6C-998F-3F64E961E880}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector Express\PDX.EXE
FirewallRules: [{4E81B0FF-3BA0-4AF2-B90C-E0E0C6877671}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
FirewallRules: [{6F082AF8-BFDE-4FB9-B989-52479AC6FC3F}] => (Allow) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
FirewallRules: [TCP Query User{0AF121D4-C84F-4A71-9F9B-1F4216CE9932}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe
FirewallRules: [UDP Query User{442D7FC3-D5D1-4C13-9D85-D82014621323}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Block) C:\program files (x86)\epson software\event manager\eeventmanager.exe
FirewallRules: [{715A7F41-612C-49C8-993E-9A458172C0DD}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{14FA5589-EC60-403B-AAA9-77F725D0A349}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A0300A6D-5AA3-461B-9801-414C836C01B1}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{EF97939D-46D2-4135-9F45-A9D3734330E5}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{B23BEDE7-0F39-402C-9DC4-2FD1EEEC0230}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{56842EB6-8B4D-409B-90E1-ECD875E23024}] => (Allow) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\LeapfrogConnect.exe
FirewallRules: [TCP Query User{6EC1A75F-F416-49DB-8B5B-D583B1ED7374}C:\program files (x86)\iskysoft\video converter ultimate\urlreqservice.exe] => (Allow) C:\program files (x86)\iskysoft\video converter ultimate\urlreqservice.exe
FirewallRules: [UDP Query User{23BCFB8C-C5C4-4FE2-936E-2499F1AC110F}C:\program files (x86)\iskysoft\video converter ultimate\urlreqservice.exe] => (Allow) C:\program files (x86)\iskysoft\video converter ultimate\urlreqservice.exe
FirewallRules: [{2D419864-6670-441C-8AEE-AF796079CCE0}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{B1A0592A-0087-4214-8650-D596D3101743}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{E6027A77-1296-42D9-AB3A-2F2EE7F41D24}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{716D0095-327B-4509-AF9A-58150BF568F3}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{3847B58A-D1AE-4424-9450-6EBD7AA85BD3}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{C2275A14-EF6F-4CE2-9D52-502E06AED029}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{94F4A426-4DCA-4775-97C3-AD107747957B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{1F5982AA-4AFF-4F74-8BF1-C98EBC71B0E5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Sierra Wireless Inc\3G Watcher\TRUUpdater.exe] => C:\Program Files (x86)\Sierra Wireless Inc\WebUpdater\TRUUpdater.exe:*:Enabled:TRUUpdater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Sierra Wireless Inc\WebUpdater\SwiApiMuxX.exe] => Enabled:SwiApiMuxX
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Sierra Wireless Inc\3G Watcher\SwiApiMuxX.exe] => Enabled:SwiApiMuxX
StandardProfile\AuthorizedApplications: [C:\Windows\TEMP\x20su.exe] => Enabled:Policy

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (08/14/2015 07:49:26 AM) (Source: ESENT) (EventID: 215) (User: )
Description: WinMail (4520) WindowsMail0: The backup has been stopped because it was halted by the client or the connection with the client failed.

Error: (08/14/2015 07:38:48 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddWin32ServiceFiles: Unable to back up image of service Util Coupon Time since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.
.

Error: (08/14/2015 07:38:48 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddWin32ServiceFiles: Unable to back up image of service Update Coupon Time since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.
.

Error: (08/14/2015 03:00:10 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddWin32ServiceFiles: Unable to back up image of service Util Coupon Time since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.
.

Error: (08/14/2015 03:00:10 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddWin32ServiceFiles: Unable to back up image of service Update Coupon Time since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.
.

Error: (08/13/2015 09:23:36 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.


Operation:
   Gathering Writer Data

Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {010c344c-bc8e-4498-88b3-7d5c687ad3a0}

Error: (08/13/2015 09:23:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: winpl.exe, version: 1.0.0.1, time stamp: 0x555dc22c
Faulting module name: libcef.dll, version: 3.2171.1972.0, time stamp: 0x54b78ee6
Exception code: 0x80000003
Fault offset: 0x0013b7f0
Faulting process id: 0x1d48
Faulting application start time: 0xwinpl.exe0
Faulting application path: winpl.exe1
Faulting module path: winpl.exe2
Report Id: winpl.exe3

Error: (08/13/2015 09:23:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: winpl.exe, version: 1.0.0.1, time stamp: 0x555dc22c
Faulting module name: libcef.dll, version: 3.2171.1972.0, time stamp: 0x54b78ee6
Exception code: 0x80000003
Fault offset: 0x0013b7f0
Faulting process id: 0x8d4
Faulting application start time: 0xwinpl.exe0
Faulting application path: winpl.exe1
Faulting module path: winpl.exe2
Report Id: winpl.exe3

Error: (08/13/2015 09:23:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: winpl.exe, version: 1.0.0.1, time stamp: 0x555dc22c
Faulting module name: libcef.dll, version: 3.2171.1972.0, time stamp: 0x54b78ee6
Exception code: 0x80000003
Fault offset: 0x0013b7f0
Faulting process id: 0x1c68
Faulting application start time: 0xwinpl.exe0
Faulting application path: winpl.exe1
Faulting module path: winpl.exe2
Report Id: winpl.exe3

Error: (08/13/2015 09:22:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: winpl.exe, version: 1.0.0.1, time stamp: 0x555dc22c
Faulting module name: libcef.dll, version: 3.2171.1972.0, time stamp: 0x54b78ee6
Exception code: 0x80000003
Fault offset: 0x0013b7f0
Faulting process id: 0x3c4
Faulting application start time: 0xwinpl.exe0
Faulting application path: winpl.exe1
Faulting module path: winpl.exe2
Report Id: winpl.exe3


System errors:
=============
Error: (08/16/2015 02:40:37 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Modules Installer service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.

Error: (08/16/2015 02:40:37 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly.  It has done this 1 time(s).

Error: (08/16/2015 02:40:37 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (08/16/2015 02:40:37 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The iPod Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (08/16/2015 02:40:35 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Intel® PROSet/Wireless WiMAX Red Bend Device Management Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

Error: (08/16/2015 02:40:35 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Live ID Sign-in Assistant service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.

Error: (08/16/2015 02:40:34 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Intel® PROSet/Wireless WiMAX Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

Error: (08/16/2015 02:40:34 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Intel® Turbo Boost Technology Monitor service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 1000 milliseconds: Restart the service.

Error: (08/16/2015 02:40:34 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Sierra Wireless Card Detection Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (08/16/2015 02:40:34 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The SeaPort service terminated unexpectedly.  It has done this 1 time(s).


Microsoft Office:
=========================
Error: (08/14/2015 07:49:26 AM) (Source: ESENT) (EventID: 215) (User: )
Description: WinMail4520WindowsMail0:

Error: (08/14/2015 07:38:48 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Details:
AddWin32ServiceFiles: Unable to back up image of service Util Coupon Time since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.

Error: (08/14/2015 07:38:48 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Details:
AddWin32ServiceFiles: Unable to back up image of service Update Coupon Time since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.

Error: (08/14/2015 03:00:10 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Details:
AddWin32ServiceFiles: Unable to back up image of service Util Coupon Time since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.

Error: (08/14/2015 03:00:10 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Details:
AddWin32ServiceFiles: Unable to back up image of service Update Coupon Time since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.

Error: (08/13/2015 09:23:36 PM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Access is denied.


Operation:
   Gathering Writer Data

Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {010c344c-bc8e-4498-88b3-7d5c687ad3a0}

Error: (08/13/2015 09:23:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: winpl.exe1.0.0.1555dc22clibcef.dll3.2171.1972.054b78ee6800000030013b7f01d4801d0d648f7f502caC:\Users\Owner\AppData\Roaming\TWV\winpl.exeC:\Users\Owner\AppData\Roaming\TWV\libcef.dll35ab132b-423c-11e5-aadb-5404a63c37f3

Error: (08/13/2015 09:23:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: winpl.exe1.0.0.1555dc22clibcef.dll3.2171.1972.054b78ee6800000030013b7f08d401d0d648f1f46315C:\Users\Owner\AppData\Roaming\TWV\winpl.exeC:\Users\Owner\AppData\Roaming\TWV\libcef.dll2faa7377-423c-11e5-aadb-5404a63c37f3

Error: (08/13/2015 09:23:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: winpl.exe1.0.0.1555dc22clibcef.dll3.2171.1972.054b78ee6800000030013b7f01c6801d0d648ebf2aa24C:\Users\Owner\AppData\Roaming\TWV\winpl.exeC:\Users\Owner\AppData\Roaming\TWV\libcef.dll29ab1be6-423c-11e5-aadb-5404a63c37f3

Error: (08/13/2015 09:22:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: winpl.exe1.0.0.1555dc22clibcef.dll3.2171.1972.054b78ee6800000030013b7f03c401d0d648e5f0ca23C:\Users\Owner\AppData\Roaming\TWV\winpl.exeC:\Users\Owner\AppData\Roaming\TWV\libcef.dll23a6da84-423c-11e5-aadb-5404a63c37f3


CodeIntegrity:
===================================
  Date: 2015-08-08 22:36:37.388
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-08 22:36:02.068
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-08 22:35:57.958
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-08 22:34:23.314
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-08 22:34:17.884
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-08 22:34:01.130
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-08 22:33:53.980
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-08 22:32:43.448
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-08 22:32:38.109
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.

  Date: 2015-08-08 22:31:58.172
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: Intel® Core™ i7-2620M CPU @ 2.70GHz
Percentage of memory in use: 21%
Total physical RAM: 8102.76 MB
Available physical RAM: 6391.62 MB
Total Virtual: 16203.72 MB
Available Virtual: 14393.35 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:673.64 GB) (Free:447.28 GB) NTFS ==>[system with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: 496B9619)
Partition 1: (Not Active) - (Size=25 GB) - (Type=1C)
Partition 2: (Active) - (Size=673.6 GB) - (Type=07 NTFS)

==================== End of log ============================


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP